Data Processing Agreement
How Radrly processes personal data on behalf of customers who use MarginRadar (Article 28 GDPR).
Draft of 9 October 2026.
Draft for legal review. Not yet in force. This DPA applies where Radrly acts as a data processor for personal data in the app. It is a working draft until reviewed by counsel. The final version may be offered as a signable document.
1. Parties and scope
This DPA is between the Customer (the “Controller”) and Radrly Sp. z o.o., Poland (the “Processor”; registered office: ul. Tarczyńska 68, 05-831 Krakowiany, Poland; KRS 0001215510, NIP 5342706013, REGON 543658680). It forms part of the End User License Agreement and applies to personal data that the Processor processes on the Controller's behalf through the MarginRadar app. Terms such as “personal data”, “processing” and “supervisory authority” have the meaning given in Regulation (EU) 2016/679 (GDPR).
2. Subject matter, duration and nature
- Subject matter: providing MarginRadar, which calculates cost, revenue, margin and budget forecasts from Jira worklogs.
- Duration: for as long as the Controller has the app installed, plus the retention period described in section 9.
- Nature and purpose: reading Jira data inside Atlassian Forge, calculating figures, storing them in Forge hosted storage, and showing them to authorised users. No processing takes place on Radrly-operated servers.
3. Data and data subjects
- Data subjects: the Controller's employees, contractors and other Jira users whose worklogs, rates or roles are in MarginRadar.
- Categories of personal data: Atlassian account IDs; worklog-derived data (issue key, date, hours, calculated cost and billable value); user rate assignments; role assignments; audit-log entries.
- Special categories: none intended. The Controller should not enter special-category data in the app.
4. Instructions
The Processor processes personal data only on the Controller's documented instructions, which are these terms, the Controller's configuration of the app, and the Controller's use of the app's features. If the Processor believes an instruction infringes data protection law, it will inform the Controller. Processing is also allowed where required by EU or Polish law, in which case the Processor will inform the Controller beforehand where legally permitted.
5. Confidentiality and personnel
The Processor ensures that people authorised to process personal data are bound by confidentiality obligations. As the app runs on Atlassian Forge and has no code path that sends Controller data to Radrly, Radrly staff have no routine access to Controller data.
6. Security
The Processor implements appropriate technical and organisational measures under Article 32 GDPR, described in Annex II and on the Security page. In short: data is stored in Atlassian Forge hosted storage (encrypted at rest by Atlassian), the app has no external egress, access in the app is role-based, and changes are recorded in an audit log.
7. Sub-processors
The Controller gives general authorisation for the sub-processors in Annex III. The Processor will inform the Controller of intended changes so that it can object. The Processor imposes data protection obligations on sub-processors and remains responsible for them.
8. Assistance, personal data breaches and audits
- Data subject rights: the Processor will help the Controller to respond to data subject requests, taking into account the nature of the processing. The Controller can also use the app's in-app deletion and CSV export.
- Breach notification: the Processor will notify the Controller without undue delay, and in any event within 48 hours after becoming aware of a personal data breach affecting the Controller's data, with the information available to it.
- Other assistance: with security, impact assessments and prior consultation, to the extent reasonably required.
- Audits: the Processor makes available the information needed to show compliance and allows reasonable audits, which may be satisfied by documentation, Atlassian's published compliance reports, or a written questionnaire.
9. Return and deletion
The Controller can delete data at any time in the app and can export cost and billable data as CSV. After uninstall, the Forge platform soft-deletes the app's data and destroys it at the end of the retention period in Atlassian's SOC 2 report (a reinstall within 21 days can be relinked to the old data). The Processor keeps no copies, unless law requires otherwise.
10. International transfers
The Processor does not transfer personal data. Data is hosted by Atlassian in the location set by the Controller's Jira data residency choice. Any transfers by Atlassian are governed by Atlassian's own transfer mechanisms and agreements with the Controller.
11. Liability, term and law
Liability under this DPA is subject to the limitations in the End User License Agreement, to the extent the law allows. This DPA lasts as long as the Processor processes personal data for the Controller. It is governed by the laws of Poland, and disputes under it are subject to the competent courts in Warsaw, Poland. If this DPA and the EULA conflict on personal data, this DPA prevails.
Annex II – Technical and organisational measures
- Hosting on Atlassian Forge (Runs on Atlassian). Encryption at rest and in transit provided by Atlassian.
- No egress: the app makes no calls to remote hosts, uses no Forge Remote or Connect, and has no public API.
- Data minimisation: account IDs only as user identifiers; no worklog comments, issue summaries or issue descriptions stored.
- Role-based visibility (Finance, PM, Viewer) and an audit log of budget and rate changes.
- In-app data deletion; CSV export.
- Least-privilege Forge scopes (see Privacy Policy).
- Automated checks (formatting, linting, type checking, unit tests, Forge lint) before every production deployment; vulnerability reporting process (see Security).
Annex III – Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| Atlassian Pty Ltd and affiliates | Forge platform hosting (functions, Forge SQL, Key-Value Store), Jira Cloud, Rovo | As set by the Controller's Jira data residency |
Contact
To request a signed copy of this DPA or to ask questions: support@radrly.com.