Fulfilra
Data Processing Agreement
The DPA for Fulfilra, with processing details, security measures, sub-processors and restricted-transfer terms set out in its annexes.
This Data Processing Agreement (“DPA”) is incorporated into and forms part of the End User Terms for Fulfilra between ITSM Ltd and the customer identified in the applicable Atlassian Marketplace order. It takes effect automatically on installation of the App and requires no signature, but we will countersign a copy on request to support@itsm-ltd.com.
A note on scope before you read further. The App runs entirely on Atlassian Forge and stores all customer data inside Atlassian’s infrastructure. It declares no external egress domains and does not transmit customer data to us. In practical terms, the personal data that reaches our own systems is limited to support correspondence and licence records. This DPA is nonetheless a full Article 28 agreement, because we still determine how the App processes personal data on your behalf.
1. Definitions
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” have the meanings given in the UK GDPR.
“Customer Personal Data” means Personal Data contained within Your Data (as defined in the End User Terms) that we Process on your behalf under this DPA. “Data Protection Laws” means all laws applicable to the Processing of Personal Data under this DPA, including the UK GDPR, the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), the EU GDPR where applicable, and the Privacy and Electronic Communications Regulations 2003. “Restricted Transfer” means a transfer of Personal Data to a country not covered by UK or EU adequacy regulations, where such transfer requires a lawful transfer mechanism. “Standard Contractual Clauses” or “SCCs” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914. “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner under section 119A of the Data Protection Act 2018. “UK GDPR” has the meaning given in section 3(10) of the Data Protection Act 2018. “Sub-processor” means any third party engaged by us to Process Customer Personal Data.
“App”, “Atlassian”, “Your Data” and “Subscription Term” have the meanings given in the End User Terms, as do all other capitalised terms not defined here. In the event of conflict between this DPA and the End User Terms in respect of the Processing of Personal Data, this DPA prevails.
2. Roles of the parties
2.1 In respect of Customer Personal Data, you are the Controller and we are the Processor. Where you are yourself a Processor acting for a third-party Controller, we act as a Sub-processor and you warrant that you have the authority of that Controller to enter into this DPA.
2.2 Atlassian’s position in the chain. Because the App is hosted on Atlassian Forge, Atlassian acts as our Sub-processor for the hosting, compute and storage on which the App depends. Atlassian may separately act as your own Processor under your direct agreement with Atlassian for the underlying Jira product. Those two relationships are distinct: this DPA governs only our Processing, and nothing in it varies your agreement with Atlassian.
2.3 We act as an independent Controller in respect of support correspondence, licence and billing records, and business contact data, as described in section 4 of the Privacy Policy. This DPA does not apply to that Processing, which is governed by the Privacy Policy and by Data Protection Laws directly.
2.4 Each party is independently responsible for its own compliance with Data Protection Laws applicable to it in its own role.
3. Scope and duration of Processing
3.1 The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are set out in Annex 1.
3.2 This DPA applies for as long as we Process Customer Personal Data on your behalf, and survives termination of the End User Terms to the extent any such Processing continues.
4. Processing on documented instructions
4.1 We will Process Customer Personal Data only on your documented instructions, including in relation to Restricted Transfers, unless required to do otherwise by law to which we are subject. Where such a legal requirement applies, we will inform you before Processing unless the law prohibits it on important grounds of public interest.
4.2 Your instructions comprise: the End User Terms; this DPA; the configuration choices you and your users make within the App; the operations the App performs in response to actions taken by your users; and any further written instructions you give us that we accept in writing.
4.3 We will inform you if, in our opinion, an instruction infringes Data Protection Laws. We may suspend the affected Processing until the instruction is confirmed, withdrawn or amended.
4.4 We will not sell Customer Personal Data, and will not use it for our own purposes, for developing or training any machine learning or artificial intelligence model, for advertising, or for profiling.
4.5 You warrant that you have a lawful basis for the Processing you instruct, have provided any notices and obtained any consents required, and that your instructions comply with Data Protection Laws. You are responsible for the accuracy and legality of Customer Personal Data and for the content your users place in your Atlassian site.
