Customer Privacy Policy

Customer Privacy Policy

Last revision date – May 5, 2026.

 

In this Customer Privacy Policy you will find information about how we may process your personal data and what rights you have during the processing when you use our Apps and your company acts as the Customer of Broken Build under the EULA. 

Via Atlassian Marketplace, we provide two types of Apps. We provide Cloud Apps designed to be used with Atlassian’s hosted services. Our Cloud Apps are built and hosted on Atlassian Forge, and the app functionality, calculations, data processing, and storage necessary for those Apps are performed on Atlassian Forge and Forge-hosted storage. We also provide Software Apps that are downloadable for the Customer’s data center. This Customer Privacy Policy applies to all types of our Apps.

Broken Build mostly processes data of the Customers and End Users of the Apps as a data processor. This applies to the data we receive from your company (our Customer) as the controller. Such practices are strictly limited to those allowed by the Atlassian Marketplace Partner Agreement. Although the data shared with us to provide Services to our Customers may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice. Our rights and obligations, as well as the details on the transferred data are described in detail in our data processing agreement with your company. 

In other cases, Broken Build is the data controller of personal data. This means that we decide what data should be processed, how and why. Such cases are limited to entering into the agreement, certain cases of improvement of our Apps and some marketing activities. For more details please check the tables below and our Marketing Privacy Policy

Who we are

When we refer to Broken Build, we mean Broken Build LLP, a company registered in the United Kingdom (OC445385) with a registered address at 61 Bridge Street, Kington, Herefordshire, HR53DJ, United Kingdom. 

If you have questions, concerns, or complaints, or would like to exercise your rights, we are available at security@brokenbuild.net.

You can also complain to the ICO if you are unhappy with how we have used your personal data.

Information Commissioner’s Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom

Helpline number: 0303 123 1113

Detailed description of how we process your data

In the tables below you will find a detailed information about:

  • our role in data processing and to which Apps it relates;

  • what data we may process;

  • purposes of processing your data;

  • legal basis for the processing of your data (where we act as the controller);

  • retention period of your data; and

  • engaged sub-processors.

 

The data we process is both the data of your company (our Customer under the EULA) and you (End User, for whom the Customer has paid the required fees and to whom access is given to the App). Please keep in mind that we process both “personal data” within the meaning of law (relates to identified or identifiable person) and other data that is not “personal data”. Such non-personal data could still be regarded as “End User Data” within the meaning of the Atlassian Marketplace Partner Agreement. For your convenience, below we describe our processing with regard to all types of data we process, marking separately when the data is personal.

 

The information below is classified by the purpose of data processing:

To implement the Apps functionality

Agile Velocity Chart Gadget

Role of Broken Build: processor

Which Service it relates to: Cloud Apps 

Processing we perform

Data we process

Legal basis for the processing

Implement the App’s functionality.

 

Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:

 

End User data stored (does not contain personal data):

  • Board ID

  • Project ID

  • Issue ID

  • Issue type ID

  • Issue custom field ID

  • Issue status name

  • Anonymized user ID

 

End User data processed:

  • Anonymized user ID

  • Jira issue standard fields:

    • Issue key

    • Issue type

    • Issue status

    • Assignee (anonymized user ID, username, full name, URL to avatar, status) - personal data

    • Sprint ID

    • Created date

    • Reporter  (anonymized user ID, username, full name, URL to avatar, status) - personal data

    • Changelog - may contain personal data

  • App (chart) configuration including:

    • Chart title

    • JQL filter - may contain personal data

Not applicable

(data is provided to perform obligations before the Customer under the EULA, as described in the DPA)

 

Data retention period: data may be processed and stored during the term of EULA and up to 12 months after the termination of EULA. 

Sub-processors engaged:

  • Atlassian Forge (Atlassian Pty Ltd) aims to host the App and perform the app functionality, calculations, data processing, and storage necessary for the App to properly function.

