Privacy Policy
JetApps/JetBackup
Originally effective: January 2, 2021
Current version effective: September 9, 2026
1. Scope
This Privacy Policy explains how JetApps, Inc. and JetApps, LLC (collectively, “JetApps,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information in connection with JetBackup.com, JetApps.com, our billing and support portals, JetBackup products and services, product licensing and telemetry, marketing, recruiting, and other services that link to this Policy (collectively, the “Services”).
This Policy applies when JetApps determines the purposes and means of processing personal information and therefore acts as a controller or business. It does not govern personal information that our customers process using JetBackup products where JetApps acts solely as a processor or service provider on their behalf. In those circumstances, the customer’s privacy notice and our agreement with that customer govern the processing.
This Policy does not apply to third-party websites, products, or services that have their own privacy notices.
2. Who Is Responsible for Your Information
The entities responsible for personal information covered by this Policy are:
- JetApps, Inc.
- JetApps, LLC
- 940 Calle Negocio, Suite 150
- San Clemente, California 92673, United States
- Privacy email: [email protected]
- Telephone: (877) 568-1698
Data Protection Officer: Lance Larson
Contact: [email protected]
JetApps, Inc. and JetApps, LLC act as joint controllers for the processing described in this Policy. JetApps, Inc. is a legacy business entity; JetApps, LLC is responsible for billing, support, licensing, telemetry and marketing. Whatever the allocation between them, you may exercise your rights against either entity and either entity will respond. The essence of our joint-controller arrangement is available on request at [email protected].
3. Personal Information We Collect
The information we collect depends on how you interact with the Services. “Personal information” includes information that identifies, relates to, describes, is reasonably capable of being associated with, or can reasonably be linked to an individual or household, subject to applicable law.
| Category | Examples |
|---|---|
| Identifiers and contact information | Name, email address, telephone number, postal and billing address, account username, company, job title, customer or account identifier, IP address, domain, and hostname. |
| Account and commercial information | Products, licenses, subscriptions, transaction history, invoices, renewal status, account preferences, and customer-service history. |
| Payment information | Payment method, billing details, transaction identifiers, card brand, and last four digits. Full payment-card data is processed by our payment provider and is not stored by JetApps except where we expressly state otherwise at the point of collection. |
| Product, device, and telemetry information | Customer name, IP address, hostname, product version and tier, operating system, kernel release and version, control-panel version, license status, device/browser details, log data, dates and times of use, and feature interactions. |
| Support and diagnostic information | Support communications, ticket contents, server and configuration information, logs, diagnostic files, screenshots, and information you choose to provide. At your direction, this may include credentials or information contained in affected accounts. |
| Website and marketing information | Cookie identifiers, IP address, browser and device information, referring pages, pages viewed, interactions, approximate location, email opens and link clicks, marketing preferences, and campaign information. |
| Communications and content | Messages, survey responses, comments, reviews, forum submissions, contest or promotion entries, and other content submitted to us. |
| Applicant information | Résumé, employment and education history, qualifications, references, interview notes, work authorization, and voluntarily provided demographic information where lawful. |
| Privacy-request and compliance records | Identity-verification information, request correspondence, consent records, opt-out preferences, complaints, and records needed to demonstrate compliance. |
| Sensitive personal information | Account credentials, access tokens, and similar access information you provide to us for support purposes; government identifiers where required for tax or employment purposes; and racial, ethnic, or other demographic information voluntarily provided by job applicants. We collect sensitive personal information only where it is necessary for the purpose for which you provided it, and we do not use or disclose it for purposes other than those permitted under applicable law. |
4. Sources of Personal Information
We collect personal information:
- directly from you, including when you create an account, purchase or activate a product, request support, subscribe to communications, apply for a job, or contact us;
- automatically from browsers, devices, servers, installed products, cookies, SDKs, logs, and similar technologies;
- from your employer, organization, reseller, hosting provider, account administrator, or other person who purchases or manages the Services for you;
- from service providers and business partners, including payment processors, fraud-prevention providers, analytics providers, marketing platforms, and resellers; and
- from publicly available sources and professional networks, where permitted by law.
