Privacy Policy
Last updated: 2026-10-05
This document is a draft and not yet in effect. Values in [brackets] are still to be filled in.
1. Who we are
IssueMesh is operated by [Company name], [Registered address], [Company ID and register entry] ("we"). Contact for privacy matters: [privacy e-mail].
2. Two roles
Data from your Jira. When your organization uses IssueMesh, we process the content of your Jira on your organization's behalf, to synchronize it with the partner your organization chose. For this data your organization is the controller and we are the processor; the Data Processing Agreement between your organization and us applies (available on request).
Data we collect ourselves. For inquiries sent through our contact form (installation, support, questions) and our answers, for the accounts of our own operators and for technical logs of this website and the IssueMesh Hub, we are the controller.
3. Data from your Jira
Only spaces a Jira admin enabled and only the fields a space admin shares are processed. The IssueMesh Hub keeps:
- the site address, the organization name and the list of enabled spaces;
- the app's access token, encrypted;
- the settings of each pairing in every saved version, with the Atlassian account ID of the person who saved it, and people mappings (account IDs);
- for each synchronized pair of issues: their IDs and keys and the last synchronized values of the shared fields - these can contain personal data, for example names in a summary or the account ID in an assignee field;
- a log of synchronization operations including the values written, and an audit trail with the account IDs of the people who changed settings or asked for a resync;
- for issues awaiting a decision about existing issues: key, shared summary and type;
- IDs and fingerprints of copied comments, names and sizes of copied files - not comment texts and not files;
- a journal of change notifications with IDs and times only, deleted after 30 days.
The app cannot see users' e-mail addresses, and they are never processed. Details: Security and data handling.
4. Data we collect ourselves
- Inquiries: what you enter in the contact form - your name, work e-mail, company, optionally your Jira site and your partner, and your message - and our e-mail answers, to answer you, to provide installation links and to support you. The inquiry is stored without your IP address. The form is protected against spam by Cloudflare Turnstile, which checks your browser when you open the contact page; Cloudflare processes technical data of your browser and connection for this check. Legal basis: steps prior to and performance of a contract, and our legitimate interest in answering inquiries.
- Our operators: name and e-mail of the people who run the Hub, from their sign-in with Google.
- Technical logs: IP address, time and request of visits to this website and calls to the Hub, for security and operation (legitimate interest).
This website sets no cookies and uses no tracking. Cloudflare Turnstile runs only on the contact page.
5. Retention
[Retention periods for synchronized values, the operation log, the audit trail, inquiries and e-mails - to be decided.] An inquiry is deleted earlier when you ask for it. The access token of a site is deleted when the app is uninstalled. On your organization's request we delete the data of its site.
6. Recipients and transfers
Data is written only into the Jira of the partner your organization paired with, and only what your space shares. We use the subprocessors listed here. The IssueMesh Hub and its database are hosted in the EU. [Transfers outside the EU/EEA by Cloudflare and Atlassian, and their safeguards - to be confirmed.]
7. Your rights
You have the right to access, rectification, erasure, restriction, data portability and to object, and the right to lodge a complaint with a supervisory authority. For data from your organization's Jira, please contact your organization first - it decides about that data, and we support it. For other data, write to [privacy e-mail].
8. Security
Encrypted transport (HTTPS), encrypted storage of access tokens with a key per token, verification of every call signed by Atlassian, permission checks with the acting person's identity, and read-only access of our operators. See Security and data handling.
9. Changes
We publish changes of this policy on this page with a new date, material changes in advance.