Version Select — Data Processing Addendum
Publisher review version — September 10, 2026. Not effective until the execution details and transfer arrangements below are completed and accepted by both parties.
Privacy, security and DPA requests: support@fogsea.top. This is the contact entered by the Publisher in the Marketplace form; mailbox operation must be verified before release.
This Addendum forms part of the App agreement between [CUSTOMER LEGAL ENTITY] (Customer) and [PUBLISHER LEGAL ENTITY AND ADDRESS] (Processor). It applies when the Processor processes personal data on the Customer's behalf to provide VersionSelect. The Customer acts as controller or as a processor authorized by its controller. Applicable Data Protection Law means the laws applicable to that processing, including the GDPR where applicable.
Processing instructions and confidentiality
The Processor will process personal data only on documented Customer instructions, including the App agreement, configuration and authorized support requests, unless law requires otherwise. It will notify the Customer of a legal requirement before processing unless prohibited by law, and promptly inform the Customer if it considers an instruction to infringe applicable data protection law. Persons authorized to process personal data must be bound by confidentiality duties and receive access only as necessary for their work.
Security and incidents
The Processor will maintain technical and organizational measures appropriate to the risks, as specified in Schedule 2, and will not materially reduce the overall protection during the agreement. It will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data. Available information will include its nature, affected data and individuals where known, likely consequences, contact point, and mitigation. Information may be provided in phases without undue delay. Notification does not itself admit liability. The Customer remains responsible for its regulatory and individual notifications, with reasonable assistance from the Processor.
Subprocessors and transfers
The Customer grants general written authorization for the subprocessors specifically identified in the completed Schedule 3. Before adding or replacing a Publisher-appointed subprocessor, the Processor will give at least 30 days’ advance notice to the Customer’s designated email address, allowing an objection on reasonable data protection grounds. The Publisher must monitor upstream provider notices and communicate relevant changes; this clause does not claim control over Atlassian’s own notification timetable. The parties will seek a reasonable resolution; where no compliant alternative is available, the Customer may terminate the affected processing. The Processor will impose equivalent data protection obligations by contract and remains responsible for its subprocessor obligations as required by law.
The Processor will make restricted international transfers only with a lawful mechanism recorded in Schedule 3. Storage location alone is not a transfer mechanism. No SCC module or adequacy basis is deemed completed by this draft. Customer-selected APIs are documented recipients; they are not automatically Processor-appointed subprocessors.
Assistance and audit
Taking account of the processing and available information, the Processor will reasonably assist with individual rights requests, security duties, breach assessment, data protection impact assessments and regulator consultation. Requests received directly concerning Customer-controlled data will be referred promptly to the Customer unless law requires otherwise.
The Processor will make available information necessary to demonstrate compliance and allow and contribute to audits, including inspections, by the Customer or its mandated auditor. Reasonable confidentiality, scope and scheduling arrangements may protect other customers and security but will not prevent legally required audit rights. The Processor will promptly advise if an audit instruction infringes applicable data protection law.
Return and deletion
Customer administrators can create, view, edit, delete and reorder services and versions on the manual data-source configuration page, or maintain the active API catalog in their own backend service. Removing an active catalog entry does not automatically erase old manual-catalog records or Jira field values. Those records follow their separate retention and deletion processes. The Customer initiates and controls administrator actions; the Publisher is not granted access to customer data by this workflow. Customer control of active entries does not replace the need for an available execution path for a valid retained-data deletion instruction.
At the Customer's choice, after processing services end the Processor will return or delete personal data and delete existing copies unless law requires retention. Retained data will be isolated, protected and used only for the legal requirement. The agreed deletion scope, available execution route and completion evidence must be recorded in Schedule 1 before execution. A limitation of the current UI does not waive the Processor’s legal or contractual deletion obligations. If a lawful instruction cannot be fulfilled while the installation remains active, the parties must agree a compliant alternative or stop the affected processing; the Processor must not report an unresolved deletion as complete. Jira values and Customer-selected API records require action by the responsible operator; the Processor will assist within its control.
Priority and signatures
This Addendum prevails over conflicting App terms for its subject matter. Mandatory rights and obligations remain unaffected. Authorized signatures and dates: [CUSTOMER], [PROCESSOR].
Schedule 1 — Processing details
Purpose/nature: provide catalog lookup, Jira field selection snapshots, configuration and customer-directed technical support. Operations: receive, transmit, query, store, retrieve, update and delete as authorized. Duration: service term plus the finalized deletion/legally required retention period.
