WarrantySync
Data Processing Agreement
The processor terms, in force on installation with no signature required. Four annexes cover the processing details, the technical measures, the sub-processors and restricted transfers.
This Data Processing Agreement (“DPA”) is incorporated into and forms part of the End User Terms for WarrantySync between ITSM Ltd and the customer identified in the applicable Atlassian Marketplace order. It takes effect automatically on installation of the App and requires no signature, but we will countersign a copy on request to support@itsm-ltd.com.
A note on scope before you read further. The App runs entirely on Atlassian Forge and stores all customer data inside Atlassian’s infrastructure. It operates no servers or databases of its own, and it transmits no customer data to us. It does make outbound calls, and they are the point of the product: the App sends device serial numbers to the manufacturer of that device — Dell, Lenovo or HP — to ask when the device’s warranty ends. A serial number is the only customer data that ever leaves Atlassian’s infrastructure. That transmission happens only for a manufacturer the Customer has connected using the Customer’s own credentials, and the manufacturers are independent controllers rather than our Sub-processors: clause 2.5 explains why. The personal data that reaches our own systems remains limited to support correspondence and licence records. This DPA is a full Article 28 agreement, because we still determine how the App processes personal data on your behalf.
1. Definitions
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” have the meanings given in the UK GDPR.
“Customer Personal Data” means Personal Data contained within Your Data (as defined in the End User Terms) that we Process on your behalf under this DPA. “Data Protection Laws” means all laws applicable to the Processing of Personal Data under this DPA, including the UK GDPR, the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), the EU GDPR where applicable, and the Privacy and Electronic Communications Regulations 2003. “Manufacturer” means Dell Inc., Lenovo Group Limited or HP Inc., each operating the warranty lookup service identified in Annex 3, Part B, and any further manufacturer added to the App by a later version. “Manufacturer Credential” means the client identifier, client secret or API key issued to you by a Manufacturer and entered into the App by your administrator. “Restricted Transfer” means a transfer of Personal Data to a country not covered by UK or EU adequacy regulations, where such transfer requires a lawful transfer mechanism. “Standard Contractual Clauses” or “SCCs” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914. “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner under section 119A of the Data Protection Act 2018. “UK GDPR” has the meaning given in section 3(10) of the Data Protection Act 2018. “Sub-processor” means any third party engaged by us to Process Customer Personal Data on our behalf.
“App”, “Atlassian”, “Your Data” and “Subscription Term” have the meanings given in the End User Terms, as do all other capitalised terms not defined here. In the event of conflict between this DPA and the End User Terms in respect of the Processing of Personal Data, this DPA prevails.
2. Roles of the parties
2.1 In respect of Customer Personal Data, you are the Controller and we are the Processor. Where you are yourself a Processor acting for a third-party Controller, we act as a Sub-processor and you warrant that you have the authority of that Controller to enter into this DPA.
2.2 Atlassian’s position in the chain. Because the App is hosted on Atlassian Forge, Atlassian acts as our Sub-processor for the hosting, compute and storage on which the App depends. Atlassian may separately act as your own Processor under your direct agreement with Atlassian for the underlying Jira product. Those two relationships are distinct: this DPA governs only our Processing, and nothing in it varies your agreement with Atlassian.
2.3 We act as an independent Controller in respect of support correspondence, licence and billing records, and business contact data, as described in section 4 of the Privacy Policy. This DPA does not apply to that Processing, which is governed by the Privacy Policy and by Data Protection Laws directly.
2.4 Each party is independently responsible for its own compliance with Data Protection Laws applicable to it in its own role.
2.5 Manufacturers are independent controllers, not our Sub-processors. When you connect a Manufacturer, the App sends device serial numbers to that Manufacturer’s warranty lookup service, authenticated with your own Manufacturer Credential. We are not a party to your agreement with that Manufacturer, we receive nothing from it, and we have no contractual means of imposing obligations on it. The Manufacturer determines its own purposes and means for the data it receives, under its own agreement with you. It is therefore an independent controller receiving Personal Data on your documented instruction, and not a Sub-processor of ours. Annex 3, Part B identifies each Manufacturer, the endpoint it operates and the data it receives. Clause 7.5 (our liability for Sub-processors) does not apply to Manufacturers; clause 4.6 sets out what does.
