Data Processing Addendum
Effective date: 2026-04-27 Last updated: 2026-06-09 Version: 1.0.4
This Data Processing Addendum ("DPA") supplements and forms an integral part of the Threadmaker Terms of Service at threadmaker.dev/terms ("Main Agreement") between:
CT Core (trading name of Viktar Martavitski, Polish sole proprietor, NIP 9512543228, REGON 522272970, ul. Hoza 86/410, 00-682 Warsaw, Poland) — the "Processor"; and
The entity that installs and uses the Service ("Customer" or "Controller").
Where the Customer acts as a Controller and CT Core processes Personal Data on its behalf, this DPA governs. In the event of conflict between this DPA and any other document (including the Main Agreement), this DPA prevails as to the processing of Personal Data.
1. Definitions
Terms not otherwise defined have the meanings ascribed to them in the GDPR (Regulation (EU) 2016/679). In particular:
- "Personal Data", "Controller", "Processor", "Data Subject", "Processing", and "Supervisory Authority" have the meanings given in GDPR Art. 4;
- "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller;
- "SCCs" means the Standard Contractual Clauses annexed to EU Commission Implementing Decision 2021/914 of 4 June 2021;
- "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK ICO, in force 21 March 2022;
- "DPF" means the EU-US Data Privacy Framework certified under European Commission Decision C(2023) 4745.
2. Subject matter, duration, nature and purpose
| Item | Description |
|---|---|
| Subject matter | Bidirectional synchronization of comments and messages between the Customer's Slack workspace(s) and Atlassian Jira site(s) via the Threadmaker Service. |
| Duration | From the Effective Date until termination of the Main Agreement, plus the retention period set out in Section 9. |
| Nature | Automated transmission, temporary storage for queueing, retry and idempotency, delivery to the counterpart platform, and audit logging. No secondary analysis. |
| Purpose | To provide the Service for which the Controller has contracted. |
2.1 Transit Customer Content and Stored Operational Metadata
The Service functions as a synchronization and routing layer between Customer-controlled Slack and Atlassian Jira environments. Message bodies, Jira comment text, rich-text formatting, emoji, mentions, and file attachments selected by Customer for synchronization may be processed transiently in memory or during API transmission solely to deliver the requested synchronization.
The Processor does not intentionally persist message bodies, Jira comment text, or file attachments in its application database, logs, backups, monitoring systems, analytics systems, or administrative tools.
The Processor persistently stores only operational metadata required to provide, secure, troubleshoot, and audit the Service, including workspace and team identifiers, bot and user identifiers, mapped channel and project identifiers, Jira issue keys, Jira comment identifiers, Slack message timestamps, synchronization mappings, deduplication markers, retry metadata, audit-log metadata, proxy-routing metadata, authentication artifacts, and installation-specific secrets.
3. Categories of Personal Data and Data Subjects
3.1 Categories of Personal Data
| Category | Examples | Storage position |
|---|---|---|
| Transit-only Customer Content | Slack messages, Jira comments, rich-text formatting, emoji, mentions, and file attachments selected by Customer for synchronization. | Processed transiently for synchronization only. Not intentionally persisted by the Processor. |
| Stored Operational Metadata | Slack team IDs, bot user IDs, mapped channel IDs, thread timestamps, Jira issue keys, Jira comment IDs, Slack message timestamps, synchronization direction, success/failure status, error metadata, short-lived deduplication markers, retry metadata, proxy-routing metadata, and installation-specific connection UUIDs. | Stored only as necessary to operate, secure, troubleshoot, and audit the Service, subject to the retention schedule in Section 9. |
| Authentication Artifacts | Slack bot OAuth token, per-installation HMAC secret, installation connection token. | Stored only as necessary to authenticate, route, and secure the Service. The Processor does not store Jira API tokens. |
| Controller Administrator Data | Administrator name, email address, billing or procurement contact details, and service-notice preferences. | Processed by CT Core as an independent controller where used for account administration, billing, legal notices, or sub-processor notifications, as described in the Privacy Policy. |
3.2 Categories of Data Subjects
- The Controller's employees, contractors, and collaborators using the Slack workspace or Jira site;
- Third parties mentioned within synced messages or comments.
