ServiceAccord
Data Processing Agreement
The Article 28 agreement covering the App's export functions, incorporated into the End User Terms automatically on installation.
This Data Processing Agreement (“DPA”) is incorporated into and forms part of the End User Terms for ServiceAccord between ITSM Ltd and the customer on whose Atlassian site the App is installed. It takes effect automatically on installation of the App and requires no signature, but we will countersign a copy on request to support@itsm-ltd.com.
A note on scope before you read further. The App runs entirely on Atlassian Forge and keeps no store of its own. Everything your users enter into the App’s macros is saved by Confluence as part of the page on which the macro sits. The App requests no OAuth scopes, declares no external egress domains and does not transmit customer data to us. Its only server-side code is three export functions, which run on Atlassian Forge compute when a page is exported to PDF or Word; they process the macro’s content in memory and store nothing. In practical terms, the personal data that reaches our own systems is limited to support correspondence and any Marketplace records Atlassian makes available to us. This DPA is nonetheless a full Article 28 agreement, because the App’s export functions process Customer Personal Data on your behalf on infrastructure we engage.
1. Definitions
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” have the meanings given in the UK GDPR.
“Customer Personal Data” means Personal Data contained within Your Data (as defined in the End User Terms) that we Process on your behalf under this DPA. “Data Protection Laws” means all laws applicable to the Processing of Personal Data under this DPA, including the UK GDPR, the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), the EU GDPR where applicable, and the Privacy and Electronic Communications Regulations 2003. “Restricted Transfer” means a transfer of Personal Data to a country not covered by UK or EU adequacy regulations, where such transfer requires a lawful transfer mechanism. “Standard Contractual Clauses” or “SCCs” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914. “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner under section 119A of the Data Protection Act 2018. “UK GDPR” has the meaning given in section 3(10) of the Data Protection Act 2018. “Sub-processor” means any third party engaged by us to Process Customer Personal Data.
“App”, “Atlassian”, “Your Data” and “Subscription Term” have the meanings given in the End User Terms, as do all other capitalised terms not defined here. In the event of conflict between this DPA and the End User Terms in respect of the Processing of Personal Data, this DPA prevails.
2. Roles of the parties
2.1 In respect of Customer Personal Data, you are the Controller and we are the Processor. Where you are yourself a Processor acting for a third-party Controller, we act as a Sub-processor and you warrant that you have the authority of that Controller to enter into this DPA.
2.2 Atlassian’s position in the chain. The App’s export functions run on Atlassian Forge compute, which we engage as a Forge developer. For that compute, Atlassian acts as our Sub-processor. Storage of Your Data is different: Confluence stores it as part of your pages, under your direct agreement with Atlassian, in which Atlassian acts as your own Processor. Those two relationships are distinct: this DPA governs only our Processing, and nothing in it varies your agreement with Atlassian.
2.3 We act as an independent Controller in respect of support correspondence, Marketplace records and business contact data, as described in section 4 of the Privacy Policy. This DPA does not apply to that Processing, which is governed by the Privacy Policy and by Data Protection Laws directly.
2.4 Each party is independently responsible for its own compliance with Data Protection Laws applicable to it in its own role.
3. Scope and duration of Processing
3.1 The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are set out in Annex 1.
3.2 This DPA applies for as long as we Process Customer Personal Data on your behalf, and survives termination of the End User Terms to the extent any such Processing continues.
4. Processing on documented instructions
4.1 We will Process Customer Personal Data only on your documented instructions, including in relation to Restricted Transfers, unless required to do otherwise by law to which we are subject. Where such a legal requirement applies, we will inform you before Processing unless the law prohibits it on important grounds of public interest.
4.2 Your instructions comprise: the End User Terms; this DPA; the content you and your users enter into the App’s macros; the operations the App performs in response to actions taken by your users, including exporting a page; and any further written instructions you give us that we accept in writing.
4.3 We will inform you if, in our opinion, an instruction infringes Data Protection Laws. We may suspend the affected Processing until the instruction is confirmed, withdrawn or amended.
