IssueRescue

Data Processing Agreement

Effective date: 13 September 2026

This Data Processing Agreement ("DPA") describes how Stephen Hutchins ("IssueRescue", "we", "us"), the developer and provider of IssueRescue for Jira, processes personal data contained in a customer's Jira Cloud data ("Customer Data") when providing IssueRescue for Jira (the "Service") to the organization that has installed it ("Customer", "you").

Controller and processor roles. For personal data contained in Customer Data, Customer is the controller (or, where Customer itself processes that data on behalf of another controller, the processor for that controller) and IssueRescue acts as processor for Customer Personal Data processed to provide the Service, as described below and in the Privacy Policy. Where IssueRescue acts as processor and Atlassian processes Forge-hosted End User Personal Data on IssueRescue's behalf in order to provide the Service (see Section 9), Atlassian acts as IssueRescue's sub-processor, consistent with Atlassian's own Forge Data Processing Addendum. This DPA applies automatically to any Customer that installs and uses IssueRescue for Jira, for as long as the Service is used, and forms part of the terms on which the Service is provided alongside the Terms of Use and Atlassian's standard End User Agreement for the Marketplace subscription.

1. Definitions

"Controller", "Processor", "Sub-processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in Applicable Data Protection Law. "Applicable Data Protection Law" means, to the extent applicable to the processing of Customer Personal Data under this DPA: the UK GDPR and the Data Protection Act 2018; the EU General Data Protection Regulation (Regulation (EU) 2016/679); and any other data protection or privacy law that applies to that processing. "Customer Data" means the data held within Customer's Jira Cloud site — issue fields, comments, worklogs, and associated Atlassian account references — that IssueRescue processes in order to provide the Service, as described in Section 5. "Documentation" means IssueRescue's published product and privacy documentation (this site). This DPA does not claim, and should not be read as claiming, that IssueRescue holds any particular data protection certification.

2. Subject matter and duration

Subject matter: IssueRescue's provision of deletion-recovery ("recycle bin") functionality for Jira Cloud issues, which involves processing Customer Data contained in issues, comments, and worklogs in order to capture, retain, and — on Customer's instruction — restore or permanently delete that data.

Duration: This DPA applies for as long as IssueRescue remains installed on Customer's Jira site, and continues to apply afterwards for any period during which data already captured continues to be held under the retention terms described in Section 10.

3. Nature and purpose of processing

IssueRescue processes Customer Data solely to provide the Service, specifically to:

IssueRescue does not process Customer Data for any other purpose — no advertising, analytics, profiling, or use in training AI/ML models.

4. Categories of personal data

IssueRescue processes:

IssueRescue does not require or request special categories of personal data (such as data revealing health, racial or ethnic origin, political opinions, or similar sensitive data) in order to provide the Service, and nothing about the Service is intended to encourage Customer or its users to place such data into Jira. Because the free-text fields above are authored by Customer's own Jira users, they could incidentally include such data if a user chose to enter it there; IssueRescue does not inspect, classify, or treat such content differently from any other issue content. Customer remains responsible for ensuring that data it or its users enter into Jira, and processes through IssueRescue, is lawful and permitted under Applicable Data Protection Law and under the Atlassian terms governing Customer's Jira Cloud site.

IssueRescue does not collect or store attachment file contents, the full Jira change history/audit log for an issue, or any Atlassian API token, password, or credential — see the Privacy Policy for the full list of what is and isn't collected.

5. Categories of data subjects

Individuals who are, or whose information appears as, Jira users on Customer's Jira Cloud site: an issue's assignee or reporter; a comment or worklog author; the user recorded as having deleted an issue; or an individual @mentioned by another Jira user inside an issue, comment, or worklog. These are typically Customer's own employees or contractors, but may incidentally include any other individual a Jira user has referenced by account mention.

6. Processing on Customer's instructions

IssueRescue processes Customer Data only on Customer's documented instructions. Customer's installation, configuration, and use of the Service (including the actions its administrators take within it — restoring a deleted issue, permanently deleting a stored snapshot), together with this DPA and the other terms applicable to Customer's use of the Service (see Section 17), constitute those documented instructions. Where reasonably necessary, Customer may submit additional lawful instructions to support@issuerescue.co.uk. We will process Customer Data in accordance with those instructions unless we are required to do otherwise by law, in which case we will inform Customer of that legal requirement first unless the law prohibits this.

