Data processing addendum
Effective October 6, 2026
This addendum ("DPA") forms part of the terms of use between NPDesigned LLC ("we", "Processor") and the organization using NPRecycle ("you", "Controller"). It applies when we process Personal Data on your behalf that is subject to Data Protection Laws. If this DPA conflicts with the terms of use, this DPA prevails.
1. Definitions
- Data Protection Laws: all laws that apply to the processing of Personal Data under the terms of use, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, and the California Consumer Privacy Act ("CCPA").
- Personal Data, processing, controller, processor, data subject, Personal Data Breach have the meanings in the GDPR.
- Customer Data: the Personal Data that NPRecycle processes in your Jira site, described in Annex 1.
- Subprocessor: a third party we engage to process Customer Data.
2. Roles
You are the controller of Customer Data, or a processor acting for your own controller. We are your processor, or subprocessor.
3. Processing on your instructions
We process Customer Data only on your documented instructions, unless the law requires otherwise. Your instructions are: the terms of use, this DPA, and your configuration and use of NPRecycle (for example, the retention period, the attachment storage budget and the restores you start). We'll tell you if we believe an instruction breaks Data Protection Laws.
CCPA. We act as your service provider. We won't sell or share Customer Data, retain, use or disclose it outside our direct business relationship with you or for any purpose other than providing NPRecycle, or combine it with personal information from other sources, except as the CCPA allows.
4. How NPRecycle processes Customer Data
NPRecycle runs on Atlassian Forge. It stores Customer Data in Atlassian-hosted storage for your Jira site, and sends none of it to systems we operate. We don't access Customer Data except in the following cases, and only to the extent needed:
- operational logs that Atlassian makes available to us, which are designed to contain identifiers rather than content;
- information that you or your users choose to send us, for example in a support request.
5. Confidentiality
We make sure that anyone we authorize to process Customer Data is bound by confidentiality.
6. Security
We implement the technical and organizational measures in Annex 2, and keep them appropriate to the risk.
7. Subprocessors
You authorize us to use the Subprocessors listed in Annex 3. We'll give at least 30 days' notice of a new Subprocessor by updating this page and notifying customer contacts. You may object on reasonable data protection grounds within that period. If we can't reasonably address the objection, you may stop using NPRecycle. We impose data protection obligations on each Subprocessor that are no less protective than this DPA, and remain responsible for their performance.
8. Data subject requests
Taking into account the nature of the processing, we'll help you respond to requests from data subjects to exercise their rights. Much of this is in your control within NPRecycle. You can shorten the retention period, which deletes deleted work items and their attachment copies sooner, or uninstall NPRecycle. If we receive a request directly, we'll pass it to you.
9. Assistance
We'll provide reasonable help with your data protection impact assessments and consultations with supervisory authorities about NPRecycle, taking into account the information available to us.
10. Personal Data Breaches
We'll notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data. We'll provide the information you reasonably need to meet your obligations, and take reasonable steps to contain and remedy it.
11. Deletion
NPRecycle deletes deleted work items and their attachment copies at the end of the retention period you set. When NPRecycle is uninstalled, Atlassian deletes its stored data according to its retention policy for Forge-hosted storage. We don't keep copies of Customer Data outside NPRecycle's storage, except information you sent us, which we delete on request unless the law requires us to keep it.
12. Audits
We'll make available the information reasonably needed to demonstrate compliance with this DPA, and respond to reasonable written questions. For the hosting infrastructure, we rely on Atlassian's security programs and certifications. If the law requires an audit, it must be on reasonable notice, at your cost, during business hours, no more than once a year, and in a way that protects other customers' data.
13. International transfers
Customer Data stays in Atlassian-hosted storage and follows Atlassian's data residency arrangements for Forge apps. Where a transfer of Personal Data to a country without an adequacy decision occurs under this DPA, the Standard Contractual Clauses adopted by European Commission Decision 2021/914 (Module 2 or 3, as applicable), and for the UK the International Data Transfer Addendum, are incorporated by reference.
14. Liability
Each party's liability under this DPA is subject to the limitations in the terms of use, to the extent Data Protection Laws allow.
Annex 1: Details of processing
| Item | Details |
|---|---|
| Subject matter | Providing NPRecycle: capturing Jira work items so that deleted ones can be restored |
| Duration | While NPRecycle is installed, plus the retention periods in section 11 |
| Nature and purpose | Storing copies of work items, comments, worklogs and attachment files; showing who deleted what; recreating deleted work items on request |
| Data subjects | Users of your Jira site; people mentioned in or affected by work item content |
| Personal Data | Atlassian account ids (of authors, assignees, reporters and the people who delete or restore work items); any personal data in work item content, comments, worklogs and attachment files. Names, email addresses and time zones are removed before storage. |
| Special categories | None intended. Work item content is controlled by you; avoid putting special category data in it unless you have a lawful basis. |
| Frequency | Continuous while installed |
Annex 2: Technical and organizational measures
- Hosting: runs on Atlassian Forge. All Customer Data is stored in Atlassian-hosted storage for your site (Forge SQL and the Forge Object Store). There are no external data transfers.
- Data minimization: user records are reduced to account ids before storage. Names are looked up only when they're displayed. Troubleshooting event details are off by default and exclude names and email addresses.
- Retention: deleted work items are kept for an administrator-set period (7–180 days). Attachment copies are kept within an administrator-set budget, and the oldest are removed first.
- Access control: only Jira administrators can open NPRecycle, and every server-side action re-checks Jira's Administer permission. Restores are recorded with the administrator's account id.
- Least privilege: NPRecycle requests only the Jira scopes listed on the Security page.
- Logging: operational logs are designed to contain identifiers rather than content.
- Personnel: access to logs and support data is limited to people who need it, under confidentiality.
- Vulnerability management: a published security contact, with prompt fixes for reported issues.
Annex 3: Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Atlassian (Atlassian US, Inc. and affiliates) | Forge platform: hosting NPRecycle's code and storage | As set by your organization's Atlassian data residency, where supported |
| Proton Mail for Business (Proton AG) | Support mailbox, only for information you send us | Switzerland |