Search Help

Joyner TMS — Data Processing Agreement

Effective Date: January 1, 2026 Last Updated: January 1, 2026 Applies To: All Joyner TMS Subscribers

1. Purpose & Scope

This Data Processing Agreement ("DPA") governs the processing of personal data by Joyner Transportation & Logistic Services LLC ("Joyner," "we," "us," or "our") on behalf of Customer in connection with the Joyner TMS platform ("Platform"). This DPA supplements and is incorporated into the Joyner TMS SaaS Terms of Service. In the event of a conflict between this DPA and the SaaS Terms of Service with respect to data processing matters, this DPA controls.

This DPA applies to the extent that Joyner processes personal data on behalf of Customer as a data processor (or service provider under applicable U.S. state privacy law) in connection with providing the Platform. It does not apply to personal data that Joyner processes as an independent data controller for its own purposes.

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person that Customer submits to, or that is generated by, the Platform in connection with Customer's use of the service.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, deletion, or other handling.
  • "Data Controller" (or "Business" under CCPA) means Customer, who determines the purposes and means of processing Personal Data through the Platform.
  • "Data Processor" (or "Service Provider" under CCPA) means Joyner, who processes Personal Data on Customer's behalf and under Customer's instructions.
  • "Sub-processor" means any third party engaged by Joyner to process Personal Data in connection with providing the Platform.
  • "Applicable Privacy Law" means any privacy or data protection law applicable to the processing of Personal Data under this DPA, including the EU GDPR, UK GDPR, CCPA/CPRA, and applicable U.S. state privacy laws.

3. Roles & Responsibilities

Customer is the Data Controller and is responsible for: (a) ensuring it has a lawful basis for processing Personal Data through the Platform; (b) providing required notices to data subjects regarding the use of the Platform to process their data; (c) responding to data subject rights requests (with Joyner's assistance as described in Section 7); and (d) ensuring Customer's instructions to Joyner comply with Applicable Privacy Law.

Joyner is the Data Processor and will process Personal Data only: (a) in accordance with Customer's documented instructions, including as set forth in the SaaS Terms of Service and this DPA; (b) as necessary to provide the Platform and related support services; and (c) as required by applicable law, in which case Joyner will notify Customer unless prohibited by law.

4. Categories of Personal Data Processed

In connection with Customer's use of the Platform, Joyner may process the following categories of Personal Data on Customer's behalf:

Category Examples
User account data Names, email addresses, job titles, phone numbers of Customer's platform users
Carrier and vendor data Contact information for carriers, brokers, and vendors entered into the Platform
Shipper and customer data Contact and address information for shippers and consignees in Customer's shipment records
Driver and operator data Driver names, contact information, and license data entered by Customer
Usage and access logs IP addresses, login timestamps, and feature usage data for Customer's users

Customer determines what Personal Data is entered into the Platform. Joyner processes only the Personal Data that Customer submits. Joyner does not verify the accuracy or lawfulness of Personal Data submitted by Customer.

5. Security Measures

Joyner implements and maintains the following technical and organizational security measures to protect Personal Data processed through the Platform:

  • Encryption: All Personal Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 encryption
  • Access controls: Role-based access controls limiting access to Personal Data to authorized Joyner personnel who need it to provide the Platform
  • Authentication: Multi-factor authentication required for all Joyner personnel with access to production systems containing Customer Data
  • Security assessments: Regular vulnerability assessments and penetration testing of Platform infrastructure
  • Incident response: A documented security incident response plan with defined escalation procedures
  • Vendor management: Security assessment of sub-processors before engagement and on an ongoing basis
  • Physical security: Data hosted in SOC 2 Type II certified data centers with physical access controls
  • Employee training: Annual security and privacy awareness training for all Joyner personnel with access to Customer Data

6. Sub-processors

Customer authorizes Joyner to engage sub-processors to assist in providing the Platform. Joyner's current list of sub-processors is maintained at tms.myjoyner.com/sub-processors and is updated when sub-processors are added or removed. Joyner will provide at least thirty (30) days' advance notice of any new sub-processor that will process Customer Personal Data, giving Customer an opportunity to object. Joyner ensures that sub-processors are bound by data protection obligations no less protective than those in this DPA.