3. Scope and duration of Processing
3.1 The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are set out in Annex 1.
3.2 This DPA applies for as long as we Process Customer Personal Data on your behalf, and survives termination of the End User Terms to the extent any such Processing continues.
4. Processing on documented instructions
4.1 We will Process Customer Personal Data only on your documented instructions, including in relation to Restricted Transfers, unless required to do otherwise by law to which we are subject. Where such a legal requirement applies, we will inform you before Processing unless the law prohibits it on important grounds of public interest.
4.2 Your instructions comprise: the End User Terms; this DPA; the configuration choices you and your users make within the App; the operations the App performs in response to actions taken by your users; and any further written instructions you give us that we accept in writing.
4.3 The instruction to transmit serial numbers. Storing a Manufacturer Credential in the App is your documented instruction to transmit device serial numbers to that Manufacturer for warranty lookup. A Manufacturer for which no credential is stored is never contacted. You may withdraw that instruction at any time by clearing the credential in the App’s settings, which takes effect immediately and permanently deletes the stored credential.
4.4 We will inform you if, in our opinion, an instruction infringes Data Protection Laws. We may suspend the affected Processing until the instruction is confirmed, withdrawn or amended.
4.5 We will not sell Customer Personal Data, and will not use it for our own purposes, for developing or training any machine learning or artificial intelligence model, for advertising, or for profiling. The App contains no artificial intelligence or machine learning feature and makes no call to any model or inference service.
4.6 Your responsibilities in respect of Manufacturers. You warrant that you hold a valid agreement with each Manufacturer you connect, that you are entitled to use the Manufacturer Credential you enter, and that you are entitled to submit to that Manufacturer the serial numbers of the devices in your estate. You are responsible for satisfying yourself as to that Manufacturer’s own data protection arrangements, including its processing locations and any transfer mechanism it operates, and for any notice or lawful basis your own compliance requires in respect of that disclosure. We do not warrant, and are not responsible for, a Manufacturer’s Processing.
4.7 You warrant that you have a lawful basis for the Processing you instruct, have provided any notices and obtained any consents required, and that your instructions comply with Data Protection Laws. You are responsible for the accuracy and legality of Customer Personal Data and for the content your users place in your Atlassian site — including device and asset names, which are free text and may identify an individual.
5. Confidentiality
We ensure that every person authorised to Process Customer Personal Data is bound by a written obligation of confidentiality or an appropriate statutory duty, that access is granted on a need-to-know and least-privilege basis, and that such persons receive appropriate data protection and security awareness training.
6. Security
6.1 We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 UK GDPR. Those measures are described in Annex 2 and, in more detail, in the Cloud Security Statement at https://warranty.itsm-ltd.com/legal/cloud-security-statement.
6.2 You acknowledge that the security of Customer Personal Data stored by the App depends substantially on controls operated by Atlassian, and that Annex 2 accordingly distinguishes platform-provided measures from measures we implement ourselves.
6.3 We may update the measures in Annex 2 provided the updated measures do not materially reduce the overall level of security.
6.4 You are responsible for the security decisions within your control, including administering user access to your Atlassian site and the App, deciding which of your users may open the App, choosing which Manufacturers to connect, and deciding what data your users place in the records the App reads.
7. Sub-processors
7.1 General authorisation. You give us general written authorisation to engage Sub-processors, subject to this section. The Sub-processors authorised at the effective date are listed in Annex 3, Part A.
7.2 Notice of change. We will give you at least 30 days’ notice of any intended addition or replacement of a Sub-processor, by updating Annex 3 and the sub-processor tables in the Privacy Policy and Cloud Security Statement, and by email to the technical contact on your licence.
7.3 Objection. You may object on reasonable data protection grounds within the notice period by emailing support@itsm-ltd.com. We will work with you in good faith to address the objection. If we cannot do so within 30 days, you may terminate the affected subscription by written notice.
7.4 Objection to Atlassian. Atlassian is a Sub-processor that cannot be replaced or removed: the App exists only on the Atlassian platform. If you object to Atlassian as a Sub-processor, your only remedy is to terminate under clause 7.3.
