Data processing addendum / Effective 1 September 2026

Data Processing Addendum.

This Data Processing Addendum (the DPA) supplements the AfterIncident Terms of Use (the Agreement) between the customer that accepts the Agreement (Customer) and Joaquín Orozco García, trading as TechnofyStore, NIF 47905190P, of Carrer Pau Claris 37, 08830 Sant Boi de Llobregat, Barcelona, Spain (Provider). It applies when Provider processes Personal Data on Customer's behalf through AfterIncident for Jira Cloud (the Service).

Provider contact and authorised representative: Joaquín Orozco García, support@callsiq.com.

Electronic acceptance. This DPA is incorporated by reference into the Agreement. A Customer accepts it when an authorised administrator acquires, installs, renews or uses AfterIncident after being given access to the Agreement and this DPA through the Atlassian Marketplace acquisition or installation flow. A mutually executed order or agreement that references this DPA is an additional valid acceptance method.

1. Roles and definitions

Customer is the controller and Provider is the processor for Personal Data processed to provide the Service, except where applicable law assigns a different role. Customer determines the purposes and means of its Jira use and is responsible for its lawful instructions, notices, legal basis, permissions, retention choices and data-subject requests.

“Personal Data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given by the GDPR or other applicable data-protection law. “GDPR” means Regulation (EU) 2016/679. “Customer Data” means data submitted to, accessed by or generated for Customer through the Service.

2. Subject matter and instructions

Provider will process Personal Data only:

  1. to provide, secure, maintain and support AfterIncident as described in the Agreement and Annex 1;
  2. on Customer's documented instructions, including configuration and use of the Service; or
  3. where required by applicable law, after informing Customer unless the law prohibits notice.

Provider will promptly inform Customer if, in Provider's reasonable opinion, an instruction infringes applicable data-protection law. Provider will not sell Customer Personal Data, use it for advertising, train AI models with it, or determine an effectiveness result automatically.

3. Confidentiality and personnel

Provider will ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations and receive access only as necessary for the Service. Access to Customer's Jira content remains governed by Jira permissions and Forge installation boundaries.

4. Security

Taking account of the state of the art, implementation costs, and the nature, scope, context and purposes of processing, Provider will maintain measures appropriate to the risk, including those in Annex 2. The Service uses Atlassian Forge hosted compute and storage and has no separate external application backend. Customer remains responsible for configuring Jira access, issue security, workflows and the information its users enter.

5. Sub-processors

Customer grants general written authorisation for the sub-processors in Annex 3. Provider will impose data-protection obligations appropriate to the processing and remains responsible for each sub-processor's performance of its obligations to Provider.

Provider will give reasonable advance notice of a material new sub-processor where it has a direct choice over that appointment. Customer may object on reasonable data-protection grounds within 30 days. The parties will work in good faith on a commercially reasonable solution; if none is available, either party may terminate the affected Service.

Atlassian selects and manages infrastructure and group sub-processors used by Forge. Their current details and update mechanism are maintained on Atlassian's sub-processor page. Customer acknowledges that the Service necessarily depends on those Atlassian platform providers.

6. Data-subject rights

Taking into account the nature of the processing, Provider will provide reasonable assistance for Customer to respond to requests to exercise data-subject rights. AfterIncident supports identity de-linking and administrator deletion of selected app metadata. Customer administers native Jira issues, comments, attachments, links and permissions, which the app's deletion controls do not delete.

If Provider receives a request relating to Customer Personal Data, Provider will direct the requester to Customer where legally permitted and will not independently respond on Customer's behalf unless authorised or required by law.

7. Assistance and breach notification

Taking into account the nature of processing and information available to Provider, Provider will reasonably assist Customer with security, breach-notification, data-protection impact assessment and supervisory-authority consultation obligations applicable to the Service.

Provider will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data and will provide information reasonably available to help Customer meet its obligations. Notification is not an admission of fault or liability. Customer's contact for notices is the current billing or technical contact associated with its Marketplace acquisition; Provider's contact is support@callsiq.com.

