Version: 1.0
Publication/version date: 29 August 2026
Last updated: 29 August 2026
Processor: Will Perry trading as PezTech Software, a sole trader in the United Kingdom
Contact: support@peztechsoftware.co.uk
Legal-notice address: [The Bristol Office, 2nd Floor, 5 High Street, Westbury-on-Trym, Bristol, BS9 3BY, England]
1. Scope and status
- This Data Processing Addendum (“DPA”) forms part of the agreement for Bulk Approvals for Jira Service Management between the Customer and PezTech Software (the “Agreement”).
- It applies where PezTech Software processes Customer Personal Data solely on behalf of the Customer to provide the Product.
- The Customer is the controller, or a processor acting on another controller’s lawful instructions. PezTech Software is the processor. Atlassian Forge is a sub-processor/platform provider as described in Schedule 2.
- Marketplace/customer administration and ordinary direct support records for which PezTech Software determines its own business purposes are separate controller activities described in the Privacy Notice.
- Terms such as controller, processor, personal data, processing, personal-data breach and data subject have the meanings in applicable data-protection law.
2. Precedence, term and liability
- For Customer Personal Data and other data-protection matters, this DPA controls over the Provider-Specific Terms and Standard Agreement to the extent of a conflict.
- Otherwise, the order of precedence in the Provider-Specific Terms and Standard Agreement applies.
- This DPA begins on the Agreement’s Effective Date and continues until PezTech Software has ceased processing Customer Personal Data.
- Contractual liability under this DPA is governed by the Standard Agreement as modified by the Provider-Specific Terms. Contractual claims for breach of this DPA are subject to the General Cap stated in the Provider-Specific Terms, to the extent permitted by law; no separate Enhanced Cap applies.
- The General Cap allocates contractual risk between the parties only. Nothing in the Agreement or this DPA excludes or limits statutory data-subject rights, direct obligations or liability under applicable data-protection law, or regulatory powers and penalties where these cannot lawfully be excluded or limited.
- This DPA creates no additional indemnity.
3. Customer instructions and responsibilities
- PezTech Software will process Customer Personal Data only on the Customer’s documented instructions, including this DPA, the Agreement, the applicable Order, Product configuration and authorised actions taken through the Product.
- PezTech Software may process Customer Personal Data where required by UK law. Unless law prohibits it, PezTech Software will tell the Customer of that legal requirement before processing.
- PezTech Software will inform the Customer if, in its reasonable opinion, an instruction infringes applicable data-protection law.
- The Customer determines whether the Product and its configuration are appropriate for its processing and is responsible for its lawful basis, notices, data accuracy, Jira/JSM permissions and instructions.
- The Customer must minimise request content and configured context fields and must not intentionally use the Product for unlawful processing.
- If PezTech Software processes data outside the Customer’s instructions and determines the purposes and means, it will be a controller for that processing to the extent required by law.
4. Confidentiality
- PezTech Software will ensure that each person authorised to process Customer Personal Data is bound by an appropriate contractual or statutory duty of confidentiality.
- Access will be limited to persons and service providers who need it to perform the Agreement or meet applicable law.
5. Security
- Taking account of the state of the art, implementation cost, processing nature, scope, context and purposes, and the risks to people, PezTech Software will maintain appropriate technical and organisational measures meeting Article 32 requirements.
- Current measures are summarised in Schedule 3.
- PezTech Software may update those measures where protection is not materially reduced.
- The Customer remains responsible for configuring Jira/JSM permissions, workflows, request types, fields and users appropriately.
6. Personal-data breaches
- PezTech Software will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data.
- Taking account of the information available, PezTech Software will provide or assist with:
- the nature of the breach;
- relevant categories and approximate numbers of data subjects and records, where available;
- a contact point for further information;
- likely consequences; and
- measures taken or proposed to contain, investigate, remedy and mitigate the breach.
- Information may be supplied in phases without undue further delay where it is not all available initially.
- PezTech Software will reasonably assist the Customer with any required regulator or data-subject notification. Notice under this clause is not an admission of fault or liability.
7. Sub-processors
- The Customer gives PezTech Software general written authorisation to use sub-processors needed to provide the Product.
- Current core sub-processing is identified in Schedule 2. PezTech Software will make the current list available through its published legal documentation or another durable notice location.
- PezTech Software will give reasonable advance notice of a material addition or replacement where practicable, including through the published list, email or another durable mechanism.
- The Customer may object within 15 days of notice on reasonable, substantiated data-protection grounds.
- PezTech Software will consider the objection in good faith and seek a commercially reasonable solution. If no reasonable solution is available, either party may terminate the affected Product entitlement in accordance with the Agreement; this does not require PezTech Software to cease using infrastructure essential to the Product for all customers.
- PezTech Software will impose data-protection obligations on each sub-processor that provide an equivalent level of protection required by Article 28 for the relevant processing.
- PezTech Software remains liable to the Customer for a sub-processor’s performance of its data-protection obligations as required by applicable law and the Agreement.
- This general-authorisation model does not require individual written consent whenever Atlassian changes an infrastructure sub-processor.
8. International transfers
- PezTech Software will not transfer Customer Personal Data outside the United Kingdom except on the Customer’s documented instructions and in compliance with applicable transfer law.
- The Customer authorises transfers inherent in the approved sub-processors’ documented infrastructure and locations, subject to applicable adequacy regulations, the UK International Data Transfer Agreement or Addendum, recognised standard contractual clauses, or another lawful safeguard.
- Atlassian’s Forge terms, DPA, data-residency information and sub-processor list describe the current Forge transfer chain.
- PezTech Software will provide available information reasonably required for the Customer’s transfer assessment.
9. Data-subject rights
- Taking account of the nature of processing, PezTech Software will use appropriate technical and organisational measures to assist the Customer with requests to exercise data-subject rights.
- If PezTech Software receives a request relating to Customer Personal Data, it will refer the requester to the Customer where appropriate and will not respond substantively on the Customer’s behalf unless instructed or legally required.
- Assistance will be proportionate to the Product’s transient, Atlassian-hosted architecture and the information available to PezTech Software.
10. Compliance assistance
Taking account of the nature of processing and information available, PezTech Software will reasonably assist the Customer with:
- security of processing;
- assessment and notification of personal-data breaches;
- data-protection impact assessments; and
- prior consultation with the ICO or another competent authority where required.
The Customer remains responsible for determining whether notification, a DPIA or consultation is required.
11. Information, audits and inspections
- PezTech Software will provide information reasonably necessary to demonstrate compliance with Article 28, beginning with available DPA, security, privacy, architecture, test and sub-processor documentation.
- If that material is reasonably insufficient, PezTech Software will provide reasonable additional information, subject to confidentiality, security and protection of other customers.
- Where legally required, or where documentary evidence remains reasonably insufficient, the Customer may conduct an audit or inspection itself or through an independent auditor who is not a competitor and is bound by confidentiality.
- Unless urgent circumstances or law require otherwise, the Customer must give at least 30 days’ notice, conduct the audit during normal business hours and avoid unreasonable disruption.
- An audit must be limited to systems, records and processing relevant to this DPA. It must not expose another customer’s data, security-sensitive information beyond what is necessary, unrelated systems, the proprietor’s home, or personal devices.
- Remote review and documentary evidence must be used where they can reasonably meet the audit purpose.
- The Customer normally bears its own audit costs and reimburses reasonable Provider costs for assistance beyond ordinary compliance information. This does not apply where law requires otherwise or the audit establishes material non-compliance by PezTech Software.
- Nothing in this section prevents a legally competent regulator from exercising its statutory powers.
12. End of processing, return and deletion
- On termination or expiry, PezTech Software will cease processing Customer Personal Data except where law requires otherwise.
- At the Customer’s choice, PezTech Software will delete or return Customer Personal Data in its possession or control where technically possible, and delete existing copies, unless UK law requires retention.
