Data Processing Agreement (DPA)
Pursuant to Art. 28 of the General Data Protection Regulation (GDPR)
Last updated: August 2026
1. Parties
Processor: Perlumetrics UG (haftungsbeschränkt), Wilhelm-Busch-Straße 7, 74626 Bretzfeld, Germany ("Perlumetrics", "Processor")
Controller: the customer that installs and uses the add-on "Perlumetrics Time & Budget" within its Jira Cloud instance ("Customer", "Controller").
This DPA supplements the agreement governing the use of the add-on (in particular the terms concluded via the Atlassian Marketplace and the Atlassian Marketplace Terms of Use) and applies to all processing of personal data carried out by the Processor on behalf of the Controller.
2. Subject matter, nature and purpose of processing
The Processor provides the add-on "Perlumetrics Time & Budget" (Basic and Pro editions), a cloud application for time recording, budget and project management, and invoice generation, operated on the Atlassian Forge platform. Processing serves solely the provision and operation of the add-on for the Controller.
3. Duration
This DPA applies for the duration of the Controller's use of the add-on and for any statutory retention obligations thereafter, subject to the deletion and return provisions in clause 10.
4. Categories of data subjects and personal data
Data subjects: the Controller's employees and users who use the add-on, and — where the Controller enters corresponding master data — the Controller's own customers (natural persons).
Categories of personal data:
- Jira account IDs of users, managers, and users performing or reviewing actions;
- display names of users (as recorded in audit logs);
- time-booking data, including free-text descriptions and linked Jira issues;
- customer and billing master data, including name, address, VAT identification number, and bank details;
- invoices and generated PDF documents.
5. Obligations of the Processor (Art. 28(3) GDPR)
- The Processor processes personal data only on documented instructions of the Controller, including with regard to transfers to third countries, unless required to do so by law.
- The Processor ensures that persons authorised to process the personal data are committed to confidentiality.
- The Processor implements appropriate technical and organisational measures as set out in Annex 1.
- The Processor engages sub-processors only in accordance with clause 6.
- The Processor assists the Controller, where possible, in fulfilling data-subject requests and its obligations under Art. 32–36 GDPR.
- The Processor notifies the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach.
- The Processor makes available to the Controller all information necessary to demonstrate compliance and allows for and contributes to audits in accordance with Art. 28(3)(h) GDPR.
- The Processor deletes or returns all personal data in accordance with clause 10.
6. Sub-processors
The Controller authorises the Processor to engage Atlassian Pty Ltd (Atlassian) as a sub-processor for the hosting and operation of the Forge platform on which the add-on runs. The Processor will inform the Controller of any intended changes to the list of sub-processors, giving the Controller the opportunity to object.
7. Data subject requests
Data subjects may direct requests regarding their personal data to https://perlumetrics.atlassian.net/servicedesk or to security-contact@perlumetrics.com. The Processor will forward any such request to the Controller and assist the Controller in responding.
8. Personal data breach notification
The Processor shall notify the Controller of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it, providing the information required under Art. 33(3) GDPR.
9. Audit rights
The Processor shall make available all information necessary to demonstrate compliance with Art. 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the Controller or a mandated auditor.
10. Deletion and return of data
- The Controller may delete its operational data at any time using the in-app "Wipe Data" function.
- Audit-relevant data (audit log, time-booking history, and user/manager and group assignments) is retained for accounting and compliance purposes (including German GoBD principles).
- Upon termination of the add-on use, the Processor shall, at the choice of the Controller, delete or return all personal data, subject to statutory retention obligations.
- Following uninstallation of the add-on, remaining data is retained for a limited period per Atlassian's standard data-retention policy and then permanently deleted.
11. International transfers
Personal data remains within Atlassian infrastructure. To the extent processing involves a transfer outside the European Economic Area, the parties rely on the Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR, as concluded between the Controller (data exporter) and, where applicable, Atlassian, and as referenced by the Processor.
12. Liability
The liability of the Processor shall be governed by the underlying agreement and applicable law.
Annex 1 — Technical and organisational measures (TOMs)
- Confidentiality: processing exclusively on Atlassian Forge infrastructure; role-based access via Jira groups (six personas); no storage or processing of passwords or personal access tokens.
- Encryption: encryption in transit (TLS) and encryption at rest managed by the Atlassian Forge platform.
- Access control: fine-grained, group-based authorisation within the add-on; administrative functions gated behind Jira admin checks.
- Auditing: persistent audit logging of administrative actions and of status changes on time bookings (audit log and time-booking history).
- Data minimisation: the add-on stores only data required for its functionality; no logging of personal data.
- Availability and resilience: hosting on Atlassian Forge, operated by Atlassian with its stated platform availability and security commitments.