Plug that App!

Atlassian Marketplace

Data Processing Agreement

The agreement under which we process personal data for you, for every app we publish on the Atlassian Marketplace. It applies from the moment an app is installed, and this public page is its canonical text.

Version 1.2, effective 3 September 2026What changed
Agreement

What this is, and how it applies

  • Version 1.2 is effective from 3 September 2026 and supersedes version 1.0.
  • This agreement is between you — the customer installing an app of ours from the Atlassian Marketplace — and us, Plug that App!, the Marketplace partner publishing it. It forms part of the terms under which you use the app.
  • It applies automatically from the moment an app of ours is installed on your Atlassian site, for as long as it stays installed. Nothing needs to be signed for it to bind us; if your procurement needs a countersigned copy, ask at the address at the end and you will get one.
  • It covers every app we publish under Plug that App! on the Atlassian Marketplace. Today that is Ganttry, and an app added later is covered from the day it is listed.
  • You are the controller

    The personal data an app touches is your employees', your projects' and your customers', in your Atlassian products. You decide what is in there, who may see it, and how long it is kept.

  • We are the processor

    We publish software that processes customer data for the documented scheduling and governance features, including bounded reliability and security events. We do not use customer data for advertising, profiling or unrelated purposes.

  • Atlassian is the sub-processor

    Atlassian supplies Forge compute, KVS, logs and static web-trigger transport and is the only infrastructure sub-processor declared for app processing. Its Forge terms and DPA govern platform processing alongside the customer's Atlassian agreement. Support correspondence must be considered separately in the legal review.

Article 28(3)

The processing, set out

What Article 28(3) requires an agreement like this to pin down before any clause of it: what is processed, for how long, why, and about whom.

  • Subject matter

    The personal data inside your Atlassian products that an app reads when someone uses it; plan, approval, policy, revision and tamper-evident audit records in Forge KVS; and bounded content-free operational events in Forge logs.

  • Duration

    While the app is installed, subject to the feature-specific retention limits. After uninstall, Forge storage follows Atlassian's soft-deletion and recovery lifecycle; logs and customer exports follow their separate retention rules. Uninstall is not immediate physical erasure.

  • Nature and purpose

    Reading work items and the people they belong to to compute and draw schedules; storing the plan; enforcing reviewed Jira changes; producing customer-requested exports/backups; and recording content-free reliability and security events. There is no profiling, advertising or measurement of individuals.

  • Types of personal data

    Atlassian account ids and display names; what work is assigned to whom; availability and allocations; requester, reviewer, policy/revision actor and audit-event actor account ids; and Jira work content selected by the user. Content-free logs deliberately exclude account ids and customer payloads. No special categories are requested, no payment data is processed by the app, and the service is not directed at children.

  • Categories of data subjects

    The people who appear in your Atlassian products: your employees, contractors and collaborators.

Our obligations

What we are bound to as processor

Clauses (a) through (h) of Article 28(3), each in the strongest form the architecture permits. The measures they lean on are itemised on the security page and the data on the privacy policy, both of which are part of this agreement by reference.

We process only on your documented instructions
Installing the app, granting its scopes, using its controls and sending an authenticated integration command are the instructions. Jira permissions, server-side role gates, HMAC roles and the reviewed method/path firewall bound what can happen. We do not transfer the data to our own systems or another vendor. If an instruction would, in our view, infringe data protection law, we will tell you before acting on it.
The people processing it are bound to confidentiality
Access by authorized personnel is limited to their duties and subject to confidentiality obligations. The app has no support impersonation feature, but Forge contributor access, customer-shared logs and support files still require access controls. We do not represent that developer access is technically impossible.
Security measures, per Article 32
The technical measures are the platform's and the app's design together: Atlassian's tenant isolation, encryption in transit and at rest, and a permission model the app cannot exceed; on our side, the narrowest scopes that draw the chart, no credentials of yours asked for or stored, and no egress. The security page lists them item by item, and it is part of this agreement by reference.
Sub-processors need your prior authorisation
The declared infrastructure sub-processor is Atlassian. A proposed change must receive the notice and authorization required by the effective agreement before processing starts. The sub-processor list and relevant app permissions must be updated; permission prompts alone are not a substitute for contractual notice.
We assist with data subject rights
Authorized users can export and correct supported plan values, while policy and audit functions require administrative access. Backups are not a complete subject-access export, and immutable security records have separate retention. Contact the customer administrator and us for requests outside these controls, including any platform assistance required.
We assist with breach notification
If we become aware of a personal data breach touching an app of ours, we notify you without undue delay at the administrator contacts Atlassian holds for your site, with what we know: what happened, what data and whose, and what we are doing. Since the data sits in your tenancy on Atlassian's infrastructure, incidents there are covered by Atlassian's own notification duties as well; ours is to pass on, immediately, anything we learn first.
Deletion and return at the end of processing
Return is the in-app chart backup for the plan-scoped parts in its versioned schema. Jira records, installation-wide source, visits, approval policy/state, enterprise policy, revision history, audit events, security claims, secrets and Forge logs are excluded and follow their separate lifecycle or authorized export. Deletion uses supported feature controls and the Atlassian uninstall lifecycle; support records require separate handling.
We make available what an audit needs
This page, the privacy policy and the security page are the record of processing, kept current and versioned. Beyond them we will answer your questionnaires and complete your audit forms at the address below. We cannot grant physical audits of the infrastructure, because it is Atlassian's, not ours — their own compliance programme and certifications cover it, under your agreement with them.
International transfers

Where the data goes: nowhere

  • The app has no declared external egress or separate vendor-operated customer-data backend. That does not by itself establish that international-transfer obligations are inapplicable.
  • In-scope plan and administrative records use Forge hosted storage and Atlassian's supported pinning and migration controls. Logs, platform operational metadata, customer exports and support correspondence are not covered by that app-storage residency statement.
  • We evaluate the countries, role allocation and required mechanisms under the Forge DPA, customer agreements and relevant law before an international transfer begins.
The rest

Precedence, liability, signatures

  • Order of precedence

    For the processing of personal data, this agreement prevails over anything less specific in the app's listing or our other pages. The privacy policy states the same facts in more detail and neither contradicts the other; if a conflict is ever found, this document wins and we fix the other one.

  • Liability

    Liability under this agreement follows the liability terms of the agreement under which you license the app, and nothing here enlarges or shrinks what the GDPR itself assigns to controller and processor.

  • A countersigned copy

    Write to hi@plugthatapp.com and we will return a signed copy of this version. The public page stays the canonical text: a signature changes who has ink on it, not what applies.

Changes

What changed, and when

A clause is never edited in place. When one changes, the version goes up and the change is written here, before the release that makes it true ships.

  • 1.2 · 3 September 2026Added approval/API control records, content-free operational events, enterprise policy revisions, and tamper-evident administrator/Jira-action audit records.
  • 1.0 · 25 August 2026First published.