Concessa
Data Processing Agreement
The DPA between you as controller and ITSM Ltd as processor, with the field inventory, the sub-processor list and the transfer mechanism.
This Data Processing Agreement (“DPA”) is incorporated into and forms part of the End User Terms for Concessa between ITSM Ltd and the customer identified in the applicable Atlassian Marketplace order. It takes effect automatically on installation of the App and requires no signature, but we will countersign a copy on request to support@itsm-ltd.com.
A note on scope before you read further. The App runs entirely on Atlassian Forge and stores all customer data inside Atlassian’s infrastructure. It declares no external egress domains and does not transmit customer data to us. In practical terms, the personal data that reaches our own systems is limited to support correspondence and licence records. This DPA is nonetheless a full Article 28 agreement, because we still determine how the App processes personal data on your behalf.
1. Definitions
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” have the meanings given in the UK GDPR.
“Customer Personal Data” means Personal Data contained within Your Data (as defined in the End User Terms) that we Process on your behalf under this DPA. “Data Protection Laws” means all laws applicable to the Processing of Personal Data under this DPA, including the UK GDPR, the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), the EU GDPR where applicable, and the Privacy and Electronic Communications Regulations 2003. “Restricted Transfer” means a transfer of Personal Data to a country not covered by UK or EU adequacy regulations, where such transfer requires a lawful transfer mechanism. “Standard Contractual Clauses” or “SCCs” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914. “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner under section 119A of the Data Protection Act 2018. “UK GDPR” has the meaning given in section 3(10) of the Data Protection Act 2018. “Sub-processor” means any third party engaged by us to Process Customer Personal Data.
“App”, “Atlassian”, “Your Data” and “Subscription Term” have the meanings given in the End User Terms, as do all other capitalised terms not defined here. In the event of conflict between this DPA and the End User Terms in respect of the Processing of Personal Data, this DPA prevails.
2. Roles of the parties
2.1 In respect of Customer Personal Data, you are the Controller and we are the Processor. Where you are yourself a Processor acting for a third-party Controller, we act as a Sub-processor and you warrant that you have the authority of that Controller to enter into this DPA.
2.2 Atlassian’s position in the chain. Because the App is hosted on Atlassian Forge, Atlassian acts as our Sub-processor for the hosting, compute and storage on which the App depends. Atlassian may separately act as your own Processor under your direct agreement with Atlassian for the underlying Jira or Jira Service Management product. Those two relationships are distinct: this DPA governs only our Processing, and nothing in it varies your agreement with Atlassian.
2.3 We act as an independent Controller in respect of support correspondence, licence and billing records, and business contact data, as described in section 4 of the Privacy Policy. This DPA does not apply to that Processing, which is governed by the Privacy Policy and by Data Protection Laws directly.
2.4 Each party is independently responsible for its own compliance with Data Protection Laws applicable to it in its own role.
3. Scope and duration of Processing
3.1 The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are set out in Annex 1.
3.2 This DPA applies for as long as we Process Customer Personal Data on your behalf, and survives termination of the End User Terms to the extent any such Processing continues.
4. Processing on documented instructions
4.1 We will Process Customer Personal Data only on your documented instructions, including in relation to Restricted Transfers, unless required to do otherwise by law to which we are subject. Where such a legal requirement applies, we will inform you before Processing unless the law prohibits it on important grounds of public interest.
4.2 Your instructions comprise: the End User Terms; this DPA; the configuration choices you and your users make within the App; the operations the App performs in response to actions taken by your users; and any further written instructions you give us that we accept in writing.
4.3 We will inform you if, in our opinion, an instruction infringes Data Protection Laws. We may suspend the affected Processing until the instruction is confirmed, withdrawn or amended.
4.4 We will not sell Customer Personal Data, and will not use it for our own purposes, for developing or training any machine learning or artificial intelligence model, for advertising, or for profiling.
