Data Processing Agreement
Last updated: September 29, 2026
Between
[Customer legal name], [address] ("Controller")
and
Helkrypt AI AS, org. no. 936 351 034, Postboks 14, 4756 Hovden i Setesdal, Norway ("Processor")
1. Subject matter and duration
The Processor provides the Atlassian Marketplace app(s) listed in Annex 1 to the Controller. This agreement applies for as long as the Controller has the app installed, and ends automatically when the app is uninstalled from all of the Controller's Atlassian sites.
2. Nature and purpose of processing
The app runs on Atlassian's Forge platform inside the Controller's Atlassian site. It processes data only to provide the app's features, as described in Annex 1.
3. Types of personal data and data subjects
See Annex 1.
4. Instructions
The Processor processes personal data only on the Controller's documented instructions. The Controller's configuration and use of the app are its instructions. If EU or EEA law requires other processing, the Processor will inform the Controller first, unless the law forbids it.
5. Confidentiality
Everyone at the Processor who can access personal data is bound by confidentiality.
6. Security
The Processor takes the measures required by GDPR art. 32. They are listed in Annex 2.
7. Sub-processors
The Controller gives general authorisation to use the sub-processors in Annex 3. The Processor will give at least 30 days' notice before adding or replacing a sub-processor, by email to the Controller's technical contact on the Atlassian Marketplace. The Controller can object within that period. If the parties can't agree, the Controller can uninstall the app, and the Processor will refund any prepaid fees for the remaining period. The Processor imposes the same data protection obligations on its sub-processors and remains responsible for them.
8. Assistance
The Processor helps the Controller, as far as possible given the nature of the processing, to:
- answer requests from data subjects (GDPR art. 15–22)
- meet its obligations on security, personal data breaches, data protection impact assessments and prior consultation (GDPR art. 32–36)
9. Personal data breaches
The Processor notifies the Controller without undue delay, and no later than 48 hours after becoming aware of a personal data breach that affects the Controller's data. The notice includes what the Processor knows at that time.
10. Deletion
When the app is uninstalled, the app data in Forge hosted storage is deleted by Atlassian according to the Forge hosted storage lifecycle. The Processor keeps no copies outside Atlassian. For Epic Rollup for Jira, the epic totals stored on epics (numbers only) are not removed by uninstalling. To remove them, an administrator turns off searchable totals and lets the background job finish before uninstalling.
11. Audits
The Processor makes available all information needed to show compliance with this agreement, and allows for and contributes to audits by the Controller or an auditor it chooses, with reasonable notice. The Controller covers its own audit costs.
12. International transfers
The app sends no personal data outside Atlassian. Any transfer by Atlassian is covered by Atlassian's own data processing terms with the Controller.
13. Governing law
Norwegian law. Disputes go to Oslo District Court (Oslo tingrett).
Annex 1 – Processing details
| Auto Issue & Description Templates for Jira | Epic Rollup for Jira | Smart Defaults for Jira | Comment & Reply Templates for Jira | |
|---|---|---|---|---|
| Purpose | Add description templates to Jira work items | Show progress totals (story points, time, percent done) for Jira epics | Fill empty system fields (priority, labels, components, due date) on new Jira work items with default values set by an administrator | Let Jira users post reusable comment and reply templates, written by an administrator, as their own comments |
| Data stored by the app | Template names and text, selected project and work type IDs, default flag, last-updated time | Admin settings (story points field per project, feature switches). Epic totals as a property on each epic: counts, story points, logged and remaining time, percent done, last-updated time. Numbers and a date only, no issue keys, titles or names. | Rules: name, project and work type IDs, priority and component IDs, labels, number of days until the due date | Templates: name, text, project and work type IDs, default visibility in service projects |
| Personal data | None stored by the app. Templates may contain personal data if an administrator writes it. The app reads reporter and assignee display names to fill in variables, and does not store them. | None stored by the app. The app reads child issues (key, summary, status, story points, time fields, parent, team) to calculate totals, and does not store them. If an administrator turns on the optional "time logged per person" setting (off by default), the app reads worklog authors and logged time in the viewer's browser to show them on the epic. This is never stored. | None stored by the app. The app reads the new work item's project, work type, priority, labels, components and due date to see which fields are empty, and does not store them. It reads no user fields. | None stored by the app. The app reads the work item's key, summary, project, work type, reporter and assignee in the user's browser to fill in template variables, and does not store them. The posted comment is stored by Jira, not by the app. |
| Data subjects | The Controller's Jira users | The Controller's Jira users | The Controller's Jira users (only indirectly: work items they create get default field values) | The Controller's Jira users and, in service projects, the Controller's customers (only indirectly: their names can be filled into a comment the user posts) |
| Where | Atlassian Forge hosted storage, in the same region as the Controller's Jira site | Admin settings: Atlassian Forge hosted storage, in the same region as the Controller's Jira site. Epic totals: a property on the epic in the Controller's Jira site. | Atlassian Forge hosted storage, in the same region as the Controller's Jira site | Atlassian Forge hosted storage, in the same region as the Controller's Jira site |
| Retention | Until an administrator deletes the template, or until the app is uninstalled | Admin settings: until the app is uninstalled. Epic totals: until an administrator turns off searchable totals (a background job then removes them from every epic), or until the epic is deleted. Uninstalling does not remove them. | Until an administrator deletes the rule, or the app is uninstalled | Until an administrator deletes the template, or the app is uninstalled |
Annex 2 – Security measures
All apps
- The app runs only on Atlassian's Forge platform ("Runs on Atlassian"). There are no Helkrypt servers.
- No egress: the app sends no data outside Atlassian.
- Helkrypt's developer accounts use two-step verification.
- Atlassian's security measures for Forge apply to hosting and storage.
Auto Issue & Description Templates for Jira
- Minimal permissions:
read:jira-work,write:jira-work,storage:app. - Only Jira administrators can create, change or delete templates. This is checked on every request.
- Logs contain only work item keys, template IDs and status codes. Never content or names.
Epic Rollup for Jira
- Minimal permissions:
read:jira-work,write:jira-work,storage:app,read:board-scope:jira-software,read:project:jira,read:epic:jira-software. - Only Jira administrators can change settings. This is checked on every request.
- "Time logged per person" is off by default and is calculated in the viewer's browser. It is never stored, and is not shown on the dashboard gadget or in JQL.
- Logs contain only work item IDs, event types, counts and status codes. Never content or names.
Annex 3 – Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Atlassian (Forge platform) | Hosting, storage, logs | Same region as the Controller's Atlassian site |
Signed for the Controller: ______________________ Date: __________
Signed for Helkrypt AI AS: ______________________ Date: __________