ReplyTurn

Data Processing Addendum

Version 1.2 — customer data-processing terms for ReplyTurn.

Effective and last updated: 7 September 2026

1. Parties, scope, and roles

This Data Processing Addendum (DPA) forms part of the agreement governing ReplyTurn (Agreement) between the customer identified in the applicable Atlassian Marketplace order (Customer) and the provider identified in that order under the trade name Sovereign World Labs (Provider). Sovereign World Labs is a trade name and is not represented here as an incorporated entity or separate legal person.

This DPA applies when Provider processes personal data contained in Customer Data to provide ReplyTurn (Customer Personal Data). Customer is a controller or processor, as applicable. Provider is Customer’s processor or subprocessor. Atlassian processes Forge-hosted app data for Provider as Provider’s processor or subprocessor under the Forge terms and Forge DPA. Roles are determined by actual processing activities, not labels alone.

Provider is an independent controller for business contact data used to administer Marketplace orders and direct support, privacy, or security correspondence. The Privacy Policy explains that separate processing.

2. Instructions, purpose, and duration

Provider will process Customer Personal Data only on Customer’s documented instructions in the Agreement and use of ReplyTurn; to operate, secure, maintain, and support ReplyTurn; or when required by law after notice unless law prohibits it. Provider will inform Customer if it reasonably believes an instruction infringes applicable data-protection law.

Provider will not sell Customer Personal Data, use it for advertising or profiling, train models with it, or use it for unrelated analytics. Customer is responsible for lawful instructions, notices and legal bases; its Jira data; and user permissions. ReplyTurn neither requires nor is designed for intentional processing of special-category, criminal-offence, or similarly sensitive personal data.

3. Confidentiality

Provider will keep Customer Personal Data confidential, restrict access to people who need it to perform the Agreement, and ensure authorized persons are subject to an appropriate continuing duty of confidentiality.

4. Security

Provider will maintain appropriate technical and organizational measures, taking account of implementation costs, processing context, and risk. Atlassian is responsible for the Forge platform controls described in its documentation and agreements. Provider is responsible for app code, permissions, configuration, data minimization, and operational practices within its control.

  • Forge-only runtime with no Remote, external backend, external fetch domain, advertising, tracking, or app analytics.
  • Atlassian-hosted tenant-scoped storage, app-owned Jira fields, and Atlassian-managed encryption in transit and at rest.
  • Five documented Jira/Forge scopes; current-user authorization for interactive reads and app authorization for background work.
  • Input validation, tenant isolation, idempotency, rate-limit-aware retry, rolling TTLs, issue-deletion cleanup, and controlled releases.
  • Immediate discard of comment bodies; no bodies, account IDs, issue IDs/keys, payloads, or REST bodies in application logs.

5. Subprocessors

Customer gives Provider general written authorization to use the subprocessors listed below. Provider will require each subprocessor to protect Customer Personal Data as applicable law requires. Provider will make the current list available, give reasonable advance notice of a new or replacement subprocessor that processes Customer Personal Data, and consider a Customer objection made on reasonable data-protection grounds.

SubprocessorProcessingSafeguards
Atlassian Pty Ltd and relevant affiliates/subprocessorsJira Cloud, Forge functions, queues, hosted storage, logs, app fields, licensing and platform operationForge Terms and Forge DPA, including SCCs; Atlassian security, subprocessor and residency documentation

Cloudflare Email Routing and the Provider’s private Google-hosted mailbox handle only person-initiated correspondence. They are not connected to ReplyTurn’s runtime and receive no automatic Jira data; that separate Provider-controller processing is disclosed in the Privacy Policy.

6. International transfers

Provider will not make a restricted transfer without a lawful mechanism. ReplyTurn uses Atlassian Forge only. Atlassian’s Forge DPA incorporates EU Standard Contractual Clauses and provisions for UK and Swiss transfers. Customer-selected Global residency can allow Atlassian to move in-scope hosted data between supported realms, and Forge compute can execute outside the host product’s storage realm as Atlassian documents. Provider does not promise all processing occurs in one country.

