Version Workload Reports for Jira

Privacy Policy

Version 1.0 — how Version Workload Reports processes and protects information inside Atlassian Cloud.

Effective and last updated: 9 September 2026

1. Scope and roles

This policy covers Version Workload Reports for Jira (VWR). The provider is identified in the applicable Atlassian Marketplace order under the trade name Sovereign World Labs (Provider). Sovereign World Labs is a trade name and is not represented here as an incorporated entity or separate legal person.

For personal data in customer-controlled Jira, the customer is controller or processor and Provider acts as its processor or subprocessor under the VWR Data Processing Addendum. Atlassian processes Forge-hosted app data for Provider under the Forge terms and Forge DPA. For business contact data used to administer Marketplace orders and direct support, privacy, security, or legal correspondence, Provider acts as an independent controller.

VWR runs entirely on Atlassian Forge and in the user’s browser. It has no Forge Remote, SWL-hosted report backend, external database, advertising, tracking, external analytics, or app-initiated customer-data egress.

2. Information accessed

VWR reads only the data needed for a report requested by the signed-in user: accessible project, version, and saved-filter identifiers and names; issue ID, key, summary, type, and status category; current assignee account ID, display name, and availability state; original estimate, cumulative time spent, and remaining estimate; and minimal technical invocation data such as environment or version, counts, pages, duration, completeness, entitlement state, and public error code.

Issue summaries, identifiers, and assignee information can be personal data. VWR does not request descriptions, comments, attachments, email addresses, full worklogs, or credentials. Jira access uses the initiating user’s identity and existing Jira permissions; there is no privileged fallback or impersonation path for report data.

3. Purpose and operations

VWR validates the selected scope, retrieves Jira issues the signed-in user may access, deduplicates them, calculates workload, estimate coverage, and forecast variance, displays totals and contributing detail, and creates a CSV when the user exports a complete result. It also enforces licensing and documented safety limits and produces privacy-safe operational diagnostics.

The customer determines the legal basis for its Jira data and instructs Provider through the Marketplace agreement and authorized use of VWR. Direct correspondence is processed as necessary to provide and secure the service, respond to requests, comply with law, and operate a safe business-support channel.

4. Storage and export

VWR does not persist app-owned reports, derived report state, Jira issue copies, filters, versions, preferences, queues, or analytics. Report data exists transiently in a Forge invocation and the browser session until it is replaced or the session ends. Jira source records remain in Jira.

A CSV is generated in the browser from the complete report already displayed and does not trigger another Jira query. Once downloaded, the CSV is controlled by the user and customer. VWR has no remote copy to erase.

Sanitized operational logs follow Atlassian Forge’s platform-controlled lifecycle. They contain bounded technical fields such as invocation correlation, environment or app version, normalized entitlement state, operation, duration, page and issue counts, completeness, and public error codes. They exclude JQL, issue content, source names, user names and account IDs, CSV data, credentials, tokens, and full Forge contexts.

5. Hosting, recipients, and transfers

Atlassian and its Forge subprocessors provide the platform used for customer Jira processing. Atlassian documents its applicable subprocessor and transfer mechanisms, including Standard Contractual Clauses where required, in its terms and Forge DPA. VWR does not promise that all processing occurs in one country and does not alter the customer’s Jira data-residency choices.

Direct email to the support or security aliases is person-initiated, separate from the app runtime, and routed through Cloudflare Email Routing to Provider’s private Google-hosted mailbox. Cloudflare and Google process it to route, protect, store, and deliver the correspondence under their applicable terms and transfer mechanisms. The private destination is not published, and VWR does not automatically send Jira report data to them.

6. Sharing and sale

VWR does not sell personal data, share it for cross-context behavioural advertising, use it for model training, or make legal or similarly significant automated decisions. Professional advisers or authorities receive only what is necessary when required by law.

7. Retention and deletion

VWR normally has no app-owned customer Jira data to retain or delete. Transient report data ends with the relevant invocation or browser session. Jira retention remains controlled by the customer, downloaded CSV files remain under customer control, and Forge operational records follow Atlassian’s platform lifecycle.

Direct support, privacy, and security correspondence is normally deleted or anonymized no later than 12 months after closure, with longer retention only for a documented active incident, claim, fraud-prevention need, or legal obligation. Marketplace, accounting, and legal records are retained only for the applicable business and statutory purpose.

Following termination or expiration, Provider will delete or return Customer Personal Data in its possession or control within 60 days of an authorized request, subject to customer-controlled Jira data, Atlassian lifecycle or backups, and law. VWR cannot remotely delete Jira records or CSV files controlled by the customer.

8. Rights

For Jira data, people should normally contact the organization that controls the Jira site. Authorized customer administrators may request Provider assistance with access, correction, export, restriction, or deletion at support@sovereignworldlabs.com. VWR is read-only and cannot change the customer’s Jira records.

For correspondence controlled by Provider, individuals may use the same address to exercise applicable privacy rights and may complain to their competent supervisory authority. Provider may verify identity, authority, site, or installation before acting. Do not send passwords, tokens, Jira contents, or CSV files with a request.

9. Security and logs

VWR uses Forge hosting, one Jira read scope, initiating-user authorization, server-side identifier validation, bounded pagination and retries, fail-closed incomplete results, one contribution per issue ID, CSV formula protection, no app-owned report store, and privacy-safe logging. Atlassian manages platform encryption and infrastructure. VWR has no independent compliance certification, and these measures do not constitute an absolute-security or uninterrupted-availability guarantee.

10. Sensitive data and children

VWR is a business productivity app, is not directed to children, and does not require or intentionally use special-category, criminal-offence, or similarly sensitive personal data. Customer-entered issue summaries can nevertheless contain such data. Customers should not intentionally place unnecessary sensitive information in a reporting scope.

11. Contact and changes

Privacy and data-subject requests: support@sovereignworldlabs.com. Security reports: security@sovereignworldlabs.com. Material changes will be published here with a revised effective date and remain subject to applicable contractual and legal mechanisms.

See the VWR documentation, Data Processing Addendum, Provider-Specific Terms, and Support Policy and SLA.