4.5 You warrant that you have a lawful basis for the Processing you instruct, have provided any notices and obtained any consents required, and that your instructions comply with Data Protection Laws. You are responsible for the accuracy and legality of Customer Personal Data and for the content your users place in your Atlassian site.
5. Confidentiality
We ensure that every person authorised to Process Customer Personal Data is bound by a written obligation of confidentiality or an appropriate statutory duty, that access is granted on a need-to-know and least-privilege basis, and that such persons receive appropriate data protection and security awareness training.
6. Security
6.1 We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 UK GDPR. Those measures are described in Annex 2 and, in more detail, in the Cloud Security Statement at https://concessa.itsm-ltd.com/legal/cloud-security-statement.
6.2 You acknowledge that the security of Customer Personal Data stored by the App depends substantially on controls operated by Atlassian, and that Annex 2 accordingly distinguishes platform-provided measures from measures we implement ourselves.
6.3 We may update the measures in Annex 2 provided the updated measures do not materially reduce the overall level of security.
6.4 You are responsible for the security decisions within your control, including administering user access to your Atlassian site and the App, configuring App permissions appropriately, and deciding what data your users place in the App.
7. Sub-processors
7.1 General authorisation. You give us general written authorisation to engage Sub-processors, subject to this section. The Sub-processors authorised at the effective date are listed in Annex 3.
7.2 Notice of change. We will give you at least 30 days’ notice of any intended addition or replacement of a Sub-processor, by updating Annex 3 and the sub-processor tables in the Privacy Policy and Cloud Security Statement, and by email to the technical contact on your licence.
7.3 Objection. You may object on reasonable data protection grounds within the notice period by emailing support@itsm-ltd.com. We will work with you in good faith to address the objection. If we cannot do so within 30 days, you may terminate the affected subscription by written notice and request a pro-rata refund from Atlassian for the unused portion of the Subscription Term.
7.4 Objection to Atlassian. Atlassian is a Sub-processor that cannot be replaced or removed: the App exists only on the Atlassian platform. If you object to Atlassian as a Sub-processor, your only remedy is to terminate under clause 7.3.
7.5 Terms and liability. We impose on each Sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for the acts and omissions of our Sub-processors as if they were our own.
8. International transfers
8.1 Customer Personal Data stored by the App resides in Forge hosted storage and inherits the data residency configuration of your Atlassian product. Where you have pinned your product data to a UK or EEA region, in-scope App data is pinned to the same region.
8.2 Where a Restricted Transfer occurs, the parties agree that the mechanism set out in Annex 4 applies, and that Annex 4 is incorporated into this DPA.
8.3 We will not make a Restricted Transfer of Customer Personal Data except in accordance with Annex 4 or another lawful transfer mechanism.
8.4 Each party will provide reasonable assistance to the other in carrying out any transfer risk assessment required by Data Protection Laws.
9. Assistance with Data Subject rights
9.1 Taking into account the nature of the Processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise Data Subject rights under Chapter III UK GDPR.
9.2 The practical position. Because Customer Personal Data resides in your own Atlassian site, you can in most cases respond to a Data Subject request directly, without our involvement, using the administrative tools in your Atlassian product and the App. Where App-specific data must be located, amended, exported or deleted and you cannot do so yourself, contact support@itsm-ltd.com and we will assist.
9.3 If we receive a request directly from a Data Subject relating to Customer Personal Data, we will not respond to it substantively. We will acknowledge receipt, direct the individual to you, and notify you within 5 business days.
9.4 A limit on erasure you should know about before you buy. The App keeps an append-only, hash-chained audit trail: each entry carries a hash of the one before it, so an entry cannot be altered or removed without breaking verification for every entry after it. That is what makes the trail evidence. It also means erasure is not uniformly available, and the position differs field by field:
- Fields that are not chained can be redacted cleanly, with no consequence for the trail: a CAB agenda item’s text, a CAB action’s description, and a CAB attendee’s display name. None of these is carried by any audit entry.
