ThreadOpen for Jira

Privacy Policy

Last updated: 2026-06-30

Who we are

ThreadOpen for Jira ("the app") is provided by Tech Lake Systems Sp. z o.o. ("Tech Lake Systems", "we", "us", "the vendor"), a limited liability company registered in Poland (European Union). Our role under the GDPR depends on the data. For the Jira content the app processes on your behalf — for example an issue's summary and link posted into your connected Slack workspace — your organization is the data controller and Tech Lake Systems acts as a data processor. For the limited operational data the app determines itself — audit records (the account ID of the admin who connects Slack or configures a mapping), workspace connection metadata, and app configuration — Tech Lake Systems is the data controller.

Contact: support@threadopen.com. Our full registered address is available via our Atlassian Marketplace vendor profile or on request.

What data we collect

The app collects the minimum data needed to bridge Jira issues to Slack threads:

DataSourcePurpose
Slack workspace OAuth tokenSlack (after user grant)Authenticate API calls to post messages and read channels
Slack workspace metadataSlack (auth.test)Display "Connected to <workspace>" in the admin UI
Slack channel list + visibilitySlack (conversations.list)Populate the channel picker; show visibility warnings
Jira project listJira RESTPopulate the mapping admin page
Jira issue summaryJira RESTUsed as the parent message text when creating a thread
Project-to-channel mappingsUser inputRouting future thread creations for that project
Thread metadata (channel ID, parent ts, first reply ts, permalink URL)Generated when creating a threadSkip re-creation on subsequent issue clicks
Audit log entriesApp-internalRecord mapping changes, OAuth events, visibility overrides
User account ID of mapping authorAtlassian contextAudit attribution ("Configured by …")

The app does NOT collect:

Legal basis for processing

As a controller established in the EU, we rely on the following legal bases under the General Data Protection Regulation (GDPR), Article 6:

We do not process special categories of personal data, and we do not use the data for advertising, profiling, or automated decision-making.

Where it's stored

All data is stored in Atlassian Forge KVS (key-value storage):

Who we share it with

Data is shared only with:

No third-party advertisers, analytics services, or data brokers receive any data from the app.

International transfers

To provide the app, End-User Data may be transferred outside the European Economic Area (EEA), specifically to:

These transfers are governed by GDPR-approved transfer mechanisms — Standard Contractual Clauses (SCCs) and, where applicable, the EU-U.S. Data Privacy Framework — provided through Atlassian's and Slack's data processing agreements, on which we rely as their customer. The app does not transfer End-User Data to any other third parties.

Retention

Your rights

If you are in the EU/EEA — or another jurisdiction with comparable data protection law — you have the right to:

To exercise any of these rights, contact support@threadopen.com.

You also have the right to lodge a complaint with a data protection supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO — Urząd Ochrony Danych Osobowych, uodo.gov.pl).

Cookies and tracking

The app uses no cookies of its own. The Atlassian-hosted iframes that render the app's UI may use Atlassian's session cookies for authentication; consult Atlassian's privacy policy.

Children

The app is not directed at children under 16. It's a productivity tool intended for use in workplace contexts.

Changes

Material changes to this policy will be reflected by updating the "Last updated" date and (where possible) notifying installed customers via the admin page.

Contact

For privacy questions or to exercise any of your rights: support@threadopen.com.