To implement the Apps functionality

Agile Reports and Gadgets

Role of Broken Build: processor

Which Service it relates to: Cloud Apps 

Processing we perform

Data we process

Legal basis for the processing

Implement the App’s functionality.

 

Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:

 

End User data stored (does not contain personal data):

  • Board ID

  • Project ID

  • Issue ID

  • Issue type ID

  • Issue custom field ID

  • Issue status name

  • Anonymized user ID

 

End User data processed:

  • Anonymized user ID

  • Jira issue standard fields:

    • Issue key

    • Issue type

    • Issue status

    • Assignee (anonymized user ID, username, full name, URL to avatar, status) - personal data

    • Sprint ID

    • Created date

    • Reporter  (anonymized user ID, username, full name, URL to avatar, status) - personal data

    • Changelog - may contain personal data

  • App (chart) configuration including:

    • Chart title

    • JQL filter - may contain personal data

Not applicable

(data is provided to perform obligations before the Customer under the EULA, as described in the DPA)

 

Data retention period: data may be processed and stored during the term of EULA and up to 12 months after the termination of EULA. 

Sub-processors engaged:

  • Atlassian Forge (Atlassian Pty Ltd) aims to host the App and perform the app functionality, calculations, data processing, and storage necessary for the App to properly function.

To implement the Apps functionality

Subcomponents for Jira Cloud

Role of Broken Build: processor

Which Service it relates to: Cloud Apps 

Processing we perform

Data we process

Legal basis for the processing

Implement the App’s functionality.

 

Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:

 

End User data stored (does not contain personal data):

  • Anonymized user ID

  • Project ID

  • Project component ID

  • Project version ID

 

End User data processed:

  • Anonymized user ID

  • Jira project details

  • Jira project components

  • Jira project versions

  • App configuration settings including:

    • Feature enablement status

Not applicable

(data is provided to perform obligations before the Customer under the EULA, as described in the DPA)

 

Data retention period: data may be processed and stored during the term of EULA and up to 12 months after the termination of EULA. 

Sub-processors engaged:

  • Atlassian Forge (Atlassian Pty Ltd) aims to host the App and perform the app functionality, calculations, data processing, and storage necessary for the App to properly function.

To implement the Apps functionality

Cycle Time Gadget

Role of Broken Build: processor

Which Service it relates to: Cloud Apps 

Processing we perform

Data we process

Legal basis for the processing

Implement the App’s functionality.

 

Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:

 

End User data stored (does not contain personal data):

  • Board ID

  • Project ID

  • Issue ID

  • Issue type ID

  • Issue custom field ID

  • Issue status name

  • Anonymized user ID

 

End User data processed:

  • Anonymized user ID

  • Jira issue standard fields:

    • Issue key

    • Issue type

    • Issue status

    • Assignee (anonymized user ID, username, full name, URL to avatar, status) - personal data

    • Sprint ID

    • Created date

    • Reporter  (anonymized user ID, username, full name, URL to avatar, status) - personal data

    • Changelog - may contain personal data

  • App (chart) configuration including:

    • Chart title

    • JQL filter - may contain personal data

Not applicable

(data is provided to perform obligations before the Customer under the EULA, as described in the DPA)

 

Data retention period: data may be processed and stored during the term of EULA and up to 12 months after the termination of EULA. 

Sub-processors engaged:

  • Atlassian Forge (Atlassian Pty Ltd) aims to host the App and perform the app functionality, calculations, data processing, and storage necessary for the App to properly function.

To implement the Apps functionality

Forecast Gadget

Role of Broken Build: processor

Which Service it relates to: Cloud Apps 

Processing we perform

Data we process

Legal basis for the processing

Implement the App’s functionality.

