Last updated: 14 July 2026. Draft — subject to legal review.
This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Controller") and BastionTrail ("Processor") for use of the BastionTrail app, and applies where BastionTrail processes personal data on the Controller's behalf.
The Controller determines the purposes and means of processing; BastionTrail acts solely as Processor and processes personal data only on the Controller's documented instructions, including as set out in the app's configuration and documentation.
Processing consists of receiving Git event metadata, linking it to Jira issues, and producing a change-audit trail, for the duration of the app's installation.
Data: Git event metadata (commit, branch, merge-request and deployment references and URLs), Jira issue and project keys, and commit author name. Data subjects: the Controller's developers and users referenced in that Git and Jira activity.
BastionTrail will: process only on documented instructions; ensure personnel are bound by confidentiality; implement the technical and organizational measures described in our Security Overview; assist the Controller with data-subject requests and with security, breach-notification and impact-assessment obligations; and make available information needed to demonstrate compliance.
The Controller authorizes the sub-processors listed in our Privacy Policy (Atlassian, Railway, Cloudflare). We will inform the Controller of intended changes and impose equivalent data-protection obligations on each sub-processor.
Where personal data of individuals in the EEA, UK or Switzerland is transferred to a country without an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), controller-to-processor module, which are deemed executed upon adoption of this DPA. Equivalent UK and Swiss transfer mechanisms apply where relevant.
Measures include TLS in transit, encryption at rest, per-installation tenant isolation, Forge Invocation Token validation and per-installation webhook secrets. See the Security Overview.
On uninstall or written request, BastionTrail deletes the Controller's personal data; uninstall triggers automatic erasure of the installation's data from our backend.