5. Confidentiality
We ensure that every person authorised to Process Customer Personal Data is bound by a written obligation of confidentiality or an appropriate statutory duty, that access is granted on a need-to-know and least-privilege basis, and that such persons receive appropriate data protection and security awareness training.
6. Security
6.1 We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 UK GDPR. Those measures are described in Annex 2 and, in more detail, in the Cloud Security Statement at https://fulfilra.itsm-ltd.com/legal/cloud-security-statement.
6.2 You acknowledge that the security of Customer Personal Data stored by the App depends substantially on controls operated by Atlassian, and that Annex 2 accordingly distinguishes platform-provided measures from measures we implement ourselves.
6.3 We may update the measures in Annex 2 provided the updated measures do not materially reduce the overall level of security.
6.4 You are responsible for the security decisions within your control, including administering user access to your Atlassian site and the App, configuring App permissions appropriately, and deciding what data your users place in the App.
7. Sub-processors
7.1 General authorisation. You give us general written authorisation to engage Sub-processors, subject to this section. The Sub-processors authorised at the effective date are listed in Annex 3.
7.2 Notice of change. We will give you at least 30 days’ notice of any intended addition or replacement of a Sub-processor, by updating Annex 3 and the sub-processor tables in the Privacy Policy and Cloud Security Statement, and by email to the technical contact on your licence.
7.3 Objection. You may object on reasonable data protection grounds within the notice period by emailing support@itsm-ltd.com. We will work with you in good faith to address the objection. If we cannot do so within 30 days, you may terminate the affected subscription by written notice and request a pro-rata refund from Atlassian for the unused portion of the Subscription Term.
7.4 Objection to Atlassian. Atlassian is a Sub-processor that cannot be replaced or removed: the App exists only on the Atlassian platform. If you object to Atlassian as a Sub-processor, your only remedy is to terminate under clause 7.3.
7.5 Terms and liability. We impose on each Sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for the acts and omissions of our Sub-processors as if they were our own.
8. International transfers
8.1 Customer Personal Data stored by the App resides in its Forge SQL database, hosted by Atlassian, and inherits the data residency configuration of your Atlassian product. Where you have pinned your product data to a UK or EEA region, in-scope App data is pinned to the same region.
8.2 Where a Restricted Transfer occurs, the parties agree that the mechanism set out in Annex 4 applies, and that Annex 4 is incorporated into this DPA.
8.3 We will not make a Restricted Transfer of Customer Personal Data except in accordance with Annex 4 or another lawful transfer mechanism.
8.4 Each party will provide reasonable assistance to the other in carrying out any transfer risk assessment required by Data Protection Laws.
9. Assistance with Data Subject rights
9.1 Taking into account the nature of the Processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise Data Subject rights under Chapter III UK GDPR.
9.2 The practical position — stated candidly. Customer Personal Data resides in your own Atlassian site, and how a Data Subject request is executed depends on where the data sits:
- (a) Personal data inside Jira issues the App created or links to is located, rectified and erased using Jira’s own tools, without our involvement.
- (b) The App itself does not currently provide per-record deletion or export of its stored records (requests, form answers, approvals, comments, status history, notifications). Free-text content in an open request can be corrected by your users through the App’s screens; a stored record cannot be individually deleted by you.
- (c) Erasure of App-stored records is achieved either by uninstalling the App, which deletes the installation’s entire database under clause 12.1, or by vendor-assisted remediation: contact support@itsm-ltd.com, and where a specific record must be located, amended or erased we will deliver the remediation as an App update, since we have no direct access to your data.
- (d) We will acknowledge and assist with any such request within the timescales in this section 9.
9.3 If we receive a request directly from a Data Subject relating to Customer Personal Data, we will not respond to it substantively. We will acknowledge receipt, direct the individual to you, and notify you within 5 business days.
9.4 Assistance under this section is provided at no charge unless a request is manifestly unfounded, excessive or repetitive, or requires bespoke engineering effort, in which case we may charge our reasonable costs, notified to you in advance.