 

Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:

 

End User data stored (does not contain personal data):

  • Board ID

  • Project ID

  • Issue ID

  • Issue type ID

  • Issue custom field ID

  • Issue status name

  • Anonymized user ID

 

End User data processed:

  • Anonymized user ID

  • Jira issue standard fields:

    • Issue key

    • Issue type

    • Issue status

    • Assignee (anonymized user ID, username, full name, URL to avatar, status) - personal data

    • Sprint ID

    • Created date

    • Reporter  (anonymized user ID, username, full name, URL to avatar, status) - personal data

    • Changelog - may contain personal data

  • App (chart) configuration including:

    • Chart title

    • JQL filter - may contain personal data

Not applicable

(data is provided to perform obligations before the Customer under the EULA, as described in the DPA)

 

Data retention period: data may be processed and stored during the term of EULA and up to 12 months after the termination of EULA. 

Sub-processors engaged:

  • Atlassian Forge (Atlassian Pty Ltd) aims to host the App and perform the app functionality, calculations, data processing, and storage necessary for the App to properly function.

To implement the Apps functionality

Cumulative Flow Diagram

Role of Broken Build: processor

Which Service it relates to: Cloud Apps 

Processing we perform

Data we process

Legal basis for the processing

Implement the App’s functionality.

 

Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:

 

End User data stored (does not contain personal data):

  • Board ID

  • Project ID

  • Issue ID

  • Issue type ID

  • Issue custom field ID

  • Issue status name

  • Anonymized user ID

 

End User data processed:

  • Anonymized user ID

  • Jira issue standard fields:

    • Issue key

    • Issue type

    • Issue status

    • Assignee (anonymized user ID, username, full name, URL to avatar, status) - personal data

    • Sprint ID

    • Created date

    • Reporter  (anonymized user ID, username, full name, URL to avatar, status) - personal data

    • Changelog - may contain personal data

  • App (chart) configuration including:

    • Chart title

    • JQL filter - may contain personal data

Not applicable

(data is provided to perform obligations before the Customer under the EULA, as described in the DPA)

 

Data retention period: data may be processed and stored during the term of EULA and up to 12 months after the termination of EULA. 

Sub-processors engaged:

  • Atlassian Forge (Atlassian Pty Ltd) aims to host the App and perform the app functionality, calculations, data processing, and storage necessary for the App to properly function.

To implement the Apps functionality

Monte Carlo Forecast

Role of Broken Build: processor

Which Service it relates to: Cloud Apps 

Processing we perform

Data we process

Legal basis for the processing

Implement the App’s functionality.

 

Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:

 

End User data stored (does not contain personal data):

  • Board ID

  • Project ID

  • Issue ID

  • Issue type ID

  • Issue custom field ID

  • Issue status name

  • Anonymized user ID

 

End User data processed:

  • Anonymized user ID

  • Jira issue standard fields:

    • Issue key

    • Issue type

    • Issue status

    • Assignee (anonymized user ID, username, full name, URL to avatar, status) - personal data

    • Sprint ID

    • Created date

    • Reporter  (anonymized user ID, username, full name, URL to avatar, status) - personal data

    • Changelog - may contain personal data

  • App (chart) configuration including:

    • Chart title

    • JQL filter - may contain personal data

Not applicable

(data is provided to perform obligations before the Customer under the EULA, as described in the DPA)

 

Data retention period: data may be processed and stored during the term of EULA and up to 12 months after the termination of EULA. 

Sub-processors engaged:

  • Atlassian Forge (Atlassian Pty Ltd) aims to host the App and perform the app functionality, calculations, data processing, and storage necessary for the App to properly function.

To implement the Apps functionality

Throughput Chart

Role of Broken Build: processor

Which Service it relates to: Cloud Apps 

Processing we perform

Data we process

Legal basis for the processing

Implement the App’s functionality.

 

Although data shared to achieve that purpose may include personal data, accessing personal data is not our main objective. In some instances, access to personal data is purely incidental and therefore very limited in practice to:

 

End User data stored (does not contain personal data):

  • Board ID

  • Project ID