ServiceAccord
Privacy Policy
How we handle personal data, and how little of it reaches us, under UK GDPR.
1. Who we are
This Privacy Policy explains how ITSM Ltd (“we”, “us”, “our”), a company registered in England and Wales under company number 17339600 with its registered office at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, handles personal data in connection with ServiceAccord (the “App”), an application distributed through the Atlassian Marketplace.
| Field | |
|---|---|
| Data protection contact | support@itsm-ltd.com |
| Support contact | support@itsm-ltd.com |
| ICO registration number | ZC207852 |
| Postal address | 167-169 Great Portland Street, 5th Floor, London, W1W 5PF |
We are not required to appoint a Data Protection Officer. Enquiries about this policy should be sent to the data protection contact above.
Statement required by Atlassian. ITSM Ltd, and not Atlassian, is responsible for the privacy, security and integrity of any End User Data processed by us or by the App.
2. Scope of this policy
This policy applies to the App only. It does not apply to:
- Atlassian’s own products and services (Jira, Confluence, Atlassian account and related services), which are governed by the Atlassian Privacy Policy;
- our public website, which is governed by a separate website privacy notice; or
- any other application we publish, each of which has its own policy.
3. How the App works — and why this matters
The App is built entirely on Atlassian Forge, Atlassian’s serverless application platform, and it keeps no store of its own. This has a direct and material consequence for your privacy:
- Everything your users enter into the App’s macros is saved by Confluence as part of the page on which the macro sits. It is governed by that page’s permissions and by your agreement with Atlassian.
- The App’s display and editing run in the user’s browser, inside Confluence. Its only server-side code is three export functions, which run on Atlassian-operated compute when a page is exported to PDF or Word, process the macro’s content in memory and store nothing. We do not operate any servers, databases or hosting infrastructure for the App.
- The App requests no Atlassian permissions (OAuth scopes), calls no Atlassian API and declares no external egress domains. The Forge platform blocks outbound network traffic to undeclared destinations by default. Consequently, the App does not transmit your data to us or to any third party.
- We have no routine access to your data. We cannot browse, export or query the contents of your Atlassian site. We see your data only if you send it to us (section 5.4) or, in one narrow case, in the App’s error logs (section 5.6).
4. Our role under data protection law
Our role differs depending on the data concerned.
4.1 Where we act as a processor. In respect of personal data contained in the content your users enter into the App’s macros (section 5.1), you — the Atlassian customer whose site the App is installed on — are the controller. We act as a processor for the processing the App performs on that content, principally its transient processing by the App’s export functions on Atlassian Forge compute, which we engage. Atlassian acts as our sub-processor for that compute. Storage of the content is by Confluence, under your own agreement with Atlassian. Our processing on your behalf is governed by our Data Processing Agreement, available at https://serviceaccord.itsm-ltd.com/legal/data-processing-agreement and incorporated into the End User Terms.
4.2 Where we act as a controller. We act as a controller in our own right for:
- support correspondence you send to us (section 5.4);
- Marketplace records Atlassian makes available to us (section 5.5); and
- business contact records relating to your organisation.
5. Personal data we process
5.1 Information your users enter into the macros
The App collects no personal data automatically. It does not handle Atlassian account IDs, email addresses or avatars. Personal data appears only where your users type it into one of the App’s free-text fields — most likely the RACI Matrix’s role names and activity notes; the Service Review Record’s chair, attendees, action owners, KPI comments, and risks and issues; and the Service Level Targets’ owner, and notes and exclusions. That content is stored by Confluence as part of the page and is not copied to us.
5.2 Other content in your Atlassian products
The App reads only the configuration of its own macro, which Confluence supplies to it, and the viewer’s locale, which it uses to format dates. It does not read other page content, Jira issues, comments, spaces or user profiles.
5.3 No separate App records
The App stores no settings, preferences, audit entries or operational records of its own. Everything it holds is the macro content described in section 5.1.
5.4 Support correspondence
This is the one category of data that routinely reaches our own systems. When you contact support@itsm-ltd.com, we receive and process your name, email address, employer or Atlassian site details, and whatever information you choose to include in your message — including any screenshots or exported pages you attach. Please do not send us personal data, credentials or confidential content that is not necessary to diagnose your issue.
5.5 Marketplace records
The App is free. It is not sold through Atlassian’s paid licensing, Atlassian is not a merchant of record for it, and we receive and process no payment data. Where Atlassian makes information about installations of the App, or contact details for an installing organisation, available to us through the Atlassian Marketplace, we process it to administer the App’s listing and to contact you about the App.
5.6 Platform logs
The Forge platform generates operational logs for the App’s export functions. These logs are produced and retained by Atlassian under Atlassian’s own retention arrangements, and are accessible to us through the Atlassian developer console. The App writes error messages only, never routine activity, and does not log the content of its macros — with one narrow exception. Where a macro’s stored content is damaged and cannot be read, the error recorded may quote a short excerpt of it; if that happens during an export, the excerpt reaches the App’s logs. Atlassian provides a setting through which your site administrator can withdraw developers’ access to an app’s logs. We do not enable Forge front-end log capture, and we do not export the App’s logs outside Atlassian.
5.7 Analytics
The App records no usage counts, analytics or telemetry of any kind. We do not use third-party analytics, telemetry or tracking.
