# Data processing addendum

**Last updated: 09.09.2026**

Version 1.0, effective 09.09.2026. The Article 28 terms on which Oktul processes personal data for you when you use one of our applications. It is incorporated into the application licence, so it applies from the moment you install and you do not have to ask for it.

> **Published, not sent on request** Article 28(3) requires the processor contract to be in place, not obtainable. A document your reviewer has to email for is one they cannot read during the evaluation, which is exactly when they need it. So it is here, at a stable URL the licence cites. If your organisation requires a signed counterpart, ask through the Help Center and we will sign this version unchanged.

## Who this is between, and which role each of us is in

This addendum is between Oktul OÜ (Oktul LLC), registry code 17589681, of Seebi tn 1-703, 11316 Tallinn, Harjumaa, Estonia (“Oktul”, “we”, the processor), and the organisation that installs or uses an Oktul application (“you”, the controller). It forms part of the application licence at oktul.com/legal/app-terms and has no separate term: it starts when that licence does and ends when the processing does.

It covers customer data an application touches inside your Atlassian site. It does not cover the Marketplace licence and contact detail Atlassian passes us, or support correspondence you send us: for both of those Oktul is a controller in its own right, and our privacy policy covers them. Two roles, two documents, and saying which is which is the part most addenda leave out.

Where a term here conflicts with the application licence, this addendum prevails for the processing of personal data and the licence continues to apply to everything else.

## The processing, in the terms Article 28(3) asks for

Set out as a table because that is how a reviewer transfers it into their own record, and because the honest answer to several of these rows is smaller than the question implies.

- **Subject matter:** Providing the Oktul application you have installed, as described in its documentation.
- **Duration:** For as long as the application is installed on your Atlassian site. Uninstalling ends it.
- **Nature and purpose:** Reading, writing and indexing data inside your own Atlassian tenancy so the application's documented features work. There is no analysis, profiling, enrichment or secondary use of any kind.
- **Types of personal data:** Whatever your Atlassian site holds in the fields the application reads or writes, which you control. Typically Atlassian account identifiers, display names and email addresses, and any personal data your own users have put into work item or page content.
- **Categories of data subjects:** Your users, your administrators, and where a Jira Service Management portal is involved, your customers.
- **Special category data:** None is intended, and our applications are not designed for it. Whether your site holds any is a question about your site.

## We process only on your instructions

We process customer data only on your documented instructions, including for transfers, unless EU or Estonian law requires otherwise, in which case we will tell you before processing unless that law forbids it on important grounds of public interest.

Your instructions are: the application licence, this addendum, the application's own documentation, and the configuration your administrators set. Configuring the application is how you instruct it, which is why the licence makes configuration your responsibility and why each application's documentation states what a setting exposes.

If we consider an instruction to infringe the GDPR or other data protection law, we will tell you.

We will not sell customer data, will not use it to train any model, and will not use it for any purpose of our own. There is no exception to this and no setting that changes it.

## Who has access, and on what terms

Access to anything of yours is limited to named personnel bound by written confidentiality obligations that survive the end of their engagement, and it is limited to what a specific support request or defect requires rather than being standing.

Worth stating plainly, because it is the strongest fact in this document: for an application that declares no external permissions, there is no routine access at all. The data stays in your Atlassian tenancy, we operate no server and no database, and there is no console through which anyone here could look at your data. Where we need to see something to diagnose a fault, we ask you for it.

## Security measures

The measures required by Article 32, described as what they actually are rather than as a list of controls we do not operate.

The substantive control is architectural. Our applications run on Atlassian Forge, which provides tenancy isolation, encryption in transit and at rest, and a permission model declared in a manifest that Atlassian reviews. An application that declares no `permissions.external` and no `remotes` cannot reach the network at all, which is a property of the platform rather than a policy we could quietly change.

On our side: multi-factor authentication on every account that can deploy or support, full-disk encryption and automatic screen lock on every endpoint, no shared accounts, and source control with reviewed changes. We hold no certification and say so rather than implying one; what we publish instead is our CSA STAR Level 1 self-assessment, which answers 138 questions in public.

We test each application before release and publish the figures per application rather than as a company claim. Where an application has no suite, its page says so instead of carrying a number.

## Sub-processors

You give general authorisation for us to engage sub-processors on the terms below. We will impose data protection obligations on each that are no less protective than these, and we remain fully liable to you for their performance.

