Data Processing Addendum
Data-processing terms, security measures, deletion commitments, and subprocessors for Vivid Connector for Jira and Telegram.
- Effective date
- Version
- 1.0
- Product
- Vivid Connector for Jira and Telegram
Vivid Connector for Jira and Telegram (Forge Edition) Effective date: 31 July 2026 Version: 1.0
This Data Processing Addendum (“DPA”) forms part of the agreement for the App between the customer identified in the applicable Atlassian Marketplace order (“Customer”) and VIVID INSIGHT UNIPESSOAL LDA, NIF 517951371, registered at Rua Victor de Sá, 33, 4715-586 Braga, Portugal (“Provider”).
1. Definitions
“Applicable Data Protection Law” means laws applicable to Processing under the agreement, including the GDPR and applicable Portuguese implementing law. “Customer Personal Data” means Personal Data Processed by Provider on Customer's behalf through the App. “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Process/Processing”, “Personal Data Breach”, and “Supervisory Authority” have the meanings in Applicable Data Protection Law.
“Customer-Directed Service” means a third-party service selected, administered, or contracted by Customer to which Customer instructs the App to send data, including Customer's Telegram environment/bot.
2. Scope, roles, and instructions
Customer is Controller (or a Processor authorized by the relevant Controller) and Provider is Processor for Customer Personal Data. Each party is independently responsible as Controller for personal data it processes for its own account, such as business contacts, Marketplace administration, legal compliance, or support relationship records.
Provider will Process Customer Personal Data only:
to provide, secure, support, and maintain the App under the agreement;
according to Customer's configuration and documented instructions, including delivery to Customer-Directed Services;
as described in Annex 1; or
where required by law, after notifying Customer unless prohibited.
The agreement, this DPA, Customer's App configuration, and authorized support requests are Customer's documented instructions. Provider will notify Customer if it believes an instruction infringes Applicable Data Protection Law and may suspend the affected Processing while the parties resolve it.
Customer warrants that it has all rights, lawful bases, notices, and authorization needed for Customer Personal Data and instructions, including disclosure to Telegram chats and use of Jira user/work data. Customer will not instruct Provider to Process data that violates law or third-party rights.
3. Confidentiality and personnel
Provider will ensure persons authorized to Process Customer Personal Data are bound by confidentiality obligations and receive appropriate security/privacy guidance. Access will be limited to what is necessary for operation, support, security, and legal compliance.
4. Security
Provider will maintain appropriate technical and organizational measures proportionate to risk, including the measures in Annex 2. Provider may update measures as technology and threats change, provided overall protection is not materially reduced.
Customer is responsible for securely administering its Jira site, Telegram bot/token/chats, Marketplace access, users, destination membership, and App configuration. Customer must promptly rotate compromised credentials and restrict notification content/destinations appropriately.
5. Personal Data Breach
Provider will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data and will provide information reasonably available to help Customer meet legal obligations. Notification is not an admission of fault. Provider may provide information in phases and may delay details where disclosure would compromise investigation or law enforcement.
Incident contact: info@vividinsight.xyz.
6. Data-subject requests
Taking into account the nature of Processing, Provider will reasonably assist Customer with Data Subject requests. If Provider receives a request concerning Customer Personal Data, Provider will redirect the requester to Customer where lawful and will not respond substantively except on Customer's instruction or legal requirement.
Customer understands that Jira/Telegram content is principally controlled through Customer's systems. Provider's ability to locate data requires sufficient installation/site and record details and may be limited after uninstall or deletion.
7. DPIAs, consultations, and compliance assistance
Provider will provide information reasonably necessary for Customer's data protection impact assessment, prior consultation, security inquiry, or records of processing concerning the App, considering the nature of Processing and information available. Additional extensive assistance may be subject to reasonable fees unless caused by Provider's breach.
8. Subprocessors and Customer-Directed Services
Customer gives general authorization for Provider to use subprocessors listed in Annex 3. Provider will impose data-protection obligations appropriate to their services and remains responsible for subprocessor performance to the extent required by law.
Provider will publish or otherwise provide notice of a new subprocessor at least 30 days before it processes Customer Personal Data where practicable. Customer may object on reasonable data-protection grounds during that period. The parties will seek a reasonable solution; if none exists, Customer may stop the affected feature or terminate it subject to the agreement and Marketplace terms.
Telegram is a Customer-Directed Service selected and administered by Customer. To the extent Customer contracts directly with Telegram and instructs delivery, Telegram is not appointed by Provider as Provider's subprocessor solely because the App transmits data there. Provider remains responsible for securely implementing the instructed transfer, not for Telegram's independent processing.
9. International transfers
Customer authorizes Processing in locations described in Annex 3 and transfer to Customer-Directed Services. Where Provider transfers Customer Personal Data from the EEA to a country without an applicable adequacy decision, the parties will use the applicable European Commission Standard Contractual Clauses or another lawful mechanism. If UK or Swiss data-protection law applies, the relevant approved addendum or adaptation will also apply as required.
Customer is responsible for its direct arrangements and transfer assessment for Telegram as a Customer-Directed Service. Provider will reasonably provide information on Forge and its own subprocessors.
10. Return and deletion
During the subscription, Customer may delete channels/configuration and bot credentials through the App as documented. On termination/uninstall, Provider will cease active Processing and Customer Personal Data in Forge-hosted storage follows Atlassian's lifecycle, currently including a 28-day post-uninstall retention period. Telegram messages already delivered are not deleted by App uninstall.
Notification outbox/idempotency rows expire after 14 days. Recent Activity retains the latest 10 outcomes until overwritten or uninstall. The temporary migration service's application logs and backups are retained for 14 days, and that service and its retained data are scheduled for deletion no later than 31 August 2026. Provider will delete or return other Customer Personal Data on request where feasible, unless retention is required by law.
