Schedule 1 — Data Processing Addendum
Effective 7 August 2026.
1. Parties, structure and precedence
This Data Processing Addendum (the "DPA") is Schedule 1 to the Provider-Specific Terms for CloudScript.io NikoNiko Calendar (the "App") between Cloudscript Pty Ltd (ABN 14 700 662 362) ("Cloudscript", "we", "us") and the customer, and forms part of them. It applies where Cloudscript processes personal data on the customer's behalf in providing the App. Terms defined in the Provider-Specific Terms and the Standard Agreement they supplement have the same meaning here. Where this DPA conflicts with those terms in respect of personal data, this DPA prevails to the extent of the conflict.
This DPA also supplements the customer's own agreement with Atlassian. It does not vary that agreement, and nothing in it makes Cloudscript responsible for Atlassian's own processing as the customer's provider of Confluence.
2. Roles
2.1 The customer is the controller of the personal data processed through the App ("Customer Data"). Cloudscript is a processor acting on the customer's documented instructions, which are the Provider-Specific Terms, this DPA, and the customer's configuration and use of the App. Cloudscript will not process Customer Data for any purpose of its own.
2.2 Cloudscript engages Atlassian as sub-processor for hosting and platform services, under the Forge Data Processing Addendum, which incorporates the EU Standard Contractual Clauses for relevant transfers. See clause 5.
2.3 This DPA does not cover personal data Cloudscript processes as controller for its own purposes, which is limited to correspondence a customer or a user sends to our support address. That handling is described in the Privacy Policy rather than governed by this DPA.
3. Description of processing
Subject matter. Provision of the App, a Confluence macro in which team members record dated values on a scale within a calendar displayed to users of the page.
Duration. The subscription term, plus the platform deletion windows described in clause 9.
Nature and purpose. Storage and retrieval of entries for display within the customer's Confluence site, and client-side derivation of a team-level trend from data already displayed. There is no other processing. The App performs no analytics on entry content, and its Forge manifest declares no external permissions, so it makes no network request to any host outside Atlassian's platform.
Categories of data subjects. Confluence users of the customer's site who are configured in, or interact with, a calendar.
Categories of personal data. Atlassian account identifier; entry date; the scale value entered; timestamp of entry; a reference to the calendar (the page and macro instance) the entry was recorded on. Display names and avatars are retrieved from Confluence at render time and are not stored by the App. The App stores no free-text content; a calendar's optional label is a macro parameter within the customer's own Confluence page content, processed by Confluence as page content and not held in the App's storage.
Special categories. The App does not require or request special category data. The customer controls the meaning and content of entries. To the extent that the customer's use results in entries revealing information about health or any other special category, the customer is responsible for ensuring a lawful basis and, where required, a condition under Article 9(2) GDPR or the equivalent under other applicable law.
4. Cloudscript's obligations as processor
4.1 Process Customer Data only on the customer's documented instructions, unless required to do otherwise by law, in which case Cloudscript will inform the customer before processing unless the law prohibits it. Cloudscript will inform the customer immediately if, in its opinion, an instruction infringes the GDPR or another data protection provision that applies to the processing.
4.2 Ensure that the people authorised to process Customer Data, being Cloudscript's directors and any personnel or contractors it authorises, are bound by confidentiality.
4.3 Implement the technical and organisational measures described in clause 6.
4.4 Assist the customer, insofar as reasonably possible and taking into account the nature of the processing, with data subject requests (clause 7), with the security of processing, with personal data breach notification (clause 8), and with data protection impact assessments and prior consultation, as required by Articles 32 to 36 GDPR.
4.5 Delete Customer Data in accordance with clause 9.
4.6 Make available the information reasonably necessary to demonstrate compliance with this DPA, in accordance with clause 10.
