Techanics Data Processing Addendum (DPA)

Version 1.0 – Last updated: August 2026

This Data Processing Agreement (“DPA”), including its Annexes, governs the processing of personal data by Techanics GmbH on behalf of customers in connection with Techanics software applications for Atlassian products, including but not limited to User Magic for Jira, Bulk User Actions and Smart Label Manager for Confluence (collectively, the “Services”).

This DPA forms part of the agreement governing the Customer’s acquisition or use of the relevant Service, including any applicable end user agreement, Provider-Specific Terms, order, subscription or other agreement between the Customer and Techanics.

This DPA applies only to the extent that Techanics processes Personal Data on behalf of the Customer in connection with a Service and such processing falls within the processing framework described in Annex 1.

This DPA becomes binding only where it is expressly incorporated into or linked from an Agreement accepted by the Customer, or where it is otherwise validly agreed between the Parties. Merely accessing this webpage does not by itself create a contractual relationship.


1. Parties and scope

a) Customer

The Customer is the legal entity that acquires, installs or uses the relevant Service under the Agreement.

Where an individual accepts the Agreement on behalf of a company, organisation or public body, that entity is the Customer for the purposes of this DPA.

The Customer’s contact details are those stated in the Agreement, order, Atlassian Marketplace account or other applicable contractual documentation.

b) Techanics

The Processor is:

Techanics GmbH
Am Hoffeld 2
83703 Gmund am Tegernsee
Germany

Email: info [at] techanics.de

Commercial Register: HRB 289565
Register Court: Munich
VAT ID: DE365855756

Privacy and data processing enquiries may be sent to the contact details stated above.

c) Processing covered by this DPA

This DPA applies to the extent that Techanics processes Customer Personal Data on behalf of the Customer in connection with the Services.

It applies in particular to:

  • automated processing performed through the documented functions of the Services within the processing framework described in Annex 1
  • storage of app configuration and Protected Credentials where required for such functions
  • technical logging and diagnostics performed in connection with the Services
  • Customer Personal Data voluntarily submitted by the Customer for technical support where Techanics processes that information solely to investigate or resolve a problem concerning the Services on the Customer’s behalf

d) Processing not covered by this DPA

This DPA does not apply to processing activities for which Techanics independently determines the purposes and means and therefore acts as Controller.

Such separate processing includes in particular:

  • the management of technical Atlassian Marketplace contacts
  • app-related support and operational service communication through Brevo
  • the technical synchronisation of Marketplace contact information
  • the general administration of support portal accounts and support relationships
  • legal, privacy, contractual, billing and general business communication

These separate processing activities are described in the Privacy Policy for Techanics Apps.


2. Definitions and roles

a) Definitions

For the purposes of this DPA:

  • Agreement means the agreement governing the Customer’s acquisition or use of the Services.
  • Applicable Data Protection Law means the General Data Protection Regulation and any national data protection law applicable to the processing covered by this DPA.
  • Customer Personal Data means Personal Data processed by Techanics on behalf of the Customer through the Services or submitted to Techanics for requested technical support where Techanics acts on behalf of the Customer.
  • Documented Instructions means the Agreement, this DPA, the Customer’s installation, configuration and authorised use of the Services and any additional lawful written instruction accepted by Techanics.
  • Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Personal Data.
  • Protected Credential means an organisation API token, API key, authentication secret or comparable credential provided or configured by the Customer for use with a Service.
  • Services means the Techanics cloud software applications for Atlassian products covered by the Agreement, including but not limited to User Magic for Jira, Bulk User Actions and Smart Label Manager for Confluence. For the purposes of this DPA, a Service is covered only to the extent that Techanics processes Customer Personal Data on behalf of the Customer and such processing falls within the processing framework described in Annex 1.
  • Subprocessor means another processor engaged by Techanics to process Customer Personal Data on behalf of the Customer.

The terms Controller, Processor, Data Subject, Personal Data and Processing have the meanings assigned to them under Applicable Data Protection Law.

b) Customer as Controller

For the processing covered by this DPA, the Customer generally acts as Controller and Techanics acts as Processor.

The Customer determines in particular:

  • the purposes for which the Services are used
  • which Atlassian users, accounts, groups, organisations, content objects or other supported Atlassian resources are processed
  • which supported administrative or organisational actions are initiated
  • who is authorised to install, configure and operate the Services
  • the legal basis for the processing

c) Customer acting as Processor

Where the Customer processes Customer Personal Data on behalf of another Controller, the Customer acts as Processor and Techanics acts as a Subprocessor in relation to that processing.