7. Assistance and rights

Taking account of the nature of processing and information available, Provider will reasonably assist Customer with data-subject requests, security obligations, data-protection impact assessments, regulator consultations, and information reasonably necessary to demonstrate compliance. Provider will not respond directly to a Customer’s data subject unless authorized or legally required.

Requests must be sent to support@sovereignworldlabs.com without credentials or Jira content. Provider may verify identity, authority, site, and installation scope.

8. Personal data breaches

Provider will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data. As information becomes available, notice will describe the incident, affected data and people, likely consequences, mitigation, and contact point. Provider will investigate, contain, remediate, preserve appropriate non-content evidence, and cooperate with Customer. Provider will not notify regulators or data subjects for Customer unless authorized or legally required.

9. Return and deletion

Customer administrators control Jira issues and Jira-hosted field values. ReplyTurn deletes a per-request KVS record when it receives an issue-deleted event. Derived issue state, code-only diagnostics, and onboarding status/evidence in KVS have a rolling 90-day upper bound; deduplication markers expire after 30 days.

Forge asynchronous event queues retain issue IDs and keys and job/progress metadata for processing and retries. They follow Atlassian’s Async Events retention lifecycle: a 24-hour delivery window, extendable to 96 hours for platform issues. Events affected by platform errors beyond that window may remain for Atlassian intervention; this is not an absolute deletion deadline.

After termination or expiration, Provider will, at Customer’s choice and subject to law, delete or return Customer Personal Data in Provider’s possession or control within 60 days of an authorized request. Customer remains responsible for uninstalling ReplyTurn and managing Jira-controlled data. Atlassian currently retains Forge hosted storage for 28 days after uninstall and requires a recovery request within 21 days. Backups or data retained by law remain protected and unavailable for other purposes until deletion.

10. Audit and compliance

Provider will make available information reasonably necessary to demonstrate compliance, normally through current documentation, security answers, Atlassian/Forge control information, and written responses. Where those materials are insufficient, Customer may conduct or commission a reasonable audit as applicable law requires, subject to notice, confidentiality, security, tenant isolation, and no access to other customers’ data or Atlassian systems Customer is not authorized to test. Provider will address substantiated findings within its control.

11. Other privacy laws

Where a law uses equivalent processor or service-provider concepts, Provider will process Customer Personal Data only for the limited business purposes in this DPA; will not sell or share it for cross-context behavioural advertising; and will not combine it with unrelated personal data except as law permits.

12. Duration, liability, and precedence

This DPA remains in effect while Provider processes Customer Personal Data. Liability under this DPA is governed by the Agreement except where law prohibits that result. This DPA governs only data-protection obligations; it does not change the Standard Agreement’s warranties, liability, indemnities, governing law, refunds, cancellation, suspension, or termination. The order of precedence in Section 1.4 of the Bonterms Standard End User Agreement applies.

Annex 1 — processing details

Subject matterDerive and display whose turn it is to reply in active JSM and CSM requests.
Nature and purposeRead request/comment metadata; determine public-conversation state; write app-owned Jira fields; store derived state and onboarding/idempotency records; queue background jobs; display authorized status; troubleshoot with non-content diagnostics.
DurationSubscription plus 30/90-day KVS TTLs, the separate Forge Async Events lifecycle described in section 9, Atlassian’s uninstall/recovery lifecycle, and the 60-day authorized post-termination deletion commitment.
Data subjectsCustomer personnel and agents; portal customers/requesters; request participants; and people represented in Customer-controlled Jira metadata.
Persisted dataJira issue ID; derived reply state/timestamps; diagnostic code/severity; onboarding run/cursor/count/retry timestamps; opaque deduplication markers; installed app field IDs. Forge queues additionally retain issue IDs and keys and job/progress metadata, without comment bodies or author profiles. Issue keys are not stored in KVS.
Transient dataProject/request/channel metadata; comment ID, timestamp, visibility and body; author account ID; current agent authorization; summary, project, assignee, priority, roles/groups and participants when returned or displayed. Bodies are immediately discarded.

Contact

DPA and privacy requests: support@sovereignworldlabs.com.