Legal
Data Processing Addendum
Version 1.0. Effective August 1st, 2026. This is a new document; there is no previous version.
1. Introduction and Incorporation
1.1. This Data Processing Addendum (the “DPA”) is concluded on the basis of Article 28(3) of Regulation (EU) 2016/679 (the “GDPR”) between eXtensi Chudziński Jędryka spółka jawna, with its registered office in Wrocław, at ul. Rysia 1A/362, 53-656 Wrocław, Poland, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court for Wrocław-Fabryczna in Wrocław, VI Commercial Division of the National Court Register, under KRS number 0000807163, NIP (VAT ID): PL8943146425, REGON: 384560483 (“eXtensi”, “we”, “us”) and the Customer.
1.2. This DPA forms an integral part of the agreement between eXtensi and any Customer of eXtensi Cloud Apps. It is concluded and becomes binding upon the Customer’s installation or use of a Cloud App. No signature is required. A copy of this DPA signed by eXtensi (for countersignature by the Customer where its procurement processes require a signed copy) is available on request via support.no-spam@spam-trap.invalid@extensi.io.invalid.
1.3. The term of this DPA follows the term of the agreement between eXtensi and the Customer: it applies for as long as eXtensi processes Customer Personal Data and ends once all Customer Personal Data has been deleted or returned in accordance with Section 12.
1.4. In the event of a conflict between this DPA and the End User Terms (including the Standard Agreement) with respect to the processing of personal data, this DPA prevails.
2. Definitions
2.1. Capitalized terms used but not defined in this DPA have the meanings given in the End User Terms. In this DPA:
- “Standard Agreement” means the Bonterms Standard End User Agreement Version 1.0 as made available by Atlassian for the Atlassian Marketplace (https://www.atlassian.com/licensing/marketplace/end-user-agreement-v1 (opens in a new tab)).
- “End User Terms” means the eXtensi End User Terms available at /policies/eula/, consisting of the Standard Agreement and the eXtensi Provider-Specific Terms.
- “Cloud Apps” means the eXtensi Apps distributed via the Atlassian Marketplace for Atlassian cloud products. The current portfolio, including each App’s deployment model, is published on eXtensi’s Atlassian Marketplace vendor page and on each App’s Marketplace listing.
- “Self-Managed Apps” means the eXtensi Apps distributed via the Atlassian Marketplace for Atlassian Data Center or Atlassian Server products.
- “End User Data” has the meaning given in the End User Terms.
- “Customer Personal Data” means any personal data within the meaning of the GDPR contained in End User Data that eXtensi processes on behalf of the Customer in connection with the Cloud Apps.
- “Sub-processor” means any third party engaged by eXtensi to process Customer Personal Data.
- “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- “Data Protection Laws” means the GDPR and any applicable national data-protection legislation of an EU or EEA Member State, including the Polish Act of 10 May 2018 on the Protection of Personal Data.
3. Roles of the Parties
3.1. With respect to Customer Personal Data, the Customer acts as controller, and eXtensi acts as processor on the Customer’s behalf.
3.2. Where the Customer itself acts as a processor for a third-party controller, eXtensi acts as the Customer’s sub-processor. In that case the Customer warrants that: (a) its instructions to eXtensi are consistent with the instructions of the relevant controller; and (b) it has obtained the controller’s authorization to engage eXtensi.
3.3. The Customer is responsible for the lawfulness of the processing of Customer Personal Data, including a valid legal basis and any required notices to data subjects. The Customer must not submit to the Cloud Apps any categories of data that are prohibited under the Standard Agreement (including health information, financial account numbers, government-issued identifiers, and special categories of personal data within the meaning of Article 9 GDPR).
3.4. For the purposes of Article 28(3) GDPR, the Customer’s rights and obligations as controller are set out in this DPA (in particular Sections 3, 5, 8, 10, and 13) and in the End User Terms.
4. Scope
4.1. This DPA applies only to the Cloud Apps.
4.2. The Self-Managed Apps are expressly out of scope of this DPA. Self-Managed Apps run entirely on infrastructure operated by or for the Customer, and eXtensi does not access or process End User Data in connection with them. The only exception is personal data that the Customer or its personnel voluntarily include in support tickets; such data is processed by eXtensi as a controller and is covered by the Privacy Policy, not this DPA.