In that case, the Customer confirms that:

  • it is authorised by the relevant Controller to engage Techanics
  • its instructions to Techanics are consistent with the instructions of that Controller
  • it will provide the relevant Controller with the information required concerning Techanics and its Subprocessors

d) Techanics as Processor

Techanics processes Customer Personal Data only on behalf of the Customer, for the purposes described in Annex 1 and in accordance with the Customer’s Documented Instructions.

The fact that the Services process data automatically and are operated by authorised Customer users does not change the allocation of roles between the Parties.


3. Details and duration of processing

The subject matter, duration, nature and purposes of the processing, the categories of Customer Personal Data and the categories of Data Subjects are set out in Annex 1.

The processing continues for the duration of the Agreement and for as long as Techanics or an authorised Subprocessor processes Customer Personal Data on behalf of the Customer.

Obligations concerning confidentiality, security, deletion and the protection of Customer Personal Data continue to apply for as long as Customer Personal Data remains in processing or retention systems.


4. Documented Instructions and Customer responsibilities

a) Scope of the instructions

Techanics will process Customer Personal Data only:

  • on behalf of the Customer
  • for the purposes described in the Agreement and Annex 1
  • in accordance with the Customer’s Documented Instructions
  • as otherwise required by applicable European Union or Member State law

The Customer’s acquisition, installation, configuration and authorised use of a Service constitute Documented Instructions for the processing necessary to provide the documented functionality of that Service.

The Customer’s acquisition, installation or use of one Service does not instruct or authorise Techanics to process Customer Personal Data solely for the functionality of another Service that the Customer has not acquired or used.

The Customer also instructs Techanics to engage the Subprocessors identified in Annex 3 and to permit the processing and international transfers required to provide the Services in accordance with this DPA.

b) Additional instructions

Additional instructions must be submitted in writing and must relate to the processing covered by this DPA.

Techanics will assess whether an additional instruction is lawful, technically feasible and consistent with the Services.

Where an instruction requires a material change to the Services or substantial work outside their normal operation, the Parties may agree separately on its implementation, timing and reasonable costs.

c) Processing required by law

Where Techanics is required by applicable European Union or Member State law to process Customer Personal Data other than on the Customer’s instructions, Techanics will inform the Customer before the processing unless the law prohibits such information on important grounds of public interest.

d) Instructions that may infringe data protection law

Techanics will inform the Customer without undue delay if, in its reasonable opinion, a Documented Instruction infringes Applicable Data Protection Law.

Techanics may suspend the affected processing until the Customer confirms, modifies or withdraws the instruction.

e) Customer responsibilities

The Customer is responsible for ensuring that its use of the Services and its instructions to Techanics comply with Applicable Data Protection Law.

The Customer is responsible in particular for:

  • establishing and documenting an appropriate legal basis
  • providing legally required privacy information to Data Subjects
  • obtaining any legally required consents or authorisations
  • ensuring that only authorised persons install, configure and operate the Services
  • configuring access rights and permissions appropriately
  • ensuring the accuracy, relevance and lawfulness of Customer Personal Data
  • protecting its Atlassian accounts and Protected Credentials

f) Special categories of Personal Data

The Services are not designed to require or intentionally process special categories of Personal Data under Article 9 GDPR or Personal Data relating to criminal convictions and offences under Article 10 GDPR.

Incidental processing cannot be completely excluded where Customer-defined user, group, label, configuration or comparable metadata or information voluntarily submitted for support itself contains or reveals such information.

The Customer will avoid including such information unless the processing is lawful, necessary and covered by appropriate safeguards and Documented Instructions.


5. Obligations of Techanics

a) Purpose limitation

Techanics will process Customer Personal Data only for the purposes covered by the Customer’s Documented Instructions.

Techanics will not use Customer Personal Data processed under this DPA for:

  • advertising or direct marketing
  • behavioural profiling
  • sale of data
  • unrelated analytics
  • other independent commercial purposes

b) Data minimisation

Techanics will limit the processing to the categories and scope required to provide the documented functions of the relevant Service.

App permissions and Atlassian API access are limited to the permissions required for those functions.

c) Atlassian Forge architecture

The core functions of the Services covered by the processing framework in Annex 1 are hosted and executed through Atlassian Forge.

Techanics does not operate a separate external application backend or external application database for those core functions.

