Customer Data Processing Addendum
Version: September 14, 2026
1. Parties, application and precedence
This Data Processing Addendum (DPA) supplements the agreement for HourMargin Budget Guard for Jira between Ahmet Çağrı Şimşek, operating as HourMargin in the Netherlands (Provider), and the customer identified in the applicable Marketplace order or separately signed agreement (Customer). Privacy contact: privacy@hourmargin.com. Security contact: support@hourmargin.com.
This DPA becomes binding when incorporated into the parties' accepted agreement or separately accepted by their authorized representatives. Merely viewing this page does not establish a contract. It applies where Provider processes personal data on Customer's behalf through the app and the EU General Data Protection Regulation (GDPR) applies. GDPR terms have their statutory meanings.
Customer acts as controller, or as a processor authorized by its controller to engage Provider. Provider acts as processor or subprocessor respectively. Customer determines why its Jira data is used; app configuration supplies operational instructions. This DPA takes precedence over conflicting app-agreement provisions concerning that processing, without overriding mandatory law or applicable standard contractual clauses. Other commercial terms remain unchanged.
Separate website lead collection and Provider's own business-contact administration are not app processing under this DPA. The privacy notice describes those activities. This DPA does not make Customer's separate Jira agreement with Atlassian an agreement with Provider.
2. Processing schedule
- Service
- Project budget, cost, billable-value and margin calculations for an installed Jira Cloud site
- Operations
- Read minimized Jira fields; synchronize and reconcile worklogs; store settings and ledger inputs; calculate totals; display and export results; apply role/user rates; send administrator-configured summaries through Jira; maintain configuration audit and privacy-processing records
- People
- Customer's Jira users, administrators, employees and contractors whose identifiers, worklogs or rates are included; designated Jira summary recipients
- Personal-data types
- Jira account IDs, cached display names, account-linked worklog/issue/project/role identifiers, worklog dates and duration, user/role rates and related financial values, audit actor IDs/timestamps, notification-recipient references, synchronization and privacy-processing metadata
- Frequency and duration
- Processing while the installation operates, including scheduled worklog/privacy tasks; thereafter only for instructed return/deletion or legally required retention
- Excluded inputs
- No intended processing of special-category or criminal-conviction data. Customer must not supply such data through app settings or support requests. The app does not store issue/worklog descriptions, comments, attachments, passwords, API tokens or bank details
Customer is responsible for lawful instructions, notices and its authority to make Jira data available. Provider must promptly flag instructions it believes unlawful; it will not carry them out while the issue remains unresolved.
3. Processor commitments
Provider will:
- follow documented Customer instructions, including for transfers, except where EU or Member-State law requires otherwise; notify Customer of that requirement unless legally prohibited;
- bind authorized personnel to confidentiality and limit access to their duties;
- maintain risk-appropriate security and the measures in section 4;
- assist Customer with individual-rights requests, security, breach assessment, impact assessments and supervisory consultation, considering the processing and information available;
- provide compliance information and permit Customer or its mandated auditor to conduct audits, including inspections;
- return or delete personal data at Customer's choice when processing ends, including copies, except legally required retention;
- contractually impose equivalent protection on subprocessors and remain responsible for their performance.
Audits will be coordinated to protect other customers and service security. Existing evidence may be used first, but does not replace an inspection where necessary. Scheduling, confidentiality arrangements and any agreed costs must not obstruct statutory or regulatory rights. Provider will cooperate with competent supervisory authorities.
4. App-specific security measures
- Forge hosts the app runtime and installation-scoped KVS; app backend processing does not use a Provider-operated external database or Forge Remote. Forge provides encrypted transport and hosted-storage encryption.
- Financial reads, settings changes, exports and deletion require server-side Jira administrator authorization. Customer controls Jira account access and administrator assignments.
- App data is minimized to the fields in section 2. Error handling avoids deliberate logging of customer worklog payloads, credentials or financial values.
- Cached profile-name reporting/cleanup is implemented. Name cleanup does not erase all identifier-linked records; section 7 explains the distinction.
- Provider uses MFA for operational accounts, restricts production access, reviews dependency findings and performs automated tests and release checks. Security reports go to the named owner.
- Provider will review these measures as risks and app features change and will not materially reduce the overall protection during the agreement.