3.3 Special categories
The Processor does not intentionally process special categories of Personal Data (GDPR Art. 9). The Controller shall not instruct the Processor to process special categories through the Service without first agreeing in writing additional safeguards.
3.4 Attachment handling
Where Customer configures the Service to synchronize attachments, the Processor may transmit attachment metadata and attachment content between the relevant Customer-controlled Slack and Atlassian Jira environments solely to complete the requested synchronization. The Processor does not intentionally store attachment content after transmission. Any stored records relating to attachments are limited to operational metadata required for synchronization, troubleshooting, deletion/edit mapping, or audit purposes, and are retained in accordance with Section 9.
4. Role allocation
The Controller determines the purposes and means of processing. The Processor processes Personal Data only:
- On documented instructions from the Controller, including with regard to international transfers;
- Insofar as required by EU or Member State law to which the Processor is subject (in which case the Processor will inform the Controller of that legal requirement unless prohibited by law).
The Main Agreement, this DPA, and the Controller's use of Service configuration (channel mapping, slash commands, message shortcuts, App Home toggles) constitute the Controller's complete and final instructions to the Processor.
For limited data about the Controller administrator as such (account creation, billing identifiers, sub-processor notifications), CT Core acts as an independent Controller as set out in the Privacy Policy.
4.1 US State Privacy Laws
To the extent Customer Personal Data is subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act, or similar US state privacy laws, the Processor acts as Customer's service provider or processor.
The Processor shall not: (i) sell or share Customer Personal Data; (ii) retain, use, or disclose Customer Personal Data for any purpose other than providing the Service or as otherwise permitted by applicable law; (iii) retain, use, or disclose Customer Personal Data outside the direct business relationship between the Processor and Customer; (iv) use Customer Personal Data for cross-context behavioral advertising; or (v) combine Customer Personal Data with personal data obtained from other sources except as permitted for service providers or processors under applicable law. The Processor certifies that it understands and will comply with the restrictions in this Section.
5. Processor's obligations
The Processor shall:
- Process Personal Data only on the Controller's documented instructions (Section 4);
- Ensure persons authorized to process Personal Data are bound by confidentiality (employment contract, contractor agreement, or statutory duty);
- Implement the technical and organizational measures set out in Annex II;
- Assist the Controller, taking into account the nature of processing, in responding to Data Subject rights requests (Section 8);
- Assist the Controller in complying with GDPR Arts. 32–36 (security, breach notification, DPIA);
- At the Controller's choice, delete or return all Personal Data after the end of provision of the Service, subject to law-mandated retention (Section 9);
- Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow audits as set out in Section 10;
- Notify the Controller without undue delay if, in the Processor's opinion, an instruction infringes the GDPR or other applicable data-protection law.
5.1 No Sale, Advertising, or Model Training
The Processor shall not sell Customer Data or Customer Personal Data, use Customer Data or Customer Personal Data for cross-context behavioral advertising, or use Customer Data or Customer Personal Data to train artificial intelligence or machine-learning models, except where Customer has expressly instructed or authorized such processing in writing. The Processor may use aggregated or de-identified operational metrics solely to operate, secure, improve, and measure the Service, provided such metrics do not identify Customer, Customer users, or Data Subjects and cannot reasonably be re-identified.
6. Sub-processors
6.1 General authorization
The Controller grants the Processor general authorization to engage Sub-processors provided each Sub-processor is bound by data-protection obligations substantively equivalent to this DPA.