7. Confidentiality

We ensure that any person we authorize to process Customer Data is subject to an appropriate obligation of confidentiality — whether by contract, professional duty, or otherwise — and that access to Customer Data is limited to what is necessary to provide the Service. This obligation applies to Stephen Hutchins personally as the current operator of IssueRescue, and would extend to any future staff, contractor, or other person we authorize to process Customer Data.

8. Security measures

We implement and maintain the following technical and organizational measures, and will not materially reduce their overall level of protection while this DPA applies:

9. Sub-processing: Atlassian Forge

IssueRescue is built entirely on, and hosted entirely within, Atlassian's Forge platform. Atlassian provides the underlying cloud/platform infrastructure IssueRescue runs on: compute for the app's functions, the Jira Cloud REST API IssueRescue calls to read and write issue data, the Forge Key-Value Store IssueRescue uses for all of its own data storage, and the Forge Personal Data Reporting mechanism described in Section 11. We operate no separate server, database, or hosting infrastructure of our own. No analytics, advertising, or tracking service of any kind receives Customer Data, and none is used by IssueRescue at all.

By installing and using IssueRescue, Customer gives IssueRescue general authorization to use Atlassian as a sub-processor for this purpose, on the terms of Atlassian's Forge Data Processing Addendum. Atlassian may itself engage further sub-processors to provide the Forge platform; the current list of those sub-processors is published by Atlassian at atlassian.com/legal/sub-processors, and notice of, and the ability to object to, any change to that list is handled by Atlassian directly under its own Forge Data Processing Addendum — we do not operate a separate notification mechanism of our own for changes to Atlassian's sub-processors, since we have no independent visibility into or control over that list beyond what Atlassian publishes. We do not engage, and this DPA does not authorize, any sub-processor of our own beyond Atlassian. If that changes, we will update this page and provide reasonable advance notice before Customer Data is processed by any newly engaged sub-processor of ours.

10. Location of data and international transfers

Customer Data is stored within Atlassian's Forge hosted storage, and any international transfer of that data is carried out by Atlassian, not by us — we operate no infrastructure of our own, in any country, that would separately relocate, copy, or transfer Customer Data. Where Atlassian transfers Forge-hosted personal data internationally, the applicable transfer safeguards are governed by Atlassian's Forge Data Processing Addendum, including the EU Standard Contractual Clauses and the related UK and Swiss transfer provisions it incorporates. For Atlassian's own current hosting locations and data-residency options for Customer's Jira site, see Atlassian's published documentation for the Jira Cloud/Forge platform.

11. Assistance with data subject rights

Taking into account the nature of the processing, we provide Customer with reasonable assistance, so far as technically possible, to help Customer respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, and objection) under Applicable Data Protection Law.

IssueRescue also participates in Atlassian Forge's own Personal Data Reporting program, reporting the Atlassian account identifiers it currently stores to Atlassian on a weekly schedule. When Atlassian reports that an account has closed, IssueRescue automatically erases that account's identity information — the account ID, any cached display name, and any @mention of that account embedded in stored content — from every record it holds, while preserving the surrounding content where possible without that identity. When Atlassian reports that an account's data was updated, IssueRescue invalidates its own cached copy of that account's display name while keeping the account identifier itself, since it remains needed for a possible future restore.

This automated process is currently triggered only by Atlassian's own weekly report — it is not yet a self-service, on-demand tool for a named individual. A request received some other way should be sent to privacy@issuerescue.co.uk, and we will handle it without undue delay.

12. Personal data breach cooperation

We will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data processed under this DPA, and will provide Customer with information reasonably available to us to help Customer meet its own breach-assessment and regulator/data-subject notification obligations.

13. Assistance with data protection impact assessments

We provide Customer with reasonable assistance, taking into account the nature of processing and information available to us, with any data protection impact assessment and any prior consultation with a supervisory authority that Customer is required to carry out under Applicable Data Protection Law in relation to its use of the Service. Contact privacy@issuerescue.co.uk to request this assistance.