7.5 Terms and liability. We impose on each Sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for the acts and omissions of our Sub-processors as if they were our own.
7.6 Manufacturers are outside this section. For the reasons in clause 2.5, a Manufacturer is not a Sub-processor and clauses 7.1 to 7.5 do not apply to it. Adding support for a further manufacturer changes the App’s declared egress and requires a new version of the App, which Atlassian re-reviews and which we will notify under clause 16.1; connecting it remains your choice, and until you enter a credential for it the App never contacts it.
8. International transfers
8.1 Customer Personal Data stored by the App resides in Forge hosted storage within Atlassian’s infrastructure. The App does not support Atlassian’s data residency pinning, because it declares outbound access to Manufacturer hosts as handling in-scope end-user data. Where you have pinned your product data to a UK or EEA region, App data is therefore not guaranteed to remain in that region, and Atlassian’s own terms govern where it is processed. Serial numbers transmitted to a Manufacturer also leave your region, because a Manufacturer’s warranty service is operated by that Manufacturer at locations it determines. Annex 3, Part B records the processing location of each Manufacturer so far as it is known to us.
8.2 Where a Restricted Transfer occurs between you and us, the parties agree that the mechanism set out in Annex 4 applies, and that Annex 4 is incorporated into this DPA.
8.3 We will not make a Restricted Transfer of Customer Personal Data except in accordance with Annex 4, on your instruction under clause 4.3, or under another lawful transfer mechanism.
8.4 A transmission of serial numbers to a Manufacturer is a disclosure to an independent controller made on your instruction. The transfer mechanism for that disclosure is a matter between you and the Manufacturer under your agreement with it, and Annex 4 does not purport to govern it. Each party will provide reasonable assistance to the other in carrying out any transfer risk assessment required by Data Protection Laws.
9. Assistance with Data Subject rights
9.1 Taking into account the nature of the Processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise Data Subject rights under Chapter III UK GDPR.
9.2 The practical position. Customer Personal Data held by the App originates in your own Atlassian site, so you can respond to most Data Subject requests directly, using the administrative tools in Jira and, where applicable, JSM Assets. Two points of detail matter when you do:
- Access and rectification. The App’s own copy of a device record is refreshed from your site on each sync. Correcting a device or asset name, or a serial number, at source causes the App’s copy to be corrected on the next run.
- Erasure. The App has no per-record delete control in its interface. A device record is removed automatically by the App’s daily sweep once the record has been stale for twice the configured freshness period and the App has re-queried your site and confirmed the device is gone. Deleting the device at source therefore results in the App’s record being removed, but not immediately. Where you need a record removed sooner than that, contact support@itsm-ltd.com and we will advise what is possible.
9.3 If we receive a request directly from a Data Subject relating to Customer Personal Data, we will not respond to it substantively. We will acknowledge receipt, direct the individual to you, and notify you within 5 business days.
9.4 Assistance under this section is provided at no charge unless a request is manifestly unfounded, excessive or repetitive, or requires bespoke engineering effort, in which case we may charge our reasonable costs, notified to you in advance.
9.5 A request that concerns data held by a Manufacturer must be directed to that Manufacturer, which is an independent controller of what it receives. We can tell you which serial numbers were sent and when; we cannot act on your behalf against a Manufacturer.
10. Personal Data Breach
10.1 We will notify you of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 72 hours of becoming aware of it.
10.2 The notification will include, to the extent known at the time: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information is not all available at once, we will provide it in phases without undue delay.
10.3 We will take reasonable steps to contain, investigate and mitigate the breach, and will preserve relevant evidence.
10.4 We will assist you in meeting your own obligations to notify the Information Commissioner’s Office or other Supervisory Authority and, where required, affected Data Subjects.
10.5 We will not notify any Supervisory Authority or Data Subject about a breach affecting Customer Personal Data on your behalf, or name you publicly in connection with it, unless you instruct us to or we are legally required to.
10.6 We will separately notify Atlassian of security incidents affecting the App within 48 hours, as required by the Atlassian Marketplace Partner Agreement. That notification does not discharge our obligation to you under clause 10.1.