A Service that materially departs from this architecture or requires processing outside the framework described in Annex 1 will not be treated as covered by that framework unless this DPA or appropriate additional terms are updated before such processing begins.

This does not affect the separate Controller activities described in the Privacy Policy for Techanics Apps.


6. Confidentiality and security

a) Confidentiality

Techanics will ensure that persons authorised to process Customer Personal Data:

  • process it only as necessary for their assigned tasks
  • are subject to an appropriate contractual or statutory duty of confidentiality
  • receive appropriate data protection and information security instructions
  • have access only for as long as required

b) Technical and organisational measures

Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of the processing and the risks to the rights and freedoms of Data Subjects, Techanics will implement and maintain appropriate technical and organisational measures in accordance with Article 32 GDPR.

The measures implemented or controlled by Techanics are described in Annex 2.

Infrastructure-level security measures implemented by Atlassian are governed by the applicable Atlassian data processing terms and security documentation referred to in Sections 7 and 12.

c) Changes to security measures

Techanics may update or replace individual technical and organisational measures to reflect technical development, changes to the Services or changes to the Atlassian platform.

Such changes will not materially reduce the overall level of protection for Customer Personal Data.


7. Atlassian and other Subprocessors

a) General authorisation

The Customer grants Techanics general written authorisation to engage the Subprocessors identified in Annex 3 for the purposes described there.

The authorisation also covers the onward Subprocessors engaged by Atlassian in accordance with the applicable Atlassian data processing terms and identified in Atlassian’s current Subprocessor list.

b) Atlassian Forge

Techanics uses Atlassian Forge to host and execute the core functions of the Services covered by this DPA.

To the extent Atlassian processes Customer Personal Data on behalf of Techanics through Forge-hosted compute, storage, logging or associated Forge platform services, Atlassian acts as a Subprocessor.

The relationship between Techanics and Atlassian for Forge processing is governed by the Forge Data Processing Addendum entered into between Techanics as the Forge developer and Atlassian:

Atlassian Forge Data Processing Addendum

The Forge Data Processing Addendum governs Atlassian’s obligations to Techanics concerning instructions, confidentiality, security, onward Subprocessors, Data Subject requests, security incidents, deletion, audits and international transfers.

The Customer does not become a party to the Forge Data Processing Addendum merely by accepting this DPA.

Techanics remains responsible to the Customer for the performance of its obligations under this DPA, including the obligations applicable to its Subprocessors under Article 28(4) GDPR.

c) Customer’s direct relationship with Atlassian

The Customer may also have a separate direct contractual relationship with Atlassian for Jira, Confluence and other Atlassian products.

Processing performed by Atlassian as part of the Customer’s direct use of those products may additionally be governed by the applicable agreement between the Customer and Atlassian.

Nothing in this DPA changes the allocation of responsibilities under that separate relationship.

d) Jira Service Management

Where the Customer voluntarily submits Customer Personal Data for technical support and Techanics processes that information solely on behalf of the Customer, Techanics may process the information through its Jira Service Management support environment.

Atlassian’s processing for Jira Service Management is governed by the Atlassian data processing terms applicable to Techanics’ Jira Service Management subscription:

Atlassian Data Processing Addendum

e) Obligations imposed on Subprocessors

Techanics will ensure that each direct Subprocessor is bound by written data protection obligations that provide substantially the same level of protection as the obligations applicable to Techanics under this DPA, to the extent relevant to the processing assigned to that Subprocessor.

Techanics remains responsible for the performance of its direct Subprocessors’ data protection obligations as required by Article 28(4) GDPR.

f) Changes to direct Subprocessors

Techanics will inform the Customer of an intended addition or replacement of a direct Subprocessor that will process Customer Personal Data.

Where reasonably practicable, Techanics will provide notice at least 14 days before the new direct Subprocessor begins processing Customer Personal Data.

Notice may be sent to the contractual, administrative or technical contact available to Techanics under the Agreement or through another active notification mechanism made available to the Customer.

g) Changes to Atlassian’s onward Subprocessors

Techanics will subscribe to or regularly review the applicable Atlassian Subprocessor notifications.

Techanics will make relevant changes concerning Atlassian’s onward Subprocessors available to the Customer without undue delay and, where reasonably possible, before the relevant Subprocessor begins processing Customer Personal Data.

Atlassian’s current Subprocessor list and notification mechanism are available at:

Atlassian Subprocessor List

h) Customer objection

The Customer may object to a new Subprocessor on reasonable grounds relating specifically to data protection.

