Data Processing Addendum (DPA)
This DPA is accepted electronically through use of our services. Please create a ticket if you would like to receive a signed copy from us.
Effective Date: 17 March 2026
This Data Processing Addendum ("DPA") is entered into by and between:
Data Processor Pio Software Ltd 128, City Road, London EC1V 2NX, United Kingdom Company No. 14617087 (hereinafter referred to as the "Data Processor")
and
Data Controller The customer entity that purchases, subscribes to, or uses the Data Processor services under the applicable agreement (hereinafter referred to as the "Data Controller").
The Data Controller and Data Processor are collectively referred to as the "Parties."
Background
Pio Software Ltd provides applications that facilitate the import of data from various cloud providers to Atlassian JSM (Jira Service Management). The Data Controller wishes to use Pio Software Ltd's applications and may provide personal data to the Data Processor for processing.
1. Definitions
1.1 "Data Protection Laws" means all applicable data protection and privacy laws, including but not limited to the General Data Protection Regulation (GDPR). 1.2 "Data Subject," "Personal Data," "Processing," and "Processor" shall have the meanings ascribed to them in the Data Protection Laws.
2. Subject Matter and Duration
2.1 The subject matter of the data processing under this DPA is the personal data provided by the Data Controller to the Data Processor in connection with the use of Pio Software Ltd's applications. The processing shall have the duration as long as the Data Controller uses the applications.
3. Nature and Purpose of Processing
3.1 The Data Processor shall process Personal Data as necessary to provide the services outlined in the relevant agreement between the Parties. 3.2 The Data Processor shall process Personal Data solely for the purpose of providing the services and in accordance with the documented instructions of the Data Controller. 3.3 The Personal Data processed by the Data Processor on behalf of the Data Controller includes the types of personal data relating to the categories of data subjects as made available by the Data Controller through or to the services of the Data Processor.
4. Data Security
4.1 The Data Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including protecting Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
5. Data Subject Rights and Other Obligations of Data Processor
5.1 The Data Processor shall assist the Data Controller in responding to data subject requests, as required by applicable Data Protection Laws. 5.2 The Data Processor shall provide reasonable assistance to the Data Controller with any data protection impact assessments and prior consultations with supervisory authorities, including by providing information about the nature of the Processing and the technical and organizational measures implemented. The Data Processor shall cooperate, on request, with the competent data protection supervisory authority in the performance of its tasks. 5.3 The Data Processor shall ensure that all personnel authorized to Process Personal Data are subject to a binding written obligation of confidentiality that survives the termination of their employment.
6. Sub-Processing and Data Transfers
6.1 The Data Controller provides general authorization for the Data Processor to engage sub-processors. The Data Processor shall maintain an up-to-date list of sub-processors and notify the Data Controller of any intended changes at least fourteen (14) days before such intended change, giving the Data Controller the opportunity to object via email to insert contact email. 6.2 The list of sub-processors at the time of conclusion of this DPA is available on request. 6.3 Personal Data shall be processed within the European Economic Area (EEA) or US depending on the choice of Data Controller.
7. Data Breach Notification
7.1 The Data Processor shall notify the Data Controller without undue delay after becoming aware of a Personal Data breach.
8. Data Deletion or Return
8.1 Upon termination of the relevant agreement or upon the Data Controller's request, the Data Processor shall delete or return all Personal Data processed under this DPA.
9. Audit and Compliance
9.1 The Data Processor shall make available to the Data Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA. 9.2 Audits shall be conducted no more than once per year, upon reasonable prior written notice, during normal business hours, and subject to confidentiality obligations. The Data Processor may satisfy audit obligations by providing relevant certifications, reports, or documentation (e.g., SOC 2, security documentation).
10. General Provisions
10.1 This DPA is governed by and construed in accordance with the laws of the United Kingdom. 10.2 Any amendments to this DPA must be in writing. 10.3 This DPA forms part of the applicable customer agreement and is accepted electronically through execution of that agreement and/or use of the services.
