Version Workload Reports for Jira
Data Processing Addendum
Version 1.0 — customer data-processing terms for Version Workload Reports for Jira.
Effective and last updated: 9 September 2026
1. Parties, scope, and roles
This Data Processing Addendum (DPA) forms part of the agreement governing Version Workload Reports for Jira (Agreement) between the customer identified in the applicable Atlassian Marketplace order (Customer) and the provider identified in that order under the trade name Sovereign World Labs (Provider). Sovereign World Labs is a trade name and is not represented here as an incorporated entity or separate legal person.
This DPA applies when Provider processes personal data contained in Customer Data to provide VWR (Customer Personal Data). Customer is a controller or processor, as applicable. Provider is Customer’s processor or subprocessor. Atlassian processes Forge-hosted app data for Provider under the Forge terms and Forge DPA. Roles are determined by actual processing activities, not labels alone.
Provider is an independent controller for business contact data used to administer Marketplace orders and direct support, privacy, security, or legal correspondence. The Privacy Policy explains that separate processing.
2. Instructions, purpose, and duration
Provider will process Customer Personal Data only on Customer’s documented instructions in the Agreement and authorized use of VWR; to operate, secure, maintain, and support VWR; or when required by law after notice unless law prohibits it. Provider will inform Customer if it reasonably believes an instruction infringes applicable data-protection law.
Customer instructs Provider to validate the Jira scope selected by an authorized signed-in user, retrieve permitted fields, deduplicate issues, calculate and display reports, show contributing detail, create a requested complete-result CSV, enforce entitlement and limits, and provide privacy-safe operational support.
Provider will not sell Customer Personal Data, use it for advertising or profiling, train models with it, or use it for unrelated analytics. Customer is responsible for lawful instructions, notices, legal bases, Jira data, and user permissions.
3. Confidentiality
Provider will keep Customer Personal Data confidential, restrict access to people who need it to perform the Agreement, and ensure authorized persons are subject to an appropriate continuing duty of confidentiality.
4. Security
Provider will maintain appropriate technical and organizational measures, taking account of implementation costs, processing context, and risk. Atlassian is responsible for the Forge platform controls described in its documentation and agreements. Provider is responsible for app code, permissions, configuration, data minimization, and operational practices within its control.
- Forge-only runtime with no Remote, SWL-hosted report backend, external database, advertising, tracking, or external analytics.
- Jira scope
read:jira-workand initiating-user authorization for interactive reads, with no privileged fallback or impersonation path. - Server-side allow-listing and revalidation of project, version, and filter identifiers.
- Bounded pages, issue count, duration, and retries; incomplete retrieval is non-authoritative and cannot be exported.
- Each issue ID contributes at most once, and formula-like CSV text is neutralized.
- No app-owned report, derived-state, issue-copy, preference, queue, or analytics persistence.
- Sanitized logs without JQL, issue or source content, user identifiers, CSV, credentials, tokens, or full contexts.
5. Subprocessors
Customer gives Provider general written authorization to use the subprocessors listed below. Provider will require each subprocessor to protect Customer Personal Data as applicable law requires. Provider will make the current list available, give reasonable advance notice of a new or replacement subprocessor that processes Customer Personal Data, and consider a Customer objection made on reasonable data-protection grounds.
| Subprocessor | Processing | Safeguards |
|---|---|---|
| Atlassian Pty Ltd and relevant affiliates or subprocessors | Jira Cloud, Forge functions, platform logs, licensing, and platform operation | Forge Terms and Forge DPA, including applicable SCCs; Atlassian security, subprocessor, and residency documentation |
Provider will consider a reasonable data-protection objection in good faith. If no reasonable alternative is available, the affected processing or subscription may end under the existing Agreement. This DPA adds no fixed objection period, refund right, or separate termination rule.
Cloudflare Email Routing and Provider’s private Google-hosted mailbox handle only person-initiated correspondence for Provider’s separate controller activities. They are not connected to VWR’s runtime and receive no automatic Jira report data.