14. Deletion and retention of data

Two separate retention mechanisms apply, at different layers — see the Privacy Policy for the full customer-facing description:

In addition to the above, upon termination of the Service or a valid request from Customer, we will, at Customer's choice and subject to applicable law, delete the Customer Data we hold or make a copy of it available to Customer where reasonably and technically possible, and will then delete any remaining copies in our possession, except to the extent we are required by law to retain it. IssueRescue does not currently offer a self-service, on-demand bulk-export feature — a request under this Section should be sent to privacy@issuerescue.co.uk, and we will respond based on what is reasonably and technically possible given the data described in Section 4 and the retention mechanisms described above.

15. Audits and compliance information

We will make available to Customer information reasonably necessary to demonstrate our compliance with this DPA — which may consist of this DPA, the current Privacy Policy, and a written summary of the security measures in Section 8, rather than bespoke material prepared for each request. We will also allow, and contribute to, reasonable audits or inspections that Customer (or its mandated auditor) is required to carry out under Applicable Data Protection Law, including in relation to this DPA and Section 8. This is subject to reasonable advance notice, reasonable confidentiality and security protections, and avoiding unnecessary disruption to the Service; given the nature of the Service — a single-operator, Forge-hosted app with no separate physical infrastructure of our own — an audit or inspection under this Section will ordinarily take the form of documentation review and written questions rather than an on-site visit, unless the Parties agree otherwise or applicable law requires more.

16. Termination

This DPA terminates when Customer uninstalls IssueRescue and the retention periods described in Section 14 have run their course, or when the agreement(s) governing Customer's use of the Service otherwise end, whichever is later. Sections of this DPA that by their nature should survive termination (including confidentiality and any obligations relating to data already retained under Section 14) continue to apply for as long as relevant.

17. Relationship to your Marketplace subscription

This DPA supplements, and does not replace, Atlassian's standard customizable End User Agreement (EUA) governing Customer's Marketplace subscription for IssueRescue, and any IssueRescue-specific Provider-Specific Terms we publish alongside it (see the Terms of Use). We do not reproduce or restate Atlassian's EUA text in this DPA, and this DPA does not itself set out a separate liability cap — liability in connection with the Service is addressed under the agreement(s) governing your subscription. For matters concerning the processing of personal data, this DPA prevails over any conflicting provision of the Terms of Use, any Provider-Specific Terms, or the Atlassian EUA, to the extent of that conflict.

18. Governing law

The governing law and jurisdiction for the Atlassian standard End User Agreement covering your Marketplace subscription is as set out in that agreement. For this DPA and any IssueRescue Provider-Specific Terms we publish, the governing law is the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising specifically from them.

19. Contact

Schedule 1 — Details of processing

Subject matterProvision of deletion-recovery functionality for Jira Cloud issues
DurationFor as long as IssueRescue is installed on Customer's Jira site, plus the retention periods in Section 14
Nature of processingAutomated capture on Jira issue events; storage in Forge's hosted Key-Value Store; administrator-triggered restoration or permanent deletion; weekly Personal Data Reporting to Atlassian with automated erasure/invalidation on closed/updated accounts
Purpose of processingSolely to provide the deletion-recovery ("recycle bin") functionality described in the Documentation
Categories of data subjectsJira users on Customer's site acting as issue assignees, reporters, comment/worklog authors, or issue deleters; individuals @mentioned inside issue, comment, or worklog content
Categories of personal dataAtlassian account identifiers and, where available, display names for the roles above, including where embedded as an @mention; free-text issue/comment/worklog/custom-field content that may incidentally contain personal data; restore/history metadata
Retention — deleted-issue snapshotsUp to 30 days from deletion, enforced by a scheduled daily cleanup plus opportunistic checks; an administrator can also delete a specific snapshot immediately
Retention — after uninstallGoverned by Atlassian's own Forge platform hosted-storage lifecycle (Section 14), not by us

Schedule 2 — Security measures

See Section 8 above for the full list of technical and organizational measures currently in place.