Last updated: 12 August 2026
This Data Processing Agreement ("DPA") governs the processing of personal data by the Time Off app for Jira Cloud ("the app"), supplied by Kauê Natan Gonçalves Bidim, trading as Saoirse Software, in Ireland ("we", "us", "the Processor"). It forms part of the Terms of Service and should be read with the Privacy Policy.
How this DPA is entered into. This DPA applies automatically between us and your organisation from the moment the app is installed on your Jira site, for as long as it remains installed. No signature is required for it to be binding. If your legal team needs a countersigned copy, or needs it attached to your own paper, email support@saoirsesoftware.com and we will sign and return it.
Your organisation — the Atlassian customer that installed the app — is the data controller. It decides which employees are recorded, what leave entitlements they get and what is entered about them. We are the data processor: we process that data only to make the app work, and only on your instructions.
Your instructions are given through the app itself and through this DPA. We will not process personal data from your Jira site for any other purpose — not for our own analytics, not for product research, not for marketing, and not for training any machine-learning or AI model. We do not sell personal data and receive no payment from anyone for access to it.
| Subject matter | Recording, approving and reporting employee leave inside your Jira site. |
|---|---|
| Duration | For as long as the app is installed on your Jira site. |
| Nature and purpose | Storing, retrieving, calculating and displaying leave records so your team can request leave, managers can decide on it, and balances and reports can be produced. |
| Categories of data subject | Your employees, contractors and other people who hold a user account on your Jira site and are recorded in the app. |
| Categories of personal data |
|
| Special category data | The app does not ask for health data and has no field for it. However, a leave type of "sick leave", or a free-text note explaining an absence, may in practice reveal information about a person's health. Section 6 sets out how the app limits who can see it. You remain responsible for instructing your staff on what to write in those notes. |
| Not processed | Email addresses, phone numbers, home addresses, passwords, payment details, and any Jira issue content, project data or attachments. |
Leave balances are never stored. They are recalculated from the requests each time a screen is opened, so there is no second copy of the figures to go stale or leak.
All personal data processed by the app is held in Atlassian Forge storage, within the Atlassian cloud region of your own Jira site. The app is built on Atlassian's Forge platform and declares no external network access in its manifest, which means the platform itself prevents the app from sending data to any address outside Atlassian. There is no server of ours anywhere in the path.
We carry out no international transfer of your data, because we never receive it. Any transfer that occurs is Atlassian's own, under Atlassian's terms with you and Atlassian's own transfer safeguards.
We use one sub-processor for the personal data in the app:
| Sub-processor | What it does | Where |
|---|---|---|
| Atlassian Pty Ltd (and its group companies) | Provides the Forge platform, the compute that runs the app and the storage that holds all of the data described in section 2. | The Atlassian cloud region of your own Jira site. |
Atlassian is already your own data processor for Jira, under the agreement you hold directly with Atlassian. We add no other sub-processor for the data in the app: no analytics provider, no error-reporting service, no hosting provider of ours, no AI service.
One thing to be aware of separately: if you or your staff email our support address, that correspondence sits in a Google-hosted mailbox, which processes it as a sub-processor of that correspondence only. It never contains data pulled out of your Jira site unless you choose to put it in the email yourself.
If we ever intend to add or replace a sub-processor, we will publish the change on this page and update the date at the top at least 30 days before it takes effect. If you object on reasonable data-protection grounds within that period, you may uninstall the app and end this DPA; billing stops under Atlassian's rules.
The app's security rests mainly on a deliberate design decision: it holds nothing of its own and has nowhere to send anything. Concretely:
read:jira-user and read:permission:jira) plus its own storage.
It does not request permission to read your issues, projects, comments or
attachments — so it could not read them even if a future version tried.Being straight about the limits: we hold no security certification — no ISO 27001, no SOC 2 — and we do not claim one. We do not run a bug bounty programme or commission penetration tests. What we offer instead is a much smaller attack surface than an app with its own servers, and the platform-level assurances Atlassian publishes for Forge.
Because the app is designed so that we hold no copy of your data, most of what you need you can do yourself, immediately, inside the app. We will assist where you cannot.
When a Jira administrator uninstalls the app, Atlassian deletes the app's storage for your site as part of its normal uninstall process. We keep no copy anywhere, because we never had one, so there is nothing further for us to return or destroy. If you require written confirmation of deletion, ask and we will provide it.
If we become aware of a personal data breach affecting personal data processed through the app, we will notify you without undue delay and in any event within 72 hours of becoming aware. The notice will describe what we know, the likely consequences and what is being done. We will assist you with your own notification duties under Articles 33 and 34 GDPR.
Two honest points about how that notice reaches you. First, the app deliberately stores no email addresses, so we will contact you using the technical contact Atlassian provides to us for your licence, and any address you have written to us from. If you want breach notices to reach a specific mailbox — a security team, a DPO — email that address to us and we will record it against your licence. Second, because the data lives in Atlassian's infrastructure and not ours, a breach of the underlying platform would be detected and notified by Atlassian under your agreement with them, and we would very likely learn of it at the same time you do.
On reasonable written request, and no more than once a year unless a breach or a supervisory authority requires otherwise, we will provide the information you need to verify our compliance with this DPA — how the app stores data, what permissions it holds, and how the access rules work. Being straight again: as a sole trader we cannot host an on-site audit, and there is no infrastructure of ours to inspect. For the platform layer, Atlassian's own published compliance material is the applicable evidence.
This DPA takes effect on installation and ends when the app is uninstalled and any remaining data is deleted, whichever is later. Where its terms conflict with the Terms of Service on a matter of data protection, this DPA prevails. The liability limits in the Terms of Service apply to this DPA, except where the GDPR does not permit them to. This DPA is governed by the laws of Ireland.
If this DPA changes, the date at the top changes and the new version is published here. For changes that reduce your protections, or that add or replace a sub-processor, we give 30 days' notice on this page before they take effect.
Time Off is supplied by Kauê Natan Gonçalves Bidim, trading as Saoirse Software, in Ireland. Data protection questions, requests under this DPA and security reports all go to support@saoirsesoftware.com. Emails reach the person who writes the code.