Privacy Policy
In short: ArtUp Trace runs entirely on Atlassian's infrastructure. Its data is stored by Atlassian in your Jira site's data residency region, ArtUp Labs operates no servers that receive it, and the app sends nothing to third parties. This website uses no cookies and no analytics.
1. Who we are
ArtUp Labs is the trade name of Artyom Karpets, an individual entrepreneur (sole proprietor) registered in the Republic of Kazakhstan ("ArtUp Labs", "we", "us").
- Registered address: Protozanov Street 119, apt. 33, Ust-Kamenogorsk (Oskemen), East Kazakhstan Region, Republic of Kazakhstan
- IIN: 911223350864
- Email: hello@artuplabs.com
2. Scope
This policy covers:
- ArtUp Trace for Jira Cloud (the "App"), an Atlassian Forge app for requirements traceability, distributed through the Atlassian Marketplace; and
- the website at artuplabs.com (the "Website").
Your use of Jira Cloud itself is governed by Atlassian's own privacy policy and terms. This policy does not cover Atlassian's processing.
3. Controller and processor roles
For data the App processes within your Jira site, the customer (the organisation that installed the App) is the data controller, and ArtUp Labs acts as a processor on the customer's behalf. The App processes this data only to provide its features, on Atlassian's infrastructure.
For email correspondence you send us (for example, a support request), ArtUp Labs is the controller of that correspondence.
4. What data ArtUp Trace processes
4.1 Data the App reads from Jira
The App reads Jira data as the current user, so it can only see what that user is already permitted to see. It reads issues, issue links, statuses and basic user information needed to display them. The App never writes to Jira issues.
The App requests only these Atlassian scopes:
read:jira-work— read issues, issue links and project data;read:jira-user— read basic user information needed to show who confirmed a link;storage:app— store the App's own data in Forge storage.
4.2 Data the App stores
The App stores the following in Forge SQL and Forge storage:
| Category | Contents |
|---|---|
| Project settings | Which issue types and link types count as requirements and verification. |
| Requirement records | Issue id, issue key, summary, status, and a fingerprint hash of the summary and description (used to detect changes). |
| Link records | Link type, the other issue's key and status, confirmation timestamp, and the Atlassian account id of the user who confirmed the link. |
| Baselines | Frozen snapshots of the requirement and link records above. |
| Sync job metadata | Technical information about background synchronisation jobs (for example, progress and timing). |
The App does not store names or email addresses. It stores Atlassian account ids only to record who confirmed a link. It does not store passwords, access tokens or payment data. The full description text of issues is not stored; only a hash of it is.
4.3 CSV export
When a user exports to CSV, the file is generated and downloaded directly to that user's device. ArtUp Labs does not receive a copy.
4.4 Logs
The Atlassian Forge platform keeps logs of errors raised by the App. By design, the App does not log issue content; logs contain error messages only. ArtUp Labs can view these logs in the Atlassian developer console to diagnose problems.
5. Why we process it
Data is processed only to provide the App's features: showing coverage of requirements, detecting suspect links, creating and comparing baselines, producing exports, and diagnosing errors. We do not use App data for advertising, profiling, selling, or training machine-learning models.
Where the GDPR applies, the customer as controller determines the legal basis for processing its Jira data. Our processing of App data is on the customer's instructions, as expressed by installing and using the App. Our processing of support correspondence is based on our legitimate interest in answering your request.
6. Where the data is stored
ArtUp Trace is an Atlassian Forge app with the "Runs on Atlassian" designation. It has no external servers and makes no outbound network calls (no egress). All stored data remains in Forge SQL and Forge storage on Atlassian's infrastructure, in the customer's data residency region as handled by Atlassian. ArtUp Labs does not copy App data to its own systems.
7. Retention and deletion
- App data is kept while the App is installed, so that coverage, confirmations and baselines remain available.
- Atlassian deletes app data stored in Forge after the app is uninstalled, according to Atlassian's data retention policy. See Atlassian's Forge storage documentation for reference.
- Forge platform logs are retained by Atlassian according to Atlassian's policies.
- Support emails are kept for as long as needed to handle the request and any follow-up, and deleted on request unless we must keep them by law. Support emails are deleted no later than 24 months after the last message in the conversation.
8. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Atlassian | Hosting and running the App (Forge), storage (Forge SQL and Forge storage), platform logs, Marketplace licensing and billing | Customer's data residency region as handled by Atlassian |
We use no other sub-processors for App data. We will update this list before adding one.
9. This website
The Website is a set of static pages. It sets no cookies, uses no analytics, and loads no third-party scripts, fonts or trackers. Pages are served through Cloudflare, which as our hosting and DNS provider may process technical request data (such as IP addresses) to deliver and protect the site.
10. When you email us
If you email hello@artuplabs.com or security@artuplabs.com, we receive your email address, name (if included) and whatever you choose to send, such as screenshots. Please do not send more Jira content than needed. We use this only to answer you. Email is handled by our email provider, Zoho Mail (Zoho Corporation).
11. Payments
Purchases, licensing and payments are handled by Atlassian through the Atlassian Marketplace. ArtUp Labs does not receive or store payment card data. Atlassian may share with us licence and billing contact information for the purposes described in Atlassian's Marketplace terms.
12. Security
See our Security page for the App's architecture, access scopes, and how we handle vulnerabilities and incidents.
13. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability, and to complain to a data protection authority.
- App data: because the customer is the controller, please direct requests to your organisation's Jira administrator first. We will help the customer respond. Administrators can remove all App data by uninstalling the App.
- Correspondence with us: email hello@artuplabs.com. We will respond within one month.
14. Children
The App and Website are business tools and are not directed at children.
15. Changes to this policy
We may update this policy, for example when the App gains new features or we add a sub-processor. We will change the "Last updated" date above and, for material changes, notify customers through the Marketplace listing or by email to the technical contact before the change takes effect.
16. Contact
ArtUp Labs (Artyom Karpets, individual entrepreneur), Protozanov Street 119, apt. 33, Ust-Kamenogorsk (Oskemen), East Kazakhstan Region, Republic of Kazakhstan
Email: hello@artuplabs.com