- Fields that are chained cannot be: an approval comment, a change summary, a post-implementation review’s lesson, the reasons given for revising a change’s recorded outcome or correcting that review, a freeze window’s name and reason, a freeze override’s reason, a meeting’s cancellation reason, the CAB standing agenda template, and the account identifiers recorded as actor attributions throughout.
Our position on a chained field is that retaining it is Processing necessary for the establishment, exercise or defence of legal claims and for your own compliance record — an audit trail whose entries can be removed on request is not an audit trail. Where erasure of a chained field is nonetheless required, there are two honest options and no third: erase the field and accept that verification will report a break from that entry forward, or uninstall the App and lose the whole installation’s record — every project’s, not only the one concerned — rather than one person’s part of it. We will take that decision with you, not for you, and record it.
9.5 Assistance under this section is provided at no charge unless a request is manifestly unfounded, excessive or repetitive, or requires bespoke engineering effort, in which case we may charge our reasonable costs, notified to you in advance.
10. Personal Data Breach
10.1 We will notify you of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 72 hours of becoming aware of it.
10.2 The notification will include, to the extent known at the time: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information is not all available at once, we will provide it in phases without undue delay.
10.3 We will take reasonable steps to contain, investigate and mitigate the breach, and will preserve relevant evidence.
10.4 We will assist you in meeting your own obligations to notify the Information Commissioner’s Office or other Supervisory Authority and, where required, affected Data Subjects.
10.5 We will not notify any Supervisory Authority or Data Subject about a breach affecting Customer Personal Data on your behalf, or name you publicly in connection with it, unless you instruct us to or we are legally required to.
10.6 We will separately notify Atlassian of security incidents affecting the App within 48 hours, as required by the Atlassian Marketplace Partner Agreement. That notification does not discharge our obligation to you under clause 10.1.
11. Data protection impact assessments
Taking into account the nature of the Processing and the information available to us, we will provide reasonable assistance with any data protection impact assessment or prior consultation with a Supervisory Authority under Articles 35 and 36 UK GDPR. We maintain a standard information pack for this purpose, comprising this DPA, the Cloud Security Statement and the App’s scope justifications; that pack will normally be sufficient, and is available from support@itsm-ltd.com.
12. Deletion and return of data
12.1 On uninstallation of the App, Forge app data is deleted by Atlassian in accordance with its platform deletion processes. We hold no independent copy of Customer Personal Data and are therefore unable to return or restore it.
12.2 If you require an export of App data, you must take it before uninstalling. The App provides one: Project → Concessa → Evidence produces a verified export of the governance record — the whole project or a single change, in JSON or CSV, with each change’s recorded outcome and post-implementation review, change metrics for a period you choose, and the audit trail and its chain verification included. The export is rendered on the page for you to copy; there is deliberately no download button, because generating a file would require the App to call out of Atlassian, which it does not do. It is documented at https://concessa.itsm-ltd.com/guides.
12.3 We offer no facility to delete an individual audit entry, for the reasons given in clause 9.4. Deletion of App data held in Forge storage is all-or-nothing at the level of the installation. The status values described in clause 12.6 are not held in Forge storage, and can be removed project by project.
12.4 Support correspondence and licence records that we hold as Controller are retained and deleted in accordance with the retention table in section 10 of the Privacy Policy.
12.5 We may retain Customer Personal Data to the extent required by law, in which case we will continue to protect it in accordance with this DPA and Process it only for the purpose requiring retention.
12.6 Where a project administrator has switched on publishing to Jira, the App writes status values onto Jira issue properties. They are Your Data (as defined in the End User Terms) held in your own Atlassian site, not App data held in Forge storage, and what the App writes into them contains no Customer Personal Data. The App cannot remove them once it is uninstalled, and we have no other means of returning or deleting them. While the App is installed you can remove them yourself: section 3.6 of the Cloud Security Statement describes how, and which issues that cannot reach.
13. Audit and information
13.1 We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR.
13.2 How we satisfy audit rights in practice. In recognition of the fact that we operate no infrastructure and hold no Customer Personal Data outside Atlassian, audit rights are exercised as follows:
- First, by reference to the Cloud Security Statement, this DPA and the App’s published scope justifications.
