Capacity Compass Privacy Policy
Effective date: [TO COMPLETE: effective date]
This policy explains how Capacity Compass, a Jira Cloud app published by Trisolas Inc. ("Trisolas", "we", "us"), handles data. It covers the app as installed from the Atlassian Marketplace.
The short version
- Capacity Compass is built on Atlassian Forge. It runs on Atlassian's cloud infrastructure, and everything it stores sits in Forge-hosted storage that belongs to your Jira site's installation.
- The app sends no data to Trisolas servers or to any third party. We operate no external backend, database, analytics or tracking service for the app.
- The app only reads from Jira. It has no Jira write permission and cannot change issues, boards, projects or workflows.
- The app stores some personal data: Jira account IDs and display names of the people added to plans, the capacity figures recorded for them, and the account IDs of people who make certain changes. Details are in "What the app stores" below.
- We do not sell data, use it for advertising, or use it to profile anyone.
Roles
For the data your organization puts into or processes with Capacity Compass, your organization (the Atlassian customer that installed the app) decides what is processed and why. Under the GDPR and similar laws, your organization is the controller and Trisolas acts as a processor on its behalf.
Atlassian provides the Forge platform the app runs on, including hosting, storage and logging. Atlassian's handling of that data is governed by your agreement with Atlassian and the Atlassian Privacy Policy.
Trisolas is the controller for information you send to us directly, such as support requests.
How the app works
Capacity Compass runs as a Forge app inside Jira:
- The screens you see are served by Atlassian and shown inside Jira.
- The app's backend functions run on Atlassian's Forge runtime.
- The app's data is stored in Forge SQL, a database that Atlassian provisions separately for each installation. One customer's data is not visible to another customer's installation.
- The app declares no external network destinations, remote backends or external storage.
What the app reads from Jira
The app reads the following through Jira's APIs to calculate capacity and show plans. Unless it is listed under "What the app stores", this information is used while a request is being handled and is not saved by the app.
| Jira data | Used for |
|---|---|
| Boards and projects | Listing boards that can be planned, and telling Scrum boards from Kanban boards |
| Sprints | Sprint names, dates and state, which set the planning window |
| Users | Account ID, display name and avatar, to find people and add them to a plan |
| Issues in the sprint being planned | Key, summary, type, status, assignee and the chosen estimate field, to work out each person's assigned load |
| Time spent, or a time field you select | Comparing logged time against planned time, if you turn this on |
| Fields and field configuration | Letting you choose which fields hold estimates and logged time |
| Your Jira permissions | Checking whether you may change board availability or site settings |
| Your site's licence status | Checking that a trial or subscription is active. Not stored |
Depending on a person's Atlassian profile visibility settings, Jira's user API may also return an email address. Capacity Compass does not use or store email addresses.
The app reads issues only for the sprint being planned, not your whole backlog. It does not read comments, attachments, descriptions or issue history.
What the app stores
The app stores the following in your installation's Forge SQL database.
| Stored data | Contents | Personal data involved |
|---|---|---|
| Plans | Plan name, project and board identifiers and names, sprint identifier and name, dates, status | Account ID of the person who created the plan |
| Plan members | The people in a plan and the capacity recorded for each | Account ID, display name, capacity hours or status |
| Activities and attendance | Meeting and activity names, categories, hours, recurrence, optional notes, and who attends | Account IDs of attendees and their hours. Names and notes are free text, so they contain whatever users type |
| Plan and board settings | Estimate field, point-to-hours conversion, logged-time source, default hours, standing meetings | None |
| Board availability and site settings | Which boards are enabled, with board name and project key, and the site default | Account ID of the administrator who last changed a setting |
| Sprint snapshots | Captured at sprint start and sprint close to show how sprints landed | At sprint start: the keys and estimates of issues in the sprint, no summaries. At sprint close: totals plus, for each member, account ID, display name, meeting hours and compared estimated and logged hours |
| Timestamps | When records were created and last changed | Linked to the records above |
The app does not store issue summaries, descriptions, comments, attachments, worklog entries, avatars or email addresses.
Capacity Compass is a planning tool. It does not calculate productivity scores, rank individuals or compare people's delivery. Per-person figures exist so that plans reflect real availability.
Personal data your users type
Plan names, activity names and notes are free text. Avoid entering sensitive personal information in them, such as health details behind an absence. Record availability as hours, not reasons.
Data stored in your browser
The app does not set cookies. It saves two preferences in your browser's local storage, inside the frame where Jira shows the app:
| Key | Contents | Purpose |
|---|---|---|
co.plannerMode |
scm or person |
Remembers which view of a plan you last used |
co.plannerIdentity |
A Jira account ID | Remembers which plan member you are, if Jira did not supply your identity and you chose it manually |
These values stay on your device, are never sent to Trisolas, and can be removed by clearing your browser's site data. Jira and Atlassian set their own cookies, which are covered by Atlassian's policies. See the Capacity Compass Cookie Notice.
Operational logs
The app writes operational logs to Atlassian's Forge logging service so we can find and fix faults. By design these logs contain only technical information, such as the operation name, a random reference, timings, call counts and error codes. The app's logging code rejects names, email addresses, account IDs, issue keys, user-entered text, queries and request contents.
Atlassian also attaches its own metadata to Forge logs, such as the site, app version and function involved. Atlassian keeps these logs for a limited period under its own policies.
Atlassian lets developers see logs for sites that allow log sharing. Your site administrator can turn log sharing off in Atlassian Administration at any time. If you do, we can no longer see logs from your site, and troubleshooting may need your help.