4.4 We will not sell Customer Personal Data, and will not use it for our own purposes, for developing or training any machine learning or artificial intelligence model, for advertising, or for profiling.
4.5 You warrant that you have a lawful basis for the Processing you instruct, have provided any notices and obtained any consents required, and that your instructions comply with Data Protection Laws. You are responsible for the accuracy and legality of Customer Personal Data and for the content your users place in your Atlassian site.
5. Confidentiality
We ensure that every person authorised to Process Customer Personal Data is bound by a written obligation of confidentiality or an appropriate statutory duty, that access is granted on a need-to-know and least-privilege basis, and that such persons receive appropriate data protection and security awareness training.
6. Security
6.1 We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 UK GDPR. Those measures are described in Annex 2 and, in more detail, in the Cloud Security Statement at https://serviceaccord.itsm-ltd.com/legal/cloud-security-statement.
6.2 You acknowledge that the security of Customer Personal Data depends substantially on controls operated by Atlassian, which stores it as part of your Confluence pages and provides the compute on which the App’s export functions run, and that Annex 2 accordingly distinguishes platform-provided measures from measures we implement ourselves.
6.3 We may update the measures in Annex 2 provided the updated measures do not materially reduce the overall level of security.
6.4 You are responsible for the security decisions within your control, including administering user access to your Atlassian site and the App, deciding who can view and edit the pages that contain the App’s macros, and deciding what data your users enter into them.
7. Sub-processors
7.1 General authorisation. You give us general written authorisation to engage Sub-processors, subject to this section. The Sub-processors authorised at the effective date are listed in Annex 3.
7.2 Notice of change. We will give you at least 30 days’ notice of any intended addition or replacement of a Sub-processor, by updating Annex 3 and the sub-processor tables in the Privacy Policy and Cloud Security Statement, and by notice in accordance with clause 13.3 of the End User Terms.
7.3 Objection. You may object on reasonable data protection grounds within the notice period by emailing support@itsm-ltd.com. We will work with you in good faith to address the objection. If we cannot do so within 30 days, you may terminate by uninstalling the App.
7.4 Objection to Atlassian. Atlassian is a Sub-processor that cannot be replaced or removed: the App exists only on the Atlassian platform. If you object to Atlassian as a Sub-processor, your only remedy is to terminate under clause 7.3.
7.5 Terms and liability. We impose on each Sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for the acts and omissions of our Sub-processors as if they were our own.
8. International transfers
8.1 Customer Personal Data is stored by Confluence as part of your pages and therefore follows your Confluence data residency configuration. The App keeps no store of its own and adds no separate storage location. The App’s export functions process macro content transiently, in memory, on Atlassian Forge compute in locations determined by Atlassian, and retain nothing once the export completes.
8.2 Where a Restricted Transfer occurs, the parties agree that the mechanism set out in Annex 4 applies, and that Annex 4 is incorporated into this DPA.
8.3 We will not make a Restricted Transfer of Customer Personal Data except in accordance with Annex 4 or another lawful transfer mechanism.
8.4 Each party will provide reasonable assistance to the other in carrying out any transfer risk assessment required by Data Protection Laws.
9. Assistance with Data Subject rights
9.1 Taking into account the nature of the Processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise Data Subject rights under Chapter III UK GDPR.
9.2 The practical position. Customer Personal Data exists only in the content of the App’s macros on your own Confluence pages, so you can respond to a Data Subject request directly, without our involvement, by opening the macro’s configuration to read, correct or remove the data. Three points affect how you do so:
- (a) the App does not opt its macro content into Confluence search indexing, so a Confluence search should not be relied on to find it — identify the pages that use the App through your space owners;
- (b) earlier values remain in the page’s version history until you remove those versions with Confluence’s own tools; and
- (c) PDF or Word exports of a page, once made, are outside both Confluence and the App.
If you need help, contact support@itsm-ltd.com and we will assist.
9.3 If we receive a request directly from a Data Subject relating to Customer Personal Data, we will not respond to it substantively. We will acknowledge receipt, direct the individual to you, and notify you within 5 business days.