5. Sub-processing
5.1 The customer generally authorises Atlassian as sub-processor, for Forge platform hosting and storage. Atlassian's own sub-processors for the Forge platform are published in Atlassian's sub-processor list. Atlassian is the only sub-processor Cloudscript engages for the App: no other recipient exists, because the App declares no external network permissions.
5.2 Cloudscript will give notice of any change to its sub-processors by posting the change on this page at least 30 days before it takes effect, and the customer may object to a change on reasonable data-protection grounds within that period. Where an objection cannot be resolved, the customer may stop using the App and uninstall it.
5.3 Any sub-processor Cloudscript engages is bound by a written contract imposing data protection obligations equivalent to those in this DPA. For Atlassian, that contract is the Forge Data Processing Addendum.
5.4 Cloudscript remains liable for the performance of its sub-processors' obligations.
6. Security
Cloudscript implements technical and organisational measures appropriate to the risk, having regard to the fact that entry content is controlled by the customer and its users and may be sensitive. Those measures are:
- Per-tenant isolation by construction. Entries are held in Forge hosted storage, partitioned per installation by the Forge platform itself. No tenant discriminator appears in the App's key material, so one installation's entries are not addressable from another.
- Data minimisation. An entry holds only the five items listed in clause 3. No free-text content, display name, email address or derived field is stored.
- No network egress from the App. The App's Forge manifest declares no external permissions, and the Forge platform blocks any outbound request an app has not declared in advance.
- Least privilege. The App requests four permission scopes: read access to Confluence content details, read access to content permission metadata (used to verify a caller's permission on a page before entries are served or recorded), application storage, and the personal-data reporting scope Atlassian requires for its account-closure and reporting flow.
- Encryption in transit and at rest, as provided by the Forge platform for hosted storage.
- Platform security controls operated by Atlassian under the Forge shared responsibility model, which allocates platform security to Atlassian and app-layer conduct to Cloudscript.
- Access control on the vendor accounts. Access to the Marketplace vendor account, the Forge developer console and the source repository is limited to a small number of authorised individuals bound by the same access rules.
Cloudscript holds no security certification of its own. The SOC 2 and ISO 27001 attestations that apply to the platform the App runs on are Atlassian's, and are referenced here as Atlassian's rather than claimed as Cloudscript's. Our site-wide security practices are described at https://cloudscript.io/security.
7. Data subject requests
7.1 If a data subject request reaches Cloudscript directly, Cloudscript will refer the requester to the customer without undue delay, and will not respond substantively except on the customer's instruction or where legally required.
7.2 Where an Atlassian account is closed, the App erases every entry belonging to that account within one reporting cycle, which runs every seven days. This is driven by Atlassian's personal-data reporting flow and requires no action by the customer.
7.3 Where the data subject is a user of the customer's site, the App provides self-service means. A user may correct any of their own entries at any time by overwriting them through the calendar, may permanently delete their own entry for a given day on the calendar it was recorded on, and may permanently delete their entire entry history, which operates across every calendar on the site and deliberately requires no page permission, so that a user who has lost access to a page is not thereby prevented from erasing entries recorded there. Deletion removes the stored record itself, immediately and irreversibly; no copy is retained, and no marker is stored in its place.
7.4 For requests the customer handles as controller (including requests concerning a person who has left the customer's organisation or whose account is deactivated but not closed), the App provides Confluence site administrators with an administration screen listing the accounts for which the App stores entries. The listing is drawn from the App's own storage rather than from the site's user directory, so deactivated and departed accounts remain visible and actionable, and it discloses only which accounts have stored entries. From that screen an administrator may permanently delete every entry for a named account, and may run a site-wide deletion of entries older than a date the administrator chooses, which proceeds as a resumable operation reporting its progress and completion. Each operation runs only on the administrator's confirmation; per-account deletion takes effect immediately. Administrative deletion operates across every calendar and is never limited to one. The App never deletes Customer Data on a schedule of its own: every deletion is a self-service deletion under clause 7.3, an operation confirmed by the customer's administrator under this clause, or the account-closure erasure under clause 7.2. Administrative operations are refused server-side unless the caller holds Confluence site administration permission, and that check fails closed.
