Third Party Index

Snapshot 51725

Document
Data processing addendum
URL
https://oktul.com/legal/dpa/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
73649 bytes
SHA-256 (raw)
b0eba0ccd5d8783a717cb51c06c2a2de8ff4906dce46aa3f1aa8e8200449c8a8
SHA-256 (normalized text)
6c1cfb99dfa65b9d26ba4c49d5c4247fd91dc1d98a48fedaddb224aa0b5cabb2

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to content
Legal
Data processing addendum
Version 1.3, effective 05.10.2026. The terms under Article 28 of the GDPR on which Oktul processes personal data on your behalf when you use an Oktul application. This addendum forms part of the application licence and applies from installation.
Last updated 05.10.2026 · Oktul OÜ · Registry code 17589681
1. Parties, scope and precedence
1.1 This data processing addendum (the “Addendum”) is between Oktul OÜ, registry code 17589681, Seebi tn 1-703, 11316 Tallinn, Harjumaa, Estonia (“Oktul”, the processor), and the organisation that installs or uses an Oktul application (“you”, the controller). It forms part of the application licence at oktul.com/legal/app-terms (the “Licence”). Terms defined in the Licence have the same meaning in this Addendum, and “GDPR” means Regulation (EU) 2016/679.
1.2 This Addendum applies to personal data contained in Customer Data processed by an Application. It does not apply to the licence information Atlassian provides to Oktul or to support correspondence, for which Oktul is a controller and which are governed by Oktul’s privacy policy.
1.3 In the event of a conflict, this Addendum prevails over the Licence as regards the processing of personal data.
1.4 This Addendum takes effect with the Licence and remains in effect for as long as Oktul processes personal data on your behalf.
2. Details of the processing
2.1 The processing is described below, as required by Article 28(3) of the GDPR.
Subject matter
Provision of the Application you have installed, as described in its Documentation.
Duration
For as long as the Application is installed on your Atlassian site.
Nature and purpose
Processing data in your Atlassian site, and through the services named in the Application’s privacy policy, to provide the functions of the Application described in its Documentation. No analysis, profiling, enrichment or other secondary use.
Types of personal data
The data the Application reads, writes or receives, which you control: typically Atlassian account identifiers, display names and email addresses, and personal data your users enter in the content the Application processes. A further type named in the Application’s privacy policy, such as the national identification number a signing certificate can carry, is included.
Categories of data subjects
Your users and administrators, where a Jira Service Management portal is used, your customers, and any other person the Application’s privacy policy names, such as a signer invited by email address who has no account on your site.
Special categories of personal data
None intended. The Applications are not designed for the processing of such data.
3. Instructions
3.1 Oktul processes personal data only on your documented instructions, including with regard to transfers to a third country, unless required to do so by Union or Member State law. In that case Oktul informs you of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
3.2 Your instructions consist of the Licence, this Addendum, the Documentation and the configuration set by your administrators.
3.3 Oktul immediately informs you if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
3.4 Oktul does not sell personal data, does not use it to train any model and does not process it for its own purposes.
4. Confidentiality and access
4.1 Oktul ensures that the persons authorised to process personal data are bound by written confidentiality obligations that continue after their engagement ends.
4.2 Access is limited to named personnel and to what a specific support request or defect requires. Oktul has no standing access. For an Application that declares no external permissions, Oktul has no means of access to Customer Data, as the data remains in your Atlassian site and Oktul operates no server or database. Where what an Application writes to the Forge logs, which Atlassian shares with Oktul unless your administrator turns log sharing off, can include Customer Data, its privacy policy says so. Where Oktul requires information to diagnose a fault, it requests the information from you.
5. Security of processing
5.1 Oktul implements the technical and organisational measures required by Article 32 of the GDPR, as set out in this clause.
5.2 The Applications run on Atlassian Forge. According to Atlassian’s documentation, Forge provides tenant isolation and encryption in transit and at rest, and an application that declares no permissions.external and no remotes in its manifest cannot send data outside the Atlassian platform. The permissions of an Application are declared in its manifest and shown to the administrator on installation.
5.3 Oktul applies multi-factor authentication to every account with deployment or support access, full-disk encryption and automatic screen lock on every device, and reviewed changes in source control. Accounts are not shared.
5.4 Oktul holds no security certification. Where an Application has a CSA STAR Level 1 self-assessment, a CAIQ Lite questionnaire of 138 questions, it is published and named in that Application’s privacy policy. A self-assessment is not an independent audit.
5.5 Oktul tests each Application before release. Test figures are published for each Application.
6. Sub-processors
6.1 You give Oktul general written authorisation to engage sub-processors in accordance with this clause.
6.2 Oktul imposes on each sub-processor data protection obligations no less protective than those in this Addendum, and remains fully liable to you for the performance of each sub-processor’s obligations.
6.3 Atlassian Pty Ltd hosts the Applications on the Forge platform on Oktul’s behalf and is Oktul’s sub-processor for that hosting, under the Forge Data Processing Addendum between Atlassian and Oktul and the standard contractual clauses it incorporates. Atlassian’s own sub-processors are listed at atlassian.com/legal/sub-processors. Any other sub-processor of an Application is listed in that Application’s privacy policy.
