Skip to main content

Privacy Policy

Last updated: 2026-05-31

This Privacy Policy describes how Attestsys processes personal data in compliance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR").


1. Who we are (controller identity)

Data controller: Ilgiz Khusnullin, trading as Attestsys Berblingerstr. 3 89073 Ulm, Germany Contact: legal@attestsys.com

The Tamper-Evident Audit Log for Jira app is operated by Attestsys and published on the Atlassian Marketplace. Additional Attestsys apps (GitHub Evidence Pack for Jira; Signed Approvals for Jira) are in development and will be covered by this policy once published.


2. Scope of this policy

This policy applies to personal data processed by Attestsys apps when installed in your Atlassian Jira workspace. It covers:

  • Data processed through the Atlassian Forge platform by the Attestsys Forge app
  • Data transmitted to and stored on the Attestsys backend infrastructure
  • Data collected through the attestsys.com website

This policy does not cover personal data processed by Atlassian directly (Atlassian's own Privacy Policy applies) or personal data your organisation processes within Jira independently of the Attestsys apps.


3. Roles: controller and processor

For data processed by Attestsys apps within your Jira workspace:

  • You (the Jira workspace administrator / your organisation) are the data controller — you determine the purposes and means of processing.
  • Attestsys (as the Attestsys operator) is the data processor — we process personal data only on your behalf and according to your instructions.

Our Data Processing Agreement (DPA) governs this processor relationship. By installing and using the Attestsys apps, you agree to the terms of the DPA.

For personal data collected through the attestsys.com website (enquiries, contact form submissions, if any), Attestsys acts as the data controller.


4. What data we process and why

4.1 Data processed via the Attestsys Jira apps

Data categoryExamplesLegal basis (Art. 6 GDPR)Retention
Jira event dataEvent type, issue key, changed field names and values, timestampArt. 6(1)(b) — performance of contract with the data controller (you)Per edition: Free 30 days, Standard 1 year, Advanced unlimited, Enterprise custom
Atlassian user identifiersAtlassian accountId (an opaque identifier assigned by Atlassian)Art. 6(1)(b) — performance of contractSame as above
Jira workspace identifiercloudId (Atlassian workspace UUID)Art. 6(1)(b) — performance of contractDuration of the customer relationship
Cryptographic audit chainHash-chained records (SHA-256), individually signed with ECDSA P-256 (RFC 6979 deterministic)Art. 6(1)(b) — performance of contractSame retention as event data
HMAC ingestion credentialsEncrypted key material used to authenticate event ingestionArt. 6(1)(b) — performance of contractDuration of the customer relationship

Note on accountId: Atlassian accountId values are opaque identifiers — they are not names, email addresses, or other directly identifying data. However, they are linked to a specific Atlassian account and therefore constitute personal data under GDPR.

What we do NOT collect through the apps:

  • Jira issue descriptions, comment text, or attachment content beyond what the Jira event webhook payload contains
  • Jira user names or email addresses (we use accountId only)
  • Any data unrelated to the events captured by the Attestsys apps

4.2 Data collected through attestsys.com

Data categoryExamplesLegal basis (Art. 6 GDPR)Retention
Enquiry and contact dataName, email address, message content submitted via contact formsArt. 6(1)(b) — pre-contractual steps or Art. 6(1)(f) — legitimate interests2 years after last contact, unless a contract is entered

The attestsys.com website does not deploy analytics tooling, tracking pixels, or third-party cookies. Functional cookies set by our edge provider (Cloudflare __cf_bm for bot mitigation) are strictly necessary for the service to operate.


5. How we protect your data

Infrastructure and data residency

All Attestsys app data is processed and stored exclusively on Hetzner Cloud infrastructure in Nuremberg, Germany (EU). No customer data is transferred to or stored in the United States or any other non-EU jurisdiction.

  • Provider: Hetzner Online GmbH, Nuremberg, Germany
  • Certification: BSI C5 Type 2, ISO 27001:2022
  • CLOUD Act exposure: None — Hetzner is a German company with no US parent entity

Encryption

  • In transit: TLS 1.2 or higher on all connections. HSTS enabled on the backend API.
  • At rest: AES-256-GCM application-level encryption of all stored data on Hetzner Cloud infrastructure in Nuremberg, Germany.

Cryptographic audit chain

Attestsys apps create a tamper-evident, hash-chained audit record of Jira events. Each record is individually signed with ECDSA P-256 (RFC 6979 deterministic) and independently verifiable. This is a security property of the product — not just a feature.