The objection must be submitted within the period stated in the relevant notice or, where no period is stated, within 14 days after the Customer receives the notice.

The objection must explain the relevant data protection concern.

The Parties will work in good faith to identify a reasonable solution, which may include:

  • additional safeguards
  • a technically feasible alternative
  • restriction of the affected processing
  • raising the concern with Atlassian where the objection relates to an Atlassian onward Subprocessor

If no reasonable solution is available and the Service cannot be provided without the relevant Subprocessor, the Customer may terminate the affected Service in accordance with the Agreement.


8. Assistance to the Customer

a) Data Subject rights

Taking into account the nature of the processing, Techanics will assist the Customer through appropriate technical and organisational measures, insofar as reasonably possible, in responding to requests concerning the exercise of Data Subject rights under Applicable Data Protection Law.

The Customer will first use the administrative, account, correction, export and deletion capabilities available through Atlassian and the Services.

Where additional assistance is required, the Customer must provide sufficient information to identify the relevant Customer Personal Data and request.

b) Requests received directly by Techanics

If Techanics receives a Data Subject request relating to Customer Personal Data and the relevant Customer can be identified, Techanics will forward or redirect the request to the Customer without undue delay.

Techanics will not substantively respond on the Customer’s behalf unless authorised by the Customer or legally required to do so.

c) Assistance under Articles 32 to 36 GDPR

Taking into account the nature of the processing and the information available to Techanics, Techanics will provide reasonable assistance to the Customer in complying with its obligations concerning:

  • security of processing
  • assessment and notification of Personal Data Breaches
  • data protection impact assessments
  • prior consultation with a supervisory authority

The Customer will provide sufficient information concerning the requested assistance and the relevant processing activity.

d) Costs of assistance

Techanics will provide the standard information and reasonable cooperation required to comply with Article 28 GDPR without an additional charge.

Where a request requires exceptional, repetitive or disproportionately extensive work outside the normal operation of the Services and is not caused by a breach of this DPA by Techanics, the Parties may agree reasonable costs before the additional work begins.

Any cost arrangement will not prevent or unreasonably discourage the Customer from exercising its statutory rights.


9. Personal Data Breaches

Techanics will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data processed by Techanics or one of its Subprocessors.

Where Techanics receives relevant information concerning a Personal Data Breach from Atlassian or another Subprocessor, Techanics will forward the information required by the Customer without undue delay.

Taking into account the information available to Techanics, the notification will include or be supplemented with:

  • a description of the nature of the Personal Data Breach
  • the categories of affected Customer Personal Data and Data Subjects, where known
  • the approximate number of affected records or persons, where known
  • the likely consequences of the breach, where known
  • the measures taken or proposed to contain, investigate and mitigate the breach
  • an appropriate contact for further information

Where complete information is not immediately available, Techanics may provide the information in stages without undue further delay.

Techanics will take reasonable steps within its control to contain, investigate and mitigate the Personal Data Breach.

The Customer remains responsible for determining whether notification to a supervisory authority or affected Data Subjects is legally required.

A notification by Techanics does not constitute an acknowledgement of fault or liability.


10. Return and deletion

a) Customer choice

At the end of the provision of the Services, the Customer may instruct Techanics to return or delete Customer Personal Data.

Where a returnable copy of Customer Personal Data is technically available to Techanics, Techanics will provide that copy in a commonly usable format or through the export and retrieval options available within the Services.

Where the Services or the Atlassian platform do not provide a separate return or export function, Techanics will inform the Customer and provide reasonable assistance concerning the retrieval options available before uninstallation.

b) Timing of the instruction

The Customer should communicate its return instruction before uninstalling the relevant Service or within the recovery period supported by Atlassian Forge.

If the Customer does not issue a return instruction within the available period, the Customer instructs Techanics to delete the Customer Personal Data in accordance with the applicable Service and Forge lifecycle.

c) Forge-hosted data

Customer Personal Data stored through Forge-hosted storage is retained, recovered and deleted in accordance with the app lifecycle and retention processes provided by Atlassian Forge.

The current Forge-hosted storage lifecycle is described by Atlassian at:

Data lifecycle for Forge-hosted storage

Following uninstallation, Atlassian may retain Forge-hosted data for a limited platform recovery period before final deletion.

d) Protected Credentials

Where a documented function of a Service requires a Protected Credential provided or configured by the Customer, the credential is used only for the relevant function and is subject to the security measures described in Annex 2.

