Techanics Apps – Privacy Policy

Last updated: August 2026

This Privacy Policy applies to the cloud apps offered by Techanics GmbH through the Atlassian Marketplace for use with Atlassian products such as Jira and Confluence.

It explains how personal data is processed in connection with the installation, configuration and use of our apps, technical diagnostics, app-related support, the management of technical Marketplace contacts and app-related support and service communication.

The specific data processed depends on the relevant app and the functions used. The processing activities of our current apps are described in Section 7.

Where a new Techanics app processes additional categories of personal data, the app-specific information in this Privacy Policy will be updated before the relevant processing begins.

Unless otherwise indicated, Marketplace and support contact data is processed in relation to the data subject’s professional role for the company, organisation or public body they represent.


1. Scope of this Privacy Policy

a) Processing covered by this Privacy Policy

This Privacy Policy covers the processing of personal data in connection with:

  • the installation, configuration and use of our apps
  • the provision of app functions
  • technical diagnostics and error analysis
  • the technical synchronisation of Marketplace contact data
  • app-related support
  • the management of technical Marketplace contacts
  • app-related support and operational service communication
  • associated business, legal and privacy-related communication

b) Relationship with our website Privacy Policy

This Privacy Policy does not apply to the general use of the Techanics website.

The separate Privacy Policy published for our website applies to processing connected with the use of our website, its contact forms, newsletter functions, applications and embedded content.


2. Controller and privacy contact

For processing activities for which Techanics determines the purposes and means of processing, the controller is:

Techanics GmbH
Am Hoffeld 2
83703 Gmund am Tegernsee
Germany

Email: info [at] techanics.de

Commercial Register: HRB 289565
Register Court: Munich
VAT ID: DE365855756

We have not appointed a data protection officer at this time.

Privacy-related enquiries may be sent at any time to the contact details stated above.


3. Data protection roles

a) Techanics as a processor

Where personal data is processed exclusively to provide an app function on behalf of a customer organisation and in accordance with that organisation’s instructions, Techanics acts as a processor.

This applies in particular where our apps process Atlassian user, organisation, role, group or configuration data in order to perform actions requested by an authorised customer administrator.

The respective customer organisation remains responsible for:

  • determining the purposes of the processing
  • establishing an appropriate legal basis
  • providing its own privacy information where required
  • configuring permissions and access rights
  • deciding which users are affected by an app action
  • ensuring that only authorised users operate the app
  • ensuring that its use of the app complies with applicable data protection, employment and other legal requirements

This Privacy Policy does not replace any privacy information that the customer organisation may be required to provide to its employees, users or other data subjects in relation to its use of the app.

Where required, processing is governed by a data processing agreement in accordance with Article 28 GDPR.

In connection with the provision of the Forge platform, Atlassian predominantly processes personal data on behalf of Forge developers. Depending on the role of Techanics in the relevant processing activity, Atlassian may therefore act as a processor or sub-processor.

Atlassian may act as an independent controller for certain separate purposes determined by Atlassian itself, such as the administration and security of the Forge platform, Atlassian accounts and Atlassian cloud services.

b) Techanics as a controller

Techanics acts as a controller where we independently determine the purposes and means of processing.

This applies in particular to:

  • the provision and organisation of app support
  • the management of technical Marketplace contacts
  • the technical synchronisation of Marketplace contact data
  • app-related support and operational service communication
  • the administration and security of our support processes
  • privacy and legal enquiries addressed to Techanics
  • our own business communication
  • the fulfilment of legal obligations
  • the establishment, exercise or defence of legal claims

Atlassian, Brevo, Microsoft and other service providers may process personal data on our behalf in connection with these activities.

c) Processing in accordance with the GDPR

Where Techanics processes personal data outside the functional Forge app environment, particularly through Jira Service Management, Brevo, Microsoft 365, the technical synchronisation system or internal administration processes, we process such data in accordance with the General Data Protection Regulation, the German Federal Data Protection Act and other applicable data protection law.

We organise these processing activities in accordance with the principles of:

  • lawfulness, fairness and transparency
  • purpose limitation
  • data minimisation
  • accuracy
  • storage limitation
  • integrity and confidentiality
  • accountability

Personal data is used only for specified and legitimate purposes. Processing is restricted to the information required for those purposes.

We delete or anonymise personal data when it is no longer required for the relevant purpose and no statutory retention obligation or other lawful reason for continued storage applies.

We implement appropriate technical and organisational measures based on the nature, scope, context and purposes of the processing and the risks to the rights and freedoms of the affected persons.

Where an external service provider processes personal data on our behalf, we conclude the legally required data processing agreement.


4. Provision of our apps through Atlassian Forge

a) Forge infrastructure

Our cloud apps are developed and operated using the Atlassian Forge platform.

The computing functions required for the apps are executed within infrastructure provided by Atlassian. Persistent app data is stored using Forge-hosted storage or other storage capabilities provided by Atlassian.

Techanics does not operate a separate external application backend or separate external app database for the core app functions described in this Privacy Policy.

