Privacy Policy
Last updated: 2026-06-30
Who we are
ThreadOpen for Jira ("the app") is provided by Tech Lake Systems Sp. z o.o. ("Tech Lake Systems", "we", "us", "the vendor"), a limited liability company registered in Poland (European Union). Our role under the GDPR depends on the data. For the Jira content the app processes on your behalf — for example an issue's summary and link posted into your connected Slack workspace — your organization is the data controller and Tech Lake Systems acts as a data processor. For the limited operational data the app determines itself — audit records (the account ID of the admin who connects Slack or configures a mapping), workspace connection metadata, and app configuration — Tech Lake Systems is the data controller.
Contact: support@threadopen.com. Our full registered address is available via our Atlassian Marketplace vendor profile or on request.
What data we collect
The app collects the minimum data needed to bridge Jira issues to Slack threads:
| Data | Source | Purpose |
|---|---|---|
| Slack workspace OAuth token | Slack (after user grant) | Authenticate API calls to post messages and read channels |
| Slack workspace metadata | Slack (auth.test) | Display "Connected to <workspace>" in the admin UI |
| Slack channel list + visibility | Slack (conversations.list) | Populate the channel picker; show visibility warnings |
| Jira project list | Jira REST | Populate the mapping admin page |
| Jira issue summary | Jira REST | Used as the parent message text when creating a thread |
| Project-to-channel mappings | User input | Routing future thread creations for that project |
| Thread metadata (channel ID, parent ts, first reply ts, permalink URL) | Generated when creating a thread | Skip re-creation on subsequent issue clicks |
| Audit log entries | App-internal | Record mapping changes, OAuth events, visibility overrides |
| User account ID of mapping author | Atlassian context | Audit attribution ("Configured by …") |
The app does NOT collect:
- Slack message content (only ts identifiers and channel metadata).
- Jira comment content.
- Personally identifiable information beyond the Atlassian account ID (an opaque identifier within the user's Jira site).
- Browser cookies for tracking.
- Analytics beacons or third-party telemetry.
Legal basis for processing
As a controller established in the EU, we rely on the following legal bases under the General Data Protection Regulation (GDPR), Article 6:
- Performance of a contract / steps taken at your request — to provide the app's core function (bridging Jira issues to Slack threads) once you install and configure it.
- Legitimate interests — to operate, secure, and maintain the app, and to keep an audit trail of configuration changes, balanced against your rights and freedoms.
We do not process special categories of personal data, and we do not use the data for advertising, profiling, or automated decision-making.
Where it's stored
All data is stored in Atlassian Forge KVS (key-value storage):
- Encrypted at rest by Atlassian.
- Scoped to your specific Atlassian site / app installation.
- Physically hosted on Atlassian's infrastructure (AWS regions managed by Atlassian).
- Not transmitted to or stored on any third-party servers operated by the vendor — the app has no servers of its own.
Who we share it with
Data is shared only with:
- Slack — when the app makes Slack Web API calls on your behalf (e.g. posting a thread message), using your installation's bot token. Slack's privacy policy applies.
- Atlassian — implicitly, since the data lives on Atlassian's Forge platform. Atlassian's terms apply.
No third-party advertisers, analytics services, or data brokers receive any data from the app.
International transfers
To provide the app, End-User Data may be transferred outside the European Economic Area (EEA), specifically to:
- Atlassian — the app runs on Atlassian Forge and stores its data in Atlassian's infrastructure (AWS regions managed by Atlassian), which may be located outside the EEA.
- Slack (Slack Technologies / Salesforce) — when the app posts an issue's summary and link into your connected Slack workspace, that data is processed and stored by Slack, whose infrastructure may be located outside the EEA.
These transfers are governed by GDPR-approved transfer mechanisms — Standard Contractual Clauses (SCCs) and, where applicable, the EU-U.S. Data Privacy Framework — provided through Atlassian's and Slack's data processing agreements, on which we rely as their customer. The app does not transfer End-User Data to any other third parties.
Retention
- All data persists for the lifetime of the app installation.
- Disconnecting the Slack workspace (from the admin page) revokes the bot token at Slack and deletes it from storage immediately.
- Uninstalling the app triggers the Forge
lifecycle:uninstalledevent, which revokes and deletes the stored Slack token. The remaining installation-scoped data (mappings, audit log, thread metadata, configuration) is then soft-deleted by Atlassian's Forge platform under its Standard Data Retention and Disposal policy — recoverable if the app is reinstalled within roughly 21 days, then permanently deleted. - Slack data (threads, messages) created by the app is not deleted on uninstall — those messages live in your Slack workspace and are governed by Slack's data retention. Manage them via Slack directly.
Your rights
If you are in the EU/EEA — or another jurisdiction with comparable data protection law — you have the right to:
- Access — request a copy of the data the app stores about your installation.
- Rectification — correct inaccurate data.
- Erasure — disconnect and/or uninstall the app to remove stored data (see Retention above).
- Restriction — ask us to limit certain processing.
- Objection — object to processing based on legitimate interests.
- Portability — request an export.
To exercise any of these rights, contact support@threadopen.com.
You also have the right to lodge a complaint with a data protection supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO — Urząd Ochrony Danych Osobowych, uodo.gov.pl).
Cookies and tracking
The app uses no cookies of its own. The Atlassian-hosted iframes that render the app's UI may use Atlassian's session cookies for authentication; consult Atlassian's privacy policy.
Children
The app is not directed at children under 16. It's a productivity tool intended for use in workplace contexts.
Changes
Material changes to this policy will be reflected by updating the "Last updated" date and (where possible) notifying installed customers via the admin page.
Contact
For privacy questions or to exercise any of your rights: support@threadopen.com.