Effective starting date: Dec 13, 2019
Data Security and Privacy Statement for Decadis AG Atlassian Marketplace Apps ("xApps")
Protecting your data and your privacy is a high priority and very important to the Decadis AG.
We adhere to strict policies to guarantee the security and privacy of customer data.
The Decadis AG provides a number of Software Products ("xApps", apps) that are made available through the Atlassian Marketplace, either for Atlassian Server or Data Center products (hereafter referred to as server apps) running on clients' IT systems, or hosted service Cloud apps for Atlassian Cloud products.
This Data Security and Privacy Statement will provide you with an overview of the collection and processing of your data for both cloud and server apps.
We maintain technical and organizational measures in order to ensure data security, in particular for the protection of customer personal data.
Cloud and Server apps
None of our server apps collect or store any customer data locally.
Additionally we store data on the server our app services are running on. Currently this includes:
- Access logs that are deleted periodically
Jira Workflow Toolbox Cloud
- Rule configurations and historical changes including a timestamp and a account / user ID
- Execution logs including a timestamp and account / user ID as well as load data, if applicable
- Since we store information of each rule configuration it is specifically prohibited to store personal data (except the account / user ID) as meta information in any rule configuration. It is generally recommended using user IDs instead of display names or full names.
As an active or potential customer, you may register in one or more of our dedicated xApps Service Desks in order to submit support tickets or be registered by submitting a support request per email. At that time we will store your name (if entered), email address and support details in our Service Desk systems running in the Atlassian Cloud. If the support details should include personal data, please anonymize the data beforehand. If you wish for your personal information to be removed from the Decadis xApps Service Desk(s), please contact our support team at email@example.com.
Communication and Marketing
We use your contact information to send certain communications via email, including responses to your comments, questions and requests, providing customer support, and sending you technical notices (Release Notes), updates, security alerts, and administrative messages. We also communicate with you about new product offers or promotions. You can control whether you want to receive these communications by opting-out whenever you receive such a communication from Decadis AG by using the included opt-out link or by writing a short mail to firstname.lastname@example.org.
If you are an individual in the European Economic Area (EEA), we collect and process information about you only where we have legal basis for doing so under applicable EU laws. The legal basis depends on the Services you use and how you use them. This means we collect and use your information only where:
- we need it to provide you with services pertaining to xApps Software Products;
- it satisfies a legitimate interest (which is not overridden by your data protection interests), such as for research and development, to market and promote xApps Software Products and to protect our legal rights and interests;
- you give us consent to do so for a specific purpose; or
- we need to process your data to comply with a legal obligation.
If you have consented to our use of information about you for a specific purpose, you have the right to change your mind at any time, but this will not affect any processing that has already taken place. Where we are using your information because we or a third party (e.g. your employer) have a legitimate interest to do so, you have the right to object to that use, though, in some cases, this may mean no longer using xApps Software Products.
End of subscription
If a customer unsubscribes from one of our Cloud apps, we will delete any personal data after 6 months (or earlier). Please contact email@example.com for immediate deletion if you wish.
Data is held only in Germany.
Access to Customer Data
Only authorized Decadis AG employees and subcontractors have access to customer account data. Subcontractors are contractually bound to the same data security and privacy standards that apply to our employees.