Legal
Data Processing Addendum
This Data Processing Addendum explains how Churrie Works Inc. processes End-User Data for customers using our Atlassian Marketplace apps.
- Effective date
- August 18, 2026
- Applies to
- Churrie Works Marketplace apps
- Publisher
- Churrie Works Inc.
Important: This page is provided for customer transparency and Marketplace contracting support. If you have a separately signed agreement with Churrie Works Inc., that agreement controls where it conflicts with this addendum. Product-specific privacy notices and documentation remain complementary.
Customer role
Customer determines which Apps to install, how they are configured, who may use them, and what content or personal data is submitted into Atlassian products and the Apps.
Churrie Works role
Churrie Works processes End-User Data only to provide, secure, support, and improve the Apps, and only as described in this DPA, Marketplace listings, and related customer agreements.
1. Parties and scope
This Data Processing Addendum (“DPA”) applies to Churrie Works Inc. (“Churrie Works”, “we”, “us”, or “our”) and the organization or person using one or more of our Atlassian Marketplace apps (“Customer”, “you”, or “your”).
It applies when Churrie Works processes End-User Data on behalf of Customer in connection with the Apps listed in Schedule A, including without limitation WorkPulse, WorkPulse Basic, Cadence, Timeaway, FormHub, Converse Hub, Greenlight, Classifier for Confluence, Classifier Bridge for Jira, and One-Way Sync for Confluence, and any successor or related Marketplace listings we publish under Churrie Works Inc.
This DPA supplements, and does not replace, the Atlassian Marketplace Terms of Use, Atlassian Developer Terms, and any applicable End User License Agreement for an App.
2. Definitions
Apps means the Atlassian Marketplace applications published by Churrie Works Inc. and covered by Schedule A, including Cloud and Data Center editions where listed.
End-User Data means data, content, or information about an end user that is accessed, collected, stored, or otherwise processed by an App in connection with Customer’s Atlassian site.
Personal Data has the meaning given under applicable data protection laws, including the GDPR, UK GDPR, and similar privacy laws.
Customer Content means content, configuration, work items, pages, form responses, leave records, time records, conversations, classification metadata, sync payloads, and related material provided by Customer or Customer’s end users through Atlassian products or the Apps.
3. Roles of the parties
For purposes of applicable data protection laws, Customer is generally the controller or business for End-User Data submitted to or configured in the Apps, and Churrie Works is generally the processor or service provider for that End-User Data when we process it on Customer’s behalf.
Churrie Works may act as a controller for its own account, billing, security, support, Marketplace compliance, and business records.
Data Center note: For Data Center Apps that run on Customer’s infrastructure, End-User Data typically remains on Customer’s servers. In that case, Churrie Works processes End-User Data as a processor only to the limited extent needed for support, licensing, security investigation, or other services Customer expressly requests — not as a routine host of Customer Content.
4. Customer instructions
Customer instructs Churrie Works to process End-User Data as necessary to provide the Apps, as configured by Customer, and as described in this DPA, the applicable Marketplace listing, product documentation, privacy policy, and any applicable order or written agreement.
If Churrie Works believes an instruction violates applicable data protection law, Churrie Works may notify Customer and suspend the affected processing until the issue is resolved.
5. Confidentiality and access
Churrie Works limits access to End-User Data to personnel and subprocessors who need access to provide, secure, support, or maintain the Apps. Personnel with access to End-User Data are subject to confidentiality obligations.
6. Security measures
Churrie Works uses reasonable technical and organizational safeguards appropriate to the nature of each App and the data processed. These safeguards commonly include:
- Use of Atlassian Forge hosting, storage, authentication, and permission models for Cloud Apps.
- Least-privilege Atlassian app scopes where reasonably practicable for app functionality.
- Server-side enforcement of Customer-configured access controls where the App provides them.
- Storage of app secrets using Forge secret storage where available.
- Input validation, output escaping, and size limits appropriate to the feature.
- Operational logging designed to avoid intentionally logging unnecessary personal data or Customer Content.
- Personal data reporting to Atlassian for stored Atlassian account identifiers as required by Marketplace privacy requirements.
- For Data Center Apps, reliance on Customer’s hosting, network, and access controls for data at rest on Customer infrastructure.
7. Subprocessors
Customer authorizes Churrie Works to use subprocessors to provide the Apps. Churrie Works remains responsible for subprocessors it engages to process End-User Data on behalf of Customer. Current subprocessors are listed in Schedule C.
Churrie Works may update Schedule C from time to time. Material changes will be reflected on this page or in related customer notices.
8. International transfers
End-User Data may be transferred to, processed in, or accessed from countries outside the European Economic Area, the United Kingdom, or Switzerland, including the United States, depending on Customer’s Atlassian configuration, Atlassian infrastructure, Churrie Works operations, and any optional integrations Customer enables.
Where required by applicable law, Churrie Works will rely on appropriate transfer mechanisms, which may include the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, subprocessors’ transfer mechanisms, or other lawful transfer bases.
9. Deletion, return, and retention
Customer controls many deletion actions through Atlassian products, including uninstalling Apps and deleting Jira issues, Confluence pages, attachments, and related content. Cloud Apps may retain app data in Forge storage as needed to provide history, configuration, access controls, lifecycle features, and support.