6.2 Current Sub-processors
The table below distinguishes parties engaged by Processor as Sub-processors (Processor contracts them, instructs them, and pays them) from host platforms that the Controller is independently contracted with — these are listed for transparency and to disclose the data flow, but Processor does not engage them as Sub-processors within the meaning of GDPR Art. 28 and the Controller's primary contract with each platform governs.
| Party | Engagement | Processing activity | Location |
|---|---|---|---|
| Cloudflare, Inc. (USA) — Workers | Engaged by Processor as Sub-processor | Edge compute (request handling, OAuth callbacks, slash-command and event ingest, cron triggers) | United States, region wnam |
| Cloudflare, Inc. (USA) — D1 | Engaged by Processor as Sub-processor | Primary tenant database (SQLite); platform AES-256 encryption at rest | United States, region wnam |
Cloudflare, Inc. (USA) — KV
(TENANT_SHARDS) |
Engaged by Processor as Sub-processor | Shard-routing lookup cache (workspace_id → shard binding); no message content | United States (replicated edge cache) |
| Cloudflare, Inc. (USA) — R2 | Engaged by Processor as Sub-processor | 90-day rolling retention production / 30-day staging. Daily AES-256-GCM-encrypted full-database snapshot under a Processor-controlled application-layer key, in addition to Cloudflare's at-rest encryption. Same Cloudflare legal entity as Workers and D1; same Cloudflare DPA covers it. | United States, region wnam |
| Cloudflare, Inc. (USA) — Cloudflare Access | Engaged by Processor as Sub-processor | Zero-Trust SSO gateway for the operator-only admin portal
tm-admin; not a Customer-facing surface; Customer Data is
not exposed via this channel |
United States |
| Functional Software, Inc. (Sentry) (USA) | Engaged by Processor as Sub-processor | Error reporting (scrubbed payloads only; no message bodies, no comment text) | United States |
| Atlassian, Inc. — Marketplace billing | Engaged by Processor narrowly, as the channel through which Controller pays for paid tiers | Payment-processor role (Atlassian collects subscription fees and remits to Processor net of Atlassian's revenue share) | Atlassian-managed |
| Atlassian, Inc. — Forge plugin runtime | Host platform. Processor does not engage Atlassian as a Sub-processor for runtime; the Controller's primary Atlassian Cloud Terms / Atlassian DPA govern. | Hosts the Threadmaker Jira plugin inside the Controller's licensed Atlassian tenant; Jira data does not leave Atlassian's infrastructure | Atlassian-managed |
| Slack Technologies LLC (USA) | Host platform. Processor does not engage Slack as a Sub-processor; the Controller's primary Slack Customer Terms / Slack DPA govern. | Source and sink for synced message data via the OAuth grant the Controller's workspace administrator provided | Salesforce-managed |
The current list is maintained at threadmaker.dev/privacy/subprocessors.
6.3 Change notification
The Processor will give the Controller 30 days' prior notice of the addition or replacement of a Sub-processor.
Notification channel. Notice is given by (i) updating threadmaker.dev/privacy/subprocessors with the proposed change and effective date, AND (ii) at least one of the following, in the order indicated:
- Procurement-contact email, where the Controller has subscribed by emailing dpo@threadmaker.dev with subject "Sub-processor notice subscription" (procurement, legal, or DPO teams may subscribe independently of the technical admin who installed the Service, and may unsubscribe at any time by replying to the same address);
- The email address associated with the Atlassian Marketplace billing account for the relevant Customer subscription.
We may additionally display the change in the Service's Slack App Home tab and/or the Forge plugin admin page in Jira. Such in-product notices do not substitute for written notice via channels (1) or (2).
The Controller may object on reasonable data-protection grounds within the 30-day period. If the parties cannot reach a mutually acceptable resolution, the Controller may terminate the affected portion of the Service as its sole and exclusive remedy, and the Processor shall reasonably cooperate with Atlassian and the Controller to facilitate a pro-rata refund of any prepaid, unused Subscription Fees for the remaining duration of the Customer's current billing commitment, subject to the technical parameters of the Atlassian Marketplace.
6.4 Liability for Sub-processors
The Processor remains fully liable to the Controller for the performance of Sub-processors' obligations.