4.3. The subject matter, duration, nature, and purposes of the processing, the categories of personal data, and the categories of data subjects for each Cloud App are described in Annex 3.
5. Processing on Documented Instructions
5.1. eXtensi will process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by EU or Member State law to which eXtensi is subject; in such a case, eXtensi will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
5.2. The Customer’s complete documented instructions consist of: (a) the End User Terms and this DPA; (b) the Customer’s configuration and use of the features of the Cloud Apps; and (c) any additional written instructions given via support.no-spam@spam-trap.invalid@extensi.io.invalid that are consistent with the functionality of the Cloud Apps. Instructions requiring material changes to the Cloud Apps may be declined or made subject to a separate agreement.
5.3. eXtensi will immediately inform the Customer if, in eXtensi’s opinion, an instruction infringes Data Protection Laws. eXtensi may suspend the execution of such an instruction until the Customer confirms or modifies it.
6. Confidentiality of Personnel
6.1. eXtensi ensures that all persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they process Customer Personal Data only as needed to perform their tasks.
7. Security of Processing
7.1. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to the rights and freedoms of natural persons, eXtensi implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. The measures currently implemented are described in Annex 1.
7.2. eXtensi may update the measures in Annex 1 from time to time, provided that any update does not materially lower the overall level of protection of Customer Personal Data.
8. Sub-processors
8.1. The Customer grants eXtensi a general written authorization to engage Sub-processors for the processing of Customer Personal Data. The Sub-processors engaged as of the date of this DPA are listed in Annex 2.
8.2. eXtensi will impose on each Sub-processor, by way of a contract or other legal act under EU or Member State law, the same data-protection obligations as set out in this DPA (the contract wording need not be identical, provided the obligations imposed are the same in substance), in particular providing sufficient guarantees to implement appropriate technical and organizational measures (Article 28(4) GDPR). eXtensi remains fully liable to the Customer for the performance of each Sub-processor’s obligations.
8.3. eXtensi maintains its current list of Sub-processors in Annex 2 of this DPA, as published at /policies/dpa/. eXtensi will inform the Customer of any intended addition or replacement of a Sub-processor by notice sent by email to the Customer’s technical or billing contact on record with Atlassian (or through another notification mechanism the Customer has subscribed to), and will additionally update the published list. The Customer may object to the change on reasonable, documented data-protection grounds within 14 days of the date on which that notice is sent.
8.4. If the Customer objects within the 14-day window, the parties will discuss the objection in good faith. If the objection cannot be resolved within a reasonable time, the Customer may terminate the subscription for the affected Cloud App and will receive a pro-rata refund of any prepaid fees covering the remainder of the subscription term after the effective date of termination, processed through the applicable Atlassian Marketplace refund mechanisms or, where those mechanisms do not provide for it, directly by eXtensi. This is the Customer’s sole and exclusive remedy in respect of an objection to a Sub-processor change.
8.5. On the Customer’s written request, eXtensi will provide the information reasonably necessary to enable the Customer to identify the further sub-processors engaged in the processing chain (for example, by referring the Customer to each Sub-processor’s published sub-processor list), so that the Customer can verify the chain of processing.
9. International Data Transfers
9.1. eXtensi hosts and processes Customer Personal Data in the European Union / European Economic Area: eXtensi-hosted Cloud App services run on eXtensi’s dedicated server in an OVHcloud data center in France, and where an App or App feature is built on the Atlassian Forge platform, data is stored within Atlassian’s cloud infrastructure as described in Annexes 2 and 3. eXtensi does not operate Cloud App infrastructure in the United States.
9.2. eXtensi will not transfer Customer Personal Data outside the EU/EEA unless the transfer complies with Chapter V of the GDPR, on the basis of: (a) an adequacy decision of the European Commission covering the recipient country or framework: for recipients in the United States, eXtensi will verify that the recipient holds a valid, active certification under the EU-US Data Privacy Framework before relying on Decision (EU) 2023/1795; or (b) the SCCs, applying the module that matches the actual processing chain (Module Two: controller to processor, or Module Three: processor to processor), together with any necessary supplementary measures. If an adequacy decision relied on for a transfer is invalidated or suspended, or a recipient’s certification under the relevant framework ceases to be valid, eXtensi will promptly either put in place the SCCs (together with a transfer impact assessment and any supplementary measures in accordance with Section 9.3) or suspend the affected transfer.
