Data Processing Agreement — Fair Hours

Version 1.0 — 16 August 2026

This Data Processing Agreement ("DPA") governs the processing of personal data by the Fair Hours app for Jira Cloud, supplied by Kauê Natan Gonçalves Bidim, trading as Saoirse Software, Dublin, Ireland ("Processor", "we"), on behalf of the organisation that installs the app ("Controller", "you"). It is written to meet Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the equivalent UK provisions.

No signature is needed. This DPA applies automatically from the moment the app is installed, and forms part of the Terms of Service. If your legal team requires a signed copy on your own paper, write to support@saoirsesoftware.com and we will sign yours.

1. Roles

You are the controller: the people whose data is processed are your employees, contractors or colleagues, and you decide why their time and cost are recorded. We are the processor: we supply software that processes that data on your instructions and for no purpose of our own. Atlassian is a sub-processor (section 4), and is also your own processor for Jira itself under your agreement with them.

Your instructions are given through the app's own settings and screens. We do not process the data for any other purpose, and we will not do so unless required by law — in which case we will tell you first, unless the law forbids it.

2. What is processed

Fair Hours holds remarkably little, and the distinction that matters to your legal team is between what it stores and what it merely reads live to draw a screen.

2.1 Stored by the app (in Atlassian storage, on your site)

CategoryWhat exactlyWhose
Rate settings Currency, standard working day, overtime / Saturday / Sunday / night multipliers and the night window; the company hourly rate and its effective dates; each team's hourly rate held against the Jira group ID, with the group name mirrored for display; an individual's hourly rate held against their Atlassian account ID, with effective dates. Your organisation; individuals only where you set a personal rate
Month approvals One record per project and month you approve: the date, the account ID of the approver, the total hours and cost at that moment, and one line per contributor holding an account ID with their hours and cost. Contributors to that project in that month

Names are not stored. Every personal name on screen is fetched from Jira at that moment and discarded. What is written down is the account identifier Jira itself uses.

2.2 Read live, never stored

To draw a screen the app reads, from your own Jira and with the permissions of the person using it: projects and issues (key, title and parent, so hours roll up to the epic), worklogs (author, date, duration and description), display names of the people involved, the groups a person belongs to, and that person's Jira permissions. None of this is written to the app's storage; it exists in memory for the length of one request.

2.3 Written into Jira

Worklog entries only — logging, correcting and deleting time — and always as the person using the app, never in the app's own name. The app never modifies an issue's remaining estimate, and writes no issues, comments, fields or statuses. Data written this way is your own Jira record, held under your agreement with Atlassian, and survives the app being uninstalled.

2.4 Special categories

The app is not designed to process special categories of personal data (Article 9). It stores no free text of any kind. A worklog description written by one of your people is displayed but never stored by the app; what people write there is under your control, not ours.

3. Duration and purpose

Processing lasts for as long as the app is installed on your site, for the single purpose of showing you what the time logged in your Jira costs, and of letting your people log and correct that time.

4. Sub-processors

There is exactly one: Atlassian (Atlassian Pty Ltd and its affiliates), which hosts the app and its storage on the Forge platform, inside your own site's cloud region. There is no analytics provider, no error-reporting provider, no hosting of ours, and no AI service of any kind.

The app declares no external network access in its manifest, which means the Forge platform physically prevents it from sending data anywhere else. If we ever intend to add a sub-processor, this page will be updated before it happens and you may object by uninstalling the app.

Our support mailbox is a Google (Gmail) account, used only for correspondence you choose to send us. It receives no data from the app.

5. Security measures

Stated plainly, because your legal team will ask: there is no ISO 27001, no SOC 2, no bug bounty, no penetration test and no on-site audit. Saoirse Software is an independent maker, and claiming otherwise in this document would be false.

6. Confidentiality

One person has access to the app's source code and Marketplace account: the supplier named above, who is bound by confidentiality under this DPA. There are no other staff, contractors or resellers with access.

7. Data subject rights

Because the app stores identifiers rather than profiles, your own administrator can satisfy most requests directly, in seconds, without contacting us:

If a request reaches us instead of you, we will not answer it on your behalf: we will forward it to you without undue delay, and assist you at no charge.

8. Deletion and return at the end

Uninstalling the app causes Atlassian to delete the app's storage for your site as part of its normal process; we hold no copy to return or destroy. Time logged into Jira remains in Jira, because it is your record, not ours, and its deletion is under your control in Jira itself.

9. Personal data breach

If we become aware of a breach affecting your data, we will notify you without undue delay and in any event within 72 hours, at the technical contact on your Marketplace account, with what we know, what is affected and what we are doing. We will assist your own notification duties under Articles 33 and 34. A breach of Atlassian's own platform is notified to you by Atlassian under your agreement with them.

10. Audit

On request, once per year, we will answer a reasonable written security questionnaire and provide the information needed to demonstrate compliance with this DPA. Given that all processing happens inside your own Atlassian tenancy, and that we operate no infrastructure, an on-site audit has nothing to inspect; Atlassian's certifications cover the platform layer and are published by Atlassian.

11. International transfers

The app itself transfers nothing: processing happens in the Atlassian cloud region of your own site, and the app cannot reach the public internet. Any transfer arising from Atlassian's own hosting is governed by your agreement with Atlassian, including their Standard Contractual Clauses. The supplier is established in Ireland, inside the EEA.

12. Term, changes and law

This DPA runs for as long as the app is installed. If it changes, the version and date at the top change and the new version is published here before it takes effect; a change that materially reduces your protection will be announced on the app's Marketplace listing. This DPA is governed by the laws of Ireland, and forms part of the Terms of Service. Where they conflict on data protection, this DPA prevails.

13. Contact

Data protection contact: support@saoirsesoftware.com — Kauê Natan Gonçalves Bidim, trading as Saoirse Software, Dublin, Ireland. No Data Protection Officer is appointed, and none is required at this scale (Article 37).