Data Processing Agreement
Last updated: June 2026
1. Parties & scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between EthicGuard (operated by Rostyslav Chabria, Kraków, Poland) ("Processor", "we") and the customer organisation using the EthicGuard app ("Controller", "you"). It governs our processing of personal data on your behalf in connection with the app, where required by the EU General Data Protection Regulation (GDPR) and equivalent laws. You are the controller; we are the processor.
2. Subject matter, nature & purpose
We process data solely to provide the Service: reviewing Jira acceptance criteria, producing QA findings and verdicts, and surfacing coverage/defect metrics. Duration: for the term of your subscription. Data subjects: your authorised Jira users. Categories of data: Atlassian account IDs, Jira issue and project identifiers, site (cloud) IDs, and — transiently, in memory, for a single analysis call — Jira issue summaries, descriptions and acceptance-criteria text. We do not store issue content; only identifiers and structured metadata (anchors, scores, message keys, verdict labels, audit records) are retained.
3. Processing on instructions
We process personal data only on your documented instructions (including via your configuration and use of the app), unless required otherwise by law, in which case we will inform you where permitted. We will not sell personal data or use it for our own advertising or profiling.
4. Confidentiality
Personnel authorised to process personal data are bound by confidentiality obligations.
5. Security (Art. 32)
We implement appropriate technical and organisational measures, including: encryption in transit and at rest; per-installation cryptographic isolation; data minimisation (we never store issue content); least-privilege access; redaction of end-user identifiers from logs; and an audit trail of analysis runs.
6. Sub-processors
You authorise us to engage the sub-processors below. We remain responsible for their performance and impose equivalent data- protection obligations on them. We will give notice of changes and allow you to object on reasonable grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Atlassian (Forge / Jira Cloud, Atlassian Intelligence / Rovo) | App runtime and default AI analysis | Per Atlassian's terms (global) |
| Render (managed hosting + PostgreSQL) | Backend hosting and metadata storage | EU (Frankfurt) |
Bring-your-own AI: if you enable a custom AI key, issue content is sent to the AI provider you select (Anthropic, OpenAI, or Google) under your own account and credentials. That provider acts under your direction as part of your own processing arrangement, not as our sub-processor.
7. International transfers
Where personal data of EEA/UK data subjects is transferred outside the EEA/UK (for example to a US-based AI provider), the transfer is made under an approved mechanism — the EU Standard Contractual Clauses and the relevant provider's data-processing terms.
8. Assistance to the Controller
Taking into account the nature of the processing, we will assist you with: responding to data-subject requests; data-protection impact assessments; and security/breach obligations. Because we never store issue content and hold only minimal identifiers, most requests are satisfied by acting on the relevant installation or by uninstalling.
9. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information reasonably available to us to support your own notification duties.
10. Deletion & return
On termination or uninstalling the app, we delete the identifiers and metadata held for your installation (the per-installation secret is revoked and associated records are removed), unless retention is required by law. No issue content is stored, so none persists.
11. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, contribute to audits conducted by you or an auditor you mandate.
12. General
This DPA is governed by the laws of Poland and applicable EU law and is incorporated into the Terms of Service; in case of conflict on the subject of data processing, this DPA prevails. For a countersigned copy or sub-processor notifications, contact admin@ethicguard.ai.