If we obtain your personal information from a source other than you and applicable law requires additional notice, we will provide that notice within the required time.
5. How We Use Personal Information and Our Legal Bases
| Purpose | GDPR/UK GDPR legal basis |
|---|---|
| Provide accounts, products, licenses, billing, renewals, and requested support | Performance of a contract; steps requested before entering a contract. |
| Authenticate users, validate licenses, prevent fraud, secure the Services, and investigate abuse | Legitimate interests in security, fraud prevention, and protecting our Services and users; legal obligation where applicable. |
| Operate, troubleshoot, maintain, and improve the Services | Contract and legitimate interests in reliable operation and product improvement; consent where required for optional analytics or use of identifiable support data beyond resolving the request. |
| Communicate about accounts, transactions, service changes, security, and support | Contract, legal obligation, and legitimate interests in customer administration. |
| Send product news, offers, and marketing and measure campaign performance | Consent where required; otherwise legitimate interests or applicable existing-customer rules, subject to the right to object or opt out. |
| Comply with law, respond to lawful requests, establish or defend legal claims, and enforce agreements | Legal obligation and legitimate interests in compliance and protection of legal rights. |
| Evaluate job applicants and administer recruiting | Steps before entering an employment contract, legitimate interests in recruitment, and legal obligation. |
| Administer surveys, events, contests, and promotions | Contract, consent, and legitimate interests, depending on the activity and applicable rules. |
Where we rely on legitimate interests, we consider the interests pursued, the necessity of the processing, and the impact on individuals. You may request additional information about this assessment. Where we rely on consent, you may withdraw it at any time without affecting processing that occurred before withdrawal.
We will not use personal information for a materially different purpose without first providing additional notice and obtaining any consent required by law.
6. Product Telemetry and License Validation
JetBackup products may transmit limited technical and licensing information to JetApps, including the customer name, IP address, hostname, product version and tier, operating system, kernel release and version, control-panel version, license identifier and status, and related timestamps. We use this information to authenticate and validate licenses, deliver and secure the product, diagnose reliability issues, communicate relevant service or security information, prevent fraud, and improve the product.
7. Customer Data and Technical Support
Customers control the data they back up or otherwise process using JetBackup. Unless JetApps separately determines why and how such data is used, JetApps processes that information only on the customer’s documented instructions and under the applicable Data Processing Addendum (“DPA”). Individuals seeking rights concerning customer-controlled data should contact the relevant customer. If we receive such a request, we may refer it to that customer.
JetApps does not receive, host, or have routine access to backup contents created through customers’ self-hosted JetBackup deployments. JetApps may receive limited customer-controlled information only when a customer voluntarily submits it for technical support.
Customers may request our Data Processing Addendum by contacting [email protected].
When you request technical support, do not provide passwords, private keys, backup contents, or personal information that is not necessary to resolve the issue. Where sensitive access is necessary, use the secure method we identify. We limit access to authorized personnel and service providers who need it to perform support. We will notify you when a support engagement involving temporary credentials is closed so that you can revoke or rotate them, and we delete credentials you provided in accordance with Section 13.
Support information may include credentials or other sensitive personal information when voluntarily provided and necessary to resolve a request. We use that information only to provide requested support, secure the Services, prevent fraud, and comply with law. We do not use sensitive personal information to infer characteristics about individuals.
JetApps does not use identifiable customer backup content or support data to train generalized artificial-intelligence models for unrelated purposes, and does not authorize its Service Providers to use such information to train generalized models for their own purposes.
JetApps may use artificial-intelligence-assisted tools in connection with support, security, diagnostics, administration, or operation of the Services where such use is consistent with the customer’s instructions, this Policy, the applicable DPA, and appropriate contractual and data-protection safeguards.
JetApps will not use identifiable customer-controlled content for materially different artificial-intelligence or product-development purposes without providing any notice and obtaining any consent required by applicable law.
