ValueIT Marketplace App

TraceFlow for Jira – Data Security and Privacy Statement

How TraceFlow handles Jira data, permissions, exports and security responsibilities.

Jira CloudData securityPrivacy statement

Purpose of the App

This Data Security and Privacy Statement explains how TraceFlow for Jira handles data when used within Atlassian Jira Cloud.

TraceFlow for Jira is developed and provided by ValueIT.

TraceFlow helps users explore, filter and export Jira issue change history from the project view. The app is designed to support audit, traceability and project reporting by providing structured access to Jira issue history and Excel export capabilities.

Data Accessed by the App

TraceFlow may access Jira data required to provide its functionality, including:

  • Jira issue key
  • Issue summary
  • Issue description, when available
  • Issue status
  • Issue assignee
  • Issue reporter
  • Issue type
  • Issue creation date
  • Issue update date
  • Jira issue changelog
  • Change date
  • Change author
  • Changed field
  • Previous field value
  • New field value
  • Project information

The app accesses this data only to display issue audit information, apply filters and generate user-requested exports.

Personal Data

TraceFlow may display Jira user-related information when it is part of Jira issue data or changelog data, such as display name, assignee, reporter, change author and Atlassian account identifier where provided by Jira APIs.

TraceFlow does not intentionally collect or store personal data outside what is required to provide the app functionality.

Data Storage

TraceFlow is designed not to persistently store customer Jira issue data outside Atlassian services.

The app reads Jira issue and changelog data to display results and generate exports based on user action.

If temporary processing is required during a user session, it is limited to the purpose of displaying audit information or preparing an export.

Excel Exports

TraceFlow allows users to generate Excel reports from Jira issue history. Exports may contain Jira data accessible to the user, including issue details and changelog events.

Users are responsible for storing, sharing and protecting exported Excel files according to their organization’s internal policies.

TraceFlow does not grant access to issues beyond the permissions of the current Jira user.

Permission Model

TraceFlow respects Jira permissions. The app uses Jira APIs and relies on the permissions granted to the current user and the app installation.

The app does not intentionally bypass Jira project permissions, issue security schemes, user access restrictions or Atlassian access controls.

Data Transmission

TraceFlow communicates with Atlassian Jira Cloud APIs to retrieve issue and changelog data. Data is processed for the purpose of displaying audit information and generating exports.

TraceFlow does not intentionally sell customer data or share customer data with advertisers.

Data Retention

TraceFlow does not intentionally retain Jira issue history data after it is no longer required to provide the requested functionality.

Generated Excel files are produced based on user action and are handled by the user’s browser or device. Customers should manage downloaded exports according to their own data retention policies.

Logging

TraceFlow is designed to avoid logging sensitive Jira issue content, authentication tokens or confidential customer data. Technical logs may be used to monitor app behavior, troubleshoot errors and improve reliability.

Security Practices

  • Limiting requested permissions to those required by the app
  • Respecting Jira user permissions
  • Avoiding unnecessary customer data storage
  • Avoiding logging sensitive data
  • Reviewing app behavior before Marketplace publication
  • Maintaining support channels for issue reporting

Third-Party Services

TraceFlow is designed to work within the Atlassian Forge and Jira Cloud ecosystem. If future versions introduce additional third-party services, this statement will be updated accordingly.

Customer Responsibilities

Customers are responsible for managing Jira permissions and issue security settings, controlling app access, protecting exported Excel files, reviewing exports before sharing them externally and applying internal data governance rules.

Data Deletion

Because TraceFlow does not intentionally persist Jira issue history data outside the operational use of the app, there is generally no persistent app-specific issue data to delete.

If you believe specific data has been stored or processed incorrectly, please contact ValueIT Support.

Support and Contact

For privacy, security or support questions related to TraceFlow for Jira, please contact:

Security Contact
security@valueit.ma

Updates to This Statement

ValueIT may update this Data Security and Privacy Statement from time to time to reflect product, legal or operational changes. The latest version will be available on this page.

Vendor Information

TraceFlow for Jira is provided by:

ValueIT
Website: https://www.valueit.ma
Support: contact@valueit.ma