Visual Dependencies · Version 1.1 · Effective 29.09.2026
This Addendum forms part of the agreement between Vitalii Bobak (“Provider”) and every customer organisation that has installed Visual Dependencies (“Customer”), and governs Provider’s processing of personal data on Customer’s behalf. It applies to every Customer automatically: it is identified in the Provider-Specific Terms on the app’s Marketplace listing and so forms part of the Bonterms Standard End User Agreement (Section 3.3); no request or signature is needed. “End User Terms” means the terms under which Customer licenses the app through the Atlassian Marketplace.
Where the Customer’s own DPA template is required instead, Provider will review it.
Customer is the controller. Provider is the processor. Where Customer is itself a processor for a third party, Provider is a sub-processor and this Addendum applies accordingly.
Provider acts as an independent controller for support correspondence initiated directly by individuals and for licence contact records supplied by Atlassian. That processing is governed by Provider’s Privacy Policy, not by this Addendum.
| Subject matter | Provision of the Visual Dependencies Jira app |
| Nature | Reading Jira work item and link data to render a dependency graph; storing user-defined view presets |
| Purpose | Enabling Customer’s users to visualise dependencies between work items |
| Duration | For as long as the app is installed on Customer’s Atlassian site |
Data subjects: Customer’s employees, contractors, and other authorised users of Customer’s Atlassian site.
Personal data:
Work item data is read on demand, inside Atlassian’s platform, to draw the graph for the user viewing it. It is not stored by the app, not visible to Provider, and never sent to the analytics service in Section 5. The app does not read work item descriptions, comments, attachments or watchers.
No special category data (Art. 9) is intentionally processed. Customer must not enter special category data into fields the app reads.
Provider shall:
(a) Documented instructions. Process personal data only on Customer’s documented instructions, including for transfers to a third country, unless required otherwise by EU or Member State law, in which case Provider will inform Customer before processing unless legally prohibited.
(b) Confidentiality. Ensure that persons authorised to process the personal data are bound by confidentiality obligations.
(c) Security. Implement appropriate technical and organisational measures under Art. 32, as set out in Annex 1.
(d) Sub-processors. Engage sub-processors only under Section 5.
(e) Data subject rights. Taking into account the nature of the processing, assist Customer by appropriate technical and organisational measures in fulfilling Customer’s obligation to respond to data subject requests. Because all app data resides within Customer’s own Atlassian site, Customer can in most cases action such requests directly.
(f) Assistance. Assist Customer in ensuring compliance with Arts. 32–36, taking into account the nature of the processing and the information available to Provider.
(g) Deletion or return. On termination, delete personal data as described in Section 7.
(h) Audit. Make available all information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, in the manner set out in Section 8.
Provider shall immediately inform Customer if, in its opinion, an instruction infringes the GDPR.
Customer grants general written authorisation for Provider to engage sub-processors.
Current sub-processors:
| Sub-processor | Role | Location |
|---|---|---|
| Atlassian Pty Ltd and affiliates | Application hosting, data storage (Forge storage), support portal, payment processing | Data residency region selected by Customer |
| Zoho Corporation B.V. | Business email, including support correspondence ¹ | EU (Amsterdam and Dublin) |
| PostHog Inc. | Product analytics: content-free usage events under a pseudonymous, per-installation identifier ¹ | EU (PostHog Cloud EU); DPA signed 2026-09-10 |
¹ Zoho and PostHog process only data for which Provider is itself the controller (support correspondence, and product analytics under privacy policy §3). No Customer Personal Data reaches them. They are listed for transparency, and Customer’s objection right below applies to them too.
Provider will give Customer at least 30 days’ notice before adding or replacing a sub-processor, by a note on the app’s Marketplace listing and by updating the list in this Section at the address above. Updating the list under this procedure is not an amendment of this Addendum. Customer may object on reasonable data protection grounds within that period; if the objection cannot be resolved, Customer may terminate the affected subscription.
Provider remains fully liable to Customer for its sub-processors’ performance.
Team members located in Ukraine and Canada who access personal data do so as persons acting under Provider’s authority within the meaning of Art. 29, under written data-handling authorisations and Standard Contractual Clauses. They are not sub-processors.
Provider shall notify Customer without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Customer’s personal data, and shall provide the information available to it, supplementing as further information becomes known.
Notification will be sent to the technical contact on record. Customer is responsible for any notification to supervisory authorities or data subjects.
App data is stored in Forge storage within Customer’s Atlassian site. On uninstallation, that storage — including all presets — is deleted by the Atlassian platform.
Provider does not maintain independent copies of Customer’s work item data. Any incidental copies arising from support (for example a sanitised reproduction case) are deleted within 90 days of the support matter closing.
Provider has no premises where Customer Personal Data is processed: the app runs on Atlassian Forge, and the underlying infrastructure is covered by Atlassian’s own certifications and audit reports, on which Customer may rely. Audits of Provider are therefore carried out as follows.
(a) Documentation. Provider will answer reasonable written security questionnaires and provide documentation supporting compliance with this Addendum, at no charge, no more than once per twelve months.
(b) Remote audit. Where Customer reasonably needs more than (a) — for example after a personal data breach, or at the request of a supervisory authority — Customer or an independent auditor bound by confidentiality may conduct a remote audit: a scheduled video session in which Provider shows the systems, settings and records relevant to this Addendum. Customer gives 30 days’ written notice; the audit takes place during Provider’s business hours, no more than once per twelve months, at Customer’s expense — except where it reveals material non-compliance, in which case Provider bears its reasonable costs.
(c) Authorities. Nothing in this Section limits the powers of a supervisory authority.
Where personal data is transferred out of the EEA to Provider’s team members, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 apply. They were executed between Provider and each team member on 27.09.2026, supported by a transfer impact assessment; a copy is available to Customer on request.
For transfers from the United Kingdom, the UK International Data Transfer Addendum to the SCCs applies. For transfers from Switzerland, the SCCs apply with references to the GDPR read as references to the FADP.
Liability under this Addendum is subject to the limitations in the End User Terms.
In the event of conflict between this Addendum and the End User Terms on matters of personal data processing, this Addendum prevails.
This Addendum takes effect on 29.09.2026, or when Customer installs the app if later, and continues until Provider ceases processing Customer Personal Data. Its terms are fixed for Customer’s subscription term; only the sub-processor list in Section 5 changes, under the procedure there. Sections 7 (Deletion), 8 (Audit), 9 (International transfers) and 10 (Liability and precedence) survive termination.
This Addendum is governed by the laws of Italy, subject to Clause 17 of any incorporated Standard Contractual Clauses.
Vitalii Bobak, Via Carlo Bonino 5, 29122 Piacenza (PC), Italy Data protection contact: [email protected]
Hosting and storage
Transmission
Access control
Minimisation
Incident response