...
History
| Change History |
|---|
Topics
| Table of Contents | ||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
...
Release Management Data Processing Addendum
IMPORTANT! BE SURE TO CAREFULLY READ AND UNDERSTAND ALL OF THE RIGHTS AND RESTRICTIONS SET FORTH IN THIS DATA PROCESSING ADDENDUM (“DPA”). YOU ARE NOT AUTHORIZED TO USE THIS SOFTWARE UNLESS AND UNTIL YOU ACCEPT THE TERMS OF THIS DPA.
...
In this DPA, the following terms have the following meanings:
| Expand | ||||
|---|---|---|---|---|
| ||||
(a) “Australian Data Protection Law” means the Australian Privacy Act 1988 (Cth). (b) “Agreement” means the agreement in place between Customer and Release Management covering Customer’s use of the Services. (c) “Applicable Data Protection Law” means all data protection laws and regulations applicable to the processing of personal data under this DPA, including, but not limited to, the Australian Data Protection Law, Brazilian Data Protection Law, European Data Protection Law, Japanese Data Protection Law, and U.S. Data Protection Law. (d) “Brazilian Data Protection Law” means the Brazilian General Data Protection Law No. 13,709/2018 (“LGPD”). (e) “controller”, “processor”, “data subject”, “personal data”, “personal information”, “processing” (and “process”), “commercial purpose”, and “service provider” have the meanings given in Applicable Data Protection Law, as appropriate. (f) “Customer Personal Data” means any personal data provided by (or on behalf of) Customer to Release Management in connection with the Services, all as further described in Exhibit A, Part A of this DPA. (g) “Deidentified Data” means data that cannot reasonably be used to infer information about, or otherwise be linked to, a data subject. (h) “End Users” or “Users” means an individual the Customer permits or invites to use the Release Management Products. For the avoidance of doubt: (a) individuals invited by End Users, (b) individuals under managed accounts, and (c) individuals interacting with a Release Management Product as Customer`s customers are also considered End Users. (i) “Europe” means, for the purposes of this DPA, the Member States of the European Economic Area (“EEA”), the United Kingdom (“UK”) and Switzerland. (j) “European Data Protection Law” means: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (“EU GDPR”); (ii) in respect of the United Kingdom the Data Protection Act 2018 and the EU GDPR as saved into United Kingdom law by virtue of Section 3 of the United Kingdom's European Union (Withdrawal) Act 2018 (“UK Data Protection Law”); (iii) the EU e-Privacy Directive (Directive 2002/58/EC); and (iv) the Swiss Federal Act on Data Protection and its implementing regulations (“Swiss FADP”), in each case as may be amended, superseded or replaced from time to time. (k) “Japanese Data Protection Law” means the Japanese Act on the Protection of Personal Information. (l) “Restricted Transfer” means a transfer (directly or via onward transfer) of personal data subject to European Data Protection Law from Europe to a country outside of Europe that is not subject to an adequacy decision by the European Commission, or the competent UK or Swiss authorities (as applicable). (m) “Security Incident” means any breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Customer Data processed by Release Management and/or its Sub- processors in connection with the provision of the Services. For the avoidance of doubt, "Security Incident" does not include unsuccessful attempts or activities that do not compromise the security of Customer Data, including unsuccessful login attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems. (n) “Services” means the provision of the products and services by Release Management to Customer pursuant to the Agreement. (o) “special categories of personal data” or “sensitive data” means any Customer Personal Data (i) revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, (ii) that is genetic data, biometric data processed for the purposes of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation, and (iii) relating to criminal convictions and offences. (p) “Standard Contractual Clauses” or “EU SCCs” means the contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council. (q) “Sub-processor” means any other processor engaged by Release Management in its role as a processor to assist in fulfilling its obligations with respect to providing the Services pursuant to the Agreement or this DPA where such entity processes Customer Personal Data. Sub-processors may include Release Management’s affiliates or other third parties. (r) “UK Addendum” means the International Data Transfer Addendum (version B1.0) issued by the Information Commissioner's Office under S119(A) of the UK Data Protection Act 2018, as may be amended, superseded, or replaced from time to time. (s) “U.S. Data Protection Law” means all state laws in effect in the United States of America that are applicable to the processing of personal data under this DPA, including, but not limited to, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and the Utah Consumer Privacy Act. |
...
iii. in Clause 9, Option 2 will apply, and the time period for prior notice of Sub-processor changes will be as set out in Section 2.10 of this DPA;
iv. in Clause 11, the optional language will not apply;
...
