Data Processing Agreement

Effective Date: July 16, 2026  |  Last Updated: July 16, 2026

This Data Processing Agreement ("DPA") is entered into by and between the customer using the sielTrace application ("Customer," acting as "Controller") and the individual operating under the trade name "sielTrace" ("Processor," "we," "us," "our"), and forms part of, and is incorporated by reference into, the Terms of Service accepted by Customer. This DPA applies to the extent that sielTrace processes Personal Data on Customer's behalf in connection with the Service. Capitalized terms not defined in this DPA have the meaning given in the Privacy Policy or Terms of Service.

1. Identity of the Processor

sielTrace is operated by an individual (natural person) under the trade name "sielTrace," and is not, as of the Effective Date, incorporated as a separate legal entity. References to "sielTrace," "we," "us," or "our" throughout this DPA refer to that individual, operating from Peru. Customer acknowledges this status. Should sielTrace incorporate as a legal entity in the future, this DPA will be deemed assigned to that entity, and sielTrace will provide notice of the change consistent with Section 13 of the Terms of Service.

2. Definitions

3. Roles of the Parties

For the purposes of Data Protection Laws, Customer acts as Controller (or, where applicable, Processor for its own end users, with sielTrace acting as Sub-processor) and sielTrace acts as Processor with respect to the Personal Data processed through the Service. Each party shall comply with the obligations that apply to it under Data Protection Laws in that role.

4. Subject Matter and Duration

The subject matter of this DPA is sielTrace's processing of Personal Data in the course of providing the Service described in the Terms of Service. This DPA takes effect on the date Customer first accepts the Terms of Service and remains in effect for as long as sielTrace processes Personal Data on Customer's behalf, terminating automatically upon termination of the underlying Terms of Service, subject to Section 11 (Return or Deletion of Data) of this DPA.

5. Nature and Purpose of Processing

sielTrace processes Personal Data solely to:

sielTrace shall not process Personal Data for any purpose other than those set out above, or as otherwise instructed by Customer in writing, unless required to do so by applicable law, in which case sielTrace shall inform Customer of that legal requirement before processing, unless the law prohibits such notice.

6. Categories of Data Subjects

Employees, contractors, and other authorized users of Customer's Atlassian Jira instance who interact with the Service (e.g., issue reporters, assignees, and app administrators).

7. Types of Personal Data

sielTrace does not intentionally collect special categories of Personal Data (Art. 9 GDPR) or Personal Data of children. Customer shall not submit such data through the Service and shall be solely responsible for any such data submitted in breach of this Section.

8. Processor Obligations

sielTrace shall:

9. Sub-processors

Customer provides general written authorization for sielTrace to engage the following categories of Sub-processors, each acting under a written agreement imposing data protection obligations no less protective than those set out in this DPA:

sielTrace remains liable to Customer for the performance of any Sub-processor's data protection obligations to the same extent sielTrace would be liable if performing the services of each Sub-processor directly. sielTrace will provide reasonable advance notice, via email or in-app notification, of the addition or replacement of any Sub-processor category, giving Customer a reasonable opportunity to object on legitimate data protection grounds before the change takes effect.

10. International Data Transfers

Where Personal Data originating in the European Economic Area is transferred outside the EEA (including to the United States or other Atlassian data center regions), such transfer is carried out under Standard Contractual Clauses (SCCs), as made available through Atlassian's Forge platform infrastructure, or another GDPR-approved transfer mechanism providing an adequate level of protection for the transferred data.

11. Return or Deletion of Data

Upon termination of the Terms of Service, sielTrace will delete Customer's Personal Data within the retention periods described in Section 4.3 of the Privacy Policy (within thirty (30) days of account deletion, with audit logs retained for ninety (90) days and encrypted backups retained for up to thirty (30) additional days before automatic deletion), except to the extent a longer retention period is required by applicable law. Customer may request export of its business rules and modules at any time before termination via the "Export Brain" feature in the app.

12. Audits

Upon Customer's written request, and no more than once in any rolling twelve (12) month period, sielTrace shall make available to Customer (or an independent third-party auditor designated by Customer and reasonably acceptable to sielTrace) the information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to an audit conducted by or on behalf of Customer of sielTrace's data processing practices relevant to this DPA. Customer shall provide sielTrace with at least thirty (30) days' advance written notice of any audit and shall make reasonable efforts to avoid or minimize disruption to sielTrace's business operations. Audits shall be conducted during business hours and shall not extend to Personal Data of other sielTrace customers. Costs of an audit shall be borne by Customer, unless the audit reveals a material non-compliance by sielTrace with this DPA, in which case sielTrace shall bear its own reasonable costs of cooperating with that audit.

13. Security Measures

sielTrace maintains the technical and organizational measures described in the Security Policy, including encryption at rest and in transit, logical tenant isolation between organizations, role-based access control for administrative operations, and encrypted storage of secrets (repository tokens and BYOK API keys). sielTrace may update these measures over time provided that such updates do not materially decrease the overall level of protection.

14. Liability

Each party's total liability arising out of or related to this DPA, whether in contract, tort, or otherwise, is subject to the same limitations and exclusions of liability set out in Section 9 of the Terms of Service, including the cap on damages equal to the amount Customer paid to sielTrace in the twelve (12) months preceding the event giving rise to the claim. Nothing in this DPA limits liability that cannot be limited under applicable Data Protection Laws.

15. Governing Law and Disputes

This DPA is governed by, and disputes arising from it are resolved under, the same governing law, informal resolution process, and jurisdiction set out in Section 12 of the Terms of Service (laws of the Republic of Peru; competent courts of Lima, Peru), without prejudice to any mandatory data protection provisions of Customer's jurisdiction that apply notwithstanding this choice of law.

16. Precedence

In the event of a conflict between this DPA and the Terms of Service with respect to the processing of Personal Data, this DPA prevails to the extent of the conflict. In all other respects, the Terms of Service remain in full force and effect.

17. Contact

For questions about this DPA, to request an audit under Section 12, or to exercise rights under Data Protection Laws, contact sieltrace@gmail.com.

This DPA is incorporated into and forms part of the Terms of Service accepted by Customer upon installing or using sielTrace. No separate signature is required unless specifically requested by Customer for internal compliance purposes, in which case Customer may contact sielTrace at the email above to arrange a countersigned copy.