Data Processing Addendum
This Data Processing Addendum ("DPA") applies where the developer of Bulk Participants for JSM processes personal data on behalf of a customer through the app. It supplements the applicable End User Terms and Terms of Service for Bulk Participants for JSM.
1. Scope and roles
The customer determines the purposes and means of processing data within its Jira Service Management environment. Where applicable, the customer acts as the data controller or business and the developer acts as a data processor or service provider solely for the purpose of providing Bulk Participants for JSM.
This DPA does not change the customer's responsibility for its own Jira Service Management configuration, permissions, lawful use, or compliance obligations.
2. Categories of data
The app may process or store limited operational data including:
- Atlassian account IDs
- Jira issue keys
- Operation type
- Timestamps
- Limited operation and result metadata
The app does not intentionally store:
- Email addresses
- Display names in Forge storage
- Jira request descriptions
- Comments
- Attachments
- Passwords
- API tokens
- Raw Jira API payloads
3. Processing purposes
Processing is limited to activities necessary to provide the app, including:
- Selecting and previewing Jira Service Management requests
- Adding, removing, or replacing Request Participants
- Short-term preflight validation
- Maintaining limited operation history
- Meeting privacy, retention, and erasure obligations
- Troubleshooting and safe operation of the app
4. Hosting and subprocessors
Bulk Participants for JSM runs entirely on Atlassian Forge. Persistent app data is stored using Atlassian Forge-hosted storage.
The app does not use:
- An external application backend
- An external database
- Third-party analytics
- Advertising services
- Remote application services
Atlassian provides the platform infrastructure and hosting services used by the app. No additional app-controlled subprocessors are used for stored app data.
5. Data residency
In-scope End-User Data stored by the app is stored exclusively in Atlassian Forge-hosted persistent storage and follows the data residency capabilities made available by Atlassian for Forge.
6. Retention
Preflight data used for Preview and Apply has a maximum usable lifetime of 15 minutes and is removed when consumed, expired, or cleaned up.
Operation history is retained for up to 30 days. Personal-data index references are removed when they are no longer needed. App uninstall cleanup removes retained app storage.
7. Security measures
Bulk Participants for JSM uses measures appropriate to its limited scope, including:
- Atlassian Forge-hosted runtime and storage
- Signed-in-user permission enforcement
- Least-privilege Atlassian Marketplace scopes
- No external remotes or external application database
- No customer passwords or shared API tokens
- Bounded retention periods
- Privacy reporting and erasure handling
- No intentional logging of Jira request content or personal data
8. Privacy and data subject requests
The app uses Atlassian's Personal Data Reporting API and internal erasure mechanisms to support applicable account-update and deletion requirements.
Customers may contact support@getreadycheck.com regarding privacy, deletion, or data-handling questions.
9. Confidentiality and use of data
App data is used only as necessary to provide, secure, maintain, and support Bulk Participants for JSM. The developer does not sell app data or use it for advertising.
10. Security incidents
The developer will take reasonable steps to investigate confirmed security incidents involving app-controlled data and will notify affected customers when required by applicable law or contractual obligation.
11. Customer instructions
By using the app, the customer instructs the developer to process relevant data only as necessary to provide Bulk Participants for JSM in accordance with the applicable terms and this DPA.
12. Deletion and termination
Retained app data is removed according to the documented retention process. Forge uninstall cleanup removes retained app storage when the app is uninstalled.
13. Governing terms
Any governing-law provisions in the applicable End User Terms or other customer agreement remain unchanged by this DPA.
14. Contact
Questions about this DPA may be sent to support@getreadycheck.com.