The app data required for these core functions is not exported to an external Techanics application server, external analytics provider or advertising platform.

The separate processing of Marketplace and support contact data through the technical synchronisation system, Brevo, Jira Service Management and Microsoft 365 is described in Sections 9 to 12.

b) Atlassian APIs and app permissions

Our apps use Atlassian APIs where this is necessary to provide their documented functions.

Each app processes only the Atlassian product data and metadata required for its documented functions.

The exact categories of Jira, Confluence, organisation, user or group data processed by an app are described in the app-specific overview in Section 7.

The permissions requested by an app are limited to the permissions required to provide its functions.

Further information about the permissions used by a particular app may also be provided in:

  • the relevant Atlassian Marketplace listing
  • the Marketplace Privacy and Security information
  • the app documentation
  • the applicable data processing agreement

5. Required and voluntary information

Certain technical information and configuration details are required to provide particular app functions.

Where required information is not provided:

  • the relevant app function may not be available
  • an API connection may not be established
  • an administrative action may not be completed
  • we may be unable to investigate or resolve a technical problem

a) Organisation API token

Providing an organisation API token is not a statutory requirement.

However, a valid organisation API token is technically required to use the Bulk User Actions functions that rely on the Atlassian Organizations API.

Those particular functions cannot be provided without the required access.

b) Support portal account

The use of our support portal is optional and is not required for the use of our apps.

Where a person voluntarily chooses to submit a support request, an account for our Jira Service Management portal is required.

The following information is required to create and use the support account:

  • an email address suitable for account and support communication
  • the authentication credentials required and managed by Atlassian

The requester may use an email address selected specifically for support purposes, including a suitable functional or role-based address.

An email address may nevertheless constitute personal data where it relates to an identified or identifiable person.

The password or other authentication credentials are processed within Atlassian’s authentication infrastructure. Techanics does not ask requesters to disclose their password in a support ticket and does not receive the password in readable form.

Techanics does not require a private postal address, telephone number or other additional personal identification data merely to provide access to the support portal.

c) Additional support information

All further information submitted in connection with a support request is voluntary.

This may include:

  • a description of the issue
  • the affected app
  • Atlassian Account IDs
  • organisation, site or installation identifiers
  • technical settings
  • timestamps
  • screenshots
  • selected Forge log excerpts
  • other information that the requester considers helpful

Where optional information is not provided, we will process the request on the basis of the information available.

However, a lack of relevant technical information may limit our ability to reproduce, investigate or resolve a particular issue.


6. Sources and general categories of data

a) Sources of data

Depending on the app and the function used, personal data may originate from:

  • the customer’s Jira or Confluence environment
  • Atlassian administration and organisation services
  • Atlassian APIs
  • the Atlassian Marketplace and Marketplace reporting interfaces
  • information entered by authorised customer administrators
  • technical app and platform logs
  • technical synchronisation logs
  • support requests submitted by users or administrators
  • communication with technical contacts, customers or partners

b) General categories of data

Depending on the relevant app and processing activity, the processed data may include:

  • Atlassian Account IDs
  • organisation, site, installation and directory identifiers
  • user status and product access information
  • administrative roles
  • group names and group memberships
  • information required to perform an administrator-selected action
  • app configuration data
  • technical timestamps
  • invocation and trace identifiers
  • technical status and error information
  • technical contact details
  • synchronisation status and processing records
  • support communication
  • voluntarily submitted screenshots or attachments
  • app and licence-related information

The precise categories relevant to each current app are described below.


7. App-specific processing

a) Bulk User Actions

Bulk User Actions allows authorised administrators to perform administrative actions for multiple Atlassian users.

Depending on the selected function, the app may process:

  • Atlassian Account IDs
  • organisation, site and directory identifiers
  • account and activation status
  • product access information
  • administrative roles
  • group names and group memberships
  • users selected for a bulk action
  • information about the action selected by the administrator
  • technical timestamps
  • technical result and status information
  • app configuration information
  • limited technical information required for diagnostics and error analysis

The purposes of the processing are to:

  • display and manage users within the customer’s Atlassian organisation
  • execute bulk actions selected by an authorised administrator
  • assign or remove group memberships
  • suspend, restore or otherwise manage user access where supported by the app
  • verify whether an action was completed successfully
  • investigate technical errors

Bulk User Actions does not process Jira issue content or Confluence page content.

The app does not require users to provide their Atlassian passwords to Techanics.

b) Organisation API token used by Bulk User Actions

Certain functions of Bulk User Actions require access to the Atlassian Organizations API.

For this purpose, an authorised customer administrator may provide an organisation API token.

The token is used exclusively to establish the connection requested by the customer and to perform authorised app functions.