9.4 Assistance under this section is provided at no charge unless a request is manifestly unfounded, excessive or repetitive, or requires bespoke engineering effort, in which case we may charge our reasonable costs, notified to you in advance.
10. Personal Data Breach
10.1 We will notify you of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 72 hours of becoming aware of it, in the manner set out in clause 13.3 of the End User Terms.
10.2 The notification will include, to the extent known at the time: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information is not all available at once, we will provide it in phases without undue delay.
10.3 We will take reasonable steps to contain, investigate and mitigate the breach, and will preserve relevant evidence.
10.4 We will assist you in meeting your own obligations to notify the Information Commissioner’s Office or other Supervisory Authority and, where required, affected Data Subjects.
10.5 We will not notify any Supervisory Authority or Data Subject about a breach affecting Customer Personal Data on your behalf, or name you publicly in connection with it, unless you instruct us to or we are legally required to.
10.6 We will separately notify Atlassian of security incidents affecting the App within 48 hours, as required by the Atlassian Marketplace Partner Agreement. That notification does not discharge our obligation to you under clause 10.1.
11. Data protection impact assessments
Taking into account the nature of the Processing and the information available to us, we will provide reasonable assistance with any data protection impact assessment or prior consultation with a Supervisory Authority under Articles 35 and 36 UK GDPR. We maintain a standard information pack for this purpose, comprising this DPA, the Cloud Security Statement and the App’s declaration that it requests no OAuth scopes; that pack will normally be sufficient, and is available from support@itsm-ltd.com.
12. Deletion and return of data
12.1 The App keeps no store of its own. Customer Personal Data exists only in the content of the App’s macros on your Confluence pages, which Confluence stores and which remains there when the App is uninstalled. There is therefore nothing for us to return or delete on uninstallation, and we hold no copy of Customer Personal Data from which to return or restore it.
12.2 To delete Customer Personal Data, edit or remove the macros that contain it and, where required, remove earlier page versions with Confluence’s own tools, as described in clause 9.2. While the App is not installed, Confluence does not display its macros; if you need a readable copy of their content, export the relevant pages to PDF or Word before uninstalling. Guidance is at https://serviceaccord.itsm-ltd.com/guides.
12.3 Support correspondence and Marketplace records that we hold as Controller are retained and deleted in accordance with the retention table in section 10 of the Privacy Policy.
12.4 We may retain Customer Personal Data to the extent required by law, in which case we will continue to protect it in accordance with this DPA and Process it only for the purpose requiring retention.
13. Audit and information
13.1 We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR.
13.2 How we satisfy audit rights in practice. In recognition of the fact that we operate no infrastructure and hold no Customer Personal Data outside Atlassian, audit rights are exercised as follows:
- First, by reference to the Cloud Security Statement, this DPA and the App’s published declaration that it requests no OAuth scopes and declares no egress.
- Second, by reference to Atlassian’s independent certifications and audit reports covering the infrastructure on which the App runs, which you may obtain directly from Atlassian. We cannot supply Atlassian’s audit reports on Atlassian’s behalf.
- Third, by written questionnaire to support@itsm-ltd.com, which we will answer within 5 business days, no more than once in any 12-month period unless a Personal Data Breach has occurred or a Supervisory Authority requires otherwise.
13.3 On-site or remote inspection. Where the steps in clause 13.2 are demonstrably insufficient to meet a requirement of Data Protection Laws or of a Supervisory Authority, you may conduct an inspection subject to: 30 days’ written notice; conduct during our normal business hours; no more than once in any 12-month period unless a Personal Data Breach has occurred; execution of a confidentiality agreement by you and any auditor; no access to other customers’ data or to our other confidential information; and use of an independent auditor who is not our competitor. You bear your own costs and will reimburse our reasonable costs of supporting an inspection beyond one business day.
13.4 We do not hold, and are not certified under, SOC 2, ISO/IEC 27001 or comparable standards. Section 9 of the Cloud Security Statement explains this and identifies which certifications belong to Atlassian.
14. Liability
14.1 The limitations and exclusions of liability in clause 11 of the End User Terms apply to this DPA, and each party’s total aggregate liability arising out of or in connection with this DPA and the End User Terms together is subject to a single cap as set out in that clause.