Protected Credentials stored for a Service are deleted or replaced when:

  • the Customer removes the credential
  • a replacement credential is stored
  • the relevant configuration is deleted
  • the relevant app data is deleted following uninstallation

Where the relevant Atlassian administration functions allow independent revocation of a Protected Credential, the Customer may additionally revoke the credential through those functions.

e) Existing copies and Subprocessors

Following a deletion instruction, Techanics will delete existing copies under its control and will ensure that its Subprocessors delete Customer Personal Data in accordance with the applicable contractual and platform deletion processes.

f) Legally required retention

Where applicable European Union or Member State law requires continued retention, Techanics will isolate and protect the relevant Customer Personal Data from further processing except for the legally required purpose.

g) Confirmation

Upon reasonable written request, Techanics will confirm completion of deletion to the extent that Techanics can verify the deletion through its own systems and the information made available by its Subprocessors.


11. Compliance information and audits

a) Information demonstrating compliance

Techanics will make available to the Customer the information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR.

This may include, as applicable:

  • this DPA and its Annexes
  • the Privacy Policy for Techanics Apps
  • information concerning the app architecture and processed data
  • information concerning Subprocessors
  • the description of Techanics’ technical and organisational measures
  • relevant Atlassian audit reports, certifications, security documentation and compliance information made available to Techanics

b) Audit procedure

If the information provided under subsection (a) is not reasonably sufficient to demonstrate compliance, the Customer may conduct an audit itself or appoint an independent auditor.

Unless a supervisory authority requires otherwise, a Personal Data Breach has occurred or reasonable evidence of material non-compliance justifies an additional or urgent audit:

  • an audit may ordinarily be conducted no more than once in any 12-month period
  • the Customer should provide at least 30 days’ prior written notice
  • the audit will take place during normal business hours
  • the scope will be limited to processing covered by this DPA
  • the audit will be conducted in a manner that does not unnecessarily compromise the security, confidentiality or availability of the Services
  • an external auditor must be independent, suitably qualified and subject to confidentiality obligations

These procedural arrangements do not restrict the powers of a competent supervisory authority or prevent the Customer from exercising its statutory audit rights where an urgent or additional audit is reasonably necessary.

c) Atlassian infrastructure

Where processing is performed through Atlassian Forge or Jira Service Management, Techanics may demonstrate the relevant infrastructure-level compliance by providing or referring to audit reports, certifications, security documentation and written responses made available by Atlassian under the applicable Atlassian data processing terms.

An audit under this DPA does not entitle the Customer or its auditor to:

  • direct access to Atlassian systems beyond the access legally and contractually available to Techanics
  • access to Personal Data or confidential information belonging to another customer
  • access to credentials, source code or vulnerability information not reasonably necessary for the audit

d) Audit costs

Techanics will provide standard compliance information and reasonable cooperation required under Article 28 GDPR without an additional charge.

The Customer bears its own internal and external audit costs.

Where an audit requires exceptional, repetitive or disproportionately extensive assistance beyond the reasonable cooperation required under Article 28 GDPR, Techanics may request reasonable costs agreed with the Customer in advance.

No fee will be imposed in a manner that prevents or unreasonably discourages the Customer from exercising its statutory audit rights.


12. International transfers

Techanics is established in Germany.

To provide the Services, Techanics engages Atlassian as described in Section 7. Atlassian operates a global cloud infrastructure and may process Customer Personal Data outside the European Economic Area.

International transfers by Atlassian in connection with Forge are governed by the Forge Data Processing Addendum, including the transfer mechanisms incorporated into that agreement where required.

International transfers in connection with Techanics’ Jira Service Management environment are governed by the applicable Atlassian Data Processing Addendum.

Techanics will not independently transfer Customer Personal Data to another third country or international organisation unless:

  • the transfer is covered by the Customer’s Documented Instructions
  • the transfer complies with Chapter V GDPR
  • the Customer has been informed as required by this DPA

Further information concerning the safeguards applicable to a particular transfer and, where available, a copy of the relevant safeguards may be requested using the contact details in Section 1.

Information may be redacted where necessary to protect confidential information, security measures or the rights of third parties.


13. Term, changes and order of precedence

a) Term

This DPA applies for as long as Techanics processes Customer Personal Data on behalf of the Customer.

b) Additional Services and updates

The release or availability of an additional Techanics software application does not by itself amend this DPA or change the processing performed for an existing Customer.

An additional Service becomes subject to this DPA only where the Customer acquires, installs or uses that Service under an Agreement incorporating this DPA and the processing performed through that Service falls within the processing framework described in Annex 1.

