Goor Software

Data Processing Agreement

Export work items for Jira · Last updated: 17 August 2026

This agreement covers personal data in connection with the app Export work items for Jira. Two facts define it: the provider never receives a copy of the data, and the exported file is delivered to the computer of the person who exported it.

1. Parties and scope

This Data Processing Agreement (“DPA”) is entered into between the organisation that installs the app (“Customer”) and Goor Software (“Provider”). It supplements the end-user agreement for the app and applies where the Provider processes personal data on the Customer’s behalf under the GDPR or comparable data protection law.

The Customer acts as controller. The Provider acts as processor and processes personal data only as described here.

2. Subject matter, nature and purpose

The app reads work items from the Customer’s Jira site and assembles a spreadsheet file from them in the browser of the requesting user. The purpose of the processing is to produce that file. There is no other purpose.

3. Duration

Processing occurs while an export is running and ends when it completes. Nothing is carried over between sessions. The arrangement lasts as long as the app is installed on the Customer’s site.

4. Categories of data

See Annex I. Unlike a fixed-purpose viewer, the categories here are chosen by the Customer’s own user: the app reads the fields selected as columns and no others. Those fields may include free-text content such as summary, description and comments, and fields naming people such as assignee and reporter.

5. Processing on instructions only

The Provider processes personal data only to produce the file the Customer’s user requested, and for no independent purpose. The Provider does not sell personal data, does not use it to train models, does not profile data subjects, and runs no analytics or advertising code in the app.

Access follows the Customer’s own permissions: every request the app makes to Jira is made in the name of the signed-in user, so the app cannot include a work item that user could not already open in Jira.

6. Access control over export

Because an exported file leaves the reach of Jira’s permissions, the app makes exporting a separate right. It declares a Jira global permission, Export work items, which a site administrator grants in Jira settings → System → Global permissions. Only administrators hold it until the Customer decides otherwise.

The check is enforced on the server side, on every request that returns data, and not only in the user interface.

7. No transfer to the Provider

The app is built on Atlassian Forge and executes entirely within Atlassian’s cloud infrastructure, under Atlassian’s Runs on Atlassian model. It makes no network request to any destination outside Atlassian. The Provider operates no servers, receives no copy of the Customer’s data, and has no technical means of retrieving personal data from the Customer’s site.

The exported file is written directly by the browser to the device of the user who requested it. It does not pass through the Provider and is not transmitted to any third party. Once written, the file is under the Customer’s control and outside the app’s reach.

8. Storage

The app stores no data. It holds no storage permission and maintains no database or cache. The only persisted item is the list of field identifiers a user last selected as columns, kept in that user’s own browser; it contains no work item content and no personal data. This is described in the privacy policy.

9. Confidentiality and security

The Provider keeps confidential any Customer information it becomes aware of, including through support requests. Personnel with access are bound by confidentiality; the app is maintained by a single named individual.

Technical and organisational measures are set out in Annex II. Because the app holds no write permission, has no external network access and retains no data, the measures rest on the Atlassian Forge platform’s controls together with the app’s minimal permission footprint.

10. Personal data breaches

If the Provider becomes aware of a personal data breach affecting Customer personal data processed through the app, it will notify the Customer without undue delay and provide the information reasonably needed for the Customer to meet its own notification obligations. Incidents affecting the underlying Atlassian platform are handled by Atlassian under the Customer’s agreement with Atlassian.

11. Sub-processors

The Provider engages no sub-processors. Atlassian hosts the Customer’s Jira site and the app’s execution environment under the Customer’s own agreement with Atlassian, and is therefore not a sub-processor engaged by the Provider.

12. Assistance, audits and data subject rights

Because the Provider holds no copy of personal data, requests from data subjects to access, correct, export or erase their data are fulfilled by the Customer within its own Jira site. The Provider will assist with such requests, and with data protection impact assessments and regulator enquiries, to the extent the app is relevant.

On reasonable request the Provider will supply information needed to demonstrate compliance with this DPA. The app’s permissions are published on its Marketplace listing and can be inspected before installation.

13. Deletion and return

There is no personal data to return or delete: none is retained. On uninstallation the app loses access to the Customer’s Jira immediately. Files already exported are the Customer’s own records, held on the Customer’s devices, and are managed by the Customer.

14. International transfers and governing law

The app initiates no transfer of personal data. Data remains within the Atlassian environment already chosen by the Customer for its Jira site, and any transfer occurring there is governed by the Customer’s agreement with Atlassian. Where an exported file is subsequently moved, that is an act of the Customer.

This DPA is governed by the laws of the State of Israel, without prejudice to mandatory data protection law applicable to the Customer.

Annex I — Details of processing

Annex II — Technical and organisational measures

Contact

Goor Software · support@goor.email