Data Protection Addendum

Last updated: 5 October 2026

Summary

This Data Protection Addendum ("DPA") governs the processing of personal data by DVLS Labs ("Provider") on behalf of customers of Access Review & Audit Trail for Jira ("the App"). It consists of the Bonterms Data Protection Addendum, Version 2.0 — an open, industry-standard DPA — incorporated by reference, together with the DPA Details set out on this page.

1. Incorporation

The Bonterms Data Protection Addendum, Version 2.0 (the "Bonterms DPA"), as published by Bonterms, Inc. at bonterms.com/download-center/data-protection-addendum, is incorporated into the Main Agreement by this reference, unmodified, and applies to the Processing of Customer Personal Data in connection with the App. The DPA Details below complete the Bonterms DPA. Capitalised terms used on this page have the meanings given in the Bonterms DPA.

2. DPA Details

  • Main Agreement: the Standard Agreement of the Atlassian Marketplace entered into between Provider and Customer upon Customer's first order of the App through the Atlassian Marketplace, including any Provider-Specific Terms.
  • Provider (processor): DVLS Labs, Podgorica, Montenegro — support@dvlslabs.com.
  • Customer (controller): the entity that orders the App through the Atlassian Marketplace.
  • Effective date: the date of Customer's first order of the App.

3. Subject matter and details of Processing

  • Nature and purpose: taking point-in-time snapshots of Jira permission metadata, computing differences between snapshots, recording reviewer sign-off decisions, and generating audit evidence (CSV/PDF) — all at Customer's instruction, as described in the App's Privacy Policy.
  • Categories of personal data: Atlassian account IDs, display names and avatar URLs of users who hold Jira permissions, and of reviewers who record sign-off decisions (with timestamps). No special categories of personal data are processed.
  • Data subjects: Customer's Jira users and administrators.
  • Duration: the term of the App's installation. On uninstall, stored data is deleted by Atlassian in accordance with the Forge hosted-storage data lifecycle (permanent deletion after the platform's 28-day retention window).
  • Location of Processing: entirely within Customer's own Atlassian cloud environment, on Atlassian Forge infrastructure. The App declares no egress network permissions and cannot, by design, transmit Customer Personal Data outside Atlassian; this is verified by Atlassian through the "Runs on Atlassian" program. Provider operates no servers and holds no independent copy of Customer Personal Data.

4. Security measures

Technical and organisational measures applicable to the App:

  • All compute and storage runs on the Atlassian Forge platform: AES-256 encryption at rest, TLS 1.2+ in transit, and tenant segregation between installations, under Atlassian's ISO 27001 / ISO 27018 / SOC 2 certified controls.
  • No data egress: the App declares no external network domains (verified by Atlassian's automated checks).
  • No Provider runtime access: for Runs on Atlassian apps the platform provides no path by which Provider personnel could access Customer data.
  • Supply-chain account protection: the Atlassian, GitHub and vendor-mailbox accounts controlling the App's distribution are individually protected with TOTP-based two-factor authentication.
  • Personal data lifecycle: the App implements Atlassian's Personal Data Reporting API — stored account IDs are reported to Atlassian on a weekly schedule, and display names are anonymised when Atlassian signals that an account has been closed.

5. Subprocessors

Provider's Subprocessor List consists of a single entry:

  • Atlassian — operator of the Forge platform hosting the App's runtime and storage, under Customer's existing agreement with Atlassian and Atlassian's own privacy and security commitments.

Provider uses no other subprocessors. Changes to the Subprocessor List will be published on this page with advance notice as provided in the Bonterms DPA.

6. Cross-border transfers (Exhibit A)

Provider does not itself access Customer Personal Data or transfer it outside Customer's Atlassian environment. To the extent any Processing by Provider nevertheless constitutes a restricted transfer under applicable Data Protection Laws, Exhibit A of the Bonterms DPA (Cross-Border Transfer Mechanisms, including the EU Standard Contractual Clauses with the UK and Swiss modifications) applies as set out in the Bonterms DPA. Transfers performed by Atlassian as platform operator are governed by Atlassian's own data processing addendum with Customer.

7. Region-specific terms (Exhibit B)

Exhibit B of the Bonterms DPA (Region-Specific Terms, including the California Consumer Privacy Act service-provider terms) applies.

8. Contact

Questions about this DPA or data protection: support@dvlslabs.com

The Bonterms Data Protection Addendum is © 2026 Bonterms, Inc., used unmodified under CC BY 4.0. Bonterms does not provide legal advice, does not guarantee the enforceability or effect of these terms and has no liability relating to use of these terms.