7. International transfers
The Controller acknowledges that Stored Operational Metadata, authentication artifacts, and limited diagnostic data will be transferred to and processed in the United States by the Processor's infrastructure and monitoring Sub-processors, including Cloudflare, Inc. and Functional Software, Inc. d/b/a Sentry.
For these transfers, the parties rely on the following layered mechanisms:
- Primary: EU-US Data Privacy Framework. Cloudflare, Inc. self-certifies under the DPF (Commission Decision C(2023) 4745 of 10 July 2023). This constitutes an adequacy decision under GDPR Art. 45.
- Secondary / fallback: Standard Contractual Clauses. Module Two (controller-to-processor) of the SCCs is incorporated by reference where the DPF is unavailable or challenged, completed as set out in Annex III.
- UK data. The UK Addendum to the EU SCCs applies where the Controller is subject to UK GDPR.
- Swiss data. The Swiss FDPIC's Addendum to the EU SCCs applies where the Controller is subject to Swiss FADP.
Technical safeguards are set out in Annex II.
8. Data Subject rights
Taking into account the nature of processing, the Processor shall assist the Controller by appropriate technical and organizational measures in fulfilling the Controller's obligation to respond to requests for exercising rights under GDPR Chapter III (access, rectification, erasure, restriction, portability, objection).
Specifically:
- On Controller request, Processor will provide a JSON export of the Controller's mapping and configuration data within 15 business days;
- On Controller request, Processor will delete identified Data Subject records within the retry queue, audit log, and mapping tables within 30 calendar days;
- Uninstallation of the Service triggers automated deletion per the retention schedule (Section 9).
If the Processor receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Controller, the Processor will forward the request to the Controller without undue delay and will not itself respond except to acknowledge receipt and direct the Data Subject to the Controller.
9. Retention and deletion
| Data | Retention |
|---|---|
message_origins (echo-prevention flags) |
Purged every 10 minutes |
retry_queue completed entries |
7 days |
retry_queue failed entries |
30 days |
retry_queue abandoned pending entries |
7 days |
audit_log |
90 days. Metadata only, including synchronization direction, issue key, relevant platform identifiers, success/failure status, error category, and timestamp. Audit logs do not intentionally contain Slack message bodies, Jira comment text, or attachment content. |
metric_events |
30 days |
rate_limits |
Rolling 1 hour (window auto-resets) |
slack_users_cache (email + Atlassian accountId mapping
for @mention rendering) |
Cache value refreshed on demand every 24 hours; row deleted 30 days after last refresh, OR immediately on workspace uninstall via FK CASCADE, OR within 30 days of an operator-handled data-subject erasure request |
comment_attachment_map, reaction_sync_map,
project_settings (per-tenant integration state) |
Duration of install; deleted on uninstall via FK CASCADE on
workspaces_local(id) |
workspaces, channel_project_map,
issue_threads, comment_map |
Deleted on uninstall (app_uninstalled event) —
typically within minutes of the trigger; SLA upper bound 30 days for DSR
erasure requests under Article 17 |
workspace_deletions (tombstone — workspace ID, deletion
timestamp, DSR ticket reference) |
Retained for as long as reasonably necessary to demonstrate compliance with deletion obligations and defend against legal claims (no content; acts as the audit trail that the Article 17 erasure was performed). |
admin_audit_log (internal CT Core staff access via
tm-admin tool) |
2 years. Calibrated to GDPR Art. 28(3)(h) Sub-Processor accountability and the typical 12–18 month claim-emergence window for commercial disputes. |
| Billing records | 7 years — Ustawa o rachunkowości Art. 74 § 2 pkt 1 (księgi rachunkowe) and Ordynacja podatkowa Art. 86 § 1 (ewidencja podatkowa). Retained solely for that purpose. |
| D1 backup snapshots in Cloudflare R2 | 90-day rolling retention in production / 30-day in staging. Daily AES-256-GCM-encrypted snapshot. Article 17 erasure requests are satisfied within the rolling window per GDPR Recital 65. |
Upon termination of the Main Agreement, the Processor shall delete or, at Controller's written choice, return all Personal Data to the Controller within 30 days, save for copies required to be retained by applicable law (billing records only).