No amendment to this DPA is required solely because Techanics introduces an additional Service whose processing remains within that existing framework.

Techanics may otherwise update this DPA only where reasonably necessary to reflect:

  • changes in Applicable Data Protection Law
  • material changes to the processing framework or technical architecture of the Services
  • changes to Subprocessors
  • changes to technical and organisational measures
  • requirements imposed by a competent supervisory authority

Updates will not apply retroactively unless required by applicable law.

Techanics will notify the Customer of material changes in advance where reasonably possible.

No update will materially reduce the protection of Customer Personal Data during an existing subscription.

Where a material change adversely affects the Customer and no legally compliant and technically reasonable alternative is available, the Customer may terminate the affected Service in accordance with the Agreement.

c) Order of precedence

If there is a conflict between this DPA and another part of the Agreement concerning the processing of Customer Personal Data, this DPA prevails to the extent of the conflict.

If there is a conflict between this DPA and mandatory provisions of applicable Standard Contractual Clauses, the Standard Contractual Clauses prevail with respect to the relevant international transfer.

Mandatory provisions of Applicable Data Protection Law remain unaffected.


Annex 1 – Details of processing

1. Parties

Controller or instructing ProcessorThe Customer identified in the Agreement, order or Atlassian Marketplace account
ProcessorTechanics GmbH, Am Hoffeld 2, 83703 Gmund am Tegernsee, Germany
Customer contactThe contractual, administrative, security or technical contact identified by the Customer
Techanics contactinfo [at] techanics.de

2. Services covered

This Annex applies to Techanics cloud software applications for Atlassian products that are acquired, installed or used by the Customer under an Agreement incorporating this DPA, including but not limited to User Magic for Jira, Bulk User Actions and Smart Label Manager for Confluence.

The categories of Customer Personal Data, Data Subjects, processing operations and purposes described in this Annex constitute the common processing framework covered by this DPA.

Each individual Service processes only the categories of Customer Personal Data and performs only the processing operations necessary for its documented functionality.

The Customer’s acquisition, installation or use of one Service does not instruct or authorise Techanics to process Customer Personal Data solely for the functionality of another Service.

App-specific details may be further described in the applicable Atlassian Marketplace Privacy & Security information, Privacy Policy or product documentation. Such documentation may specify a narrower subset of the processing described in this Annex but does not expand the processing permitted under this DPA.

A Service whose processing materially exceeds this framework is not covered by this Annex unless this DPA or appropriate additional terms are updated before such processing begins.

3. Subject matter

Automated processing of Atlassian user, account, organisation, group, role, access, label, content identifier, configuration and comparable Atlassian metadata required to provide the documented functions selected and used by the Customer.

The processing may also include Customer Personal Data voluntarily submitted by the Customer for the purpose of investigating or resolving a technical problem concerning the Services.

4. Duration

The processing is performed for the duration of the relevant Service installation and use, together with the limited retention and recovery periods applicable under the Atlassian platform lifecycle.

Technical support information covered by this DPA is processed for as long as required to investigate, resolve and appropriately document the relevant technical request.

5. Nature of processing

  • retrieval and consultation
  • display
  • organisation and structuring
  • temporary use
  • storage of configuration information and Protected Credentials
  • modification of user, group, label, access or comparable supported Atlassian metadata as instructed by the Customer
  • execution of administrative or organisational actions
  • generation of technical status and result information
  • technical logging and diagnostics
  • restriction, return and deletion

6. Purposes

  • provision of the documented functions of the relevant Service
  • user and group administration where supported by the relevant Service
  • execution of Customer-selected administrative, organisational or bulk actions
  • management or assignment of group memberships, labels or comparable Atlassian metadata where supported
  • management of user access and account status where supported
  • storage of required app configuration
  • technical diagnostics and error analysis
  • security and reliability of the Services
  • requested technical support

7. Categories of Data Subjects

  • users of the Customer’s Atlassian environment
  • employees and other personnel of the Customer
  • contractors, consultants and external collaborators with Atlassian accounts
  • Customer administrators
  • persons initiating or affected by an app action
  • persons whose Personal Data is contained in technical support information voluntarily submitted by the Customer

8. Categories of Customer Personal Data

  • Atlassian Account IDs and comparable Atlassian identifiers
  • names, display names and business email addresses where required for the documented functionality of a Service
  • organisation, site, installation and directory identifiers
  • account and activation status
  • product access information
  • administrative roles
  • group names and group memberships
  • source and target user information required for a supported action
  • information about the user initiating an action
  • content identifiers, labels and comparable Atlassian metadata where required for the documented functionality of a Service
  • app configuration information
  • technical timestamps
  • installation, invocation, trace and request identifiers
  • technical status, result and error information
  • Protected Credentials where required for a documented function of a Service
  • technical support information voluntarily submitted by the Customer, including selected log excerpts, screenshots or attachments

9. Protected Credentials

Where a documented function of an individual Service requires a Customer-provided API token, API key, authentication secret or comparable credential, Techanics processes that Protected Credential only for the relevant function.