6. International transfers
Provider will not make a restricted transfer without a lawful mechanism. VWR creates no SWL remote report-data egress. Atlassian’s Forge DPA incorporates applicable Standard Contractual Clauses and other documented transfer mechanisms. Provider does not promise all processing occurs in one country, and VWR does not alter Customer’s Jira data-residency choices.
7. Assistance and rights
Taking account of the nature of processing and information available, Provider will reasonably assist Customer with data-subject requests, security obligations, data-protection impact assessments, regulator consultations, and information reasonably necessary to demonstrate compliance. Provider will not respond directly to Customer’s data subject unless authorized or legally required.
Requests must be sent to support@sovereignworldlabs.com without credentials or Jira content. Provider may verify identity, authority, site, and installation scope.
8. Personal data breaches
Provider will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data. As information becomes available, notice will describe the incident, affected data and people, likely consequences, mitigation, and contact point. Provider will investigate, contain, remediate, preserve appropriate non-content evidence, and cooperate with Customer. Provider will not notify regulators or data subjects for Customer unless authorized or legally required.
9. Return and deletion
VWR normally has no app-owned Jira data or report corpus to return or delete. Report data exists transiently in the Forge invocation and browser session. Customer controls Jira records and downloaded CSV files, and Atlassian controls Forge platform records.
After termination or expiration, Provider will, at Customer’s choice and subject to law, delete or return Customer Personal Data in Provider’s possession or control within 60 days of an authorized request. Customer remains responsible for managing Jira-controlled data and downloaded CSV files. Backups or records retained by law remain protected and unavailable for other purposes until deletion.
10. Audit and compliance
Provider will make available information reasonably necessary to demonstrate compliance, normally through current documentation, security answers, Atlassian or Forge control information, and written responses. Where those materials are insufficient, Customer may conduct or commission a reasonable audit as applicable law requires, subject to notice, confidentiality, security, tenant isolation, and no access to other customers’ data or Atlassian systems Customer is not authorized to test. Provider will address substantiated findings within its control.
11. Other privacy laws
Where a law uses equivalent processor or service-provider concepts, Provider will process Customer Personal Data only for the limited business purposes in this DPA; will not sell or share it for cross-context behavioural advertising; and will not combine it with unrelated personal data except as law permits.
12. Duration, liability, and precedence
This DPA remains in effect while Provider processes Customer Personal Data. Liability under this DPA is governed by the Agreement except where law prohibits that result. This DPA governs only data-protection obligations; it does not change the Standard Agreement’s warranties, liability, indemnities, governing law, refunds, cancellation, suspension, or termination. The order of precedence in Section 1.4 of the Bonterms Standard End User Agreement, Version 1.0 applies.
Annex 1 — processing details
| Subject matter | On-demand workload, estimate-coverage, and forecast-variance reporting from a Customer-selected Jira scope. |
|---|---|
| Nature and purpose | Validate permitted sources; retrieve Jira issues as the initiating user; deduplicate; calculate and display reports and contributing detail; generate a user-requested complete-result CSV; enforce entitlement and limits; and troubleshoot with non-content diagnostics. |
| Duration | The Forge invocation and browser session, plus Atlassian’s platform-controlled sanitized-log lifecycle and the common 60-day authorized post-termination commitment. VWR has no separate SWL report store. |
| Data subjects | Customer Jira users, current assignees, and people referenced in permitted issue summary or identifier fields. |
| Data | Project, version, and filter metadata; issue ID, key, summary, type, and status category; current assignee account ID, display name, and state; original estimate, cumulative time spent, remaining estimate; and minimal technical invocation fields. |
| Storage and export | Transient Forge and browser memory; no app-owned report, derived-state, issue-copy, preference, queue, or analytics store. Jira and user-downloaded CSV files remain under Customer control. |
Contact
DPA and privacy requests: support@sovereignworldlabs.com. See also the Privacy Policy, VWR documentation, Provider-Specific Terms, and Support Policy and SLA.