Data Processing Agreement for Repeating Issues valid from May 1, 2026

Data Processing Agreement for Repeating Issues valid from May 1, 2026

This DPA will be in effect from May 1, 2026

1. Parties

This Data Processing Agreement (“Agreement”) is entered into between:

Controller: Customer using the application
and
Processor: Codedoers Sp. z o.o., registered in Poland

This Agreement forms part of the Terms of Service and applies to the processing of personal data in connection with the application Repeating Issues for Jira Cloud.


2. Definitions

Terms such as personal data, processing, controller, processor shall have the meaning given in the GDPR (Regulation (EU) 2016/679).


3. Subject Matter and Duration

The Processor processes personal data on behalf of the Controller for the purpose of providing the application functionality.

Processing takes place:

  • during the term of the agreement

  • and for up to 180 days after uninstall of the application


4. Nature and Purpose of Processing

Processing includes:

  • reading Jira work items

  • creating new Jira work items

  • storing scheduling configurations and templates

  • executing automated work item creation and workflows based on schedules

Purpose:

  • enabling automated creation of recurring Jira work item


5. Categories of Personal Data

The Processor processes the following categories:

  • Atlassian account identifiers (accountId) (e.g. reporter, assignee)

  • work item metadata, system fields and custom fields

The Controller acknowledges that Jira work items, including descriptions, may contain personal data (including special categories of personal data) entered by its users. The Processor does not control the content of such data and processes it solely on behalf of the Controller.


6. Categories of Data Subjects

  • users of the Controller’s Jira instance (employees, collaborators)

  • individuals whose data may be included in Jira work items

6a. Controller Responsibility for Data Content

The Controller is solely responsible for:

  • determining the types of personal data included in Jira work items, comments, and other content

  • ensuring that such data is processed lawfully and in accordance with applicable data protection laws

  • avoiding the inclusion of unnecessary or excessive personal data, including special categories of personal data, unless strictly required

The Processor does not monitor, control, or validate the content of data submitted by the Controller’s users.


7. Processor Obligations

The Processor shall:

  • process data only on documented instructions from the Controller

  • ensure confidentiality of authorized personnel

  • implement appropriate technical and organizational measures

  • assist the Controller in fulfilling GDPR obligations

  • notify the Controller of personal data breaches without undue delay (max 72h)


8. Sub-processors

The Controller authorizes the use of the following sub-processors:

Infrastructure

  • DigitalOcean, LLC – hosting and database services (USA)

Platform provider

  • Atlassian Pty Ltd – Jira Cloud platform

The Processor shall:

  • ensure sub-processors are bound by equivalent data protection obligations

  • inform customers of material changes (e.g. via website or documentation)


9. International Data Transfers

Personal data is transferred outside the EEA to:

  • United States (DigitalOcean)

Such transfers are safeguarded using:

  • Standard Contractual Clauses (SCCs) or equivalent safeguards provided by the sub-processor


10. Security Measures

The Processor implements:

Technical measures

  • encryption in transit (TLS)

  • encryption at rest (managed by DigitalOcean)

  • tenant isolation (database per tenant)

  • restricted logging (no business data, only IDs)

Organizational measures

  • access limited to authorized personnel (currently 2 persons)

  • access is logged and linked to internal service requests

  • controlled support access procedures

Backup

  • backups managed by DigitalOcean (retention: 5–7 days)


11. Data Retention and Deletion

  • Data is retained during use of the application

  • After uninstall:

    • retained for 180 days

    • then permanently deleted

  • Backups are automatically deleted after 5–7 days


12. Data Subject Rights

The Processor assists the Controller by:

  • providing access to data upon request

  • supporting correction and deletion

Requests are handled via:

  • service desk process

  • identity verification (if required)


13. Personal Data Breach

In case of a breach, the Processor shall:

  • notify the Controller without undue delay (max 72h)

  • provide relevant details

  • cooperate in mitigation


14. Audits

The Processor provides:

  • self-assessment documentation upon request

No on-site audits are guaranteed unless separately agreed.


15. Return and Deletion of Data

Upon termination:

  • data is deleted according to retention policy (180 days)

  • no data is returned unless explicitly requested


16. Liability

Liability is governed by the main Terms of Service.


17. Governing Law

This Agreement shall be governed by the laws applicable to the Processor (Poland), unless otherwise agreed.