8. Cookies and Similar Technologies
We and our providers use cookies and similar technologies to operate the website, remember preferences, understand use, measure communications, prevent fraud, and measure the performance of our own communications. Strictly necessary technologies operate because they are required to provide requested functionality or protect the Services. Where required, we obtain consent before using analytics, advertising, or other nonessential technologies.
Our cookie settings tool explains the technology, provider, purpose, category, and duration and allows you to accept, reject, or later change nonessential choices. Browser controls may also block cookies, but parts of the Services may not function correctly. Where legally required, we recognize browser-based opt-out preference signals, including Global Privacy Control, as a request to opt out of sale or sharing for the browser or device from which the signal is sent.
Do Not Track. Some browsers can transmit a “Do Not Track” signal. There is no common industry standard for interpreting these signals, and JetApps does not currently respond to them. We do honor Global Privacy Control signals as described above.
9. Marketing Communications
You may unsubscribe from marketing emails using the link in each message or by contacting us. We may retain a suppression record so that we can honor your preference. Opting out of marketing does not stop transactional, security, support, or other non-promotional communications relating to an existing relationship. You may object at any time to our use of personal information for direct marketing, including related profiling.
10. How We Disclose Personal Information
We may disclose personal information to:
- service providers and contractors that provide hosting, cloud infrastructure, communications, customer support, payment processing, accounting, analytics, security, fraud prevention, marketing, recruiting, and professional services;
- resellers, distributors, integration partners, and account administrators when necessary to provide or manage the Services;
- professional advisers, auditors, insurers, and financing sources subject to appropriate duties of confidentiality;
- law-enforcement agencies, regulators, courts, and other parties when disclosure is required by law or reasonably necessary to protect rights, safety, and security; and
- parties to an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate safeguards.
We require processors and service providers to protect personal information and process it only for authorized purposes. A current list of relevant subprocessors is available at https://www.jetbackup.com/legal/subprocessors/. We will provide advance notice of material subprocessor changes where our contracts require it.
JetApps does not sell personal information or share personal information for cross-context behavioral advertising, as those terms are defined under California law. JetApps also does not process personal information for targeted advertising as defined under applicable U.S. state privacy laws.
11. International Transfers
JetApps is located in the United States, and we and our providers may process personal information in the United States and other countries whose privacy laws may differ from those where you live.
For transfers from the European Economic Area, United Kingdom, or Switzerland, we rely as applicable on adequacy decisions, the EU-U.S. Data Privacy Framework and its UK Extension, the Swiss-U.S. Data Privacy Framework, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, or another lawful transfer mechanism. We use supplementary measures where appropriate. You may contact us to request information about the applicable safeguard and how to obtain a copy, subject to necessary redactions.
12. Data Privacy Framework
JetApps, LLC complies with the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (“Swiss-U.S. DPF”) as set forth by the U.S. Department of Commerce. JetApps, LLC has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with respect to personal information received from the European Economic Area, the UK Extension to the EU-U.S. DPF with respect to personal information received from the United Kingdom and Gibraltar, and the Swiss-U.S. DPF Principles with respect to personal information received from Switzerland. JetApps, Inc. is included in the certification as a covered entity. For purposes of this Section, references to “JetApps” include JetApps, Inc. and JetApps, LLC to the extent covered by the certification. If this Policy conflicts with the applicable DPF Principles, the Principles govern. To view our certification, visit https://www.dataprivacyframework.gov/list and search for “JetApps, LLC”
JetApps’ DPF certification applies to non-HR personal information. It does not cover personal information transferred from the European Economic Area, United Kingdom, or Switzerland in the context of an employment relationship. Where employment-related personal information is transferred internationally, JetApps relies on another lawful transfer mechanism permitted by applicable law, such as the applicable Standard Contractual Clauses.
JetApps verifies its compliance with the DPF Principles through self-assessment.
Where required by the applicable DPF Principles, JetApps provides individuals with an opportunity to opt out before personal information covered by the DPF is disclosed to a non-agent third party or used for a purpose materially different from the purpose for which it was originally collected or subsequently authorized. JetApps obtains affirmative express consent before disclosing sensitive personal information to a non-agent third party or using sensitive personal information for a materially different purpose, except where an exception under the applicable DPF Principles applies. Individuals may exercise these choices by contacting [email protected].