10. Personal Data Breach
10.1 We will notify you of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 72 hours of becoming aware of it.
10.2 The notification will include, to the extent known at the time: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information is not all available at once, we will provide it in phases without undue delay.
10.3 We will take reasonable steps to contain, investigate and mitigate the breach, and will preserve relevant evidence.
10.4 We will assist you in meeting your own obligations to notify the Information Commissioner’s Office or other Supervisory Authority and, where required, affected Data Subjects.
10.5 We will not notify any Supervisory Authority or Data Subject about a breach affecting Customer Personal Data on your behalf, or name you publicly in connection with it, unless you instruct us to or we are legally required to.
10.6 We will separately notify Atlassian of security incidents affecting the App within 48 hours, as required by the Atlassian Marketplace Partner Agreement. That notification does not discharge our obligation to you under clause 10.1.
11. Data protection impact assessments
Taking into account the nature of the Processing and the information available to us, we will provide reasonable assistance with any data protection impact assessment or prior consultation with a Supervisory Authority under Articles 35 and 36 UK GDPR. We maintain a standard information pack for this purpose, comprising this DPA, the Cloud Security Statement and the App’s scope justifications; that pack will normally be sufficient, and is available from support@itsm-ltd.com.
12. Deletion and return of data
12.1 On uninstallation of the App, Forge app data is deleted by Atlassian in accordance with its platform deletion processes. We hold no independent copy of Customer Personal Data and are therefore unable to return or restore it.
12.2 The App does not currently provide an export facility. Where a request created a Jira issue, that issue and its content remain in your Jira project after uninstallation. Any App records you need beyond uninstallation should be captured from the App’s screens before you uninstall; contact support@itsm-ltd.com before uninstalling and we will advise what is possible.
12.3 Support correspondence and licence records that we hold as Controller are retained and deleted in accordance with the retention table in section 10 of the Privacy Policy.
12.4 We may retain Customer Personal Data to the extent required by law, in which case we will continue to protect it in accordance with this DPA and Process it only for the purpose requiring retention.
12.5 Status values the App publishes onto Jira issue entity properties are Customer data held in your own Atlassian site, not App data held in Forge storage. They are a closed set of status values, dates and counts and contain no Customer Personal Data. We neither hold nor control them, and we do not return or delete them on termination: clause 7.5 of the End User Terms and section 3.6 of the Cloud Security Statement explain how to remove them yourself.
13. Audit and information
13.1 We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR.
13.2 How we satisfy audit rights in practice. In recognition of the fact that we operate no infrastructure and hold no Customer Personal Data outside Atlassian, audit rights are exercised as follows:
- First, by reference to the Cloud Security Statement, this DPA and the App’s published scope justifications.
- Second, by reference to Atlassian’s independent certifications and audit reports covering the infrastructure on which the App runs, which you may obtain directly from Atlassian. We cannot supply Atlassian’s audit reports on Atlassian’s behalf.
- Third, by written questionnaire to support@itsm-ltd.com, which we will answer within 5 business days, no more than once in any 12-month period unless a Personal Data Breach has occurred or a Supervisory Authority requires otherwise.
13.3 On-site or remote inspection. Where the steps in clause 13.2 are demonstrably insufficient to meet a requirement of Data Protection Laws or of a Supervisory Authority, you may conduct an inspection subject to: 30 days’ written notice; conduct during our normal business hours; no more than once in any 12-month period unless a Personal Data Breach has occurred; execution of a confidentiality agreement by you and any auditor; no access to other customers’ data or to our other confidential information; and use of an independent auditor who is not our competitor. You bear your own costs and will reimburse our reasonable costs of supporting an inspection beyond one business day.
13.4 We do not hold, and are not certified under, SOC 2, ISO/IEC 27001 or comparable standards. Section 9 of the Cloud Security Statement explains this and identifies which certifications belong to Atlassian.
