Korbition Logo
Legal

Data Processing Agreement

Korbition processes customer data on behalf of its customers. This agreement sets the terms under which that processing takes place.

Version 1.0 · 2026-10-01

1. Parties and scope

This Data Processing Agreement ("DPA") is entered into by Korbition (owner: Helena Margjeka, Bahnhofstraße 125, 82269 Geltendorf, Germany; sole proprietorship) ("Korbition", "processor") and the customer of the applicable Korbition product ("customer", "controller"). It applies to the processing of personal data by Korbition on behalf of the customer in the course of providing Korbition products (currently: Rulekestra for Jira, an Atlassian Marketplace app). It supplements — and is incorporated into — the customer's agreement with Atlassian for the Marketplace app, the Korbition Terms of Service and the EULA.

2. Roles of the parties

3. Subject matter, duration and categories

Subject matter: execution of the customer's automation rules and hosting of the associated operational data.

Duration: from installation of the product until the later of (a) uninstall by the customer or (b) completion of the deletion commitments in §6.

Categories of data subjects: users of the customer's Jira instance (rule authors, event actors, assignees, watchers, notification recipients).

Categories of data: Jira issue content that rules operate on (issue keys, summaries, descriptions, comments, statuses, field values); Jira user identifiers (display names, Atlassian account IDs, e-mail addresses); notification target identifiers (Slack channel IDs, Microsoft Teams channel/thread IDs, e-mail addresses, webhook URLs); rule definitions; execution records (run receipts, event payloads, dead-letter entries, parked approval continuations).

Special categories: the product is not intended to process special categories of data under Art. 9 GDPR, and Korbition does not require them. The customer is responsible for what its rules process.

4. Processing instructions and compliance

Korbition processes personal data only on the customer's instructions: the rules the customer authors and enables, the notification targets the customer configures, and support or administrative requests the customer submits. Korbition informs the customer if an instruction infringes data protection law (Art. 28(3) GDPR). Korbition complies with EU data protection law applicable to processors.

5. Confidentiality and personnel

Access to customer content is limited to the founder-operator of Korbition, who is bound by confidentiality, processes data only to deliver support and the service, and is trained on the handling requirements in the Privacy Policy. No other personnel have access to customer content.

6. Retention, deletion and return of data

7. Security measures

Korbition maintains the technical and organizational measures described in the Trust Center, including: TLS 1.3 in transit; encryption at rest (AES-256; application-layer envelope encryption, AES-256-GCM, for stored event payloads); strict per-tenant logical isolation at the data layer; least-privilege, permission-scoped execution (actions run with the author's authority and are withheld when it cannot be established); authenticated, per-tenant-secret-protected endpoints; vulnerability scanning and coordinated disclosure with security contact [email protected]; and sealed, honest execution receipts. Full-disk and storage-level encryption are also provided by the infrastructure sub-processors in §8.

8. Sub-processors

Korbition uses the following sub-processors to deliver the service, each pinned to the EU (Frankfurt) region for customer content. The customer is deemed to have given general written authorization to these engagements on installation; Korbition will give notice of new sub-processors and the customer may object on reasonable data-protection grounds.

RoleSub-processorLocation
Compute & container hostingFly.io, Inc.Frankfurt, EU
Managed PostgreSQL & encrypted storageNeon, Inc. (on AWS)Frankfurt, EU
Edge & network protectionCloudflare, Inc.Global edge (DNS, TLS, DDoS)

Optional, customer-initiated: if the customer enables AI-assisted rule authoring, project metadata (project names, issue types, statuses, custom field names — not issue content) is relayed through an EU-hosted gateway to the customer's selected LLM provider, acting on the customer's separate instruction and API key where supplied ("bring your own key"). This is off by default and disclosed on the Trust Center.

Notification delivery: executed rules deliver issue content to the Slack workspace, Microsoft Teams tenant, e-mail server or webhook URL the customer configures. These are the customer's own directed deliveries, integral to the automation function, not Korbition-initiated sharing.

9. Data location and transfers

All customer content is stored and processed exclusively in the EU (Frankfurt, Germany). Korbition does not transfer End-User Data outside the EEA. The customer support contact operates from Germany. The Trust Center documents residency in detail.

10. Assistance, audits and incidents

11. Contact

Privacy and DPA matters: [email protected] · Security: [email protected] · Legal: [email protected] · General support: support portal.