The organisation API token:

  • is stored within the Atlassian Forge infrastructure
  • is additionally encrypted by Techanics at application level using AES-GCM
  • is used exclusively for the functions configured by the customer
  • is not transmitted to Brevo, Microsoft or other external communication providers
  • is not intentionally included in regular application logs
  • is deleted in accordance with the applicable Forge storage lifecycle when it is removed, replaced or the app is uninstalled

The customer is responsible for creating, authorising, restricting, rotating and revoking the token in accordance with its internal security requirements and Atlassian’s applicable specifications.

c) User Magic for Jira

User Magic for Jira processes the user and group information required to perform the functions selected by an authorised user or administrator.

Depending on the function used, this may include:

  • Atlassian Account IDs
  • organisation, site or directory identifiers
  • source and target users
  • group names and group memberships
  • user and configuration information required for the selected action
  • information about the user initiating the action
  • technical timestamps
  • limited technical information required for diagnostics and error analysis

The purpose of the processing is to provide the user and group administration functions of the app, including the transfer or assignment of group memberships where requested by an authorised user.

User Magic for Jira uses only the Atlassian APIs and permissions made available through the Forge environment that are required to provide its documented functions.

User Magic for Jira does not require or store a separate organisation API token or personal API token.

The app does not transfer its functional app data to a separate external application backend operated by Techanics.

User Magic for Jira does not process Jira issue content or Confluence page content.

d) Future apps

Future Techanics apps may process different categories of Atlassian product data or metadata where required for their respective functions.

Before a new app is released, Techanics assesses:

  • which data categories are accessed
  • which Atlassian permissions are required
  • which data is stored
  • which data is processed only temporarily
  • whether personal data may appear in technical logs
  • whether data is transferred to another recipient
  • which retention periods apply
  • which data is in scope for data residency
  • whether this Privacy Policy and the Marketplace Privacy and Security information must be updated

Where a future app, such as a Confluence administration or label-management app, processes additional Confluence metadata, the relevant categories and purposes will be added to this section before the processing begins.


8. Technical logs and error analysis

a) Purpose and origin of Forge logs

Atlassian Forge provides application logs that allow us to:

  • identify technical errors
  • investigate failed app functions
  • diagnose unexpected behaviour
  • maintain the reliability and security of our apps
  • provide technical support

Forge logs may contain:

  • log messages generated by the app for diagnostic purposes
  • information concerning unhandled app or platform errors
  • the date and time of an invocation
  • the app version and environment
  • installation, site, invocation or trace identifiers
  • technical status and error information
  • the function in which an error occurred
  • in limited cases, an Atlassian Account ID where this is necessary to trace a user-specific technical problem

Atlassian Account IDs may be used instead of names or email addresses where an individual technical event must be assigned to an Atlassian account.

For Bulk User Actions and User Magic for Jira, Atlassian Account IDs may therefore form part of technical logs where this is necessary to associate a technical event with the affected account.

The creation and availability of Forge logs form part of the Atlassian Forge platform.

Log processing is separate from the functional purpose of the relevant app and is carried out for diagnostics, security and support.

b) Data-minimised logging

We design our application logging according to the principle of data minimisation.

We do not intentionally write the following information to regular application logs:

  • organisation API tokens
  • API keys
  • passwords
  • authorisation headers
  • Brevo access credentials
  • comparable authentication secrets

We avoid logging complete request headers, complete authentication objects, complete API responses, unnecessary personal data, confidential customer information and technical objects that may contain authentication data.

Because Forge logs may also include information generated in connection with unhandled app or platform errors, we cannot guarantee that Atlassian’s platform will automatically remove every sensitive value from every possible error message.

Where we become aware that authentication data or other unnecessary sensitive information has been included in a log, we restrict access to the information, investigate the cause, take appropriate remedial action and take steps to prevent recurrence.

c) Access to logs

Access to Forge logs is restricted to authorised Techanics personnel who require access for assigned development or support tasks.

Access is additionally subject to the log-sharing and administration controls provided by Atlassian.

Depending on the relevant Atlassian environment, customers may be able to control whether Techanics can access logs associated with their app installation.

Techanics does not export Forge logs to a separate external logging or analytics platform.

d) Retention

Forge app logs are currently available through the Atlassian developer console for up to 30 days.

Techanics does not independently extend this period by copying the logs to an external long-term logging system.


9. Marketplace technical contact data

a) Source of the data

When a customer installs, tests or licenses one of our apps through the Atlassian Marketplace, Atlassian may provide Techanics with information relating to the customer organisation, the app installation, the licence and the designated technical contact.

This information is not necessarily collected directly from the affected contact by Techanics.

The data is obtained from Atlassian Marketplace reports, Marketplace APIs or corresponding Atlassian interfaces and not from publicly accessible sources.

