Data Processing Addendum

Last updated: 19 August 2026

This Data Processing Addendum (“DPA”) is between the Atlassian Cloud customer that installs a Berkly Marketplace app (“Customer”, controller) and Berkly N.V. (“Processor”). It is Berkly’s own DPA. It is not Atlassian’s DPA.

Processor: Berkly N.V., Sint Pieterstraat 34, Kerkrade, the Netherlands

Contact: berkkarabacak@gmail.com

This DPA applies when Customer installs JQL Extensions Library or another Berkly Forge app that processes personal data on Customer’s behalf. It forms part of the agreement created by installing the app from the Atlassian Marketplace and accepting the listing EULA.

1. Roles

Customer is the controller of personal data in its Jira Cloud site. Berkly N.V. is a processor only to the extent the app processes that data to provide the app. Atlassian is a separate processor / infrastructure provider under Customer’s Atlassian Cloud terms. This DPA does not replace Atlassian’s DPA.

2. Subject matter, nature, and purpose

Subject matter: providing the installed Forge app.

Nature and purpose for JQL Extensions Library:

The app does not export issue content off the Atlassian platform and does not use personal data for Berkly’s own marketing.

3. Duration

This DPA lasts for the life of the installation, plus any short period needed to delete residual support email. Uninstall ends processing for that site.

4. Types of personal data and data subjects

Data subjects: Customer’s Jira users and, indirectly, people named in Jira issues that a searcher is already allowed to see.

Personal data for JQL Extensions Library:

Special-category data is not requested. If it appears inside a Jira issue, Jira’s own permission model applies; the app does not copy it.

5. Instructions

Berkly processes personal data only to provide the app and to follow documented Customer instructions (install, configure, uninstall, support). Customer’s instructions are the Marketplace listing, this DPA, and written support requests. Berkly will tell Customer if an instruction appears unlawful.

6. Confidentiality

Anyone acting for Berkly who could see support email is bound to confidentiality. App runtime access is limited to the Forge sandbox on Atlassian.

7. Security

Berkly relies on Atlassian Forge controls: sandboxed functions, Atlassian-managed authentication, and Atlassian-hosted storage. The JQL app requests only read:app-data:jira and write:app-data:jira. There is no external fetch, no vendor logging endpoint, and no Berkly-hosted database of Customer data.

8. Subprocessors

Authorised infrastructure sub-processor: Atlassian Pty Ltd / Atlassian, Inc. (Forge runtime and storage). Berkly uses no other subprocessors for these apps.

Berkly will post a change here before adding a subprocessor and will give Customer a chance to object by uninstalling or by emailing the contact above.

9. International transfers

Berkly does not transfer Customer Jira data to its own systems. Any transfer is inside Atlassian Cloud under Customer’s Atlassian agreement. Support email sent to Berkly may be received in the EU (the Netherlands).

10. Assistance

Because the JQL app does not keep a Customer database, most data-subject requests are handled in Customer’s Jira site. Berkly will reasonably help with requests or DPIAs that actually relate to the app, via the contact email.

11. Personal-data breaches

If Berkly becomes aware of a personal-data breach in its processing, it will notify Customer without undue delay (and where feasible within 72 hours) at the admin email Atlassian has for the site or at an address Customer gives us, with facts then known and steps taken.

12. Deletion and return

On uninstall, Forge app data for that installation is deleted by the platform. Berkly has no separate copy of Jira issues to return. Support email can be deleted on written request.

13. Audits

Customer may ask for information reasonably needed to show this DPA is being met (architecture summary, scopes, and this page). On-site audits are not offered; the apps run only on Atlassian Forge. Customer may also review Atlassian’s independent reports via the Atlassian Trust Center.

14. Liability and law

Liability follows the Marketplace EULA accepted at install. This DPA is governed by the laws of the Netherlands, without affecting mandatory data-protection rights. The competent courts are those of Limburg, the Netherlands, unless a mandatory consumer or data-protection venue applies.

15. Order of documents

If this DPA conflicts with the listing EULA on a data-protection point, this DPA controls for that point. Atlassian’s terms control the Forge platform itself.

16. Related documents

Privacy Policy