Data Processing Addendum

Effective date: 2026-04-27 Last updated: 2026-06-09 Version: 1.0.4


This Data Processing Addendum ("DPA") supplements and forms an integral part of the Threadmaker Terms of Service at threadmaker.dev/terms ("Main Agreement") between:

Where the Customer acts as a Controller and CT Core processes Personal Data on its behalf, this DPA governs. In the event of conflict between this DPA and any other document (including the Main Agreement), this DPA prevails as to the processing of Personal Data.

1. Definitions

Terms not otherwise defined have the meanings ascribed to them in the GDPR (Regulation (EU) 2016/679). In particular:

2. Subject matter, duration, nature and purpose

Item Description
Subject matter Bidirectional synchronization of comments and messages between the Customer's Slack workspace(s) and Atlassian Jira site(s) via the Threadmaker Service.
Duration From the Effective Date until termination of the Main Agreement, plus the retention period set out in Section 9.
Nature Automated transmission, temporary storage for queueing, retry and idempotency, delivery to the counterpart platform, and audit logging. No secondary analysis.
Purpose To provide the Service for which the Controller has contracted.

2.1 Transit Customer Content and Stored Operational Metadata

The Service functions as a synchronization and routing layer between Customer-controlled Slack and Atlassian Jira environments. Message bodies, Jira comment text, rich-text formatting, emoji, mentions, and file attachments selected by Customer for synchronization may be processed transiently in memory or during API transmission solely to deliver the requested synchronization.

The Processor does not intentionally persist message bodies, Jira comment text, or file attachments in its application database, logs, backups, monitoring systems, analytics systems, or administrative tools.

The Processor persistently stores only operational metadata required to provide, secure, troubleshoot, and audit the Service, including workspace and team identifiers, bot and user identifiers, mapped channel and project identifiers, Jira issue keys, Jira comment identifiers, Slack message timestamps, synchronization mappings, deduplication markers, retry metadata, audit-log metadata, proxy-routing metadata, authentication artifacts, and installation-specific secrets.

3. Categories of Personal Data and Data Subjects

3.1 Categories of Personal Data

Category Examples Storage position
Transit-only Customer Content Slack messages, Jira comments, rich-text formatting, emoji, mentions, and file attachments selected by Customer for synchronization. Processed transiently for synchronization only. Not intentionally persisted by the Processor.
Stored Operational Metadata Slack team IDs, bot user IDs, mapped channel IDs, thread timestamps, Jira issue keys, Jira comment IDs, Slack message timestamps, synchronization direction, success/failure status, error metadata, short-lived deduplication markers, retry metadata, proxy-routing metadata, and installation-specific connection UUIDs. Stored only as necessary to operate, secure, troubleshoot, and audit the Service, subject to the retention schedule in Section 9.
Authentication Artifacts Slack bot OAuth token, per-installation HMAC secret, installation connection token. Stored only as necessary to authenticate, route, and secure the Service. The Processor does not store Jira API tokens.
Controller Administrator Data Administrator name, email address, billing or procurement contact details, and service-notice preferences. Processed by CT Core as an independent controller where used for account administration, billing, legal notices, or sub-processor notifications, as described in the Privacy Policy.

3.2 Categories of Data Subjects

3.3 Special categories

The Processor does not intentionally process special categories of Personal Data (GDPR Art. 9). The Controller shall not instruct the Processor to process special categories through the Service without first agreeing in writing additional safeguards.

3.4 Attachment handling

Where Customer configures the Service to synchronize attachments, the Processor may transmit attachment metadata and attachment content between the relevant Customer-controlled Slack and Atlassian Jira environments solely to complete the requested synchronization. The Processor does not intentionally store attachment content after transmission. Any stored records relating to attachments are limited to operational metadata required for synchronization, troubleshooting, deletion/edit mapping, or audit purposes, and are retained in accordance with Section 9.

4. Role allocation

The Controller determines the purposes and means of processing. The Processor processes Personal Data only:

  1. On documented instructions from the Controller, including with regard to international transfers;
  2. Insofar as required by EU or Member State law to which the Processor is subject (in which case the Processor will inform the Controller of that legal requirement unless prohibited by law).

The Main Agreement, this DPA, and the Controller's use of Service configuration (channel mapping, slash commands, message shortcuts, App Home toggles) constitute the Controller's complete and final instructions to the Processor.

For limited data about the Controller administrator as such (account creation, billing identifiers, sub-processor notifications), CT Core acts as an independent Controller as set out in the Privacy Policy.

4.1 US State Privacy Laws

To the extent Customer Personal Data is subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act, or similar US state privacy laws, the Processor acts as Customer's service provider or processor.