These measures are not claims of ISO/SOC certification, independent penetration testing, continuous security monitoring or guaranteed round-the-clock response coverage. Atlassian operates platform resilience and storage infrastructure; Provider does not promise a separate backup of Customer's Jira app data.
5. Subprocessors and changes
Customer gives general written authorization for Atlassian, under the applicable Forge contracting relationship, to provide hosted runtime, storage and supporting platform services. Atlassian's downstream providers are identified in its Forge-relevant subprocessor disclosures. Provider will keep the app subprocessor information accessible and supply relevant contractual-entity and processing-location information on request.
Provider will notify Customer's designated privacy contact before adding or replacing a subprocessor, allowing at least 30 days for a reasoned data-protection objection. Provider will pass on platform change notices promptly and will not silently treat a platform change as exempt from this process. If advance notice cannot be met, Provider will address the issue with Customer before continuing affected processing.
The parties will seek a reasonable resolution of objections. If the objection cannot be resolved, Customer may stop the affected processing and terminate the affected service without an early-termination penalty; return/deletion obligations survive. Provider will seek any corresponding unused-service refund through the applicable Marketplace billing process rather than promise unilateral control of Atlassian billing.
Website hosting and email services are not authorized to receive Jira app datasets under this schedule. A support investigation that would require such a transfer needs a separately documented, lawful arrangement first. Do not send raw customer datasets or credentials to the support mailbox.
6. Locations and international transfers
Persistent Forge app data follows the supported residency configuration of the parent Jira product. This is not a promise that every platform operation, operational log or account-metadata field remains in one country. Provider has no independent app-data hosting region outside Forge.
Provider must establish an applicable GDPR Chapter V safeguard before any restricted international transfer. For transfers to Atlassian under Forge, the applicable Forge DPA and its transfer provisions govern that processing relationship. They do not replace this Customer–Provider DPA. Provider will provide relevant safeguard information and assistance with transfer assessments on request. This document does not claim that merely linking to contractual clauses executes them, or that residency alone establishes transfer compliance.
7. Requests, return and deletion
Customer can instruct Provider through an authorized Jira administrator or privacy@hourmargin.com. Identity and authority will be verified without requesting passwords or API tokens. Individual requests received directly will be referred to Customer and supported as appropriate; Provider will not disclose another user's or customer's data.
Customer should export needed app reports before uninstalling. CSV reports are not a complete copy of every stored personal-data category. Customer can request return of remaining relevant data through the verified privacy process before deletion; Provider will coordinate a secure method instead of ordinary email attachments.
Project deletion removes that project's app records. Site-wide deletion also covers shared privacy-processing state. Profile-name erasure triggered by Atlassian does not automatically remove worklog author IDs, account-linked rates, financial history or all shared metadata. Provider will assist with broader requests and explain any need for project/site deletion or coordination with Atlassian.
After uninstallation, Forge-hosted installation data may remain in Atlassian's soft-retention lifecycle for up to 28 days. During that period it is not available through the uninstalled app. Provider will use available deletion mechanisms and coordinate platform-dependent requests; retained copies must remain protected and not be reused for unrelated purposes. Legally required retention will be limited to the required data and period and disclosed unless prohibited. Provider will confirm completion or identify any outstanding platform-dependent step honestly.
8. Personal-data breaches
Provider will notify Customer without undue delay after becoming aware of a personal-data breach affecting the app data. Initial information may be incomplete: Provider will share known scope, likely effects, containment and contact information, then provide further findings promptly. Provider will not wait for a completed investigation or an arbitrary 72-hour period before first notification.
Customer decides its own required notifications to individuals and authorities; Provider will assist. Provider's separate obligations to notify Atlassian do not replace notice to Customer. Provider will maintain an incident record and take corrective action. Notices are factual and do not promise an impact assessment unsupported by evidence.
9. Contact and version changes
Customer must supply and maintain a privacy/security contact capable of receiving notices. Provider will keep a record of the applicable DPA version, Customer's acceptance and the designated contact. Material amendments require the agreement's valid notice/acceptance process and must not retroactively reduce mandatory protections. This DPA survives termination to the extent needed to conclude protected return/deletion and other continuing obligations.