10.7 A breach occurring within a Manufacturer’s own systems is that Manufacturer’s to notify to you under your agreement with it. If we become aware of one, we will tell you what we know and, where the risk warrants it, we will disable the affected Manufacturer in a released version of the App.
11. Data protection impact assessments
Taking into account the nature of the Processing and the information available to us, we will provide reasonable assistance with any data protection impact assessment or prior consultation with a Supervisory Authority under Articles 35 and 36 UK GDPR. We maintain a standard information pack for this purpose, comprising this DPA, the Cloud Security Statement and the App’s scope justifications; that pack will normally be sufficient, and is available from support@itsm-ltd.com.
12. Deletion and return of data
12.1 What the App retains while installed. The App’s retention behaviour is a function of its code, and is as follows:
| Record | Retention |
|---|---|
| Device record (one per device: identifiers, name, serial, warranty end, status) | Held for as long as the device exists in your site. Removed automatically once the record has been stale for twice the configured freshness period and the App has re-queried your site and confirmed the device is gone |
| Batch log of sync runs | The 100 most recent batch records. Older records are pruned automatically. Batch records contain device keys and outcomes; they contain no serial numbers and no device names |
| Pre-scan samples | Overwritten on each pre-scan. Up to 100 device keys and 25 unrecognised manufacturer strings |
| Pending expiry-issue queue | Cleared at the end of every run |
| Manufacturer Credential | Held until your administrator clears it, or until the App is uninstalled |
| Manufacturer access token (Dell only) | Held in encrypted secret storage with a time-to-live of no more than 55 minutes |
| Run lease | Expires automatically after 3 hours |
12.2 On uninstallation. Forge app data is deleted by Atlassian in accordance with Atlassian’s published platform deletion processes for Forge apps. We hold no independent copy of Customer Personal Data and are therefore unable to return or restore it. The timing and completeness of that deletion are determined by Atlassian, not by us; the current position is published by Atlassian.
12.3 If you require an export of App data, you must take it before uninstalling. The App provides a CSV export from its dashboard; because the Forge platform provides no file-download facility, the export is presented on screen for copying and is capped at 2,000 rows per page.
12.4 Support correspondence and licence records that we hold as Controller are retained and deleted in accordance with the retention table in section 10 of the Privacy Policy.
12.5 We may retain Customer Personal Data to the extent required by law, in which case we will continue to protect it in accordance with this DPA and Process it only for the purpose requiring retention.
12.6 Data already received by a Manufacturer is retained and deleted under that Manufacturer’s own arrangements with you. Uninstalling the App does not reach it.
13. Audit and information
13.1 We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR.
13.2 How we satisfy audit rights in practice. In recognition of the fact that we operate no infrastructure and hold no Customer Personal Data outside Atlassian, audit rights are exercised as follows:
- First, by reference to the Cloud Security Statement, this DPA and the App’s published scope justifications.
- Second, by reference to Atlassian’s independent certifications and audit reports covering the infrastructure on which the App runs, which you may obtain directly from Atlassian. We cannot supply Atlassian’s audit reports on Atlassian’s behalf.
- Third, by written questionnaire to support@itsm-ltd.com, which we will answer within 5 business days, no more than once in any 12-month period unless a Personal Data Breach has occurred or a Supervisory Authority requires otherwise.
13.3 On-site or remote inspection. Where the steps in clause 13.2 are demonstrably insufficient to meet a requirement of Data Protection Laws or of a Supervisory Authority, you may conduct an inspection subject to: 30 days’ written notice; conduct during our normal business hours; no more than once in any 12-month period unless a Personal Data Breach has occurred; execution of a confidentiality agreement by you and any auditor; no access to other customers’ data or to our other confidential information; and use of an independent auditor who is not our competitor. You bear your own costs and will reimburse our reasonable costs of supporting an inspection beyond one business day.
13.4 We do not hold, and are not certified under, SOC 2, ISO/IEC 27001 or comparable standards. Section 9 of the Cloud Security Statement explains this and identifies which certifications belong to Atlassian.
13.5 We cannot audit a Manufacturer on your behalf. Audit rights in respect of a Manufacturer arise under your own agreement with it.