Where Article 14 GDPR applies, we provide the required privacy information within one month after obtaining the data and, where the data is used to communicate with the affected person, no later than the first communication.

b) Data processed

Depending on the information supplied by Atlassian, we may process:

  • the email address of the technical contact
  • first name and last name
  • company or customer organisation
  • country
  • installed Techanics app
  • date of first installation
  • current installation or activation status
  • licence-related status information
  • the name of an Atlassian partner involved in the transaction, where provided

Technical information required to manage and document the synchronisation may also be processed, including:

  • the time of the most recent synchronisation
  • the relevant app assignment
  • the Brevo contact identifier
  • the data categories included in a synchronisation
  • technical processing and synchronisation status
  • delivery status
  • bounce information
  • objection or suppression status

c) Purposes

We use this information to:

  • identify the appropriate technical contact for an active app installation
  • organise app-related support
  • associate support and service information with the correct app and customer organisation
  • communicate in an appropriate language where possible
  • provide app-related support and operational information
  • communicate information about known errors and available fixes
  • provide links to documentation and the support portal
  • identify whether an app installation remains active
  • keep our technical contact records accurate
  • document and troubleshoot the technical synchronisation between Atlassian and Brevo

The country information is used in particular to select an appropriate language for communication where possible.

The date of first installation and current activation status are used to understand whether the contact is associated with a current app installation and to manage the lifecycle of the support contact.

The name of an Atlassian partner is used where necessary to understand and coordinate the support or customer relationship.

d) Legal basis

Where the data subject is personally a contracting party or requests a contractual or pre-contractual service, processing may be based on Article 6(1)(b) GDPR.

In most business-to-business cases, processing is based on Article 6(1)(f) GDPR.

Our legitimate interests lie in providing reliable app support, maintaining accurate technical contact information, communicating relevant operational information concerning active app installations, resolving known technical issues, providing access to documentation and support resources, ensuring the correct technical synchronisation of contact data and protecting the security and reliability of our apps and support processes.


10. App-related support and service communication through Brevo

a) Provider

We use Brevo to manage the technical contacts associated with active installations of our apps and to send app-related support and operational service communication.

The provider is:

Sendinblue SAS, trading as Brevo
9–17 rue Salneuve
75017 Paris
France

Brevo is not used to receive, manage or answer individual support tickets.

Individual support cases and our responses to them are handled through Jira Service Management as described in Section 11.

b) Data processed through Brevo

The following information may be transferred from Atlassian to Brevo through an API-based synchronisation:

  • email address of the technical contact
  • first name and last name, where provided by Atlassian
  • company or customer organisation
  • country
  • relevant Techanics app
  • date of first installation
  • active or inactive installation status
  • name of an Atlassian partner, where provided

Brevo may additionally process technical delivery and contact-management information, including:

  • date and time of transmission
  • delivery status
  • bounce or error information
  • contact identifier
  • app or list assignment
  • objection or suppression status

The following information is not transferred to Brevo as part of the Marketplace contact synchronisation:

  • support ticket descriptions
  • support replies
  • screenshots
  • support attachments
  • Forge log files
  • passwords
  • organisation API tokens
  • other authentication secrets

c) Purpose of the communication

We use the contact data in Brevo exclusively for support and operational service communication relating to the Techanics apps associated with the relevant technical contact.

This communication may include:

  • information concerning the installed app
  • information about updates and new versions where relevant to the operation, compatibility, security or support of the installed app
  • notices concerning bug fixes
  • information about known technical issues
  • information about available workarounds
  • security notices
  • availability or operational notices
  • information required to maintain or configure the app
  • links to relevant app documentation
  • links to help articles
  • links to our Jira Service Management support portal
  • information explaining how support can be obtained

We do not use these contact details for advertising, promotional communication, cross-selling, general company newsletters or the promotion of unrelated products or services.

The communication is limited to the support, maintenance, security and reliable operation of the relevant Techanics app.

d) Legal basis

The data protection legal basis is Article 6(1)(b) GDPR where the data subject is personally a contracting party or the communication relates to a support service requested by that person.

In other cases, processing is based on Article 6(1)(f) GDPR.

Our legitimate interests lie in:

  • maintaining accurate contact information for active app installations
  • providing reliable app support
  • informing technical contacts about relevant operational updates
  • informing technical contacts about known errors and available fixes
  • communicating security-related and operational information
  • preventing avoidable technical problems
  • making relevant documentation and support resources available

Brevo processes personal data on our behalf as a processor in accordance with Article 28 GDPR.

e) Technical synchronisation and encrypted synchronisation log

Brevo cannot access the Atlassian Marketplace interfaces directly. Techanics therefore operates a technical synchronisation process that retrieves the relevant Marketplace contact and installation information from Atlassian and transfers the required data to Brevo.

To enable, monitor and document this synchronisation, Techanics maintains an encrypted technical synchronisation log.

The log may contain:

  • the email address or technical contact identifier
  • the relevant app assignment
  • the categories of data included in the synchronisation
  • the date and time of processing
  • technical synchronisation status
  • technical success or error information

The synchronisation log is used exclusively to:

  • execute and monitor the synchronisation
  • identify failed or incomplete transfers
  • avoid incorrect or duplicate processing
  • verify which data was processed at a particular time
  • investigate and resolve technical synchronisation errors

The log is not used for advertising, profiling, employee monitoring or analysis of app usage.