6. Purposes and lawful bases
| Data | Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Content entered into the App’s macros (5.1); App logs (5.6) | Delivering the App’s functionality, including export, on the customer’s instructions | Processed on behalf of the customer as controller; the customer determines the lawful basis |
| Support correspondence (5.4) | Responding to enquiries, diagnosing faults, maintaining a support record | Art. 6(1)(b) performance of a contract; Art. 6(1)(f) legitimate interests in providing and improving support |
| Marketplace records (5.5) | Administering the App’s listing and contacting you about the App | Art. 6(1)(f) legitimate interests in administering and supporting the App |
We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile individuals. We do not knowingly process special category data; if your use of the App involves special category data within your Atlassian content, you remain the controller of that data and are responsible for identifying an Article 9 condition.
7. Where your data is stored
Content your users enter into the App’s macros is stored by Confluence as part of your pages, and therefore follows your Confluence data residency configuration, including any migration between regions. The App adds no separate storage location. The export functions process that content transiently on Atlassian Forge compute, in locations determined by Atlassian, and retain nothing. Data residency is managed by Atlassian; details and the current list of supported regions are published at Atlassian’s data residency pages.
Support correspondence (5.4) and Marketplace records (5.5) are held in our own business systems: email in Google Workspace, and support records in Jira Service Management, Atlassian’s service desk product, on our own Atlassian site, under that site’s data residency configuration.
8. Sharing and sub-processors
We do not sell personal data, and we do not share it for advertising or marketing purposes.
| Recipient | Role | Purpose | Location |
|---|---|---|---|
| Atlassian Corporation / Atlassian Pty Ltd | Sub-processor | Forge compute for the App’s export functions; Marketplace distribution; Jira Service Management, our support tool | Determined by Atlassian |
| Google Ireland Limited (Google Workspace) | Sub-processor | Delivery and storage of support email | Ireland / European Economic Area |
Storage of macro content in Confluence is under your own agreement with Atlassian, not ours. Our support tool is Atlassian’s Jira Service Management, so Atlassian, listed above, holds support correspondence alongside Google. Section 9 explains the safeguards applied.
We will give 30 days’ notice of any change to this list, in the manner set out in clause 13.3 of the End User Terms, and will update this policy and its effective date. We may also disclose personal data where required by law, court order or a regulator, or to establish, exercise or defend legal claims.
9. International transfers
Because content entered into the App’s macros is held and processed within Atlassian’s infrastructure, transfers of it are governed by Atlassian’s arrangements, including its Data Processing Addendum and the Standard Contractual Clauses with the UK International Data Transfer Addendum where applicable. Where we transfer support or Marketplace data outside the United Kingdom, we rely on UK adequacy regulations or, where no adequacy decision applies, the International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses. A copy of the relevant safeguards is available on request.
10. Retention
| Data | Retention |
|---|---|
| Content entered into the App’s macros | Part of your Confluence pages, including their version history; retained and deleted under your Confluence settings. Uninstalling the App deletes nothing. We retain no copy |
| App logs | Retained by Atlassian under its platform log retention arrangements |
| Support correspondence | 24 months from closure of the enquiry |
| Marketplace records | For as long as the App is installed on your site, then deleted within 24 months |
11. Security
Content entered into the App’s macros is encrypted in transit and at rest by the Atlassian platform as part of Confluence page storage, and is visible to the people who can view the page that contains it. The App itself declares no permissions. Our security measures are described in full in the Cloud Security Statement at https://serviceaccord.itsm-ltd.com/legal/cloud-security-statement, which is the authoritative account of them. Where we act as your processor, the same measures are set out as technical and organisational measures in Annex 2 of the Data Processing Agreement.
Where a security incident affects personal data we hold or process, we will notify you, in the manner set out in clause 13.3 of the End User Terms, without undue delay and in any event within 72 hours of becoming aware, and will assist you in meeting your own regulatory notification obligations. Incident handling is described in section 8 of the Cloud Security Statement.
We are not ourselves certified to SOC 2, ISO/IEC 27001 or comparable standards. The Atlassian infrastructure on which the App runs is independently certified; those certifications belong to Atlassian and may be verified at the Atlassian Trust Center.
12. Your rights
Where we act as a controller (support correspondence, Marketplace records), you have the right under UK GDPR to:
- request access to your personal data;
- request rectification of inaccurate data;
- request erasure, where a ground applies;
- request restriction of processing;
- object to processing carried out on the basis of legitimate interests;
- request portability of data you provided to us; and
- withdraw consent, where processing is based on consent, without affecting prior processing.
To exercise a right, email support@itsm-ltd.com. We will respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies. There is normally no charge.
Where we act as a processor (content entered into the App’s macros), please direct your request to the Atlassian customer whose site holds the data — normally your own organisation’s administrator. We will assist that customer in responding.
Complaints. If you are dissatisfied with how we have handled your personal data, please tell us first at support@itsm-ltd.com; we operate a complaints procedure and will acknowledge your complaint within 5 business days and respond substantively within 30 days. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post to Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
13. Notice to residents of California
If you are a California resident, you have rights under the California Consumer Privacy Act as amended, including rights to know, delete, correct and opt out. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not process personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes requiring an opt-out. To exercise a right, contact support@itsm-ltd.com; we will not discriminate against you for doing so.
14. Children
The App is a business tool licensed to organisations and is not directed at children. We do not knowingly process the personal data of anyone under 18 in connection with the App.
15. Changes to this policy
We may update this policy from time to time. Material changes will be notified by updating the effective date above and, where the change materially affects your rights, by notice in the manner set out in clause 13.3 of the End User Terms at least 30 days before the change takes effect. Previous versions are available on request.
This Privacy Policy is published in accordance with the Atlassian Marketplace Partner Agreement. It should be read alongside the End User Terms, the Cloud Security Statement and the Support and Maintenance Description for ServiceAccord.