Scope and Roles
This Data Processing Agreement ("DPA") applies when RedmineUP processes Personal Data on behalf of a customer in connection with the RedmineUP Cloud service.
For the purposes of applicable data protection law:
- The customer acts as the data controller and determines the purposes and means of processing Customer Data.
- RedmineUP acts as the data processor and processes Customer Data only to provide, operate, secure, maintain, and support the RedmineUP Cloud service and in accordance with the customer's documented instructions.
- If RedmineUP believes that a customer instruction violates applicable data protection law, we will inform the customer where legally permitted.
This DPA forms part of the agreement governing the customer's use of RedmineUP Cloud where processing of Personal Data is subject to the GDPR or other applicable data protection laws.
Processing Details
The subject matter of processing is the provision of the RedmineUP Cloud service.
Processing may include hosting, storing, organizing, retrieving, transmitting, backing up, securing, maintaining, troubleshooting, and deleting Customer Data.
The duration of processing is the term of the customer's RedmineUP Cloud service, together with the limited retention periods described below.
Categories of data subjects may include:
- Customer employees, users, administrators, contractors, and consultants
- Customer clients, prospects, suppliers, and business contacts
- End users and other individuals whose information is entered into RedmineUP by the customer
Types of Personal Data may include:
- Account and profile information, including names, email addresses, usernames, roles, and contact details
- Project and issue data, comments, activity history, attachments, time entries, and custom fields
- CRM and Helpdesk data, including customer contacts, support requests, email correspondence, and related metadata
- Financial and commercial information stored by the customer, such as project budgets, billing data, quotations, and invoices
- Any other Personal Data entered, uploaded, or generated by the customer through Redmine and RedmineUP plugins
RedmineUP does not require customers to store special categories of Personal Data. If a customer chooses to store such data, the customer is responsible for ensuring that the processing is lawful and that appropriate instructions and safeguards are in place.
Confidentiality and Access
Access to production Customer Data is restricted to authorized RedmineUP support personnel on a need-to-know basis and only where necessary to provide support, maintenance, security, or troubleshooting.
- Production access is limited to authorized personnel.
- Access is provided through individual accounts and is revoked when no longer required.
- Customer database dumps and attachments are not downloaded to local employee devices for debugging.
- Authorized support personnel located in Armenia may remotely access Customer Data where necessary to provide the service.
All personnel authorized to process Customer Data are subject to confidentiality obligations.
Security Measures
RedmineUP maintains appropriate technical and organizational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
These measures include:
- Hosting of RedmineUP Cloud infrastructure and Customer Data in Amazon Web Services (AWS), EU (Ireland) region
- Encryption of data in transit using TLS 1.2/1.3
- Encryption of data at rest using AES-256
- Logical segregation of customer environments
- Restricted production access for authorized support personnel
- Infrastructure monitoring, logging, backup, and recovery procedures
- Security maintenance and vulnerability remediation processes
Additional information is available in the RedmineUP Data Security Standards.
Sub-processors
The customer provides general authorization for RedmineUP to engage sub-processors where necessary to provide the RedmineUP Cloud service.
RedmineUP:
- Maintains a current list of sub-processors used for RedmineUP Cloud
- Requires sub-processors to provide appropriate data protection and security safeguards
- Remains responsible for its obligations under this DPA when processing is performed by an authorized sub-processor
- Will provide notice of material changes to the sub-processor list where required by applicable law or the customer's agreement
The current list is available on the RedmineUP Sub-processors page.
International Data Transfers
RedmineUP Cloud Customer Data and backups are hosted in the AWS EU (Ireland) region.
Authorized RedmineUP support personnel located in Armenia may remotely access Customer Data where necessary to provide support, maintenance, security, or troubleshooting.
Where processing involves a transfer of Personal Data subject to Chapter V of the GDPR, RedmineUP will use an applicable lawful transfer mechanism and appropriate safeguards. Where required, this may include the Standard Contractual Clauses adopted by the European Commission under Implementing Decision (EU) 2021/914.
Email processing may involve the United States when the standard Mailgun US region is used. An EU-region Mailgun configuration can be provided upon request for customers with specific data residency requirements.
Data Subject Requests
Taking into account the nature of the processing, RedmineUP will provide reasonable assistance to the customer in responding to requests from data subjects exercising their rights under applicable data protection law.
If RedmineUP receives a request directly from a data subject relating to Customer Data, RedmineUP will direct the request to the relevant customer where appropriate and legally permitted.
Personal Data Breaches
RedmineUP maintains procedures for identifying, investigating, and responding to security incidents.
If RedmineUP becomes aware of a Personal Data Breach affecting Customer Data, RedmineUP will:
- Notify the affected customer without undue delay and, where practicable, within 48 hours after becoming aware of the breach
- Provide available information reasonably necessary for the customer to meet its notification and documentation obligations
- Take reasonable steps to contain, investigate, and mitigate the effects of the incident
Data Retention and Deletion
Upon termination or expiration of the RedmineUP Cloud service:
- Customer Data in active systems is scheduled for deletion within 30 days
- Backup copies may be retained for up to 180 days and are deleted through the normal backup lifecycle
- Earlier deletion may be requested by the customer where technically feasible and subject to applicable legal obligations
During backup retention periods, retained Customer Data remains protected by the security measures applicable to the RedmineUP Cloud service.
Assistance and Compliance
Taking into account the nature of processing and the information available to RedmineUP, we will provide reasonable assistance to the customer with:
- Data protection impact assessments where relevant to the RedmineUP Cloud service
- Security and breach-related obligations
- Demonstrating compliance with applicable processor obligations
- Reasonable compliance information requests from customers
Upon reasonable request, RedmineUP will make available information necessary to demonstrate compliance with its obligations as a data processor. Any audit or inspection request must be subject to reasonable notice, appropriate confidentiality obligations, and measures designed to avoid unnecessary disruption to RedmineUP services and other customers.
Customer Responsibilities
The customer is responsible for:
- Providing lawful instructions for the processing of Personal Data
- Ensuring that it has an appropriate legal basis for Personal Data uploaded to or processed through RedmineUP
- Configuring user access and permissions appropriately
- Responding to data subject requests as the data controller
- Avoiding the unnecessary storage of sensitive Personal Data
Order of Precedence
If there is a conflict between this DPA and other contractual terms between the customer and RedmineUP regarding the processing of Personal Data, this DPA will prevail to the extent of that conflict.
Last updated: September 18, 2026