6. Sub-processors

We use the following sub-processors to provide the Attestsys service:

Sub-processorRoleLocation
Hetzner Online GmbHCloud infrastructure (compute, storage, networking) for the Attestsys backendNuremberg, Germany (EU)
Cloudflare, Inc.DNS resolution; TLS edge termination at EU POPs; Cloudflare Tunnel for secure backend exposureEU POPs (primarily Germany, Netherlands, Belgium)
Atlassian Pty LtdForge platform hosting for app frontend modules; AVI event dispatch from Jira to backendCustomer-region-pinned by Atlassian

We will notify you of any changes to sub-processors as required by our Data Processing Agreement.


7. Data subject rights

Because Attestsys acts as a data processor for data processed through the Jira apps, requests to exercise data subject rights under GDPR Arts. 15–21 should in the first instance be directed to your Jira workspace administrator (the data controller), who is responsible for responding to data subject requests.

Where we can assist as a processor, we will do so within the timeframes required by GDPR.

Rights you may exercise (through your data controller):

  • Art. 15 — Access: right to obtain confirmation of whether personal data concerning you is processed and, if so, access to it.
  • Art. 16 — Rectification: right to have inaccurate personal data corrected.
  • Art. 17 — Erasure ("right to be forgotten"): right to request deletion of personal data. Note: audit chain entries are never deleted in response to data subject requests — deletion would break the cryptographic chain integrity. Instead, a signed redaction marker is appended to the chain, and the tenant's signing key is tombstoned if full erasure is required. This approach preserves cryptographic chain continuity while enabling GDPR compliance. This limitation is inherent to the tamper-evident nature of the product and is disclosed here and in the Data Processing Agreement.
  • Art. 18 — Restriction: right to request restriction of processing in certain circumstances.
  • Art. 20 — Portability: right to receive personal data in a structured, commonly used, machine-readable format. Evidence bundle exports (ZIP) are available for this purpose.
  • Art. 21 — Objection: right to object to processing based on legitimate interests.

To exercise rights in relation to attestsys.com website data (where we are the controller), contact us directly at legal@attestsys.com.

Atlassian Personal Data Reporting API

Attestsys apps store Atlassian accountId values as part of the audit chain. As required by Atlassian's Marketplace user privacy developer guidelines, we acknowledge and implement the Atlassian Personal Data Reporting API. Personal data linked to a specific Atlassian accountId can be identified and reported on request within a cycle of at most 7 days. To submit a request, contact legal@attestsys.com.


8. International transfers

No personal data processed by Attestsys apps is transferred outside the European Economic Area (EEA). All data remains on Hetzner Cloud infrastructure in Germany (EU).

For attestsys.com website operations, if any service provider outside the EEA is used (for example, email delivery), appropriate transfer mechanisms (Standard Contractual Clauses or equivalent) are in place.


9. Cookies and tracking

The attestsys.com website does not deploy cookies for tracking, analytics, or advertising. Functional cookies set by our edge provider (Cloudflare __cf_bm for bot mitigation) are strictly necessary for the service to operate and require no consent under the ePrivacy Directive.

The Attestsys Jira apps (running within the Atlassian Forge platform) do not set cookies in your browser independently — cookie handling within the Jira interface is governed by Atlassian.


10. Supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. As the data controller is established in Ulm, Baden-Württemberg, the competent authority is:

Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW) Königstraße 10a, 70173 Stuttgart, Germany www.baden-wuerttemberg.datenschutz.de

You may also contact the supervisory authority in your EU member state of habitual residence or place of work.


11. Data Processing Agreement

If you process personal data through the Attestsys apps and are subject to GDPR, you may require a Data Processing Agreement (DPA) with us as your processor (Art. 28 GDPR).

A standard DPA is available at /dpa. To request a signed copy or discuss customised DPA terms for Enterprise contracts, contact legal@attestsys.com.


12. Changes to this policy

We will update this policy when our data practices change materially. We will notify Marketplace customers of material changes via the Atlassian Marketplace listing update mechanism and post the updated policy at this URL. The "Last updated" date at the top of this page reflects the date of the most recent revision.


13. Contact

For privacy-related questions, to exercise data subject rights (where we are the controller), or to report a concern:

Email: legal@attestsys.com Postal: Ilgiz Khusnullin, Berblingerstr. 3, 89073 Ulm, Germany