14. Liability
14.1 The limitations and exclusions of liability in clause 11 of the End User Terms apply to this DPA, and each party’s total aggregate liability arising out of or in connection with this DPA and the End User Terms together is subject to a single cap as set out in that clause.
14.2 Clause 14.1 does not limit either party’s liability to a Data Subject, or to a Supervisory Authority, or any liability that cannot lawfully be limited under Data Protection Laws.
14.3 Nothing in this DPA affects Article 82 UK GDPR (right to compensation) or Article 83 (administrative fines) as between a party and a Supervisory Authority or Data Subject.
15. California Consumer Privacy Act
Where we Process personal information of California residents on your behalf, we act as a “service provider” as defined by the CCPA as amended by the CPRA. We: Process such personal information only to perform the services under the End User Terms; do not sell or share it; do not retain, use or disclose it for any purpose other than performing the services or as otherwise permitted by the CCPA; do not combine it with personal information from other sources except as permitted; and certify that we understand and will comply with these restrictions. You may take reasonable steps under this DPA to ensure our use is consistent with your CCPA obligations. A disclosure of serial numbers to a Manufacturer at your instruction is made for a business purpose and is not a sale or share.
16. General
16.1 Changes. We may amend this DPA where required by a change in Data Protection Laws, by a Supervisory Authority, or by a change in our Processing. Where an amendment materially reduces your rights, we will give at least 30 days’ notice to the technical contact on your licence, and it will not apply retrospectively or reduce our obligations during your then-current Subscription Term.
16.2 Governing law. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, save where a transfer mechanism in Annex 4 requires otherwise for the Processing to which it applies.
16.3 General provisions. Clauses 13.1 to 13.9 of the End User Terms (assignment, notices, force majeure, third-party rights, severance, waiver, export and sanctions) apply to this DPA as if set out here.
16.4 Order of precedence. Where this DPA conflicts with a transfer mechanism in Annex 4, that mechanism prevails in respect of the transfers it governs.
Annex 1 — Details of the Processing
| Subject matter | Provision of WarrantySync to the Customer through the Atlassian Marketplace |
| Duration | For the duration of the Subscription Term and until the App is uninstalled, plus any period of legally required retention |
| Nature of Processing | Collection, recording, organisation, structuring, storage, retrieval, consultation, use, alteration and erasure of Customer Personal Data within Atlassian Forge hosted storage and the Customer’s Atlassian products, by automated means; and transmission of device serial numbers to a Manufacturer the Customer has connected, for the sole purpose of retrieving that device’s warranty end date |
| Purpose | Determining when the warranty on each device in the Customer’s hardware estate expires, recording that date against the device, and raising Jira issues before expiry; and providing support |
| Frequency | Continuous, in response to user actions; plus one scheduled sync per day at an hour the Customer configures, and an hourly watchdog that resumes or tidies an interrupted run |
Categories of Data Subjects
- The Customer’s employees, contractors and other authorised users to whom a device in the Customer’s hardware estate is assigned, or whose name or identifier appears in a device or asset record
- The Customer’s administrators and technical contacts, including the administrator who configures the App and enters Manufacturer Credentials
- Any individual whose personal data the Customer’s users have entered into the Jira issues or JSM Assets objects that the App reads
Types of Personal Data
The App stores the following in Forge hosted storage. Only the first item is ever transmitted outside Atlassian’s infrastructure.
- Device serial numbers. A serial identifies a device within the Customer’s estate and, where a device is assigned to a named individual, may itself constitute personal data. This is why the App declares its manufacturer egress hosts as in scope for end-user data.
- Device and asset names. Free text controlled by the Customer. These frequently identify an individual in practice — “Jane Smith’s laptop” is a common naming convention — and the Customer determines what they contain.
- Jira issue keys and JSM Assets object keys identifying the record each device came from, together with the internal identifier of that record.
- One Atlassian account identifier, where the Customer’s administrator has chosen an optional default assignee for the Jira issues the App raises. The App requests no user-reading scope, resolves no user, and displays no name or avatar; this identifier is typed in by the administrator and stored verbatim.
- Device attributes retrieved or derived: manufacturer, warranty end date, service level, ship date, derived warranty status and the timestamp of the last check.
