1. Parties and scope
This Data Processing Addendum ("DPA") forms part of the agreement between you, the customer who has subscribed to or installed a UX Software Product ("Customer", acting as Data Controller), and UX Software ("Processor", "we", "us"), governing the Processor's processing of personal data on the Customer's behalf.
This DPA applies uniformly to every Product UX Software distributes — current and future — the same way the company's Privacy Policy and End-User License Agreement do. The specifics of what a given Product processes — categories of personal data, storage location, retention — are set out in that Product's own Data Security Statement, referenced from its Marketplace listing. Where this DPA and a Product's Data Security Statement address the same point, the Data Security Statement controls for that Product as the more specific document.
Capitalised terms not defined here have the meaning given in the EU General Data Protection Regulation (GDPR) or the equivalent applicable data protection law.
2. Subject matter and duration
The Processor processes personal data solely to provide the functionality of the Product the Customer has subscribed to or installed, on the Customer's instructions as expressed through the Customer's own use of that Product. Processing continues for as long as the Product remains installed on the Customer's Atlassian site, plus any retention period stated in that Product's Data Security Statement.
3. Nature and purpose of processing
Each Product processes personal data only as needed to provide its documented features, as directed by the Customer's own users. The Processor does not use Customer personal data for any secondary purpose — no analytics on End-User Data, no profiling, no advertising, no sale or sharing with third parties — regardless of which Product is involved.
4. Categories of data subjects
Jira, Confluence or other Atlassian-product users on the Customer's site who use the Product, and any individual named or referenced within data the Product processes (for example, through a Product's own user-reference fields, or free text a Customer's user enters). A given Product's Data Security Statement may describe this more precisely.
5. Categories of personal data processed
Processed categories differ by Product and are listed exhaustively in that Product's Data Security Statement, not repeated here — a category hard-coded into this company-wide addendum would drift out of date the moment a Product's feature set changes. As a general matter, no UX Software Product collects Atlassian account passwords, API tokens, payment details, or any special category of data (GDPR Art. 9) as a defined feature; any such data appearing in Customer-entered free text is entered at the Customer's own discretion and is not a data category the Processor defines.
6. Sub-processors
Every UX Software Product runs entirely on Atlassian infrastructure. For Cloud Products this means the Atlassian Forge platform — Forge-hosted storage (Key-Value Store, Entity Store, SQL), compute and, where a Product uses it, Forge Remote. For Data Center Products, all runtime data stays inside the Customer's own Jira or Confluence database, and Atlassian is not a data sub-processor for that Product's runtime data.
Atlassian is the Processor's sole sub-processor common to every Product. A Product that integrates with a further, Customer-configured destination (for example, a webhook receiver the Customer's administrator points the Product at) treats that destination as chosen and controlled by the Customer, not as a sub-processor of the Processor — see that Product's Data Security Statement for specifics.
The Processor relies on Atlassian's own data processing terms and security commitments, available at . The Customer's agreement with Atlassian governs Atlassian's processing as a sub-processor.
Support correspondence a Customer sends the Processor directly (for example, an email or attachment for a support request) may be handled through the Processor's own support tooling, outside Atlassian. This is limited to what the Customer chooses to send when contacting support, and is not part of any Product's own data flow.
7. Data residency and retention
Where a Product stores all in-scope personal data exclusively in Atlassian-hosted storage, that data follows the data residency realm of the Customer's own Atlassian site — see the Product's Data Residency declaration on its Marketplace listing. Retention periods are stated in the Product's Data Security Statement.
8. Security measures
- Every Product runs under Atlassian's own infrastructure security controls for the storage it uses (Forge-hosted storage for Cloud Products; the Customer's own database for Data Center Products).
- Every action a signed-in user takes through a Product is authorised under that user's own permissions in the host product; a Product performs no action a user could not perform themselves, except where its documentation states otherwise (for example, an app-scoped write needed to keep a searchable index correct). Product-specific credentials the Processor issues (for example, an administrator- generated API key for an optional integration endpoint) are stored only as a salted hash, never in plaintext, and can be revoked individually — see the Product's Data Security Statement for whether it offers such a credential.
- Each Product requests no more platform access than its features require; the justification for each requested permission is published on that Product's Marketplace listing.
9. Assistance with data subject rights
The Processor will provide reasonable assistance to the Customer in responding to requests from data subjects exercising their rights under applicable data protection law (access, rectification, erasure, restriction, portability), to the extent the Processor is able to given the nature of the processing. Requests should be directed to .
10. Personal data breach notification
The Processor will notify the Customer without undue delay, and in any event within [BREACH NOTIFICATION WINDOW], after becoming aware of a personal data breach affecting the Customer's data processed under this DPA, and will provide the information reasonably necessary for the Customer to meet its own notification obligations.
11. Return and deletion of data on termination
On termination of the Customer's use of a Product (uninstallation), the Product's stored data is removed per the retention policy stated in that Product's Data Security Statement and, for Cloud Products, per Atlassian's own platform-level retention policy for uninstalled apps. The Customer may also request earlier deletion by contacting .
12. Audit rights
The Processor will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice and confidentiality.
13. International transfers
Where a Product processes and stores personal data exclusively within Atlassian's own infrastructure, any international transfer of that data is governed by Atlassian's own data processing terms and transfer mechanisms, referenced in Section 6. Where a Product's Data Security Statement describes a different arrangement, that document controls for that Product.
14. Governing law
This DPA is governed by the laws applicable at the Processor's principal place of residence, consistent with the governing-law clause of the UX Software End-User License Agreement.
15. Contact
Questions about this DPA, or a request under Sections 9 or 11, should go to .