← Filter Delta overview

Filter Delta for Jira / Data processing

One standard DPA.
Completed product details.

The standing data-processing information intended to accompany Filter Delta Marketplace Orders.

Jira Cloud Preparing for public release

Updated 23 September 2026 · Pre-release DPA details

DPA structure

The launch contract package is intended to incorporate the Bonterms Data Processing Addendum v2.0 Attachment Version into the Filter Delta end-user agreement. This page supplies the product-specific DPA Details.

Before public release, the package remains subject to independent legal review. This page alone does not create a subscription or activate a DPA without an applicable Marketplace Order.

Parties and roles

Customer
The customer identified in the Marketplace Order; controller, or processor for its own controller. Contact and address details are the technical or billing details recorded in the Order or associated Atlassian customer account. Customer activities are its use and administration of Jira Cloud and Filter Delta.
Provider / Data Importer
Robert Freese, trading as Untiefe, Katharinenberg 38, 18439 Stralsund, Germany; info@untiefe.dev; processor for Customer Data. Provider activities are development, operation, support, security and maintenance of Filter Delta.
Main Agreement
The Marketplace Order, Bonterms Standard End User Agreement v1.0 and Filter Delta provider-specific terms.
Duration
The Marketplace subscription term plus the documented retention and deletion periods.

Processing details

Subject and purpose: operate personal Jira saved-filter/JQL monitors, retrieve result membership, create bounded snapshots, calculate added and removed issue membership, display history, schedule daily scans, and handle retries, limits, privacy reporting and deletion.

Data subjects: Jira users and administrators using Filter Delta, and people indirectly referenced by issue identifiers returned by monitored queries.

Personal data: Atlassian account IDs; internal owner, monitor, request, snapshot and deletion identifiers; monitor names; saved-filter IDs or direct JQL; source hashes; issue IDs; timestamps; counts; scan, status, error, maintenance, privacy-reporting and deletion metadata. Current issue keys and summaries may be retrieved for display but are not stored as history.

Frequency: continuously or occasionally according to customer use and enabled schedules. Sensitive data: none intended or authorised; customers must not put special-category or highly sensitive data into monitor names or JQL.

Retention: snapshots for 14 days and no more than 100 per monitor; requests, cancellation markers and deletion receipts for up to 7 days; monitor and owner data until deletion or the installation lifecycle ends; Forge hosted storage currently 28 days after uninstall.

Processing locations and transfers

Persistent in-scope app data follows the host Jira product’s supported Forge location. The Global realm may move data among Atlassian-supported regions, and Forge compute may sometimes execute outside the pinned region. See Atlassian’s current location information.

The Bonterms DPA’s transfer mechanism applies where required. Atlassian’s processing for Forge is governed by the Forge Data Processing Addendum incorporated into the Forge Terms.

Approved subprocessor

Atlassian Pty Ltd and the Atlassian subprocessors used for Forge provide Jira API access, app compute, queues, schedules, hosted storage, logging and platform operations. See the current Filter Delta subprocessor list.

Customers will receive at least 30 days’ advance notice of a new app-data subprocessor by email to the Marketplace technical or billing contact when available, or another direct in-product or administrator notice.

Security, deletion and requests

The security page describes Forge hosting, owner-scoped authorisation, Jira-permission checks, minimised snapshot content, restricted logging and vulnerability intake. Under the planned Bonterms DPA v2.0, notice to an affected customer is due without undue delay and no later than 48 hours after awareness of a Security Incident. The deletion guide explains user controls and the uninstall lifecycle.

There is no self-service bulk export. A customer may make a verified written request during the subscription or within 60 days after termination for stored Filter Delta Customer Data in a reasonable machine-readable form where technically available and legally permitted.