Data Processing Agreement for Repeating Issues valid from May 1, 2026
This DPA will be in effect from May 1, 2026
1. Parties
This Data Processing Agreement (“Agreement”) is entered into between:
Controller: Customer using the application
and
Processor: Codedoers Sp. z o.o., registered in Poland
This Agreement forms part of the Terms of Service and applies to the processing of personal data in connection with the application Repeating Issues for Jira Cloud.
2. Definitions
Terms such as personal data, processing, controller, processor shall have the meaning given in the GDPR (Regulation (EU) 2016/679).
3. Subject Matter and Duration
The Processor processes personal data on behalf of the Controller for the purpose of providing the application functionality.
Processing takes place:
during the term of the agreement
and for up to 180 days after uninstall of the application
4. Nature and Purpose of Processing
Processing includes:
reading Jira work items
creating new Jira work items
storing scheduling configurations and templates
executing automated work item creation and workflows based on schedules
Purpose:
enabling automated creation of recurring Jira work item
5. Categories of Personal Data
The Processor processes the following categories:
Atlassian account identifiers (accountId) (e.g. reporter, assignee)
work item metadata, system fields and custom fields
The Controller acknowledges that Jira work items, including descriptions, may contain personal data (including special categories of personal data) entered by its users. The Processor does not control the content of such data and processes it solely on behalf of the Controller.
6. Categories of Data Subjects
users of the Controller’s Jira instance (employees, collaborators)
individuals whose data may be included in Jira work items
6a. Controller Responsibility for Data Content
The Controller is solely responsible for:
determining the types of personal data included in Jira work items, comments, and other content
ensuring that such data is processed lawfully and in accordance with applicable data protection laws
avoiding the inclusion of unnecessary or excessive personal data, including special categories of personal data, unless strictly required
The Processor does not monitor, control, or validate the content of data submitted by the Controller’s users.
7. Processor Obligations
The Processor shall:
process data only on documented instructions from the Controller
ensure confidentiality of authorized personnel
implement appropriate technical and organizational measures
assist the Controller in fulfilling GDPR obligations
notify the Controller of personal data breaches without undue delay (max 72h)
8. Sub-processors
The Controller authorizes the use of the following sub-processors:
Infrastructure
DigitalOcean, LLC – hosting and database services (USA)
Platform provider
Atlassian Pty Ltd – Jira Cloud platform
The Processor shall:
ensure sub-processors are bound by equivalent data protection obligations
inform customers of material changes (e.g. via website or documentation)
9. International Data Transfers
Personal data is transferred outside the EEA to:
United States (DigitalOcean)
Such transfers are safeguarded using:
Standard Contractual Clauses (SCCs) or equivalent safeguards provided by the sub-processor
10. Security Measures
The Processor implements:
Technical measures
encryption in transit (TLS)
encryption at rest (managed by DigitalOcean)
tenant isolation (database per tenant)
restricted logging (no business data, only IDs)
Organizational measures
access limited to authorized personnel (currently 2 persons)
access is logged and linked to internal service requests
controlled support access procedures
Backup
backups managed by DigitalOcean (retention: 5–7 days)
11. Data Retention and Deletion
Data is retained during use of the application
After uninstall:
retained for 180 days
then permanently deleted
Backups are automatically deleted after 5–7 days
12. Data Subject Rights
The Processor assists the Controller by:
providing access to data upon request
supporting correction and deletion
Requests are handled via:
service desk process
identity verification (if required)
13. Personal Data Breach
In case of a breach, the Processor shall:
notify the Controller without undue delay (max 72h)
provide relevant details
cooperate in mitigation
14. Audits
The Processor provides:
self-assessment documentation upon request
No on-site audits are guaranteed unless separately agreed.
15. Return and Deletion of Data
Upon termination:
data is deleted according to retention policy (180 days)
no data is returned unless explicitly requested
16. Liability
Liability is governed by the main Terms of Service.
17. Governing Law
This Agreement shall be governed by the laws applicable to the Processor (Poland), unless otherwise agreed.