vii. Annex I of the EU SCCs is deemed completed with the information set out in Exhibit A to this DPA, as applicable; and
viii. Subject to Section 2.8 of this DPA, Annex II of the EU SCCs is deemed completed with the information set out in Exhibit B to this DPA;
...
vi. Annex I of the EU SCCs is deemed completed with the information set out in Exhibit A to this DPA, as applicable; and
vii. Subject to Section 2.8 of this DPA, Annex II of the EU SCCs is deemed completed with the information set out in Exhibit B to this DPA;
(c) In relation to transfers of personal data governed by UK Data Protection Law, the EU SCCs: (i) apply as completed in accordance with paragraphs (a) and (b) above; and (ii) are deemed amended as specified by the UK Addendum, which is deemed executed by the parties and incorporated into and forming an integral part of this DPA. In addition, Tables 1 to 2 in Part 1 of the UK Addendum is deemed completed respectively with the information set out in Section 2.9, as well as Exhibits A and B of this DPA; Any conflict between the terms of the EU SCCs and the UK Addendum will be resolved in accordance with Section 10 and Section 11 of the UK Addendum.
...
Release Management and, to the extent required under the Agreement, Customer must implement appropriate technical and organizational measures in accordance with Applicable Data Protection Law (e.g., Art. 32 GDPR) to protect Customer Personal Data from Security Incidents and to preserve the security and confidentiality of the Customer Personal Data. Release Management’s current technical and organizational measures are described in Exhibit B (“Security Measures”). Customer acknowledges that the Security Measures are subject to technical progress and development and that Release Management may update or modify the Security Measures from time to time, provided that such updates and modifications do not materially decrease the overall security of the Services.
...
All Cloud and DC ProductsRelease Management as a processor or sub-processor | |
|---|---|
Categories of data subjects | Customer, Customers' employees (namely Technical and Billing Contacts specified) , Customers' partners (namely Atlassian Solution Partners) on behalf of the Customer/Atlassian. |
Categories of personal data transferred | Technical and Billing Contacts Information, for example:
Customers' Atlassian Solution Partner, for example:
Additional Release Management/Atlassian Product license information, for example:
|
Sensitive data transferred? (as defined in Section 2.1) | None |
Frequency of the transfer | Daily |
Nature of the processing | The nature of the processing (incl. transfer) is the following: export from Atlassian Marketplace (controller or processor), secure transit and import into PLG CRM tools (sub-processor) for the purpose defined below. |
Purpose of the data transfer | The purpose of data processing (incl. transfer) is the following:
|
Duration of processing | Data will be deleted upon request according to Data Deletion Policy in accordance with Section 2.13 of this DPA |
...
Release Management and Roadmaps for Jira CloudRelease Management as a processor | |
|---|---|
Categories of data subjects | Customer, Customers' employees, Customers' collaborators, as well as all relevant End Users of the Services on behalf of the Customer. |
Categories of personal data transferred | Personal data relating to or obtained in connection with the operation, support or use of the “Release Management and Roadmaps“ Product, e.g.: For any user generated content submitted, Release Management acts as a processor of such personal data and Sections 2.2(a) as well as 2.6(a) DPA apply accordingly. Board Configuration (for Admins only), for example:
Board Usage (could be segregated for Manage and Read Only permissions), for example:
free text*/plain JQL* Customer as controller of the data has to assure implementation of internal policies so that there is no sensitive data (as defined in Section 2.1) being submitted to above mentioned free text fields and plain JQL. Implemented permission model allows to shortlist users that can enter/alter these free text fields and plain JQL. |
Sensitive data transferred? (as defined in Section 2.1) | None |
Frequency of the transfer | Continuous |
Nature of the processing | Processing of relevant personal data for the purposes identified below |
Purpose of the data transfer | Personal data will be processed for Release Management’s legitimate business purposes. This entails in particular the following:
|
Duration of processing | Data will be deleted upon request according to Data Deletion Policy in accordance with Section 2.13 of this DPA |
...
Advanced Kanban & Agile Boards for Jira CloudRelease Management as a processor | |
|---|---|
Categories of data subjects | Customer, Customers' employees, Customers' collaborators, as well as all relevant End Users of the Services on behalf of the Customer. |
Categories of personal data transferred | Personal data relating to or obtained in connection with the operation, support or use of the “Advanced Kanban & Agile Boards“ Product, e.g.: For any user generated content submitted, Release Management acts as a processor of such personal data and Sections 2.2(a) as well as 2.6(a) DPA apply accordingly. Board Configuration (for Admins only), for example:
Board Usage (could be segregated for Manage and Read Only permissions), for example:
free text*/plain JQL* Customer as controller of the data has to assure implementation of internal policies so that there is no sensitive data (as defined in Section 2.1) being submitted to above mentioned free text fields and plain JQL. Implemented permission model allows to shortlist users that can enter/alter these free text fields and plain JQL. |
Sensitive data transferred? (as defined in Section 2.1) | None |
Frequency of the transfer | Continuous |
Nature of the processing | Processing of relevant personal data for the purposes identified below |
Purpose of the data transfer | Personal data will be processed for Release Management’s legitimate business purposes. This entails in particular the following:
|
Duration of processing | Data will be deleted upon request according to Data Deletion Policy in accordance with Section 2.13 of this DPA |
...