The synchronisation log is stored in encrypted form. Access is restricted to authorised personnel who require access to maintain or troubleshoot the synchronisation process.

Transmission between the relevant systems takes place through protected and encrypted connections. Where technically applicable, protected information is additionally secured at application level using AES-GCM.

f) No processing of individual support requests through Brevo

Brevo is not our ticketing system.

Individual support requests are not answered through Brevo.

Where individual assistance is required, the recipient is directed to our Jira Service Management support portal.

The support request and the subsequent support communication are then processed through the Atlassian-based support environment described in Section 11.

Recipients should not reply to an app-related Brevo message with passwords, API tokens, confidential customer information, Jira or Confluence content, detailed log data or other authentication information.

g) No advertising or general newsletter subscription

The installation or use of a Techanics app and the designation as a technical contact do not result in a subscription to the general Techanics marketing newsletter.

Technical contact information synchronised to Brevo is used only for the app-related support and operational service purposes described in this section.

We do not send advertising or unrelated promotional communication to technical Marketplace contacts through this process.

h) Removal of inactive contacts

The installation status is regularly synchronised with the information provided by Atlassian.

Where no active installation of a Techanics app remains for a contact, the contact is automatically removed from active app-related contact management in Brevo.

This does not apply where:

  • the contact remains associated with another active Techanics app
  • an ongoing legal or privacy matter still requires the information
  • legal retention obligations apply
  • the data is required for the establishment, exercise or defence of legal claims
  • the person has separately requested or consented to another form of communication

i) Suppression records

Where a person objects to a particular form of communication, we may retain a minimal suppression record.

This may include:

  • the email address
  • the date of the objection
  • the relevant objection or suppression status

The record is used solely to ensure that the objection continues to be respected and that the contact is not unintentionally reactivated through a later automated synchronisation.

The suppression record is not used for advertising, profiling or unrelated support analysis.

According to Brevo, the hosting servers on which it processes and stores its databases are located within the European Union.


11. Optional support through Jira Service Management

a) Voluntary support service

We provide a shared support portal for all Techanics apps using Jira Service Management.

Use of the support portal is voluntary.

A support portal account is not required to:

  • install a Techanics app
  • configure a Techanics app
  • use the regular functions of a Techanics app
  • receive the app functions purchased or activated by the customer

A portal account is required only where a person chooses to:

  • submit an individual support request
  • receive and view responses to that request
  • provide additional information
  • review the current status of the request
  • review the previous communication connected with the request

Jira Service Management portal users do not require a separate Jira, Confluence or Jira Service Management product licence merely to access the help centre and submit requests.

b) Atlassian-based support environment

The support portal, the support account and the support tickets are operated within the Atlassian Cloud and Jira Service Management infrastructure.

Individual support cases are submitted, received, processed, answered and documented within Jira Service Management.

Brevo is not used as the ticketing system for individual support requests.

Microsoft 365 is not used as the regular system for receiving and answering individual app support tickets.

Email notifications relating to a support ticket may be sent through the notification functions provided by Atlassian.

The authoritative support conversation and ticket history remain within Jira Service Management.

c) Account information

To create and use the support account, the requester must provide:

  • an email address suitable for account and support communication
  • a password or other authentication method required and managed by Atlassian

The requester may choose an email address specifically intended for support purposes, including a suitable functional or role-based address.

Techanics does not require the requester to provide a private email address.

The password or other authentication credentials are processed by Atlassian for authentication.

Techanics does not ask the requester to disclose the password in a support request and does not have access to the password in readable form.

Techanics does not require additional personal identification data merely to provide access to the support portal.

d) Voluntary support information

In addition to the account information, the requester may voluntarily provide information required or helpful to investigate the issue.

This may include:

  • the affected Techanics app
  • a description of the issue
  • Atlassian site identifiers
  • installation identifiers
  • organisation identifiers
  • Atlassian Account IDs
  • relevant technical settings
  • timestamps
  • steps required to reproduce the issue
  • screenshots
  • selected Forge log excerpts
  • other attachments

The requester decides which additional information to provide.

e) Purposes

We process support information only to:

  • receive and assign the request
  • understand the reported issue
  • reproduce the reported issue where possible
  • communicate with the requester
  • investigate technical causes
  • resolve technical errors
  • document the support process
  • protect the security and reliability of our apps
  • identify recurring technical problems
  • establish, exercise or defend legal claims where necessary

Support data is not used for advertising, behavioural profiling, employee monitoring by Techanics or unrelated product or marketing analysis.

f) Legal basis

Where support is provided as part of an existing contractual relationship or at the request of the data subject, processing is based on Article 6(1)(b) GDPR.

In other cases, processing is based on Article 6(1)(f) GDPR.

Our legitimate interests lie in providing reliable app support, resolving technical problems, protecting the security and stability of the apps and securely documenting the handling of support requests.

Atlassian processes the portal account and support data on our behalf, subject to the applicable contractual and data protection terms.

g) Data minimisation

Please provide only the information required to investigate the relevant issue.