Data subjects: Customer users or other individuals whose information is incidentally included in catalog content or customer-directed technical support material. Data: catalog names/groups/version values and IDs; lookup text; API URL and credential; operational metadata; personal data in customer-directed technical support material. Independently managed support-contact and legal-compliance records are covered by the Privacy Policy rather than this processing instruction. Special-category data is not intended or required; the Customer must not submit it through catalog fields.
Customer rights/duties: issue lawful instructions, establish a lawful basis, provide required notices, manage access and external recipients, and decide retention of Jira values and exported files.
Complete before signing: applicable retention/deletion deadlines, return format and method, treatment of platform backups and legal holds, Customer notification contact, and validated execution path for old catalog records. The current App has no complete selective-erasure interface; see the support and deletion guidance.
Schedule 2 — Measures
Implemented application measures: installation-scoped Forge hosted storage; Forge secret storage for saved catalog Tokens; no saved Token returned to the browser; HTTPS catalog requests and rejection of redirects; administrator settings separated from field resolvers; validated inputs, pagination and response limits; error mapping that avoids deliberately logging request contents or credentials. Infrastructure encryption and lifecycle depend on Atlassian's applicable service commitments.
Operational measures to validate before signing: named access owners, periodic access review, staff confidentiality, incident contact and procedure, support-file retention, deletion verification and audit evidence. The existence of this document does not certify those practices have already been performed.
Schedule 3 — Providers and locations
Atlassian Pty Ltd (ABN 53 102 443 916): Forge compute, hosted storage and platform logging. This entity is identified in the published Forge DPA. The Publisher must confirm that the applicable Forge account is bound by those terms and retain evidence. See the provider and transfer register for scope and official links. Jira-hosted field values are also governed by the Customer’s separate Atlassian arrangement.
Customer-configured catalog: [Customer records operator, endpoint origin, location, categories received and contractual role.] In manual mode the App does not call this catalog; saved API configuration can remain stored.
Publisher support: the individual Publisher operates in mainland China and uses support@fogsea.top. Customers download logs themselves for their own troubleshooting; the Publisher does not view customer logs online or download them. Customer-controlled downloads are not Publisher-held copies. Receipt of customer-supplied attachments, any additional tools and applicable email/transfer arrangements remain to be confirmed; these must not be inferred from customer self-service troubleshooting.
Schedule 4 — California personal information (where applicable)
Where the Customer is a business subject to the CCPA and the Publisher processes covered personal information on its behalf, the Publisher acts as a service provider for the limited purposes in Schedule 1. It will not sell or share that information; retain, use or disclose it outside those purposes or the direct business relationship; or combine it with information obtained from other customers or its own consumer interactions except as permitted by the CCPA. It will comply with applicable CCPA obligations and provide the same level of protection required by that law.
The Customer may take reasonable and appropriate steps to verify compliant use, and, on notice, stop and remediate unauthorized use. The Publisher will notify the Customer if it can no longer meet these obligations and will assist with applicable consumer requests. Subcontracted processing must be subject to a compliant written contract. The Publisher certifies that it understands and will comply with these restrictions upon execution. This clause does not assert that either party currently meets a statutory definition solely because it signs this document.
Schedule 5 — Execution record
Complete for each executed agreement; customer-specific blanks are normal contract fields, not a declaration that the agreement has already been signed.
- Publisher: an individual operating from mainland China. Legal name and valid contractual address: [PUBLISHER LEGAL NAME], [CONTRACT ADDRESS INCLUDING POSTAL CODE], China
- Customer legal name, address and controller/processor role: [CUSTOMER TO COMPLETE]
- Customer privacy/subprocessor-notice email: [CUSTOMER TO COMPLETE]
- Publisher support access location: mainland China. Contact mailbox: support@fogsea.top. The Publisher does not view customer logs online or download them; customers download logs themselves for their own troubleshooting. The Publisher reports no current ability to view customer logs online. Additional support tools remain to be confirmed.
- Return format and secure delivery method: JSON for available catalog exports; additional configuration return scope and available tooling [AGREE AND VERIFY]. Never email live credentials.
- Deletion scope, execution route, deadline, platform residuals and evidence: [AGREE AND VERIFY]; consult the deletion operating procedure. A manual catalog export is not a complete export of all hosted data.
- Applicable transfer mechanism for each restricted transfer, required annexes, assessment and supplementary measures: [COMPLETE BEFORE RELEVANT TRANSFER].
- Effective date and authorized acceptance/signatures: [BOTH PARTIES].
A signed DPA addresses processing duties. It does not, by itself, complete an international transfer mechanism. The standard contract must not be described as available for acceptance until Publisher-side fields and operational commitments are resolved.