14.2 Clause 14.1 does not limit either party’s liability to a Data Subject, or to a Supervisory Authority, or any liability that cannot lawfully be limited under Data Protection Laws.
14.3 Nothing in this DPA affects Article 82 UK GDPR (right to compensation) or Article 83 (administrative fines) as between a party and a Supervisory Authority or Data Subject.
15. California Consumer Privacy Act
Where we Process personal information of California residents on your behalf, we act as a “service provider” as defined by the CCPA as amended by the CPRA. We: Process such personal information only to perform the services under the End User Terms; do not sell or share it; do not retain, use or disclose it for any purpose other than performing the services or as otherwise permitted by the CCPA; do not combine it with personal information from other sources except as permitted; and certify that we understand and will comply with these restrictions. You may take reasonable steps under this DPA to ensure our use is consistent with your CCPA obligations.
16. General
16.1 Changes. We may amend this DPA where required by a change in Data Protection Laws, by a Supervisory Authority, or by a change in our Processing. Where an amendment materially reduces your rights, we will give at least 30 days’ notice in accordance with clause 13.3 of the End User Terms. No amendment applies retrospectively, and if you do not accept an amendment you may uninstall the App before it takes effect.
16.2 Governing law. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, save where a transfer mechanism in Annex 4 requires otherwise for the Processing to which it applies.
16.3 General provisions. Clauses 13.1 to 13.9 of the End User Terms (assignment, notices, force majeure, third-party rights, severance, waiver, export and sanctions) apply to this DPA as if set out here.
16.4 Order of precedence. Where this DPA conflicts with a transfer mechanism in Annex 4, that mechanism prevails in respect of the transfers it governs.
Annex 1 — Details of the Processing
| Field | |
|---|---|
| Subject matter | Provision of ServiceAccord to the Customer through the Atlassian Marketplace |
| Duration | For as long as the App is installed on the Customer’s Atlassian site, plus any period of legally required retention. Each export operation lasts only for the export it serves |
| Nature of Processing | Retrieval, consultation, structuring and use of macro content, in memory, by the App’s export functions on Atlassian Forge compute, to produce the exported form of a page. Recording, alteration and erasure of macro content by the App’s user interface, which runs in the user’s browser and writes to the Confluence page only through Confluence’s own interfaces, in response to the user’s actions. The App stores no Customer Personal Data of its own |
| Purpose | Delivering the documented functionality of the App on the Customer’s instructions, and providing support |
| Frequency | Each time a page containing one of the App’s macros is exported to PDF or Word and, as Atlassian documents, when an earlier version of such a page is viewed in page history. The App performs no scheduled or background operations |
Categories of Data Subjects
- The Customer’s employees, contractors and other authorised users whose names or details are entered into the App’s macros
- Any other individual whose personal data the Customer’s users enter into the App’s macros — which may include the Customer’s own customers, suppliers or partners, for example as attendees at a service review
Types of Personal Data
The App collects no personal data automatically. It does not handle Atlassian account identifiers, email addresses or avatars. Personal data appears only where the Customer’s users type it into one of the App’s free-text fields. The fields in which that is most likely are:
- RACI Matrix: role names, where a role is named after a person, and activity notes
- Service Review Record: chair, attendees, improvement-action owners, KPI comments, and risks and issues
- Service Level Targets: owner, and notes and exclusions
Any other free-text field could contain personal data if a user types it there; the Customer determines what is entered. In the circumstances described in Annex 2 (Logging), an error message in the App’s logs may quote a short excerpt of macro content.
Special category or criminal offence data
None is required by the App. The App does not solicit special category data. If the Customer’s users enter special category or criminal offence data into content that the App Processes, the Customer remains the Controller and is responsible for identifying an Article 9 or Article 10 condition and for notifying us in advance so that we can assess whether additional measures are required.
Location of Processing
Storage: Confluence page storage, in the region determined by the Customer’s Atlassian data residency configuration. Transient processing by the export functions: Atlassian Forge compute, in locations determined by Atlassian.