Screenshots, log files and attachments should be checked before submission.

Personal, confidential or otherwise sensitive information that is unrelated to the support request should be removed or redacted where possible.

The following information should not be submitted in a support ticket unless Techanics expressly provides a specific secure procedure:

  • passwords
  • organisation API tokens
  • personal access tokens
  • API keys
  • authorisation headers
  • comparable authentication secrets

Special categories of personal data within the meaning of Article 9 GDPR are not required for our app support and should not be submitted.

If a requester provides personal data relating to another person, the requester should ensure that the disclosure is authorised and lawful.

h) Access and confidentiality

Access to support requests is restricted to authorised Techanics personnel who require the information to handle the request, investigate the technical problem, maintain the affected app or fulfil legal or security obligations.

Persons with access to support data are subject to appropriate confidentiality obligations.

i) Retention of support requests

Support requests and related communication are stored for as long as necessary to resolve and document the request.

They may be retained beyond the closure of a ticket where this is necessary:

  • for technical follow-up
  • to identify recurring errors
  • to document security-related events
  • to comply with statutory retention obligations
  • for the establishment, exercise or defence of legal claims

Information that is no longer required is deleted or anonymised in accordance with our retention procedures.


12. Microsoft 365 and general business communication

Microsoft 365 is not used as the regular system for receiving, managing or answering individual app support requests.

Official app support is provided through the Jira Service Management portal described in Section 11.

Microsoft 365 may nevertheless process personal data where a person independently contacts Techanics through a general company email address or communicates with us concerning:

  • contracts
  • licences or billing
  • partnerships
  • legal matters
  • privacy enquiries
  • general business enquiries
  • other matters outside the regular app support process

Where a person submits an app support request through a general company email address, we may direct the person to the Jira Service Management support portal and continue the support process there.

The provider is:

Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18
Ireland

Depending on the communication, the processed data may include:

  • name
  • email address
  • company
  • professional role
  • communication content
  • documents and attachments
  • appointment information
  • contract or business-related information

Processing is based on:

  • Article 6(1)(b) GDPR for contractual or pre-contractual communication
  • Article 6(1)(c) GDPR where processing is necessary to comply with a legal obligation
  • Article 6(1)(f) GDPR for secure, efficient and traceable business communication

Microsoft processes the relevant data on our behalf under the applicable contractual and data protection terms.

Microsoft describes an EU Data Boundary for eligible enterprise online services, including Microsoft 365. Limited transfers outside this boundary may nevertheless occur in the circumstances described by Microsoft.


13. Recipients and processors

Personal data is disclosed only where:

  • this is necessary for the relevant purpose
  • a legal obligation exists
  • the data subject has consented
  • another legal basis permits the disclosure

Recipients or processors may include:

  • Atlassian group companies as providers of Forge, Jira, Confluence, Jira Service Management, Marketplace services and associated infrastructure
  • Atlassian sub-processors used to provide the relevant cloud services
  • Brevo for app-related technical contact management and the delivery of app-related support and operational service messages
  • hosting and infrastructure providers used to operate and secure the technical Marketplace-to-Brevo synchronisation process
  • Microsoft for general business communication and collaboration
  • IT service providers involved in the secure administration of our systems
  • legal and tax advisers where necessary
  • courts, supervisory authorities and other public bodies where legally required
  • other recipients expressly authorised by the customer or data subject

Where a service provider processes personal data on our behalf, we conclude the required data processing agreements in accordance with Article 28 GDPR.

Where Techanics acts as a processor for a customer organisation, sub-processors are engaged in accordance with the applicable data processing agreement.


14. Data residency and international transfers

a) European locations where Techanics controls the selection

Where Techanics can select or configure the geographic processing or storage location of a system used for app-related support, administration or technical synchronisation, we give preference to a location within the European Union or another appropriate European region, where such a location is available and suitable for the relevant service.

Where Atlassian provides an appropriate European data residency option for our own Jira Service Management or other Techanics-controlled Atlassian environments, we select a European location where possible.

European data residency does not necessarily mean that every temporary technical operation, support process or infrastructure process is performed exclusively within one particular country.

The provider’s documented data residency scope, infrastructure and exceptions remain relevant.

b) Forge-hosted persistent data

Our Forge apps are designed to support Atlassian’s data residency functionality where technically applicable.

Persistent in-scope app data stored through Forge-hosted storage follows the data residency location selected for the customer’s Atlassian environment where:

  • the customer’s Jira or Confluence environment is pinned to a supported location
  • the app is eligible for pinned status
  • the data is within the scope of Atlassian’s Forge data residency functionality

If an eligible Forge app using persistent Forge-hosted storage is installed on an Atlassian environment that is already pinned to a supported location, the persistent in-scope Forge app data is assigned to that location in accordance with Atlassian’s data residency functionality.

If the customer subsequently migrates the pinned Atlassian product data to another supported location, eligible persistent Forge-hosted data may also be migrated by Atlassian.

