Service Transition & Readiness
Effective date: 1st September 2026 Last reviewed: 1st September 2026 Version: 1.0
1. Who we are
This Privacy Policy explains how ITSM Ltd (“we”, “us”, “our”), a company registered in England and Wales under company number 17339600 with its registered office at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, handles personal data in connection with Service Transition & Readiness (the “App”), an application distributed through the Atlassian Marketplace.
| Data protection contact | support@itsm-ltd.com |
| Support contact | support@itsm-ltd.com |
| ICO registration number | ZC207852 |
| Postal address | 167-169 Great Portland Street, 5th Floor, London, W1W 5PF |
We are not required to appoint a Data Protection Officer. Enquiries about this policy should be sent to the data protection contact above.
Statement required by Atlassian. ITSM Ltd, and not Atlassian, is responsible for the privacy, security and integrity of any End User Data processed by us or by the App.
2. Scope of this policy
This policy applies to the App only. It does not apply to:
- Atlassian’s own products and services (Jira, Confluence, Atlassian account and related services), which are governed by the Atlassian Privacy Policy;
- our public website, which is governed by a separate website privacy notice; or
- any other application we publish, each of which has its own policy.
3. How the App is hosted — and why this matters
The App is built entirely on Atlassian Forge, Atlassian’s serverless application platform. This has a direct and material consequence for your privacy:
- The App runs on compute infrastructure operated by Atlassian. We do not operate any servers, databases or hosting infrastructure for the App.
- All data the App stores is held in Forge hosted storage inside Atlassian’s cloud environment.
- The App declares no external egress domains in its manifest. The Forge platform blocks outbound network traffic to undeclared destinations by default. Consequently, the App does not transmit your data to us or to any third party.
- We have no routine access to your data. We cannot browse, export or query the contents of your Atlassian site or the App’s stored data. The only circumstances in which we see your data are set out in section 5.4 below.
4. Our role under data protection law
Our role differs depending on the data concerned.
4.1 Where we act as a processor. In respect of personal data contained within your Atlassian site that the App reads, writes or stores (see sections 5.1 to 5.3), you — the Atlassian customer whose site the App is installed on — are the controller and we act as a processor on your instructions. Atlassian acts as a sub-processor in that chain, because it provides the hosting and storage on which the App depends. Our processing on your behalf is governed by our Data Processing Agreement, available at https://str.itsm-ltd.com/legal/data-processing-agreement and incorporated into the End User Terms.
4.2 Where we act as a controller. We act as a controller in our own right for:
- support correspondence you send to us (section 5.4);
- licence and subscription records supplied to us by Atlassian (section 5.5); and
- business contact records relating to your organisation.
5. Personal data we process
5.1 Atlassian account identifiers
The App handles Atlassian account IDs (AAIDs) — opaque identifiers assigned by Atlassian — in order to attribute App records to the correct user, apply permissions and render user references in the App’s interface. Where the App displays a user’s name or avatar, it retrieves that information from Atlassian at the point of display and does not retain a copy.
5.2 Content held in your Atlassian products
To perform its function, the App reads and, where applicable, writes content in your Atlassian products — for example issue fields, comments, page content, attachments metadata or project and space configuration, according to the scopes the App declares. That content may contain personal data if your users have entered personal data into it. This content remains within your Atlassian site at all times; it is not copied to us.
5.3 App configuration and operational data
The App stores its own configuration and operational records — settings, preferences, mappings, audit entries and similar — in Forge hosted storage. These records are scoped to your installation and may include Atlassian account IDs.
5.4 Support correspondence
This is the one category of data that reaches our own systems. When you contact support@itsm-ltd.com, we receive and process your name, email address, employer or Atlassian site details, and whatever information you choose to include in your message — including any screenshots, log extracts or exported data you attach. Please do not send us personal data, credentials or confidential content that is not necessary to diagnose your issue.
5.5 Licence and billing records
Where the App is licensed through the Atlassian Marketplace, Atlassian supplies us with licence records including the Support Entitlement Number (SEN), the licensed tier, the licence status and dates, the customer organisation name and a technical or billing contact. Atlassian is the merchant of record for such transactions; we do not receive or process payment card data.
5.6 Platform logs
The Forge platform generates operational logs for the App’s functions. These logs are produced and retained by Atlassian under Atlassian’s own retention arrangements. The App is designed not to write personal data into logs, in line with Atlassian’s mandatory security requirements for cloud apps.
5.7 Analytics
The App records aggregated, non-identifying usage counts within Forge hosted storage so that we can understand which features are used. These counts contain no personal data and are not transmitted outside Atlassian’s infrastructure. We do not use third-party analytics, telemetry or tracking of any kind.
6. Purposes and lawful bases
| Data | Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Atlassian account IDs; product content; App configuration (5.1–5.3) | Delivering the App’s functionality on the customer’s instructions | Processed on behalf of the customer as controller; the customer determines the lawful basis |
| Support correspondence (5.4) | Responding to enquiries, diagnosing faults, maintaining a support record | Art. 6(1)(b) performance of a contract; Art. 6(1)(f) legitimate interests in providing and improving support |
| Licence and billing records (5.5) | Verifying entitlement, administering the licence, renewals and compliance | Art. 6(1)(b) performance of a contract; Art. 6(1)(c) legal obligation (accounting records) |
| Aggregated usage counts (5.7, Option B) | Understanding feature adoption to prioritise development | Art. 6(1)(f) legitimate interests in improving the App |
We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile individuals. We do not knowingly process special category data; if your use of the App involves special category data within your Atlassian content, you remain the controller of that data and are responsible for identifying an Article 9 condition.
