Data processing addendum

These processing details accompany the Report Steward product agreement. Last updated 12 September 2026.

These details incorporate the Bonterms Data Protection Addendum Version 2.0, Attachment Version, including Exhibits A and B, when the customer accepts the product agreement. The standard DPA is © 2026 Bonterms, Inc., available under CC BY 4.0.

Parties and agreement

Main agreement
The customer’s Report Steward Marketplace order, the Bonterms Standard End User Agreement Version 1.0 and the provider-specific terms.
Effective date
The date the customer accepts the product agreement incorporating this DPA.
Provider
Mikhail Eshchenko, Marketplace vendor 923094361. Greenfield Villas 3, 311/30, moo 6, Bang Lamung, Chonburi 20150, Thailand.
Privacy contact
support@misheno.com.
Customer
The organization and contact identified in the order and installation records; a different privacy contact may be designated by written notice.
Roles
Customer: controller, or processor acting on its controller’s instructions. Provider: processor.
EU Standard Contractual Clauses
Ireland is the designated governing law and member state solely for those clauses where applicable. The competent supervisory authority is determined under Clause 13.

Processing details

The customer operates a Jira Service Management Cloud workspace. The provider supplies and supports customer reporting. Processing consists of discovering authorized selections, reading request metadata, organization membership and native SLA records, generating customer files, running the customer’s saved schedule, checking current access before delivery, and storing configuration and temporary report results.

Data subjects include the reporting user and people whose information appears in customer organization names, service branding or other processed metadata. Data categories include the owner account ID, project and issue identifiers, organization IDs and names, creation and current resolution dates, status category, SLA cycle results, setup selections, uploaded logos, access information and run records.

The app does not require special-category data. Customers should not include such data unless they have established an appropriate legal basis and safeguards. Issue descriptions, comments, attachments, reporter and assignee fields are not read for this reporting workflow.

Processing occurs on the customer’s instructions through use of the app. It continues during the product agreement and as necessary for permitted return, deletion and platform retention. Report payloads have limited retention; saved setup revisions, committed logos and owner records have no automatic expiry. The retention table describes the controls and their limits. Downloaded files are controlled by the customer.

Services and subprocessors

Atlassian Forge provides hosting, compute, storage, identity and operational diagnostics. Atlassian’s applicable terms and subprocessor information govern its services. This does not guarantee a particular region for all processing or other services.

No separate external service receives report data automatically. Information voluntarily sent to the provider’s Google-hosted support mailbox is handled separately as described in Website privacy. Do not send full Jira exports, credentials or special-category data to support.

Security measures and additional terms

The security measures are incorporated as the technical and organizational measures. They describe owner-bound authorization, installation and account isolation, limited read fields, current access checks, bounded processing, file integrity and export safeguards.

Generating and downloading reports requires an active license or trial. Deletion controls remain available while the license is inactive. Deleting setup does not immediately erase all stored historical revisions or logos. Clearing app data does not delete Jira content or downloaded files. Atlassian applies its platform retention and recovery rules after uninstall; retained data remain subject to this DPA.

No other modifications to the incorporated standard DPA are made. Its incident notification, assistance, audit, subprocessor notification and cross-border transfer provisions apply where relevant. This page does not claim certification under the Data Privacy Framework.