The location of a customer’s Jira or Confluence environment is selected and administered by the customer’s authorised Atlassian administrators.

Techanics cannot independently override the data residency location selected for the customer’s Atlassian environment.

Where no particular location is pinned, Atlassian’s global hosting location may apply.

c) Forge invocations and temporary processing

The data residency location of persistent Forge-hosted data must be distinguished from the location in which an individual app invocation is temporarily executed.

Forge aims to execute app invocations from the same location as the host Atlassian product.

However, Atlassian may in some cases execute an invocation from another location in order to support cloud functionality, reliability, performance, security or fraud prevention.

Techanics therefore does not represent that every temporary Forge invocation is guaranteed to execute in the same geographic location in which the customer’s persistent app data is pinned.

Temporary execution in another location does not in itself change the pinned location of the persistent in-scope data stored through Forge-hosted storage.

d) Jira Service Management support environment

Our support portal is operated through Jira Service Management.

Atlassian provides data residency controls for in-scope Jira Service Management data.

Where an appropriate European location is available and supported for the Techanics environment, the support environment is configured to use a European data residency location.

The precise categories of Jira Service Management data covered by Atlassian’s data residency functions are determined by Atlassian.

e) Brevo

According to Brevo, the hosting servers on which it processes and stores its databases are located within the European Union.

f) Microsoft

For eligible Microsoft 365 enterprise online services, Microsoft describes an EU Data Boundary within which customer data and personal data are generally stored and processed for eligible EU and EFTA customers.

Microsoft also describes limited circumstances in which data may continue to be transferred or remotely accessed outside the EU Data Boundary.

g) International transfers

In connection with Atlassian, Microsoft or their sub-processors, limited processing in countries outside the European Union or the European Economic Area cannot be completely excluded.

This may apply, for example, to global cloud service provision, resilience and disaster recovery, security, fraud prevention, service administration, technical support or legally required access.

Where personal data is transferred to a third country, the transfer is based on an applicable legal mechanism, such as:

  • an adequacy decision of the European Commission
  • certification under the EU–U.S. Data Privacy Framework, where applicable
  • the European Commission’s Standard Contractual Clauses
  • supplementary contractual, technical or organisational safeguards
  • another mechanism permitted under Articles 44 to 49 GDPR

Further information about the safeguards applicable to a particular transfer and, where available, a copy of the relevant safeguards may be requested using the contact details provided in Section 2.

Certain information may be redacted where necessary to protect confidential information or the rights of third parties.


15. Retention and deletion

a) General principle

We retain personal data only for as long as it is required for the relevant purpose or for as long as:

  • a statutory retention obligation applies
  • a contractual obligation requires storage
  • a security-related reason requires temporary storage
  • the data is required for the establishment, exercise or defence of legal claims

Where storage is no longer required, the data is deleted or anonymised.

b) App data in Forge-hosted storage

Persistent app data is generally stored for the duration of the relevant app installation.

After an app is uninstalled, Atlassian currently retains data stored in Forge-hosted storage for up to 28 days.

Recovery may be possible during this period under the conditions specified by Atlassian and with the customer’s consent.

A recovery request must currently be submitted within 21 days of uninstallation so that it can be processed before the retention period ends.

After the applicable Atlassian retention period has expired, the data is deleted in accordance with Atlassian’s platform processes.

A licence suspension or temporary deactivation may not automatically result in immediate deletion where the installation or associated Atlassian environment continues to exist.

c) Organisation API tokens

An organisation API token stored for Bulk User Actions is retained only for as long as it is required for the configured connection.

It is deleted or replaced when:

  • the customer removes the token
  • a replacement token is stored
  • the relevant configuration is deleted
  • the app data is deleted in accordance with the Forge data lifecycle

Customers may also revoke the token directly through the applicable Atlassian administration functions.

d) Forge technical logs

Forge application logs are currently available for up to 30 days.

Techanics does not maintain an external long-term archive of these logs.

e) Synchronisation logs

Encrypted synchronisation logs are retained only for as long as required to ensure technical traceability, investigate errors and verify the correct processing of Marketplace contact data.

They are subsequently deleted or anonymised unless continued storage is required in connection with a specific security incident, legal obligation or legal claim.

f) Brevo technical contact data

App-related technical contact data in Brevo is removed from active contact management when the contact is no longer associated with an active Techanics app installation.

This is subject to the exceptions described in Sections 10(h) and 10(i).

g) Support requests

Support requests and related communication are stored for as long as necessary to resolve and document the request.

They may be retained beyond the closure of a ticket where this is necessary:

  • for technical follow-up
  • to identify recurring errors
  • to document security-related events
  • to comply with statutory retention obligations
  • for the establishment, exercise or defence of legal claims

Information that is no longer required is deleted or anonymised in accordance with our retention procedures.

h) Business communication

Business, contract and invoice-related communication may be retained in accordance with applicable commercial, tax and limitation periods.


