Data Processing Addendum
The Article 28 terms on which We The Folks processes personal data on your behalf when you use GitHub Actions for Jira. It forms part of the End User Terms and applies automatically, with no signature required.
Last updated 25 July 2026
Parties and incorporation
This Data Processing Addendum (the Addendum) is entered into between We The Folks (Processor, we) and the organization that installs GitHub Actions for Jira (the App) into its Atlassian Jira site (Controller, you).
It forms part of, and is incorporated into, the End User Terms. It takes effect when you install the App and requires no separate signature. If your procurement process needs a countersigned copy, write to dominik.szymanski@wethefolks.eu.
Definitions
Data Protection Law means Regulation (EU) 2016/679 (the GDPR), the UK GDPR, and any other law on the protection of personal data applicable to the processing under this Addendum.
Controller, processor, data subject, personal data, processing, and personal data breach have the meanings given in the GDPR.
Customer Personal Data means personal data contained in the data the App processes in your Atlassian site, as described in Annex I.
Roles of the parties
You are the controller of Customer Personal Data. We are a processor acting on your behalf. Where you are yourself a processor for another controller, we are a sub-processor, and your instructions to us must be consistent with that controller's instructions to you.
Atlassian is not our sub-processor in the ordinary commercial sense but the platform on which the App runs, and it processes data in your Atlassian site under your own agreement with Atlassian. It is listed in Annex III for completeness, because the App's storage is Atlassian's storage.
Each party is responsible for its own compliance with Data Protection Law. You are responsible for the lawfulness of the personal data you make available to the App and for the notices and legal bases required for it.
Processing on documented instructions
We process Customer Personal Data only on your documented instructions, including on transfers to a third country, unless required to do otherwise by law that applies to us. In that case we will inform you before processing, unless the law prohibits it on important grounds of public interest.
Your documented instructions are:
- This Addendum and the End User Terms.
- The configuration your administrators enter in the App, and the deployments your users launch through it.
- Any further written instruction you give us, as agreed between the parties.
We will inform you if, in our opinion, an instruction infringes Data Protection Law. We do not process Customer Personal Data for our own purposes, and we do not use it to develop or train machine learning models.
Confidentiality of personnel
We ensure that the people authorized to process Customer Personal Data are bound by an obligation of confidentiality, are informed of the confidential nature of the data, and are granted access only where necessary to perform under the End User Terms. Access is limited to the smallest number of people that support and operation of the App require.
Security of processing
We implement appropriate technical and organizational measures under Article 32 of the GDPR, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of the processing, as well as the risk to data subjects. The measures in force are described in Annex II.
We may update those measures over time, provided the level of security is not reduced.
Sub-processors
You give general authorization for the engagement of sub-processors. The sub-processors engaged at the date of this Addendum are listed in Annex III.
We will give at least thirty days' notice, through the Marketplace listing or by updating Annex III, before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may terminate your subscription to the App and stop using it, which is your exclusive remedy.
We impose on each sub-processor data protection obligations no less protective than those in this Addendum, and we remain fully liable to you for their performance.
Assistance with data subject rights
Taking into account the nature of the processing, we assist you by appropriate technical and organizational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights.
In practice, you can do most of this yourself: the App's data is in your own Atlassian site, and your administrators can amend or delete configuration and deployment records directly, or remove them entirely by uninstalling the App. Where a request cannot be handled that way, contact us and we will assist. If a data subject contacts us directly about Customer Personal Data, we will not respond substantively, and will refer them to you without undue delay.
Personal data breaches
We notify you without undue delay, and in any event within forty-eight hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned as far as known, the likely consequences, the measures taken or proposed, and a contact point for further information.
Where we cannot provide all of that at once, we will provide it in phases without further undue delay. We assist you in meeting your own obligations under Articles 33 and 34 of the GDPR.
Impact assessments and prior consultation
We provide reasonable assistance with data protection impact assessments and with prior consultation of a supervisory authority under Articles 35 and 36 of the GDPR, taking into account the nature of the processing and the information available to us. This Addendum and the Privacy Policy are written to give you most of what such an assessment needs.
Deletion and return of personal data
At your choice, we delete or return Customer Personal Data after the end of the provision of services, and delete existing copies, unless law requires storage.
In practice this is automatic:
- Deployment records are deleted thirty days after a deployment reaches a final state, by a scheduled job in the App.
- Disconnecting a project removes that project's GitHub connection. Deleting a configuration removes it.
- Uninstalling the App causes Atlassian to remove the App's storage from your site under its own deletion process for Forge apps.
