Data Processing Summary
This page provides a concise vendor-assessment view of processing performed by Customer Portal Toolkit for JSM. It should be read with the Privacy Policy and any separately signed data processing agreement.
| Provider | Piotr Mederak, ul. Magnolii 1K/2, 05-500 Nowa Wola, Poland, trading as Mederak Apps. |
|---|---|
| Customer role | Normally controller/business for Jira/JSM content and App configuration. |
| Provider role | Normally processor/service provider for customer data used to deliver the App; independent controller for support, security, legal/vendor administration and consent-based website analytics. |
| Processing location | Atlassian Jira Cloud and Forge-hosted services, subject to the customer's Atlassian data residency configuration and Atlassian's current service coverage. |
| Remote infrastructure | None for the App runtime. No Forge Remote, vendor-hosted App database or End-User Data egress. |
| Duration | For the subscription/installation and the record-specific periods in the Privacy Policy; Forge hosted storage is currently retained by Atlassian for 28 days after uninstall. |
Subject matter and purposes
Processing is limited to providing configurable customer portal content; privacy-treated service context; permission-checked customer actions; configuration drafting, preview, approval and publication; operational security and replay prevention; bounded jobs and caching; optional installation-local analytics; optional Forge LLM output; and support or security investigation.
Categories of data subjects
- Jira/JSM administrators, project administrators, agents and other licensed users.
- JSM portal customers, request participants and organization members.
- Individuals referenced in customer-authorized Jira/JSM request content.
- Support and security reporters and public website visitors.
Categories of data
- Atlassian account identifiers and display/context data needed for permissions, publication, actions and approved-participant policy.
- Jira project, request type, request, workflow, field, SLA, service, Assets, participant and organization data permitted for the current feature and actor.
- Public comments/history and attachment metadata where a supported widget/action needs them. Private comments and attachment contents are not used for customer aggregate or AI paths.
- App configuration, localized copy, links/tokens, drafts, versions, approvals, settings and capability metadata.
- Privacy-treated aggregate results, historical metric snapshots and freshness/sample/confidence metadata.
- Content-free audit, analytics, idempotency, rate, budget, cache, lease, migration and job metadata.
- Optional minimized Forge LLM input and validated output.
- Support contact details, ticket content and safe technical diagnostics supplied by the reporter.
Processing operations
The App may read, validate, transform, aggregate, generalize, suppress, cache, store, retrieve, display, publish and delete or expire records. Customer-selected allowlisted actions may create a public comment, add a bounded attachment, edit an allowlisted field, manage an approved participant or execute an available workflow transition after current permission checks.
Instructions and confidentiality
Customer instructions are expressed through the authorized installation, published configuration, enabled features, Jira/JSM permissions and documented support requests. Mederak Apps will process customer data only to provide, secure and support the App, comply with law or follow documented customer instructions. Persons authorized to access support or security information are subject to confidentiality obligations.
Subprocessors and transfers
Atlassian supplies the App runtime and storage. Public website and support services are listed separately on Subprocessors. International processing follows those providers' applicable locations and safeguards. The App does not independently transfer customer Jira data to a vendor remote or external analytics provider.
Security measures
- Forge-hosted installation-scoped storage and platform authentication.
- Trusted context and backend re-authorization for sensitive operations.
- Schema validation, allowlisted configuration and bounded inputs/queries/jobs.
- Privacy minimums, suppression/generalization and no raw cross-request rows in customer aggregates.
- Current-user permission checks, confirmation, rate limits and idempotency for actions.
- Content-free logs/audits, dependency/security validation and environment-specific Forge eligibility checks.
Assistance, deletion and incidents
Mederak Apps will provide reasonable assistance for privacy requests, security investigations and documented deletion questions, taking into account the nature of Forge processing and information available to us. The customer remains responsible for Jira-native records and for verifying requester authority. Use Mederak Apps Service Desk; do not submit secrets or unnecessary customer data.
Details: Uninstall and Data Deletion · Security Incident Response · Data Residency.