Data Processing Agreement
This agreement covers personal data in connection with the app Read-only Gantt for Jira. Its central fact is short: the app displays personal data that is already in your Jira, and the provider never receives a copy of it.
1. Parties and scope
This Data Processing Agreement (“DPA”) is entered into between the organisation that installs the app (“Customer”) and Goor Software (“Provider”). It supplements the end-user agreement for the app and applies where the Provider processes personal data on the Customer’s behalf under the GDPR or comparable data protection law.
The Customer acts as controller. The Provider acts as processor and processes personal data only as described here.
2. Subject matter, nature and purpose
The app reads issue data from the Customer’s Jira site and renders it as a Gantt chart inside that same Jira site. Personal data is involved only insofar as an issue names an assignee, whose display name and avatar are shown on the chart.
The purpose of the processing is to display that chart to a user of the Customer’s Jira site. There is no other purpose.
3. Duration
Processing occurs while a user has the chart open, and ends when the page is closed. Personal data is not carried over between sessions. The arrangement lasts as long as the app is installed on the Customer’s site.
4. Categories of data
See the Annex. In summary: the display name and avatar of a Jira user named as the assignee of an issue. No other category of personal data is read, and none is stored.
5. Processing on instructions only
The Provider processes personal data only to render the chart the Customer’s users request, and for no independent purpose. The Provider does not sell personal data, does not use it to train models, does not profile data subjects, and runs no analytics or advertising code in the app.
Access follows the Customer’s own permissions: every request the app makes to Jira is made in the name of the signed-in user, so the app cannot make an issue — or an assignee — visible to anyone who could not already see it in Jira.
6. No transfer to the Provider
The app is built on Atlassian Forge and executes entirely within Atlassian’s cloud infrastructure, under Atlassian’s Runs on Atlassian model. It makes no network request to any destination outside Atlassian. The Provider operates no servers, receives no copy of the Customer’s data, and has no technical means of retrieving personal data from the Customer’s site.
7. Storage
The app stores no personal data. Its only stored records are technical configuration — identifiers of the Jira fields used for dates, project keys, issue link type names and a timestamp — held in Atlassian Forge storage. This is described in full in the privacy policy.
8. Confidentiality and security
The Provider keeps confidential any Customer information it becomes aware of, including through support requests. Personnel with access are bound by confidentiality; the app is maintained by a single named individual.
Technical and organisational measures are set out in Annex II. Because the app holds no write permission, has no external network access and retains no personal data, the measures rest on the Atlassian Forge platform’s controls together with the app’s minimal permission footprint.
9. Personal data breaches
If the Provider becomes aware of a personal data breach affecting Customer personal data processed through the app, it will notify the Customer without undue delay and provide the information reasonably needed for the Customer to meet its own notification obligations. Incidents affecting the underlying Atlassian platform are handled by Atlassian under the Customer’s agreement with Atlassian.
10. Sub-processors
The Provider engages no sub-processors. Atlassian hosts the Customer’s Jira site and the app’s execution environment under the Customer’s own agreement with Atlassian, and is therefore not a sub-processor engaged by the Provider.
11. Assistance, audits and data subject rights
Because the Provider holds no copy of personal data, requests from data subjects to access, correct, export or erase their data are fulfilled by the Customer within its own Jira site. The Provider will assist with such requests, and with data protection impact assessments and regulator enquiries, to the extent the app is relevant.
On reasonable request the Provider will supply information needed to demonstrate compliance with this DPA. The app’s permissions are published on its Marketplace listing and can be inspected before installation.
12. Deletion and return
There is no personal data to return or delete: none is retained. On uninstallation the app loses access to the Customer’s Jira immediately, and its stored technical configuration is held by Atlassian for 28 days under the retention period applied to Forge hosted storage, then deleted.
13. International transfers and governing law
The app initiates no transfer of personal data. Data remains within the Atlassian environment already chosen by the Customer for its Jira site, and any transfer occurring there is governed by the Customer’s agreement with Atlassian.
This DPA is governed by the laws of the State of Israel, without prejudice to mandatory data protection law applicable to the Customer.
Annex I — Details of processing
- Categories of data subjects: users of the Customer’s Jira site who are named as the assignee of an issue.
- Types of personal data: display name and avatar image, as held in Jira. No contact details, no special categories of data, no location data, no behavioural data.
- Nature and purpose: reading and on-screen display within a Gantt chart rendered inside the Customer’s Jira.
- Frequency: on demand, when a user opens the chart.
- Retention: none. Data exists in the user’s browser for the duration of the session only.
Annex II — Technical and organisational measures
- The app holds two permissions,
read:jira-workandstorage:app. It has no write permission and cannot alter Customer data. - All requests to Jira are made as the signed-in user, so the app cannot exceed that user’s existing access rights.
- The app makes no network request outside Atlassian and transmits no data to the Provider or to third parties.
- No personal data is written to storage, and the app writes no application logs containing Customer data.
- Authentication, tenant isolation, encryption in transit and at rest, and infrastructure security are provided by the Atlassian Forge platform.
- The app is distributed solely through the Atlassian Marketplace and is subject to Atlassian’s security requirements for cloud apps.
Contact
Goor Software · support@goor.email