Data Processing Agreement (DPA)
Version 1.0 · Effective 26 July 2026
1. Parties & Roles
This Data Processing Agreement (“DPA”) forms part of the licence agreement between the Customer (“Controller”) and Exportelier, a sole proprietorship operated by Julia Röhling (“Processor”). It governs processing of personal data carried out by the Processor on behalf of the Controller in connection with the Apps.
2. Subject Matter & Duration
The subject matter is the provision of the Apps as described in the licence agreement (the Atlassian standard end-user agreement together with our Provider Specific Terms). Processing lasts for the duration of the Apps' use by the Controller and until deletion in accordance with Section 11.
3. Nature, Purpose, Data Types & Data Subjects
- Nature & purpose: rendering exports and documents from Jira content, generating and retaining audit-log metadata, and — where the Automation app is used — delivering documents to destinations the Controller configures.
- Types of personal data: data contained in Jira issues and related objects chosen by the Controller (e.g. names, email addresses, comments, worklogs, attachments) and Atlassian account identifiers; audit-log metadata uses pseudonymous account IDs.
- Categories of data subjects: the Controller's users, collaborators and any individuals referenced in the exported Jira content.
4. Processing on Documented Instructions
The Processor processes personal data only on the Controller's documented instructions, including regarding transfers, unless required otherwise by EU or Member State law (in which case the Processor informs the Controller, unless prohibited). The licence agreement, this DPA and the configuration the Controller sets in the Apps constitute the Controller's complete instructions. The Processor informs the Controller if, in its opinion, an instruction infringes data-protection law.
5. Confidentiality
The Processor ensures that persons authorised to process personal data are bound by confidentiality and are trained on their obligations.
6. Security Measures (Art. 32 GDPR)
The Processor implements appropriate technical and organisational measures, taking into account the state of the art and the risk, including:
- data minimisation — the main app processes Jira content within Atlassian Forge and does not transmit it to the Processor's own servers; generated documents are not retained;
- encryption of data in transit (TLS);
- least-privilege access controls and the Forge platform security model;
- pseudonymous identifiers in the audit log; a 30-day visibility and export window in Free that does not delete older entries; configurable physical retention from 30 to 730 days in Standard and Pro (default: 365 days); and a daily purge that uses the stored retention value regardless of edition;
- SSRF protection and encrypted provider URLs in the Automation app;
- tenant isolation — each customer's app data is stored within that customer's own Atlassian environment, not commingled across customers;
- logging and monitoring of export and admin events — the app writes metadata-only audit entries (event type, timestamp, template, pseudonymous Atlassian account IDs) to the Controller's own Forge storage under the retention described in Section 11; platform-level function logs are operated and retained by Atlassian and contain no exported document content;
- vulnerability and dependency management — dependencies are pinned via lockfile, reviewed before every Marketplace release and scanned for known advisories; findings rated critical or high are remediated in a patch release, and Atlassian's Marketplace vulnerability scan must pass before any version is published;
- secret and credential handling — customer signing certificates, certificate passwords and provider API tokens are held as encrypted Forge secrets or encrypted storage entries, are never returned to the browser after saving and are never written to logs; they are rotated on suspicion of compromise, on personnel change and whenever the Controller replaces them;
- backup and recovery — availability, backup and disaster recovery of the underlying storage are provided by Atlassian as platform operator; the Processor holds no separate copy of Controller data and therefore performs no independent backup. Controllers can export their templates and configuration as JSON at any time;
- incident detection and response — application errors and Atlassian security channels are monitored, reports are assessed without undue delay, and the Controller is notified in accordance with Section 10. Security reports may be sent to [email protected].
7. Sub-processors
The Controller grants general authorisation for the Processor to engage sub-processors. The Processor imposes data-protection obligations equivalent to this DPA on each sub-processor and remains liable for their performance. The main app engages only Atlassian (app platform/Marketplace). Additional sub-processors apply only if the Controller installs the optional Automation app and configures egress, namely Brevo (managed email delivery), Slack (incoming webhooks) and Microsoft (Power Platform / Teams Workflows) — each only when the Controller enables that specific channel. The Processor will inform the Controller of intended changes and allow a reasonable period to object.
8. International Transfers
Where processing involves a transfer of personal data outside the EEA, it is carried out under an EU adequacy decision or the European Commission's Standard Contractual Clauses, with supplementary measures where required. Where the Controller's Atlassian site uses data residency, app data held in Forge storage remains in the selected region.
9. Assistance & Data-Subject Rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, to respond to data-subject requests and to comply with its obligations under Articles 32–36 GDPR (security, breach notification, impact assessments and prior consultation).
10. Personal Data Breaches
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and provides information reasonably available to assist the Controller's own notification obligations.
11. Return & Deletion
After the end of the provision of the services, the Processor deletes or returns all personal data processed on the Controller's behalf, at the Controller's choice, and deletes existing copies unless Union or Member State law requires continued storage (Art. 28 (3)(g) GDPR). Because the main app stores Controller data exclusively inside the Controller's own Atlassian environment, the Controller can export that data at any time using the app's built-in export functions; a separate return by the Processor is therefore normally unnecessary. If the Controller nevertheless requests return, the Processor will provide the data in a structured, commonly used format within a reasonable period.
While the Apps are installed, the Controller can configure physical audit-log retention from 30 to 730 days in Standard and Pro (default: 365 days). Free's 30-day visibility and export window is not a deletion instruction and does not remove older entries. The daily purge always uses the stored retention value regardless of edition; older entries hidden in Free may reappear after an upgrade unless they have already been purged. On uninstall, app data held in Forge follows Atlassian's hosted-storage lifecycle: it is first soft-deleted and retained for the remainder of Atlassian's retention period before permanent deletion, and reinstalling within Atlassian's relink window (currently around 21 days) may restore access to the previous data. The Processor keeps no copies on its own servers — the main app stores no Controller data outside Atlassian. Where statutory retention applies, deletion is deferred until those obligations lapse. For details, see Atlassian's Forge hosted-storage data lifecycle.
12. Audits
The Processor makes available information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality and the following conditions: no more than once per calendar year unless a personal data breach or a supervisory-authority requirement gives cause, and with the Controller bearing its own costs unless the audit reveals a material breach by the Processor.
13. Liability & Miscellaneous
Liability under this DPA is subject to the limitations agreed in the licence agreement (the Atlassian standard end-user agreement together with our Provider Specific Terms), to the extent permitted by law. If any provision conflicts with that agreement on data-protection matters, this DPA prevails. This DPA is governed by German law.