Where we process personal data on your behalf, the Bonterms Data Protection Addendum (Version 1.0) applies, incorporated by reference, as set out in this DPA Setup Page. It is an Attachment to the Agreement and applies automatically when you accept the Agreement. Capitalized terms not defined here have the meanings given in the DPA or the Agreement.
| Subprocessor | Purpose / Processing | Location |
|---|---|---|
| Atlassian Pty Ltd (and affiliates) | Cloud platform, hosting, and storage on which the App (a Forge app) runs; hosts and stores Customer Personal Data within the Atlassian platform. | Per Atlassian’s cloud infrastructure |
No other Subprocessors. No third-party analytics, error monitoring, or external storage in the data path.
| Name | The Customer organization accepting the Agreement. |
|---|---|
| Contact for data protection | The individual or email that administers the App on the Customer’s behalf, as applicable. |
| Address | The Customer’s address, as applicable. |
| Role | Controller |
| Name | Kade Schemahorn (Access Governance for Jira), sole proprietor. |
|---|---|
| Contact for data protection | privacy@citizenkade.com |
| Address | 101 Short St, Chapel Hill, NC 27517, United States. |
| Role | Processor |
| Subject matter | Provider’s provision of the App to Customer under the Agreement. |
|---|---|
| Categories of Data Subjects | The Customer’s Jira users and administrators. |
| Categories of Customer Personal Data | Atlassian account IDs; user display names; group and project-role memberships; permission grants; activity-derived (in)activity signals. (Of these, the App stores only Atlassian account IDs, together with group, scheme, project, and role configuration; user display names are resolved live from Jira for display and are not stored. The App does not read or store email addresses.) |
| Special categories of data | None. The App does not collect or process any special-category personal data. |
| Nature of the Processing | Reading and analyzing the Customer’s Jira access and permission configuration to provide access-governance features. Read-only with respect to the Customer’s Jira data; no profiling or automated decision-making is performed. |
| Purpose of the Processing | To provide effective-access views, permission-change impact analysis, inactive-license identification, and access reviews. |
| Frequency | Continuous / on-demand during the Customer’s use of the App. |
| Duration / Retention | For the term of the Agreement; Customer Personal Data is held only in Atlassian-hosted Forge storage and is deleted when the App is uninstalled, in accordance with Atlassian’s Forge platform data lifecycle. In addition, Provider will delete Customer Personal Data on Customer’s written request — without requiring uninstallation — and provide written confirmation of deletion, as set out in the Provider-Specific Terms. |
| Transfers to Subprocessors | Customer Personal Data is hosted and stored by Atlassian (see the Subprocessor List above) solely for hosting, storage, and operation of the App. |
Provider’s technical and organizational measures are the Security Measures, incorporated by reference. In summary: built on Atlassian Forge; read-only Jira scopes; no data egress off the Atlassian platform; storage only in Atlassian-hosted Forge storage; encryption in transit and at rest provided by the Atlassian platform; in-product audit logging; deletion on uninstall.
Audit. The App is a Forge app that runs entirely on Atlassian’s infrastructure, and Provider operates no separate hosting infrastructure. Provider satisfies audit and inspection rights under the DPA by making available, on reasonable request: (i) Atlassian’s then-current third-party certifications and attestations for the underlying platform (for example, SOC 2 and ISO/IEC 27001) together with a description of the Atlassian Forge security model; and (ii) Provider’s responses to a reasonable security questionnaire and supporting documentation. Such audits are limited to once per calendar year (absent a documented security incident or a binding regulatory requirement), are conducted at Customer’s expense and under a non-disclosure agreement, and take the form of a documentation review rather than on-site or physical inspection of infrastructure Provider does not operate.
Provider initiates no Restricted Transfer of Customer Personal Data: the data remains within the Atlassian platform that already hosts the Customer’s Jira data, and Provider operates entirely on Atlassian’s infrastructure with no egress. Provider does not itself export Customer Personal Data across borders, and any cross-border processing of Customer Personal Data is governed by Atlassian’s own platform transfer terms and data-residency controls. Where a Restricted Transfer nonetheless applies to a Customer, the transfer mechanisms in Schedule 3 of the Bonterms DPA (for example, the EU Standard Contractual Clauses and the UK International Data Transfer Addendum) apply.
The Region-Specific Terms in Schedule 4 of the Bonterms DPA (Version 1.0) apply, as applicable to the Customer’s jurisdiction (for example, US/CCPA, EU GDPR, UK GDPR, Swiss FADP). For California, Provider acts as a “service provider,” processes Customer Personal Data only to provide the App, and does not sell or share that data or combine it with other personal information except as the CCPA permits.