14. Liability
14.1 The limitations and exclusions of liability in clause 11 of the End User Terms apply to this DPA, and each party’s total aggregate liability arising out of or in connection with this DPA and the End User Terms together is subject to a single cap as set out in that clause.
14.2 Clause 14.1 does not limit either party’s liability to a Data Subject, or to a Supervisory Authority, or any liability that cannot lawfully be limited under Data Protection Laws.
14.3 Nothing in this DPA affects Article 82 UK GDPR (right to compensation) or Article 83 (administrative fines) as between a party and a Supervisory Authority or Data Subject.
15. California Consumer Privacy Act
Where we Process personal information of California residents on your behalf, we act as a “service provider” as defined by the CCPA as amended by the CPRA. We: Process such personal information only to perform the services under the End User Terms; do not sell or share it; do not retain, use or disclose it for any purpose other than performing the services or as otherwise permitted by the CCPA; do not combine it with personal information from other sources except as permitted; and certify that we understand and will comply with these restrictions. You may take reasonable steps under this DPA to ensure our use is consistent with your CCPA obligations.
16. General
16.1 Changes. We may amend this DPA where required by a change in Data Protection Laws, by a Supervisory Authority, or by a change in our Processing. Where an amendment materially reduces your rights, we will give at least 30 days’ notice to the technical contact on your licence, and it will not apply retrospectively or reduce our obligations during your then-current Subscription Term.
16.2 Governing law. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, save where a transfer mechanism in Annex 4 requires otherwise for the Processing to which it applies.
16.3 General provisions. Clauses 13.1 to 13.9 of the End User Terms (assignment, notices, force majeure, third-party rights, severance, waiver, export and sanctions) apply to this DPA as if set out here.
16.4 Order of precedence. Where this DPA conflicts with a transfer mechanism in Annex 4, that mechanism prevails in respect of the transfers it governs.
Annex 1 — Details of the Processing
| Subject matter | Provision of Fulfilra to the Customer through the Atlassian Marketplace |
| Duration | For the duration of the Subscription Term and until the App is uninstalled, plus any period of legally required retention |
| Nature of Processing | Collection, recording, organisation, structuring, storage, retrieval, consultation, use, alteration and erasure of Customer Personal Data within the App’s Atlassian-hosted Forge SQL database and the Customer’s Atlassian products, by automated means |
| Purpose | Delivering the documented functionality of the App on the Customer’s instructions, and providing support |
| Frequency | Continuous, in response to user actions and scheduled App operations |
Categories of Data Subjects
- The Customer’s employees, contractors and other authorised users of its Atlassian site
- Any individual whose personal data the Customer’s users enter into content within the Customer’s Atlassian site that the App reads, writes or stores — which may include the Customer’s own customers, suppliers, partners or applicants
- The Customer’s administrators and technical contacts
Types of Personal Data
- Atlassian account identifiers (AAIDs). The App stores no email addresses and no user profile records; display names and avatars are resolved from Jira at the point of display and not retained, with the one exception noted below
- Content within Jira issues and comments that the App reads or writes, insofar as that content contains personal data — the Customer determines what this includes
- Service request records: reference, summary, status, and the requester’s and assignee’s account IDs
- Form answers entered by requesters against the Customer’s configured catalog fields — free text whose content the Customer determines. The App’s shipped template library includes request types whose forms may invite personal data; templates concerning occupational health are flagged in-product as involving UK GDPR special category data, with data-minimisation guidance
- Approval steps and decisions: the approver’s account ID, the decision, its timestamp and any free-text decision note
- Comments: the author’s account ID, the comment body and an internal/requester-facing flag; comments mirrored from public comments on a linked Jira issue additionally store the Jira commenter’s display name as a caption
- Request status history: the acting user’s account ID, timestamps and any free-text note
- App roles: the account IDs of users named as agents or approvers, and of the administrator who granted the role
- In-app notifications: the recipient’s account ID, a title and a body that may quote a note
- Jira issue links: the issue key and URL and the account ID of the linking user
Special category or criminal offence data
None is required by the App. The App does not solicit special category data. If the Customer’s users enter special category or criminal offence data into content that the App Processes, the Customer remains the Controller and is responsible for identifying an Article 9 or Article 10 condition and for notifying us in advance so that we can assess whether additional measures are required.