- Batch log records — the 100 most recent, each a truncated list of device keys and per-device outcomes for one batch of a sync run. These contain no serial numbers and no device names.
- Pre-scan samples — up to 100 device keys for devices with no serial number or an unsupported manufacturer, and up to 25 unrecognised manufacturer strings.
- A pending queue of expiry-issue candidates, holding up to 200 entries that include serial number and device name, cleared at the end of every run.
- Content the App writes into the Customer’s own Jira site: a warranty end date in the Customer-mapped field; and Jira issues whose description, for a per-device issue, contains the device name, manufacturer, serial number, warranty end date and service level. Digest and first-run summary issues contain no serial numbers.
Manufacturer Credentials are not personal data, but are recorded here for completeness: the client identifier, client secret or API key the Customer’s administrator enters is held in Forge encrypted secret storage, is never returned to any interface, and is never written to a log.
Special category or criminal offence data
None is required by the App. The App does not solicit special category data and has no field in which to record it. If the Customer’s users enter special category or criminal offence data into a device or asset record that the App Processes — for example within a device name — the Customer remains the Controller and is responsible for identifying an Article 9 or Article 10 condition and for notifying us in advance so that we can assess whether additional measures are required.
Location of Processing
Atlassian Forge hosted storage, in a region determined by Atlassian (the App does not support data residency pinning, clause 8.1); and, for serial numbers only, the Manufacturer endpoints identified in Annex 3, Part B.
Annex 2 — Technical and organisational measures
This Annex is the authoritative statement of our technical and organisational measures for the purposes of Article 32 UK GDPR and Annex II of the Standard Contractual Clauses. The Cloud Security Statement at https://warranty.itsm-ltd.com/legal/cloud-security-statement is a narrative expansion of the same measures for security reviewers; where the two differ, this Annex governs.
Measures marked Atlassian are provided by Atlassian as part of the Forge platform. Measures marked ITSM Ltd are implemented by us.
| Area | Measures |
|---|---|
| Pseudonymisation and encryption | Encryption at rest for Forge hosted storage Atlassian. TLS 1.2 or above in transit Atlassian. Manufacturer Credentials and manufacturer access tokens held in Forge encrypted secret storage, write-only by construction — no interface of the App returns a stored credential ITSM Ltd. Manufacturer access tokens held with a time-to-live of no more than 55 minutes ITSM Ltd |
| Confidentiality | Tenant isolation enforced by the Forge platform; storage automatically scoped per installation Atlassian. Exactly three external egress hosts declared in the App manifest, one per supported manufacturer; the Forge platform blocks all other outbound traffic Atlassian / ITSM Ltd. Data minimisation at the egress boundary: the manufacturer adapters accept an array of serial numbers and nothing else, so no device name, account identifier, issue key or issue content is capable of reaching a manufacturer. An automated architecture test asserts that the manifest allowlist and the adapter set correspond in both directions, and fails the build if they diverge ITSM Ltd. A manufacturer for which no credential is stored is never contacted ITSM Ltd. Least-privilege scopes: nine are requested, and the user-reading scope is deliberately not among them ITSM Ltd. Administrator permission re-checked server-side, as the calling user, on every configuration write ITSM Ltd. Written confidentiality obligations and security awareness training for all personnel ITSM Ltd |
| Integrity | Input validation and output encoding, including neutralisation of spreadsheet formula injection in the CSV export ITSM Ltd. Error taxonomy that prevents any credential, token, stack trace or raw upstream response body reaching an interface, a log line or an issue description ITSM Ltd. Peer review and branch protection before release ITSM Ltd. Separation of development, staging and production Forge environments ITSM Ltd |
| Availability and resilience | Platform compute, storage and disaster recovery operated by Atlassian Atlassian. Backup of persistent storage for platform disaster recovery Atlassian. Replicated source control and documented release procedures ITSM Ltd. No independent backup of Customer Personal Data is held by us |
| Restoration of availability | Restoration is a function of Atlassian’s platform disaster recovery Atlassian. We offer no separate RTO or RPO |