6.4 Oktul gives at least thirty days’ notice of an intended addition or replacement of a sub-processor that Oktul engages directly, by updating the Application’s privacy policy and release notes. Changes to Atlassian’s own sub-processors are published by Atlassian on the list in clause 6.3; Oktul subscribes to Atlassian’s notifications of those changes and informs you of each through the release notes. You may object on reasonable data protection grounds within that period through the Oktul Help Center. If the parties do not agree on an alternative, you may terminate the Licence for the affected Application; where Atlassian does not refund the fees for the remainder of the Subscription term, Oktul will refund the unused portion.
7. Assistance
7.1 Taking into account the nature of the processing, Oktul assists you by appropriate technical and organisational measures in responding to requests from data subjects exercising their rights. Customer Data is held in your Atlassian site, where your administrators can access, rectify and erase it. Where you require Oktul’s assistance, you may request it through the Oktul Help Center, free of charge.
7.2 Oktul assists you in ensuring compliance with Articles 32 to 36 of the GDPR, including data protection impact assessments and prior consultation, and answers security questionnaires.
7.3 Oktul notifies you of a personal data breach affecting Customer Data without undue delay and in any event within 24 hours of becoming aware of it, with the information then available, the measures taken and the measures recommended. The assessment of whether the breach must be notified to a supervisory authority or to data subjects is yours as controller.
8. Deletion and return
8.1 At the end of the processing, Oktul deletes or returns the personal data, at your choice, unless Union or Member State law requires its storage.
8.2 What remains after an Application is uninstalled, and for how long Atlassian keeps it, is stated in the data portability section of that Application’s privacy policy. Atlassian deletes the data in accordance with its data retention policy and the Forge Data Processing Addendum. You must export the data you require before uninstalling. Oktul holds no copy, backup or extract of Customer Data outside the Atlassian platform except as that section states.
8.3 Personal data Oktul holds outside your Atlassian site, such as support correspondence, is deleted in accordance with the retention periods in Oktul’s privacy policy, or earlier on request, unless the law requires its retention.
9. Information and audits
9.1 Oktul makes available all information necessary to demonstrate compliance with Article 28 of the GDPR, and allows for and contributes to audits, including inspections, conducted by you or by an auditor mandated by you.
9.2 An audit requires reasonable prior notice, takes place during business hours, is subject to confidentiality, and may take place no more than once in any twelve months unless required by a supervisory authority or following a personal data breach. It may not be conducted by a competitor of Oktul. Each party bears its own costs, and you bear Oktul’s reasonable costs of an audit that is not prompted by a breach or by a finding of non-compliance.
9.3 Customer Data is stored on Atlassian’s infrastructure, which is covered by Atlassian’s certifications and audit reports. Oktul’s source code, manifests, access controls and any CSA STAR self-assessment are available for audit.
10. International transfers
10.1 Oktul operates no infrastructure outside the European Economic Area. For an Application that declares no external permissions, Customer Data does not leave the Atlassian platform. Its location is determined by Atlassian: where you have configured data residency for your Atlassian site, Atlassian stores the data in Forge hosted storage in the same location as your product data.
10.2 Where Oktul transfers personal data outside the European Economic Area as exporter, the standard contractual clauses in Commission Implementing Decision (EU) 2021/914, Module Three (processor to processor), apply, governed by Estonian law, with the Estonian Data Protection Inspectorate as the competent supervisory authority. Transfers to Atlassian Pty Ltd rest on the standard contractual clauses incorporated in the Forge Data Processing Addendum.
10.3 Where an Application sends data to a third party by design, the recipient, the data and the purpose are stated in that Application’s privacy policy before installation, and the transfer is made on your instruction.
11. Liability
11.1 Oktul’s obligations under this Addendum and applicable data protection law are not subject to the limitation of liability in clause 15.2 of the Licence.
11.2 Nothing in this Addendum limits the rights of data subjects or the powers of a supervisory authority.
12. Changes
12.1 Oktul may amend this Addendum. Where an amendment is material and adverse to you, Oktul publishes it on this page and in the release notes of each Application concerned, and notifies the technical contact of your Installation by email, at least thirty days before it takes effect.
Version history. 1.3, effective 05.10.2026: the types of personal data and the categories of data subjects include those an Application’s privacy policy names; Forge logs in clause 4.2; a CSA STAR self-assessment stated per Application in clauses 5.4 and 9.3. 1.2, effective 28.09.2026: the description of the processing and clause 8.2 stated for any Application, with retention after uninstallation referred to each Application’s privacy policy; Atlassian Pty Ltd named as sub-processor for Forge hosting; Forge hosted storage retention and data location stated as Atlassian documents them; notice of Atlassian’s own sub-processor changes; refund on objection to a sub-processor. 1.1, effective 28.09.2026: restated in numbered clauses, with the wording of Article 28(3) of the GDPR. 1.0, effective 09.09.2026: first published version.
Questions about this document
Write to legal@oktul.com.
For what a specific application does with the data on your Atlassian site, see the privacy policy in its own documentation. Every application is listed on the applications page. Those answers are per application, so this document does not give them.