Overview

This policy describes how Offboarding Transfer Utility (the App) processes information when it is installed on a Jira Cloud site. The App provider is Abenezer Anglo, the Marketplace partner identified on the App’s Atlassian Marketplace listing.

Forge hosted

Jira data and App storage remain on Atlassian infrastructure.

Limited retention

Transfer audit records expire automatically after 180 days.

No external tracking

No external remotes, analytics, advertising, or tracking.

Administrator control

Jira administrators can delete all retained audit history.

Data the App processes

The App processes only the information needed to discover supported Jira assets, perform an administrator-requested transfer, report the outcome, and maintain the transfer audit.

  • Atlassian account IDs and display names for the initiating administrator, departing user, and successor.
  • Jira asset identifiers and names for filters, dashboards, projects, components, and issues.
  • Transfer timestamps, category counts, outcomes, and bounded Jira error messages.

Scanned asset details are transient. They are held in the administrator’s current App page session and sent to Forge resolvers for the requested transfer. The App does not write a separate asset inventory to storage.

Data stored by the App

The App writes one audit record for each completed transfer run to Atlassian Forge Key-Value Store (KVS). Each record contains:

  • Account IDs and display names for the initiating administrator, departing user, and successor.
  • The time of the transfer.
  • Attempted, successful, and failed counts for each supported asset category.
  • Up to 25 bounded error messages per category.

The App does not store passwords, API tokens, customer credentials, or other secrets.

Purpose and legal basis

The App processes this data only to perform Jira asset transfers requested by a Jira administrator, report partial or failed changes, provide an operational audit trail, and meet Atlassian user-privacy lifecycle requirements.

The customer that installs the App determines the applicable legal basis for using it within its organization and remains responsible for its Jira users, content, retention obligations, and offboarding decisions.

Hosting, location, and sharing

The App runs entirely on Atlassian Forge. It reads from and writes to the customer’s Jira Cloud site, and it stores audit records in Forge KVS.

  • No external remotes or network egress are configured.
  • The App provider does not use independent third-party analytics or engage subprocessors outside Atlassian’s Jira Cloud and Forge platform.
  • The App does not sell personal data or serve advertising.
  • No customer credentials or secrets are collected or retained.

Atlassian processes data as the Jira Cloud and Forge platform provider under Atlassian’s applicable terms and data-processing commitments.

Retention, deletion, and account lifecycle

180-day retention: every new audit record is saved with a 180-day time to live and expires automatically.

A Jira administrator can immediately delete all retained audit records for the site from the App’s Transfer history section. This deletion cannot be undone through the App.

A weekly Forge function reports the Atlassian accounts referenced by current audit records to Atlassian’s Privacy API. When Atlassian reports an account as closed, the App removes the stored account ID and replaces the display name with “Deleted user.” When Atlassian reports profile data as changed, the App refreshes the retained display name without extending the record’s original retention period.

Security and access controls

The App uses the following controls:

  • Atlassian authentication and tenant-isolated Forge storage.
  • A native Jira administration page built with Forge UI Kit.
  • An independent check for Jira’s global ADMINISTER permission on every user-invoked resolver.
  • Jira product requests made as the invoking user, so Jira applies that administrator’s own permissions to reads and writes.
  • Strict resolver input validation, bounded scans and transfer batches, controlled write concurrency, and explicit response checks.
  • No personal data written to application logs.

Access, correction, and privacy requests

Jira administrators can view retained transfer history, delete all retained history, and use Jira’s own administration controls for current user and asset data.

A user may submit an access, correction, or deletion request by emailing nordappshq@proton.me. The customer’s Jira administrator may need to verify the requester’s identity, authority, and site before information is disclosed or changed.

Changes to this policy

Material changes will be published at this URL with a revised effective date. The current effective date appears at the top of this page.

Privacy contact

Questions or requests?

Email the App support contact at nordappshq@proton.me. Include the Jira site URL and a clear description of the request, but do not send passwords, API tokens, or unnecessary Jira content.