Nexus · test management for Jira
Menu
Talk to the Nexus team

Nexus Data Processing Agreement

Last updated 9 October 2026.

If your organisation needs a counter-signed copy of this Data Processing Agreement, email nexus-support@resync.co.nz.

1. Parties, scope and acceptance

This Data Processing Agreement ("DPA") is between Resync Consulting Limited, c/- Findex NZ Limited, Level 1 Findex House, 57 Willis Street, Wellington 6011, New Zealand (NZBN 9429047299030) ("Resync", "Processor"), and the organisation that installs or uses the Nexus app on an Atlassian Jira Cloud site ("Customer", "Controller").

It applies to the personal data that Nexus processes on the Customer's behalf when the Customer uses Nexus. It forms part of the Nexus terms of service and should be read with the Nexus privacy policy.

This DPA applies automatically to every customer who installs or uses Nexus. This page is the agreement, and no signature is needed for it to apply. A customer that wants a counter-signed copy can email nexus-support@resync.co.nz.

2. Roles

The Customer is the data controller for the personal data in its Jira site and in the content its users put into Nexus, such as requirements, test cases, test runs and test data. Resync is the data processor. Nexus processes that data only to provide Nexus's features to the Customer.

Nexus runs on Atlassian Forge, Atlassian's cloud platform. Resync operates no servers of its own. The data Nexus stores is kept in the Customer's Jira site and in Forge storage inside Atlassian's cloud, and Resync does not receive it.

Resync is a controller only for the small amount of information it handles directly, such as emails sent to it and the installation and licence details Atlassian shares with app vendors. The privacy policy covers that information.

3. Details of the processing

Element Description
Nature of processing Reading and writing the Customer's Jira data through Jira's own APIs, within the Jira permissions Nexus declares in its Marketplace listing and the acting user's own Jira permissions. Storing Nexus's working data (such as run results, test case history, test data sets, environment and release records, settings and audit records) in Forge storage for the Customer's site. If a Jira administrator connects an AI provider, sending the content an AI action needs to that provider. If an administrator connects a migration source, reading test cases from it into Jira.
Purpose of processing Only to provide the test management, AI-assisted test design, automation, release readiness and reporting features the Customer uses. Never for Resync's own purposes, for marketing, for sale, or to train AI models.
Duration While Nexus is installed, subject to the retention rules in section 8, and until the data is deleted as described there.
Categories of data subjects The Customer's Jira users who use Nexus or are recorded as doing something in it, and any people the Customer's users mention in content they put into Jira or Nexus.
Categories of personal data Atlassian account IDs, recorded where Nexus notes who did something. Nexus does not store names, email addresses or avatars. Also any personal data the Customer's users choose to include in their own test content, such as requirement or test case text. Resync does not decide what that content contains. Nexus test data sets are meant for made-up (synthetic) values.
Special categories of data None are required by Nexus.

4. Processor obligations

Resync will:

  1. Follow instructions. Process personal data only on the Customer's documented instructions, which are this DPA, the terms of service and the Customer's configuration and use of Nexus's features, unless the law requires otherwise. If Resync believes an instruction breaks data protection law, it will tell the Customer.
  2. Keep it confidential. Make sure any person Resync authorises to process Customer personal data is bound by confidentiality.
  3. Keep it secure. Maintain appropriate technical and organisational security measures, described in section 7.
  4. Help with data subject requests. Help the Customer respond to requests from people exercising their data protection rights, as set out in section 9.
  5. Report breaches. Notify the Customer of a personal data breach as set out in section 6.
  6. Help with compliance. Give the Customer reasonable help with data protection impact assessments and consultations with regulators, as far as they concern Nexus.
  7. Show compliance. Make available the information reasonably needed to show that Resync meets this DPA, and allow for and contribute to audits by the Customer or an auditor it appoints, on reasonable notice, at reasonable intervals and subject to confidentiality. Resync may first answer by providing written information, such as its security and privacy answers.

5. Sub-processors

Resync uses one sub-processor:

Sub-processor What it does Where
Atlassian Hosts Nexus and its storage as the Forge platform provider. Atlassian's cloud, following the data residency of the Customer's Jira site.

Resync engages no other sub-processor. Atlassian's processing is governed by Atlassian's own data processing terms for Forge.

AI providers are the Customer's own, not Resync sub-processors. Nexus uses AI only when a Jira administrator connects the Customer's own account with an AI provider (Anthropic, OpenAI, Google, Moonshot (Kimi) or xAI (Grok)). The Customer chooses and contracts that provider. When someone runs an AI action, the requirement content the action needs is sent directly from Atlassian's Forge platform to that provider. Resync runs no server in between and never receives that content. How the provider processes, stores and uses it, including where, is governed by the Customer's own agreement with the provider. The privacy policy lists exactly what is sent and the redaction options.

