BPMN, UML, Workflow Automation & Portfolio Manager
Last Updated:
This Privacy Policy describes how BPMN, UML, Workflow Automation & Portfolio Manager ("we", "our", or "the App") collects, uses,
and protects your information when you use our application integrated with Atlassian Forge platform.
By using the App, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Information Provided by Atlassian/Jira
As a Forge app running within your Atlassian environment, we access only the data explicitly granted
through Atlassian permissions:
Project data: Project keys, names, leads, and avatar URLs
Issue data: Issue keys, titles, statuses, assignees, and dependency links
Epic/Roadmap data: Epic titles, start/due dates, and status categories
User context: Atlassian user ID and display name (for personalization only)
1.2 Content You Create in the App
Some features let you author content directly inside the App, rather than pulling it from Jira. This content
is saved so you can come back to it, review its history, and collaborate with teammates:
Diagram definitions: BPMN process diagrams and UML diagrams (written in Mermaid syntax) that you create
Version & revision history: version names, timestamps, optional commit messages, and the account ID/display name of whoever saved or reverted each version
Automation rules: any workflow automation rules you configure against a diagram
1.3 Information We Do NOT Collect
✅ We do NOT collect:
Passwords, API tokens, or authentication credentials
Issue descriptions, comments, attachments, or custom field content beyond what's needed for display
Personal email addresses, phone numbers, or physical addresses
Usage analytics, tracking pixels, or third-party cookies
Data from outside your Atlassian organization
1.4 Automatically Collected Technical Data
Minimal technical information is processed temporarily to ensure app functionality:
Browser type and version (for compatibility checks)
Forge runtime environment identifiers (managed by Atlassian)
Error logs (anonymized, retained max 30 days for debugging)
2. How We Use Your Information
We use the collected data solely to provide and improve the App's core functionality:
Display portfolio views: Render projects, dependencies, and roadmap timelines
Enable diagramming: Store and version the BPMN and UML diagrams you create, so you can browse history, compare versions, and revert changes
Enable filtering & search: Allow you to filter by project, lead, or dependency type
Support real-time updates: Refresh stats and diagram changes when Jira issues or diagrams change (via Forge events and Forge Realtime)
Maintain app state: Preserve your selected filters and tab preferences during your session
Ensure security: Validate permissions and prevent unauthorized data access
We do not: sell, rent, trade, or monetize your data in any way.
3. Data Storage & Security
3.1 Where Data Is Processed
Client-side rendering: Portfolio views, dependency graphs, and diagram previews render directly in your browser.
Diagram & version persistence: BPMN/UML diagrams, their version history, and automation rules you save are stored using Atlassian Forge's built-in Storage API, within Atlassian's infrastructure — not on servers we operate.
Atlassian Forge: Temporary caching may also occur within Atlassian's secure infrastructure per their Privacy Policy.
No external databases: We do not operate independent databases or servers of our own; all persisted app content lives within Atlassian's Forge platform.
3.2 Security Measures
✅ All communication uses HTTPS/TLS encryption
✅ Forge sandbox isolation prevents cross-tenant data access
✅ Principle of least privilege: App requests only required Atlassian scopes
✅ Regular security reviews and dependency updates
✅ No logging of sensitive issue content or user identifiers
4. Data Sharing & Third Parties
We do not share your Jira data with any third parties.
The only external service involved is the Atlassian Forge platform, which hosts and runs the app.
Atlassian's data handling practices are governed by their own privacy policy and enterprise agreements.
We do not integrate with analytics services (Google Analytics, Mixpanel, etc.), advertising networks,
or data brokers.
5. Your Rights & Choices
5.1 Access & Control
View your data: All data displayed in the App comes directly from your Jira instance, or from diagrams you authored in the App. You control what projects/issues are visible via Jira permissions.
Delete your content: Diagrams and their version history can be deleted from within the App by anyone with edit permission on the associated project.
Revoke access: Remove the App anytime via Atlassian Admin → Apps → Manage apps. All cached session data is immediately cleared.
Data portability: Export portfolio views using your browser's print/save functionality or Jira's native export tools.
5.2 Regional Rights (GDPR/CCPA)
If you are in the European Economic Area, California, or other regions with data protection laws, you may have
additional rights including:
Right to access, correct, or delete personal data
Right to restrict or object to processing
Right to data portability
GDPR Classifications: For the personal data and issue content managed within your Atlassian site, the Customer acts as the Data Controller. Because the App runs exclusively via the Atlassian Forge serverless framework and renders directly within the user's web browser, BPMN, UML, Workflow Automation & Portfolio Manager does not transmit, store, or access your data on independent infrastructure. Therefore, BPMN, UML, Workflow Automation & Portfolio Manager does not act as a Data Processor or Data Controller under the GDPR for your Jira content, and a Data Processing Agreement (DPA) is not required.
CCPA Classifications: BPMN, UML, Workflow Automation & Portfolio Manager does not meet the thresholds of a Business, nor does it act as a Service Provider under the CCPA, as we do not collect, retain, use, or disclose consumers' personal information outside of your local Atlassian environment.
Data Subject Rights: If you wish to exercise your rights under the GDPR or CCPA (such as the right to access, delete, or restrict processing), please direct your request to your Atlassian organization administrator, who controls the primary data environment.
For App-specific inquiries, contact us below.
6. Children's Privacy
The App is not directed to individuals under 16. We do not knowingly collect information from children.
If you believe a minor has provided data through your Jira instance, please contact your Atlassian administrator.
7. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements.
Updates will be posted here with a revised "Last Updated" date. Material changes will be communicated via:
In-app notification banner
Atlassian Marketplace listing update
Email to registered app administrators (if contact info is provided)
Continued use of the App after changes constitutes acceptance of the updated policy.
8. Contact Us
For questions about this Privacy Policy or the App's data practices: