CFR Dashboard — Privacy Policy

Effective: 29 September 2026 · Last updated: 29 September 2026

1. Who we are

The CFR Dashboard app for Atlassian Jira Cloud (the "App") is developed and operated by Gergely Orbán, sole proprietor, Hungary ("Provider", "we"). The App processes data in your Jira projects on your instructions and according to your settings. For that processing, you (the customer) are the data controller and we are the data processor.

2. What data the App processes

2.1 Jira data

Using the read:jira-work scope, the App reads:

2.2 Git repository data

From the Git provider the customer configured (GitHub, Bitbucket Cloud, GitLab.com or Azure Repos), using the customer's own access token, the App retrieves the commit SHA, commit message and commit date. Author names and e-mail addresses are not stored. Commit messages are free text and may incidentally contain a person's name.

2.3 Credentials

An administrator provides the Git provider access token and, optionally, credentials for the chosen export destination (Google BigQuery service account key or Amazon S3 access key). These are stored in Forge's encrypted secret storage and are never displayed again after saving.

2.4 What we do not collect

The App has no analytics, sets no cookies of its own and collects no browsing or device data about its users.

3. Purpose

Data is processed solely to provide the App's function: calculating Change Failure Rate and Mean Time to Restore and, at your request, exporting the underlying events.

4. Where data is stored and for how long

DataWhereRetention
Project configuration (provider, repository, time window)Forge Key-Value Store on Atlassian's Forge infrastructureWhile the App is installed or until an administrator deletes it
Access token / export credentialsForge Key-Value Store, encrypted secret storageUntil replaced or deleted, or the App is uninstalled
Calculated dashboard result (cache)Forge Key-Value StoreUp to 15 minutes
Last-sync timestamp and sync progress markerForge Key-Value StoreWhile the App is installed
Exported CSV / events sent to your BigQuery or S3Not stored by the App. CSV is generated in your browser; exported events go to the destination you configuredGoverned by your own data management

When the App is uninstalled, Atlassian removes its Forge storage under Forge's own data-deletion process.

5. Who we share data with

We do not share data with any other third party on our own initiative, do not sell it and do not use it for advertising.

6. International transfers

Because the App runs on Forge, hosting location and any resulting transfers are governed by Atlassian's own documentation. If you choose a Git provider or export destination outside the European Economic Area, you are responsible for the resulting transfer as data controller, under the safeguards offered by those providers.

7. Access control

The App checks Jira permissions on the requesting user: viewing the dashboard requires permission to browse the project, and changing settings or triggering a sync requires project administrator permission.

8. Your rights

If a context field you selected contains personal data, data subjects can exercise their rights of access, rectification, erasure, restriction and objection, primarily towards you as controller. We will assist you within a reasonable time on request.

9. Security

The App relies on Forge's built-in security: encrypted secret storage, credentials never redisplayed after saving, and the minimum Jira scopes needed (read:jira-work, storage:app). Report suspected vulnerabilities to security@cfrdashboard.app.

10. Contact and complaints

Privacy questions or requests: support@cfrdashboard.app. You may also complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, www.naih.hu) or to your local supervisory authority.

11. Changes

We will update this policy when the App's features change (for example a new Git provider or export destination) and will announce material changes through the Atlassian Marketplace listing.