Current sub-processor categories include: cloud infrastructure providers, database hosting services, email delivery services, customer support platforms, analytics services, and payment processors.

7. Data Subject Rights

Joyner will assist Customer in fulfilling data subject rights requests to the extent technically feasible and consistent with Joyner's role as Data Processor. Upon Customer's written request, Joyner will:

  • Provide Customer with access to Personal Data held in the Platform for a specific data subject
  • Correct inaccurate Personal Data in the Platform at Customer's direction
  • Delete Personal Data from the Platform at Customer's direction, subject to applicable retention requirements
  • Export Personal Data in a structured, machine-readable format to facilitate data portability requests
  • Restrict processing of specific Personal Data at Customer's direction

Customer is responsible for receiving, verifying, and directing Joyner with respect to data subject rights requests. Joyner will not respond directly to data subject rights requests without Customer's prior authorization, except as required by applicable law.

8. Data Breach Notification

In the event of a confirmed security breach affecting Personal Data processed under this DPA, Joyner will:

  • Notify Customer without undue delay and in any event within seventy-two (72) hours of Joyner becoming aware of the breach
  • Provide a written incident report describing: the nature of the breach; the categories and approximate number of data subjects and records affected; the likely consequences of the breach; and the measures taken or proposed to address the breach
  • Cooperate with Customer in investigating and remediating the breach
  • Provide reasonable assistance to Customer in fulfilling any breach notification obligations to regulators or data subjects under Applicable Privacy Law

Customer is responsible for determining whether the breach triggers notification obligations under Applicable Privacy Law and for notifying regulators and data subjects as required.

9. International Data Transfers

Joyner stores and processes Customer Data in the United States. For Customers in the EEA, UK, or other jurisdictions with data transfer restrictions, transfers of Personal Data to Joyner in the United States are made pursuant to:

  • EEA customers: EU Standard Contractual Clauses (Module 2: Controller to Processor), which are incorporated into this DPA by reference
  • UK customers: UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs, as applicable
  • Other jurisdictions: Joyner will work with Customer to implement appropriate transfer mechanisms upon written request

10. Confidentiality of Processing

Joyner ensures that all personnel authorized to process Personal Data under this DPA are subject to binding confidentiality obligations, whether through employment agreements, contractor agreements, or applicable professional obligations.

11. Audits & Compliance

Joyner will provide Customer with information reasonably necessary to demonstrate compliance with this DPA upon written request, including summaries of security assessments and certifications. Customer may request an audit of Joyner's data processing practices no more than once per calendar year, with at least sixty (60) days' written notice, at Customer's expense. Audit requests must be reasonable in scope and conducted in a manner that minimizes disruption to Joyner's operations. Joyner may satisfy audit requests by providing relevant third-party audit reports (e.g., SOC 2 Type II) in lieu of a direct audit.

12. Data Retention & Deletion

Upon expiration or termination of the subscription, Customer may export Customer Data through the Platform's export tools within thirty (30) days of termination. After this period, Joyner will delete Customer Data from its production systems within sixty (60) days, except where retention is required by applicable law. Joyner will provide written confirmation of deletion upon Customer's written request.

13. U.S. State Privacy Law Compliance

To the extent Applicable Privacy Law includes U.S. state privacy laws (including CCPA/CPRA, Virginia CDPA, Colorado CPA, Connecticut CTDPA, or similar laws), Joyner agrees to:

  • Process Personal Data only as a Service Provider / Processor for the business purposes described in the SaaS Terms of Service and this DPA
  • Not sell or share Personal Data for cross-context behavioral advertising
  • Not use Personal Data for any purpose other than providing the Platform and as permitted by Applicable Privacy Law
  • Assist Customer in responding to consumer rights requests as described in Section 7
  • Notify Customer if Joyner determines it can no longer meet its obligations under Applicable Privacy Law

14. Governing Law

This DPA is governed by the same governing law as the Joyner TMS SaaS Terms of Service. For EEA and UK customers, the EU SCCs and UK IDTA are governed by the laws specified therein.

15. Contact

Data protection inquiries: privacy@myjoyner.com | Joyner Transportation & Logistic Services LLC | Atlanta, Georgia.

Scroll to Top

We value privacy. We may collect personal information from you for business, marketing, and commercial purposes. Read more

Do Not Sell or Share My Personal Information (CA residential only)