Instruction limited
Customer data is processed only to provide Sense and follow documented customer instructions.
Customer data processing addendum
This Data Processing Addendum sets the terms under which Decionis processes personal data for customers using Sense.
Effective July 18, 2026 · Version 1.0
Customer data is processed only to provide Sense and follow documented customer instructions.
Tenant separation, least privilege, encryption, redaction, and evidence hashing protect the processing path.
Atlassian-derived data tied to an uninstalled cloud site is scheduled for deletion within 30 days.
This Customer Data Processing Addendum ("DPA") forms part of the agreement between the customer identified in the applicable order, online acceptance, or other agreement ("Customer") and Decionis, Inc. ("Decionis") for Customer's use of Sense.
Capitalized terms not defined here have the meaning given in the agreement. The parties agree that this DPA is effective when Customer accepts the agreement or begins processing Customer Personal Data through Sense, whichever occurs first.
01
"Customer Personal Data" means personal data submitted to, stored in, or otherwise processed by Sense on Customer's behalf. "Data Protection Laws" means privacy and data-protection laws applicable to that processing, including the EU GDPR and UK GDPR where applicable.
Customer is the controller or business and Decionis is the processor or service provider for Customer Personal Data. Customer is responsible for its instructions, notices, legal bases, permissions, and the lawfulness of data supplied to Sense. Decionis will notify Customer if an instruction appears to violate applicable Data Protection Laws, unless legally prohibited from doing so.
02
Decionis processes Customer Personal Data to authenticate users, operate customer workspaces, connect authorized sources, produce judgments and contradiction findings, preserve customer-selected evidence and decision records, provide support, secure the service, and perform the agreement.
Processing continues for the term of the agreement and any documented return, export, backup, legal-retention, or deletion period described below.
Data subjects may include Customer's users, team members, contractors, collaborators, customers, candidates, and other people referenced in content Customer elects to process.
Customer Personal Data may include account and workspace identifiers; business contact and profile information; work artifacts, excerpts, tasks, meetings, issue and page metadata; judgments, findings, evidence hashes, and decision records; connector authorization metadata; and operational security and audit data. Sense is not designed for special-category or highly regulated personal data unless the parties expressly agree in writing.
03
The agreement, Customer's configuration and authorized use of Sense, and written support requests are Customer's documented instructions. Decionis will process Customer Personal Data only on those instructions, including for transfers, unless law requires other processing. If law requires other processing, Decionis will inform Customer before it occurs unless the law prohibits notice.
Decionis will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only where needed for their responsibilities.
04
Decionis maintains technical and organizational measures designed for the nature of the processing and the risks to data subjects. These measures include:
05
Customer authorizes Decionis to use subprocessors needed to provide Sense. Decionis remains responsible for each subprocessor's performance of its data-protection obligations and requires protections materially consistent with this DPA.
Purpose: application hosting, managed infrastructure, storage, networking, security, and recovery. Primary Sense production region: Finland, European Union.
Decionis will publish changes to this list and provide reasonable advance notice of a new subprocessor where Data Protection Laws require it. Customer may object on reasonable data-protection grounds by contacting privacy@decionis.com within 15 days of notice. The parties will work in good faith on a reasonable alternative; if none is available, either party may terminate the affected service.
06
Taking into account the nature of processing and information available to Decionis, Decionis will reasonably assist Customer with verified data-subject requests, security obligations, data protection impact assessments, and regulator consultations. Customer remains responsible for responding to requests and may use available workspace controls before requesting assistance.
Decionis will notify Customer without undue delay after confirming a personal-data breach affecting Customer Personal Data and will provide available information reasonably needed for Customer's legal notifications. Notice is not an admission of fault or liability.
07
During the agreement, Customer may use available export, share, revocation, connector, and deletion controls. After termination or a verified deletion request, Decionis will delete or return Customer Personal Data within 30 days unless Customer requests an earlier technically available export or law requires retention. Data retained by law will remain protected and isolated from ordinary product use.
When Sense receives an authenticated Forge pre-uninstall event, Jira and Confluence credentials bound to that Atlassian cloud site are revoked or made unusable immediately. Connector records, synchronized events, related work items, evidence memory, and connector-created login sessions tied to that site are scheduled for deletion no later than 30 days after the uninstall request.
A verified reinstall during that window cancels the scheduled deletion. The uninstall process does not delete unrelated Sense projects, ledgers, devices, or data from other connectors. Snapshot backups are overwritten with the sanitized state when the scheduled purge completes.
08
Decionis will not transfer Customer Personal Data across borders except as permitted by Data Protection Laws. Where a restricted transfer requires a transfer mechanism, the parties incorporate the European Commission Standard Contractual Clauses, Module Two (controller to processor), as updated or replaced, with Customer as data exporter and Decionis as data importer. The UK International Data Transfer Addendum applies where required for UK transfers.
09
Decionis will make information reasonably necessary to demonstrate compliance with this DPA available to Customer. No more than once annually, unless required by a regulator or after a confirmed incident, Customer may request a reasonable audit. Audits must protect other customers, confidentiality, security, and service availability, and Customer bears its costs unless the audit identifies material noncompliance by Decionis.
If this DPA conflicts with the agreement on processing Customer Personal Data, this DPA controls. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses control. The remainder of the agreement stays in effect.
10
This DPA is offered electronically and does not require a separate signature where Customer has accepted the agreement online. For a countersigned copy, privacy questions, or a subprocessor objection, contact the address below.
Privacy and DPA requests
privacy@decionis.com