Data Processing Agreement
This Data Processing Agreement ("DPA") is entered into by and between the customer using the sielTrace application ("Customer," acting as "Controller") and the individual operating under the trade name "sielTrace" ("Processor," "we," "us," "our"), and forms part of, and is incorporated by reference into, the Terms of Service accepted by Customer. This DPA applies to the extent that sielTrace processes Personal Data on Customer's behalf in connection with the Service. Capitalized terms not defined in this DPA have the meaning given in the Privacy Policy or Terms of Service.
1. Identity of the Processor
sielTrace is operated by an individual (natural person) under the trade name "sielTrace," and is not, as of the Effective Date, incorporated as a separate legal entity. References to "sielTrace," "we," "us," or "our" throughout this DPA refer to that individual, operating from Peru. Customer acknowledges this status. Should sielTrace incorporate as a legal entity in the future, this DPA will be deemed assigned to that entity, and sielTrace will provide notice of the change consistent with Section 13 of the Terms of Service.
2. Definitions
- "Personal Data", "Processing", "Data Subject", "Controller", and "Processor" have the meanings given in the GDPR (Regulation (EU) 2016/679) and, where applicable, the CCPA.
- "Sub-processor" means any third party engaged by sielTrace to process Personal Data on Customer's behalf.
- "Data Protection Laws" means the GDPR, the CCPA, and any other data protection legislation applicable to the processing described in this DPA.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed under this DPA.
3. Roles of the Parties
For the purposes of Data Protection Laws, Customer acts as Controller (or, where applicable, Processor for its own end users, with sielTrace acting as Sub-processor) and sielTrace acts as Processor with respect to the Personal Data processed through the Service. Each party shall comply with the obligations that apply to it under Data Protection Laws in that role.
4. Subject Matter and Duration
The subject matter of this DPA is sielTrace's processing of Personal Data in the course of providing the Service described in the Terms of Service. This DPA takes effect on the date Customer first accepts the Terms of Service and remains in effect for as long as sielTrace processes Personal Data on Customer's behalf, terminating automatically upon termination of the underlying Terms of Service, subject to Section 11 (Return or Deletion of Data) of this DPA.
5. Nature and Purpose of Processing
sielTrace processes Personal Data solely to:
- Refine user stories using Customer's business rules and repository context;
- Generate acceptance criteria and technical context;
- Detect conflicts between requirements and existing business rules or code;
- Provide customer support and maintain the Service;
- Enforce usage quotas and billing.
sielTrace shall not process Personal Data for any purpose other than those set out above, or as otherwise instructed by Customer in writing, unless required to do so by applicable law, in which case sielTrace shall inform Customer of that legal requirement before processing, unless the law prohibits such notice.
6. Categories of Data Subjects
Employees, contractors, and other authorized users of Customer's Atlassian Jira instance who interact with the Service (e.g., issue reporters, assignees, and app administrators).
7. Types of Personal Data
- Atlassian account ID, display name, and email address (provided by Atlassian);
- Content of Jira issues submitted for refinement (titles, descriptions, comments);
- Content of business rules, modules, and Confluence pages voluntarily added to the app;
- Usage and audit log metadata (timestamps, actions taken, IP address).
sielTrace does not intentionally collect special categories of Personal Data (Art. 9 GDPR) or Personal Data of children. Customer shall not submit such data through the Service and shall be solely responsible for any such data submitted in breach of this Section.
8. Processor Obligations
sielTrace shall:
- Process Personal Data only on Customer's documented instructions, as reflected in the Terms of Service and Customer's configuration of the Service, unless otherwise required by applicable law, in which case sielTrace shall inform Customer accordingly unless prohibited from doing so;
- Ensure that any personnel authorized to process Personal Data are bound by written confidentiality obligations;
- Implement the technical and organizational security measures described in the Security Policy (encryption at rest and in transit, logical tenant isolation between organizations, role-based access control for administrative operations, and encrypted storage of secrets), taking into account the state of the art, the costs of implementation, and the nature, scope, and risk of the processing;
- Taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures, insofar as reasonably possible, in responding to Data Subject requests to exercise their rights (access, rectification, erasure, restriction, portability, objection) under Data Protection Laws;
- Assist Customer in ensuring compliance with its obligations under Data Protection Laws relating to the security of processing, Personal Data Breach notification, and data protection impact assessments, taking into account the nature of processing and the information available to sielTrace;
- Notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware, of any Personal Data Breach affecting Customer's Personal Data, providing the information reasonably available at the time and updating it as further information becomes available;
- At Customer's written election made within thirty (30) days of termination of the Service, delete or return all Personal Data processed under this DPA, and delete existing copies, except to the extent applicable law requires retention, consistent with the retention periods described in Section 4.3 of the Privacy Policy;
- Make available to Customer the information reasonably necessary to demonstrate compliance with the obligations in this Section 8.