Release Gadgets for Jira CloudRelease Management as a processor | |
|---|---|
Categories of data subjects | Customer, Customers' employees, Customers' collaborators, as well as all relevant End Users of the Services on behalf of the Customer. |
Categories of personal data transferred | Personal data relating to or obtained in connection with the operation, support or use of the “Release Gadgets“ Product, e.g.: For any user generated content submitted, Release Management acts as a processor of such personal data and Sections 2.2(a) as well as 2.6(a) DPA apply accordingly. Gadgets Configuration, for example:
free text*/plain JQL* Customer as controller of the data has to assure implementation of internal policies so that there is no sensitive data (as defined in Section 2.1) being submitted to above mentioned free text fields and plain JQL. Implemented permission model allows to shortlist users that can enter/alter these free text fields and plain JQL. |
Sensitive data transferred? (as defined in Section 2.1) | None |
Frequency of the transfer | Continuous |
Nature of the processing | Processing of relevant personal data for the purposes identified below |
Purpose of the data transfer | Personal data will be processed for Release Management’s legitimate business purposes. This entails in particular the following:
|
Duration of processing | Data will be deleted upon request according to Data Deletion Policy in accordance with Section 2.13 of this DPA |
...
Time in Status Calendar & Worklog Roadmap for Jira CloudRelease Management as a processor | |
|---|---|
Categories of data subjects | Customer, Customers' employees, Customers' collaborators, as well as all relevant End Users of the Services on behalf of the Customer. |
Categories of personal data transferred | Personal data relating to or obtained in connection with the operation, support or use of the “Time in Status Calendar & Worklog Roadmap“ Product, e.g.: For any user generated content submitted, Release Management acts as a processor of such personal data and Sections 2.2(a) as well as 2.6(a) DPA apply accordingly. Changelog Calendar Configuration, for example:
Changelog Calendar Usage (could be segregated for Manage and Read Only permissions), for example:
free text*/plain JQL* Customer as controller of the data has to assure implementation of internal policies so that there is no sensitive data (as defined in Section 2.1) being submitted to above mentioned free text fields and plain JQL. Implemented permission model allows to shortlist users that can enter/alter these free text fields and plain JQL. |
Sensitive data transferred? (as defined in Section 2.1) | None |
Frequency of the transfer | Continuous |
Nature of the processing | Processing of relevant personal data for the purposes identified below |
Purpose of the data transfer | Personal data will be processed for Release Management’s legitimate business purposes. This entails in particular the following:
|
Duration of processing | Data will be deleted upon request according to Data Deletion Policy in accordance with Section 2.13 of this DPA |
...
Easy Delivery Roadmaps for Jira CloudRelease Management as a processor | |
|---|---|
Categories of data subjects | Customer, Customers' employees, Customers' collaborators, as well as all relevant End Users of the Services on behalf of the Customer. |
Categories of personal data transferred | Personal data relating to or obtained in connection with the operation, support or use of the “Easy Delivery Roadmaps“ Product, e.g.: For any user generated content submitted, Release Management acts as a processor of such personal data and Sections 2.2(a) as well as 2.6(a) DPA apply accordingly. Plan Configuration (for Admins only), for example:
Plan Usage (could be segregated for Manage and Read Only permissions), for example:
free text*/plain JQL* Customer as controller of the data has to assure implementation of internal policies so that there is no sensitive data (as defined in Section 2.1) being submitted to above mentioned free text fields and plain JQL. Implemented permission model allows to shortlist users that can enter/alter these free text fields and plain JQL. |
Sensitive data transferred? (as defined in Section 2.1) | None |
Frequency of the transfer | Continuous |
Nature of the processing | Processing of relevant personal data for the purposes identified below |
Purpose of the data transfer | Personal data will be processed for Release Management’s legitimate business purposes. This entails in particular the following:
|
Duration of processing | Data will be deleted upon request according to Data Deletion Policy in accordance with Section 2.13 of this DPA |
...