Where Techanics stores such a Protected Credential for continued use by a Service:

  • it is stored within Atlassian Forge
  • it is additionally protected by application-level authenticated encryption based on AES-GCM
  • it is used only for the documented functions configured by the Customer
  • it is not intentionally included in regular application logs
  • it may be removed or replaced through the relevant Service where supported
  • it may additionally be revoked through the relevant Atlassian administration functions where such independent revocation is supported
  • it is deleted in accordance with the relevant app configuration and Forge storage lifecycle

A Protected Credential is treated as confidential security information regardless of whether it constitutes Personal Data in a particular case.

10. Jira and Confluence content

The Services covered by this processing framework are not intended to access or process the substantive textual content of Jira issues or Confluence pages as part of their documented functions.

Where required for a documented function, a Service may process technical identifiers, labels, configuration information or comparable Atlassian metadata without processing the substantive textual content itself.

A Service that materially requires the processing of substantive Jira issue content, Confluence page content, attachments or another materially different category of Customer Personal Data falls outside this processing framework unless this DPA or appropriate additional terms are updated before such processing begins.

11. Special categories

No special categories of Personal Data under Article 9 GDPR or Personal Data relating to criminal convictions and offences under Article 10 GDPR are required or intentionally processed as part of the documented functions covered by this processing framework.

Incidental processing may occur where Customer-defined metadata or technical support information itself contains or reveals such information.

12. Frequency

Processing occurs on an event-driven and, where required by the relevant functionality, recurring basis for the duration of the Customer’s installation and use of the relevant Service.

13. Retention criteria

Customer Personal Data is retained for the duration required for the Customer’s use of the relevant Service and for the limited deletion or recovery period provided by Atlassian Forge after uninstallation.

Technical logs are retained according to the Forge platform retention period and are not independently archived by Techanics for long-term storage.

Technical support data covered by this DPA is retained only for as long as required to process and appropriately document the relevant support request and any associated security or legal matter.


Annex 2 – Technical and organisational measures controlled by Techanics

1. Scope

This Annex describes the technical and organisational measures implemented or controlled by Techanics.

It does not reproduce the infrastructure-level measures implemented by Atlassian. Those measures are governed by the Forge Data Processing Addendum, the Atlassian Data Processing Addendum and Atlassian’s applicable security documentation.

2. Data minimisation and app architecture

  • App permissions and API access are restricted to those required for the documented functions of the relevant Service.
  • Each Service processes only the user, account, group, organisation, access, label, configuration or comparable Atlassian metadata required for its documented functionality.
  • The Services covered by the processing framework do not intentionally process the substantive textual content of Jira issues or Confluence pages as part of their documented functions.
  • Technical identifiers, labels and comparable Atlassian metadata may be processed where required for a documented function.
  • The core app code is executed through Atlassian Forge.
  • Techanics does not operate a separate external application backend or application database for the core app functions covered by this DPA.
  • Customer Personal Data processed under this DPA is not used for advertising, profiling, sale of data or unrelated analytics.

3. Access and confidentiality

  • Access to app development, Forge administration, logs and support systems is restricted to authorised personnel.
  • Access is granted according to assigned responsibilities and legitimate operational need.
  • Individual accounts and secure authentication mechanisms are used where supported by the relevant system.
  • Multi-factor authentication is used for privileged accounts where supported and enabled by the relevant system.
  • Access rights are removed or adjusted when they are no longer required.
  • Authorised personnel are subject to appropriate confidentiality obligations.

4. Protected Credentials

  • Protected Credentials are processed only where required for a documented function of the relevant Service.
  • Protected Credentials stored by a Service for continued use are stored within Atlassian Forge.
  • Stored Protected Credentials are additionally protected at application level using authenticated encryption based on AES-GCM.
  • Protected Credentials are used only for the app functions configured by the Customer.
  • Protected Credentials are not transmitted to Brevo, Microsoft or unrelated service providers.
  • Protected Credentials are not intentionally written to regular application logs.
  • Protected Credentials are retained only for as long as required for the configured function and the applicable Forge storage lifecycle.