If JetApps withdraws from the DPF Program or its certification otherwise lapses, JetApps will continue to apply the applicable DPF Principles to personal information received in reliance on the DPF for as long as JetApps retains that information, unless JetApps provides adequate protection for the information through another authorized means.
JetApps is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission. We may be required to disclose personal information in response to lawful public-authority requests, including national-security or law-enforcement requirements. In connection with onward transfers to third parties, JetApps remains responsible under the EU-U.S. DPF Principles, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF Principles if a third party that receives personal information processes it in a manner inconsistent with the applicable Principles, unless JetApps proves that it is not responsible for the event giving rise to the damage.
If you have a question or complaint concerning personal information handled in reliance on the EU-U.S. DPF, UK Extension to the EU-U.S. DPF, or Swiss-U.S. DPF, please first contact JetApps at [email protected] or use the other contact information in Section 18. JetApps will respond to a DPF-related complaint within 45 days after receiving it.
If your complaint remains unresolved, you may submit it, at no cost, to the applicable independent recourse authority:
- For individuals in the European Economic Area: the applicable EU Data Protection Authority.
- For individuals in the United Kingdom: the UK Information Commissioner’s Office DPF complaints tool.
- For individuals in Switzerland: the Swiss Federal Data Protection and Information Commissioner.
Under certain conditions described in Annex I of the DPF Principles, an individual may invoke binding arbitration after exhausting other available recourse mechanisms.
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, JetApps commits to cooperate and comply with the advice of the panel established by the EU data protection authorities, the UK Information Commissioner’s Office, and the Swiss Federal Data Protection and Information Commissioner with regard to unresolved complaints concerning our handling of personal information received in reliance on those frameworks.
13. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security, complying with tax and accounting obligations, resolving disputes, enforcing agreements, and demonstrating compliance. We consider the amount, nature, sensitivity, purpose, risk, and applicable legal requirements when determining retention.
| Record category | Retention period |
|---|---|
| Account and subscription records | Contract, billing, and tax records: 10 years after the end of the account term. Other account data, including profile, preferences, configuration, and activity records: 24 months after the end of the account term. |
| Invoices, payments, and tax records | 10 years, as required by tax and accounting law in the jurisdictions where we operate, including Germany (HGB § 257; AO § 147) and France. |
| Support tickets and communications | 1 year after ticket closure. |
| Uploaded diagnostics and temporary support data | Deleted within 30 days of ticket closure, and typically sooner, unless needed for an active investigation or legal claim. |
| Product telemetry and license logs | Identifiable telemetry: 24 months, after which it is anonymized. License-validation logs: the license term plus 24 months. |
| Website security logs | 1 year. |
| Analytics data | 1 year. |
| Marketing contacts | Until opt-out or 3 years of inactivity; suppression records retained as needed to honor opt-outs. |
| Applicant records | United States: 4 years after the hiring decision. European Economic Area and United Kingdom: 6 months after the hiring decision, unless the applicant consents to longer retention in our talent pool. |
| Privacy requests and consent records | 3 years after completion or withdrawal. |
When retention expires, we delete, de-identify, or securely isolate the information unless continued retention is required or permitted by law. De-identified information will be maintained and used in de-identified form, and we will not attempt to reidentify it except as permitted by law.
Backups. Copies of personal information may persist in backup media after deletion from active systems until routine backup rotation overwrites them. During that period the information remains isolated, is not used for any other purpose, and remains subject to the security controls described in Section 14.
The periods above are maximums. They do not override a valid request to delete or erase personal information, which we will honor unless a specific exemption under applicable law permits or requires us to retain the information.
14. Security and Personal-Data Incidents
We use administrative, technical, and physical safeguards designed to protect personal information, including access controls, encryption in transit, monitoring, personnel confidentiality requirements, vendor oversight, vulnerability management, and incident-response procedures. No security measure is perfect, and we cannot guarantee absolute security.
