Data processing addendum

Last updated 11 September 2026. These History Steward details incorporate the Bonterms Data Protection Addendum Version 2.0, Attachment Version, including Exhibits A and B, when the customer accepts the product agreement. The standard DPA is © 2026 Bonterms, Inc., available under CC BY 4.0.

Key terms

Main agreement
The customer’s History Steward Marketplace order, the Bonterms Standard End User Agreement Version 1.0 and the provider-specific terms.
Effective date
The date the customer accepts the product agreement incorporating this DPA.
Provider
Mikhail Eshchenko, Marketplace vendor 923094361. Greenfield Villas 3, 311/30, moo 6, Bang Lamung, Chonburi 20150, Thailand.
Privacy contact
support@misheno.com.
Customer
The organization and contact identified in the order and installation records; a different privacy contact may be designated by written notice.
Roles
Customer: controller, or processor acting on its controller’s instructions. Provider: processor.
EU Standard Contractual Clauses
Ireland is the designated governing law and member state solely for those clauses where applicable. The competent supervisory authority is determined under Clause 13.

Processing details

The customer operates a Jira Cloud workspace. The provider supplies and supports field-history reports. Processing consists of discovering authorized selections, reading work item metadata and changelogs, applying filters, checking access, creating files in the browser, and storing user-requested report presets with ownership and retention metadata. Account IDs and collection dates are periodically reported to Atlassian to process account privacy requests, including erasure of saved presets when requested by Atlassian.

Data subjects include Jira users, people who made changes and people whose information appears in selected work items, field values or query text. Data categories include account IDs and display names, work item/space/filter/field identifiers, keys and summaries, timestamps, old and new values, access information and saved configuration.

Reports process history transiently in Forge and the browser. Presets persist until deleted by their owner, erased following an Atlassian account privacy request, or handled under the platform lifecycle. Downloaded files are controlled by the customer. The app does not require special-category data; customers should not include such data unless they have established an appropriate legal basis and safeguards.

Processing occurs on the customer’s instructions through use of the app. It continues during the product agreement and as necessary for permitted return, deletion and platform retention. See Privacy for deletion controls and retention.

Services and subprocessors

Atlassian Forge provides hosting, compute, storage, identity and operational diagnostics. Atlassian’s applicable terms and subprocessor information govern its services. No particular processing region is promised by this document.

No separate external service receives report data automatically. Information voluntarily sent to the provider’s Google-hosted support mailbox is handled separately as described in Website privacy. Do not send full Jira exports, credentials or special-category data to support.

Security measures and additional terms

The security measures are incorporated as the technical and organizational measures. They describe current-user authorization, installation and account isolation, limited stored data, access checks, bounded processing and export safeguards.

The customer can export accessible data and delete their own presets, including while the license is inactive. Clearing presets does not delete Jira content or downloaded files. Atlassian applies its platform retention and recovery rules after uninstall; retained data remain subject to this DPA.

No other modifications to the incorporated standard DPA are made. Its incident notification, assistance, audit, subprocessor notification and cross-border transfer provisions apply where relevant. This page does not claim certification under the Data Privacy Framework.