The current list is published per application, in that application's own privacy policy, because it is a per-application fact and a portfolio-wide list would be wrong for at least one of them. An application that keeps every byte inside your tenancy has no sub-processor at all, because there is no data flow for one to sit in. An application that sends data to a named third party names it, on its own page, before you install it.

We will give you at least thirty days' notice before adding or replacing a sub-processor, by updating that application's privacy policy and saying so in its release notes. If you reasonably object on data protection grounds within that period, tell us through the Help Center: we will work with you to find an alternative, and if there is none you may terminate the licence for that application and seek a refund of the unused portion of the fees.

## Helping you meet your own obligations

Taking into account the nature of the processing, we will assist you as Articles 28(3)(e) and (f) require. In practice most of this resolves in your favour more simply than it usually does, and the reason is worth understanding rather than taking on trust.

For a data subject request, the data is in your Atlassian site and your administrators can read, correct and delete it with the same tools they use for the rest of the site. Coming to us first adds a step and cannot produce a faster answer. Where you nevertheless need our help, ask through the Help Center and we will provide it without charge.

We will assist with your data protection impact assessments and any prior consultation, and we will answer a security questionnaire. Our CSA STAR entry answers most of one already.

If we become aware of a personal data breach affecting customer data we process for you, we will tell you without undue delay and in any event within 24 hours, with what we know, what we are doing, and what we recommend you do. We will not decide on your behalf whether it is notifiable: that judgement is the controller's.

## Deletion and return

On the end of the processing you may choose deletion or return of customer data. For our applications this is usually already done by the act of uninstalling.

Uninstalling removes the application's field types and the values stored against them, in the same way Atlassian removes any other custom field, and Forge storage goes with the application. Export what you need before you uninstall. Because all of it lives in your tenancy, deletion is your action rather than a request you make of us, and there is nothing left afterwards: no copy outside your instance, no backup, and no anonymised extract.

Where we hold anything of yours outside your tenancy, which in practice means a support conversation, it is deleted on the retention schedule in our privacy policy or sooner if you ask, unless a law requires us to keep it.

## Information and audit

We will make available the information needed to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

What we ask in return is proportionate rather than obstructive: reasonable notice, no more than once in any twelve months unless a supervisory authority requires it or a breach has occurred, during business hours, subject to confidentiality, and not by an auditor who is a competitor of ours. You bear your own costs and ours if the audit is not the result of a breach or a finding.

Before commissioning one, note what there is to inspect. There is no Oktul data centre, no server and no database. The infrastructure your data sits on is Atlassian's, and Atlassian's own certifications and audit reports are what cover it. What we can show you is our source, our manifest, our access controls and our STAR assessment.

## International transfers

Oktul is in Estonia and we operate no infrastructure outside the EEA. For an application that declares no external permissions, customer data does not leave your Atlassian tenancy at all, and its residency is the residency you have configured for your Atlassian site rather than anything we control.

Where a transfer outside the EEA does occur, it rests on a named mechanism. Where we are the exporter, the EU standard contractual clauses in Commission Implementing Decision (EU) 2021/914 apply, Module Three for processor to processor, with Estonia as the supervisory authority's member state and Estonian law governing. The processors involved and their own mechanisms are named in our privacy policy.

Where an application sends data to a named third party by design, that recipient, what is sent and why are stated on that application's own page before you install it, and the transfer is made on your instruction rather than ours.

## Liability, and how this sits with the licence

Our obligations under this addendum and under applicable data protection law sit outside the liability cap in the application licence. That is stated here as well as there, because a cap that swallowed the processor obligations would make this document decorative and a reviewer is right to check both ends of it.

Nothing here limits a data subject's rights or a supervisory authority's powers, and neither of us can contract out of them.

## Changes to this addendum

We may update this addendum. Where a change is material and adverse to you, we will publish it here and in the release notes of every application it applies to, and tell you by email where we hold an address for your installation, at least thirty days before it takes effect.

The version and date at the top are when this last changed. This is version 1.0, the first published version. Before 09.09.2026 the licence promised this document on request, which is what this replaces.

---

## Published by

- Oktul OÜ (Oktul LLC)
- Oktul OÜ · Reg. nr 17589681 · Tallinn, Harjumaa, Estonia
- Email: hello@oktul.com
- Web: https://oktul.com/
- Atlassian Marketplace: https://marketplace.atlassian.com/vendors/534484195
- Estonian: https://oktul.com/et/
