Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

History

Change History

Topics

Table of Contents
maxLevel6
minLevel1
include
outlinefalse
indent
excludeHistory|Topics
styledefault
typelist
printabletrue
class

...

Release Management Data Processing Addendum

IMPORTANT! BE SURE TO CAREFULLY READ AND UNDERSTAND ALL OF THE RIGHTS AND RESTRICTIONS SET FORTH IN THIS DATA PROCESSING ADDENDUM (“DPA”). YOU ARE NOT AUTHORIZED TO USE THIS SOFTWARE UNLESS AND UNTIL YOU ACCEPT THE TERMS OF THIS DPA.

...

In this DPA, the following terms have the following meanings:

Expand
breakoutWidth760
titleFull list of definitions

(a) “Australian Data Protection Law” means the Australian Privacy Act 1988 (Cth).

(b) “Agreement” means the agreement in place between Customer and Release Management covering Customer’s use of the Services.

(c) “Applicable Data Protection Law” means all data protection laws and regulations applicable to the processing of personal data under this DPA, including, but not limited to, the Australian Data Protection Law, Brazilian Data Protection Law, European Data Protection Law, Japanese Data Protection Law, and U.S. Data Protection Law.

(d) “Brazilian Data Protection Law” means the Brazilian General Data Protection Law No. 13,709/2018 (“LGPD”).

(e) “controller”, “processor”, “data subject”, “personal data”, “personal information”, “processing” (and “process”), “commercial purpose”, and “service provider” have the meanings given in Applicable Data Protection Law, as appropriate.

(f) “Customer Personal Data” means any personal data provided by (or on behalf of) Customer to Release Management in connection with the Services, all as further described in Exhibit A, Part A of this DPA.

(g) “Deidentified Data” means data that cannot reasonably be used to infer information about, or otherwise be linked to, a data subject.

(h) “End Users” or “Users” means an individual the Customer permits or invites to use the Release Management Products. For the avoidance of doubt: (a) individuals invited by End Users, (b) individuals under managed accounts, and (c) individuals interacting with a Release Management Product as Customer`s customers are also considered End Users.

(i) “Europe” means, for the purposes of this DPA, the Member States of the European Economic Area (“EEA”), the United Kingdom (“UK”) and Switzerland.

(j) “European Data Protection Law” means: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (“EU GDPR”); (ii) in respect of the United Kingdom the Data Protection Act 2018 and the EU GDPR as saved into United Kingdom law by virtue of Section 3 of the United Kingdom's European Union (Withdrawal) Act 2018 (“UK Data Protection Law”); (iii) the EU e-Privacy Directive (Directive 2002/58/EC); and (iv) the Swiss Federal Act on Data Protection and its implementing regulations (“Swiss FADP”), in each case as may be amended, superseded or replaced from time to time.

(k) “Japanese Data Protection Law” means the Japanese Act on the Protection of Personal Information.

(l) “Restricted Transfer” means a transfer (directly or via onward transfer) of personal data subject to European Data Protection Law from Europe to a country outside of Europe that is not subject to an adequacy decision by the European Commission, or the competent UK or Swiss authorities (as applicable).

(m) “Security Incident” means any breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Customer Data processed by Release Management and/or its Sub- processors in connection with the provision of the Services. For the avoidance of doubt, "Security Incident" does not include unsuccessful attempts or activities that do not compromise the security of Customer Data, including unsuccessful login attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems.

(n) “Services” means the provision of the products and services by Release Management to Customer pursuant to the Agreement.

(o) “special categories of personal data” or “sensitive data” means any Customer Personal Data (i) revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, (ii) that is genetic data, biometric data processed for the purposes of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation, and (iii) relating to criminal convictions and offences.

(p) “Standard Contractual Clauses” or “EU SCCs” means the contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.

(q) “Sub-processor” means any other processor engaged by Release Management in its role as a processor to assist in fulfilling its obligations with respect to providing the Services pursuant to the Agreement or this DPA where such entity processes Customer Personal Data. Sub-processors may include Release Management’s affiliates or other third parties.

(r) “UK Addendum” means the International Data Transfer Addendum (version B1.0) issued by the Information Commissioner's Office under S119(A) of the UK Data Protection Act 2018, as may be amended, superseded, or replaced from time to time.

(s) “U.S. Data Protection Law” means all state laws in effect in the United States of America that are applicable to the processing of personal data under this DPA, including, but not limited to, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and the Utah Consumer Privacy Act.

