Data Processing Agreement

Effective date: September 17, 2026

Key point: This DPA takes effect automatically as part of the Terms & EULA — there is no separate signature step. It applies wherever your use of the app involves us processing personal data on your behalf.

1. Purpose and scope

This Data Processing Agreement ("DPA") supplements the End User Licence Agreement for Contextra Secure Field (the "Agreement") between Contextra Labs ("Processor", "we") and the entity that installed the app ("Customer", "Controller"). It sets out the terms required by Article 28 of the EU General Data Protection Regulation ("GDPR") and, where applicable, UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL").

This DPA is incorporated by reference into the Agreement and takes effect automatically for any Customer whose use of the app processes personal data — matching how the app is actually distributed: a self-service Atlassian Marketplace installation, not a negotiated enterprise contract. If you need a separately countersigned copy for your own records, request one at support@contextra-labs.com.

2. Definitions

Terms not defined here have the meaning given in the GDPR (Article 4) or, where the UAE PDPL applies and its terms differ, the UAE PDPL. In particular:

  • Personal Data — any information relating to an identified or identifiable natural person.
  • Processing — any operation performed on Personal Data, including storage, retrieval, encryption, and deletion.
  • Data Subject — the natural person to whom Personal Data relates.
  • Sub-processor — any third party engaged by the Processor to process Personal Data on the Controller's behalf.
  • Personal Data Breach — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
  • End-User Data — has the meaning used in the Atlassian Marketplace Partner Agreement.

3. Roles of the parties

For Personal Data processed through the app, the Customer is the Controller and Contextra Labs is the Processor. Your own users decide what to type into a Secure Field or Secure Attachment field and who else can see it; our role is to encrypt, store, and permission-gate that value without inspecting or using it for any independent purpose.

The audit log the app generates is worth stating plainly: it is personal data Contextra Labs itself generates, as a direct output of the app's security feature, on the Customer's behalf and at the Customer's instruction. We remain the Processor for that data too, not an independent controller of it.

4. Subject matter, duration, nature, and purpose of processing

Subject matter Encrypting, storing, permission-gating, and logging access to values entered through the Secure Field and Secure Attachment custom field types.
Duration For as long as your subscription is active and the relevant data has not been overwritten, expired, or the app uninstalled. Processing ends, and all Personal Data is deleted, on uninstall.
Nature of processing Server-side AES-256-GCM encryption and decryption; storage in Forge's key-value store; per-request re-evaluation of the field's allow-list; append-only audit logging.
Purpose of processing Providing the app's core function: storing a sensitive value inside Jira in a form that is not the field's own Jira-visible data, gated by an allow-list you configure.
Categories of data subjects Your own Jira users who attempt to reveal, edit, or are denied access to a field — recorded by Atlassian account ID. Separately, and opaquely to us: whoever the encrypted value itself might describe, if your users choose to store personal data as the value — we cannot see, categorize, or identify this.
Categories of personal data Atlassian account IDs (audit log). Encrypted, opaque values (field content) — we do not know their type, format, or whether they constitute personal data at all.

5. Processor obligations

Contextra Labs, as Processor:

  • Processes Personal Data only on documented instructions — the Agreement, this DPA, and your own configuration choices in the app. The app has no mechanism for us to process your data outside what you configure and Jira's own APIs return.
  • Ensures confidentiality — no employee or contractor has an operational need to access your encrypted values or audit log content; the app's resolvers run inside Atlassian's Forge sandbox, not on infrastructure we operate or can inspect ad hoc.
  • Implements the security measures described in our Security Policy, summarized in Section 6 below.
  • Uses no Sub-processors. The only infrastructure involved is Atlassian's own Forge platform, which is not a sub-processor we engaged — it is the platform you chose by installing a Forge app. If this ever changes, we will give you prior written notice and a reasonable opportunity to object before that sub-processor begins processing.
  • Assists with Data Subject rights requests, within the limits of what we can actually see. We can identify, correct, or delete audit log entries concerning a specific Atlassian account ID. We cannot decrypt, search, or identify content within an encrypted field value — a request concerning what your own user chose to store must be directed to, and fulfilled by, you, since you control the allow-list and can reveal or overwrite the value directly.
  • Assists with your own Article 32–36 obligations (security, breach notification, impact assessments) by providing our Security Policy, this DPA, and prompt cooperation on request.
  • Deletes all Personal Data at the end of the relationship. Uninstalling the app deletes every encrypted value, every field's configuration, and the entire audit log. No copy survives at Contextra Labs outside Atlassian's infrastructure to delete separately, because none is ever made.
  • Makes available information to demonstrate compliance and allows audits, subject to reasonable notice, confidentiality, and the practical constraints of a shared multi-tenant Forge platform. Where an audit requires evidence from Atlassian's own environment, we will help you request it through Atlassian's own compliance channels.

6. Security measures (summary)

Full detail is in our Security Policy. In summary: AES-256-GCM authenticated encryption performed only inside the resolver, never in the browser; a deny-by-default allow-list re-evaluated against Jira's own permission APIs on every reveal/edit request; an append-only audit log with its own separate visibility allow-list; an additional Jira site-administrator permission gate on the migration wizard; and reliance on Atlassian's own Forge platform security (tenant isolation, SOC 2, ISO 27001) for everything below the application layer, since Contextra Labs operates no infrastructure of its own for this app.

7. International data transfers

All processing happens exclusively within Atlassian's Forge infrastructure, in the region Atlassian assigns to your site. Contextra Labs does not itself transfer Personal Data to any other country or infrastructure — there is no separate transfer for a GDPR-approved mechanism (Standard Contractual Clauses, adequacy decision, etc.) to attach to, because we never receive a copy of the data outside Atlassian's platform in the first place. If this changes, this DPA will be updated to name the mechanism used.

8. Personal Data Breach notification

We will notify you without undue delay after becoming aware of a Personal Data Breach affecting your data, consistent with our incident response commitment in the Terms & EULA, and will provide the information reasonably available to us to help you meet your own notification obligations under GDPR Article 33/34 or the UAE PDPL.

9. Liability

This DPA does not create liability additional to, or broader than, the liability terms already set out in the Terms & EULA (warranty disclaimer and limitation of liability). Nothing in this DPA excludes or limits any liability that cannot lawfully be excluded or limited under the laws of the United Arab Emirates.

10. Term and termination

This DPA runs for as long as the Agreement is in effect and terminates automatically with it. The deletion obligation in Section 5 survives termination to the extent Personal Data has not already been deleted.

11. Order of precedence

If this DPA conflicts with the Agreement on a matter of data protection, this DPA prevails to the extent of the conflict. On all other matters, the Agreement governs.

12. Governing law and jurisdiction

This DPA is governed by, and construed in accordance with, the federal laws of the United Arab Emirates and the laws of the Emirate of Dubai, matching the Terms & EULA. The courts of the Emirate of Dubai have exclusive jurisdiction over any dispute arising out of or in connection with this DPA.

13. Contact

support@contextra-labs.com

See also the Privacy Policy, Security Policy, and Terms & EULA for Contextra Secure Field for Jira.