The Processor shall not: (i) sell or share Customer Personal Data; (ii) retain, use, or disclose Customer Personal Data for any purpose other than providing the Service or as otherwise permitted by applicable law; (iii) retain, use, or disclose Customer Personal Data outside the direct business relationship between the Processor and Customer; (iv) use Customer Personal Data for cross-context behavioral advertising; or (v) combine Customer Personal Data with personal data obtained from other sources except as permitted for service providers or processors under applicable law. The Processor certifies that it understands and will comply with the restrictions in this Section.

5. Processor's obligations

The Processor shall:

  1. Process Personal Data only on the Controller's documented instructions (Section 4);
  2. Ensure persons authorized to process Personal Data are bound by confidentiality (employment contract, contractor agreement, or statutory duty);
  3. Implement the technical and organizational measures set out in Annex II;
  4. Assist the Controller, taking into account the nature of processing, in responding to Data Subject rights requests (Section 8);
  5. Assist the Controller in complying with GDPR Arts. 32–36 (security, breach notification, DPIA);
  6. At the Controller's choice, delete or return all Personal Data after the end of provision of the Service, subject to law-mandated retention (Section 9);
  7. Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow audits as set out in Section 10;
  8. Notify the Controller without undue delay if, in the Processor's opinion, an instruction infringes the GDPR or other applicable data-protection law.

5.1 No Sale, Advertising, or Model Training

The Processor shall not sell Customer Data or Customer Personal Data, use Customer Data or Customer Personal Data for cross-context behavioral advertising, or use Customer Data or Customer Personal Data to train artificial intelligence or machine-learning models, except where Customer has expressly instructed or authorized such processing in writing. The Processor may use aggregated or de-identified operational metrics solely to operate, secure, improve, and measure the Service, provided such metrics do not identify Customer, Customer users, or Data Subjects and cannot reasonably be re-identified.

6. Sub-processors

6.1 General authorization

The Controller grants the Processor general authorization to engage Sub-processors provided each Sub-processor is bound by data-protection obligations substantively equivalent to this DPA.

6.2 Current Sub-processors

The table below distinguishes parties engaged by Processor as Sub-processors (Processor contracts them, instructs them, and pays them) from host platforms that the Controller is independently contracted with — these are listed for transparency and to disclose the data flow, but Processor does not engage them as Sub-processors within the meaning of GDPR Art. 28 and the Controller's primary contract with each platform governs.

Party Engagement Processing activity Location
Cloudflare, Inc. (USA) — Workers Engaged by Processor as Sub-processor Edge compute (request handling, OAuth callbacks, slash-command and event ingest, cron triggers) United States, region wnam
Cloudflare, Inc. (USA) — D1 Engaged by Processor as Sub-processor Primary tenant database (SQLite); platform AES-256 encryption at rest United States, region wnam
Cloudflare, Inc. (USA) — KV (TENANT_SHARDS) Engaged by Processor as Sub-processor Shard-routing lookup cache (workspace_id → shard binding); no message content United States (replicated edge cache)
Cloudflare, Inc. (USA) — R2 Engaged by Processor as Sub-processor 90-day rolling retention production / 30-day staging. Daily AES-256-GCM-encrypted full-database snapshot under a Processor-controlled application-layer key, in addition to Cloudflare's at-rest encryption. Same Cloudflare legal entity as Workers and D1; same Cloudflare DPA covers it. United States, region wnam
Cloudflare, Inc. (USA) — Cloudflare Access Engaged by Processor as Sub-processor Zero-Trust SSO gateway for the operator-only admin portal tm-admin; not a Customer-facing surface; Customer Data is not exposed via this channel United States
Functional Software, Inc. (Sentry) (USA) Engaged by Processor as Sub-processor Error reporting (scrubbed payloads only; no message bodies, no comment text) United States
Atlassian, Inc. — Marketplace billing Engaged by Processor narrowly, as the channel through which Controller pays for paid tiers Payment-processor role (Atlassian collects subscription fees and remits to Processor net of Atlassian's revenue share) Atlassian-managed
Atlassian, Inc. — Forge plugin runtime Host platform. Processor does not engage Atlassian as a Sub-processor for runtime; the Controller's primary Atlassian Cloud Terms / Atlassian DPA govern. Hosts the Threadmaker Jira plugin inside the Controller's licensed Atlassian tenant; Jira data does not leave Atlassian's infrastructure Atlassian-managed
Slack Technologies LLC (USA) Host platform. Processor does not engage Slack as a Sub-processor; the Controller's primary Slack Customer Terms / Slack DPA govern. Source and sink for synced message data via the OAuth grant the Controller's workspace administrator provided Salesforce-managed

The current list is maintained at threadmaker.dev/privacy/subprocessors.

