Service Transition & Readiness
Effective date: 1st September 2026 Last reviewed: 1st September 2026 Version: 1.0
This Data Processing Agreement (“DPA”) is incorporated into and forms part of the End User Terms for Service Transition & Readiness between ITSM Ltd and the customer identified in the applicable Atlassian Marketplace order. It takes effect automatically on installation of the App and requires no signature, but we will countersign a copy on request to support@itsm-ltd.com.
A note on scope before you read further. The App runs entirely on Atlassian Forge and stores all customer data inside Atlassian’s infrastructure. It declares no external egress domains and does not transmit customer data to us. In practical terms, the personal data that reaches our own systems is limited to support correspondence and licence records. This DPA is nonetheless a full Article 28 agreement, because we still determine how the App processes personal data on your behalf.
1. Definitions
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” have the meanings given in the UK GDPR.
“Customer Personal Data” means Personal Data contained within Your Data (as defined in the End User Terms) that we Process on your behalf under this DPA. “Data Protection Laws” means all laws applicable to the Processing of Personal Data under this DPA, including the UK GDPR, the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), the EU GDPR where applicable, and the Privacy and Electronic Communications Regulations 2003. “Restricted Transfer” means a transfer of Personal Data to a country not covered by UK or EU adequacy regulations, where such transfer requires a lawful transfer mechanism. “Standard Contractual Clauses” or “SCCs” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914. “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner under section 119A of the Data Protection Act 2018. “UK GDPR” has the meaning given in section 3(10) of the Data Protection Act 2018. “Sub-processor” means any third party engaged by us to Process Customer Personal Data.
“App”, “Atlassian”, “Your Data” and “Subscription Term” have the meanings given in the End User Terms, as do all other capitalised terms not defined here. In the event of conflict between this DPA and the End User Terms in respect of the Processing of Personal Data, this DPA prevails.
2. Roles of the parties
2.1 In respect of Customer Personal Data, you are the Controller and we are the Processor. Where you are yourself a Processor acting for a third-party Controller, we act as a Sub-processor and you warrant that you have the authority of that Controller to enter into this DPA.
2.2 Atlassian’s position in the chain. Because the App is hosted on Atlassian Forge, Atlassian acts as our Sub-processor for the hosting, compute and storage on which the App depends. Atlassian may separately act as your own Processor under your direct agreement with Atlassian for the underlying Jira, Confluence or other Atlassian product. Those two relationships are distinct: this DPA governs only our Processing, and nothing in it varies your agreement with Atlassian.
2.3 We act as an independent Controller in respect of support correspondence, licence and billing records, and business contact data, as described in section 4 of the Privacy Policy. This DPA does not apply to that Processing, which is governed by the Privacy Policy and by Data Protection Laws directly.
2.4 Each party is independently responsible for its own compliance with Data Protection Laws applicable to it in its own role.
3. Scope and duration of Processing
3.1 The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are set out in Annex 1.
3.2 This DPA applies for as long as we Process Customer Personal Data on your behalf, and survives termination of the End User Terms to the extent any such Processing continues.
4. Processing on documented instructions
4.1 We will Process Customer Personal Data only on your documented instructions, including in relation to Restricted Transfers, unless required to do otherwise by law to which we are subject. Where such a legal requirement applies, we will inform you before Processing unless the law prohibits it on important grounds of public interest.
4.2 Your instructions comprise: the End User Terms; this DPA; the configuration choices you and your users make within the App; the operations the App performs in response to actions taken by your users; and any further written instructions you give us that we accept in writing.
4.3 We will inform you if, in our opinion, an instruction infringes Data Protection Laws. We may suspend the affected Processing until the instruction is confirmed, withdrawn or amended.
4.4 We will not sell Customer Personal Data, and will not use it for our own purposes, for developing or training any machine learning or artificial intelligence model, for advertising, or for profiling.
4.5 You warrant that you have a lawful basis for the Processing you instruct, have provided any notices and obtained any consents required, and that your instructions comply with Data Protection Laws. You are responsible for the accuracy and legality of Customer Personal Data and for the content your users place in your Atlassian site.
5. Confidentiality
We ensure that every person authorised to Process Customer Personal Data is bound by a written obligation of confidentiality or an appropriate statutory duty, that access is granted on a need-to-know and least-privilege basis, and that such persons receive appropriate data protection and security awareness training.
6. Security
6.1 We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 UK GDPR. Those measures are described in Annex 2 and, in more detail, in the Cloud Security Statement at https://str.itsm-ltd.com/legal/cloud-security-statement.