...

iii. in Clause 9, Option 2 will apply, and the time period for prior notice of Sub-processor changes will be as set out in Section 2.10 of this DPA;

iv. in Clause 11, the optional language will not apply;

...

vii. Annex I of the EU SCCs is deemed completed with the information set out in Exhibit A to this DPA, as applicable; and

viii. Subject to Section 2.8 of this DPA, Annex II of the EU SCCs is deemed completed with the information set out in Exhibit B to this DPA;

...

vi. Annex I of the EU SCCs is deemed completed with the information set out in Exhibit A to this DPA, as applicable; and

vii. Subject to Section 2.8 of this DPA, Annex II of the EU SCCs is deemed completed with the information set out in Exhibit B to this DPA;

(c) In relation to transfers of personal data governed by UK Data Protection Law, the EU SCCs: (i) apply as completed in accordance with paragraphs (a) and (b) above; and (ii) are deemed amended as specified by the UK Addendum, which is deemed executed by the parties and incorporated into and forming an integral part of this DPA. In addition, Tables 1 to 2 in Part 1 of the UK Addendum is deemed completed respectively with the information set out in Section 2.9, as well as Exhibits A and B of this DPA; Any conflict between the terms of the EU SCCs and the UK Addendum will be resolved in accordance with Section 10 and Section 11 of the UK Addendum.

...

Release Management and, to the extent required under the Agreement, Customer must implement appropriate technical and organizational measures in accordance with Applicable Data Protection Law (e.g., Art. 32 GDPR) to protect Customer Personal Data from Security Incidents and to preserve the security and confidentiality of the Customer Personal Data. Release Management’s current technical and organizational measures are described in Exhibit B (“Security Measures”). Customer acknowledges that the Security Measures are subject to technical progress and development and that Release Management may update or modify the Security Measures from time to time, provided that such updates and modifications do not materially decrease the overall security of the Services.

...

All Cloud and DC Products

Release Management as a processor or sub-processor

Categories of data subjects

Customer, Customers' employees (namely Technical and Billing Contacts specified) , Customers' partners (namely Atlassian Solution Partners) on behalf of the Customer/Atlassian.

Categories of personal data transferred

Technical and Billing Contacts Information, for example:

  • Full name

  • Email address

  • Office / address

  • Office / phone number

  • Company / organization

  • Company web-site URL

Customers' Atlassian Solution Partner, for example:

  • Full name

  • Email address

  • Company / organization

  • Company web-site URL

Additional Release Management/Atlassian Product license information, for example:

  • App entitlement id and number

  • Host entitlement id and number

  • Host product edition and frequency of renewals

  • License type and status

  • License start and end dates

  • License tier

Sensitive data transferred?

(as defined in Section 2.1)

None

Frequency of the transfer

Daily

Nature of the processing

The nature of the processing (incl. transfer) is the following: export from Atlassian Marketplace (controller or processor), secure transit and import into PLG CRM tools (sub-processor) for the purpose defined below.

Purpose of the data transfer

The purpose of data processing (incl. transfer) is the following:

  • Update Customers about new important features and capabilities delivered

  • Provide support and services to Customers

  • Update Customer about important terms and conditions changed (including pricing tier upgrades), changes to EULA, DPA, Sub-processors list, other policies, etc.

  • Informing Customers about P0, P1 incidents (including security incidents), remediate actions taken and time to resolution, follow up with root cause analysis delivered according to Security Vulnerabilities Process

Duration of processing

Data will be deleted upon request according to Data Deletion Policy in accordance with Section 2.13 of this DPA

...

Release Management and Roadmaps for Jira Cloud

Release Management as a processor

Marketplace Listing, Documentation Space

Categories of data subjects

Customer, Customers' employees, Customers' collaborators, as well as all relevant End Users of the Services on behalf of the Customer.

Categories of personal data transferred

Personal data relating to or obtained in connection with the operation, support or use of the “Release Management and Roadmaps“ Product, e.g.:

For any user generated content submitted, Release Management acts as a processor of such personal data and Sections 2.2(a) as well as 2.6(a) DPA apply accordingly.

Board Configuration (for Admins only), for example:

  • Jira Project IDs

  • Atlassian User IDs, Groups IDs for Permission Management

  • Jira standard and custom datetime field IDs for Epics Sync

  • Free-text* titles of Versions and Packages workflow steps

  • Automation rules configurations including URLs, Headers, Bodies definition that might include authorization tokens

  • Free-text* custom properties names

  • Version defaults configuration including free-text* names and descriptions as well as milestones names and descriptions as free-text*

  • Definitions of backlout periods that includes free-text* name and dates

Board Usage (could be segregated for Manage and Read Only permissions), for example:

  • Jira Version IDs, Epic IDs, Sprint IDs plus plain JQL* for JQL-based versions, User IDs, Atlassian Compass & Jira Classic Component IDs

  • Free-text* versions and packages names, descriptions, comments, custom properties and milestones names/descriptions + appropriate package templates

  • Encrypted Api Tokens (https://id.atlassian.com/manage-profile/security/api-tokens) if configured to access “Commits/Deployments/Environments” information and/or “Upload to Confluence“ release notes

  • Release notes templates that are combinations of a bunch of Free-text* sections and plain JQL* tables

  • Free-text* deployment environments names and descriptions

  • Free-text* Classic Component names and descriptions

free text*/plain JQL*

Customer as controller of the data has to assure implementation of internal policies so that there is no sensitive data (as defined in Section 2.1) being submitted to above mentioned free text fields and plain JQL. Implemented permission model allows to shortlist users that can enter/alter these free text fields and plain JQL.