8. Deletion and return

During the subscription, Customer may use the Service's available controls to erase identity mappings and delete selected action metadata. On termination or uninstall, access ends and Forge-hosted storage follows Atlassian's hosted-storage lifecycle. Forge currently retains hosted app data for 28 days after uninstall; reinstall does not automatically restore it. Provider cannot shorten or bypass Atlassian's platform retention or backup deletion schedule.

At Customer's written request before termination, Provider will provide reasonable assistance with available data retrieval. After the applicable retention period, Personal Data will be deleted or rendered inaccessible unless applicable law requires retention. Native Jira records remain under Customer's control.

9. Audits and information

Provider will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant Service documentation and available Atlassian/Forge security materials. No more than once annually, unless required by a supervisory authority or following a material incident, Customer may request a reasonable audit. Audits must use an independent auditor, protect confidential information, avoid access to other customers' data and minimise disruption. Customer bears its costs unless the audit identifies Provider's material breach.

Provider does not claim an independent certification, penetration test or Marketplace Security Bug Bounty participation for AfterIncident unless the Marketplace listing is later updated with verified evidence.

10. International transfers

Provider will not independently transfer Customer Personal Data outside the Atlassian services used by the Service. Hosting, support and transfers performed by Atlassian for Forge are governed by Atlassian's applicable Forge data-processing terms, transfer mechanisms, data-residency capabilities and sub-processor commitments.

If Provider later introduces processing that requires its own restricted transfer, the parties will use a valid transfer mechanism required by applicable law, including applicable Standard Contractual Clauses, and complete any required annexes before that processing begins.

11. Liability, precedence and duration

This DPA forms part of the Agreement. If there is a conflict concerning processing of Personal Data, this DPA prevails. The Agreement's liability limitations apply to this DPA to the maximum extent permitted by law. This DPA remains effective while Provider processes Customer Personal Data and for as long afterward as its obligations apply.

Annex 1 — Processing details

ItemDescription
Subject matterCorrective-action governance, implementation evidence, scheduled effectiveness reviews, recurrence candidates, dashboards, configuration and auditability inside Jira Cloud.
DurationSubscription or use period plus deletion and backup retention governed by the Agreement and Forge lifecycle.
Nature and purposeRead required Jira fields; create and link native Jira action issues; persist workflow metadata; verify evidence references; schedule and record human reviews; propose deterministic recurrence candidates; display permission-filtered records; support audit, privacy reporting and deletion.
Data subjectsCustomer's Jira users, project administrators, incident and action participants, assignees, reviewers and people mentioned in user-supplied free text.
Personal DataAtlassian account IDs and opaque actor references; Jira project, issue and workflow identifiers or keys; summaries, assignee display information and due dates read for display; evidence notes, URLs and Jira comment or attachment references; review rationales and results; recurrence issue references; audit events; project configuration; support correspondence submitted separately by Customer.
Sensitive dataNot intentionally required. Customer must not enter credentials, secrets, special-category data or other sensitive material unless authorised, necessary and appropriately protected.
FrequencyContinuous or event-driven while installed, plus an hourly scheduler and asynchronous workers where configured and licensed.

Annex 2 — Technical and organisational measures

Annex 3 — Sub-processors

Sub-processorLocation / serviceProcessing
Atlassian and the Atlassian group and sub-processors listed on Atlassian's sub-processor pageLocations and entities identified by Atlassian; Forge and Jira data residency applies where supported.Jira Cloud and Forge hosting, storage, compute, platform security, support and related infrastructure necessary to deliver the Service.

The public documentation website is separately hosted on Cloudflare. It receives no Jira or Forge app data. Ordinary web delivery necessarily processes connection metadata such as IP address; that independent website processing is described in the AfterIncident Privacy Notice and is not used to provide the in-product processing described in this Annex.