10. Audit rights
The Controller may, at its own expense, audit the Processor's compliance with this DPA once per 12 months on 30 days' written notice, during business hours, and without unreasonably disrupting the Processor's business. The audit must be conducted by a mutually acceptable independent third-party auditor bound by confidentiality obligations no less protective than this DPA. Provided, however, that if such audit reveals an unmitigated material breach of this DPA or a systemic security vulnerability within the Service infrastructure, the Processor shall reimburse the Controller for the direct, reasonable, and documented costs of the independent third-party auditor.
In lieu of an on-site audit, the Processor may satisfy an audit obligation by providing SOC 2 Type II reports (when available), ISO 27001 certificates (when available), Sub-processor audit artefacts, and documented responses to the Controller's reasonable written questionnaires.
For 2026, as CT Core is a pre-certification vendor, audit cooperation will take the form of documented responses to the Controller's questionnaire and the sub-processor audit reports listed above. Compliance certifications, when achieved, will be available upon written request to dpo@threadmaker.dev.
11. Security and breach notification
11.1 Security measures
The Processor shall maintain the technical and organizational measures set out in Annex II throughout the term.
11.2 Breach notification
Upon becoming aware of a Personal Data breach affecting Controller data, the Processor shall (i) notify the Controller without undue delay, and in any event within 72 hours of awareness, via the procurement-contact email registered under Section 6.3 (or, in its absence, the Atlassian Marketplace billing-account email), with dpo@threadmaker.dev copied; (ii) provide information sufficient for the Controller to meet its obligations under GDPR Arts. 33 and 34; (iii) cooperate in investigating and mitigating the breach; and (iv) maintain its own internal record of all breaches in accordance with GDPR Art. 33(5).
12. DPIA assistance
The Processor shall provide reasonable cooperation with Data Protection Impact Assessments conducted by the Controller where the processing, in conjunction with the Processor's activities, is likely to result in a high risk to Data Subjects (GDPR Art. 35).
13. Governing law, venue, and conflict
Polish law governs this DPA, consistent with Section 13 of the Main Agreement. The Standard Contractual Clauses, where relied on, are governed by their own terms (typically law of an EU Member State — here, Poland).
In case of conflict between this DPA, the Main Agreement, any SCCs, and applicable law, the following order of precedence applies:
- Applicable data-protection law;
- SCCs (for cross-border transfers only);
- This DPA;
- The Main Agreement;
- Any other document.
14. Term and survival
This DPA takes effect on the Effective Date and remains in force until deletion of all Personal Data per Section 9. Sections 5–13 survive termination as required to give them effect.
14.1 Corporate succession
This DPA and the processing authorizations granted herein shall automatically extend to any permitted successor corporate entity or corporate assignee of CT Core designated under Section 14.3 of the Main Agreement, provided such entity assumes all performance obligations and data-protection commitments of the Processor.
15. Signatures
This DPA takes effect on its acceptance by the Controller through the Service checkout, OAuth-install, or Marketplace purchase flow — no wet signature is required for the publicly published version.
Where the Controller's procurement, legal, or DPO function requires a counter-signed paper or PDF counterpart, the Processor will provide one on request to dpo@threadmaker.dev, prepared on the same terms as the version published at threadmaker.dev/dpa, with both parties' details filled in and signed by the Processor's authorised signatory.
Annex I — Details of Processing
Reproduced from Sections 2 and 3 above for completeness and SCCs purposes.
- Nature and purpose: synchronization of Slack/Jira comments on Controller's instructions.
- Data subjects: Controller's employees and collaborators; persons mentioned in synced messages.
- Categories: identifiers, content, technical metadata, auth artefacts.
- Special categories: none instructed.
- Frequency: continuous for the duration of the Main Agreement.
