Privacy Policy

Last updated: 25 June 2026

Summary

Access Review & Audit Trail for Jira ("the App") is an Atlassian Forge app published by DVLS Labs ("we", "us"). The App runs entirely on Atlassian's infrastructure. It does not send your data to any external server, third-party service, or analytics provider. All data the App reads and stores remains inside your Atlassian cloud environment.

1. Who we are

DVLS Labs is the developer of the App and acts as a data processor on behalf of you, the Atlassian customer, who remains the data controller of your Jira data. Contact: support@dvlslabs.com.

2. What data the App accesses

The App uses read-only Jira permission scopes. It reads only the metadata needed to compute access reviews:

  • Group memberships — which accounts belong to which Jira groups.
  • Project roles — which accounts and groups hold which project roles.
  • Project permission schemes — which principals are granted which permissions on which projects.
  • Audit log records — permission-change events, used to enrich the change history.
  • Account identifiers — Atlassian account IDs, display names, and avatar URLs needed to label who holds access.

The App does not read issue content, comments, attachments, worklogs, or any business data inside your projects.

3. What data the App stores, and where

To produce a diff between reviews, the App stores snapshots of the permission metadata listed above in Forge SQL — a managed database provided by Atlassian and hosted within Atlassian's cloud infrastructure. This includes:

  • Access "edges" (who has what access) per snapshot.
  • Change events (grants added or removed between snapshots).
  • Review cycles and reviewer sign-off (attestation) records, including the reviewer's account ID and a timestamp.
  • Principal labels (account/group/project IDs and display names) for readability.

No data is stored on DVLS Labs servers, because DVLS Labs operates no servers for this App. We have no independent copy of your data.

4. No data egress

The App declares no external (egress) network domains. It cannot, by design, transmit your data outside Atlassian. Reports (CSV and PDF) are generated locally in your browser and downloaded directly to your device — they are not routed through any external service.

5. Sub-processors

The only sub-processor is Atlassian, which hosts the App runtime and the Forge SQL database under its own privacy and security commitments. We use no other sub-processors, no third-party analytics, and no advertising or tracking technologies.

6. Data retention and deletion

Snapshots and review history are retained so that the App can show change over time and preserve audit evidence beyond Jira's native 180-day audit-log limit. When you uninstall the App, the associated Forge SQL data is removed by Atlassian in accordance with the Forge data-retention lifecycle. You may also request deletion of stored review data at any time by contacting us.

7. Legal basis & your rights (GDPR)

Because the App processes data only on your instruction and within your Atlassian environment, you (the controller) determine the legal basis for processing. As the App holds no independent copy of your data, requests to access, correct, or delete personal data are fulfilled directly within your Atlassian instance, or by uninstalling the App. We will assist with any such request — contact support@dvlslabs.com.

8. Changes to this policy

We may update this policy as the App evolves. Material changes will be reflected by the "Last updated" date above and, where appropriate, in the App's release notes.

9. Contact

Questions about privacy or data handling: support@dvlslabs.com