Data Processing Agreement
The agreement under which we process personal data for you, for every app we publish on the Atlassian Marketplace. It applies from the moment an app is installed, and this public page is its canonical text.
Agreement
What this is, and how it applies
- This agreement is between you — the customer installing an app of ours from the Atlassian Marketplace — and us, Plug that App!, the Marketplace partner publishing it. It forms part of the terms under which you use the app.
- It applies automatically from the moment an app of ours is installed on your Atlassian site, for as long as it stays installed. Nothing needs to be signed for it to bind us; if your procurement needs a countersigned copy, ask at the address at the end and you will get one.
- It covers every app we publish under Plug that App! on the Atlassian Marketplace. Today that is Ganttry, and an app added later is covered from the day it is listed.
You are the controller
The personal data an app touches is your employees', your projects' and your customers', in your Atlassian products. You decide what is in there, who may see it, and how long it is kept.
We are the processor
We publish the software that processes that data on your instruction. We decide nothing about what is collected, and we make no use of the data of our own — the architecture leaves us no copy to use.
Atlassian is the sub-processor
The app runs on Atlassian's Forge platform and writes to Forge storage inside your own Atlassian site, under your existing agreement with Atlassian. They are the only sub-processor, and the data never leaves your tenancy.
Article 28(3)
The processing, set out
What Article 28(3) requires an agreement like this to pin down before any clause of it: what is processed, for how long, why, and about whom.
Subject matter
The personal data inside your Atlassian products that an app reads when someone uses it, and the records the app stores in Forge app storage in your site.
Duration
For as long as the app is installed on your site. Uninstalling it ends the processing and removes the app's storage with it.
Nature and purpose
Reading work items and the people they belong to in order to compute and draw the schedule the user asked for, and storing what was computed so it is there next time. Nothing else — no profiling, no analytics, no measuring of individuals.
Types of personal data
Atlassian account ids, display names, what work is assigned to whom, and when individual people are away. No special categories under Article 9, no payment data, and nothing about children — these are business tools sold to organisations.
Categories of data subjects
The people who appear in your Atlassian products: your employees, contractors and collaborators.
Our obligations
What we are bound to as processor
Clauses (a) through (h) of Article 28(3), each in the strongest form the architecture permits. The measures they lean on are itemised on the security page and the data on the privacy policy, both of which are part of this agreement by reference.
- We process only on your documented instructions
- Installing the app, granting its scopes and pressing its buttons are the instructions, and the app can do nothing else: a Forge app's permissions are declared ahead of time and enforced by the platform, not by our restraint. We do not transfer the data anywhere, a third country included, because no path out of your tenancy exists. If an instruction of yours would, in our view, infringe data protection law, we will tell you before acting on it.
- The people processing it are bound to confidentiality
- No person at ours can reach your data at all. There is no admin console, no support impersonation and no back door; an installed app's storage is readable by that app running in your site, not by us. When a support case needs to see something, you send it to us, and the people who then see it are bound by this agreement.
- Security measures, per Article 32
- The technical measures are the platform's and the app's design together: Atlassian's tenant isolation, encryption in transit and at rest, and a permission model the app cannot exceed; on our side, the narrowest scopes that draw the chart, no credentials of yours asked for or stored, and no egress. The security page lists them item by item, and it is part of this agreement by reference.
- Sub-processors need your prior authorisation
- You authorise one: Atlassian, named above. Engaging another is impossible without changing the app itself, and a change that added one would alter the app's declared permissions — which your admin has to approve before the new version runs. We would update this page, bump its version, and record it in the history below before any such release shipped.
- We assist with data subject rights
- Mostly by having built the tooling into the app: access and portability are the in-app backup, erasure and rectification are edits and deletions anyone with chart access can make, and your own Jira administrator can do all of it without us. Where something is stuck, we help at the address below within the response times our SLA commits to.
- We assist with breach notification
- If we become aware of a personal data breach touching an app of ours, we notify you without undue delay at the administrator contacts Atlassian holds for your site, with what we know: what happened, what data and whose, and what we are doing. Since the data sits in your tenancy on Atlassian's infrastructure, incidents there are covered by Atlassian's own notification duties as well; ours is to pass on, immediately, anything we learn first.
- Deletion and return at the end of processing
- Return is the in-app backup: everything the app stores, written to a file you keep, available any day, not just the last one. Deletion is uninstalling, which removes the app's Forge storage, or the in-app deletion of a chart's data before that. We keep no copy to delete on our side, which is the whole of our compliance with this clause and the strongest form it can take.
- We make available what an audit needs
- This page, the privacy policy and the security page are the record of processing, kept current and versioned. Beyond them we will answer your questionnaires and complete your audit forms at the address below. We cannot grant physical audits of the infrastructure, because it is Atlassian's, not ours — their own compliance programme and certifications cover it, under your agreement with them.
International transfers
Where the data goes: nowhere
- We transfer nothing internationally, because we transfer nothing: the data stays in Forge storage in your Atlassian site, in whichever region your site is in.
- If you have pinned your site to a region with Atlassian's data residency settings, the app's storage is pinned with it — by Atlassian, not by a setting of ours.
- Standard Contractual Clauses and adequacy decisions govern transfers between parties, and no transfer to us occurs for them to govern. Transfers inside Atlassian's own infrastructure are governed by your agreement with Atlassian.
The rest
Precedence, liability, signatures
Order of precedence
For the processing of personal data, this agreement prevails over anything less specific in the app's listing or our other pages. The privacy policy states the same facts in more detail and neither contradicts the other; if a conflict is ever found, this document wins and we fix the other one.
Liability
Liability under this agreement follows the liability terms of the agreement under which you license the app, and nothing here enlarges or shrinks what the GDPR itself assigns to controller and processor.
A countersigned copy
Write to hi@plugthatapp.com and we will return a signed copy of this version. The public page stays the canonical text: a signature changes who has ink on it, not what applies.
Changes
What changed, and when
A clause is never edited in place. When one changes, the version goes up and the change is written here, before the release that makes it true ships.
- 1.0 · 25 August 2026First published.