Effective August 21, 2026

Data Processing Addendum

This product-specific addendum governs Korinvale Software's processing of personal data for customers of Notification Hygiene for Jira.

This Data Processing Addendum (“DPA”) forms part of the agreement governing a Customer's use of Notification Hygiene for Jira (“Agreement”). It applies only to the extent Korinvale Software processes Personal Data on Customer's behalf.

1. Parties and scope

“Customer” is the person or entity that obtains the app through Atlassian Marketplace. “Provider” is Alan Shen, operating as a sole proprietor under the Korinvale Software brand. Customer and Provider are each a “Party” and together the “Parties.”

This DPA applies to Notification Hygiene for Jira. It takes effect when the Agreement takes effect and continues while Provider processes Personal Data on Customer's behalf. If this DPA conflicts with the Agreement on the processing of Personal Data, this DPA controls.

2. Definitions and roles

Capitalized privacy terms not defined here have the meanings given by applicable Data Protection Law. “Data Protection Law” includes the GDPR, the UK GDPR, and the CCPA to the extent each applies.

For GDPR-covered processing, Customer is the controller and Provider is the processor, except where Customer acts as a processor for another controller, in which case Provider is Customer's subprocessor. For CCPA-covered processing, Provider acts as Customer's service provider or contractor and not as a business for Customer Personal Information.

3. Processing details and instructions

Provider will process Personal Data only to provide, secure, support, and maintain the app; comply with documented instructions in the Agreement and Customer's authorized use of the app; or comply with applicable law. If law requires other processing, Provider will notify Customer before processing unless the law prohibits notice.

  • Subject matter and purpose: Read Jira notification-scheme configuration, generate deterministic audit findings, and maintain a compact configuration-drift history.
  • Nature: Automated retrieval, organization, comparison, hashing, temporary analysis, bounded storage, display, and deletion within Atlassian Forge.
  • Duration: The term of the Agreement, plus Atlassian Forge's documented post-uninstallation storage lifecycle where applicable.
  • Data subjects: Jira users and other individuals referenced in Customer's notification-scheme configuration.
  • Personal Data processed transiently: Account identifiers or labels, group names, project roles, custom-field references, user status, direct-email recipients, and other recipient configuration exposed by the Jira APIs used by the app.
  • Personal Data retained: The app is designed not to retain recipient details. Forge KVS retains capture times, scheme identifiers and names, SHA-256 configuration fingerprints, bounded scheme-level change metadata, and scheduled-scan status. A scheme name may contain Personal Data if Customer places it there.

Customer instructs Provider to use Atlassian Forge and the subprocessors described below. Customer is responsible for the lawfulness and accuracy of its instructions and Personal Data.

4. Provider obligations

Provider will:

  • ensure each person authorized to process Personal Data is bound by confidentiality;
  • maintain appropriate technical and organizational measures described in Section 9;
  • notify Customer if Provider believes an instruction infringes applicable Data Protection Law;
  • provide reasonable assistance, taking into account the nature of processing and information available to Provider, with data-subject requests, security obligations, breach notifications, data-protection impact assessments, and regulator consultations;
  • notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data and provide reasonably available information needed for Customer's response; and
  • make information reasonably necessary to demonstrate compliance with this DPA available to Customer, subject to confidentiality, security, and reasonable scope protections.

5. Data-subject and government requests

If Provider receives a request from a data subject concerning Customer Personal Data, Provider will direct the requester to Customer unless law prohibits doing so. Provider will not independently respond on Customer's behalf except on Customer's documented instruction or as required by law.

Provider will notify Customer of a legally binding government request for Customer Personal Data unless prohibited by law and will reasonably challenge an unlawful or overbroad request where appropriate.

6. Subprocessing

Customer gives Provider general written authorization to use Atlassian and its applicable affiliates and subprocessors to host and operate the app through Atlassian Forge. Atlassian's current subprocessor information is available on its subprocessor page.

Provider will require subprocessors under its control to protect Personal Data to a standard materially consistent with this DPA and remains responsible for their performance to the extent required by Data Protection Law. Provider will not add a non-Atlassian remote backend or other app-controlled subprocessor without updating this DPA and giving reasonable advance notice. Customer may object on reasonable data-protection grounds by contacting Provider; if the Parties cannot resolve the objection, Customer may stop using and uninstall the app.

7. International transfers

The app declares no external egress and does not intentionally transfer Customer Personal Data outside the Atlassian products and Forge services used to provide it. Forge-hosted processing and any platform-level transfers are governed by Atlassian's applicable data-processing and transfer commitments.

Provider will not add an app-controlled restricted transfer of Customer Personal Data from the EEA, United Kingdom, or Switzerland without first implementing a legally valid transfer mechanism and updating the applicable customer terms and disclosures.

8. CCPA commitments

Provider will process Customer Personal Information only for the limited and specified business purposes described in this DPA. Provider will not sell or share Customer Personal Information, retain, use, or disclose it outside the direct business relationship with Customer or for a commercial purpose other than those specified here, or combine it with personal information received from another person or collected from Provider's own interaction with an individual, except as permitted by the CCPA.

Provider certifies that it understands and will comply with these restrictions. Customer may take reasonable and appropriate steps to help ensure compliant use, may require Provider to stop and remediate unauthorized use, and may monitor compliance through the measures in Section 10.

9. Security measures

  • Atlassian Forge hosts the app UI, compute, scheduled function, and KVS storage.
  • The app declares no remote backend, external egress, analytics, advertising, or AI service.
  • Jira integration is limited in application code to documented GET requests for notification schemes and project mappings.
  • Interactive access is subject to the signed-in Jira user's permissions; the page is restricted to global Jira administrators.
  • Stored drift history is minimized, deterministically fingerprinted, and bounded to 20 change records.
  • Recipient details, raw Jira responses, credentials, and event-level configuration are not retained.
  • Safe error handling, bounded pagination, deterministic tests, dependency review, and release checks are used.

Additional details are available in the Security overview.

10. Review and audits

Customer will first use Provider's current documentation, Atlassian Forge assurance materials, and written responses to reasonable security or privacy questions. If those are insufficient, Customer may request an audit reasonably necessary to verify compliance. Audits must be proportionate, protect other customers and Provider systems, avoid unnecessary disruption, and occur no more than once per year unless required by a regulator or following a substantiated incident. Each Party bears its own costs unless applicable law requires otherwise.

11. Return and deletion

At Customer's choice, Provider will delete or return Customer Personal Data after the processing services end, unless law requires retention. Because the app does not provide an external data store, the available return mechanism is Customer's existing Jira configuration and in-app report.

A Jira administrator may use Reset drift history to delete the retained baseline and history even without an active app license. Uninstalling the app initiates Atlassian Forge's hosted-storage deletion lifecycle. Requests may be sent to support@korinvale.com.

12. Changes and contact

Provider may update this DPA to reflect changes in law, Atlassian Forge, or the app. Provider will not materially reduce Customer's data-protection rights during an active subscription without reasonable notice. The effective date at the top identifies the current version.

Data-protection questions and legally required notices should be sent to support@korinvale.com.