Customer Privacy Policy
Last revision date – May 5, 2026.
In this Customer Privacy Policy you will find information about how we may process your personal data and what rights you have during the processing when you use our Apps and your company acts as the Customer of Broken Build under the EULA.
Via Atlassian Marketplace, we provide two types of Apps. We provide Cloud Apps designed to be used with Atlassian’s hosted services. Our Cloud Apps are built and hosted on Atlassian Forge, and the app functionality, calculations, data processing, and storage necessary for those Apps are performed on Atlassian Forge and Forge-hosted storage. We also provide Software Apps that are downloadable for the Customer’s data center. This Customer Privacy Policy applies to all types of our Apps.
Broken Build mostly processes data of the Customers and End Users of the Apps as a data processor. This applies to the data we receive from your company (our Customer) as the controller. Such practices are strictly limited to those allowed by the Atlassian Marketplace Partner Agreement. Although the data shared with us to provide Services to our Customers may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice. Our rights and obligations, as well as the details on the transferred data are described in detail in our data processing agreement with your company.
In other cases, Broken Build is the data controller of personal data. This means that we decide what data should be processed, how and why. Such cases are limited to entering into the agreement, certain cases of improvement of our Apps and some marketing activities. For more details please check the tables below and our Marketing Privacy Policy.
Who we are
When we refer to Broken Build, we mean Broken Build LLP, a company registered in the United Kingdom (OC445385) with a registered address at 61 Bridge Street, Kington, Herefordshire, HR53DJ, United Kingdom.
If you have questions, concerns, or complaints, or would like to exercise your rights, we are available at security@brokenbuild.net.
You can also complain to the ICO if you are unhappy with how we have used your personal data.
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Helpline number: 0303 123 1113
Detailed description of how we process your data
In the tables below you will find a detailed information about:
our role in data processing and to which Apps it relates;
what data we may process;
purposes of processing your data;
legal basis for the processing of your data (where we act as the controller);
retention period of your data; and
engaged sub-processors.
The data we process is both the data of your company (our Customer under the EULA) and you (End User, for whom the Customer has paid the required fees and to whom access is given to the App). Please keep in mind that we process both “personal data” within the meaning of law (relates to identified or identifiable person) and other data that is not “personal data”. Such non-personal data could still be regarded as “End User Data” within the meaning of the Atlassian Marketplace Partner Agreement. For your convenience, below we describe our processing with regard to all types of data we process, marking separately when the data is personal.
The information below is classified by the purpose of data processing:
To implement the Apps functionality | ||
Agile Velocity Chart Gadget | ||
Role of Broken Build: processor | ||
Which Service it relates to: Cloud Apps | ||
Processing we perform | Data we process | Legal basis for the processing |
Implement the App’s functionality.
| Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:
End User data stored (does not contain personal data):
End User data processed:
| Not applicable (data is provided to perform obligations before the Customer under the EULA, as described in the DPA)
|
Data retention period: data may be processed and stored during the term of EULA and up to 12 months after the termination of EULA. | ||
Sub-processors engaged:
| ||
To implement the Apps functionality | ||
Agile Reports and Gadgets | ||
Role of Broken Build: processor | ||
Which Service it relates to: Cloud Apps | ||
Processing we perform | Data we process | Legal basis for the processing |
Implement the App’s functionality.
| Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:
End User data stored (does not contain personal data):
End User data processed:
| Not applicable (data is provided to perform obligations before the Customer under the EULA, as described in the DPA)
|
Data retention period: data may be processed and stored during the term of EULA and up to 12 months after the termination of EULA. | ||
Sub-processors engaged:
| ||
To implement the Apps functionality | ||
Subcomponents for Jira Cloud | ||
Role of Broken Build: processor | ||
Which Service it relates to: Cloud Apps | ||
Processing we perform | Data we process | Legal basis for the processing |
Implement the App’s functionality.
| Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:
End User data stored (does not contain personal data):
End User data processed:
| Not applicable (data is provided to perform obligations before the Customer under the EULA, as described in the DPA)
|
Data retention period: data may be processed and stored during the term of EULA and up to 12 months after the termination of EULA. | ||
Sub-processors engaged:
| ||
To implement the Apps functionality | ||
Cycle Time Gadget | ||
Role of Broken Build: processor | ||
Which Service it relates to: Cloud Apps | ||
Processing we perform | Data we process | Legal basis for the processing |
Implement the App’s functionality.
| Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:
End User data stored (does not contain personal data):
End User data processed:
| Not applicable (data is provided to perform obligations before the Customer under the EULA, as described in the DPA)
|
Data retention period: data may be processed and stored during the term of EULA and up to 12 months after the termination of EULA. | ||
Sub-processors engaged:
| ||
To implement the Apps functionality | ||
Forecast Gadget | ||
Role of Broken Build: processor | ||
Which Service it relates to: Cloud Apps | ||
Processing we perform | Data we process | Legal basis for the processing |
Implement the App’s functionality.
| Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:
End User data stored (does not contain personal data):
End User data processed:
| Not applicable (data is provided to perform obligations before the Customer under the EULA, as described in the DPA)
|
Data retention period: data may be processed and stored during the term of EULA and up to 12 months after the termination of EULA. | ||
Sub-processors engaged:
| ||
To implement the Apps functionality | ||
Cumulative Flow Diagram | ||
Role of Broken Build: processor | ||
Which Service it relates to: Cloud Apps | ||
Processing we perform | Data we process | Legal basis for the processing |
Implement the App’s functionality.
| Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:
End User data stored (does not contain personal data):
End User data processed:
| Not applicable (data is provided to perform obligations before the Customer under the EULA, as described in the DPA)
|
Data retention period: data may be processed and stored during the term of EULA and up to 12 months after the termination of EULA. | ||
Sub-processors engaged:
| ||
To implement the Apps functionality | ||
Monte Carlo Forecast | ||
Role of Broken Build: processor | ||
Which Service it relates to: Cloud Apps | ||
Processing we perform | Data we process | Legal basis for the processing |
Implement the App’s functionality.
| Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:
End User data stored (does not contain personal data):
End User data processed:
| Not applicable (data is provided to perform obligations before the Customer under the EULA, as described in the DPA)
|
Data retention period: data may be processed and stored during the term of EULA and up to 12 months after the termination of EULA. | ||
Sub-processors engaged:
| ||
To implement the Apps functionality | ||
Throughput Chart | ||
Role of Broken Build: processor | ||
Which Service it relates to: Cloud Apps | ||
Processing we perform | Data we process | Legal basis for the processing |
Implement the App’s functionality.
| Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:
End User data stored (does not contain personal data):
| |