Data Processing Agreement
Last updated: August 26, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the customer installing or using the Audit Otter application ("Customer") and Abrega Inc., doing business as Audit Otter ("Abrega"), and applies whenever Abrega processes personal data on Customer's behalf. A countersigned copy is available on request from privacy@auditotter.com.
1. Roles and scope
For personal data contained in Customer's compliance program data (described in Annex 1), Customer is the controller and Abrega is the processor. "Data protection law" means the law applicable to the processing, including, where relevant, the EU and UK GDPR and US state privacy laws. For data Abrega collects for its own purposes (such as the website launch list), Abrega is the controller and its Privacy Policy applies instead of this DPA.
2. Processing on instructions
Abrega processes Customer personal data only on Customer's documented instructions: the agreement between the parties, Customer's configuration of the application (including which tools Customer connects and what Customer's users ask the application to do), and this DPA. Abrega will inform Customer if, in its opinion, an instruction infringes data protection law, and may suspend the affected processing until the instruction is confirmed or changed. Abrega does not sell Customer personal data, use it for advertising, or use it to train machine-learning models.
3. Confidentiality
Abrega ensures that persons authorized to process Customer personal data are bound by confidentiality obligations, and limits access to those who need it to operate, secure, and support the service.
4. Security
Abrega implements and maintains the technical and organisational measures described in Annex 2, and will not materially reduce the overall security of the service during a subscription term.
5. Subprocessors
Customer gives general authorization for Abrega to engage subprocessors. Current subprocessors:
- Amazon Web Services, Inc. (cloud hosting: compute, database, object storage, secrets management), United States.
- Atlassian Pty Ltd (the Forge platform the application runs on, and the Atlassian sites the application reads from), per Customer's own Atlassian hosting.
Abrega will give notice (by email or in-app) at least 30 days before adding or replacing a subprocessor that processes Customer personal data. If Customer reasonably objects on data-protection grounds and the parties cannot resolve the objection, Customer may terminate the affected service and export its data. Abrega imposes data-protection obligations on subprocessors that are no less protective than this DPA and remains liable for their performance.
6. Assistance
Taking into account the nature of the processing, Abrega will assist Customer, by appropriate technical and organisational measures and insofar as reasonably possible, with (a) responding to data subject requests (access, rectification, erasure, restriction, portability, objection), and (b) Customer's obligations regarding security, breach notification, data protection impact assessments, and consultations with supervisory authorities. If a data subject contacts Abrega directly about Customer's program data, Abrega will refer the request to Customer without undue delay.
7. Personal data breach
Abrega will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer personal data, and will provide information reasonably required for Customer to meet its own notification obligations, updating the notice as the investigation progresses.
8. Deletion and return
Customer can export its program data at any time through the application. On termination of the service, or on a verified deletion request from Customer's administrator, Abrega deletes Customer personal data promptly and at most within 30 days, unless law requires longer retention of specific records, in which case the data remains protected under this DPA until deleted.
9. Audits and information
Abrega will make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of security measures and, when available, third-party audit reports. Where data protection law grants Customer an audit right that these materials do not satisfy, Customer may conduct an audit at most once per year, on at least 30 days' notice, during business hours, under confidentiality, without access to other customers' data, and at Customer's cost.
10. International transfers
Customer personal data is processed in the United States on Amazon Web Services infrastructure. Where the EU or UK GDPR applies to a transfer, the parties rely on an applicable adequacy mechanism (including the EU-U.S. Data Privacy Framework where Abrega or the relevant subprocessor participates) or, failing that, the European Commission's Standard Contractual Clauses (Module Two: controller to processor) and the UK Addendum, which are incorporated into this DPA by reference, with Annexes completed by Annex 1 and Annex 2 of this DPA.
11. Liability, term, and precedence
This DPA applies for as long as Abrega processes Customer personal data. Liability under this DPA is subject to the limitations in the agreement governing Customer's use of the Audit Otter application. If this DPA conflicts with that agreement, this DPA controls for data-protection matters. If Customer has a separately negotiated DPA with Abrega, that agreement controls instead of this page.
Annex 1 · Details of processing
- Subject matter and nature: hosting and operating the Audit Otter compliance application: scheduled and on-demand collection of evidence from Customer-connected tools, integrity hashing, mapping to framework requirements, policy and questionnaire management, Trust Center publishing, and export.
- Duration: the term of Customer's use of the application, plus the deletion period in section 8.
- Categories of data subjects: Customer's personnel and contractors who appear in connected tools; auditors and reviewers Customer works with; buyers and other recipients Customer grants Trust Center access to.
- Categories of personal data: business identifiers (names, work email addresses, Atlassian account IDs, usernames in connected tools); activity attribution (who approved, changed, or reviewed something and when); and personal data incidentally contained in evidence artifacts Customer's tools produce (for example, a name appearing in an audit log or a page history).
- Special categories: none intended; Customer agrees not to use the application to process special-category data.
- Frequency: continuous, on an hourly collection schedule and on demand.
Annex 2 · Technical and organisational measures
- Encryption in transit (TLS) for all connections, including between Customer's Atlassian site and Abrega's backend, authenticated with short-lived, signed Forge app tokens.
- Encryption at rest for the production database and the evidence object store; secrets held in a managed secrets service, not in code or configuration files.
- Application-layer encryption for Customer's integration credentials, which are never returned to the client after entry.
- Least-privilege access: the application requests narrow, Atlassian-reviewed scopes; user identity and permissions come from Customer's Atlassian site; Abrega maintains no separate password store for Customer users.
- Integrity: evidence artifacts are hashed (SHA-256) and timestamped at collection.
- Environment separation between staging and production; immutable, vulnerability-scanned container images; infrastructure defined as code and access-restricted at the network edge.
- Operational logging and monitoring; documented retention and deletion practices per section 8 and the Privacy Policy.
Contact
Questions about this DPA, signed copies, and subprocessor notices: privacy@auditotter.com.