- Request, approval, requester, context, search, selection, processing and result data is transient and has no intentional PezTech Software retention.
- Forge-hosted configuration data is subject to Atlassian’s current Forge storage retention and deletion lifecycle. PezTech Software has no separate copy and cannot promise deletion outside that supported lifecycle.
- Data awaiting platform deletion will be put beyond ordinary Product use where the platform permits and remains protected until deletion.
- PezTech Software may retain separate records for which it acts as controller, or records required by law, in accordance with the Privacy Notice and retention schedule; such retention does not authorise continued processing on the Customer’s behalf.
13. Standard DPA
- This published DPA is PezTech Software’s standard processing agreement for the Product.
- Bespoke customer DPAs are not offered by default and are outside standard self-service Marketplace support.
- PezTech Software may consider a customer-specific DPA for a sufficiently material commercial opportunity but has no obligation to accept one. Any such proposal is considered separately and is outside standard self-service Marketplace support.
Schedule 1 — Processing details
| Item | Description |
|---|---|
| Subject matter | Processing customer-controlled Jira Service Management data to provide Bulk Approvals for JSM. |
| Duration | The Product entitlement/installation term and the applicable Forge hosted-storage lifecycle. |
| Nature | Authorised reading, transient display/search/selection, human-directed native approval writing, result reconciliation, configuration storage and privacy-safe technical logging. |
| Purpose | Enable signed-in JSM approvers to review and decide native approvals and authorised project administrators to configure supported request types and context fields. |
| Data subjects | Customer employees, contractors, agents, requesters, approvers and other people represented in customer-visible Jira/JSM requests. |
| Personal-data categories | Request/requester display data; request and approval identifiers/status; signed-in Atlassian user context; submission time; configured portal-visible context fields; and related project, service-desk and request-type metadata. |
| Persistent Product data | Configuration metadata only: scope identifiers, up to three field identifiers and action flags. |
| Transient Product data | Request, approval, requester, context, search, selection, progress and result state. |
| Sensitive data | The Product is not designed specifically for special-category or highly sensitive data. PezTech Software does not select customer fields; customer administrators choose eligible portal-visible context fields, and customer-controlled summaries or fields could nevertheless contain sensitive information. Customers should avoid configuring unnecessary sensitive information for display, minimise content and ensure lawful, appropriate use. This DPA and the Product’s security/privacy controls apply to Customer Personal Data processed through the Product. |
| Processing location | Atlassian-hosted Jira/JSM and Forge services subject to Atlassian’s data-residency, sub-processor and transfer arrangements. |
Schedule 2 — Current sub-processors
| Sub-processor | Purpose | Location / transfer information |
|---|---|---|
| Applicable Atlassian entity providing Forge | Forge compute, supported Atlassian API access and configuration-only hosted storage | Atlassian Forge DPA, data-residency documentation and current Atlassian sub-processor list. |
Atlassian’s own authorised infrastructure sub-processors form part of the Forge chain. PezTech Software does not operate a separate Jira-data backend.
Schedule 3 — Technical and organisational measures
- Forge-hosted execution and configuration storage with no PezTech external Jira-data backend.
- Supported Atlassian APIs operating in the signed-in customer context.
- Jira server-side permission and native approval-authority enforcement.
- Least-privilege application scopes and project-admin authorisation for configuration.
- Input, identifier and configuration validation.
- Portal-visible supported-field filtering and bounded configuration.
- Duplicate-submit and stale-state protections; no automatic approval-write retry.
- No browser persistence for request, selection or result state.
- Technical logging designed to exclude Jira request/approval content and personal information.
- No external analytics or telemetry receiving Jira/JSM request data.
- Maintained automated regression, Forge lint and release security/accessibility evidence.
- Access limitation, confidentiality and controlled support handling.
These measures describe the current Product and do not claim certification, penetration testing, guaranteed availability or an absolute security outcome.
_Last reviewed: 29 August 2026._