8. Personal data breach
Cloudscript will notify the customer without undue delay on becoming aware of a personal data breach affecting Customer Data, and will provide the information reasonably required for the customer to meet its own notification obligations, including notification to a supervisory authority within 72 hours under GDPR and notification to the OAIC and affected individuals under the Australian Notifiable Data Breaches scheme where it applies. A breach may arise at the app layer or at the platform layer. App-layer events (a defect in the App, or a compromise of the accounts from which the App is developed and published) are Cloudscript's own to detect and notify. For platform-level events, Cloudscript's awareness depends on Atlassian's notice to it under the Forge Data Processing Addendum.
9. Deletion and return
9.1 On uninstall or termination, Customer Data held by the App is deleted by Atlassian in accordance with the Forge hosted storage data lifecycle, described at https://developer.atlassian.com/platform/forge/storage-reference/hosted-storage-data-lifecycle/. Cloudscript holds no copy of Customer Data anywhere else, because the App writes to no store other than Forge hosted storage on the customer's own site, and it retains no copy after deletion. Cloudscript does not, and is unable to, retain Customer Data after deletion, and is under no legal obligation to retain it.
9.2 The App provides no export function. Cloudscript therefore makes no commitment to return Customer Data in a structured format, and a customer that wants a record of the values displayed in a calendar should take it from the Confluence page while the App is installed and licensed.
10. Audit
Cloudscript will make available the information reasonably necessary to demonstrate compliance with this DPA, including its Atlassian Marketplace security self-assessment for the App, its record of processing activities under Article 30(2) GDPR, and a description of the measures in clause 6, and will respond to a customer's reasonable written questions about its processing. Because Cloudscript operates no infrastructure of its own for the App, the platform controls a customer would otherwise wish to inspect are Atlassian's, and are addressed by Atlassian's own attestations for the Forge platform.
Where that information does not answer a customer's reasonable concern, Cloudscript will contribute to an audit or inspection conducted by the customer or an auditor it mandates, on reasonable written notice, no more than once a year unless a personal data breach affecting the customer or a documented compliance failure gives cause for another, and subject to confidentiality. The customer bears the full costs of any audit or inspection, including the annual one: its own costs, its auditor's costs, and Cloudscript's reasonable costs of contributing, at a reasonable rate agreed in writing before the audit begins. The one exception: where the audit follows a personal data breach caused by Cloudscript, or finds material non-compliance by Cloudscript with this DPA, Cloudscript bears its own costs of contributing.
11. International transfers
Transfers to Atlassian and its sub-processors are governed by the Forge Data Processing Addendum's incorporated EU Standard Contractual Clauses, together with the UK and Swiss addenda where they apply. Cloudscript operates no infrastructure for the App and receives Customer Data in no country: the App's entries are held exclusively in Forge hosted storage on the customer's own Confluence site, and their physical location is determined by the customer's existing arrangements with Atlassian rather than by anything Cloudscript provides or can vary.
12. Australian Privacy Act
Where the Privacy Act 1988 (Cth) applies to the customer or to Cloudscript, Cloudscript will handle Customer Data consistently with the obligations under Australian Privacy Principles 11 and 12 that apply to it, and will cooperate with the customer's obligations under the Notifiable Data Breaches scheme on the timeline in clause 8. Cloudscript will not use or disclose Customer Data except as instructed by the customer, and has no practical means of doing otherwise: it holds no copy of Customer Data, has no administrative access to any customer's Confluence site, and the App transmits nothing outside the customer's own Atlassian environment.
13. Liability
Liability under this DPA is subject to the limitations of liability in the Provider-Specific Terms and the Standard Agreement they supplement.
Contact
Cloudscript Pty Ltd (ABN 14 700 662 362)
Support: support@cloudscript.io