Legal

Privacy Policy — Helkrypt apps for Atlassian and customer support

Version 1.2 · Last updated: 29 September 2026(1.2: added Comment & Reply Templates for Jira, section 4.4)

This policy explains how Helkrypt AI AS handles personal data in our apps for Atlassian cloud products and in our customer support. Our general privacy policy for the Helkrypt website and other services is at https://www.helkrypt.no/privacy.


1. Who we are

"We" means Helkrypt AI AS, a Norwegian company.

CompanyHelkrypt AI AS (org. no. 936 351 034)
Registered officeMjånesvegen 83, 5551 Auklandshamn, Norway
Postal addressPostboks 14, 4756 Hovden i Setesdal, Norway
Privacy contactsupport@helkrypt.no
Name on Atlassian MarketplaceHelkrypt

2. What this policy covers

  • Our apps on the Atlassian Marketplace (section 4)
  • Support requests sent to support@helkrypt.no (section 3.1)
  • Licence and sales information we receive from Atlassian (section 3.2)

3. Data we are responsible for (we are the controller)

3.1 Customer support

DataYour name and email address, the subject and text of your message, the file names of any attachments, email headers used to keep messages in the same thread, the case number and timestamps. We do not keep attachment contents: they are discarded when your email is processed.
WhyTo answer your support request and keep a history of the case.
Legal basisIf you are a customer: performance of a contract (GDPR art. 6(1)(b)). If you are not a customer yet, for example with a question before buying: our legitimate interest in answering questions about our products (art. 6(1)(f)).
How longCases and messages are deleted automatically 12 months after the case is closed. Copies in the support mailbox are deleted after 30 days.

How it works: you email support@helkrypt.no. An automation server reads the mailbox and creates a case in our internal support system. You get an automatic reply with your case number. We reply to you by email through an email delivery provider.

Logs: the automation server does not keep data from runs that succeed. If a run fails, it keeps that run for up to 14 days so we can fix the problem.

3.2 Licence information from Atlassian

DataAtlassian shares licence, trial and transaction information with us in its vendor portal. This can include the organisation name and the name and email of technical and billing contacts. This contact information stays in Atlassian's vendor portal: we do not copy it into our own systems. In our own reporting we store only aggregated figures from Atlassian's public Marketplace API, such as installs, ratings and reviews.
WhyContact information: billing and support. Aggregated figures: understanding how our apps are doing.
Legal basisOur legitimate interest in running our business (art. 6(1)(f)). Accounting records: legal obligation (art. 6(1)(c)).
How longContact information is kept by Atlassian under Atlassian's rules. Accounting records are kept as long as Norwegian accounting law requires.

4. Data in your Atlassian site (we are a processor)

When your organisation uses one of our apps, your organisation is the controller for the data in its Atlassian site. We act only as a processor, and process that data only to run the app. The apps run on Atlassian's Forge platform.

All our current apps:

  • keep all data inside Atlassian, in the same region as your site (data residency is supported)
  • send no data outside Atlassian, use no cookies and have no tracking or analytics
  • qualify for Atlassian's "Runs on Atlassian" programme
  • log only technical information (such as IDs and status codes), never work item content or names

4.1 Auto Issue & Description Templates for Jira

  • Stores: template names and text, the projects and work types a template applies to, whether it is a default template, and when it was last changed. Stored in Forge hosted storage.
  • Reads but does not store:a work item's description, project, work type, reporter and assignee. Names are used only to fill in template variables such as {{reporter}}.
  • Personal data stored by the app:none. Template text can contain anything an administrator writes, so please don't put personal or confidential information in templates.
  • How long: until an administrator deletes the template or the app is uninstalled. After uninstall, Atlassian deletes the app data under the Forge hosted storage lifecycle.

4.2 Epic Rollup for Jira

  • Stores: admin settings (story points field per project, feature switches) in Forge hosted storage, and epic totals (number of child issues, story points, time, percent done, last updated) as a property on the epic. The totals contain only numbers and a date, never issue keys, titles or names.
  • Reads but does not store:the epic's child issues (key, summary, status, story points, time fields, parent, Atlassian team).
  • Optional: time logged per person.Off by default. If a Jira administrator turns it on, the app shows logged time per person on an epic. It is calculated in the viewer's browser, never stored, ranked or exported. Your organisation decides whether this is lawful (for example under employment law on monitoring staff) and must inform employees before turning it on.
  • Personal data stored by the app: none.
  • How long: settings until the app is uninstalled. Epic totals until an administrator turns off searchable totals (a background job then removes them) or the epic is deleted. Uninstalling does not remove the totals, because the app can no longer reach Jira after uninstall. Turn off searchable totals before uninstalling if you want them removed.

