Data Processing Agreement
Where you (the site) are the controller and Datum is the processor of the issue and page data our apps handle for you.
Last updated: 2 September 2026
This DPA is incorporated into the Terms of Service and applies whenever a Datum App processes personal data on your behalf. You are the controller; datadir s. r. o. is the processor.
1. Subject matter and duration
We process personal data only to provide the Apps you've installed, for as long as they're installed, plus the short wind-down period in section 7.
2. Nature and purpose
Reading and writing issue and page data (issues, projects, fields, changelog, pages, spaces) and, where a feature needs it, limited end-user data — solely to deliver that App's function.
3. Categories of data and data subjects
- Data subjects: the site's users and the people its work involves (approvers, ticket contacts, page owners).
- Data: issue and page configuration and content; and, per feature, identifiers such as an approver's Atlassian identity or a page owner. We minimise this to what the feature requires.
4. Our obligations
- Process only on your documented instructions (installing and configuring an App is such an instruction).
- Ensure personnel are bound by confidentiality.
- Apply appropriate technical and organisational security measures (section 6).
- Assist you with data-subject requests and with your security, breach, and impact-assessment obligations.
- Notify you without undue delay after becoming aware of a personal-data breach.
5. Sub-processors
You authorise the sub-processors below. We'll give notice of any intended change and a chance to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Atlassian Pty Ltd | The platform your site runs on, and — via Atlassian Forge (hosted on AWS) — the cloud that hosts the app and any data it stores | Per Atlassian's terms & sub-processors |
| Transactional notification / email relay | Sending notifications or emails for apps that send them (e.g. review reminders) | Named here before any such app goes live |
6. Security measures
- Per-install isolation — an app's stored data is scoped to a single install (site + app), so no site's install can read another's data.
- Verified requests — every invocation carries a signed Atlassian-issued token verified against the app before any data is shown, and every inbound webhook is checked against its signing secret before it's acted on.
- Dependable, auditable state — where an app owns a decision (an approval, a sign-off) that state is app-owned so it isn't silently overwritten; Rewind and Signet keep full, exportable histories.
- Encryption in transit; access on least-privilege; hosting on Atlassian Forge.
7. Return and deletion
On uninstall, or on your request, we delete or return the personal data we process for you, except where the law requires retention.
8. International transfers
The apps and their stored data are hosted on Atlassian Forge (AWS). Atlassian's own data-residency and international-transfer safeguards apply to that hosting.
9. Audits
On reasonable request and notice, we'll make available the information needed to demonstrate compliance with this DPA.
Questions about this DPA: support@datadir.co. Company details: Legal notice.