DATA PROCESSING ADDENDUM · 31 AUGUST 2026

Processing on your instructions.

This addendum forms part of the CustomerChase subscription agreement between the customer and TechnofyStore (the Provider). It applies when the Provider processes personal data on the customer’s behalf through CustomerChase and supplements the standard end-user agreement. For that processing, the customer determines the purposes and is the controller (or an authorized processor); the Provider acts as processor (or subprocessor).

1. Subject, purpose and duration

Processing supports configured customer follow-up in Jira Service Management: permission checks, request matching, reply detection, public reminder rendering, configured transitions, diagnostics and support. Processing lasts for the subscription and the limited retention needed to end the service, as described below. The customer’s installation, policy settings and authorized support requests constitute documented instructions. The Provider will not process app data for advertising or sell it.

2. Data and data subjects

Data subjects are the customer’s Jira users, service agents, reporters and request participants. Data may include Jira account references and display names read transiently, issue identifiers and summaries, public comments read for reply checks, administrator-authored templates, configuration and cycle/action metadata. The app does not persist reporter or participant account IDs, ticket descriptions, customer comment bodies, email addresses or external tokens in its own store. Customer-authored templates and rendered public reminders may themselves contain personal data. Sensitive data is not required and must not be deliberately included for processing by CustomerChase.

3. Instructions and confidentiality

The Provider will process personal data only on documented instructions, including for transfers, unless applicable law requires otherwise. Where permitted, the Provider will inform the customer of a conflicting legal requirement or an instruction it believes infringes applicable data protection law. Personnel authorized to access personal data must be bound by confidentiality obligations and access is limited to what is necessary.

4. Safeguards

App runtime and stored app data use Atlassian Forge, with per-installation storage, platform-managed encryption and authenticated Jira API access. Application controls include project-administrator authorization for configuration, JSM-agent and issue-access checks, server-side validation, escaped UI rendering and sanitized operational logging. The app manifest has no third-party runtime egress. No independent security certification is asserted.

5. Subprocessors and hosting

The customer authorizes Atlassian’s Forge platform and its applicable infrastructure subprocessors to host and execute the app. Atlassian also provides the customer’s Jira environment under its separate agreement with the customer. The Provider will impose appropriate data-protection obligations on any additional subprocessor it engages for app processing, remain responsible for its obligations, and provide advance notice of intended additions or replacements so the customer may raise reasonable data-protection objections. The current app has no external backend or additional app-data recipients.

Cloudflare hosts this public documentation website and processes web delivery/security information; the website does not receive Jira app data. Do not submit Jira personal data in general email support unless necessary and agreed for resolving your request.

6. International transfers

The Provider will use a lawful transfer mechanism where applicable data protection law requires one. Forge processing location and platform infrastructure follow Atlassian’s applicable hosting and data-residency arrangements. This addendum does not promise an EU-only location or constitute an independent transfer mechanism. Contact support before sending data where your organization requires additional transfer documentation or contractual safeguards.

7. Assistance and incidents

Taking account of the nature of processing and the information available, the Provider will reasonably assist the customer with data-subject requests, security obligations, impact assessments and regulatory consultation relating to CustomerChase. The Provider will notify the customer without undue delay after becoming aware of a personal-data breach affecting app data it processes, supply available information needed for the customer’s obligations and cooperate in remediation. Requests received directly from data subjects will be referred to the customer unless law requires otherwise.

8. Return and deletion

During the subscription, an authorized administrator can request app-held records through support. On termination, the Provider will assist with return or deletion as instructed, subject to applicable legal retention and platform constraints. Uninstallation stops app processing. Forge-managed uninstalled storage is currently retained for 28 days under Atlassian’s retention policy. Reinstallation does not automatically restore prior storage. Comments already posted to Jira remain customer-controlled Jira records, not separate Provider storage.

9. Demonstrating compliance

The Provider will make reasonably necessary information available to demonstrate its obligations under this addendum and cooperate with proportionate audits or inspections as required by applicable law, with reasonable confidentiality, notice and security arrangements. This does not grant unauthorized access to other customers’ data or permit testing of Atlassian infrastructure outside its rules.

10. Contact and precedence

Send instructions, objections or privacy requests to support@callsiq.com. The requester’s authority may need verification. This addendum controls conflicts with the main subscription agreement concerning processing of personal data. Mandatory applicable data protection law is not excluded.