Privacy Policy
We are committed to protecting your personal information and being transparent about the data we hold about you (“personal data“). This privacy policy applies to visitors and users of our website including https://www.jrni.com (“sites”) and related services as well as to any personal data you provide by phone, SMS, email, in letters, other correspondence and in person.
Please read this privacy policy carefully to learn how we collect, use, share and otherwise process your personal data and to learn about your rights and choices in relation to it.
A reference to ‘JRNI’, ‘we’ or ‘us’ is a reference to JRNI Limited or the relevant JRNI group company involved in the processing activity. Details of our group companies can be found here.
1. WHO IS RESPONSIBLE FOR YOUR INFORMATION?
1.1 JRNI is the controller of your personal data for the activities described in this privacy policy. This policy covers our marketing website, direct sales and support interactions, business relationships, and office administration
1.2 Please be aware that this privacy policy does not apply to the extent that we process personal data in the role of a processor on behalf of our customers who use the JRNI platform. This includes where we offer our booking platform and related services to our customers through which they can interact with their own customers, staff, users and other individuals including by (i) enabling them to schedule and manage appointments, events or bookings (ii) sending them electronic communications (iii) selling or offering their own products and services or (iv) otherwise collecting, using sharing or processing personal data via JRNI’s products and services. We are not responsible for the privacy or data security practices of our customers. Where our customer is controller as described above, please contact the customer directly for information about how they use and process your personal data. Processing within customer deployments of the JRNI platform is governed by the relevant customer’s own privacy notice and our data processing agreement with that customer.
2. WHAT INFORMATION DO WE COLLECT AND HOW?
2.1 We may collect, store and use the following kinds of personal data in connection with our controller activities as described in Section 1.1:
Identity Data: name, job title, company name, and other identifiers;
Contact Data: email address, telephone number, and other contact details;
Technical Data: internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the sites;
Profile Data: your interests, preferences, feedback and survey responses;
Usage Data: information about how you use our sites or services;
Marketing and Communications Data: your preferences in receiving marketing from us and our third parties and your communication preferences;
AI-Derived Data: information generated, inferred or derived through the use of artificial intelligence, machine learning or similar automated technologies applied to data collected under this policy, such as content recommendations or interest profiling to improve our sites and marketing; and
Other: any other information you choose to send or otherwise make available to us.
2.2 We use different methods to collect personal data from and about you as follows:
Direct Interactions: We may collect your personal data directly from you when you:
interact with the sites or emails including when you use our “speak to an expert”, website chat or similar contact function on our sites;
request a demo or additional information about our services;
access and download certain content from our sites (e.g. blogs);
subscribe to our newsletter and other marketing communications;
sign up for / attend an event or webinar.
enter a competition or promotion or fill out a survey;
visit our offices and register as a visitor; or
give us feedback, report a problem with our sites or services or otherwise contact us by email, phone, in person or by any other means.
Automated Technologies or interactions: As you interact with our sites and services, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this data by using cookies and other similar technologies. We categorize cookies as: (a) strictly necessary cookies, which are required for our sites to function and are set without requiring consent; (b) analytics and performance cookies, which help us understand how visitors use our sites; and (c) marketing and targeting cookies, which are used to deliver relevant advertising and track campaign effectiveness. Non-essential cookies (categories (b) and (c)) are not set until you have provided your consent through our cookie management tool. We may also receive Technical Data about you if you visit other websites employing our cookies.
Third parties or publicly available sources: We may receive personal data about you from various third parties for example: Technical Data from search information providers, advertising networks and analytics providers.
