Data Processing Addendum
Last updated: October 4, 2026
This Data Processing Addendum (“DPA”) forms part of the LeanZero Terms of Service. It sets out the terms required by Article 28(3) of Regulation (EU) 2016/679 (“GDPR”) for the personal data that LeanZero SRL processes when you use our Atlassian Marketplace apps.
It applies automatically to every customer that installs CogniRunner, Sentinel Vault or LeanZero Management. No signature is needed. If your organisation needs a countersigned copy, email office@leanzero.net.
1. Parties and Roles
- Customer (you): the organisation that installs one of our apps on its Atlassian site. You are the controller.
- LeanZero SRL (we), Str. Toamnei 23 G, CAM. 1, Bragadiru, Ilfov, Romania, CUI 51336260: the processor.
Where you are yourself a processor for someone else, we act as your sub-processor on the same terms.
2. Details of the Processing
- Subject matter and purpose: providing the app you installed and its support, as described in its documentation.
- Duration: while the app is installed, and afterwards until the data is deleted as described in section 8.
- Nature: storing, reading, analysing (including with AI), changing and deleting data in your Atlassian site, as the app’s features and your configuration require.
- Data subjects: the users of your Atlassian site, and people named in the content the app works on (for example customers in a service desk).
- Special categories: none are required. Avoid putting them in content the apps process unless you have a legal basis.
| App | Categories of personal data |
|---|---|
| CogniRunner | Atlassian account IDs and display names; the content of the Jira work items, comments, attachments, Confluence pages and repositories that rules and agents work on; notes agents keep about people and voice samples taken from their comments; execution, audit and incident logs; if a deploy pipeline is set up, the deploy identity’s Atlassian email and API token. |
| Sentinel Vault | Atlassian account IDs, display names and email addresses on seals; edit and steward requests with reasons; approvals, decisions, reasons and signature evidence; read confirmations; activity logs; authenticator secrets of users who turn on code signing; Confluence page text sent to AI review. |
| LeanZero Management | Atlassian account IDs and display names of assignees, reporters and plan members; work item summaries and dates, project descriptions and comments sent to AI features; capacity per person; audit logs. |
Our Privacy Policy describes in more detail what each app stores and for how long.
3. Our Obligations
- Instructions. We process personal data only on your documented instructions: the Terms, this DPA, and the way you configure and use the app. If we believe an instruction breaks data protection law, we will tell you. If the law requires us to process data otherwise, we will tell you first unless the law forbids it.
- Confidentiality. Everyone at LeanZero who can access your data is bound by confidentiality.
- Security. We take the measures in section 4.
- Sub-processors. We follow section 5.
- Assistance. Taking into account the nature of the processing, we help you answer data subject requests (access, rectification, erasure, restriction, portability, objection), and with data protection impact assessments and prior consultations. If we receive a request directly, we forward it to you.
- Breaches. If we become aware of an actual or suspected personal data breach affecting your data, we notify you without undue delay, and no later than 48 hours after we become aware of it, with the information you need to meet your own obligations. We also notify Atlassian within 24 hours, as our Support SLA says. As your processor we do not notify supervisory authorities about your data; that is your decision as controller.
- Deletion or return. We follow section 8.
- Information and audits. We make available the information needed to show compliance with Article 28 GDPR, and allow and contribute to audits by you or an auditor you appoint, on reasonable notice, at most once a year unless a breach or a supervisory authority requires more, and in a way that protects other customers’ data. Written answers and our documentation come first.
4. Security Measures
- The apps run on Atlassian Forge and store their data in Forge storage on your Atlassian site. Apart from the optional MCP demo servers described in section 5, we operate no servers that hold app data. Sentinel Vault and LeanZero Management send no data outside Atlassian.
- AI features use Forge LLM (Atlassian-hosted models) by default; prompts do not leave Atlassian. In CogniRunner, any other AI provider, MCP server or git host is one you choose and connect yourself.
- All connections use HTTPS. Keys are never kept in source code.
- Each app has its own access controls on top of Atlassian’s permissions. CogniRunner and LeanZero Management keep an audit log of administrative actions; Sentinel Vault keeps an activity log of seal, workflow and classification events.
- Access to our development and production tooling is limited to LeanZero staff who need it.
- We fix vulnerabilities within the timelines of Atlassian’s Security Bug Fix Policy and accept reports under our Vulnerability Disclosure Policy.