6.2 You acknowledge that the security of Customer Personal Data stored by the App depends substantially on controls operated by Atlassian, and that Annex 2 accordingly distinguishes platform-provided measures from measures we implement ourselves.
6.3 We may update the measures in Annex 2 provided the updated measures do not materially reduce the overall level of security.
6.4 You are responsible for the security decisions within your control, including administering user access to your Atlassian site and the App, configuring App permissions appropriately, and deciding what data your users place in the App.
7. Sub-processors
7.1 General authorisation. You give us general written authorisation to engage Sub-processors, subject to this section. The Sub-processors authorised at the effective date are listed in Annex 3.
7.2 Notice of change. We will give you at least 30 days’ notice of any intended addition or replacement of a Sub-processor, by updating Annex 3 and the sub-processor tables in the Privacy Policy and Cloud Security Statement, and by email to the technical contact on your licence.
7.3 Objection. You may object on reasonable data protection grounds within the notice period by emailing support@itsm-ltd.com. We will work with you in good faith to address the objection. If we cannot do so within 30 days, you may terminate the affected subscription by written notice and request a pro-rata refund from Atlassian for the unused portion of the Subscription Term.
7.4 Objection to Atlassian. Atlassian is a Sub-processor that cannot be replaced or removed: the App exists only on the Atlassian platform. If you object to Atlassian as a Sub-processor, your only remedy is to terminate under clause 7.3.
7.5 Terms and liability. We impose on each Sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for the acts and omissions of our Sub-processors as if they were our own.
8. International transfers
8.1 Customer Personal Data stored by the App resides in Forge hosted storage and inherits the data residency configuration of your Atlassian product. Where you have pinned your product data to a UK or EEA region, in-scope App data is pinned to the same region.
8.2 Where a Restricted Transfer occurs, the parties agree that the mechanism set out in Annex 4 applies, and that Annex 4 is incorporated into this DPA.
8.3 We will not make a Restricted Transfer of Customer Personal Data except in accordance with Annex 4 or another lawful transfer mechanism.
8.4 Each party will provide reasonable assistance to the other in carrying out any transfer risk assessment required by Data Protection Laws.
9. Assistance with Data Subject rights
9.1 Taking into account the nature of the Processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise Data Subject rights under Chapter III UK GDPR.
9.2 The practical position. Because Customer Personal Data resides in your own Atlassian site, you can in most cases respond to a Data Subject request directly, without our involvement, using the administrative tools in your Atlassian product and the App. Where App-specific data must be located, amended, exported or deleted and you cannot do so yourself, contact support@itsm-ltd.com and we will assist.
9.3 If we receive a request directly from a Data Subject relating to Customer Personal Data, we will not respond to it substantively. We will acknowledge receipt, direct the individual to you, and notify you within 5 business days.
9.4 Assistance under this section is provided at no charge unless a request is manifestly unfounded, excessive or repetitive, or requires bespoke engineering effort, in which case we may charge our reasonable costs, notified to you in advance.
10. Personal Data Breach
10.1 We will notify you of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 72 hours of becoming aware of it.
10.2 The notification will include, to the extent known at the time: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information is not all available at once, we will provide it in phases without undue delay.
10.3 We will take reasonable steps to contain, investigate and mitigate the breach, and will preserve relevant evidence.
10.4 We will assist you in meeting your own obligations to notify the Information Commissioner’s Office or other Supervisory Authority and, where required, affected Data Subjects.
10.5 We will not notify any Supervisory Authority or Data Subject about a breach affecting Customer Personal Data on your behalf, or name you publicly in connection with it, unless you instruct us to or we are legally required to.
10.6 We will separately notify Atlassian of security incidents affecting the App within 48 hours, as required by the Atlassian Marketplace Partner Agreement. That notification does not discharge our obligation to you under clause 10.1.
11. Data protection impact assessments
Taking into account the nature of the Processing and the information available to us, we will provide reasonable assistance with any data protection impact assessment or prior consultation with a Supervisory Authority under Articles 35 and 36 UK GDPR. We maintain a standard information pack for this purpose, comprising this DPA, the Cloud Security Statement and the App’s scope justifications; that pack will normally be sufficient, and is available from support@itsm-ltd.com.
12. Deletion and return of data
12.1 On uninstallation of the App, Forge app data is deleted by Atlassian in accordance with its platform deletion processes. We hold no independent copy of Customer Personal Data and are therefore unable to return or restore it.
12.2 If you require an export of App data, you must take it before uninstalling. Where the App provides an export facility it is documented at https://str.itsm-ltd.com/guides; where it does not, contact support@itsm-ltd.com before uninstalling and we will advise what is possible.
