Cost Slasher Data Processing Addendum
This addendum governs LeanZero's processing of personal data for the organisation using Cost Slasher. It forms part of the Cost Slasher beta terms and applies to paid use and evaluations whenever LeanZero acts as a processor.
Effective 4 October 2026
1. Parties, scope and priority
The customer is the organisation identified in the applicable Marketplace order, authorised installation or other written order, acting through its authorised representative. The processor is LeanZero SRL, trade register J2025012835002, CUI 51336260, registered office Str. Toamnei 23 G, CAM. 1, Bragadiru, Ilfov, 077025, Romania. Privacy and contractual contact: office@leanzero.net.
The customer determines the purposes of its workforce licence administration and is the controller, or is a processor authorised by its controller to appoint LeanZero. Where the customer is a processor, references to its instructions and rights include its obligations to the relevant controller. This addendum takes priority over conflicting app terms on personal-data processing and does not restrict mandatory statutory rights.
Customer personal data means personal data processed on the customer's behalf through the app and its recovery service. It does not include information LeanZero independently controls for direct sales, support, billing administration or its own legal obligations; that processing is covered by the privacy statement and applicable law. A support submission can also contain customer personal data and remains protected accordingly.
2. Documented instructions
LeanZero processes customer personal data only on documented instructions to provide, secure and support the configured service, including authorised transfers. The order, this addendum, permitted app settings and authorised support instructions record those instructions. LeanZero will inform the customer immediately if, in its opinion, an instruction infringes applicable data-protection law, and suspend the affected processing until a lawful instruction is agreed.
If Union or Member State law requires processing outside those instructions, LeanZero will inform the customer of the legal requirement before processing unless the law prohibits notice on important public-interest grounds. The customer is responsible for lawful collection, appropriate workforce notices, its own retention policies and authority to supply instructions. Neither party may use that allocation to avoid its own legal duties.
3. Processing details
Subject matter and purpose: licence and access administration, observed inactivity checks, explicit self-service recovery, time-away commitments, group routing, permissions, audit and usage reporting, notifications, privacy requests and consistent handling of their operation outcomes. Processing includes collection, verification, organisation, storage, retrieval, authorised disclosure, export, restriction and deletion. Processing is ongoing while the service is provided and continues only as necessary to complete the customer's lawful return or deletion instructions and required legal retention.
Data subjects: the customer's Atlassian users, organisation administrators, app-role holders and people whose accounts are eligible for the configured service. Data categories: account identifiers, names and email addresses where returned or needed; organisation, directory, site, app and relevant group identifiers; access, activity and eligibility observations; app permissions and policies; time-away dates and timezones; capacity and operation records; scoped audit and usage evidence; notification recipients and content; pseudonymous request, session and security references; and necessary support information.
The service is not intended to receive special-category data, medical details, criminal records, payment-card details or Atlassian passwords. Time-away bookings require dates and timezone, not a reason for the absence. Customers must not supply sensitive personal information unsupported by Atlassian or unnecessary to the service.
4. Confidentiality and security
LeanZero will ensure that persons authorised to process customer personal data are bound to confidentiality and have access only as needed for their duties. LeanZero will maintain technical and organisational safeguards appropriate to the risk, including scoped identity and permission checks, installation binding, encrypted managed storage, HTTPS, protected secret stores, session revocation, request-integrity checks, minimised logs and controlled operational access.
The implemented product measures and their verification limits are described in the security policy. LeanZero will assess, test and review relevant safeguards and maintain its records of processing. This agreement does not claim a certification, completed customer journey or guaranteed workload capacity.
5. Subprocessors
The customer gives general written authorisation for the providers listed here: Atlassian for Forge hosting, encrypted app storage, platform identity, personal-data reporting and the LeanZero support portal; Amazon Web Services for the external recovery origin, encrypted records and secrets, notifications, logs and static delivery; and Microsoft 365 for the LeanZero business mailbox when support or privacy correspondence includes customer personal data. AWS's configured origin region is Ireland; CloudFront operates globally. Atlassian and Microsoft control their own service locations and applicable residency options. The actual supplier contracting entities are those in LeanZero's applicable supplier agreements.
The current onward-provider and location registers are Atlassian's subprocessor register, AWS's subprocessor register and the Microsoft Trust Center's subprocessor information. These registers describe supplier arrangements and do not establish that every listed service is used by Cost Slasher. LeanZero will provide relevant supplier and processing-location information on request.
LeanZero will actively notify the customer's recorded administration or contractual contact of an intended new or replacement direct subprocessor at least thirty days before its use, with the proposed role and available safeguards. The customer may object on reasonable data-protection grounds during that period. The parties will seek a lawful alternative; if none is possible, the customer may end the affected service without a penalty for that termination. LeanZero will not start the disputed new processing until the objection is resolved or the affected service ends.