Location of Processing
The App’s Forge SQL database, hosted by Atlassian, in the region determined by the Customer’s Atlassian data residency configuration.
Annex 2 — Technical and organisational measures
This Annex is the authoritative statement of our technical and organisational measures for the purposes of Article 32 UK GDPR and Annex II of the Standard Contractual Clauses. The Cloud Security Statement at https://fulfilra.itsm-ltd.com/legal/cloud-security-statement is a narrative expansion of the same measures for security reviewers; where the two differ, this Annex governs.
Measures marked Atlassian (Forge platform) are provided by Atlassian as part of the Forge platform. Measures marked ITSM Ltd are implemented by us. The split is deliberate: it records which measures we actually operate.
| Area | Measures |
|---|---|
| Pseudonymisation and encryption | Encryption at rest for the App’s Forge SQL database Atlassian (Forge platform). TLS 1.2 or above in transit Atlassian (Forge platform). The App holds no credentials, tokens or secrets of its own; it authenticates to Jira solely through Forge-managed app identity ITSM Ltd. Use of opaque Atlassian account identifiers rather than directly identifying data wherever the App’s function permits — no email addresses or profile records are stored ITSM Ltd |
| Confidentiality | Tenant isolation is structural: one Forge SQL database per installation, so no other customer’s data is present Atlassian (Forge platform). No external egress declared in the App manifest, so Customer Personal Data cannot be transmitted outside Atlassian’s infrastructure; the manifest is regression-tested for this on every build ITSM Ltd. Least-privilege OAuth scopes (four); the site-administrator check runs as the acting user on every invocation, and per-user visibility within an installation is enforced in the App’s query logic and covered by an automated test sweep ITSM Ltd. Written confidentiality obligations and security awareness training for all personnel ITSM Ltd |
| Integrity | Input validation and output encoding ITSM Ltd. Peer review and branch protection before release ITSM Ltd. Separation of development, staging and production Forge environments ITSM Ltd |
| Availability and resilience | Platform compute, storage and disaster recovery operated by Atlassian Atlassian (Forge platform). Backup of persistent storage for platform disaster recovery Atlassian (Forge platform). Replicated source control and documented release procedures ITSM Ltd. No independent backup of Customer Personal Data is held by us |
| Restoration of availability | Restoration is a function of Atlassian’s platform disaster recovery Atlassian (Forge platform). We offer no separate RTO or RPO |
| Testing and evaluation | Participation in Atlassian Ecoscanner and Atlassian’s app and partner security review Atlassian (Forge platform) / ITSM Ltd. Automated dependency vulnerability scanning and secret scanning in the build pipeline ITSM Ltd. Annual review of this DPA and the Cloud Security Statement ITSM Ltd |
| Access control | Access to source control, the Atlassian developer console and the support inbox restricted to named personnel, protected by multi-factor authentication, reviewed quarterly and revoked on the day a person leaves ITSM Ltd. No administrative back door, support console or data export facility grants us access to Customer Personal Data ITSM Ltd |
| Logging | Platform operational logs produced and retained by Atlassian Atlassian (Forge platform). The App is designed not to write personal data into application logs ITSM Ltd |
| Vulnerability management | Remediation of confirmed vulnerabilities to Atlassian’s cloud-app timeframes: Critical 10 days, High 4 weeks, Medium 12 weeks, Low 25 weeks ITSM Ltd. Automatic propagation of minor and patch releases across all installations Atlassian (Forge platform) |
| Incident management | Documented incident procedure; notification to the Customer within 72 hours and to Atlassian within 48 hours ITSM Ltd |
| Data minimisation | The App requests only the scopes required for its documented function and stores only the configuration and operational records necessary to deliver it ITSM Ltd |
Annex 3 — Authorised Sub-processors
| Sub-processor | Entity and location | Purpose | Data Processed |
|---|---|---|---|
| Atlassian | Atlassian Pty Ltd (Australia) / Atlassian Corporation (USA); Processing in the region determined by the Customer’s data residency configuration | Hosting, compute and storage for the App; Marketplace licensing and billing; Jira Service Management, our support tool | All Customer Personal Data Processed by the App; and support correspondence held in ITSM Ltd’s Jira Service Management |
| Google Workspace | Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland | Delivery and storage of support email | Support correspondence only — not Customer Personal Data held by the App |
ITSM Ltd keeps support records in Atlassian’s Jira Service Management, so Atlassian, listed above, is the provider that holds them. This Annex is kept in step with the sub-processor tables in section 8 of the Privacy Policy and section 10 of the Cloud Security Statement. Changes are notified under clause 7.2.
