Data processing addendum

These processing details accompany the Follow-up Steward product agreement. Last updated 13 September 2026.

These details incorporate the Bonterms Data Protection Addendum Version 2.0, Attachment Version, including Exhibits A and B, when the customer accepts the product agreement. The standard DPA is © 2026 Bonterms, Inc., available under CC BY 4.0.

Parties and agreement

Main agreement
The customer’s Follow-up Steward Marketplace order, the Bonterms Standard End User Agreement Version 1.0 and the provider-specific terms.
Effective date
The date the customer accepts the product agreement incorporating this DPA.
Provider
Mikhail Eshchenko, Marketplace vendor 923094361. Greenfield Villas 3, 311/30, moo 6, Bang Lamung, Chonburi 20150, Thailand.
Privacy contact
support@misheno.com.
Customer
The organization and contact identified in the order and installation records. A different privacy contact may be designated by written notice.
Roles
Customer: controller, or processor acting on its controller’s instructions. Provider: processor.
EU Standard Contractual Clauses
Ireland is the designated governing law and member state solely for those clauses where applicable. The competent supervisory authority is determined under Clause 13.

Processing details

The customer operates a Jira or Jira Service Management Cloud workspace. Processing consists of reading authorized issue metadata and user eligibility, storing reminder instructions, resolving the current assignee, checking current access, submitting due Jira notifications, managing personal snoozes and opt-outs, and recording technical outcomes and ownership changes.

Data subjects include reminder owners, selected recipients, current assignees, administrators who manage reminders, and people mentioned in issue summaries or reminder notes. Data categories include account IDs, issue and project identifiers, current summary and status, assignment and access information, schedules and time zones, notes, preferences, license state and technical event records.

The app does not require special-category data. Customers should not include it unless they have established an appropriate legal basis and safeguards. Issue descriptions, comments and attachments are not copied for the reminder workflow.

Processing occurs on the customer’s instructions through use of the app. Duration covers the agreement and permitted retention or deletion afterward. Active schedules and pending personal returns retain their settings; terminal settings and rolling history use the 90-day retention rules. Explicit deletion, privacy erasure and the inactive-license purge take priority over future returns.

Services and recipients

Atlassian Forge provides hosting, compute, storage, identity and operational diagnostics. Jira processes notification submissions. Atlassian’s applicable terms and subprocessor information govern its services.

The customer instructs the app to submit due email to selected eligible recipients through Jira. Email then passes to their mailbox services, outside the stored-reminder residency scope. Email already accepted by Jira cannot be recalled by this app.

No separate provider-operated SMTP service or external analytics provider receives reminder data automatically. Information voluntarily sent to the Google-hosted support mailbox is handled separately under Misheno website privacy. Do not send credentials, full issue exports or special-category data to support.

Security measures and additional terms

The security measures are incorporated as the technical and organizational measures. They cover installation isolation, private and team authorization, separate owner and recipient checks, limited Jira reads, protected state changes, bounded retries and deletion controls.

Deletion controls remain available while the license is inactive. Deletion does not change Jira source content or remove email from recipient mailboxes. Atlassian applies its platform retention and recovery rules after uninstall; retained data remain subject to this DPA.

No other modifications to the incorporated standard DPA are made. Its incident notification, assistance, audit, subprocessor notification and cross-border transfer provisions apply where relevant. This page does not claim certification under the Data Privacy Framework.