6.3 Change notification

The Processor will give the Controller 30 days' prior notice of the addition or replacement of a Sub-processor.

Notification channel. Notice is given by (i) updating threadmaker.dev/privacy/subprocessors with the proposed change and effective date, AND (ii) at least one of the following, in the order indicated:

  1. Procurement-contact email, where the Controller has subscribed by emailing dpo@threadmaker.dev with subject "Sub-processor notice subscription" (procurement, legal, or DPO teams may subscribe independently of the technical admin who installed the Service, and may unsubscribe at any time by replying to the same address);
  2. The email address associated with the Atlassian Marketplace billing account for the relevant Customer subscription.

We may additionally display the change in the Service's Slack App Home tab and/or the Forge plugin admin page in Jira. Such in-product notices do not substitute for written notice via channels (1) or (2).

The Controller may object on reasonable data-protection grounds within the 30-day period. If the parties cannot reach a mutually acceptable resolution, the Controller may terminate the affected portion of the Service as its sole and exclusive remedy, and the Processor shall reasonably cooperate with Atlassian and the Controller to facilitate a pro-rata refund of any prepaid, unused Subscription Fees for the remaining duration of the Customer's current billing commitment, subject to the technical parameters of the Atlassian Marketplace.

6.4 Liability for Sub-processors

The Processor remains fully liable to the Controller for the performance of Sub-processors' obligations.

7. International transfers

The Controller acknowledges that Stored Operational Metadata, authentication artifacts, and limited diagnostic data will be transferred to and processed in the United States by the Processor's infrastructure and monitoring Sub-processors, including Cloudflare, Inc. and Functional Software, Inc. d/b/a Sentry.

For these transfers, the parties rely on the following layered mechanisms:

  1. Primary: EU-US Data Privacy Framework. Cloudflare, Inc. self-certifies under the DPF (Commission Decision C(2023) 4745 of 10 July 2023). This constitutes an adequacy decision under GDPR Art. 45.
  2. Secondary / fallback: Standard Contractual Clauses. Module Two (controller-to-processor) of the SCCs is incorporated by reference where the DPF is unavailable or challenged, completed as set out in Annex III.
  3. UK data. The UK Addendum to the EU SCCs applies where the Controller is subject to UK GDPR.
  4. Swiss data. The Swiss FDPIC's Addendum to the EU SCCs applies where the Controller is subject to Swiss FADP.

Technical safeguards are set out in Annex II.

8. Data Subject rights

Taking into account the nature of processing, the Processor shall assist the Controller by appropriate technical and organizational measures in fulfilling the Controller's obligation to respond to requests for exercising rights under GDPR Chapter III (access, rectification, erasure, restriction, portability, objection).

Specifically:

If the Processor receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Controller, the Processor will forward the request to the Controller without undue delay and will not itself respond except to acknowledge receipt and direct the Data Subject to the Controller.

9. Retention and deletion

Data Retention
message_origins (echo-prevention flags) Purged every 10 minutes
retry_queue completed entries 7 days
retry_queue failed entries 30 days
retry_queue abandoned pending entries 7 days
audit_log 90 days. Metadata only, including synchronization direction, issue key, relevant platform identifiers, success/failure status, error category, and timestamp. Audit logs do not intentionally contain Slack message bodies, Jira comment text, or attachment content.
metric_events 30 days
rate_limits Rolling 1 hour (window auto-resets)
slack_users_cache (email + Atlassian accountId mapping for @mention rendering) Cache value refreshed on demand every 24 hours; row deleted 30 days after last refresh, OR immediately on workspace uninstall via FK CASCADE, OR within 30 days of an operator-handled data-subject erasure request
comment_attachment_map, reaction_sync_map, project_settings (per-tenant integration state) Duration of install; deleted on uninstall via FK CASCADE on workspaces_local(id)
workspaces, channel_project_map, issue_threads, comment_map Deleted on uninstall (app_uninstalled event) — typically within minutes of the trigger; SLA upper bound 30 days for DSR erasure requests under Article 17
workspace_deletions (tombstone — workspace ID, deletion timestamp, DSR ticket reference) Retained for as long as reasonably necessary to demonstrate compliance with deletion obligations and defend against legal claims (no content; acts as the audit trail that the Article 17 erasure was performed).
admin_audit_log (internal CT Core staff access via tm-admin tool) 2 years. Calibrated to GDPR Art. 28(3)(h) Sub-Processor accountability and the typical 12–18 month claim-emergence window for commercial disputes.
Billing records 7 years — Ustawa o rachunkowości Art. 74 § 2 pkt 1 (księgi rachunkowe) and Ordynacja podatkowa Art. 86 § 1 (ewidencja podatkowa). Retained solely for that purpose.
D1 backup snapshots in Cloudflare R2 90-day rolling retention in production / 30-day in staging. Daily AES-256-GCM-encrypted snapshot. Article 17 erasure requests are satisfied within the rolling window per GDPR Recital 65.