9.3. Before relying on the SCCs, eXtensi will carry out a transfer impact assessment of the laws and practices of the destination country and will implement supplementary measures where the assessment shows they are needed. On request, eXtensi will provide the Customer with a summary of the transfer mechanism relied on for any given transfer.
10. Assistance with Data Subject Requests
10.1. Taking into account the nature of the processing, eXtensi will assist the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR (including access, rectification, erasure, restriction, portability, and objection).
10.2. If a data subject submits a request directly to eXtensi concerning Customer Personal Data, eXtensi will forward the request to the Customer without undue delay and will not respond to the data subject directly, except to refer the data subject to the Customer or where required by law.
11. Personal Data Breach; Assistance with Articles 32-36 GDPR
11.1. eXtensi will notify the Customer of a personal data breach affecting Customer Personal Data without undue delay, and in any event no later than 48 hours after becoming aware of it.
11.2. The notification will, to the extent the information is available, describe the nature of the breach (including, where possible, the categories and approximate number of data subjects and records concerned), the likely consequences, the measures taken or proposed in response, and a contact point. Where not all information is available at once, eXtensi may provide it in phases without undue further delay.
11.3. eXtensi will cooperate with the Customer in the investigation, mitigation, and remediation of the breach. eXtensi’s notification of, or response to, a breach is not an acknowledgment of fault or liability.
11.4. Taking into account the nature of the processing and the information available to eXtensi, eXtensi will assist the Customer in ensuring compliance with the Customer’s obligations under Articles 32 to 36 GDPR, including security of processing, breach notification to supervisory authorities and data subjects, data protection impact assessments, and prior consultation.
12. Deletion and Return of Customer Personal Data
12.1. During the subscription term, the Customer may obtain an export of End User Data held by eXtensi through the cloud switching and exit assistance described in the End User Terms and the SLA.
12.2. Upon termination or expiration of the agreement, eXtensi will, at the Customer’s choice, delete or return all Customer Personal Data, and will delete existing copies, within 60 days of termination, unless EU or Member State law requires eXtensi to retain specific data (in which case eXtensi will protect the retained data under this DPA, not otherwise process it, and delete it once the retention obligation ends).
12.3. On the Customer’s written request, eXtensi will confirm the deletion in writing.
13. Audit and Information Rights
13.1. eXtensi will make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA.
13.2. Audits proceed as follows. First, the Customer may submit written questions and requests for explanations or documentation to support.no-spam@spam-trap.invalid@extensi.io.invalid; eXtensi will respond within 14 days. If the written explanations are reasonably insufficient to demonstrate compliance, the Customer (or an independent auditor mandated by the Customer) may conduct an announced on-site audit at eXtensi’s premises, on at least 14 days’ prior written notice, during eXtensi’s business hours (Monday through Friday, 8:00–17:00 CET/CEST, excluding Polish public holidays).
13.3. Audits must not unreasonably disrupt eXtensi’s operations, and unless a supervisory authority requires otherwise or an audit follows a personal data breach, audits may take place no more than once in any 12-month period. Each party bears its own costs of the audit. Any auditor must enter into a confidentiality undertaking with eXtensi before the audit; eXtensi may refuse an auditor who is a competitor of eXtensi.
13.4. Sections 13.1 to 13.3 apply without prejudice to the powers of competent supervisory authorities.
14. Liability
14.1. The liability of each party under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the End User Terms, including the increased cap for breaches of security and data-protection obligations equal to three times (3x) the general liability cap, as inherited from the Standard Agreement.
14.2. Nothing in this DPA excludes or limits liability for damage caused intentionally or through gross negligence (cf. Article 473 § 2 of the Polish Civil Code), or any other liability that cannot be limited or excluded under Data Protection Laws or other applicable law, or affects the rights of data subjects or the powers of supervisory authorities under the GDPR, including a data subject’s right to compensation under Article 82 GDPR.
15. Final Provisions
15.1. Notices under this DPA may be sent to eXtensi at support.no-spam@spam-trap.invalid@extensi.io.invalid. eXtensi will send notices to the Customer’s technical or billing contact on record with Atlassian or via the eXtensi website; notices of Sub-processor changes are always given as set out in Section 8.3.
15.2. This DPA is governed by the same law, and subject to the same jurisdiction, as the End User Terms. Amendments to this DPA follow the revision mechanism set out in the End User Terms, except that Sub-processor changes are governed by Section 8.