Migration sources. If a Customer administrator connects Xray Cloud, Zephyr Scale Cloud, Zephyr Squad Cloud or AIO Tests Cloud to migrate test cases, Nexus uses the credentials the administrator enters to read test cases from that service into the Customer's Jira site. The credentials are stored encrypted in Nexus's Forge storage on the Customer's site, used only for that migration, and deleted when it finishes (by default) or after 30 days. No Jira data is sent to those services. They are services the Customer already uses, not Resync sub-processors.

If Resync plans to add a sub-processor, it will update this page and tell the Customer through the Marketplace contact on record before the change takes effect, so the Customer can object. A change like that would also need the Customer's administrator to approve a new version of Nexus.

6. Security incidents

Resync will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data processed under this DPA. Resync will use the technical and billing contacts the Customer gave Atlassian, give the information reasonably available at the time, and update the Customer as more becomes known. Resync will also report the incident to Atlassian as Atlassian requires.

To report a security concern or a suspected incident to Resync, email nexus-support@resync.co.nz with "Security" in the subject line.

7. Security measures

Nexus is built on Atlassian's security controls, including encryption in transit and at rest for Forge storage and Atlassian's access controls. In addition:

  • Nexus checks the acting user's own Jira permissions, including issue-level security, before showing or changing anything.
  • Nexus asks only for the Jira and Confluence permissions (scopes) listed in its Marketplace listing.
  • CI API keys are stored only as salted hashes, shown once and compared in constant time.
  • AI provider keys are kept in Forge's secret storage and never sent back to the browser. Migration credentials are stored encrypted and deleted after use.
  • Operational logs hold no End-User Data. They record status codes, counts, error types and opaque reference codes only, never issue text, test content, issue or project keys, or account IDs.
  • Database queries are parameterised, and XML uploaded to the automation results endpoint is parsed with external entities turned off.
  • Test data sets are scanned for likely real personal information, real card numbers are always refused, and values in sets marked sensitive are masked.
  • Optional redaction can replace selected kinds of personal data with placeholders before content is sent to the Customer's AI provider.

8. Retention, return and deletion

  • While Nexus is installed, Nexus's own working history is removed after 180 days by default. The Customer's Jira administrator can change this per project, from 30 to 3,650 days.
  • Audit records are kept for 7 years by default, adjustable per project from 1 to 10 years, because they serve as audit and release evidence.
  • Return. A Jira administrator can export everything Nexus stores at any time (Nexus Setup → Backup & Restore). The export never contains secrets such as API keys.
  • Jira data stays with the Customer. Nexus never deletes the Customer's Jira issues. Test cases, test sets and test executions are ordinary Jira issues and stay in Jira if Nexus is uninstalled.
  • After uninstall, Atlassian keeps Nexus's Forge storage for a limited period under its platform retention policy and then deletes it permanently. Resync cannot read or keep a copy of that storage.
  • Support content. If the Customer sends Resync content from its Jira site for support, Resync uses it only to answer and deletes it when it is no longer needed.

The privacy policy has the full retention detail.

9. Data subject rights and removed users

Most personal data in scope sits in the Customer's own Jira site and is handled with Atlassian's own tools. For data Nexus stores itself:

  • Nexus uses Atlassian's personal data reporting API. Each week it checks which of the account IDs it stores belong to closed Atlassian accounts, and Jira also tells it when a user is deleted from the site. Nexus then deletes that person's own records (such as preferences and saved views) and replaces their account ID with "unknown" in working records.
  • Audit records keep the bare account ID, never a name or email address, so that the audit trail stays complete as evidence. They are deleted at the end of the audit retention period.
  • Resync will give the Customer reasonable help with any other request about personal data in Nexus. Email nexus-support@resync.co.nz.

10. International transfers

Resync is based in New Zealand. The European Commission recognises New Zealand as providing an adequate level of data protection, and Resync relies on that adequacy decision for any processing from New Zealand. The data Nexus stores stays in Atlassian's platform, and Atlassian's own transfer mechanisms apply to that hosting.

11. California (CCPA)

For the purposes of the California Consumer Privacy Act, as amended, Resync acts as a service provider to the Customer, not as a business. Resync will not sell or share personal information it processes for the Customer, will not keep, use or disclose it for any purpose other than providing Nexus, and will not combine it with personal information from other sources except as the law allows a service provider to do.

12. Liability and term

Each party's liability under this DPA is subject to the limits in the terms of service, except where the law does not allow liability to be limited.

This DPA applies while the Customer uses Nexus and continues until all Customer personal data Nexus stores has been deleted as described in section 8.

13. Precedence, governing law and changes

If this DPA and the terms of service conflict about processing personal data, this DPA applies to the extent of the conflict.

This DPA is governed by the law of New Zealand, and the courts of New Zealand have non-exclusive jurisdiction.

Resync may update this DPA to reflect changes to Nexus or the law. The version on this page applies, and the date at the top shows when it last changed. If a change materially reduces the Customer's protection, Resync will tell the Customer through the Marketplace contact on record before it applies.

14. Contact

Data protection questions and security incident notices: nexus-support@resync.co.nz.

Resync Consulting Limited, c/- Findex NZ Limited, Level 1 Findex House, 57 Willis Street, Wellington 6011, New Zealand. NZBN 9429047299030.