Upon termination of the Main Agreement, the Processor shall delete or, at Controller's written choice, return all Personal Data to the Controller within 30 days, save for copies required to be retained by applicable law (billing records only).

10. Audit rights

The Controller may, at its own expense, audit the Processor's compliance with this DPA once per 12 months on 30 days' written notice, during business hours, and without unreasonably disrupting the Processor's business. The audit must be conducted by a mutually acceptable independent third-party auditor bound by confidentiality obligations no less protective than this DPA. Provided, however, that if such audit reveals an unmitigated material breach of this DPA or a systemic security vulnerability within the Service infrastructure, the Processor shall reimburse the Controller for the direct, reasonable, and documented costs of the independent third-party auditor.

In lieu of an on-site audit, the Processor may satisfy an audit obligation by providing SOC 2 Type II reports (when available), ISO 27001 certificates (when available), Sub-processor audit artefacts, and documented responses to the Controller's reasonable written questionnaires.

For 2026, as CT Core is a pre-certification vendor, audit cooperation will take the form of documented responses to the Controller's questionnaire and the sub-processor audit reports listed above. Compliance certifications, when achieved, will be available upon written request to dpo@threadmaker.dev.

11. Security and breach notification

11.1 Security measures

The Processor shall maintain the technical and organizational measures set out in Annex II throughout the term.

11.2 Breach notification

Upon becoming aware of a Personal Data breach affecting Controller data, the Processor shall (i) notify the Controller without undue delay, and in any event within 72 hours of awareness, via the procurement-contact email registered under Section 6.3 (or, in its absence, the Atlassian Marketplace billing-account email), with dpo@threadmaker.dev copied; (ii) provide information sufficient for the Controller to meet its obligations under GDPR Arts. 33 and 34; (iii) cooperate in investigating and mitigating the breach; and (iv) maintain its own internal record of all breaches in accordance with GDPR Art. 33(5).

12. DPIA assistance

The Processor shall provide reasonable cooperation with Data Protection Impact Assessments conducted by the Controller where the processing, in conjunction with the Processor's activities, is likely to result in a high risk to Data Subjects (GDPR Art. 35).

13. Governing law, venue, and conflict

Polish law governs this DPA, consistent with Section 13 of the Main Agreement. The Standard Contractual Clauses, where relied on, are governed by their own terms (typically law of an EU Member State — here, Poland).

In case of conflict between this DPA, the Main Agreement, any SCCs, and applicable law, the following order of precedence applies:

  1. Applicable data-protection law;
  2. SCCs (for cross-border transfers only);
  3. This DPA;
  4. The Main Agreement;
  5. Any other document.

14. Term and survival

This DPA takes effect on the Effective Date and remains in force until deletion of all Personal Data per Section 9. Sections 5–13 survive termination as required to give them effect.

14.1 Corporate succession

This DPA and the processing authorizations granted herein shall automatically extend to any permitted successor corporate entity or corporate assignee of CT Core designated under Section 14.3 of the Main Agreement, provided such entity assumes all performance obligations and data-protection commitments of the Processor.

15. Signatures

This DPA takes effect on its acceptance by the Controller through the Service checkout, OAuth-install, or Marketplace purchase flow — no wet signature is required for the publicly published version.

Where the Controller's procurement, legal, or DPO function requires a counter-signed paper or PDF counterpart, the Processor will provide one on request to dpo@threadmaker.dev, prepared on the same terms as the version published at threadmaker.dev/dpa, with both parties' details filled in and signed by the Processor's authorised signatory.


Annex I — Details of Processing

Reproduced from Sections 2 and 3 above for completeness and SCCs purposes.

Annex II — Technical and Organizational Measures (TOMs)

Access control

Encryption

Authentication and integrity

Availability and resilience

Monitoring and logging

Retention and purge

Supplier and personnel management

Incident response

Development and change management

Annex III — SCCs completion notes

Where the EU Standard Contractual Clauses (Module Two, controller-to-processor) are relied on as a transfer mechanism:


CT Core does not yet hold SOC 2 Type II or ISO 27001 certifications. Engagement with an external assessor is planned. Pending certification, this DPA together with the TOMs in Annex II constitutes our written representation of the security posture, subject to audit right in Section 10.

Note: it is recommended that this DPA be reviewed by a Poland-qualified data-protection lawyer before execution with a first enterprise customer.