LeanZero will bind each subprocessor to substantially the same data-protection duties relevant to its processing, verify appropriate safeguards, and remain responsible to the customer for its subprocessors' performance. Provider contracts do not replace this customer addendum.
6. Assistance and personal-data breaches
LeanZero will assist the customer, taking account of the nature of processing and information available, with data-subject access, correction, restriction, portability, objection and deletion requests. Requests received directly will be forwarded to the customer where appropriate. LeanZero will act on the customer's verified instructions and provide available scoped exports, record references, retention information and completion evidence; an app receipt alone is not completion of an erasure.
LeanZero will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer personal data. Notice will provide the known nature of the breach, affected data and people, likely consequences, contact and measures taken or proposed. Information may be supplied in phases as it becomes available. LeanZero will cooperate in containment, investigation and legally required notices; the customer retains responsibility for its controller notices.
For security assessments, data-protection impact assessments and supervisory-authority consultation, LeanZero will provide available data-flow, supplier, safeguard and incident information, respond to relevant questions and implement agreed lawful instructions. Contact office@leanzero.net with the organisation, installation scope and non-secret request reference. Do not send credentials or unredacted data in an initial request.
7. Information and audits
LeanZero will make available information needed to demonstrate compliance with this addendum and Article 28 GDPR and allow and contribute to audits, including inspections, by the customer or its mandated independent auditor. The parties will agree reasonable arrangements for scope, notice, security and confidentiality without preventing an audit required by law, a supervisory authority or a material incident. Audits must protect other customers' data and supplier security boundaries. No certification is required as a substitute for these rights.
8. International transfers
The customer authorises the processing locations and provider operations described in this addendum. LeanZero will not make a covered international transfer without a lawful mechanism required by applicable data-protection law, including an applicable adequacy decision or standard contractual clauses and required supplementary safeguards. Supplier DPAs and conditional transfer clauses apply according to their own terms; Ireland hosting alone does not prove that global transit or all supplier processing stays in the EEA.
This addendum is a customer-processing agreement, not an assertion that all account-specific transfer documentation has been independently certified, and is not itself the European Commission's international-transfer standard contractual clauses. LeanZero will provide relevant transfer information on request and agree any additional required documentation before the affected processing.
9. End of processing
At the customer's choice, LeanZero will return or delete customer personal data after the end of the processing services and delete existing copies, unless Union or Member State law requires storage. LeanZero will confirm completion and identify any legal requirement for retained data, its limited purpose and applicable period. Retained data remains protected and is not used to continue the terminated service.
Uninstalling the app does not automatically erase its external records or prove physical deletion. Current external registry, handover, authority and backup records have no automatic finite maximum, and unresolved request references can remain. The customer and LeanZero must coordinate a scoped instruction, stopping automation, revoking sessions, identifying original outcomes and arranging export or deletion. Unresolved work, a retained cloud resource or a missed response is not by itself a legal exception to return or deletion. LeanZero will not reconstruct a successful deletion from a request receipt or erase evidence by an arbitrary timeout.
Where backup deletion cannot be immediate, LeanZero will isolate the affected data from active use, arrange its removal under the applicable backup lifecycle and provide the customer with the actual applicable completion information. If a protected backup is restored, the completed deletion instructions must be reapplied. No fixed global physical-deletion deadline is represented by this addendum.
10. California processing where applicable
Where the customer is a business subject to the California Consumer Privacy Act, including its amendments, and provides covered personal information, LeanZero acts as its service provider for the limited service purposes in section 3. LeanZero will comply with applicable service-provider obligations and provide the same level of privacy protection required by that law.
LeanZero will not sell or share that information, retain, use or disclose it outside the specified purposes or direct business relationship except as permitted by law, or combine it with information from other customers or LeanZero's own interactions except where the law permits. LeanZero certifies that it understands and will comply with these restrictions.
The customer may take reasonable steps to monitor compliance and, on notice, stop and remediate unauthorised use. LeanZero will notify the customer if it can no longer meet these obligations, cooperate in correction and assist with covered consumer requests. This conditional provision does not declare that every customer or LeanZero independently meets the statutory definition of a CCPA business.
11. Suspension, changes and contact
If LeanZero cannot comply with this addendum, it will promptly inform the customer and suspend the affected processing. The customer may require remediation or terminate affected processing where compliance cannot be restored. Return and deletion duties survive termination. Material processing changes require documented notice and, where required, agreement; they do not remove statutory protections.
Romanian law applies subject to mandatory data-protection law and statutory rights. This addendum creates processing obligations between the customer and LeanZero; it does not change Atlassian's separate platform terms or transfer obligations to an app user. Contact LeanZero through the Cost Slasher support portal or office@leanzero.net.