15.3. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force.
Annex 1: Technical and Organizational Measures
eXtensi implements the following technical and organizational measures for the Cloud Apps. eXtensi does not hold ISO 27001, SOC 2, or comparable certifications and claims none.
- Encryption in transit. All connections to and between Cloud App components are encrypted using TLS.
- Encryption at rest. Customer Personal Data stored by the Cloud Apps is encrypted at rest at the storage layer.
- Tenant isolation. eXtensi-hosted Cloud App services are operated as isolated, per-customer service instances, so that one customer’s data is logically and operationally separated from other customers’ data.
- Access control. Access to production systems and Customer Personal Data is restricted to authorized eXtensi personnel on a least-privilege, need-to-know basis, using individual accounts and strong authentication.
- Backups. Production data is backed up regularly; backups are protected consistently with production data and tested for restorability.
- Logging and monitoring. Production systems are logged and monitored for availability and security-relevant events; logs are protected against tampering.
- Patch and vulnerability management. Operating systems, runtimes, and dependencies are updated regularly; security patches are prioritized, and vulnerability reports received via support.no-spam@spam-trap.invalid@extensi.io.invalid are triaged in line with the SLA.
- Personnel. Personnel with access to Customer Personal Data are bound by confidentiality obligations (Section 6) and instructed in data-protection practices.
- Incident management. eXtensi operates a security-incident process covering identification, containment, assessment, remediation, and the notification duties in Section 11, aligned with eXtensi’s 48-hour incident-reporting obligation toward Atlassian.
- Data minimization and retention. The Cloud Apps request only the Atlassian permission scopes needed for their functionality, and Customer Personal Data is deleted in accordance with Section 12.
Annex 2: Approved Sub-processors
The following Sub-processors are engaged as of the date of this DPA. Items marked “[operator to confirm]” are pending verification and will be finalized before the effective date.
| Entity | Seat / Country | Role | Safeguard |
|---|---|---|---|
| Atlassian Pty Ltd and its affiliates | Australia / USA (global) | Hosting and storage of app data within the Atlassian Forge platform, for Cloud Apps or App features built on Forge | Atlassian Forge Data Processing Addendum, incorporating the SCCs; EU-US Data Privacy Framework verification where applicable |
| OVH SAS (OVHcloud) [operator to confirm the contracting OVHcloud entity on the hosting agreement] | Roubaix, France | Hosting of eXtensi’s dedicated (private) server in an OVHcloud data center in France, which runs the eXtensi-hosted Cloud App services and stores Customer Personal Data, encrypted at rest | Processing in the EU/EEA (France); OVHcloud’s data-processing agreement under Article 28(4) GDPR |
| Mailjet SAS (a Sinch company) | Paris, France | Transactional and support email delivery for the Cloud Apps | Processing in the EU/EEA; Article 28(4) data-processing agreement |
Annex 3: Description of Processing
This Annex describes the processing of Customer Personal Data for the Cloud Apps generically. It serves as the description required by Article 28(3) GDPR and as the exportable-data catalogue referenced in the End User Terms. Each App’s specifics (whether it is eXtensi-hosted, Forge-hosted, or both, its storage location and data-residency support, and its data categories) are published on the App’s Atlassian Marketplace Privacy & Security tab, which supplements this Annex.
- Subject matter: operation of the Cloud Apps as services hosted on eXtensi’s dedicated server in an OVHcloud data center in France and/or, for Apps or App features built on the Atlassian Forge platform, within Atlassian’s cloud infrastructure; and provision of related support and maintenance.
- Duration: the term of the Customer’s subscription, plus the deletion period in Section 12.
- Nature and purposes: hosting, storage (encrypted at rest on eXtensi infrastructure), retrieval, structuring, display, transmission, and backup of data processed by the Cloud Apps within the Customer’s Atlassian products; authentication and authorization of end users via Atlassian; troubleshooting, support, and service operation.
- Categories of personal data: Atlassian account identifiers and display names; email addresses; content that end users post, receive, or share in an App, which may contain any personal data such users choose to include (for example names, roles, team and profile details, or contact details such as a phone number submitted in content or forms); and transient request metadata, such as IP addresses and signed Atlassian context identifiers.
- Categories of data subjects: the Customer’s end users (employees, contractors, and other persons authorized to use the Customer’s Atlassian products) and other individuals whose personal data is contained in content processed through an App.