7. Where your data is stored
Data stored by the App resides in Forge hosted storage and inherits the data residency configuration of the Atlassian product it is installed alongside. Where you have pinned your Jira or Confluence data to a particular Atlassian region, in-scope App data is pinned to that region, and Atlassian migrates it with your product data if you move regions. Data residency for Forge apps is managed by Atlassian; details and the current list of supported regions are published at Atlassian’s data residency pages.
Support correspondence (5.4) and licence records (5.5) are held in our own business systems: email in Google Workspace, and support records in a support application built and operated by us, hosted on Vercel and Supabase, both configured to United Kingdom regions.
8. Sharing and sub-processors
We do not sell personal data, and we do not share it for advertising or marketing purposes.
| Recipient | Role | Purpose | Location |
|---|---|---|---|
| Atlassian Corporation / Atlassian Pty Ltd | Sub-processor | Hosting, compute and storage for the App; Marketplace licensing and billing | Per your data residency settings |
| Google Ireland Limited (Google Workspace) | Sub-processor | Delivery and storage of support email | Ireland / European Economic Area |
| Vercel Inc. | Sub-processor | Application hosting for our support application | United Kingdom region |
| Supabase Inc. | Sub-processor | Database and storage for our support application | United Kingdom region |
Our support application is built and operated by us, not licensed from a third party, so it is not itself a sub-processor. The providers that host it are. Both are configured to United Kingdom regions, so support correspondence is stored in the UK; both are US-incorporated, and section 9 explains the safeguards applied.
We will give 30 days’ notice of any change to this list by updating this policy and the effective date. We may also disclose personal data where required by law, court order or a regulator, or to establish, exercise or defend legal claims.
9. International transfers
Because App data is held within Atlassian’s infrastructure, transfers are governed by Atlassian’s arrangements, including its Data Processing Addendum and the Standard Contractual Clauses with the UK International Data Transfer Addendum where applicable. Where we transfer support or licence data outside the United Kingdom, we rely on UK adequacy regulations or, where no adequacy decision applies, the International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses. A copy of the relevant safeguards is available on request.
10. Retention
| Data | Retention |
|---|---|
| App data in Forge hosted storage | Retained for as long as the App is installed. On uninstallation, Atlassian deletes Forge app data in accordance with its platform deletion processes; we retain no copy |
| Support correspondence | 24 months from closure of the enquiry |
| Licence and billing records | 7 years, to meet UK statutory accounting and tax requirements |
| Aggregated usage counts (where applicable) | 13 months |
11. Security
App data is encrypted in transit and at rest by the Atlassian platform, is isolated per tenant, and is accessible to the App only through the minimum permissions it declares. Our security measures are described in full in the Cloud Security Statement at https://str.itsm-ltd.com/legal/cloud-security-statement, which is the authoritative account of them. Where we act as your processor, the same measures are set out as technical and organisational measures in Annex 2 of the Data Processing Agreement.
Where a security incident affects personal data we hold or process, we will notify the technical contact on your licence without undue delay and in any event within 72 hours of becoming aware, and will assist you in meeting your own regulatory notification obligations. Incident handling is described in section 8 of the Cloud Security Statement.
We are not ourselves certified to SOC 2, ISO/IEC 27001 or comparable standards. The Atlassian infrastructure on which the App runs is independently certified; those certifications belong to Atlassian and may be verified at the Atlassian Trust Center.
12. Your rights
Where we act as a controller (support correspondence, licence records), you have the right under UK GDPR to:
- request access to your personal data;
- request rectification of inaccurate data;
- request erasure, where a ground applies;
- request restriction of processing;
- object to processing carried out on the basis of legitimate interests;
- request portability of data you provided to us; and
- withdraw consent, where processing is based on consent, without affecting prior processing.
To exercise a right, email support@itsm-ltd.com. We will respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies. There is normally no charge.
Where we act as a processor (data inside your Atlassian site), please direct your request to the Atlassian customer whose site holds the data — normally your own organisation’s administrator. We will assist that customer in responding.
Complaints. If you are dissatisfied with how we have handled your personal data, please tell us first at support@itsm-ltd.com; we operate a complaints procedure and will acknowledge your complaint within 5 business days and respond substantively within 30 days. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post to Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
13. Notice to residents of California
If you are a California resident, you have rights under the California Consumer Privacy Act as amended, including rights to know, delete, correct and opt out. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not process personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes requiring an opt-out. To exercise a right, contact support@itsm-ltd.com; we will not discriminate against you for doing so.
14. Children
The App is a business tool licensed to organisations and is not directed at children. We do not knowingly process the personal data of anyone under 18 in connection with the App.
15. Changes to this policy
We may update this policy from time to time. Material changes will be notified by updating the effective date above and, where the change materially affects your rights, by email to the technical contact on your licence at least 30 days before the change takes effect. Previous versions are available on request.
This Privacy Policy is published in accordance with the Atlassian Marketplace Partner Agreement. It should be read alongside the End User Terms, the Cloud Security Statement and the Support and Maintenance Description for Service Transition & Readiness.