9. Sub-processors
Customer provides general written authorization for sielTrace to engage the following categories of Sub-processors, each acting under a written agreement imposing data protection obligations no less protective than those set out in this DPA:
- Atlassian — hosting and platform infrastructure (Forge), per Atlassian's Forge Security Policy;
- AI providers — Atlassian's native Forge LLM by default, or a third-party provider (e.g., OpenAI, Anthropic) only if Customer explicitly configures Bring Your Own Key (BYOK);
- Repository providers — GitHub, GitLab, Bitbucket, or AWS CodeCommit, only if and to the extent Customer connects a repository hosted by that provider.
sielTrace remains liable to Customer for the performance of any Sub-processor's data protection obligations to the same extent sielTrace would be liable if performing the services of each Sub-processor directly. sielTrace will provide reasonable advance notice, via email or in-app notification, of the addition or replacement of any Sub-processor category, giving Customer a reasonable opportunity to object on legitimate data protection grounds before the change takes effect.
10. International Data Transfers
Where Personal Data originating in the European Economic Area is transferred outside the EEA (including to the United States or other Atlassian data center regions), such transfer is carried out under Standard Contractual Clauses (SCCs), as made available through Atlassian's Forge platform infrastructure, or another GDPR-approved transfer mechanism providing an adequate level of protection for the transferred data.
11. Return or Deletion of Data
Upon termination of the Terms of Service, sielTrace will delete Customer's Personal Data within the retention periods described in Section 4.3 of the Privacy Policy (within thirty (30) days of account deletion, with audit logs retained for ninety (90) days and encrypted backups retained for up to thirty (30) additional days before automatic deletion), except to the extent a longer retention period is required by applicable law. Customer may request export of its business rules and modules at any time before termination via the "Export Brain" feature in the app.
12. Audits
Upon Customer's written request, and no more than once in any rolling twelve (12) month period, sielTrace shall make available to Customer (or an independent third-party auditor designated by Customer and reasonably acceptable to sielTrace) the information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to an audit conducted by or on behalf of Customer of sielTrace's data processing practices relevant to this DPA. Customer shall provide sielTrace with at least thirty (30) days' advance written notice of any audit and shall make reasonable efforts to avoid or minimize disruption to sielTrace's business operations. Audits shall be conducted during business hours and shall not extend to Personal Data of other sielTrace customers. Costs of an audit shall be borne by Customer, unless the audit reveals a material non-compliance by sielTrace with this DPA, in which case sielTrace shall bear its own reasonable costs of cooperating with that audit.
13. Security Measures
sielTrace maintains the technical and organizational measures described in the Security Policy, including encryption at rest and in transit, logical tenant isolation between organizations, role-based access control for administrative operations, and encrypted storage of secrets (repository tokens and BYOK API keys). sielTrace may update these measures over time provided that such updates do not materially decrease the overall level of protection.
14. Liability
Each party's total liability arising out of or related to this DPA, whether in contract, tort, or otherwise, is subject to the same limitations and exclusions of liability set out in Section 9 of the Terms of Service, including the cap on damages equal to the amount Customer paid to sielTrace in the twelve (12) months preceding the event giving rise to the claim. Nothing in this DPA limits liability that cannot be limited under applicable Data Protection Laws.
15. Governing Law and Disputes
This DPA is governed by, and disputes arising from it are resolved under, the same governing law, informal resolution process, and jurisdiction set out in Section 12 of the Terms of Service (laws of the Republic of Peru; competent courts of Lima, Peru), without prejudice to any mandatory data protection provisions of Customer's jurisdiction that apply notwithstanding this choice of law.
16. Precedence
In the event of a conflict between this DPA and the Terms of Service with respect to the processing of Personal Data, this DPA prevails to the extent of the conflict. In all other respects, the Terms of Service remain in full force and effect.
17. Contact
For questions about this DPA, to request an audit under Section 12, or to exercise rights under Data Protection Laws, contact sieltrace@gmail.com.