Data Processing Addendum
Version: August 19, 2026
This addendum covers the limited personal-data processing performed by Change Decision Evidence for Jira Service Management.
Agreement and parties
This page supplies the DPA Details for the Bonterms Data Protection Addendum v2.0, Attachment Version, released July 17, 2026 (the “Bonterms DPA”). The Bonterms DPA and these DPA Details are incorporated into the Atlassian Marketplace standard end-user agreement for Change Decision Evidence (the “Main Agreement”).
The “Provider” is Bounded Signal Technologies, British Columbia, Canada. The “Customer” is the customer identified in the Main Agreement. This addendum becomes effective when the Main Agreement identifying it as a Provider-Specific Term takes effect.
Roles and instructions
The Customer is a controller or processor of Customer Personal Data. Bounded Signal Technologies acts as the Customer’s processor or subprocessor, as applicable. The Main Agreement, this addendum, and the Customer’s authorized use and configuration of the app are the Customer’s documented processing instructions.
Processing details
| Service | Change Decision Evidence for Jira Service Management Cloud. |
|---|---|
| Purpose | Read the Jira information visible to the signed-in user and compare selected request details with the latest completed approval that can be connected reliably to the request’s history. |
| Data subjects | Customer users, request participants, approvers, and people identified in Customer-controlled Jira content. |
| Personal data | Jira request fields and selected values; status and timestamps; visible change history; Jira Service Management approval history and decisions; and limited Atlassian account identifiers required to interpret approvals. |
| Frequency | Intermittently when an authorized user opens the recent-changes view or starts a review. |
| Duration | Only for the active request and browser view. The app does not retain Customer Personal Data after processing. |
| Sensitive data | The service does not require sensitive or special-category personal data. Customers should not select such data for review unless their use is lawful and appropriately protected. |
Storage, transfers, and subprocessors
The app runs on Atlassian Forge. It has no app-managed storage, remote service, analytics, advertising tracker, or external data transfer. Jira content remains within Atlassian apps and services and the user’s embedded browser. The app does not log Customer Personal Data.
Atlassian provides Forge compute as Provider’s subprocessor under the Forge Data Processing Addendum and may use the subprocessors on Atlassian’s current subprocessor list. Bounded Signal Technologies uses no additional subprocessor for Customer Personal Data processed by the app. Business email sent voluntarily to Bounded Signal Technologies is separate from app processing and is described in the Privacy Policy.
Security measures
- The app requests only
read:jira-workandread:servicedesk-request. - Jira reads run as the current signed-in user and remain subject to that user’s Jira permissions.
- The app has no Jira write permission, app-managed storage, remote backend, or configured external egress.
- Inputs, Jira responses, pagination, and request counts are bounded and incomplete or ambiguous evidence returns Cannot determine.
- The app does not ask customers for passwords, personal access tokens, or other shared secrets.
Deletion, return, and assistance
Because the app does not retain Customer Personal Data, it has no app-managed customer-content datastore to return or delete. Original Jira data remains under the Customer’s Atlassian controls. Bounded Signal Technologies will provide reasonable assistance required by the Bonterms DPA using the information available to it.
Contact
Privacy and DPA questions: privacy@boundedsignal.com
Security reports: security@boundedsignal.com