LogMyTime — Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the LogMyTime Terms of Service between Bazoho (“we”, “us”, the “Processor”) and the customer installing or using the LogMyTime app for Jira Cloud (“you”, the “Controller”). It applies whenever we process personal data on your behalf in connection with the App and is entered into automatically when you install the App. It reflects the requirements of Article 28 of the EU General Data Protection Regulation (“GDPR”) and applies equivalently under the UK GDPR and similar data-protection laws.
1. Roles
You are the data controller of all personal data processed by the App in your installation. We are the data processor. Atlassian, which hosts all compute and storage for the App on its Forge platform, is our sole sub-processor (section 6).
2. Details of processing
- Subject matter: operation of the LogMyTime time-tracking and timesheet app inside your Jira Cloud site.
- Duration: for as long as the App is installed on your site.
- Nature and purpose: recording, storing, displaying, approving, and reporting on work time entered by your users; optional mirroring of worklogs to Jira; data export.
- Categories of data subjects: users of your Jira Cloud site.
- Categories of personal data:
- Worklogs — the author’s Atlassian account ID, associated Jira issue ID/key, start time and timezone, duration, billable time, and the user-entered free-text work description.
- Timesheets and approvals — periods, statuses, submission snapshots, and approver actions with comments, keyed by account ID.
- Organizational configuration — team memberships, approver assignments, schedule and holiday-calendar assignments, keyed by account ID.
- User settings — per-user preferences (timezone, calendar, week start, pinned issues).
- Audit trail — actor account ID, action, and timestamp for approval-relevant and administrative actions.
- Transiently (never stored): Jira user display names and avatars, and Jira issue data, fetched live from the Jira API to render the App’s interface.
- Special categories of data: none are requested or required by the App. Free-text fields are under your users’ control; do not enter special-category data into them.
3. Our obligations as processor
- Instructions. We process personal data only as needed to provide the App’s functionality as documented, and otherwise only on your documented instructions, unless required by law. Your configuration and use of the App constitute your instructions.
- No independent access. The App runs entirely on Atlassian’s Forge platform with no external egress; all data is stored in Atlassian-hosted storage inside your own installation. Our personnel have no access to your personal data in the ordinary course of operations.
- Confidentiality. Any person we authorize to process personal data is bound by confidentiality obligations.
- Security. We implement appropriate technical and organizational measures, described in the Annex below and in our Security Policy.
- Assistance. Taking into account the nature of the processing, we will reasonably assist you in fulfilling data-subject requests (access, rectification, erasure, restriction, portability) and your obligations under Articles 32–36 GDPR. Site administrators can also action most requests directly in the App; contact support@bazoho.com for anything else.
- Breach notification. We will notify you without undue delay after becoming aware of a personal data breach affecting your data, providing the information reasonably required for your own notification obligations.
- Deletion. Uninstalling the App permanently deletes your installation’s entire database under Atlassian’s platform policies. No copies are retained by us; we hold none to begin with.
- Demonstrating compliance. We will make available the information reasonably necessary to demonstrate compliance with this DPA — including our published security and privacy documentation and, where relevant, Atlassian’s compliance certifications for the underlying platform — and will reasonably cooperate with audits you are legally entitled to conduct.
4. Your obligations as controller
You are responsible for the lawfulness of the processing you instruct (including an appropriate legal basis for monitoring working time in your jurisdiction), for the accuracy of data your users enter, and for managing access within your Jira site.
5. International transfers
App data is stored in Atlassian-hosted storage in your Jira Cloud site’s location, following Atlassian’s data-residency support (including pinning and migration). Any transfer of personal data performed by Atlassian as sub-processor is governed by Atlassian’s own data-processing terms and transfer mechanisms, including standard contractual clauses where applicable.
6. Sub-processors
You provide general authorization for our use of Atlassian (Forge platform: hosting, compute, storage, identity) as our sole sub-processor. We engage no other sub-processors — no analytics, telemetry, or third-party services. If that ever changes, we will update this DPA and our Privacy Policy and give notice via the Marketplace listing or our website before the change takes effect; if you object, your remedy is to stop using and uninstall the App, which deletes your data.
7. Liability and governing law
The liability provisions of the Terms of Service apply to this DPA. This DPA is governed by the same law and jurisdiction as the Terms, except where the data-protection law applicable to you mandatorily provides otherwise.
Annex — Technical and organizational measures
- 100% Atlassian Forge: Atlassian-managed encryption in transit (TLS) and at rest, backups, physical and network security.
- No external egress declared; the Forge platform blocks undeclared network calls at runtime. The app carries Atlassian’s “Runs on Atlassian” badge.
- Data minimization: the only stored identifier is the Atlassian account ID; names, email addresses, and avatars are never persisted.
- Server-side authorization in every resolver; caller identity taken solely from the Forge invocation context; Jira reads run as the viewing user so Jira’s permission model applies.
- All SQL via parameterized prepared statements; CSV export formula-injection neutralization; strict Content Security Policy.
- No credentials, tokens, or secrets held by the App.
- Immutable audit trail of administrative and approval actions.
- Vendor account security: MFA on developer accounts; dependency vulnerability scanning.
Questions about this DPA: support@bazoho.com.