If a personal-data breach occurs, we will investigate, mitigate, document, and notify regulators, customers, and affected individuals when and within the time required by applicable law. Under the GDPR and UK GDPR, this can include notifying the competent supervisory authority within 72 hours after becoming aware of a reportable breach and notifying affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms.
15. Your Privacy Rights
European Economic Area, United Kingdom, and Switzerland
Subject to applicable conditions and exceptions, you may have the right to:
- access your personal information and receive a copy;
- correct inaccurate or incomplete information;
- request deletion;
- restrict processing;
- object to processing based on legitimate interests and object at any time to direct marketing;
- receive certain information in a structured, commonly used, machine-readable format and transmit it to another controller;
- withdraw consent at any time; and
- lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner’s Office.
JetApps uses automated processes to validate licenses and to detect fraud and abuse. Where such a process would produce a legal or similarly significant effect on you, a person reviews the outcome before it becomes final. You may contact us to obtain human review of, express your point of view on, or contest such a decision, and to request information about the logic involved, its significance, and its expected consequences.
United States
Depending on where you live and subject to legal exceptions, you may have rights to confirm processing; access, correct, or delete personal information; obtain a portable copy; opt out of sale, targeted advertising, sharing, or certain profiling; limit certain uses of sensitive personal information; withdraw consent; and appeal a denied request. We will not discriminate against you for exercising a privacy right.
To exercise a right, email [email protected] or call (877) 568-1698 where a telephone method is required. JetApps does not currently sell personal information, share it for cross-context behavioral advertising, or process it for targeted advertising. If our practices change, we will update this Policy and provide any legally required opt-out mechanism before beginning that processing. To appeal a denied request, email [email protected] with “Privacy Appeal” in the subject line.
We will verify requests using information reasonably related to the request and will request only what is necessary. An authorized agent may submit a request where permitted by law; we may require proof of authorization and direct verification with the individual. If we cannot fulfill a request, we will explain why and describe available appeal or complaint options.
California “Shine the Light.” California residents may request information about personal information we disclosed to third parties for those parties’ own direct marketing purposes during the preceding calendar year. JetApps does not disclose personal information to third parties for their own direct marketing purposes. Requests may be sent to [email protected].
Nevada. Nevada residents may submit a verified request directing us not to sell certain covered information. JetApps does not sell covered information as defined under Nevada law. Requests may be sent to [email protected].
Accessibility. If you need this Policy in an alternative accessible format, contact [email protected] and we will provide one.
16. Information Required to Provide the Services
We identify mandatory fields when information is collected. Account, contact, licensing, and payment information may be contractually required to open an account, purchase, activate, secure, or support a product. If you do not provide required information, we may be unable to create the account, complete the transaction, validate the license, provide support, or deliver the requested Service. Other information, including optional marketing preferences or survey responses, is voluntary.
17. Children’s Privacy
The Services are intended for businesses and professionals and are not directed to children under 16. We do not knowingly collect personal information from children under 16 through the Services, and we do not knowingly collect personal information from children under 13 in any circumstance. If you believe a child has provided personal information to us contrary to this Policy, contact us so we can investigate and take appropriate action. Customer-controlled data processed through JetBackup may contain information about children; the relevant customer is responsible for the legal basis and notices for that processing.
18. Contact Us and Complaints
For questions, complaints, or requests concerning this Policy or our privacy practices, contact:
- JetApps, Inc. and JetApps, LLC — Privacy Team
- 940 Calle Negocio, Suite 150, San Clemente, California 92673, United States
- Email: [email protected]
- Telephone: (877) 568-1698
We will acknowledge and respond within the period required by applicable law. You may also complain to the data-protection or privacy regulator where you live or work or where you believe a violation occurred.
19. Changes to This Policy
We may update this Policy to reflect changes in the Services, our practices, or legal requirements. We will post the revised Policy with a new “Current version effective” date. If a change materially affects how we use previously collected personal information or materially reduces your rights, we will provide additional notice and obtain consent where required by law.
