Effective 15 September 2026. This agreement forms part of the terms of service for every app published on the Atlassian Marketplace by Two Little Moons Consulting (ABN 49 732 400 198, Australia), referred to as "we", "us" or "the processor". It applies automatically to any customer whose use of an app involves personal data, without needing to be signed. If you need a countersigned copy for your records, email support@twolittlemoons.com and we will return one.
It is written in plain language on purpose. The apps are small, they run inside Atlassian, and the honest description of what they do with data fits on one page.
You are the controller of the personal data in your Jira site. We are a processor, and only in the narrow sense that an app we publish processes that data inside your Atlassian installation on your instructions. Under the California Consumer Privacy Act we are a service provider on the same terms.
We never become a controller of your data. We do not decide what to collect, we do not use it for our own purposes, and we hold no copy of it.
Each app processes only the Jira data its feature needs, itemised per app in the privacy policy. In general terms:
We will:
We have one sub-processor for every app, and it is the one you already chose:
| Sub-processor | Role | Applies to |
|---|---|---|
| Atlassian Pty Ltd | Hosts the Forge platform the apps run on and the storage they use. Governed by your own Atlassian Cloud Terms of Service and Atlassian's Data Processing Addendum. | All eleven apps |
Two apps can transmit data to a further service, in each case only to an account you hold and configure, so that service is your own processor rather than our sub-processor:
We will not add a sub-processor without updating this page and the affected app's release notes at least 30 days before it takes effect, and you may object by uninstalling the app before then.
Nine of the eleven apps transfer no data anywhere. They run inside Atlassian's platform, and data residency follows your Atlassian site under Atlassian's own arrangements. For those apps there is no transfer for us to make and no transfer mechanism for us to provide.
For Mailpost and Git Links, data goes only to a service you have chosen and hold your own agreement with. Where that service is outside your jurisdiction, the transfer is made under your relationship with that service, not ours. We do not offer Standard Contractual Clauses of our own, because we are not the party making the transfer.
You are responsible for having a lawful basis for the personal data in your Jira site, for the instructions you give an app through its configuration, and for your own agreements with Atlassian and any provider you connect. If an instruction would, in our view, breach data protection law, we will tell you.
Liability under this agreement is subject to the limits in the terms of service. This agreement lasts as long as an app is installed on your site and ends automatically when it is removed, except for obligations that by their nature survive, such as confidentiality.
This agreement is governed by the laws of New South Wales, Australia. Where the General Data Protection Regulation or the UK GDPR applies to your processing, this agreement is intended to satisfy Article 28(3) and should be read accordingly.
We will update this page and its effective date if what the apps do with data changes. A new sub-processor or a new category of stored data is announced in the app's release notes first.