2.3 We do not intentionally collect any special categories of personal data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Nor do we collect any information about criminal convictions and offenses. If you voluntarily provide any such data to us, we will handle it in accordance with applicable law
3. HOW DO WE USE YOUR PERSONAL DATA?
3.1 We may collect and use your personal data for the purposes identified below, together with the lawful basis we rely on for each purpose:
to operate and administer our sites and to provide you with the content you access and request (e.g. to download content from the sites) [legitimate interests];
to provide you with services you may have requested from us and/or to enter into or perform a contract with you or your business [contract, legitimate interests];
to deal with your enquiries and provide you with information about us and to demonstrate our services [contract; legitimate interests];
to promote the security of our sites and services by tracking use of our sites and services, creating aggregated, non-personal data, investigating suspicious activity and enforcing our terms of use and policies [legitimate interests];
to develop and improve our sites and services [legitimate interests; consent where legally required];
to personalize our sites and services using artificial intelligence, machine learning and similar automated technologies, including to analyse browsing patterns and optimise content recommendations [legitimate interests; consent where legally required];
to ask you to leave a review, carry out a survey and for us to conduct market research and advertise our sites and services [legitimate interests; consent where legally required];
to assess new potential customer opportunities [legitimate interests];
to register office visitors and manage non-disclosure agreements that visitors may be required to sign [legitimate interests];
to send you marketing communications about our products, services and events (see Section 4 below) [legitimate interests; consent where legally required];
to send you email notifications you have specifically requested [consent, legitimate interests];
to monitor or record your communications with us (including emails, telephone calls, online live chat) to assist us with the development of our sites and services; to train our staff; and if requested, by order of a court, regulatory body or law enforcement organization [legitimate interests; legal obligation];
to deal with any complaints lodged by you [legitimate interests; legal obligation];
to notify you about changes to our privacy policy [legitimate interests; legal obligation];
to comply with our legal obligations, for example when we are required to cooperate with public and government authorities, courts or regulators under applicable law [legal obligation]; and
to protect our rights and those of third parties [legitimate interests].
4. MARKETING
4.1 We may use your personal data to form a view on what products, services and offers may be of interest to you (“marketing“).
4.2 You will receive marketing communications from us if you have requested information from us or purchased services from us and you have not opted out of receiving that marketing. We may also contact prospective customers who have expressed an interest in our products or services. Where required by applicable laws in the relevant jurisdiction, we will obtain your consent before sending you electronic marketing communications.
4.3 We will always obtain your express opt-in consent before we share your personal data with any third party for their own marketing purposes.
4.4 You can ask us or, if applicable, our third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you.
4.5 Where we send you marketing or transactional communications by SMS, additional terms apply, including information about message frequency, opt-out mechanisms, and applicable charges. Please see our SMS Terms and Conditions for further details.
5. LAWFUL BASIS FOR USING YOUR PERSONAL DATA
5.1 We process your personal data based on the lawful bases set out below or as more specifically outlined at section 3 above. We may process information you provide based on more than one lawful basis depending on the specific purpose for which we are using it.
Contract: To enter into a contract with you and fulfil our contractual obligations to you (e.g. to provide you with services which you have subscribed for)
Consent: Where you have consented to our use of your personal data, for example where you opt-in to receive relevant marketing communications from us or where consent is required for the use of certain cookies. You may withdraw consent at any time by contacting us or using the unsubscribe or cookie preference mechanism provided.
Legal Obligation: Where processing is necessary to comply with legal or statutory requirements on us. This may include cooperating with law enforcement in relation to their investigations.
Legitimate interest: Where processing is necessary for our legitimate interests (or those of a third party) provided that these do not override your interests or fundamental rights.
6. WHO DO WE SHARE YOUR PERSONAL DATA WITH?
6.1 JRNI does not sell your personal data to third parties and will only share your personal data with a third-party as set out in this privacy policy.
6.2 We may share your personal data as follows:
with any of our Group Companies from time to time for the purposes and pursuant to the lawful bases described above.
with our contracted third-party service providers for services such as IT, systems administration and hosting, research and analytics, CRM, marketing and customer support for the purposes and pursuant to the legal bases described above;
with artificial intelligence and machine learning service providers who process data on our behalf in connection with our internal operations, subject to appropriate data processing agreements and contractual restrictions on the use of data for model training;
with our professional advisors such as our lawyers, bankers, auditors, insurers based in the countries in which we operate;
to the extent that we are required to do so by law, or in connection with any legal or criminal or law enforcement proceedings;
to establish, exercise or defend our legal rights (including providing information to others for the purpose of fraud prevention and reducing credit risk); and
in the event that we sell or buy any business or assets, or in the event of a merger, restructuring or financing transaction, to the prospective buyer or seller or relevant party of such business and assets and their advisers.