4.3 Smart Defaults for Jira

  • Stores: rules in Forge hosted storage: rule name, the projects and work types it applies to, and the default values (priority, labels, components and number of days until the due date). The rules contain IDs, labels and numbers, not work item content.
  • Reads but does not store:a new work item's project, work type, priority, labels, components and due date, to see which fields are empty. The app reads no user fields.
  • Personal data stored by the app:none. Rule names and labels are free text written by an administrator, so please don't put personal or confidential information in them.
  • How long: until an administrator deletes the rule or the app is uninstalled. After uninstall, Atlassian deletes the app data under the Forge hosted storage lifecycle. Values the app has set on work items are normal Jira field values and stay on the work items.

4.4 Comment & Reply Templates for Jira

  • Stores: templates in Forge hosted storage: template name and text, the projects and work types it applies to, whether it is posted as an internal note or a reply to the customer in service projects, and when it was last changed.
  • Reads but does not store:a work item's key, summary, project, work type, reporter and assignee, in the user's browser, to fill in template variables such as {{reporter}}. They only end up in the comment the user chooses to post.
  • Comments: the user posts the comment as themselves. It is stored by Jira as a normal comment, not by the app.
  • Personal data stored by the app:none. Template text can contain anything an administrator writes, so please don't put personal or confidential information in templates.
  • How long: until an administrator deletes the template or the app is uninstalled. After uninstall, Atlassian deletes the app data under the Forge hosted storage lifecycle. Posted comments are normal Jira comments and stay on the work items.

4.5 Requests about data in your site

Send requests about access, correction or deletion of data in your Atlassian site to your own site administrator. We help your organisation answer them. Customers who need a data processing agreement can find ours at https://www.helkrypt.no/dpa.

5. AI in customer support

We use AI to write draft replies to support requests, based on the messages in the case. A person at Helkrypt always reads, edits if needed, and approves every reply before it is sent. The AI never decides anything about you, so there is no automated decision-making under GDPR art. 22.

Our apps themselves do not use AI.

6. Service providers and international transfers

We use these providers. All of them have signed a data processing agreement with us.

ProviderWhat they do for usWhere data is processedTransfer safeguard
AtlassianHosts our apps (Forge), Marketplace and licensingYour site's region; Atlassian also operates in the USEU–US Data Privacy Framework and Standard Contractual Clauses (Atlassian DPA)
Domene AS (Domene.no)Hosts the support@helkrypt.no mailboxEEAWithin the EEA
HostingerHosts our workflow automation serverGermany (Frankfurt)Within the EEA (Hostinger DPA)
Base44 (Wix.com Ltd)Internal support system and AI draft repliesUnited States (Wix: Israel)Standard Contractual Clauses (Modules 2/3); EU adequacy decision for Israel (Base44 DPA)
OpenAI and Anthropic, through Base44Generate AI draft repliesUnited StatesStandard Contractual Clauses (Base44 sub-processors)
Resend (Plus Five Five, Inc.)Sends support replies and automatic acknowledgementsEU (Ireland); US companyEU–US Data Privacy Framework and Standard Contractual Clauses (Resend DPA)

7. How long we keep data

DataRetention
Support cases and messages12 months after the case is closed, then deleted automatically
Copies in the support mailbox30 days
Support emails and logs at our email delivery provider30 days
Failed automation runsUp to 14 days
Licence contact informationStays in Atlassian's vendor portal, under Atlassian's rules
Aggregated Marketplace figuresWhile useful for running the business
Accounting recordsAs required by Norwegian accounting law
Data in the appsSee section 4

8. How we protect data

  • Access is limited to the people and systems that need it.
  • Passwords and API keys are kept in secret stores, never in code.
  • Data is encrypted in transit (TLS).
  • We collect as little as possible: attachment contents are discarded, successful automation runs are not stored, licence contact information stays with Atlassian, and our apps store no personal data of their own.

9. Your rights

You have the right to:

  • access the personal data we hold about you
  • correct inaccurate data
  • delete your data
  • restrict how we use it
  • receive your data in a portable format
  • object to processing based on our legitimate interest

Email support@helkrypt.noto use your rights. We answer within one month. For data in your organisation's Atlassian site, see section 4.5.

10. Complaints

You can complain to the Norwegian Data Protection Authority, Datatilsynet: https://www.datatilsynet.no/en/about-us/contact-us/how-to-complain-to-the-norwegian-dpa. You can also complain to the authority in the EEA country where you live or work.

11. Changes

When we change this policy, we update the version number and the "last updated" date at the top.