- Second, by reference to Atlassian’s independent certifications and audit reports covering the infrastructure on which the App runs, which you may obtain directly from Atlassian. We cannot supply Atlassian’s audit reports on Atlassian’s behalf.
- Third, by written questionnaire to support@itsm-ltd.com, which we will answer within 5 business days, no more than once in any 12-month period unless a Personal Data Breach has occurred or a Supervisory Authority requires otherwise.
13.3 On-site or remote inspection. Where the steps in clause 13.2 are demonstrably insufficient to meet a requirement of Data Protection Laws or of a Supervisory Authority, you may conduct an inspection subject to: 30 days’ written notice; conduct during our normal business hours; no more than once in any 12-month period unless a Personal Data Breach has occurred; execution of a confidentiality agreement by you and any auditor; no access to other customers’ data or to our other confidential information; and use of an independent auditor who is not our competitor. You bear your own costs and will reimburse our reasonable costs of supporting an inspection beyond one business day.
13.4 We do not hold, and are not certified under, SOC 2, ISO/IEC 27001 or comparable standards. Section 9 of the Cloud Security Statement explains this and identifies which certifications belong to Atlassian.
14. Liability
14.1 The limitations and exclusions of liability in clause 11 of the End User Terms apply to this DPA, and each party’s total aggregate liability arising out of or in connection with this DPA and the End User Terms together is subject to a single cap as set out in that clause.
14.2 Clause 14.1 does not limit either party’s liability to a Data Subject, or to a Supervisory Authority, or any liability that cannot lawfully be limited under Data Protection Laws.
14.3 Nothing in this DPA affects Article 82 UK GDPR (right to compensation) or Article 83 (administrative fines) as between a party and a Supervisory Authority or Data Subject.
15. California Consumer Privacy Act
Where we Process personal information of California residents on your behalf, we act as a “service provider” as defined by the CCPA as amended by the CPRA. We: Process such personal information only to perform the services under the End User Terms; do not sell or share it; do not retain, use or disclose it for any purpose other than performing the services or as otherwise permitted by the CCPA; do not combine it with personal information from other sources except as permitted; and certify that we understand and will comply with these restrictions. You may take reasonable steps under this DPA to ensure our use is consistent with your CCPA obligations.
16. General
16.1 Changes. We may amend this DPA where required by a change in Data Protection Laws, by a Supervisory Authority, or by a change in our Processing. Where an amendment materially reduces your rights, we will give at least 30 days’ notice to the technical contact on your licence, and it will not apply retrospectively or reduce our obligations during your then-current Subscription Term.
16.2 Governing law. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, save where a transfer mechanism in Annex 4 requires otherwise for the Processing to which it applies.
16.3 General provisions. Clauses 13.1 to 13.9 of the End User Terms (assignment, notices, force majeure, third-party rights, severance, waiver, export and sanctions) apply to this DPA as if set out here.
16.4 Order of precedence. Where this DPA conflicts with a transfer mechanism in Annex 4, that mechanism prevails in respect of the transfers it governs.
