TELCOMA Global  /  License Audit for Jira  /  Privacy policy

What the app reads, what it keeps, and what it never does.

This policy describes what License Audit for Jira does with your data.

Effective date: 23 September 2026  ·  Provider: TELCOMA Technologies Private Limited (trading as TELCOMA Global), SCO 124, 4th Floor, Feroze Gandhi Market, Ludhiana, Punjab 141001, India  ·  support@telcomaglobal.com

1

What the app is

License Audit for Jira ("the app") is an Atlassian Marketplace app that helps a Jira Cloud administrator identify licensed users who have shown no activity in Jira over a chosen period. It runs entirely on Atlassian's Forge platform.

2

What data the app processes

The app reads the following from your Jira Cloud site, using only the read-only permissions granted at installation:

  • User directory data: account ID, active status and account type while a scan runs; display name and email address (where the user's Atlassian profile makes it visible to apps) only when a report is displayed or exported. None of these except the account ID are written to storage.
  • Application role and group membership: which product licensing groups each user belongs to, and Atlassian's per-product seat counts.
  • Issue activity metadata: for recently-updated issues, the author and timestamp of changelog entries, comments and work logs, and the creator and reporter. The app reads this to determine who was active and when. It does not read issue descriptions, comment text, attachments or custom field values.

3

What data the app stores

The app stores, in Forge's Atlassian-hosted storage within your site's data residency region:

  • Scan progress (cursors, counters, timestamps).
  • For each dormant user: the Atlassian account ID, product membership, and a dormancy band derived by the app. Display names and email addresses are not stored; they are read from Jira each time you open or export the report.

The app never stores issue content, comment text, work log descriptions, attachments, or any text authored by your users. Every stored value is regenerated by each scan and is deleted when the app is uninstalled.

4

Where data goes

Nowhere. The app makes no network requests outside Atlassian and has no servers of its own. Data does not leave your Atlassian site's hosting region.

5

What the app does not do

  • It does not deactivate, modify or delete users, and holds no permission that could.
  • It does not change any setting, issue, or configuration on your site.
  • It does not use your data for any purpose other than producing the report you request.
  • It does not sell, share, or transmit your data to any third party.

6

Legal basis and roles

You (the customer) are the data controller for the personal data on your site. TELCOMA Global is a data processor acting on your instructions, which consist of installing the app and running a scan. Where the GDPR applies, the app's processing is performed under your instructions and on Atlassian's infrastructure.

7

Retention and deletion

Report data persists on your site until the next scan overwrites it or the app is uninstalled, at which point Forge deletes all app storage for your site. You may also request deletion by contacting us.

8

Security

The app runs on Atlassian Forge, which enforces the app's permissions at the platform level, hosts its storage, and isolates it from other apps. The app requests only read scopes. Security issues may be reported to support@telcomaglobal.com; please do not post them publicly.

9

Support and contact

support@telcomaglobal.com — we respond within one business day. See the support page.

10

Changes

We will update this policy when the app's data handling changes and note the effective date above.