This Data Processing Addendum (the “DPA”) forms part of the Jolly Terms of Use between Sign With Jolly, LLC, an Indiana limited liability company (“Jolly,” “we,” “us”), and the company that has a Jolly account and places orders through it (“Customer,” “you”).
It applies automatically to every company using Jolly, with no separate signature required. It exists because our customers are frequently title companies, escrow offices, lenders, and signing services with obligations of their own — under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, under state privacy laws including the California Consumer Privacy Act, and under their own clients' contracts — and those obligations require specific commitments from the vendors they use. This document makes those commitments.
If you need a countersigned copy for your vendor file, email security@signwithjolly.com and we will execute this document for your records. If your organization requires its own data processing agreement instead, send it and we will review it.
1. Definitions
Capitalized terms not defined here have the meaning given in the Terms of Use.
- Customer Data means information Customer or its users submit to, or that Jolly processes on Customer's behalf through, the Jolly service — including orders, signer details, uploaded documents, client records, and related correspondence.
- Personal Information means information within Customer Data that identifies, relates to, or could reasonably be linked with a particular individual or household, including “personal information” as defined by the CCPA and “nonpublic personal information” as defined by the GLBA.
- Process and Processing mean any operation performed on Personal Information, including collection, storage, use, transmission, disclosure, and deletion.
- Security Incident means a confirmed breach of Jolly's security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Data in Jolly's possession. Unsuccessful attempts that do not compromise data — routine scanning, blocked sign-in attempts, denied access — are not Security Incidents.
- Subprocessor means a third party engaged by Jolly to Process Personal Information in connection with providing the service.
- CCPA means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act, and its implementing regulations. GLBA means the Gramm-Leach-Bliley Act. Safeguards Rule means the FTC Standards for Safeguarding Customer Information, 16 C.F.R. Part 314.
2. Roles of the parties
As between Jolly and Customer, Customer determines the purposes and means of Processing Customer Data and is the business (and, where applicable, the controller). Jolly Processes Customer Data on Customer's behalf as a service provider (and, where applicable, the processor).
Jolly does not decide what orders are placed, who is engaged for them, or what documents are uploaded. Customer is responsible for the lawfulness of the Personal Information it submits, for having the authority to submit it, and for the accuracy of the orders it places.
Separately from this DPA, Jolly acts as a business in its own right with respect to a limited set of information it determines the purposes of — account registration details, billing records, usage logs, and support correspondence — and with respect to notary profile information, which belongs to the notary and is maintained across the platform rather than on any one Customer's behalf. Our Privacy Policy describes that processing.
3. Scope and instructions
Jolly Processes Customer Data only:
- to provide, maintain, secure, and support the Jolly service in accordance with the Terms of Use;
- in accordance with Customer's documented instructions, of which the Terms of Use, this DPA, and Customer's use of the service's features are the complete set; and
- as required by applicable law, in which case Jolly will inform Customer of the requirement before Processing unless the law forbids it.
If Jolly determines that an instruction infringes applicable law, it will inform Customer without undue delay.
4. Service provider commitments under the CCPA
Jolly certifies that it understands the restrictions in this section and will comply with them. Jolly will not:
- sell or share Personal Information, as those terms are defined by the CCPA;
- retain, use, or disclose Personal Information for any purpose other than performing the services specified in the Terms of Use, including retaining, using, or disclosing it for a commercial purpose other than providing those services, or outside the direct business relationship between Jolly and Customer;
- combine Personal Information received from or on behalf of Customer with Personal Information received from or on behalf of any other person, or collected from Jolly's own interactions with a consumer, except as permitted by the CCPA and its regulations for a service provider;
- use Personal Information to build or improve profiles of individuals for purposes unrelated to the service; or
- use Personal Information to train any general-purpose artificial intelligence model, or provide it to any third party for that purpose.