Annex 1 — Details of the Processing
| Subject matter | Provision of Concessa to the Customer through the Atlassian Marketplace |
| Duration | For the duration of the Subscription Term and until the App is uninstalled, plus any period of legally required retention |
| Nature of Processing | Collection, recording, organisation, structuring, storage, retrieval, consultation and use of Customer Personal Data within Atlassian Forge hosted storage, by automated means. Audit records are appended and never altered or erased (clause 9.4). The Processing the App performs inside the Customer’s Jira product is: reading issue and project data; posting a plain-text comment on a change issue as the acting user; answering the App’s Jira search function when Jira calls it, which reads the App’s own records on behalf of the user Jira identifies for the call and returns an answer about a project’s freeze windows, not about any person, which Jira may keep and reuse for other users’ searches, whose results Jira’s own permission checks still filter (Cloud Security Statement 5.2); reading the status property described below on each change issue in every project set up in the App, to keep it current or remove it; and, only where a project administrator has switched on publishing to Jira, writing that property, and removing it once publishing is switched off. What the App writes into it contains no Customer Personal Data. The App also records diagnostic log lines in the Forge platform’s logs, which can contain text a user typed into its search function (Cloud Security Statement 7.4) |
| Purpose | Delivering the documented functionality of the App on the Customer’s instructions, and providing support |
| Frequency | Continuous, in response to user actions and to Jira searches that use the App’s search function. The App’s manifest declares one scheduled trigger, a daily reconciliation that keeps the status values published to Jira issues in step with the App’s records; it declares no web trigger or product-event module |
Categories of Data Subjects
- The Customer’s employees, contractors and other authorised users of its Atlassian site
- Any individual whose personal data the Customer’s users enter into content within the Customer’s Atlassian site that the App reads, writes or stores — which may include the Customer’s own customers, suppliers, partners or applicants
- The Customer’s administrators and technical contacts
- Individuals recorded by the App who may never have used it. A CAB meeting attendee or the owner of a CAB action is recorded by account identifier and display name because a colleague named them, not because they opened the App. They are Data Subjects on exactly the same footing as any other, and a request from one is answered from the records themselves rather than from any account of theirs
Types of Personal Data
The App stores nothing Jira already holds a field for. What it does store is listed exhaustively below. The App reads no email address and no avatar, and calls no Atlassian endpoint from which it takes either.
Identifiers
- Atlassian account identifiers (AAIDs) — opaque identifiers assigned by Atlassian, recorded against: the creator of a change record; an approval’s approver and requester; a freeze window’s creator; every audit entry’s actor; a CAB meeting’s attendees, creator, chair, canceller and last editor; a CAB action’s owner, creator and completer; and the administrator who last set the project’s agent roles, change scope, CAB schedule or publishing to Jira.
- Display names — as surfaced by Jira, and deliberately stored alongside the account identifier for an audit entry’s actor, an approval’s approver, a CAB attendee and a CAB action’s owner, so that a governance record remains readable after a person leaves the organisation.
Free text entered by the Customer’s users, which may contain personal data if they put it there
- Approval and rejection comments
- Change record summaries and the impacted service
- A change’s post-implementation review lesson, and the reasons given for revising a change’s recorded outcome or correcting that review
- Freeze window names and reasons, and the reason given for overriding a freeze
- CAB meeting agenda item text, and the reason a meeting was cancelled
- CAB action descriptions
- The project’s standing CAB agenda template
Records read from, or written to, the Customer’s Jira product
- Issue fields the App reads to display a change record: summary, status, issue type, project, assignee, reporter and creation date, and the dates in Jira Service Management’s change-management date fields where the Customer’s site has them; and, to decide how to post a comment, whether an issue is a Jira Service Management customer request
- Plain-text comments the App posts on a change issue, as the acting user, when an approval is requested, decided or rescinded and when a change has been reviewed at a CAB meeting. These comments name the approver or the deciding user and, for a decision, quote the free-text comment they gave
- A status property on change issues. The App writes it only where a project administrator has switched on publishing to Jira, its daily reconciliation reads it back, and the App removes it once publishing is switched off. It holds the change’s governance status, risk level and change type, the dates of its planned window, the number of approvals outstanding, the time the change record was last updated and a format version number. What the App writes into it contains no Customer Personal Data
Clause 9.4 records which of these fields are carried into the hash-chained audit trail and which are not.
Special category or criminal offence data
None is required by the App. The App does not solicit special category data. If the Customer’s users enter special category or criminal offence data into content that the App Processes, the Customer remains the Controller and is responsible for identifying an Article 9 or Article 10 condition and for notifying us in advance so that we can assess whether additional measures are required.
Location of Processing
Atlassian Forge hosted storage, in the region determined by the Customer’s Atlassian data residency configuration; and, for the comments and the status property the App writes to Jira, the Customer’s own Jira site.