Annex 4 — Restricted Transfers
A. Transfers subject to UK Data Protection Laws
Where a Restricted Transfer is subject to the UK GDPR, the parties adopt the EU Standard Contractual Clauses as modified by the UK International Data Transfer Addendum (version B1.0, in force 21 March 2022), completed as follows:
| Item | Completion |
|---|---|
| Addendum Part 1, Table 1 (Parties) | Exporter: the Customer. Importer: ITSM Ltd. Contact details as recorded in the End User Terms and clause 1 of the Privacy Policy |
| Addendum Part 1, Table 2 (Selected SCCs) | Module Two (Controller to Processor), or Module Three (Processor to Processor) where the Customer is itself a Processor |
| Addendum Part 1, Table 3 (Appendix Information) | Annex I(A) and I(B): as set out in Annex 1 of this DPA. Annex II: as set out in Annex 2 of this DPA. Annex III: as set out in Annex 3 of this DPA |
| Addendum Part 1, Table 4 (Ending the Addendum) | Neither party may end the Addendum when the Approved Addendum changes |
| SCC optional clause 7 (docking) | Applies |
| SCC clause 9 (sub-processors) | Option 2, general written authorisation, with the notice period in clause 7.2 of this DPA |
| SCC clause 11 (redress) | The optional independent dispute resolution wording does not apply |
| SCC clause 17 (governing law) | The laws of England and Wales |
| SCC clause 18 (forum) | The courts of England and Wales |
| Competent Supervisory Authority | The Information Commissioner’s Office |
B. Transfers subject to EU Data Protection Laws
Where a Restricted Transfer is subject to the EU GDPR, the parties adopt the Standard Contractual Clauses (Implementing Decision (EU) 2021/914), with the same module selection and optional-clause elections as in Part A, save that: the governing law is the law of Ireland; the forum is the courts of Ireland; and the competent Supervisory Authority is determined in accordance with clause 13 of the SCCs.
C. Transfers subject to Swiss Data Protection Law
Where a Restricted Transfer is subject to the Swiss Federal Act on Data Protection, the SCCs apply with the amendments set out in the Swiss Federal Data Protection and Information Commissioner’s guidance, and references to Supervisory Authorities include the FDPIC.
D. Order of precedence and alternative mechanisms
Where the SCCs or the UK Addendum conflict with any other provision of this DPA or the End User Terms, the SCCs or Addendum prevail in respect of the transfers they govern. If a mechanism adopted here is invalidated, replaced or superseded, the parties will in good faith adopt the successor mechanism or an alternative lawful transfer mechanism without undue delay.
E. Practical note
Where the Customer has configured Atlassian data residency to a UK or EEA region, Customer Personal Data held by the App remains in that region and no Restricted Transfer of App data arises in the ordinary course. Restricted Transfers are most likely to concern support correspondence and licence records. ITSM Ltd keeps support records in Atlassian’s Jira Service Management on its own Atlassian site. Atlassian Corporation is US-incorporated and Atlassian Pty Ltd is Australian, so Part A of this Annex applies to transfers of that data.
Published in accordance with the Atlassian Marketplace Partner Agreement. Read alongside the Privacy Policy, End User Terms, Cloud Security Statement and Support and Maintenance Description for Fulfilra.