Sensitive data transferred?

(as defined in Section 2.1)

None

Frequency of the transfer

Continuous

Nature of the processing

Processing of relevant personal data for the purposes identified below

Purpose of the data transfer

Personal data will be processed for Release Management’s legitimate business purposes. This entails in particular the following:

  • Create multiple custom Release Management Boards with predefined workflows, restrictions and automations.

  • Create different type of versions (component releases) and package it into “business releases“, process both through workflows asuring configured quality gateways and approval processes

  • Create release notes according to pre-defined templates

  • Manage and orchestrate deployment environments

  • Manage and orchestrate cross-project components

  • Provide insights about releases health, projected delivery dates and reasons for delays, etc.

Duration of processing

Data will be deleted upon request according to Data Deletion Policy in accordance with Section 2.13 of this DPA

...

Advanced Kanban & Agile Boards for Jira Cloud

Release Management as a processor

Marketplace Listing, Documentation Space

Categories of data subjects

Customer, Customers' employees, Customers' collaborators, as well as all relevant End Users of the Services on behalf of the Customer.

Categories of personal data transferred

Personal data relating to or obtained in connection with the operation, support or use of the “Advanced Kanban & Agile Boards“ Product, e.g.:

For any user generated content submitted, Release Management acts as a processor of such personal data and Sections 2.2(a) as well as 2.6(a) DPA apply accordingly.

Board Configuration (for Admins only), for example:

  • Jira Project IDs

  • Atlassian User IDs, Groups IDs for Permission Management

  • Plain JQL* to shortlist scope of the board

  • Jira standard and custom fields IDs when used as Columns and/or Swimlanes

Board Usage (could be segregated for Manage and Read Only permissions), for example:

  • Column and/or Swimlane names derived from Jira standard or custom fields values or free-text* title aliases

  • Column and Swimlane descriptions that are free-text* fields

  • Atlassian User IDs, Version IDs, Sprint IDs, Component IDs, Jira Issue IDs if used as columns and/or swimlanes

  • Column Group names that are free-text* fields

  • Quick filters aliases that are free-text* fields and plain JQL* definitions of quick filters

free text*/plain JQL*

Customer as controller of the data has to assure implementation of internal policies so that there is no sensitive data (as defined in Section 2.1) being submitted to above mentioned free text fields and plain JQL. Implemented permission model allows to shortlist users that can enter/alter these free text fields and plain JQL.

Sensitive data transferred?

(as defined in Section 2.1)

None

Frequency of the transfer

Continuous

Nature of the processing

Processing of relevant personal data for the purposes identified below

Purpose of the data transfer

Personal data will be processed for Release Management’s legitimate business purposes. This entails in particular the following:

  • Create multiple custom Kanban & Agile boards with flexible columns and/or swimlanes configurations

  • Provide descriptions of the SDLC statuses / exit criterias / quality gates

  • Manage Jira issues and hierarchy of Jira issues through SDLC lifecycle (including but not limited by managing Versions, Components, Sprints, Parent Jira Issues where Jira Issues attached to)

  • Package columns in Column Groups

  • Outline Dependencies, Statistics, etc.

  • Filter Jira issues via quick filters

  • Define and manage work-in-progress (WIP) limits

  • Define and manage Aging  limits

Duration of processing

Data will be deleted upon request according to Data Deletion Policy in accordance with Section 2.13 of this DPA

...

Release Gadgets for Jira Cloud

Release Management as a processor

Marketplace Listing, Documentation Space

Categories of data subjects

Customer, Customers' employees, Customers' collaborators, as well as all relevant End Users of the Services on behalf of the Customer.

Categories of personal data transferred

Personal data relating to or obtained in connection with the operation, support or use of the “Release Gadgets“ Product, e.g.:

For any user generated content submitted, Release Management acts as a processor of such personal data and Sections 2.2(a) as well as 2.6(a) DPA apply accordingly.

