Effective: 29 September 2026 · Last updated: 29 September 2026
The CFR Dashboard app for Atlassian Jira Cloud (the "App") is developed and operated by Gergely Orbán, sole proprietor, Hungary ("Provider", "we"). The App processes data in your Jira projects on your instructions and according to your settings. For that processing, you (the customer) are the data controller and we are the data processor.
Using the read:jira-work scope, the App reads:
KAN-123) that appear in commit messages;From the Git provider the customer configured (GitHub, Bitbucket Cloud, GitLab.com or Azure Repos), using the customer's own access token, the App retrieves the commit SHA, commit message and commit date. Author names and e-mail addresses are not stored. Commit messages are free text and may incidentally contain a person's name.
An administrator provides the Git provider access token and, optionally, credentials for the chosen export destination (Google BigQuery service account key or Amazon S3 access key). These are stored in Forge's encrypted secret storage and are never displayed again after saving.
The App has no analytics, sets no cookies of its own and collects no browsing or device data about its users.
Data is processed solely to provide the App's function: calculating Change Failure Rate and Mean Time to Restore and, at your request, exporting the underlying events.
| Data | Where | Retention |
|---|---|---|
| Project configuration (provider, repository, time window) | Forge Key-Value Store on Atlassian's Forge infrastructure | While the App is installed or until an administrator deletes it |
| Access token / export credentials | Forge Key-Value Store, encrypted secret storage | Until replaced or deleted, or the App is uninstalled |
| Calculated dashboard result (cache) | Forge Key-Value Store | Up to 15 minutes |
| Last-sync timestamp and sync progress marker | Forge Key-Value Store | While the App is installed |
| Exported CSV / events sent to your BigQuery or S3 | Not stored by the App. CSV is generated in your browser; exported events go to the destination you configured | Governed by your own data management |
When the App is uninstalled, Atlassian removes its Forge storage under Forge's own data-deletion process.
We do not share data with any other third party on our own initiative, do not sell it and do not use it for advertising.
Because the App runs on Forge, hosting location and any resulting transfers are governed by Atlassian's own documentation. If you choose a Git provider or export destination outside the European Economic Area, you are responsible for the resulting transfer as data controller, under the safeguards offered by those providers.
The App checks Jira permissions on the requesting user: viewing the dashboard requires permission to browse the project, and changing settings or triggering a sync requires project administrator permission.
If a context field you selected contains personal data, data subjects can exercise their rights of access, rectification, erasure, restriction and objection, primarily towards you as controller. We will assist you within a reasonable time on request.
The App relies on Forge's built-in security: encrypted secret storage, credentials never redisplayed after saving, and the minimum Jira scopes needed (read:jira-work, storage:app). Report suspected vulnerabilities to security@cfrdashboard.app.
Privacy questions or requests: support@cfrdashboard.app. You may also complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, www.naih.hu) or to your local supervisory authority.
We will update this policy when the App's features change (for example a new Git provider or export destination) and will announce material changes through the Atlassian Marketplace listing.