6.3 We may also share anonymous usage data with our service providers for the purpose of analysis and improvements to our sites, services and marketing, however, this will not identify you personally. We may also share such anonymous usage data on an aggregate basis in the normal course of operating our business. A current list of our sub-processors is available at ____ or upon request by emailing infosec@jrni.com.
6.4 Our sites may use automated technologies to assist in functions such as content personalization and analytics. Where such technologies are used, they are designed to support human decision-making rather than replace it. We do not use automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of applicable data protection law. If you have concerns about any automated processing, please contact us using the details in section 14. Where our customers use AI-powered or automated features within the JRNI booking platform, they act as controller for that processing. Please contact that customer directly with any questions about automated processing carried out through their use of our platform.
7. STORING AND TRANSFERRING YOUR DATA
7.1 Your personal data may be collected by our Group Companies (as disclosed in section 6) in the United Kingdom, Australia, Switzerland or in the United States and may be transferred to and stored by another Group Company as well as the third parties disclosed in section 6 in locations which may be outside of your jurisdiction, for the purposes and pursuant to the lawful bases set out in this policy.
7.2 Your personal data may therefore be processed outside of your jurisdiction and in countries that are not subject to an adequacy decision by the relevant supervisory authority and that may not provide the same level of data protection as your jurisdiction. As such, we put in place adequate measures to ensure that any transfer of personal data outside of your jurisdiction is protected according to the applicable data protection laws, including to ensure that a similar degree of protection is afforded to the transferred data by the recipient. Such safeguarding measures may include standard contractual clauses as approved by the European Commission (Art 46 GDPR), the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses, the EU-U.S. Data Privacy Framework and its UK and Swiss extensions, or such other transfer mechanisms as may be adopted from time to time under applicable data protection law.
7.3 Please contact us as set out in section 14 below if you would like further information on the specific mechanisms used by us when transferring your personal data outside of your jurisdiction.
8. SECURITY OF YOUR PERSONAL DATA
8.1 Data transmission over the Internet is inherently insecure and we cannot guarantee the security of data sent over the Internet.
8.2 We have put in place appropriate security measures to prevent your personal data from being accidentally lost, interfered with, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instruction and they are subject to a duty of confidentiality. Details of our security certifications and practices are available on our _____ page.
8.3 We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
8.4 You are responsible for keeping your password and user details confidential. We will not ask you for your password.
9. RETENTION PERIOD
9.1 We will process personal data for as long as necessary to fulfil the purpose we collected it for, including legal, accounting and reporting requirements, and for as long as necessary for the prevention and detection of criminal activity. Specific retention periods vary depending on the nature of the data and the purpose for which it was collected. The period for which we process and store the personal data varies depending on the use you make of the sites and services we offer. Where you or your business subscribes for a service we will retain your personal data for as long as necessary to continue to provide you with the service and for a further period thereafter to enable us to satisfy our legal, accounting and reporting requirements.
9.2 In some circumstances you can ask us to delete your data: see the Right to be forgotten Section below for further information.
9.3 In some circumstances we may anonymize your personal data (so that it can no longer identify or be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice.
10. YOUR RIGHTS
10.1 Depending on your jurisdiction and the circumstances, you may have some or all of the following rights in relation to your personal data:
Right of access – you have the right to request a copy of the information that we hold about you. We will respond within any applicable statutory timeframe;
Right of rectification – you have a right to correct data that we hold about you that is inaccurate or incomplete;
Right to be forgotten – in certain circumstances you can ask for the data we hold about you to be erased from our records;
Right to restriction of processing – in certain circumstances you have a right to restrict the processing;
Right of portability – in certain circumstances you have the right to have the data we hold about you transferred to another organization;
Right to object – you have the right to object to certain types of processing such as direct marketing, or processing based on legitimate interests or profiling; and
Right to complain to the supervisory authority – you have the right to complain as outlined in section 14 below.