Annex 2 — Technical and organisational measures
This Annex is the authoritative statement of our technical and organisational measures for the purposes of Article 32 UK GDPR and Annex II of the Standard Contractual Clauses. The Cloud Security Statement at https://concessa.itsm-ltd.com/legal/cloud-security-statement is a narrative expansion of the same measures for security reviewers; where the two differ, this Annex governs.
Measures marked Atlassian are provided by Atlassian as part of the Forge platform. Measures marked ITSM Ltd are implemented by us.
| Area | Measures |
|---|---|
| Pseudonymisation and encryption | Encryption at rest for Forge hosted storage Atlassian. TLS 1.2 or above in transit Atlassian. The App holds no secrets: it authenticates to no system outside Atlassian, so there is no credential to store ITSM Ltd. Use of opaque Atlassian account identifiers rather than directly identifying data wherever the App’s function permits ITSM Ltd |
| Confidentiality | Tenant isolation enforced by the Forge platform; storage automatically scoped per installation Atlassian. No external egress declared in the App manifest, so Customer Personal Data cannot be transmitted outside Atlassian’s infrastructure ITSM Ltd. Least-privilege OAuth scopes; calls made as the acting user except where the App must act as itself, each of which is listed with its reason in section 5.2 of the Cloud Security Statement ITSM Ltd. Written confidentiality obligations and security awareness training for all personnel ITSM Ltd |
| Integrity | Input validation at every resolver boundary and output encoding ITSM Ltd. Branch protection, and automated checks that must pass before a change can reach the release branch; no second-person review is claimed (Cloud Security Statement 7.1) ITSM Ltd. Separation of development, staging and production Forge environments ITSM Ltd. Append-only, hash-chained audit records with a single write path and no update or delete operation ITSM Ltd |
| Availability and resilience | Platform compute, storage and disaster recovery operated by Atlassian Atlassian. Backup of persistent storage for platform disaster recovery Atlassian. Replicated source control and documented release procedures ITSM Ltd. No independent backup of Customer Personal Data is held by us |
| Restoration of availability | Restoration is a function of Atlassian’s platform disaster recovery Atlassian. We offer no separate RTO or RPO |
| Testing and evaluation | Participation in Atlassian Ecoscanner and Atlassian’s app and partner security review Atlassian / ITSM Ltd. Automated dependency vulnerability scanning, static analysis and secret scanning in the build pipeline ITSM Ltd. Advisories that cannot be remediated are recorded in a dated exception register carrying a reason, an owner and an expiry, and an expired exception fails the build ITSM Ltd. Annual review of this DPA and the Cloud Security Statement ITSM Ltd |
| Access control | Access to source control, the Atlassian developer console and the support inbox restricted to named personnel, protected by multi-factor authentication, reviewed quarterly and revoked on the day a person leaves ITSM Ltd. No administrative back door, support console or data export facility grants us access to Customer Personal Data ITSM Ltd |
| Logging | Platform operational logs produced and retained by Atlassian Atlassian. Application log statements confined to publishing to Jira and its search function, built to carry no account identifier or display name, as described in section 7.4 of the Cloud Security Statement ITSM Ltd |
| Vulnerability management | Remediation of confirmed vulnerabilities to Atlassian’s cloud-app timeframes: Critical 10 days, High 4 weeks, Medium 12 weeks, Low 25 weeks ITSM Ltd. Automatic propagation of minor and patch releases across all installations Atlassian |
| Incident management | Documented incident procedure; notification to the Customer within 72 hours and to Atlassian within 48 hours ITSM Ltd |
| Data minimisation | The App requests only the scopes required for its documented function and stores only the configuration and operational records necessary to deliver it. It stores nothing Jira already holds a field for ITSM Ltd |
Annex 3 — Authorised Sub-processors
| Sub-processor | Entity and location | Purpose | Data Processed |
|---|---|---|---|
| Atlassian | Atlassian Pty Ltd (Australia) / Atlassian Corporation (USA); Processing in the region determined by the Customer’s data residency configuration | Hosting, compute and storage for the App; Marketplace licensing and billing | All Customer Personal Data Processed by the App |
| Google Workspace | Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland | Delivery and storage of support email | Support correspondence only — not Customer Personal Data held by the App |
There are two, and one of them is the platform the Customer is already running. We operate no support portal, no ticketing system, no analytics service and no hosting of our own; support is conducted by email. This Annex is kept in step with the sub-processor tables in section 8 of the Privacy Policy and section 10 of the Cloud Security Statement. Changes are notified under clause 7.2.