16. Data subject rights

a) Rights under the GDPR

Subject to the applicable legal requirements, data subjects have the following rights:

  • right of access under Article 15 GDPR
  • right to rectification under Article 16 GDPR
  • right to erasure under Article 17 GDPR
  • right to restriction of processing under Article 18 GDPR
  • right to data portability under Article 20 GDPR
  • right to object under Article 21 GDPR
  • right to withdraw consent under Article 7(3) GDPR
  • right to lodge a complaint with a supervisory authority under Article 77 GDPR

b) Requests concerning customer-controlled app data

Where Techanics processes personal data solely on behalf of a customer organisation, the customer organisation is generally responsible for responding to data subject requests.

In such cases, data subjects should normally contact the organisation that provides or administers their Jira or Confluence account.

Techanics supports its customers in responding to valid requests in accordance with the applicable data processing agreement and legal requirements.

c) Requests concerning processing by Techanics as controller

Where Techanics acts as controller, data subjects may exercise their rights directly by contacting us using the details provided in Section 2.

We may request appropriate information to verify the identity of the requester before disclosing, rectifying or deleting personal data.

d) Withdrawal of consent

Where processing is based on consent, consent may be withdrawn at any time with effect for the future.

The lawfulness of processing carried out before the withdrawal remains unaffected.


17. Right to object under Article 21 GDPR

Where we process personal data on the basis of Article 6(1)(f) GDPR, data subjects may object to the processing at any time on grounds relating to their particular situation.

We will then no longer process the relevant personal data unless:

  • we can demonstrate compelling legitimate grounds for the processing that override the interests, rights and freedoms of the data subject
  • the processing is required for the establishment, exercise or defence of legal claims

Where personal data is processed for direct marketing purposes in another context, the data subject may object to such processing at any time.

The Marketplace contact data described in Section 10 is not used for advertising or direct marketing.

A minimal suppression record may nevertheless be retained in accordance with Section 10(i) to ensure that an objection continues to be respected.


18. Right to lodge a complaint

Data subjects have the right to lodge a complaint with a data protection supervisory authority if they believe that the processing of their personal data infringes applicable data protection law.

For private-sector organisations in Bavaria, the competent supervisory authority is generally:

Bavarian State Office for Data Protection Supervision
Promenade 18
91522 Ansbach
Germany

A complaint may also be submitted to another competent supervisory authority, particularly in the Member State of the data subject’s habitual residence, place of work or the place of the alleged infringement.


19. Security and confidentiality

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

Depending on the processing activity, these measures include:

  • use of the Atlassian Forge security and isolation architecture
  • installation-specific separation of app data
  • encrypted transmission
  • encrypted synchronisation logs
  • access restrictions
  • role and permission concepts
  • restricted access to development, support and communication systems
  • multi-factor authentication where available
  • secure handling of authentication information
  • additional application-level encryption of protected configuration data
  • data-minimised logging
  • retention and deletion procedures
  • regular maintenance and security updates
  • procedures for handling technical and security incidents

Access to personal data, technical logs and support information is limited to authorised personnel who require access for their assigned tasks.

Persons with access to personal data are subject to appropriate confidentiality obligations.

We review and update our measures where necessary, taking into account technological developments, changes to our apps, changes to the services used, the nature of the processed data and the risks associated with the relevant processing.

No method of electronic transmission or storage can guarantee absolute security.


20. No automated decision-making

Techanics does not use personal data processed under this Privacy Policy to make decisions based solely on automated processing, including profiling, that produce legal effects concerning a person or similarly significantly affect that person.

Administrative actions performed through an app are initiated or configured by authorised users or administrators of the customer organisation.


21. Relationship with Atlassian

Atlassian and Techanics are separate providers.

Atlassian is responsible for processing activities for which Atlassian independently determines the purposes and means, including:

  • the provision and administration of Atlassian accounts
  • the Atlassian Marketplace
  • the administration and security of Atlassian cloud services
  • processing carried out by Atlassian for its own legal and operational purposes

Techanics is responsible for the processing activities described in this Privacy Policy where Techanics acts as controller.

Where Techanics acts as processor, the relevant customer organisation remains the controller and Atlassian may act as a sub-processor in relation to the Forge infrastructure.

The customer’s use of Jira, Confluence, Jira Service Management and other Atlassian services is also subject to the contractual and privacy terms agreed between the customer and Atlassian.


22. Changes to this Privacy Policy

We may update this Privacy Policy where:

  • we release a new app
  • an existing app processes additional data
  • an app’s permissions or technical architecture change
  • our support, synchronisation or communication processes change
  • a service provider changes
  • Atlassian changes the relevant Forge or Marketplace functions
  • legal requirements change
  • clarification is required

The current version is the version published by Techanics and linked from the relevant Atlassian Marketplace listings.

Where a change materially affects the processing of personal data, we will provide additional information or notification where this is legally, contractually or under the applicable Atlassian Marketplace terms required.

Version history

VersionDateMain changes
1.0August 2026Initial publication of the joint Privacy Policy for Techanics Apps