| Testing and evaluation | Participation in Atlassian Ecoscanner and Atlassian’s app and partner security review Atlassian / ITSM Ltd. Automated dependency vulnerability audit on every pull request and every change to the main branch, failing the build at any severity ITSM Ltd. Automated test suite with an enforced coverage threshold, and structural tests that fail the build if a non-negotiable architectural property is broken ITSM Ltd. Annual review of this DPA and the Cloud Security Statement ITSM Ltd |
| Access control | Access to source control, the Atlassian developer console and the support inbox restricted to named personnel, protected by multi-factor authentication, reviewed quarterly and revoked on the day a person leaves ITSM Ltd. No administrative back door, support console or data export facility grants us access to Customer Personal Data ITSM Ltd |
| Logging | Platform operational logs produced and retained by Atlassian Atlassian. The App writes no application logs of its own and therefore writes no personal data into logs ITSM Ltd |
| Vulnerability management | Remediation of confirmed vulnerabilities to Atlassian’s cloud-app timeframes: Critical 10 days, High 4 weeks, Medium 12 weeks, Low 25 weeks ITSM Ltd. Automatic propagation of minor and patch releases across all installations Atlassian |
| Incident management | Documented incident procedure; notification to the Customer within 72 hours and to Atlassian within 48 hours ITSM Ltd |
| Data minimisation | The App requests only the scopes required for its documented function, stores only the records necessary to deliver it, prunes its batch log to the 100 most recent records, and clears its pending-issue queue at the end of every run ITSM Ltd |
Annex 3 — Authorised Sub-processors and Manufacturer recipients
Part A — Sub-processors
| Sub-processor | Entity and location | Purpose | Data Processed |
|---|---|---|---|
| Atlassian | Atlassian Pty Ltd (Australia) / Atlassian Corporation (USA); Processing in a region determined by Atlassian; the App does not support data residency pinning (clause 8.1) | Hosting, compute and storage for the App; Marketplace licensing and distribution | All Customer Personal Data Processed by the App |
| Google Workspace | Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland | Delivery and storage of support email | Support correspondence only — not Customer Personal Data held by the App |
| Vercel | Vercel Inc. (Delaware, USA); Processing in the United Kingdom region | Application hosting for the support application built and operated by ITSM Ltd | Support correspondence only — not Customer Personal Data held by the App |
| Supabase | Supabase Inc. (Delaware, USA); Processing in the United Kingdom region (London) | Database and storage for the support application built and operated by ITSM Ltd | Support correspondence only — not Customer Personal Data held by the App |
ITSM Ltd builds and operates its own support application; it is not a licensed third-party product and is therefore not itself a sub-processor, but the providers hosting it are listed above. This Part is kept in step with the sub-processor tables in section 8 of the Privacy Policy and section 10 of the Cloud Security Statement. Changes are notified under clause 7.2.
Part B — Manufacturer recipients (independent controllers)
Each is contacted only if the Customer has stored that manufacturer’s credential. Each receives device serial numbers and the Customer’s own credential, and nothing else.
| Manufacturer | Endpoint | Data received | Processing location |
|---|---|---|---|
| Dell Inc. | apigtwb2c.us.dell.com |
Device serial numbers (service tags); the Customer’s Dell TechDirect client identifier and client secret, at token exchange | United States |
| Lenovo Group Limited | supportapi.lenovo.com |
Device serial numbers; the Customer’s Lenovo Support API client identifier | Not published by them; a matter between you and them under your own agreement — assume outside the UK and EEA |
| HP Inc. | css.api.hp.com |
Device serial numbers; the Customer’s HP warranty API key | Not published by them; a matter between you and them under your own agreement — assume outside the UK and EEA |
These parties are not our Sub-processors: see clause 2.5. They are independent controllers receiving Personal Data on the Customer’s documented instruction, under the Customer’s own agreement with each of them. This Part is kept in step with the corresponding tables in the Privacy Policy and the Cloud Security Statement.
Dell publishes the processing location for its warranty service. Lenovo and HP do not publish one, and we are not in a position to state it on their behalf: we hold no contract with any of the three, the Customer obtains the credential and holds the agreement, and each determines its own purposes and locations for what it receives. The Customer should treat every Manufacturer lookup as a transfer outside the United Kingdom and the EEA unless that Manufacturer has confirmed otherwise to the Customer directly — noting that clause 8.4 and Annex 4E place such a disclosure outside Annex 4, which governs Restricted Transfers between the Customer and us — and should take that into account when deciding which Manufacturers to connect. Connecting none means none is contacted.
