DetailBridge · Data processing
DetailBridge Data Processing Agreement
DetailBridge for Jira Service Management · provided by zFinia · effective 26 September 2026
This Data Processing Agreement ("DPA") applies where zFinia processes personal data on behalf of a customer ("Customer") who uses DetailBridge for Jira Service Management ("DetailBridge"). In that processing, the Customer is the controller and zFinia acts as the Customer's processor. This DPA forms part of the terms under which the Customer uses DetailBridge.
1. Subject matter and purpose
zFinia processes personal data only to perform the Customer Detail and Organisation Detail mappings the Customer's administrators configure: reading the configured Detail values for requests in the selected projects, and writing them into the Customer's own Jira fields.
2. How processing takes place
- DetailBridge runs on Atlassian Forge. Compute and storage are provided by Atlassian.
- zFinia operates no separate application server for DetailBridge, and DetailBridge makes no calls to servers outside Atlassian.
- DetailBridge keeps no separate or replicated customer database.
- DetailBridge's own storage holds configuration and status only: mapping settings, project and field identifiers, counts, error codes and example issue keys.
- Mapped values are written into the Customer's own Jira site.
3. Categories of data subjects and personal data
- Data subjects: the Customer's customers and customer contacts recorded in Atlassian Customer Service Management, and users who raise or work on Jira requests.
- Personal data: the Customer and Organisation Detail values the Customer chooses to map (which may include personal data, depending on how the Customer uses those Details), organisation membership, account identifiers and Jira issue identifiers.
DetailBridge does not require special categories of personal data. The Customer decides which Details are mapped.
4. Duration
Processing continues while DetailBridge is installed on the Customer's site. Detail values are processed transiently during each synchronisation.
5. zFinia's obligations
- Process personal data only on the Customer's documented instructions, which are given by installing DetailBridge and configuring mappings.
- Ensure people authorised to access the data are bound by confidentiality.
- Apply the security measures in section 7.
- Assist the Customer, where reasonably possible, in responding to data subject requests and in meeting its security and breach-notification obligations.
- Notify the Customer without undue delay after becoming aware of a personal data breach affecting data processed through DetailBridge.
- Make available the information reasonably necessary to demonstrate compliance with this DPA.
6. Sub-processors
Atlassian provides the Forge infrastructure on which DetailBridge runs and stores its data, and acts as zFinia's infrastructure sub-processor for DetailBridge where applicable. zFinia uses no other sub-processor to process the Customer's data through DetailBridge. zFinia will update this page before adding a sub-processor.
7. Security measures
- Least-privilege permissions, declared in the app and shown at installation.
- Configuration changes limited to Jira administrators, with the permission re-checked on every change.
- Mappings apply only to explicitly selected projects.
- No external egress, and no separate replicated customer database.
- Detail values are not stored in app storage.
- Logs exclude names, email addresses, account identifiers and Detail values.
- Tenant isolation provided by Atlassian Forge per installation.
8. Location of processing
Processing and storage take place on Atlassian's Forge infrastructure, subject to Atlassian's data residency for the Customer's site. zFinia does not transfer data processed by DetailBridge to other locations.
9. Deletion
When the Customer uninstalls DetailBridge, Atlassian deletes the app's storage under its Forge retention process. Values that DetailBridge wrote into the Customer's Jira fields remain part of the Customer's Jira data, under the Customer's control, and are removed by Jira together with the app's fields.
10. Contact
Data protection questions and security incidents: support@zfinia.com.