Effective: 30 September 2026 · Version 1.0
This Data Processing Addendum ("DPA") is between Gergely Orbán, sole proprietor, Hungary ("Processor", "Provider") and the organization that installs the CFR Dashboard app ("Controller", "Customer"). It is the "Data Protection Addendum" referred to in the End User Terms and forms part of them.
It applies to personal data that the Provider processes on the Controller's behalf and instructions when operating the App, within the meaning of Article 4(8) and Article 28 of the GDPR and, where relevant, other applicable data protection law.
| Item | Description |
|---|---|
| Subject matter | Processing needed to run the App for the Controller's Jira projects |
| Duration | From installation of the App until it is uninstalled or the agreement ends |
| Nature | Automated processing: retrieving Git commit data and selected Jira field values, calculating metrics, and optionally exporting events to a destination chosen by the Controller |
| Purpose | Calculating and displaying Change Failure Rate and Mean Time to Restore, and optionally exporting the underlying event data |
The Processor will:
Atlassian (Forge platform). The Processor uses the Atlassian Forge platform to run the App and store its data. Atlassian's commitments are set out in the Forge Data Processing Addendum and the Atlassian Data Processing Addendum. The chain is: Controller (controller) → Provider (processor) → Atlassian (sub-processor).
The Processor will inform the Controller in advance if it engages a different or additional sub-processor. The Controller may object within 30 days of that notice.
Not sub-processors: the Git provider (GitHub, Bitbucket Cloud, GitLab.com, Azure Repos) and the export destination (Google BigQuery, Amazon S3) chosen and configured by the Controller. These are the Controller's own accounts and services, accessed with credentials the Controller supplies; the Controller's agreements with them govern their processing.
The Processor will notify the Controller of a personal data breach affecting personal data it processes for the Controller without undue delay and in any case within 48 hours of becoming aware of it, providing the information then available on the nature of the breach, its likely consequences and the measures taken or proposed.
On reasonable written notice of at least 30 days, and no more than once a year, the Controller may verify the Processor's compliance with this DPA. Given the Processor's size, verification is primarily document-based (questionnaire; reference to the Forge platform's security documentation). On-site audits only in particularly justified cases on agreed terms.
Where processing involves transfers outside the European Economic Area (for example through the Atlassian Forge infrastructure, or a Git provider or destination region chosen by the Controller), the transfer mechanisms set out in Atlassian's Data Transfer Impact Assessment and, between the Processor and Atlassian, the applicable Standard Contractual Clauses apply.
Liability under this DPA is governed by the liability provisions of the agreement (the Standard Agreement and the Provider-Specific Terms), without affecting liability that cannot be limited under mandatory law. This DPA takes effect with the End User Terms and lasts as long as the Processor processes personal data on the Controller's behalf.
Data protection and DPA enquiries: support@cfrdashboard.app