Annex 2 — Technical and organisational measures
This Annex is the authoritative statement of our technical and organisational measures for the purposes of Article 32 UK GDPR and Annex II of the Standard Contractual Clauses. The Cloud Security Statement at https://serviceaccord.itsm-ltd.com/legal/cloud-security-statement is a narrative expansion of the same measures for security reviewers; where the two differ, this Annex governs.
Measures marked Atlassian are provided by Atlassian as part of Confluence and the Forge platform. Measures marked ITSM Ltd are implemented by us.
| Area | Measures |
|---|---|
| Pseudonymisation and encryption | Encryption at rest of Confluence page storage, in which macro content is stored Atlassian. TLS 1.2 or above in transit Atlassian. The App holds no credentials, secrets or environment variables ITSM Ltd. No pseudonymisation is applied: macro content is stored as entered, subject to the permissions of the page that contains it ITSM Ltd |
| Confidentiality | Access to macro content governed by Confluence page permissions Atlassian. Tenant isolation of Forge function execution Atlassian. No OAuth scopes requested and no Atlassian product API called, so the App can reach no data beyond the macro content Confluence passes to it ITSM Ltd. No external egress declared in the App manifest, so Customer Personal Data cannot be transmitted outside Atlassian’s infrastructure ITSM Ltd. An automated test, run on every change, fails the build if the manifest or source code introduces an OAuth scope, an external permission, a network call, a storage API or a product API call ITSM Ltd. Written confidentiality obligations and security awareness training for all personnel ITSM Ltd |
| Integrity | All macro content passes through a single validation function each time it is read, which accepts any input and returns a valid record ITSM Ltd. Text is rendered through Atlassian UI Kit components, which do not interpret it as markup ITSM Ltd. Linting, strict type-checking, unit tests, dependency and secret scanning, and static analysis run automatically on every change, and our release procedure requires them to pass before a production deployment ITSM Ltd. Separation of development, staging and production Forge environments ITSM Ltd |
| Availability and resilience | Platform compute, storage and disaster recovery operated by Atlassian Atlassian. Backup of Confluence page storage, and page version history Atlassian. Replicated source control and documented release procedures ITSM Ltd. No independent backup of Customer Personal Data is held by us |
| Restoration of availability | Restoration is a function of Atlassian’s platform disaster recovery and Confluence page history Atlassian. We offer no separate RTO or RPO |
| Testing and evaluation | Atlassian’s review of the App at Marketplace listing approval Atlassian / ITSM Ltd. The automated test described under Confidentiality, and unit tests, on every change ITSM Ltd. Annual review of this DPA and the Cloud Security Statement ITSM Ltd |
| Access control | Access to source control, the Atlassian developer console and the support inbox restricted to named personnel, protected by multi-factor authentication, reviewed quarterly and revoked on the day a person leaves ITSM Ltd. No administrative back door, support console or data export facility grants us access to Customer Personal Data ITSM Ltd |
| Logging | Platform operational logs produced and retained by Atlassian; a site administrator can withdraw developers’ access to an app’s logs Atlassian. The App writes error messages only, never routine activity, and does not log macro content — save that where a stored macro configuration is damaged and cannot be read, the error recorded may quote a short excerpt of it, and when that occurs during an export the excerpt reaches the App’s logs, to which we have access ITSM Ltd |
| Vulnerability management | Remediation of confirmed vulnerabilities to Atlassian’s cloud-app timeframes: Critical 10 days, High 4 weeks, Medium 12 weeks, Low 25 weeks ITSM Ltd. Automatic propagation of minor and patch releases across all installations Atlassian |
| Incident management | Documented incident procedure; notification to the Customer within 72 hours, in the manner set out in clause 13.3 of the End User Terms, and to Atlassian within 48 hours ITSM Ltd |
| Data minimisation | The App requests no OAuth scopes, collects no data automatically and keeps no store of its own ITSM Ltd |
Annex 3 — Authorised Sub-processors
| Sub-processor | Entity and location | Purpose | Data Processed |
|---|---|---|---|
| Atlassian | Atlassian Pty Ltd (Australia) / Atlassian Corporation (USA); Processing in locations determined by Atlassian | Forge compute on which the App’s export functions run; Marketplace distribution; Jira Service Management, our support tool | Macro content, processed transiently during export. Storage of that content in Confluence is under the Customer’s own agreement with Atlassian; and support correspondence held in ITSM Ltd’s Jira Service Management |
| Google Workspace | Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland | Delivery and storage of support email | Support correspondence only — not Customer Personal Data Processed by the App |
ITSM Ltd keeps support records in Atlassian’s Jira Service Management, so Atlassian, listed above, is the provider that holds them. This Annex is kept in step with the sub-processor tables in section 8 of the Privacy Policy and section 10 of the Cloud Security Statement. Changes are notified under clause 7.2.