Annex 4 — Restricted Transfers
A. Transfers subject to UK Data Protection Laws
Where a Restricted Transfer is subject to the UK GDPR, the parties adopt the EU Standard Contractual Clauses as modified by the UK International Data Transfer Addendum (version B1.0, in force 21 March 2022), completed as follows:
| Item | Completion |
|---|---|
| Addendum Part 1, Table 1 (Parties) | Exporter: the Customer. Importer: ITSM Ltd. Contact details as recorded in the End User Terms and clause 1 of the Privacy Policy |
| Addendum Part 1, Table 2 (Selected SCCs) | Module Two (Controller to Processor), or Module Three (Processor to Processor) where the Customer is itself a Processor |
| Addendum Part 1, Table 3 (Appendix Information) | Annex I(A) and I(B): as set out in Annex 1 of this DPA. Annex II: as set out in Annex 2 of this DPA. Annex III: as set out in Annex 3 of this DPA |
| Addendum Part 1, Table 4 (Ending the Addendum) | Neither party may end the Addendum when the Approved Addendum changes |
| SCC optional clause 7 (docking) | Applies |
| SCC clause 9 (sub-processors) | Option 2, general written authorisation, with the notice period in clause 7.2 of this DPA |
| SCC clause 11 (redress) | The optional independent dispute resolution wording does not apply |
| SCC clause 17 (governing law) | The laws of England and Wales |
| SCC clause 18 (forum) | The courts of England and Wales |
| Competent Supervisory Authority | The Information Commissioner’s Office |
B. Transfers subject to EU Data Protection Laws
Where a Restricted Transfer is subject to the EU GDPR, the parties adopt the Standard Contractual Clauses (Implementing Decision (EU) 2021/914), with the same module selection and optional-clause elections as in Part A, save that: the governing law is the law of Ireland; the forum is the courts of Ireland; and the competent Supervisory Authority is determined in accordance with clause 13 of the SCCs.
C. Transfers subject to Swiss Data Protection Law
Where a Restricted Transfer is subject to the Swiss Federal Act on Data Protection, the SCCs apply with the amendments set out in the Swiss Federal Data Protection and Information Commissioner’s guidance, and references to Supervisory Authorities include the FDPIC.
D. Order of precedence and alternative mechanisms
Where the SCCs or the UK Addendum conflict with any other provision of this DPA or the End User Terms, the SCCs or Addendum prevail in respect of the transfers they govern. If a mechanism adopted here is invalidated, replaced or superseded, the parties will in good faith adopt the successor mechanism or an alternative lawful transfer mechanism without undue delay.
E. Practical note
Where the Customer has configured Atlassian data residency to a UK or EEA region, Customer Personal Data held by the App remains in that region and no Restricted Transfer of App data arises in the ordinary course.
Restricted Transfers are therefore most likely to concern support correspondence and licence records, neither of which is Customer Personal Data held by the App. Support correspondence is held in Google Workspace in Ireland, which is covered by UK adequacy regulations, so no Restricted Transfer arises for it in the ordinary course either. Licence records reach us from Atlassian, whose own transfer arrangements govern them. Parts A to D above are retained so that a lawful mechanism is already in place should a transfer arise — not because one is presently relied upon.
Published in accordance with the Atlassian Marketplace Partner Agreement. Read alongside the Privacy Policy, End User Terms, Cloud Security Statement and Support and Maintenance Description for Concessa.