The short version. This app runs entirely on Atlassian's own infrastructure. Your data never leaves Atlassian, is never sent to us or to any third party, is never used for analytics or advertising, and is deleted when you uninstall the app.
Comment Audit Trail for Jira (the "App") is provided by Loggard (the "Provider", "we", "us"), established in Spain. For any question about this policy, contact privacy@loggard.com.
Under the EU General Data Protection Regulation (GDPR) and the Spanish Organic Law 3/2018 (LOPDGDD), the organisation that installs the App on its Atlassian site is the data controller. We act solely as a data processor, processing data only as needed to provide the App's functionality.
We do not determine the purposes of the processing, and we do not use the data for any purpose of our own.
The App exists to preserve a record of changes made to Jira comments — something Jira itself does not retain. To do that, it stores the following each time a comment is created, edited or deleted:
| Data | Why it is needed |
|---|---|
| Comment text | The plain-text content of each version. This is the record itself — without it there is no audit trail. |
| Atlassian account ID | Identifies who made each change. |
| Display name | Shown in the history so the record is readable. |
| Timestamps | When each version was created, to the second. |
| Issue and comment IDs | Links each record to the right Jira issue. |
Important: comment text may contain personal data if your users write personal data in comments. The App cannot know this in advance, and stores whatever the comment contained. This is inherent to the App's purpose and should be considered in your own records of processing.
The App is built on Atlassian Forge and qualifies for the Runs on Atlassian programme. All data is stored in Atlassian's own hosted storage, inside Atlassian's infrastructure and subject to Atlassian's security controls and data residency arrangements.
We operate no servers and no database of our own. The data is never transmitted to Loggard, never leaves Atlassian's environment, and is not accessible to us.
For the data the App processes, Atlassian Pty Ltd is our only sub-processor, in its capacity as the provider of the Forge platform and its storage. The App engages no other sub-processor: no analytics provider, no logging service, no advertising network, no third-party API.
Separately from the App, if you write to us for support or privacy enquiries, that correspondence is handled by our email provider, Zoho Corporation, on servers in the European Union. This covers only what you choose to send us by email. It gives Zoho no access of any kind to the records the App stores, which never leave Atlassian's infrastructure.
The history is not visible to everyone who can open an issue. It can only be viewed by users who hold the "Edit All Comments" permission in the relevant Jira project — typically project administrators and leads.
The App is read-only by design: it exposes no function to alter or delete a record. Neither an administrator nor the Provider can modify a stored entry.
The App requests two Atlassian scopes:
read:jira-work — required by Atlassian in order to receive comment events. Atlassian does not accept a narrower scope for these events.storage:app — to store records in the App's own Forge storage.The App requests no write or delete permission of any kind. It is technically incapable of modifying or removing anything in Jira.
Because we act as a processor, requests to access, rectify, erase, restrict or port personal data should be addressed to the organisation that installed the App — your Jira administrator — who is the controller. We will assist that organisation in responding to such requests as required by Article 28 GDPR.
Deleting a Jira comment does not erase its stored history: that is the entire purpose of an audit trail. To remove records, the controller must uninstall the App, after which Atlassian deletes the stored data.
Security rests on the Forge platform: data is encrypted at rest and in transit by Atlassian, the App runs in Atlassian's sandboxed runtime, and no credentials or data are held outside it. We hold no copy of your data and therefore cannot lose, leak or be compelled to disclose one.
If this policy changes materially, we will update the date at the top of this page and note the change in the App's Marketplace listing.
Loggard — privacy@loggard.com
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) or your local supervisory authority.