- Sub-processors: as per Section 6.2.
- Retention: as per Section 9.
- Transfers: as per Section 7.
Annex II — Technical and Organizational Measures (TOMs)
Access control
- All Processor infrastructure is accessed via individual Cloudflare / GitHub accounts protected by hardware-key multi-factor authentication;
- Principle of least privilege for operational roles;
- No shared production credentials.
Encryption
- At rest: Cloudflare D1 storage encryption (AES-256);
- In transit: TLS 1.2+ enforced end-to-end; HSTS at threadmaker.dev;
- Secrets: Cloudflare write-only secrets; no secrets in source control.
Authentication and integrity
- Slack OAuth tokens (workspaces) stored in Cloudflare D1 with platform-level AES-256 encryption at rest;
- HMAC-SHA256 signed internal RPC between Slack worker and Forge plugin (shared secret per install, rotatable);
- Slack signing-secret verification with strict timestamp skew tolerance;
- Connection-token rotation available to admins from the App Home tab;
- No Jira API tokens are stored. Jira operations
execute inside Atlassian's Forge runtime under the customer's licensed
tenant (
api.asApp).
Availability and resilience
- Cloudflare Workers global edge;
- D1 primary region
wnamwith Cloudflare-managed replication; - Durable retry queue with exponential back-off (2, 4, 8, 16 minutes) and alert to Controller's alerts channel on persistent failure;
- Cloudflare D1 Time Travel point-in-time recovery (30-day rolling window, always on, free tier);
- Daily encrypted full database snapshots to Cloudflare R2 in the same account region; 90-day retention in production / 30-day retention in staging; AES-256-GCM application-layer envelope under a Processor-controlled key (in addition to Cloudflare's at-rest encryption); restore-rehearsal automated monthly in staging.
Monitoring and logging
- Request logs at Cloudflare edge (7-day retention);
- Application
metric_eventstable (30-day retention; no content PII); audit_logof administrative actions (90-day retention; v1.20.5).
Retention and purge
- Automated Cloudflare cron jobs enforce retention schedule in Section 9;
- Deletion on Slack
app_uninstalledortokens_revokedevents.
Supplier and personnel management
- Sub-processor selection reviewed against this DPA's requirements;
- CT Core operates today as a sole-proprietor entity with no employees and no third-party personnel access to production systems;
- Where CT Core engages contractors with access to production systems, they are bound by written confidentiality terms and undergo standard due diligence before access is granted.
Incident response
- Documented incident-response playbook (docs/OPERATIONS.md);
- 72-hour breach notification commitment (Section 11.2);
- Post-incident blameless review and remediation tracking.
Development and change management
- All production changes via reviewed pull request;
- Static typing, automated tests, security-focused code review for auth / crypto paths;
- Dependency vulnerability alerts reviewed on schedule.
Annex III — SCCs completion notes
Where the EU Standard Contractual Clauses (Module Two, controller-to-processor) are relied on as a transfer mechanism:
- Docking clause (7): enabled.
- Clause 9 — Sub-processors: option 2 (general written authorization) with 30 days' prior notice as set out in Section 6.3.
- Clause 11 — Redress: optional independent dispute resolution body is not appointed.
- Clause 17 — Governing law: Poland.
- Clause 18 — Forum and jurisdiction: Warsaw, Poland.
- Annex I.A: Parties — as stated above.
- Annex I.B: Description of transfer — as in Annex I of this DPA.
- Annex I.C: Competent Supervisory Authority — Urzad Ochrony Danych Osobowych (UODO), Warsaw, Poland.
- Annex II: Technical and organizational measures — as in Annex II of this DPA.
CT Core does not yet hold SOC 2 Type II or ISO 27001 certifications. Engagement with an external assessor is planned. Pending certification, this DPA together with the TOMs in Annex II constitutes our written representation of the security posture, subject to audit right in Section 10.
Note: it is recommended that this DPA be reviewed by a Poland-qualified data-protection lawyer before execution with a first enterprise customer.