12.3 Support correspondence and licence records that we hold as Controller are retained and deleted in accordance with the retention table in section 10 of the Privacy Policy.
12.4 We may retain Customer Personal Data to the extent required by law, in which case we will continue to protect it in accordance with this DPA and Process it only for the purpose requiring retention.
13. Audit and information
13.1 We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR.
13.2 How we satisfy audit rights in practice. In recognition of the fact that we operate no infrastructure and hold no Customer Personal Data outside Atlassian, audit rights are exercised as follows:
- First, by reference to the Cloud Security Statement, this DPA and the App’s published scope justifications.
- Second, by reference to Atlassian’s independent certifications and audit reports covering the infrastructure on which the App runs, which you may obtain directly from Atlassian. We cannot supply Atlassian’s audit reports on Atlassian’s behalf.
- Third, by written questionnaire to support@itsm-ltd.com, which we will answer within 5 business days, no more than once in any 12-month period unless a Personal Data Breach has occurred or a Supervisory Authority requires otherwise.
13.3 On-site or remote inspection. Where the steps in clause 13.2 are demonstrably insufficient to meet a requirement of Data Protection Laws or of a Supervisory Authority, you may conduct an inspection subject to: 30 days’ written notice; conduct during our normal business hours; no more than once in any 12-month period unless a Personal Data Breach has occurred; execution of a confidentiality agreement by you and any auditor; no access to other customers’ data or to our other confidential information; and use of an independent auditor who is not our competitor. You bear your own costs and will reimburse our reasonable costs of supporting an inspection beyond one business day.
13.4 We do not hold, and are not certified under, SOC 2, ISO/IEC 27001 or comparable standards. Section 9 of the Cloud Security Statement explains this and identifies which certifications belong to Atlassian.
14. Liability
14.1 The limitations and exclusions of liability in clause 11 of the End User Terms apply to this DPA, and each party’s total aggregate liability arising out of or in connection with this DPA and the End User Terms together is subject to a single cap as set out in that clause.
14.2 Clause 14.1 does not limit either party’s liability to a Data Subject, or to a Supervisory Authority, or any liability that cannot lawfully be limited under Data Protection Laws.
14.3 Nothing in this DPA affects Article 82 UK GDPR (right to compensation) or Article 83 (administrative fines) as between a party and a Supervisory Authority or Data Subject.
15. California Consumer Privacy Act
Where we Process personal information of California residents on your behalf, we act as a “service provider” as defined by the CCPA as amended by the CPRA. We: Process such personal information only to perform the services under the End User Terms; do not sell or share it; do not retain, use or disclose it for any purpose other than performing the services or as otherwise permitted by the CCPA; do not combine it with personal information from other sources except as permitted; and certify that we understand and will comply with these restrictions. You may take reasonable steps under this DPA to ensure our use is consistent with your CCPA obligations.
16. General
16.1 Changes. We may amend this DPA where required by a change in Data Protection Laws, by a Supervisory Authority, or by a change in our Processing. Where an amendment materially reduces your rights, we will give at least 30 days’ notice to the technical contact on your licence, and it will not apply retrospectively or reduce our obligations during your then-current Subscription Term.
16.2 Governing law. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, save where a transfer mechanism in Annex 4 requires otherwise for the Processing to which it applies.
16.3 General provisions. Clauses 13.1 to 13.9 of the End User Terms (assignment, notices, force majeure, third-party rights, severance, waiver, export and sanctions) apply to this DPA as if set out here.
16.4 Order of precedence. Where this DPA conflicts with a transfer mechanism in Annex 4, that mechanism prevails in respect of the transfers it governs.