Installation and licensing information from Atlassian
When your organization installs, tries or subscribes to Capacity Compass, Atlassian gives us information about that installation through its developer and Marketplace partner tools:
| Information | Examples |
|---|---|
| Installation details | Which Jira sites have the app installed, the site address and cloud ID, the app version and when it was installed |
| Licence details | Licence status, trial and subscription dates, user tier and the Marketplace entitlement number (SEN) |
| Contacts, for trials and paid subscriptions | The technical and billing contacts on your Marketplace order, such as name, email address and organization name |
We use this information to manage licences, answer billing questions, provide support, and send service messages, such as security notices, price changes and changes to these documents. We do not send marketing email to these contacts without their consent.
Trisolas is the controller for this information. It is held in Atlassian's partner tools and, where we need it for support or accounting, in our own email and accounting systems. We keep it while your organization is a customer, and afterwards for as long as accounting, tax and other legal obligations require.
What we do not do
- We do not transfer app data out of Atlassian's infrastructure.
- We do not sell, rent or trade personal data.
- We do not use app data for advertising, marketing, profiling or automated decision-making.
- We do not run analytics or tracking in the app.
- We do not use app data to train machine-learning models.
Where data is stored
App data is stored in Forge-hosted storage in Atlassian's cloud. Because all of the app's data is held in Forge-hosted storage, it follows your Jira site's data residency location where Atlassian supports data residency for Forge apps. Operational logs are handled by Atlassian and may not follow your data residency location.
Atlassian operates and secures this infrastructure, including encryption in transit and at rest, under its own security program. See the Atlassian Trust Center.
Who can see the data
People in your Jira site. Capacity Compass appears in Jira software projects, and Jira shows it only to people who can access that project. Within a project, anyone who can open the app can view, create and change plans and board settings for the boards where the app is available, and report their own availability. Turning the app on or off for a board requires the Administer projects permission, and site-wide settings require Administer Jira. The app enforces these rules on its server, not only in the interface. Availability a person reports is visible to anyone who can open that plan.
Trisolas. The app gives us no way to view, query or export the data stored in your installation in production, and we keep no copy of it. We see operational logs and installation information as described above, and anything you choose to send us, such as screenshots in a support request. Before sending screenshots, logs or other files, please remove personal data we do not need, such as the names of people not involved in the problem.
Atlassian. Atlassian hosts and processes the data as the Forge platform provider.
Service providers
| Provider | Role | Data |
|---|---|---|
| Atlassian | Forge platform: hosting, storage, logging | All app data and logs |
| Atlassian | Marketplace: ordering, billing and licensing | Installation, licence and order contact information |
| [TO COMPLETE: email provider, e.g. Google Workspace] | Our email | Support requests and other messages you send us |
Atlassian is our only sub-processor for app data.
Retention and deletion
While the app is installed, stored data is kept until someone deletes it. The app does not delete old plans or snapshots automatically.
- Deleting a plan permanently removes the plan, its members, activities, attendance, settings and sprint snapshots.
- Removing a person from a plan removes their membership of that plan. Sprint snapshots already captured for that plan keep their record until the plan is deleted.
- Board and site settings stay until they are changed.
When the app is uninstalled, Atlassian marks the app's stored data for deletion. Atlassian keeps it for a short period, currently 28 days, and then permanently deletes it. If the app is reinstalled within 21 days, the earlier data can be reconnected to the new installation at your organization's request. After that period it cannot be recovered. These periods are set by Atlassian and may change, so treat Atlassian's data lifecycle for Forge-hosted storage as the current source. Nothing is left in Jira, because the app never wrote to Jira.
Browser preferences remain in the browser until they are cleared.
Closed and changed Atlassian accounts
Capacity Compass stores a person's display name as it was when the person was added to a plan. It does not yet check Atlassian for closed or changed accounts automatically, so a stored name is not refreshed if the person later changes it in their Atlassian profile.
Until automatic checks are available, to have a person's data corrected or removed, delete or edit the affected plans, or contact us and we will help your administrator do it.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to receive it in a portable form, and to complain to a data protection authority.
Your organization controls the data in Capacity Compass, so contact your Jira site administrator first. Plans, members and activities can be edited and deleted inside the app. If a request cannot be met from inside the app, the administrator can contact us.
How to send a request
Email privacy@trisolas.com with the subject "Privacy request: Capacity Compass" and include:
- your Jira site address, for example
your-company.atlassian.net; - your Atlassian account ID or the email address of your Atlassian account;
- the right you want to exercise;
- any details that help us find the data, such as the project, board or plan.
We may ask you to confirm your identity or your authority to act for your organization. We will respond within one month. If a request is complex or we receive many, we may extend this by up to two further months, and we will tell you within the first month if we do.
If you contact us directly about data your organization controls, we will pass your request to your organization, because we cannot see or change its data ourselves. We answer requests about information we control, such as support messages and installation contacts, ourselves.
Security
The app runs within Atlassian's Forge security model and requests only read permissions in Jira. The app enforces its access rules on its server, not only in the interface, and we keep credentials out of source code. To report a security issue, email security@trisolas.com.
If we become aware of a security incident affecting data processed by the app, we will notify affected customers and Atlassian without undue delay and as required by law and Atlassian's Marketplace requirements.
International transfers
App data stays in Atlassian's infrastructure and does not move to Trisolas. Where Atlassian transfers data internationally, it does so under its own transfer mechanisms as described in its terms with your organization. For information you send us directly, such as support email, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses where required.
Children
Capacity Compass is a workplace tool for organizations. It is not directed at children.
Changes to this policy
If we change this policy, we will publish the new version on this page and update the effective date. If a change materially affects how the app handles data, we will announce it in the Marketplace listing or release notes before it takes effect.
Contact
Trisolas Inc.
Vancouver, British Columbia, Canada
Privacy: privacy@trisolas.com
Support: support@trisolas.com