Privacy Policy
This privacy policy describes how the Atlassian Forge app Customer Assets for JSM Portal ("the App") handles data. It applies to the App only, not to Atlassian's own services (see Atlassian's privacy policy for those).
external.fetch: [] in its manifest) and is eligible for Atlassian's "Runs on Atlassian" program.What data the App processes
- Asset data (JSM Assets/Insight): read via the Assets REST API and written only for schema-approved attributes, strictly scoped to the signed-in customer. Asset data is processed in-memory per request and is not persisted by the App.
- User context: the Atlassian account ID of the signed-in user, provided by the Forge platform in a signed context. Used exclusively to scope asset queries and to raise requests on the user's behalf. The user's display name and email are read from the Jira user API for display and ticket descriptions only.
- Service requests: tickets created through the App are standard JSM requests stored in your Jira site.
- Attachments: files uploaded in the "Report asset" form are forwarded to the JSM attachment API of your site and are not stored by the App.
What the App stores
- Configuration (service desk, request types, schema/object-type selection, per-type display and process settings, portal languages and admin-maintained translations of object-type/attribute names) in Forge Key-Value Storage, hosted by Atlassian within your site's data residency boundary. Configuration contains no personal data beyond attribute names chosen by your admin.
- Anonymous usage counters (e.g. "requests created per day") in Forge storage. These contain no personal data; account IDs, emails and similar fields are explicitly stripped before storage.
What the App does NOT do
- No transfer of any data outside your Atlassian site.
- No cookies, no tracking, no third-party analytics.
- No storage of asset contents, user profiles or attachments by the App itself.
Data residency & deletion
All App storage lives in Atlassian Forge hosted storage and follows your site's data-residency configuration. Uninstalling the App removes its storage per Atlassian's Forge data-eviction policy. Configuration can also be wiped at any time via "Reset configuration" in the App's admin page.
Permissions (scopes)
The App requests the minimum scopes needed: read/write of Assets objects, read of Assets schemas/attributes, JSM request read/write, service-desk and organization read, manage:servicedesk-customer (solely for raising requests on behalf of the signed-in customer without consent prompts), Jira user/work read-write, and app storage.
This website
This website (basicdata.net) is a static site. It sets no cookies and runs no analytics. Server logs, if any, are handled by the hosting provider. The contact form is delivered by the third-party service FormSubmit (formsubmit.co). The data you enter there (name, email address, message) is transmitted to FormSubmit and forwarded to our mailbox. We use it only to answer your request.
Contact
Questions about this policy or data handling: use the contact form or the address in the Impressum.