Because the App holds no copy of Customer Personal Data on infrastructure of ours, there is nothing for us to return or delete separately once the App is uninstalled.
Information and audits
We make available to you the information necessary to demonstrate compliance with Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
Audits are limited to once in any twelve month period, unless a supervisory authority requires otherwise or a personal data breach has occurred; require thirty days' written notice; take place during business hours; must not unreasonably disrupt our operations; and are subject to confidentiality. You bear your own costs.
Because the App runs entirely on Atlassian Forge, the infrastructure controls relevant to an audit are Atlassian's, and Atlassian's own certifications and reports are the appropriate evidence for them. We will provide the information we hold about the App itself.
International transfers
We do not transfer Customer Personal Data outside the platform on which the App runs. We operate no server of our own and hold no copy of it.
Transfers arising from hosting are carried out by Atlassian under its own transfer mechanisms and your agreement with Atlassian. Transfers to GitHub arise from your instruction to dispatch a workflow and from your own relationship with GitHub. Where a transfer nevertheless requires it, the parties agree that the Standard Contractual Clauses approved by the European Commission (Decision 2021/914), module three where we act as a sub-processor and module two where we act as a processor for a controller, apply and are incorporated by reference, with Annex I and Annex II of this Addendum populating their annexes.
Liability and precedence
The limitations of liability in the End User Terms apply to this Addendum, except where Data Protection Law does not permit them.
If this Addendum conflicts with the End User Terms or the Privacy Policy on the processing of personal data, this Addendum prevails. If it conflicts with the Standard Contractual Clauses, those Clauses prevail.
Term
This Addendum takes effect on installation of the App and continues while we process Customer Personal Data on your behalf. Obligations that by their nature should survive, including confidentiality and deletion, survive its end.
Annex I: details of the processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the App: launching GitHub Actions workflows from a Jira issue and tracking their runs. |
| Duration | For as long as the App is installed, plus the retention windows in clause 11. |
| Nature and purpose | Storing per-project configuration, recording who launched which deployment for which issue, dispatching workflows to GitHub, and tracking run status back to the issue. |
| Categories of data subjects | Your personnel and contractors who use Jira: project administrators who configure the App, and users who launch deployments. |
| Categories of personal data | Atlassian account IDs; the display name of the user who launched a deployment; the login of the connected GitHub account or organization; and any personal data your users choose to put into a Jira issue summary or a workflow input value. |
| Special categories | None are requested or required. Do not place special category data into workflow inputs. |
| Frequency | Continuous, on use of the App. |
| Retention | Deployment records: thirty days after a final state. Configuration: until deleted, disconnected, or the App is uninstalled. |
Annex II: security measures
Measures in force, as described in more detail in the Privacy Policy:
- No vendor infrastructure. The App runs entirely on Atlassian Forge. Encryption in transit and at rest, tenancy isolation, access control, physical security, resilience, and backup are provided by the Atlassian platform.
- No stored credentials. No personal access tokens. GitHub installation tokens are minted per operation, used, and discarded. The administrator's OAuth token is held by Forge External Authentication and never read by the App.
- Secret management. The GitHub App private key is held as an encrypted Forge environment variable and is never exposed to the App's interface.
- Least privilege on GitHub. Actions (read and write), Contents (read), Environments (read), and Metadata (read), on the repositories you select.
- Authorization on the server. Launching requires the Jira
EDIT_ISSUESpermission; configuration requires project administrator rights. Both are re-validated server-side on every save and every launch. - Tenant and project isolation. Configuration and deployment records are scoped to the Jira project that owns them, and cross-project access is refused.
- Data minimization. Only the identifiers and values listed in Annex I are stored. Application logs carry identifiers and error messages, not issue content or input values.
- Restricted egress. The App communicates with
github.comandapi.github.comonly. There is no telemetry endpoint and no analytics provider. - Automatic deletion. A scheduled job removes terminal deployment records after thirty days without manual intervention.
Annex III: sub-processors
| Sub-processor | Processing |
|---|---|
| Atlassian | Hosting of the App, its storage, and its logs, and the external authentication that holds the GitHub OAuth connection. Location follows your Atlassian site. |
| GitHub | Receipt of workflow dispatches and the data they carry, and provision of run status. Engaged on your instruction, and also your own independent provider. |
No analytics, error-tracking, advertising, or customer data platform is used.
Contact
Data protection contact: We The Folks, dominik.szymanski@wethefolks.eu. We have not appointed a data protection officer, as the App's processing does not meet the criteria in Article 37 of the GDPR.