Annex 1 — Details of the Processing
| Subject matter | Provision of Service Transition & Readiness to the Customer through the Atlassian Marketplace |
| Duration | For the duration of the Subscription Term and until the App is uninstalled, plus any period of legally required retention |
| Nature of Processing | Collection, recording, organisation, structuring, storage, retrieval, consultation, use, alteration and erasure of Customer Personal Data within Atlassian Forge hosted storage and the Customer’s Atlassian products, by automated means |
| Purpose | Delivering the documented functionality of the App on the Customer’s instructions, and providing support |
| Frequency | Continuous, in response to user actions and scheduled App operations |
Categories of Data Subjects
- The Customer’s employees, contractors and other authorised users of its Atlassian site
- Any individual whose personal data the Customer’s users enter into content within the Customer’s Atlassian site that the App reads, writes or stores — which may include the Customer’s own customers, suppliers, partners or applicants
- The Customer’s administrators and technical contacts
Types of Personal Data
Types of Personal Data
- Atlassian account identifiers (AAIDs)
- Display names, usernames, email addresses and avatars as surfaced by the Atlassian product
- Content within Jira issues, Confluence pages, comments, custom fields and similar objects that the App reads, writes or stores, insofar as that content contains personal data — the Customer determines what this includes
- App configuration and operational records, including audit entries, that reference individual users
- Service ownership and readiness template authorship (account IDs)
- Readiness assessment scores, recording the scoring user, timestamp, and free-text notes and evidence links they enter
- Go/no-go gate decisions, recording the deciding user’s account ID and display name, decision, timestamp, notes and conditions — retained immutably as a decision audit trail
- Transition plan tasks, recording assignee, title, description and due date
- Early-life-support records: exit criteria sign-offs, warranty extensions and the final handover sign-off, each recording the acting user’s account ID, timestamp and notes, with the handover also storing the signer’s display name
- Incident trend snapshots store aggregate issue counts only and contain no personal data
Special category or criminal offence data
None is required by the App. The App does not solicit special category data. If the Customer’s users enter special category or criminal offence data into content that the App Processes, the Customer remains the Controller and is responsible for identifying an Article 9 or Article 10 condition and for notifying us in advance so that we can assess whether additional measures are required.
Location of Processing
Atlassian Forge hosted storage, in the region determined by the Customer’s Atlassian data residency configuration.
Annex 2 — Technical and organisational measures
This Annex is the authoritative statement of our technical and organisational measures for the purposes of Article 32 UK GDPR and Annex II of the Standard Contractual Clauses. The Cloud Security Statement at https://str.itsm-ltd.com/legal/cloud-security-statement is a narrative expansion of the same measures for security reviewers; where the two differ, this Annex governs.
Measures marked Service Transition & Readiness are provided by Atlassian as part of the Forge platform. Measures marked ITSM Ltd are implemented by us.
| Area | Measures |
|---|---|
| Pseudonymisation and encryption | Encryption at rest for Forge hosted storage Service Transition & Readiness. TLS 1.2 or above in transit Service Transition & Readiness. Secrets held in the Forge encrypted environment variable store ITSM Ltd. Use of opaque Atlassian account identifiers rather than directly identifying data wherever the App’s function permits ITSM Ltd |
| Confidentiality | Tenant isolation enforced by the Forge platform; storage automatically scoped per installation Service Transition & Readiness. No external egress declared in the App manifest, so Customer Personal Data cannot be transmitted outside Atlassian’s infrastructure ITSM Ltd. Least-privilege OAuth scopes, calls made as the acting user wherever the operation permits ITSM Ltd. Written confidentiality obligations and security awareness training for all personnel ITSM Ltd |
| Integrity | Input validation and output encoding ITSM Ltd. Peer review and branch protection before release ITSM Ltd. Separation of development, staging and production Forge environments ITSM Ltd |
| Availability and resilience | Platform compute, storage and disaster recovery operated by Atlassian Service Transition & Readiness. Backup of persistent storage for platform disaster recovery Service Transition & Readiness. Replicated source control and documented release procedures ITSM Ltd. No independent backup of Customer Personal Data is held by us |
| Restoration of availability | Restoration is a function of Atlassian’s platform disaster recovery Service Transition & Readiness. We offer no separate RTO or RPO |
| Testing and evaluation | Participation in Atlassian Ecoscanner and Atlassian’s app and partner security review Service Transition & Readiness / ITSM Ltd. Automated dependency vulnerability scanning and secret scanning in the build pipeline ITSM Ltd. Annual review of this DPA and the Cloud Security Statement ITSM Ltd |
| Access control | Access to source control, the Atlassian developer console and the support inbox restricted to named personnel, protected by multi-factor authentication, reviewed quarterly and revoked on the day a person leaves ITSM Ltd. No administrative back door, support console or data export facility grants us access to Customer Personal Data ITSM Ltd |
| Logging | Platform operational logs produced and retained by Atlassian Service Transition & Readiness. The App is designed not to write personal data into application logs ITSM Ltd |
| Vulnerability management | Remediation of confirmed vulnerabilities to Atlassian’s cloud-app timeframes: Critical 10 days, High 4 weeks, Medium 12 weeks, Low 25 weeks ITSM Ltd. Automatic propagation of minor and patch releases across all installations Service Transition & Readiness |
| Incident management | Documented incident procedure; notification to the Customer within 72 hours and to Atlassian within 48 hours ITSM Ltd |
| Data minimisation | The App requests only the scopes required for its documented function and stores only the configuration and operational records necessary to deliver it ITSM Ltd |
Annex 3 — Authorised Sub-processors
| Sub-processor | Entity and location | Purpose | Data Processed |
|---|---|---|---|
| Atlassian | Atlassian Pty Ltd (Australia) / Atlassian Corporation (USA); Processing in the region determined by the Customer’s data residency configuration | Hosting, compute and storage for the App; Marketplace licensing and billing | All Customer Personal Data Processed by the App |
| Google Workspace | Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland | Delivery and storage of support email | Support correspondence only — not Customer Personal Data held by the App |
| Vercel | Vercel Inc. (Delaware, USA); Processing in the United Kingdom region | Application hosting for the support application built and operated by ITSM Ltd | Support correspondence only — not Customer Personal Data held by the App |
| Supabase | Supabase Inc. (Delaware, USA); Processing in the United Kingdom region (London) | Database and storage for the support application built and operated by ITSM Ltd | Support correspondence only — not Customer Personal Data held by the App |
ITSM Ltd builds and operates its own support application; it is not a licensed third-party product and is therefore not itself a sub-processor, but the provider hosting it is listed above. This Annex is kept in step with the sub-processor tables in section 8 of the Privacy Policy and section 10 of the Cloud Security Statement. Changes are notified under clause 7.2.
