Sense- Judgement MemoryPrivacy & data policy

Customer data processing addendum

Your data. Your instructions.

This Data Processing Addendum sets the terms under which Decionis processes personal data for customers using Sense.

Effective July 18, 2026 · Version 1.0

Instruction limited

Customer data is processed only to provide Sense and follow documented customer instructions.

Security by design

Tenant separation, least privilege, encryption, redaction, and evidence hashing protect the processing path.

30-day uninstall window

Atlassian-derived data tied to an uninstalled cloud site is scheduled for deletion within 30 days.

This Customer Data Processing Addendum ("DPA") forms part of the agreement between the customer identified in the applicable order, online acceptance, or other agreement ("Customer") and Decionis, Inc. ("Decionis") for Customer's use of Sense.

Capitalized terms not defined here have the meaning given in the agreement. The parties agree that this DPA is effective when Customer accepts the agreement or begins processing Customer Personal Data through Sense, whichever occurs first.

01

Agreement and roles

"Customer Personal Data" means personal data submitted to, stored in, or otherwise processed by Sense on Customer's behalf. "Data Protection Laws" means privacy and data-protection laws applicable to that processing, including the EU GDPR and UK GDPR where applicable.

Customer is the controller or business and Decionis is the processor or service provider for Customer Personal Data. Customer is responsible for its instructions, notices, legal bases, permissions, and the lawfulness of data supplied to Sense. Decionis will notify Customer if an instruction appears to violate applicable Data Protection Laws, unless legally prohibited from doing so.

02

Processing details

Subject matter and purpose

Decionis processes Customer Personal Data to authenticate users, operate customer workspaces, connect authorized sources, produce judgments and contradiction findings, preserve customer-selected evidence and decision records, provide support, secure the service, and perform the agreement.

Duration

Processing continues for the term of the agreement and any documented return, export, backup, legal-retention, or deletion period described below.

Data subjects

Data subjects may include Customer's users, team members, contractors, collaborators, customers, candidates, and other people referenced in content Customer elects to process.

Categories of personal data

Customer Personal Data may include account and workspace identifiers; business contact and profile information; work artifacts, excerpts, tasks, meetings, issue and page metadata; judgments, findings, evidence hashes, and decision records; connector authorization metadata; and operational security and audit data. Sense is not designed for special-category or highly regulated personal data unless the parties expressly agree in writing.

03

Customer instructions

The agreement, Customer's configuration and authorized use of Sense, and written support requests are Customer's documented instructions. Decionis will process Customer Personal Data only on those instructions, including for transfers, unless law requires other processing. If law requires other processing, Decionis will inform Customer before it occurs unless the law prohibits notice.

Decionis will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only where needed for their responsibilities.

04

Security measures

Decionis maintains technical and organizational measures designed for the nature of the processing and the risks to data subjects. These measures include:

  • HTTPS/TLS for data in transit.
  • Encrypted server-side credential storage and exclusion of OAuth tokens from connector responses and application logs.
  • Tenant-aware authorization, scoped device credentials, and least-privilege connector access.
  • In-browser redaction of common personal and secret-like values before browser-extension transmission.
  • Content hashing and derived evidence records where raw source text is not required for the selected feature.
  • Backups, service monitoring, change controls, incident response, and recovery procedures appropriate to the service.

05

Subprocessors

Customer authorizes Decionis to use subprocessors needed to provide Sense. Decionis remains responsible for each subprocessor's performance of its data-protection obligations and requires protections materially consistent with this DPA.

Current infrastructure subprocessor

Google Cloud Platform

Purpose: application hosting, managed infrastructure, storage, networking, security, and recovery. Primary Sense production region: Finland, European Union.

Decionis will publish changes to this list and provide reasonable advance notice of a new subprocessor where Data Protection Laws require it. Customer may object on reasonable data-protection grounds by contacting privacy@decionis.com within 15 days of notice. The parties will work in good faith on a reasonable alternative; if none is available, either party may terminate the affected service.

06

Rights, assessments, and incidents

Taking into account the nature of processing and information available to Decionis, Decionis will reasonably assist Customer with verified data-subject requests, security obligations, data protection impact assessments, and regulator consultations. Customer remains responsible for responding to requests and may use available workspace controls before requesting assistance.

Decionis will notify Customer without undue delay after confirming a personal-data breach affecting Customer Personal Data and will provide available information reasonably needed for Customer's legal notifications. Notice is not an admission of fault or liability.

07

Return and deletion

During the agreement, Customer may use available export, share, revocation, connector, and deletion controls. After termination or a verified deletion request, Decionis will delete or return Customer Personal Data within 30 days unless Customer requests an earlier technically available export or law requires retention. Data retained by law will remain protected and isolated from ordinary product use.

Atlassian post-uninstall lifecycle

Credentials now. Derived data within 30 days.

When Sense receives an authenticated Forge pre-uninstall event, Jira and Confluence credentials bound to that Atlassian cloud site are revoked or made unusable immediately. Connector records, synchronized events, related work items, evidence memory, and connector-created login sessions tied to that site are scheduled for deletion no later than 30 days after the uninstall request.

A verified reinstall during that window cancels the scheduled deletion. The uninstall process does not delete unrelated Sense projects, ledgers, devices, or data from other connectors. Snapshot backups are overwritten with the sanitized state when the scheduled purge completes.

08

International transfers

Decionis will not transfer Customer Personal Data across borders except as permitted by Data Protection Laws. Where a restricted transfer requires a transfer mechanism, the parties incorporate the European Commission Standard Contractual Clauses, Module Two (controller to processor), as updated or replaced, with Customer as data exporter and Decionis as data importer. The UK International Data Transfer Addendum applies where required for UK transfers.

09

Audit and priority

Decionis will make information reasonably necessary to demonstrate compliance with this DPA available to Customer. No more than once annually, unless required by a regulator or after a confirmed incident, Customer may request a reasonable audit. Audits must protect other customers, confidentiality, security, and service availability, and Customer bears its costs unless the audit identifies material noncompliance by Decionis.

If this DPA conflicts with the agreement on processing Customer Personal Data, this DPA controls. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses control. The remainder of the agreement stays in effect.

10

Contact and acceptance

This DPA is offered electronically and does not require a separate signature where Customer has accepted the agreement online. For a countersigned copy, privacy questions, or a subprocessor objection, contact the address below.

Privacy and DPA requests

privacy@decionis.com
Decionis, Inc.
2810 N Church St STE 88692
Wilmington, DE 19802, United States