11. Audit information
Provider will make available information reasonably necessary to demonstrate compliance, including current security/privacy documentation and relevant third-party assurance information it is permitted to share. Once per year, Customer may request a remote audit/questionnaire on reasonable notice, limited to App Processing and subject to confidentiality, security, and non-disruption requirements.
On-site or third-party audits require a substantiated legal/security need, mutually agreed scope/timing, and reimbursement of reasonable costs unless the audit identifies a material Provider breach. Audits may not expose other customers' data, Provider secrets, or Atlassian/Telegram systems beyond Provider's rights.
12. Liability and order of precedence
Liability under this DPA is subject to the agreement's liability provisions unless Applicable Data Protection Law requires otherwise. If this DPA conflicts with the agreement on Processing Customer Personal Data, this DPA controls. Mandatory transfer terms control over conflicting provisions.
13. Term and contact
This DPA applies while Provider Processes Customer Personal Data and survives as needed for retained data. Notices:
Provider privacy contact: info@vividinsight.xyz DPO/privacy lead: no formal Data Protection Officer has been appointed; use the privacy contact above Registered address: Rua Victor de Sá, 33, 4715-586 Braga, Portugal Customer contact: the Marketplace/contract administrator unless otherwise notified.
Annex 1 — Processing details
Subject matter and purpose
Operation of a Forge app that reads configured Jira events/data, evaluates channel/project/event/filter rules, sends notifications and ticket-key replies through a customer-owned Telegram bot, maintains delivery/security state, provides support, and temporarily imports supported previous-app settings.
Duration
For the subscription/installation term plus the retention/deletion periods described in the DPA, Privacy Policy, and applicable platform rules.
Data Subjects
Customer's Jira users, issue reporters, assignees, commenters, and other persons referenced in Jira work data.
Customer's Telegram administrators, bot/chat members, and message authors whose messages contain parsed Jira keys.
Customer administrators, support contacts, and authorized users.
Other persons whose Personal Data Customer includes in Jira/Telegram content.
Personal Data categories
Names/display names and Atlassian account identifiers.
Jira issue/comment/work content and metadata.
Telegram chat/channel/usernames/IDs, bot metadata, inbound text and message IDs.
Project/event/filter/channel configuration.
Delivery state, timestamps, error/status codes, pseudonymous fingerprints, and recent activity.
Jira site base URL and supported legacy configuration during import.
Support correspondence and diagnostic information Customer chooses to provide.
Special categories
The App is not designed to require special-category or highly sensitive personal data. Such data may nevertheless appear in Customer-controlled Jira content sent to Telegram. Customer must minimize it and ensure a lawful basis and safeguards. Provider does not use it to infer sensitive traits.
Frequency
Continuous/event-driven while installed and licensed, plus administrator-initiated configuration, support, and import actions.
Annex 2 — Technical and organizational measures
Forge-managed runtime and installation-scoped SQL/KVS/secret storage.
Least-privilege Jira scopes: read work, read users, app storage; no Jira write scope.
User-driven Jira reads with
asUser; background calls limited to necessaryasAppuse.Telegram bot token and webhook secret in Forge secret storage; legacy shared secret in encrypted runtime variable.
Telegram webhook: POST only, 256 KiB maximum, installation secret, constant-time verification before parsing.
Fixed TLS egress domains and no customer-configurable remote URLs.
Parameterized SQL DML and scheduled schema migrations.
Input bounds for legacy responses/candidates, Telegram messages, filters, fields, nesting, and conditions.
Telegram HTML escaping, 4096-character splitting, global/per-chat pacing, bounded retry, and idempotency.
14-day delivery/outbox expiry and latest-10 recent activity ring buffer.
Forge App logging minimization that excludes customer content/identifiers, credentials, URLs, response bodies, and arbitrary upstream errors.
Temporary migration-service logs are limited to technical event facts, data-free errors/exceptions, and operational decision outcomes. They exclude IP addresses, Jira URLs, request/response bodies, and customer content and are retained for 14 days.
Security-focused unit/contract tests, dependency SCA, ESLint, and Forge manifest validation.
Access to production and support data is limited to authorized personnel with a business need and confidentiality obligations.
Security incidents and vulnerability reports are triaged through
info@vividinsight.xyz; the initial response target for a critical report is two business days.Material recovery and continuity dependencies are provided through Atlassian Forge; the temporary migration endpoint uses 14-day backups until its scheduled retirement.
Annex 3 — Subprocessors and recipients
Entity/service | Role and purpose | Data/location | Status |
|---|---|---|---|
Atlassian / Forge | Runtime, Jira APIs/events, Marketplace licensing, hosted SQL/KVS/secret storage | Customer Jira/App data; locations under Atlassian/Forge terms and data-residency configuration | Subprocessor; governed by the applicable Atlassian customer/data-processing terms. |
Scaleway S.A.S. | Infrastructure for the temporary | Jira base URL and supported legacy configuration; France | Subprocessor for the temporary service. Application logs contain technical event facts, data-free errors/exceptions, and decision outcomes, but no IP addresses, Jira URLs, request/response bodies, or customer content. Logs and backups are retained 14 days; service and retained data are scheduled for deletion no later than 31 August 2026. |
Telegram | Customer-Directed Service receiving notifications/replies through customer-owned bot | Jira notification content, display names, chat/message metadata; Telegram-controlled locations | Customer-selected recipient/service, not Provider-appointed subprocessor solely because the App transmits data there. |
Provider will update this list before appointing another subprocessor to process Customer Personal Data for the App.
VIVID INSIGHT