Jolly will notify Customer promptly if it determines it can no longer meet these obligations. Customer may, on notice, take reasonable and appropriate steps to stop and remediate unauthorized Processing.
5. Financial-institution customers: GLBA and the Safeguards Rule
Jolly acknowledges that Customer may be a financial institution subject to the GLBA and the Safeguards Rule, that Customer Data may include nonpublic personal information about Customer's own customers, and that Customer is obliged to select and retain service providers capable of maintaining appropriate safeguards and to contract for those safeguards.
Accordingly, Jolly will implement and maintain administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of Customer Data, as described in Section 6 and in our Security Overview. Jolly maintains a written information security program and will provide a summary of it on Customer's reasonable request.
Jolly will use nonpublic personal information only to provide the service and will not disclose it except as permitted by this DPA or required by law.
6. Security measures
Jolly maintains the technical and organizational measures described in our Security Overview, which is incorporated into this DPA and summarized in Appendix B. These include encryption of Customer Data in transit and at rest, access controls that separate each company's data from every other company's, authenticated and order-scoped access to uploaded documents, automatic deletion of signing documents after Customer's chosen retention window, and restriction of production access to personnel who require it.
Jolly may update these measures as the service evolves, provided the updates do not materially reduce the overall level of protection.
Jolly ensures that personnel authorized to Process Customer Data are subject to obligations of confidentiality.
7. Subprocessors
Customer authorizes Jolly to engage Subprocessors. The current list is published at jollyorders.com/security and forms Appendix C.
Jolly will impose on each Subprocessor data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for each Subprocessor's performance of those obligations.
Jolly will give Customer at least thirty (30) days' notice before adding a Subprocessor that will Process Personal Information, by email to the account owner. If Customer reasonably objects on data protection grounds within that period, the parties will work in good faith to find an alternative; if none is available, Customer may terminate the affected service without penalty and receive a pro-rata refund of any prepaid fees for the unused period.
8. Security incidents
On becoming aware of a Security Incident affecting Customer Data, Jolly will:
- notify Customer without undue delay and in any event within seventy-two (72) hours of confirming the incident, at the account owner's email address on file;
- describe the nature of the incident, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed;
- take reasonable steps to contain, investigate, and mitigate the incident, and preserve relevant evidence;
- provide reasonable cooperation and information to assist Customer in meeting its own notification obligations to regulators, its clients, and affected individuals; and
- provide a written summary of findings and remedial measures once the investigation concludes.
Jolly will not make a public statement identifying Customer in connection with a Security Incident without Customer's prior consent, unless required by law. Notification is not an acknowledgement of fault or liability.
9. Assisting Customer with individual rights requests
Where an individual makes a request to Customer to access, correct, delete, or limit the use of Personal Information held in Jolly, Jolly will provide reasonable assistance to Customer in responding, taking into account the nature of the Processing. Customer can retrieve, correct, and delete most Customer Data directly in the application; where it cannot, Jolly will assist on request.
If an individual contacts Jolly directly with such a request relating to Customer Data, Jolly will not respond substantively except to direct the individual to Customer, and will notify Customer of the request without undue delay unless prohibited by law.
10. Deletion and return
Uploaded signing documents are deleted automatically after the retention window Customer configures, without any action by Customer, as described in the Security Overview.
On termination of Customer's account, Jolly will delete Customer Data within ninety (90) days, except where retention is required by law or reasonably necessary for tax, accounting, or legal-defense purposes, and except for backups, which are deleted in the ordinary course of the backup cycle and remain subject to this DPA until they are. Before deletion, Customer may export its records through the application, and may request reasonable assistance in doing so.
11. Audits and vendor review
Jolly will make available the information reasonably necessary to demonstrate compliance with this DPA. Specifically, Jolly will:
- maintain a current Security Overview and Subprocessor list;
- complete Customer's standard security questionnaire, at no charge, once per year and on a material change to the service; and
- provide a summary of its written information security program on reasonable request.
