Data Processing Agreement (DPA)
Last updated - Mar 4, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Amoeboids Technologies Pvt Ltd (“Processor”) and the customer organization using the Roadmap & Idea Portal for Jira Service Management application (“Controller”).
This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with the App and is intended to satisfy the requirements of Article 28 of the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Roles of the Parties
For the purposes of applicable data protection laws:
The Controller determines the purposes and means of processing personal data within its Jira Service Management environment and the App.
Amoeboids Technologies Pvt Ltd acts as a Processor, processing personal data solely on behalf of the Controller.
The Processor does not process personal data for its own independent purposes.
2. Scope of Processing
The Processor processes personal data only to the extent necessary to provide and operate the Roadmap & Idea Portal for Jira Service Management application.
The nature, purpose, categories of personal data, and categories of data subjects are described in Annex I.
3. Processor Obligations
The Processor shall:
Process personal data only on documented instructions from the Controller.
Ensure that personnel authorized to process personal data are subject to confidentiality obligations.
Implement appropriate technical and organizational security measures.
Assist the Controller in responding to data subject rights requests where reasonably required.
Notify the Controller without undue delay after becoming aware of a personal data breach affecting the App.
Delete or return personal data upon termination of the service in accordance with the Controller’s instructions and the data retention terms described in this agreement.
4. Controller Obligations
The Controller is responsible for:
Ensuring that it has a lawful basis for processing personal data.
Providing appropriate privacy notices to its users.
Determining which personal data is processed within the App.
Responding to requests from data subjects exercising their rights under applicable data protection laws.
5. Sub-processors
The Controller authorizes the Processor to engage sub-processors necessary to support the operation of the App.
A current list of sub-processors is maintained by the Processor and is described in Annex III.
The Processor will ensure that sub-processors are subject to appropriate contractual data protection obligations.
6. Security of Processing
The Processor shall implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage.
A summary of these security measures is provided in Annex II.
7. Data Subject Rights
Taking into account the nature of the processing, the Processor shall assist the Controller in fulfilling its obligations to respond to requests from data subjects exercising their rights under applicable data protection laws.
8. Personal Data Breach
In the event of a personal data breach affecting the App, the Processor shall notify the Controller without undue delay after becoming aware of the breach and provide reasonable assistance to support the Controller’s compliance with applicable breach notification obligations.
9. Data Retention and Deletion
Personal data processed by the App will be retained only as long as necessary to provide the App’s functionality.
Upon uninstall of the App, data may remain within Atlassian Forge infrastructure for up to 60 days, after which it is permanently deleted.
10. International Data Transfers
Personal data may be processed within:
Atlassian Cloud infrastructure associated with the Controller’s Jira environment.
Infrastructure located in the European Union (Paris region) used to render the portal interface.
Where applicable, appropriate safeguards will be implemented to protect international data transfers.
11. Liability
Each party’s liability under this DPA shall be governed by the terms of the agreement governing the use of the App.
12. Contact Information
Processor:
Amoeboids Technologies Pvt Ltd
303, Archway, Sopanbaug
Balewadi, Pune – 411045
India
Email: security@amoeboids.com
Annex I – Description of Processing
Nature and Purpose of Processing
Processing necessary to operate the Roadmap & Idea Portal for Jira Service Management application, including displaying roadmap information and collecting user feedback.
Categories of Personal Data
Atlassian account identifiers (account ID, display name, email, avatar)
Votes submitted on roadmap items
Comments and feedback submitted through the portal
Idea submissions
IP addresses used to prevent duplicate voting
Jira issue information used to display roadmap entries
Categories of Data Subjects
Employees or agents of the Controller
Jira users within the Controller’s organization
External users interacting with the roadmap portal
Anonymous portal users
Annex II – Security Measures
The Processor maintains reasonable technical and organizational measures including:
Secure API communication with Atlassian services
Encryption in transit via HTTPS
Restricted access to internal systems
Infrastructure hosted within reputable cloud providers
Security controls implemented within Atlassian Forge infrastructure