5. Logging and diagnostics

  • Forge logs are used only for diagnostics, security, reliability and technical support.
  • Logging is designed according to the principle of data minimisation.
  • Techanics avoids logging complete authentication objects, request headers, API responses and unnecessary Customer Personal Data.
  • API tokens, passwords, authorisation headers and comparable authentication secrets are not intentionally included in regular app logs.
  • Access to Forge logs is restricted to authorised personnel and subject to the access and log-sharing controls provided by Atlassian.
  • Forge logs are not exported by Techanics to a separate external long-term logging or analytics platform.

6. Development and change management

  • Access to app source code and deployment functions is restricted to authorised persons.
  • Changes are deployed through the development and deployment mechanisms provided by Atlassian Forge.
  • Permissions, data flows, storage and logging behaviour are reviewed when app functions are introduced or materially changed.
  • Before a new Service or material new function is released, Techanics assesses whether its processing remains within the framework described in Annex 1.
  • Security-relevant updates are assessed and implemented according to their risk and technical feasibility.

7. Incident response

  • Techanics maintains procedures for identifying, assessing, containing and documenting security incidents.
  • Access to incident information is restricted to authorised persons.
  • Personal Data Breaches affecting Customer Personal Data are communicated to affected Customers without undue delay.
  • Causes and appropriate corrective measures are assessed following an incident.

8. Retention and deletion controls

  • Persistent app data is retained only for the duration required to provide the Services and the applicable Forge lifecycle.
  • Protected Credentials can be removed or replaced through the relevant Service where supported and may be independently revoked through Atlassian administration where supported.
  • Forge-hosted data and logs are deleted according to the applicable Atlassian retention processes.
  • Techanics does not independently create a long-term external archive of Forge logs or core app data.

9. Atlassian infrastructure measures

Infrastructure-level measures for Forge are described in the security exhibit to the Atlassian Forge Data Processing Addendum.

They include the measures implemented by Atlassian for encryption, logical separation, infrastructure access, availability, resilience, vulnerability management, physical security and independent audits.

Atlassian’s current security documentation is available at:

Atlassian Security Measures

Techanics relies on these infrastructure-level measures only to the extent that Atlassian provides the relevant infrastructure processing under the applicable Atlassian agreement.

10. Review of measures

Techanics reviews the appropriateness of its measures when:

  • new Services or app functions are introduced
  • processing activities materially change
  • Atlassian changes relevant Forge capabilities
  • a material security incident occurs
  • Applicable Data Protection Law or contractual requirements change

Annex 3 – Approved Subprocessors

SubprocessorProcessing and purposeCustomer Personal DataContractual safeguards
Atlassian Pty Ltd
ABN 53 102 443 916
Level 6, 341 George Street
Sydney NSW 2000
Australia
Provision of Atlassian Forge, including compute, hosted storage, technical logs, platform security, administration and applicable data residency functions.

Provision of Jira Service Management infrastructure to the extent Customer Personal Data is voluntarily submitted for requested technical support covered by this DPA.
The categories described in Annex 1, including Atlassian identifiers, user and group metadata, labels and comparable Atlassian metadata, app configuration information, Protected Credentials, technical data, app logs and technical support content.Atlassian Forge Data Processing Addendum for Forge processing.

Applicable Atlassian Data Processing Addendum for Jira Service Management processing.

Applicable Standard Contractual Clauses and other transfer safeguards incorporated into those agreements.

Atlassian onward Subprocessors

Atlassian’s current list of onward Subprocessors, including their processing purposes, data categories and processing locations, is available at:

Atlassian Subprocessor List

Providers outside the scope of this Annex

Brevo, Microsoft 365 and providers used exclusively for the separate synchronisation of Atlassian Marketplace contact information are not used as Subprocessors for the core functional Customer Personal Data covered by this DPA.

They are used for separate processing activities for which Techanics generally acts as Controller, as described in the Privacy Policy for Techanics Apps.

If the role or purpose of one of these providers changes so that it processes Customer Personal Data on behalf of the Customer, Techanics will update this Annex and apply the Subprocessor procedure described in Section 7.


Version history

VersionDateMain changes
1.0August 2026Initial publication of the Data Processing Agreement for Techanics Apps