Jolly does not hold a SOC 2 report or ISO 27001 certification today, and does not offer on-site audits or penetration testing of production by customers. We state this plainly here so that it is settled before a contract rather than discovered during one. If Customer's requirements go beyond what this section offers, contact us before relying on the service.
12. International transfers
Jolly Processes and stores Customer Data in the United States. Jolly does not transfer Customer Data outside the United States in the ordinary operation of the service. Jolly does not currently offer data residency in any other region.
13. Relationship to the Terms of Use
This DPA supplements the Terms of Use. In the event of a conflict between this DPA and the Terms of Use with respect to the Processing of Personal Information, this DPA controls. In all other respects the Terms of Use remain in full force.
Any limitation or exclusion of liability in the Terms of Use applies to claims arising under this DPA, and the parties' total combined liability under the Terms of Use and this DPA is subject to a single aggregate cap as stated in the Terms of Use, except where applicable law does not permit that limitation.
14. Changes to this DPA
Jolly may update this DPA to reflect changes in law, the service, or our practices. Material changes that reduce Customer's protections will be notified to account owners at least thirty (30) days before they take effect, and Customer may terminate without penalty if it does not accept them. The version identifier at the top of this page identifies the current text.
15. Governing law
This DPA is governed by the laws of the State of Indiana, without regard to its conflict of law rules, and the venue and dispute provisions of the Terms of Use apply to it.
Appendix A — Details of Processing
| Subject matter | Provision of the Jolly order-management platform for coordinating notarial signing appointments. |
| Duration | For the term of Customer's account, plus the deletion periods in Section 10. |
| Nature and purpose | Placing and tracking signing orders; locating, offering, and assigning notaries; exchanging documents and messages; confirming appointments; recording completion; invoicing and billing; notification by email and text message. |
| Categories of individuals | Customer's staff and client users; notaries engaged through the platform; signers named on an order (typically borrowers and sellers in a real estate or loan transaction); Customer's own clients' contacts. |
| Categories of Personal Information | Names; business and home addresses; email addresses; telephone and mobile numbers; signing appointment times and locations; loan or file identifiers; notary commission, bond, insurance, and background-check details; fee and payment records; and the contents of documents uploaded for a signing, which may include Social Security numbers, account numbers, income, and property information belonging to signers. |
| Sensitive information | Documents uploaded for a signing may contain nonpublic personal information under the GLBA and information classified as sensitive personal information under the CCPA, including Social Security numbers and financial account numbers. This information is Processed solely to make the document available to the assigned notary for the signing, and is deleted automatically after Customer's retention window. |
| Frequency | Continuous, for the duration of the account. |
Appendix B — Security measures
The measures described in the Jolly Security Overview, as updated from time to time, including: encryption in transit (TLS) and at rest; company-level and role-level access separation enforced server-side; authenticated, order-scoped document access with no publicly reachable file paths; bcrypt password hashing; expiring sessions; rate-limited authentication; email verification; single-use, time-limited, hashed activation and reset links; out-of-band confirmation of notary payment detail changes; automatic deletion of signing documents after the configured retention window; exclusion of full Social Security and EIN numbers, government identification, and payment card data from storage; security response headers; secrets held in environment configuration outside source control; per-order activity logging; and restriction of production access to personnel who require it.
Appendix C — Subprocessors
The current list is maintained at jollyorders.com/security and, as of the version date of this DPA, consists of: Render (hosting and file storage); Cloudflare R2 (object storage for the Send Documents tool); MongoDB Atlas (database); Stripe (payment processing); Resend (transactional email); Twilio (text message delivery); Google (address autocomplete); and Stadia Maps (map tiles).
Contact
Questions about this DPA, vendor review, or security: security@signwithjolly.com.
Sign With Jolly, LLC · PO Box 4450, Carmel, IN 46082 · app.jollyorders.com
See also our Terms of Use, Privacy Policy, Security Overview, and text-message program details.