Annex 4 — Restricted Transfers
A. Transfers subject to UK Data Protection Laws
Where a Restricted Transfer is subject to the UK GDPR, the parties adopt the EU Standard Contractual Clauses as modified by the UK International Data Transfer Addendum (version B1.0, in force 21 March 2022), completed as follows:
| Item | Completion |
|---|---|
| Addendum Part 1, Table 1 (Parties) | Exporter: the Customer. Importer: ITSM Ltd. Contact details as recorded in the End User Terms and clause 1 of the Privacy Policy |
| Addendum Part 1, Table 2 (Selected SCCs) | Module Two (Controller to Processor), or Module Three (Processor to Processor) where the Customer is itself a Processor |
| Addendum Part 1, Table 3 (Appendix Information) | Annex I(A) and I(B): as set out in Annex 1 of this DPA. Annex II: as set out in Annex 2 of this DPA. Annex III: as set out in Annex 3 of this DPA |
| Addendum Part 1, Table 4 (Ending the Addendum) | Neither party may end the Addendum when the Approved Addendum changes |
| SCC optional clause 7 (docking) | Applies |
| SCC clause 9 (sub-processors) | Option 2, general written authorisation, with the notice period in clause 7.2 of this DPA |
| SCC clause 11 (redress) | The optional independent dispute resolution wording does not apply |
| SCC clause 17 (governing law) | The laws of England and Wales |
| SCC clause 18 (forum) | The courts of England and Wales |
| Competent Supervisory Authority | The Information Commissioner’s Office |
B. Transfers subject to EU Data Protection Laws
Where a Restricted Transfer is subject to the EU GDPR, the parties adopt the Standard Contractual Clauses (Implementing Decision (EU) 2021/914), with the same module selection and optional-clause elections as in Part A, save that: the governing law is the law of Ireland; the forum is the courts of Ireland; and the competent Supervisory Authority is determined in accordance with clause 13 of the SCCs.
C. Transfers subject to Swiss Data Protection Law
Where a Restricted Transfer is subject to the Swiss Federal Act on Data Protection, the SCCs apply with the amendments set out in the Swiss Federal Data Protection and Information Commissioner’s guidance, and references to Supervisory Authorities include the FDPIC.
D. Order of precedence and alternative mechanisms
Where the SCCs or the UK Addendum conflict with any other provision of this DPA or the End User Terms, the SCCs or Addendum prevail in respect of the transfers they govern. If a mechanism adopted here is invalidated, replaced or superseded, the parties will in good faith adopt the successor mechanism or an alternative lawful transfer mechanism without undue delay.
E. Practical note
Customer Personal Data is stored by Confluence as part of the Customer’s pages, in the region set by the Customer’s Atlassian data residency configuration, and the App keeps no copy. The export functions process it transiently on Atlassian Forge compute, and any transfer arising from that processing is governed by Atlassian’s own arrangements, as described in section 9 of the Privacy Policy. Restricted Transfers are most likely to concern support correspondence. ITSM Ltd keeps support records in Atlassian’s Jira Service Management on its own Atlassian site. Atlassian Corporation is US-incorporated and Atlassian Pty Ltd is Australian, so Part A of this Annex applies to transfers of that data.
Published in accordance with the Atlassian Marketplace Partner Agreement. Read alongside the Privacy Policy, End User Terms, Cloud Security Statement and Support and Maintenance Description for ServiceAccord.