Version 1.0 · Effective and last updated: September 1, 2026
1. Agreement and parties
This DPA forms part of the agreement between Customer and Provider governing Accord. The Main Agreement is the Bonterms Standard End User Agreement (Version 1.0) offered through the Atlassian Marketplace, together with Accord’s Provider-Specific Terms.
“Provider” and the provider/data importer are the Marketplace partner identified as the provider of Accord in the applicable Marketplace listing and order. Provider’s data-protection contact is privacy@accordquality.com. Provider’s principal business address is the address maintained in its Marketplace partner records and will be supplied for a valid legal or compliance request.
“Customer” and the customer/data exporter are the person or entity identified in the applicable Marketplace order. Customer’s address and data-protection contact are the details maintained in its order or Atlassian account, unless Customer gives Provider updated details.
The DPA Effective Date is the date Customer first enters the Main Agreement for Accord. By entering the Main Agreement, the parties also enter this DPA where it applies to Provider’s processing of Customer Personal Data.
2. Roles
Customer is a controller or processor, as applicable. Provider is a processor or subprocessor when it processes Customer Personal Data on Customer’s behalf through the installed app. Each party is an independent controller for personal information it processes for its own legal, security, account, and business-administration purposes.
3. Subject matter and processing details
- Subject matter: providing, securing, supporting, and maintaining Accord’s quality-review workflow for Jira Service Management.
- Data subjects: Customer’s Jira and Jira Service Management users, including administrators, QA administrators, reviewers, agents, audit actors, employees, and contractors whose work Customer chooses to review.
- Personal data: Atlassian account IDs; Accord roles; review assignments and statuses; ticket and project identifiers; administrator-authored program settings and Jira search rules; timestamps and audit events; scores; reviewer-authored notes, evidence references, and void reasons; and other personal data Customer chooses to enter despite Accord’s instructions.
- Sensitive or special-category data: none intended or permitted. Customer must not submit it to Accord.
- Frequency: continuous while Customer uses the installed app and as needed for deletion, security, support, and legal compliance afterward.
- Nature: collection, recording, organization, retrieval, consultation, calculation, display, restriction, de-identification, and deletion as needed to provide Accord.
- Purpose: selecting review samples, assigning and completing human reviews, calculating and displaying results, enforcing permissions, maintaining audit history, securing and troubleshooting the app, and carrying out lawful Customer Instructions consistent with the Main Agreement.
- Duration: the Subscription Term and any limited period afterward during which Atlassian retains Forge-hosted storage, Provider must complete a lawful request, or retention is permitted by the DPA or law.
4. Customer instructions and responsibilities
The Main Agreement, Customer’s configuration and authorized use of Accord, and documented support or privacy requests are Customer’s instructions. Customer is responsible for the lawfulness of its instructions and Customer Personal Data, giving required notices, obtaining required consents, handling employment and workplace obligations, and responding to data-subject requests except to the extent Provider’s assistance is required.
5. Security measures
The technical and organizational measures in Accord’s Security Statement are incorporated as the Security Measures. They include Atlassian-hosted compute and persistent storage, encryption in transit and at rest through Forge, tenant partitioning, Jira-context permission checks, role-based authorization, data minimization, no external app-data egress, validation, dependency and source checks, privacy-safe logging, account-closure handling, and an incident-response process.
Accord is not separately certified under SOC 2, ISO 27001, or another independent assurance program. Atlassian’s certifications apply to the Atlassian services within their stated scope, not automatically to Provider as a separate organization.
6. Subprocessors
Customer generally authorizes Provider to use the following Subprocessors:
- Atlassian Pty Ltd, Atlassian group companies, and Atlassian’s authorized Forge subprocessors: Forge compute, persistent storage, content delivery, Jira API access, data residency and migration, platform security, maintenance, and related support. Processing locations depend on Customer’s Atlassian data-residency selection, Forge multi-region operation, and Atlassian’s published subprocessor locations.
Atlassian’s current list, purposes, locations, security information, and subscription mechanism for new-subprocessor notices are at Atlassian Sub-processors. For an Atlassian downstream subprocessor change, publication through that list and its subscription mechanism is the Subprocessor Notice Method and modifies Section 4.3 of the Bonterms DPA accordingly. Provider will identify any new direct subprocessor for installed-app Customer Personal Data on this page and, where required, by email or in-product notice at least 30 days before use.
Netlify hosts the public Accord website but does not receive installed-app Customer Personal Data and is not a Subprocessor for that data. The separate Accord support portal is an Atlassian service; information voluntarily submitted there is handled as described in the Privacy Policy.
7. International transfers
Exhibit A of the Bonterms DPA applies to Restricted Transfers. For the EU Standard Contractual Clauses, the Designated EU Governing Law is the law of Ireland and the Designated EU Member State is Ireland. The competent supervisory authority is determined under Clause 13 of the applicable EU SCCs. The UK Addendum and Swiss modifications in Exhibit A apply where relevant.
8. Return, deletion, and requests
Customer can view operational data through Accord while the app is installed. Self-service bulk export and point-in-time restore are not currently offered. Customer may request access, return, correction, restriction, or deletion through privacy@accordquality.com; Provider will respond as required by the DPA and applicable law, taking account of immutable review history, Jira permissions, technical feasibility, and lawful retention.
After uninstall, Atlassian currently retains soft-deleted Forge-hosted data for 28 days under its hosted-storage lifecycle. Provider does not keep a separate copy. A data-recovery request requires Customer consent and must reach Provider early enough to be submitted to Atlassian within 21 days after uninstall.
9. Additional terms
Claims relating to this DPA remain subject to the exclusions, limitations, procedures, and remedies in the Main Agreement to the fullest extent permitted by Data Protection Laws. Customer must first use documentation, security information, and relevant third-party audit materials made available by Provider or Atlassian before requesting a separate audit. Any separate audit must follow the Bonterms DPA’s Audit Parameters, protect other customers and platform security, and be at Customer’s expense unless applicable law requires otherwise.
If this page conflicts with the Bonterms DPA, this page controls as Additional Terms; mandatory Standard Contractual Clauses control over both. Questions and legally required notices may be sent to privacy@accordquality.com.
The Bonterms DPA is © 2026 Bonterms, Inc. and made available under CC BY 4.0. Bonterms is not a party to this DPA and does not provide legal advice.