10.2 You can exercise your rights above by emailing infosec@jrni.com or as set out at section 14 below. Note that some rights are subject to conditions and exceptions under applicable law. All requests will be forwarded on should there be a third party involved in the processing of your personal data as specified in section 6. We may not discriminate against you for exercising any of your rights listed above.
10.3A Australia. For individuals located in Australia, personal data is collected, used and disclosed in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). We collect only such personal data as is reasonably necessary for our functions and activities as described in this policy. You have the right to access and seek correction of your personal data by contacting us using the details in section 14. You may also lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au/privacy/privacy-complaints if you believe we have not complied with the APPs.
10.3B United States — California and Other State Privacy Rights. If you are a resident of California or another US state with an applicable state privacy law, you may have additional rights in relation to your personal data, including:
the right to know what personal data we collect, use, disclose and sell;
the right to request deletion of your personal data, subject to certain exceptions;
the right to correct inaccurate personal data we hold about you;
the right to opt out of the sale or sharing of your personal data (note: JRNI does not sell personal data as described in section 6.1);
the right to limit the use of sensitive personal information where applicable; and
the right not to be discriminated against for exercising any of these rights.
To exercise any of these rights, please contact us at infosec@jrni.com or using the details in section 14. We will respond within the timeframe required by applicable law (45 days for most US state privacy laws, with a possible 45-day extension where reasonably necessary). We may need to verify your identity before processing your request. 36
10.3C Switzerland. For individuals located in Switzerland, personal data is processed in accordance with the Swiss Federal Act on Data Protection (nFADP). Where JRNI transfers personal data from Switzerland to the United States, it does so in reliance on the Swiss-U.S. Data Privacy Framework as described in the DPF Notice below. You may contact the Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch/en if you have concerns about how we process your personal data. 37
10.3D Higher Education — FERPA. Where our platform is used by customers that are educational institutions subject to the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g, JRNI acknowledges that it may receive access to Education Records (as defined under FERPA) in the course of providing its services. In such circumstances:
JRNI acts as a “school official” within the meaning of FERPA (34 C.F.R. § 99.31(a)(1)) and accesses Education Records only to the extent necessary to fulfil its obligations under the applicable customer agreement;
JRNI does not use Education Records for any purpose other than providing the contracted services to the relevant educational institution;
JRNI does not disclose Education Records to any third party except as permitted under FERPA and the applicable customer agreement; and
individuals with questions about how their Education Records are used should contact the relevant educational institution directly, as the institution acts as the data controller for FERPA purposes.
JRNI’s obligations with respect to Education Records are further governed by the data processing terms in its agreements with educational institution customers. For further information please contact infosec@jrni.com. 41
10.3E Other jurisdictions. If you are located in a jurisdiction not specifically addressed above and have questions about how applicable local privacy laws apply to our processing of your personal data, please contact us at infosec@jrni.com.
10.4 Our sites are not directed at children under the age of 16, or such other age as may apply under applicable law in the relevant jurisdiction, and we do not knowingly collect personal data from such individuals. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete that information. If you believe we may have collected personal data from or about a child, please contact us using the details in section 14.
11. UPDATING INFORMATION
11.1 Please let us know if the personal data that we hold about you needs to be corrected or updated by contacting us using the contact details at section 14 below.
12. POLICY AMENDMENTS
12.1 We may update this privacy policy from time to time by posting a new version on our sites. Material changes will be indicated by an updated “Last updated” date. Continued use of our sites following any update constitutes acceptance of the revised policy.
12.2 We may also notify you of changes to our privacy policy by email.
13. THIRD PARTY WEBSITES
13.1 The sites may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.
14. CONTACT AND COMPLAINTS
14.1 If you wish to lodge a complaint or raise an issue about this privacy policy or how your personal data is being processed by JRNI, in the first instance, please contact us at:
Email: infosec@jrni.com
Phone: if you are based in UK, Australia or anywhere outside of the United States: 020 7101 9303.
Phone: if you are based in the United States: 857.305.6509.