Upon uninstall, expiration, or written request, Churrie Works will delete or return End-User Data within a reasonable period unless retention is required by law, security, billing, dispute resolution, backup, or legitimate business purposes. Data written into Customer’s Jira or Confluence remains subject to Customer’s Atlassian product configuration and deletion controls.
10. Assistance with privacy requests
Churrie Works will provide reasonable assistance, taking into account the nature of processing and information available to Churrie Works, for Customer to respond to data subject requests, security inquiries, and privacy obligations. Customers should send requests to customerService@churrieworks.com.
11. Security incidents
If Churrie Works becomes aware of a confirmed security incident involving End-User Data processed by an App, Churrie Works will notify affected customers without undue delay and provide information reasonably available to help customers meet their obligations. Security issues may be reported to customerService@churrieworks.com.
12. Audits and information
Churrie Works will make reasonable information available to demonstrate compliance with this DPA. To protect other customers and the app environment, audits must be reasonable in scope, scheduled in advance, and subject to confidentiality and security requirements.
13. CCPA and similar privacy laws
To the extent the California Consumer Privacy Act or similar laws apply, Churrie Works acts as a service provider or processor for Customer Content. Churrie Works does not sell End-User Data submitted through the Apps and does not use it for cross-context behavioral advertising.
Schedule A — Products covered
This DPA covers Churrie Works Inc. Atlassian Marketplace apps, including without limitation:
| Product | Hosting | Platform |
|---|---|---|
| WorkPulse / WorkPulse Basic | Cloud (Forge) | Jira |
| Cadence | Cloud (Forge) | Jira |
| Timeaway | Cloud (Forge) | Jira |
| FormHub | Cloud (Forge) | Confluence & Jira |
| Converse Hub | Cloud (Forge) | Confluence & Jira |
| Greenlight | Cloud (Forge) | Confluence |
| Classifier for Confluence | Data Center | Confluence |
| Classifier Bridge for Jira | Data Center | Jira |
| One-Way Sync for Confluence | Data Center | Confluence |
Successor names, editions (e.g. Standard / Advanced), and related TimeSuite apps may be added by updating this schedule without rewriting the body of the DPA.
Schedule B — Categories of End-User Data
Depending on the App and Customer configuration, processing may include the categories below. Customer decides what content to put into Atlassian products and should not use the Apps to collect sensitive personal data unless Customer has a lawful basis and appropriate safeguards.
| App family | Typical End-User Data / Customer Content |
|---|---|
| All Cloud Apps | Atlassian account identifiers, display names, emails (where available via Atlassian permissions); app configuration; operational metadata and limited logs. |
| WorkPulse | Assigned issue references; My Week / calendar preferences; timers and worklogs; billable flags; timesheet and approval records; team/risk signals as configured. |
| Cadence | Calendar events and Focus/OOO blocks; Week Compass / Day Plan content; team membership and lead-report data; optional meeting-notes space keys; Advanced capacity / time-off / release settings where licensed. |
| Timeaway | Leave / PTO requests and balances; leave types and policies; team membership and lead/approver roles; on-call assignments and handoff requests; holiday calendars; deliverable-issue references checked during leave; optional Slack notification payloads; optional ICS / availability feed metadata. |
| FormHub | Form definitions and settings; submitted responses; access-control configuration; Confluence page output; Jira issue mappings; email/integration payloads when enabled. |
| Converse Hub | Conversation content, signals, participants; links to Confluence pages and Jira issues as configured by Customer. |
| Greenlight | Approval workflow state, approver identities, page-lock / status metadata, and audit-trail entries on Confluence pages. |
| Classifier / One-Way Sync (DC) | Classification levels and restrictions; page/issue classification metadata; sync configuration and payloads processed on Customer infrastructure as described in product documentation. |
Schedule C — Subprocessors and infrastructure
| Subprocessor / service | Purpose | Use condition |
|---|---|---|
| Atlassian | Forge hosting, Jira, Confluence, app runtime, storage, authentication, Marketplace services. | Used for Cloud Apps; Atlassian also hosts Customer’s Jira/Confluence for all customers. |
| Slack (Incoming Webhooks) | Optional notification delivery (e.g. Timeaway request/approval events). | Used only when Customer configures a webhook URL in the App. |
| Email provider (e.g. Resend or configured provider) | Optional email notification delivery. | Used only when email notification features are configured and enabled. |
| Customer-configured integration endpoint | Workflow, automation, availability feed, or other egress Customer enables. | Used only when an endpoint is configured and enabled by Customer. |
Optional third-party integrations configured by Customer are Customer’s responsibility to assess under Customer’s own vendor and transfer policies. Churrie Works does not control Customer-managed webhook destinations after egress.
14. Contact
For questions about this DPA, privacy, or security for Churrie Works Apps, contact Churrie Works Inc. at customerService@churrieworks.com.
Churrie Works Inc.
Publisher of Atlassian Marketplace apps listed in Schedule A
Related: Privacy Policy · Data Security & Privacy · Legal
Last updated: August 18, 2026
Explore apps