Data Protection

Data Processing Addendum

This Data Processing Addendum (“DPA”) applies to personal data processed by Shurivo for Jira Service Management on behalf of a customer.

Effective date: October 4, 2026

This DPA is intended to accompany the customer’s agreement for use of Shurivo for Jira Service Management, including where the Atlassian standard customizable end-user agreement is used.

1. Parties and scope

This DPA is entered into between the customer using the App (“Customer”) and Sajjad Alizadeh, an independent developer operating the Shurivo product brand (“Provider”). It applies only to the extent Provider processes Personal Data on behalf of Customer in connection with Shurivo for Jira Service Management (the “App”).

If there is a conflict between this DPA and the parties’ applicable end-user agreement with respect to the processing of Personal Data, this DPA controls for that processing.

2. Roles

For Personal Data processed by Provider on Customer’s behalf, Customer acts as controller (or equivalent role under applicable data-protection law) and Provider acts as processor/service provider, as applicable. Customer is responsible for determining the lawfulness of its use of the App and for providing any notices or obtaining any consents required for its processing activities.

3. Processing instructions

Provider will process Personal Data only to provide, secure, maintain, and support the App; to comply with Customer’s documented instructions as expressed through use and configuration of the App; and as otherwise required by applicable law. Provider will notify Customer if it believes an instruction violates applicable data-protection law, unless prohibited from doing so.

4. Processing details

Subject matterProviding configurable request-editing functionality, authorization/policy enforcement, audit recording inside Jira, and App configuration for Jira Service Management.
DurationFor the duration of Customer’s use of the App and any platform-controlled retention period following uninstall, unless otherwise required by law.
Nature and purposeReading data needed to evaluate whether supported edits are allowed; writing approved changes and audit information inside Jira; storing project-level App configuration in Forge hosted storage; and providing support/security operations.
Data subjectsCustomer administrators, Jira/Jira Service Management users, requesters, request participants, and other individuals whose information is contained in relevant Jira/Jira Service Management requests.
Personal DataAtlassian account identifiers and display names; request field values that may contain Personal Data; request-participant information; project/request metadata; and audit information such as editor identity, timestamps, changed field names, and before/after values stored inside Jira.

5. Data location and storage

The App is built on Atlassian Forge. It does not use Forge Remote, a Provider-operated external runtime server, or an external customer-data database. Request contents and request before/after values are not stored in Forge KVS. Forge KVS is used for project-level App configuration.

Data written to Jira remains in Jira. Forge-hosted configuration follows Atlassian’s hosted-storage controls and lifecycle.

6. Confidentiality and access

Provider will limit access to Personal Data to the extent necessary to provide, secure, maintain, or support the App and will treat Personal Data as confidential. Provider will not sell Customer Personal Data or use it for advertising.

7. Security measures

Provider will maintain appropriate technical and organizational measures for the App, taking into account the nature of processing and the risks involved. These measures include use of Atlassian Forge hosting, App-level authorization and configured policy checks, data minimization, restricted logging practices, dependency and vulnerability management, and security-incident handling.

8. Subprocessing and external runtime services

The App does not send App runtime End-User Data to non-Atlassian third-party services and does not use non-Atlassian external runtime infrastructure for customer request data. Atlassian Forge and Jira/Jira Service Management provide the platform environment in which the App operates; Customer’s relationship with Atlassian is also governed by Customer’s applicable Atlassian agreements.

Corporate email services used for ordinary support, privacy, and security correspondence are separate from the App runtime data flow. Customers should avoid sending unnecessary request content or secrets by email.

9. Data-subject requests

Taking into account the nature of the processing, Provider will provide reasonable assistance to Customer with requests from individuals exercising applicable data-protection rights where the requested Personal Data is within Provider’s ability to access or act upon. Because request and audit data remain inside Customer’s Atlassian environment, Customer administrators may be able to address many such requests directly within Jira/Jira Service Management.

10. Assistance and compliance information

Provider will provide information reasonably necessary to demonstrate compliance with this DPA and, where required by applicable law, reasonable assistance regarding security, breach response, and data-protection impact assessments, taking into account the nature of the App and the information available to Provider.

11. Personal Data breaches

Provider will notify Customer without undue delay after becoming aware of a confirmed Personal Data breach for which Provider is responsible and will provide information reasonably available to Provider to assist Customer with applicable notification obligations. Provider may provide information in phases as it becomes available.

12. Return and deletion

Upon termination or uninstall, Provider will not retain a separate external copy of Customer request data because the App does not maintain an external customer-data database. Data stored in Jira remains subject to Customer’s Jira/Atlassian retention controls. Forge-hosted App configuration is handled according to Atlassian’s hosted-storage lifecycle. Atlassian currently documents a 28-day retention period for Forge hosted storage after App uninstallation, subject to Atlassian’s platform policies and updates.

13. International transfers

The App’s runtime and hosted configuration use Atlassian-provided infrastructure. Customer is responsible for its Atlassian account and data-residency choices. If Provider later introduces processing that requires an independent international transfer mechanism, Provider will update this DPA and the related privacy documentation before using that processing for Customer Personal Data.

14. Audits

Upon reasonable written request, Provider will make available relevant information about the App’s processing and security practices. Any audit request must be proportionate, protect confidential information, avoid unreasonable disruption, and first use available documentation where appropriate. The parties will cooperate in good faith on any additional audit steps legally required.

15. No independent certification claim

Provider does not represent that Shurivo independently holds SOC 2, ISO 27001, FedRAMP, or HIPAA certification.

16. Contact

Privacy and DPA inquiries: privacy@shurivo.com
Security matters: security@shurivo.com