14.2 We are committed to working with you to resolve any issue or complaint you may have. However, if you believe that we have not been able to assist you, you have the right to complain to your local supervisory body or regulator:
If you are located in the EEA, you can find further information about lodging a complaint with your local supervisory authority here: https://edps.europa.eu/node/75…; and
If you are located in the United Kingdom, you can contact the Information Commissioner’s Office (ICO): https://ico.org.uk/make-a-complaint/; 33
If you are located in Switzerland, you can contact the Federal Data Protection and Information Commissioner (FDPIC): https://www.edoeb.admin.ch/en;
If you are located in Australia, you can visit the ‘Complaints’ section of the Information Commissioner’s website at http://www.oaic.gov.au/privacy/privacy-complaints.
EU-U.S. Data Privacy Framework (EU-U.S. DPF), UK Extension, and Swiss-U.S. DPF Notice
JRNI complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. JRNI has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with regard to the processing of personal data transferred from the European Union and the United Kingdom (including Gibraltar) to the United States in reliance on the EU-U.S. DPF and its UK Extension. JRNI has also certified that it adheres to the Swiss-U.S. DPF Principles with regard to personal data transferred from Switzerland to the United States in reliance on the Swiss-U.S. DPF. If there is any conflict between this notice and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the DPF Principles shall govern. To learn more about the DPF program and to view the Data Privacy Framework List, please visit dataprivacyframework.gov and the Data Privacy Framework List.
Scope
This notice applies to personal data transferred to JRNI in the United States from the European Union, the United Kingdom (including Gibraltar), and Switzerland in reliance on the DPF. For most customer data JRNI acts as a processor/service provider and processes personal data only on documented instructions from the customer (the controller/business).
Your Choices and Access
Individuals have the right to access, correct, or delete personal data processed under the DPF, and to limit its use and disclosure. Where JRNI processes personal data on behalf of a customer, individuals should direct requests to that customer (the controller). JRNI will support its customers in responding to such requests consistent with the DPF Principles.
Accountability for Onward Transfers
JRNI discloses personal data received under the DPF to third parties only pursuant to written contracts requiring the recipient to provide at least the same level of protection as required by the DPF Principles. JRNI remains responsible and liable under the DPF Principles if a third party processes personal data in a manner inconsistent with the DPF Principles, unless JRNI proves it is not responsible for the event giving rise to the damage.
Types of third parties and purposes (illustrative)
JRNI affiliates for global support and essential business operations.
Hosting/infrastructure providers (e.g., AWS) to operate our platform.
Communication and support providers (e.g., Twilio for SMS, SendGrid for email, Zendesk for help desk) to deliver services.
Artificial intelligence and machine learning service providers for internal development and support operations, subject to contractual restrictions on the use of data for model training.
Public authorities where required by law, including to meet national security or law-enforcement requirements.
Security, Data Integrity, and Purpose Limitation
JRNI applies administrative, technical, and physical safeguards appropriate to the sensitivity of personal data, and limits processing to what is relevant for the purposes for which the data was collected or subsequently authorized.
Inquiries, Complaints, and Independent Recourse
Inquiries or complaints regarding our DPF compliance should first be directed to: infosec@jrni.com.
If an issue remains unresolved, individuals in the EU/EEA may seek free, independent recourse from their local Data Protection Authority (DPA) – see Data Protection Authorities. Individuals in the United Kingdom may contact the Information Commissioner’s Office (ICO) – see Make a complaint | ICO. Individuals in Switzerland may contact the Federal Data Protection and Information Commissioner (FDPIC) – see FDPIC.
Under certain conditions, individuals may invoke binding arbitration for residual claims not resolved by other DPF recourse mechanisms. For details, see the DPF Annex I binding arbitration terms: Annex I – Binding Arbitration.
U.S. Regulatory Oversight
JRNI is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC). See the FTC’s DPF page: FTC – Data Privacy Framework.
Annual Review and Updates
JRNI reviews and reaffirms its DPF certification annually and updates this notice as needed to remain accurate with our processing activities and DPF commitments.
Last updated: 6 April 2026
This Privacy Policy is published at: https://www.jrni.com/privacy/