Data Processing Addendum

Visual Dependencies · Version 1.1 · Effective 29.09.2026

This Addendum forms part of the agreement between Vitalii Bobak (“Provider”) and every customer organisation that has installed Visual Dependencies (“Customer”), and governs Provider’s processing of personal data on Customer’s behalf. It applies to every Customer automatically: it is identified in the Provider-Specific Terms on the app’s Marketplace listing and so forms part of the Bonterms Standard End User Agreement (Section 3.3); no request or signature is needed. “End User Terms” means the terms under which Customer licenses the app through the Atlassian Marketplace.

Where the Customer’s own DPA template is required instead, Provider will review it.

1. Roles

Customer is the controller. Provider is the processor. Where Customer is itself a processor for a third party, Provider is a sub-processor and this Addendum applies accordingly.

Provider acts as an independent controller for support correspondence initiated directly by individuals and for licence contact records supplied by Atlassian. That processing is governed by Provider’s Privacy Policy, not by this Addendum.

2. Subject matter, nature and purpose

Subject matter Provision of the Visual Dependencies Jira app
Nature Reading Jira work item and link data to render a dependency graph; storing user-defined view presets
Purpose Enabling Customer’s users to visualise dependencies between work items
Duration For as long as the app is installed on Customer’s Atlassian site

3. Categories of data subjects and personal data

Data subjects: Customer’s employees, contractors, and other authorised users of Customer’s Atlassian site.

Personal data:

  • Atlassian account identifiers, display names, avatar URLs
  • Work item metadata where it relates to individuals (assignee, reporter)
  • Work item summaries, to the extent Customer’s users have entered personal data into them
  • View presets, which may reference account identifiers

Work item data is read on demand, inside Atlassian’s platform, to draw the graph for the user viewing it. It is not stored by the app, not visible to Provider, and never sent to the analytics service in Section 5. The app does not read work item descriptions, comments, attachments or watchers.

No special category data (Art. 9) is intentionally processed. Customer must not enter special category data into fields the app reads.

4. Provider obligations

Provider shall:

(a) Documented instructions. Process personal data only on Customer’s documented instructions, including for transfers to a third country, unless required otherwise by EU or Member State law, in which case Provider will inform Customer before processing unless legally prohibited.

(b) Confidentiality. Ensure that persons authorised to process the personal data are bound by confidentiality obligations.

(c) Security. Implement appropriate technical and organisational measures under Art. 32, as set out in Annex 1.

(d) Sub-processors. Engage sub-processors only under Section 5.

(e) Data subject rights. Taking into account the nature of the processing, assist Customer by appropriate technical and organisational measures in fulfilling Customer’s obligation to respond to data subject requests. Because all app data resides within Customer’s own Atlassian site, Customer can in most cases action such requests directly.

(f) Assistance. Assist Customer in ensuring compliance with Arts. 32–36, taking into account the nature of the processing and the information available to Provider.

(g) Deletion or return. On termination, delete personal data as described in Section 7.

(h) Audit. Make available all information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, in the manner set out in Section 8.

Provider shall immediately inform Customer if, in its opinion, an instruction infringes the GDPR.

5. Sub-processors

Customer grants general written authorisation for Provider to engage sub-processors.

Current sub-processors:

Sub-processor Role Location
Atlassian Pty Ltd and affiliates Application hosting, data storage (Forge storage), support portal, payment processing Data residency region selected by Customer
Zoho Corporation B.V. Business email, including support correspondence ¹ EU (Amsterdam and Dublin)
PostHog Inc. Product analytics: content-free usage events under a pseudonymous, per-installation identifier ¹ EU (PostHog Cloud EU); DPA signed 2026-09-10

¹ Zoho and PostHog process only data for which Provider is itself the controller (support correspondence, and product analytics under privacy policy §3). No Customer Personal Data reaches them. They are listed for transparency, and Customer’s objection right below applies to them too.

Provider will give Customer at least 30 days’ notice before adding or replacing a sub-processor, by a note on the app’s Marketplace listing and by updating the list in this Section at the address above. Updating the list under this procedure is not an amendment of this Addendum. Customer may object on reasonable data protection grounds within that period; if the objection cannot be resolved, Customer may terminate the affected subscription.