Gadgets Configuration, for example:

  • Free-text* gadgets scope names

  • Jira Project IDs

  • Jira Version IDs

  • Plain JQL* to shortlist scope of the gadget

free text*/plain JQL*

Customer as controller of the data has to assure implementation of internal policies so that there is no sensitive data (as defined in Section 2.1) being submitted to above mentioned free text fields and plain JQL. Implemented permission model allows to shortlist users that can enter/alter these free text fields and plain JQL.

Sensitive data transferred?

(as defined in Section 2.1)

None

Frequency of the transfer

Continuous

Nature of the processing

Processing of relevant personal data for the purposes identified below

Purpose of the data transfer

Personal data will be processed for Release Management’s legitimate business purposes. This entails in particular the following:

  • Visualise portfolio of releases

  • Outline release progress and status.

  • Show release delays and reasons for it.

Duration of processing

Data will be deleted upon request according to Data Deletion Policy in accordance with Section 2.13 of this DPA

...

Time in Status Calendar & Worklog Roadmap for Jira Cloud

Release Management as a processor

Marketplace Listing, Documentation Space

Categories of data subjects

Customer, Customers' employees, Customers' collaborators, as well as all relevant End Users of the Services on behalf of the Customer.

Categories of personal data transferred

Personal data relating to or obtained in connection with the operation, support or use of the “Time in Status Calendar & Worklog Roadmap“ Product, e.g.:

For any user generated content submitted, Release Management acts as a processor of such personal data and Sections 2.2(a) as well as 2.6(a) DPA apply accordingly.

Changelog Calendar Configuration, for example:

  • Jira Project IDs

  • Plain JQL* to shortlist scope of the calendar

  • Jira standard and custom datetime field IDs

  • Jira issues workflows steps IDs

Changelog Calendar Usage (could be segregated for Manage and Read Only permissions), for example:

  • Quick filters aliases that are free-text* fields and plain JQL* definitions of quick filters

  • Free-text* worklog comments & descriptions

free text*/plain JQL*

Customer as controller of the data has to assure implementation of internal policies so that there is no sensitive data (as defined in Section 2.1) being submitted to above mentioned free text fields and plain JQL. Implemented permission model allows to shortlist users that can enter/alter these free text fields and plain JQL.

Sensitive data transferred?

(as defined in Section 2.1)

None

Frequency of the transfer

Continuous

Nature of the processing

Processing of relevant personal data for the purposes identified below

Purpose of the data transfer

Personal data will be processed for Release Management’s legitimate business purposes. This entails in particular the following:

  • Outline Jira issues on Calendar and Roadmap view.

  • Show progress according to color coded status changes and worklog made

Duration of processing

Data will be deleted upon request according to Data Deletion Policy in accordance with Section 2.13 of this DPA

...

Easy Delivery Roadmaps for Jira Cloud

Release Management as a processor

Marketplace Listing, Documentation Space

Categories of data subjects

Customer, Customers' employees, Customers' collaborators, as well as all relevant End Users of the Services on behalf of the Customer.

Categories of personal data transferred

Personal data relating to or obtained in connection with the operation, support or use of the “Easy Delivery Roadmaps“ Product, e.g.:

For any user generated content submitted, Release Management acts as a processor of such personal data and Sections 2.2(a) as well as 2.6(a) DPA apply accordingly.

Plan Configuration (for Admins only), for example:

  • Jira Project IDs

  • Atlassian User IDs, Groups IDs for Permission Management

  • Jira standard and custom datetime field IDs for Epics Sync

  • Definitions of backlout periods that includes free-text* name and dates

Plan Usage (could be segregated for Manage and Read Only permissions), for example:

  • Jira Version IDs, Epic IDs, Sprint IDs plus plain JQL* for JQL-based versions and User IDs

  • Free-text* versions names, descriptions, comments and milestones names/descriptions

free text*/plain JQL*

Customer as controller of the data has to assure implementation of internal policies so that there is no sensitive data (as defined in Section 2.1) being submitted to above mentioned free text fields and plain JQL. Implemented permission model allows to shortlist users that can enter/alter these free text fields and plain JQL.

Sensitive data transferred?

(as defined in Section 2.1)

None

Frequency of the transfer

Continuous

Nature of the processing

Processing of relevant personal data for the purposes identified below

Purpose of the data transfer

Personal data will be processed for Release Management’s legitimate business purposes. This entails in particular the following:

  • Create multiple custom Delivery Plans.

  • Create different type of deliverables - versions, epics, sprints, JQL versions

  • Outline deliverables om Roadmap and Calendar views

  • Manage intermediate milestones

  • Provide insights about deliverables health, projected delivery dates and reasons for delays, etc.

Duration of processing

Data will be deleted upon request according to Data Deletion Policy in accordance with Section 2.13 of this DPA

...