5. Sub-Processors
You authorise us to use these sub-processors for the apps:
| Sub-Processor | Purpose | Data Processed | Location | Transfer safeguard | Used for |
|---|---|---|---|---|---|
| Atlassian (Forge platform, including Forge LLM) | Hosts and runs our Marketplace apps, stores their data, and runs their AI features on Atlassian-hosted models | The Jira and Confluence content the apps work on, app configuration and logs, AI prompts and answers | Atlassian's cloud infrastructure. Data in persistent Forge storage follows your site's data residency where Atlassian supports it; Atlassian gives no residency commitment for app logs or Forge LLM requests | Atlassian's data processing addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certification | Marketplace apps |
| Microsoft (Microsoft 365) | Our business mailbox, office@leanzero.net: enquiries, quotes, support, security reports and privacy requests | Name, email address, message content and attachments | Microsoft's cloud infrastructure | Microsoft's data protection addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certification | Support |
| Atlassian (Jira Service Management) | Our support portal at leanzero.atlassian.net | Name, email address and the content of your request | Atlassian's cloud infrastructure | Atlassian's data processing addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certification | Support |
| Serper | Web search: for the AI advisors, and for MCP Web Search demo keys used without your own Serper key | Search queries (the advisor writes them from your conversation to look up public facts) | Not stated by Serper | Serper publishes no data processing agreement; we have none in place with it. Queries are written to look up public facts, not about you | CogniRunner, only with our MCP demo servers |
| Z.AI | Optional image text recognition in the MCP Doc Processor demo, when you use it without your own Z.AI key | The images you send for text recognition | Outside the EEA (Z.AI does not state where) | No adequacy decision and no data processing agreement in place; used only if you send images for recognition | CogniRunner, only with our MCP demo servers |
| Tailscale | Network access to our LeanZero Link sign-in service and our MCP demo servers | IP address and connection metadata; Link device traffic is end-to-end encrypted | Tailscale's cloud infrastructure | Tailscale's data processing addendum (Standard Contractual Clauses) | CogniRunner, only with our MCP demo servers |
Optional, CogniRunner only: if your administrator connects LeanZero’s hosted MCP demo servers, we process the content CogniRunner sends them as your processor, on servers we operate, reached through Tailscale. Their logs are deleted after 30 days; documents generated there are kept until you ask us to delete them or tell us you have disconnected the servers. Web searches go to Serper and image text recognition to Z.AI on our account unless you send your own keys; we have no data processing agreement with Serper or Z.AI, and Z.AI is outside the EEA with no adequacy decision, so do not connect the demo servers if that is not acceptable for your data. If you do not connect them, no data reaches them.
This list last changed on October 4, 2026. AI providers, MCP servers and git hosts that your administrator connects to CogniRunner with your own credentials are not our sub-processors. You choose them and contract with them directly.
We remain responsible for our sub-processors and impose data protection obligations on them wherever we can contract for it; the table shows where a provider offers no data processing agreement. We notify you of any intended addition or replacement of a sub-processor at least 30 days before it starts processing your data, by email to the technical contact on your Atlassian Marketplace licence (and to any other address you register with office@leanzero.net for this purpose), and on this page. In an emergency we notify you as soon as possible. You may object on reasonable data protection grounds within that period. If we cannot address your objection, you may stop using the affected app; for a paid app, we will support your refund request for the unused term through Atlassian.
6. International Transfers
We transfer personal data outside the European Economic Area only where the GDPR allows it: to a country with an adequacy decision, or under the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914), which are incorporated into this DPA by reference where they are needed. For data in Forge, Atlassian’s own transfer terms apply.
7. Your Obligations
You are responsible for having a legal basis for the processing you instruct, for the content you let the apps process, for the AI providers and other services you connect, and for the configuration of rules and agents.
8. Deletion and Return
Your data stays on your Atlassian site. You can export it with each app’s tools while the app is installed. After you uninstall an app, data in Forge storage is handled under Atlassian’s retention rules. Each app also keeps a backup on your own site that survives an uninstall:
- CogniRunner: the CRBAK Jira project (or CRBAK2 to CRBAK5, or properties on a work item your administrator chose). The app recreates it daily while installed, so uninstall first, then delete the project.
- Sentinel Vault: an app-restricted Confluence page. The Backup tab’s Delete moves it to the space trash; empty it from the trash. Delete it before uninstalling, because afterwards only we can help you reach it.
- LeanZero Management: Jira user properties on the app’s account, which a Jira administrator can delete through Jira’s REST API; we give you the exact calls on request.
We help with any of this on request to office@leanzero.net. Apart from support correspondence, the Forge logs Atlassian shows us (unless your administrator turns log sharing off) and, if you connect them, what our MCP demo servers hold (section 5), we keep no copy of your app data.
9. General
If this DPA and the Terms conflict on data protection, this DPA prevails; where Standard Contractual Clauses apply, they prevail over both. This DPA is governed by the same law as the Terms. Liability between you and us under this DPA is subject to the limits in section 7 of the Terms; those limits do not restrict anyone’s rights under Articles 82 to 84 GDPR. We notify you directly, as in section 5, at least 30 days before any change to this DPA takes effect; a change that reduces the protection of your data needs your agreement.
See also: Privacy Policy | Terms of Service | Trust Center