Provider remains fully liable to Customer for its sub-processors’ performance.

Team members located in Ukraine and Canada who access personal data do so as persons acting under Provider’s authority within the meaning of Art. 29, under written data-handling authorisations and Standard Contractual Clauses. They are not sub-processors.

6. Personal data breaches

Provider shall notify Customer without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Customer’s personal data, and shall provide the information available to it, supplementing as further information becomes known.

Notification will be sent to the technical contact on record. Customer is responsible for any notification to supervisory authorities or data subjects.

7. Deletion

App data is stored in Forge storage within Customer’s Atlassian site. On uninstallation, that storage — including all presets — is deleted by the Atlassian platform.

Provider does not maintain independent copies of Customer’s work item data. Any incidental copies arising from support (for example a sanitised reproduction case) are deleted within 90 days of the support matter closing.

8. Audit

Provider has no premises where Customer Personal Data is processed: the app runs on Atlassian Forge, and the underlying infrastructure is covered by Atlassian’s own certifications and audit reports, on which Customer may rely. Audits of Provider are therefore carried out as follows.

(a) Documentation. Provider will answer reasonable written security questionnaires and provide documentation supporting compliance with this Addendum, at no charge, no more than once per twelve months.

(b) Remote audit. Where Customer reasonably needs more than (a) — for example after a personal data breach, or at the request of a supervisory authority — Customer or an independent auditor bound by confidentiality may conduct a remote audit: a scheduled video session in which Provider shows the systems, settings and records relevant to this Addendum. Customer gives 30 days’ written notice; the audit takes place during Provider’s business hours, no more than once per twelve months, at Customer’s expense — except where it reveals material non-compliance, in which case Provider bears its reasonable costs.

(c) Authorities. Nothing in this Section limits the powers of a supervisory authority.

9. International transfers

Where personal data is transferred out of the EEA to Provider’s team members, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 apply. They were executed between Provider and each team member on 27.09.2026, supported by a transfer impact assessment; a copy is available to Customer on request.

For transfers from the United Kingdom, the UK International Data Transfer Addendum to the SCCs applies. For transfers from Switzerland, the SCCs apply with references to the GDPR read as references to the FADP.

10. Liability and precedence

Liability under this Addendum is subject to the limitations in the End User Terms.

In the event of conflict between this Addendum and the End User Terms on matters of personal data processing, this Addendum prevails.

11. Term and termination

This Addendum takes effect on 29.09.2026, or when Customer installs the app if later, and continues until Provider ceases processing Customer Personal Data. Its terms are fixed for Customer’s subscription term; only the sub-processor list in Section 5 changes, under the procedure there. Sections 7 (Deletion), 8 (Audit), 9 (International transfers) and 10 (Liability and precedence) survive termination.

12. Governing law

This Addendum is governed by the laws of Italy, subject to Clause 17 of any incorporated Standard Contractual Clauses.

13. Contact

Vitalii Bobak, Via Carlo Bonino 5, 29122 Piacenza (PC), Italy Data protection contact:

Annex 1 — Technical and organisational measures

Hosting and storage

  • The app runs on Atlassian Forge. App data is held in Forge hosted storage in Customer’s data residency region and inherits Atlassian’s encryption at rest.
  • Provider keeps no copies of Customer’s work item data outside Atlassian’s infrastructure.

Transmission

  • All data in transit is encrypted with TLS.

Access control

  • Multi-factor authentication on every account with access to personal data.
  • Access limited to team members who need it, each under a written confidentiality and data-handling authorisation (Art. 29); access revoked on departure.
  • The app requests only the Forge scopes its functions need.

Minimisation

  • Diagnostic material is sanitised before it is shared with a team member outside the EEA: names, email addresses, Atlassian account identifiers, site URLs and cloud IDs, and identifying screenshots are removed. Where that is not possible, the matter is handled inside the EEA.
  • No personal data in personal email accounts, messaging apps or personal cloud storage; full-disk encryption on devices used to access it.

Incident response

  • Team members report a suspected breach to Provider within 24 hours; Provider notifies Customer under Section 6.