Annex 4 — Restricted Transfers
A. Transfers subject to UK Data Protection Laws
Where a Restricted Transfer is subject to the UK GDPR, the parties adopt the EU Standard Contractual Clauses as modified by the UK International Data Transfer Addendum (version B1.0, in force 21 March 2022), completed as follows:
| Item | Completion |
|---|---|
| Addendum Part 1, Table 1 (Parties) | Exporter: the Customer. Importer: ITSM Ltd. Contact details as recorded in the End User Terms and clause 1 of the Privacy Policy |
| Addendum Part 1, Table 2 (Selected SCCs) | Module Two (Controller to Processor), or Module Three (Processor to Processor) where the Customer is itself a Processor |
| Addendum Part 1, Table 3 (Appendix Information) | Annex I(A) and I(B): as set out in Annex 1 of this DPA. Annex II: as set out in Annex 2 of this DPA. Annex III: as set out in Annex 3 of this DPA |
| Addendum Part 1, Table 4 (Ending the Addendum) | Neither party may end the Addendum when the Approved Addendum changes |
| SCC optional clause 7 (docking) | Applies |
| SCC clause 9 (sub-processors) | Option 2, general written authorisation, with the notice period in clause 7.2 of this DPA |
| SCC clause 11 (redress) | The optional independent dispute resolution wording does not apply |
| SCC clause 17 (governing law) | The laws of England and Wales |
| SCC clause 18 (forum) | The courts of England and Wales |
| Competent Supervisory Authority | The Information Commissioner’s Office |
B. Transfers subject to EU Data Protection Laws
Where a Restricted Transfer is subject to the EU GDPR, the parties adopt the Standard Contractual Clauses (Implementing Decision (EU) 2021/914), with the same module selection and optional-clause elections as in Part A, save that: the governing law is the law of Ireland; the forum is the courts of Ireland; and the competent Supervisory Authority is determined in accordance with clause 13 of the SCCs.
C. Transfers subject to Swiss Data Protection Law
Where a Restricted Transfer is subject to the Swiss Federal Act on Data Protection, the SCCs apply with the amendments set out in the Swiss Federal Data Protection and Information Commissioner’s guidance, and references to Supervisory Authorities include the FDPIC.
D. Order of precedence and alternative mechanisms
Where the SCCs or the UK Addendum conflict with any other provision of this DPA or the End User Terms, the SCCs or Addendum prevail in respect of the transfers they govern. If a mechanism adopted here is invalidated, replaced or superseded, the parties will in good faith adopt the successor mechanism or an alternative lawful transfer mechanism without undue delay.
E. Practical note
Where the Customer has configured Atlassian data residency to a UK or EEA region, Customer Personal Data held by the App remains in that region and no Restricted Transfer of App data arises in the ordinary course. Restricted Transfers are most likely to concern support correspondence and licence records. ITSM Ltd’s support application is hosted on Vercel and Supabase, both configured to United Kingdom regions, so that data is stored in the UK; because both providers are US-incorporated and may access data from outside the UK for support and administration of their own services, Part A of this Annex applies to those transfers.
Published in accordance with the Atlassian Marketplace Partner Agreement. Read alongside the Privacy Policy, End User Terms, Cloud Security Statement and Support and Maintenance Description for Service Transition & Readiness.