Annex 4 — Restricted Transfers
A. Transfers subject to UK Data Protection Laws
Where a Restricted Transfer is subject to the UK GDPR, the parties adopt the EU Standard Contractual Clauses as modified by the UK International Data Transfer Addendum (version B1.0, in force 21 March 2022), completed as follows:
| Item | Completion |
|---|---|
| Addendum Part 1, Table 1 (Parties) | Exporter: the Customer. Importer: ITSM Ltd. Contact details as recorded in the End User Terms and clause 1 of the Privacy Policy |
| Addendum Part 1, Table 2 (Selected SCCs) | Module Two (Controller to Processor), or Module Three (Processor to Processor) where the Customer is itself a Processor |
| Addendum Part 1, Table 3 (Appendix Information) | Annex I(A) and I(B): as set out in Annex 1 of this DPA. Annex II: as set out in Annex 2 of this DPA. Annex III: as set out in Annex 3, Part A of this DPA |
| Addendum Part 1, Table 4 (Ending the Addendum) | Neither party may end the Addendum when the Approved Addendum changes |
| SCC optional clause 7 (docking) | Applies |
| SCC clause 9 (sub-processors) | Option 2, general written authorisation, with the notice period in clause 7.2 of this DPA |
| SCC clause 11 (redress) | The optional independent dispute resolution wording does not apply |
| SCC clause 17 (governing law) | The laws of England and Wales |
| SCC clause 18 (forum) | The courts of England and Wales |
| Competent Supervisory Authority | The Information Commissioner’s Office |
B. Transfers subject to EU Data Protection Laws
Where a Restricted Transfer is subject to the EU GDPR, the parties adopt the Standard Contractual Clauses (Implementing Decision (EU) 2021/914), with the same module selection and optional-clause elections as in Part A, save that: the governing law is the law of Ireland; the forum is the courts of Ireland; and the competent Supervisory Authority is determined in accordance with clause 13 of the SCCs.
C. Transfers subject to Swiss Data Protection Law
Where a Restricted Transfer is subject to the Swiss Federal Act on Data Protection, the SCCs apply with the amendments set out in the Swiss Federal Data Protection and Information Commissioner’s guidance, and references to Supervisory Authorities include the FDPIC.
D. Order of precedence and alternative mechanisms
Where the SCCs or the UK Addendum conflict with any other provision of this DPA or the End User Terms, the SCCs or Addendum prevail in respect of the transfers they govern. If a mechanism adopted here is invalidated, replaced or superseded, the parties will in good faith adopt the successor mechanism or an alternative lawful transfer mechanism without undue delay.
E. Practical note — and what this Annex does not cover
This Annex governs Restricted Transfers between the Customer and ITSM Ltd. In practice those concern support correspondence and licence records. ITSM Ltd’s support application is hosted on Vercel and Supabase, both configured to United Kingdom regions, so that data is stored in the UK; because both providers are US-incorporated and may access data from outside the UK for support and administration of their own services, Part A applies to those transfers.
Customer Personal Data stored by the App remains in the Atlassian region the Customer has configured, and no Restricted Transfer of stored App data arises between the parties in the ordinary course.
Serial numbers sent to a Manufacturer are a separate matter. They leave the Customer’s configured region — Dell’s service is operated in the United States — but that disclosure is made to an independent controller on the Customer’s instruction, under the Customer’s own agreement with that Manufacturer. Clause 8.4 records that the transfer mechanism for it is a matter between the Customer and the Manufacturer, and the Customer should address it in its own transfer risk assessment. ITSM Ltd is neither exporter nor importer in respect of it.
Published in accordance with the Atlassian Marketplace Partner Agreement. Read alongside the Privacy Policy, End User Terms, Cloud Security Statement and Support and Maintenance Description for WarrantySync.
This document names the app WarrantySync; it appears in Jira, and everywhere else on this site, as WarrantySync. They are the same product. Previous versions are available on request from support@itsm-ltd.com.