Data Processing Agreement
Korbition processes customer data on behalf of its customers. This agreement sets the terms under which that processing takes place.
Version 1.0 · 2026-10-01
1. Parties and scope
This Data Processing Agreement ("DPA") is entered into by Korbition (owner: Helena Margjeka, Bahnhofstraße 125, 82269 Geltendorf, Germany; sole proprietorship) ("Korbition", "processor") and the customer of the applicable Korbition product ("customer", "controller"). It applies to the processing of personal data by Korbition on behalf of the customer in the course of providing Korbition products (currently: Rulekestra for Jira, an Atlassian Marketplace app). It supplements — and is incorporated into — the customer's agreement with Atlassian for the Marketplace app, the Korbition Terms of Service and the EULA.
2. Roles of the parties
- The customer is the controller for the personal data its Jira instance and automation rules contain. The customer determines the purposes and means of processing (what data its rules touch, who receives notifications, what content is transformed).
- Korbition is the processor: it executes the customer's configured automation rules and stores the operational records of that execution, on documented instructions from the customer, and provides no independent purposes for the customer's content.
- Korbition is a controller only for its own narrow account data (the installing administrator's identity and contact e-mail, licensing and billing records) — governed by the Privacy Policy, not this DPA.
3. Subject matter, duration and categories
Subject matter: execution of the customer's automation rules and hosting of the associated operational data.
Duration: from installation of the product until the later of (a) uninstall by the customer or (b) completion of the deletion commitments in §6.
Categories of data subjects: users of the customer's Jira instance (rule authors, event actors, assignees, watchers, notification recipients).
Categories of data: Jira issue content that rules operate on (issue keys, summaries, descriptions, comments, statuses, field values); Jira user identifiers (display names, Atlassian account IDs, e-mail addresses); notification target identifiers (Slack channel IDs, Microsoft Teams channel/thread IDs, e-mail addresses, webhook URLs); rule definitions; execution records (run receipts, event payloads, dead-letter entries, parked approval continuations).
Special categories: the product is not intended to process special categories of data under Art. 9 GDPR, and Korbition does not require them. The customer is responsible for what its rules process.
4. Processing instructions and compliance
Korbition processes personal data only on the customer's instructions: the rules the customer authors and enables, the notification targets the customer configures, and support or administrative requests the customer submits. Korbition informs the customer if an instruction infringes data protection law (Art. 28(3) GDPR). Korbition complies with EU data protection law applicable to processors.
5. Confidentiality and personnel
Access to customer content is limited to the founder-operator of Korbition, who is bound by confidentiality, processes data only to deliver support and the service, and is trained on the handling requirements in the Privacy Policy. No other personnel have access to customer content.
6. Retention, deletion and return of data
- Default retention (operational data, in the EU/Frankfurt region): encrypted event payloads 90 days; dead-letter entries 14 days; parked approval continuations 30 days; run receipts for the life of the subscription. Rule definitions persist until deleted by the customer or uninstall.
- Earlier deletion on request: the customer may request earlier deletion of stored End-User Data at any time by e-mail to [email protected]. Korbition executes such requests and confirms completion. This supplements — and does not replace — the customer's own in-product controls.
- Uninstall: when the customer uninstalls the app, Korbition purges the tenant's stored End-User Data (event payloads, execution records, rule definitions, cached identifiers) and does not retain it afterwards. Residual encrypted backups, where they exist, expire on the same default schedule with no restoration of uninstalled tenants.
- Data return: rule definitions and execution receipts are exportable by the customer in-product at any time; no proprietary format is required.
7. Security measures
Korbition maintains the technical and organizational measures described in the Trust Center, including: TLS 1.3 in transit; encryption at rest (AES-256; application-layer envelope encryption, AES-256-GCM, for stored event payloads); strict per-tenant logical isolation at the data layer; least-privilege, permission-scoped execution (actions run with the author's authority and are withheld when it cannot be established); authenticated, per-tenant-secret-protected endpoints; vulnerability scanning and coordinated disclosure with security contact [email protected]; and sealed, honest execution receipts. Full-disk and storage-level encryption are also provided by the infrastructure sub-processors in §8.
8. Sub-processors
Korbition uses the following sub-processors to deliver the service, each pinned to the EU (Frankfurt) region for customer content. The customer is deemed to have given general written authorization to these engagements on installation; Korbition will give notice of new sub-processors and the customer may object on reasonable data-protection grounds.
| Role | Sub-processor | Location |
|---|---|---|
| Compute & container hosting | Fly.io, Inc. | Frankfurt, EU |
| Managed PostgreSQL & encrypted storage | Neon, Inc. (on AWS) | Frankfurt, EU |
| Edge & network protection | Cloudflare, Inc. | Global edge (DNS, TLS, DDoS) |
Optional, customer-initiated: if the customer enables AI-assisted rule authoring, project metadata (project names, issue types, statuses, custom field names — not issue content) is relayed through an EU-hosted gateway to the customer's selected LLM provider, acting on the customer's separate instruction and API key where supplied ("bring your own key"). This is off by default and disclosed on the Trust Center.
Notification delivery: executed rules deliver issue content to the Slack workspace, Microsoft Teams tenant, e-mail server or webhook URL the customer configures. These are the customer's own directed deliveries, integral to the automation function, not Korbition-initiated sharing.
9. Data location and transfers
All customer content is stored and processed exclusively in the EU (Frankfurt, Germany). Korbition does not transfer End-User Data outside the EEA. The customer support contact operates from Germany. The Trust Center documents residency in detail.
10. Assistance, audits and incidents
- Data subject requests: Korbition assists the customer in responding to requests to access, correct or delete personal data, given that product tooling (execution receipts, rule version history, export) surfaces most data directly to the customer.
- Audits: Korbition makes available the information reasonably necessary to demonstrate compliance with Art. 28 GDPR: this DPA, the Trust Center, the Privacy Policy, and written responses to reasonable security questionnaires.
- Personal data breach: Korbition notifies the customer without undue delay after becoming aware of a personal data breach affecting the customer's data, via the administrative contact of record or [email protected], and provides information reasonably requested to meet the customer's own notification obligations.
11. Contact
Privacy and DPA matters: [email protected] · Security: [email protected] · Legal: [email protected] · General support: support portal.