Last updated: 27 July 2026
This Privacy Policy explains how the company operating Jomioz (“Jomioz,” “we”) collects, uses, and shares personal information when you use our websites, web and mobile apps, Client Hub, and related services (the “Service”). Jomioz is field-service software for customers, scheduling, jobs, estimates, invoices, payments, messaging, and related workflows. We serve customers in Europe and the Americas and design practices for EU/UK GDPR and applicable US state privacy laws (including CCPA/CPRA). Privacy: privacy@jomioz.com. For legal name, NIF/CIF, and registered office: privacy@jomioz.com or legal@jomioz.com.
When your organization uses Jomioz to manage its End Users, jobs, estimates, invoices, and messages, your organization is typically the controller (or US “business”) of that Customer Data, and Jomioz acts as a processor (or “service provider”). Jomioz is the controller of account, billing, security, and platform administration data. End Users should contact the Account Owner first for workspace data requests. B2B customers may request a DPA at privacy@jomioz.com.
Depending on features you use, we may process: Account Owner and Employee User data (name, email, role, company, locale); End User and job content (contacts, properties/addresses, schedules, jobs, estimates, invoices, notes, photos, attachments, e-signatures, Client Hub activity); messaging metadata for email and, where connected, SMS/WhatsApp; map/route-related address data; Stripe payment/billing data (no full card numbers stored on Jomioz for reuse); AI prompts/outputs where assistive features are enabled; Spanish Verifactu/fiscal data where that module is set up; technical logs (IP, device, diagnostics, auth); and analytics/cookies as described below.
Where the EU/UK GDPR applies, we rely on: (a) performance of a contract; (b) legitimate interests (security, fraud prevention, product improvement, service communications), balanced against your rights; (c) legal obligation; and (d) consent where required (non-essential cookies or optional marketing), which you may withdraw at any time. We do not sell personal information.
We do not sell personal information for money and do not share it for cross-context behavioral advertising under the CCPA/CPRA. Residents of California and similar US states may have rights to know/access, correct, delete, and obtain a portable copy of certain personal information we hold as a business, and to appeal denials where the law provides, without discrimination. Contact privacy@jomioz.com for data Jomioz controls. For End User data inside a customer workspace, contact that business first.
We use personal data to provide and operate Jomioz (including jobs, scheduling, documents, Client Hub, payments, and messaging); authenticate users (including optional two-factor authentication); send transactional and security messages; bill subscriptions; detect abuse; meet legal obligations; improve the product; and generate aggregated, anonymized statistics.
We use subprocessors under contracts that restrict their use of data (GDPR Art. 28 where applicable). Depending on enabled features, this may include cloud hosting/databases; file storage (e.g. AWS S3); Google sign-in; Resend (email); Twilio/Meta (SMS/WhatsApp where connected); Stripe (payments); Mapbox (maps); PostHog (analytics); Sentry (errors, where enabled); OpenAI (AI assist); Meilisearch (search); Firebase (push); and Invopop (Spanish Verifactu where enabled). We may disclose data if required by law or to protect rights and safety. Subprocessor overview on request: privacy@jomioz.com.
Data may be processed in the EEA, UK, United States, and other countries where we or our subprocessors operate. For EEA/UK transfers to countries without an adequacy decision, we use SCCs (and UK equivalents) plus supplementary measures where needed. Contact privacy@jomioz.com for workspace-specific details.
We use strictly necessary cookies for authentication, security, and sessions. We may use PostHog and privacy-oriented marketing analytics. Where non-essential cookies require consent under EU/UK or local law, we will request it. Blocking necessary cookies may break sign-in.
We use TLS in transit, encryption at rest where supported, role-based access, optional two-factor authentication, monitoring, and least-privilege production access. See our Security page. Retention: account life plus wind-down; Customer Data per your configuration/deletion; billing/fiscal records as required by law (including Spanish fiscal rules where Verifactu applies); security logs for a limited investigation period.
Under GDPR you may have rights to access, rectify, erase, restrict, or port data, object to certain processing, and complain to a supervisory authority (in Spain, the AEPD). US state rights are in section 5. For organization-controlled workspace data, contact your admin first; otherwise privacy@jomioz.com. We may verify identity.
Jomioz is a business service. You must be of legal age in your jurisdiction. We do not knowingly collect data from children under 16 (or under 13 in the US, or the higher age required locally). Contact privacy@jomioz.com if you believe we have.
We may update this policy and will post the revised version with an updated date; material changes may also be emailed or shown in-product. Privacy: privacy@jomioz.com. Legal: legal@jomioz.com. Security: security@jomioz.com. See also our Terms of Service and Security page.