Data Processing Addendum
This Data Processing Addendum (“DPA”) applies to personal data processed by Shurivo for Jira Service Management on behalf of a customer.
1. Parties and scope
This DPA is entered into between the customer using the App (“Customer”) and Sajjad Alizadeh, an independent developer operating the Shurivo product brand (“Provider”). It applies only to the extent Provider processes Personal Data on behalf of Customer in connection with Shurivo for Jira Service Management (the “App”).
If there is a conflict between this DPA and the parties’ applicable end-user agreement with respect to the processing of Personal Data, this DPA controls for that processing.
2. Roles
For Personal Data processed by Provider on Customer’s behalf, Customer acts as controller (or equivalent role under applicable data-protection law) and Provider acts as processor/service provider, as applicable. Customer is responsible for determining the lawfulness of its use of the App and for providing any notices or obtaining any consents required for its processing activities.
3. Processing instructions
Provider will process Personal Data only to provide, secure, maintain, and support the App; to comply with Customer’s documented instructions as expressed through use and configuration of the App; and as otherwise required by applicable law. Provider will notify Customer if it believes an instruction violates applicable data-protection law, unless prohibited from doing so.
4. Processing details
| Subject matter | Providing configurable request-editing functionality, authorization/policy enforcement, audit recording inside Jira, and App configuration for Jira Service Management. |
|---|---|
| Duration | For the duration of Customer’s use of the App and any platform-controlled retention period following uninstall, unless otherwise required by law. |
| Nature and purpose | Reading data needed to evaluate whether supported edits are allowed; writing approved changes and audit information inside Jira; storing project-level App configuration in Forge hosted storage; and providing support/security operations. |
| Data subjects | Customer administrators, Jira/Jira Service Management users, requesters, request participants, and other individuals whose information is contained in relevant Jira/Jira Service Management requests. |
| Personal Data | Atlassian account identifiers and display names; request field values that may contain Personal Data; request-participant information; project/request metadata; and audit information such as editor identity, timestamps, changed field names, and before/after values stored inside Jira. |
5. Data location and storage
The App is built on Atlassian Forge. It does not use Forge Remote, a Provider-operated external runtime server, or an external customer-data database. Request contents and request before/after values are not stored in Forge KVS. Forge KVS is used for project-level App configuration.
Data written to Jira remains in Jira. Forge-hosted configuration follows Atlassian’s hosted-storage controls and lifecycle.
6. Confidentiality and access
Provider will limit access to Personal Data to the extent necessary to provide, secure, maintain, or support the App and will treat Personal Data as confidential. Provider will not sell Customer Personal Data or use it for advertising.
7. Security measures
Provider will maintain appropriate technical and organizational measures for the App, taking into account the nature of processing and the risks involved. These measures include use of Atlassian Forge hosting, App-level authorization and configured policy checks, data minimization, restricted logging practices, dependency and vulnerability management, and security-incident handling.
8. Subprocessing and external runtime services
The App does not send App runtime End-User Data to non-Atlassian third-party services and does not use non-Atlassian external runtime infrastructure for customer request data. Atlassian Forge and Jira/Jira Service Management provide the platform environment in which the App operates; Customer’s relationship with Atlassian is also governed by Customer’s applicable Atlassian agreements.
Corporate email services used for ordinary support, privacy, and security correspondence are separate from the App runtime data flow. Customers should avoid sending unnecessary request content or secrets by email.
9. Data-subject requests
Taking into account the nature of the processing, Provider will provide reasonable assistance to Customer with requests from individuals exercising applicable data-protection rights where the requested Personal Data is within Provider’s ability to access or act upon. Because request and audit data remain inside Customer’s Atlassian environment, Customer administrators may be able to address many such requests directly within Jira/Jira Service Management.
10. Assistance and compliance information
Provider will provide information reasonably necessary to demonstrate compliance with this DPA and, where required by applicable law, reasonable assistance regarding security, breach response, and data-protection impact assessments, taking into account the nature of the App and the information available to Provider.
11. Personal Data breaches
Provider will notify Customer without undue delay after becoming aware of a confirmed Personal Data breach for which Provider is responsible and will provide information reasonably available to Provider to assist Customer with applicable notification obligations. Provider may provide information in phases as it becomes available.
12. Return and deletion
Upon termination or uninstall, Provider will not retain a separate external copy of Customer request data because the App does not maintain an external customer-data database. Data stored in Jira remains subject to Customer’s Jira/Atlassian retention controls. Forge-hosted App configuration is handled according to Atlassian’s hosted-storage lifecycle. Atlassian currently documents a 28-day retention period for Forge hosted storage after App uninstallation, subject to Atlassian’s platform policies and updates.
13. International transfers
The App’s runtime and hosted configuration use Atlassian-provided infrastructure. Customer is responsible for its Atlassian account and data-residency choices. If Provider later introduces processing that requires an independent international transfer mechanism, Provider will update this DPA and the related privacy documentation before using that processing for Customer Personal Data.
14. Audits
Upon reasonable written request, Provider will make available relevant information about the App’s processing and security practices. Any audit request must be proportionate, protect confidential information, avoid unreasonable disruption, and first use available documentation where appropriate. The parties will cooperate in good faith on any additional audit steps legally required.
15. No independent certification claim
Provider does not represent that Shurivo independently holds SOC 2, ISO 27001, FedRAMP, or HIPAA certification.
16. Contact
Privacy and DPA inquiries: [email protected]
Security matters: [email protected]