Privacy Policy — Vivid Connector for Jira and Telegram
How Vivid Insight handles personal data for Vivid Connector for Jira and Telegram, Marketplace administration, migration, security, and support.
- Effective date
- Version
- 1.0
- Product
- Vivid Connector for Jira and Telegram
Effective date: 31 July 2026 Version: 1.0
This Privacy Policy explains how VIVID INSIGHT UNIPESSOAL LDA, Portuguese tax number 517951371, with registered office at Rua Victor de Sá, 33, 4715-586 Braga, Portugal (“Vivid Insight”, “we”, “us”), handles personal data in connection with Vivid Connector for Jira and Telegram (Forge Edition) (the “App”), related Marketplace administration, and support.
1. Scope and roles
The App lets a Jira Cloud administrator connect a customer-owned Telegram bot, configure Telegram destinations, and send selected Jira issue/comment notifications or ticket-key replies to Telegram.
For Jira and Telegram content processed on a customer's documented instructions, the customer is normally the controller and Vivid Insight acts as processor/service provider. Vivid Insight acts as controller for its own Marketplace/vendor account records, legal and security communications, support contacts, billing-related records it receives, and compliance records. Specific contracts and applicable law may allocate these roles differently.
This Policy does not replace Atlassian's or Telegram's privacy terms. Customers administer their own Atlassian and Telegram environments and must provide their users with appropriate notices.
2. Data we process
Depending on configuration and use, the App processes:
Jira work data: issue key and ID, summary, description or comment text where present, issue type, status, priority, project, labels, components, versions, parent, timestamps, changes, and links.
Jira user data: Atlassian account identifiers in transient event/API data and display names for actors, assignees, reporters, commenters, or user-valued fields.
Telegram bot and chat data: bot token, bot identity, chat/channel ID, type, title, username, membership/access state, inbound message text containing candidate Jira keys, message ID, and Telegram API responses.
App configuration: selected projects and events, filter rules, channel active state, and ticket-parsing state.
Delivery and troubleshooting data: event type, issue key, destination label/identifier, pseudonymous notification fingerprint, delivery state, counts, timestamps, and bounded error/status information.
Legacy migration data: Jira site base URL and supported previous-app channel/filter configuration during administrator-initiated import.
Business/support data: name, business contact details, organization, correspondence, support content, and security/privacy request details supplied to us.
We do not request Atlassian passwords or personal access tokens. Telegram bot tokens and webhook secrets are stored using Forge secret storage and are not intentionally written to application logs.
3. Sources
Data comes from the customer's Jira Cloud site through Atlassian Forge events/APIs, from Telegram through the customer-owned bot, from administrators configuring the App, from the temporary previous-app migration service when an administrator requests import, and directly from people who contact us.
4. Purposes and legal bases
We process data to:
provide, secure, maintain, troubleshoot, and improve the contracted App;
evaluate configured routing/filter rules and deliver messages to customer-selected Telegram chats;
prevent duplicate delivery, apply rate limits, and retry transient failures;
verify subscription/license status and administer Marketplace obligations;
import supported previous-app settings at an administrator's request;
respond to support, privacy, legal, and security communications;
prevent abuse, investigate incidents, and comply with law.
Where we act as processor, we rely on the customer's instructions and Data Processing Addendum. Where we act as controller, legal bases may include performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where required.
5. Storage and recipients
App configuration, delivery metadata, recent activity, and secrets are stored in installation-scoped Atlassian Forge services. Atlassian provides the Forge runtime and hosted storage.
The App intentionally sends configured Jira notification content to Telegram. Telegram processes and may store those messages under the customer's Telegram setup and Telegram's terms. Uninstalling the App or deleting its token does not delete messages already held in Telegram chats.
During the temporary migration window, the App contacts https://jtn.ronhul.xyz to retrieve supported previous-app configuration for the current Jira site. That endpoint is hosted by Scaleway in France. Its application logs contain technical event facts, data-free errors/exceptions, and operational decision outcomes such as whether an action was taken and, where not taken, the technical reason. They do not contain IP addresses, Jira URLs, request or response bodies, or customer content. Application logs and backups are retained for 14 days. The endpoint, its logs, and its backups are scheduled for deletion no later than 31 August 2026. The Telegram bot token is not sent to that service.
Other recipients may include service providers used to operate Atlassian Forge and the temporary migration endpoint, authorities where legally required, and a successor in a lawful business transaction. We do not sell personal data or use Jira/Telegram content for third-party advertising.
6. International transfers and data residency
Forge-hosted storage follows Atlassian's Forge data residency capabilities. Message delivery to Telegram and the temporary migration service is outside Forge-hosted residency controls and may involve processing in other countries.
The temporary migration endpoint is hosted in France within the EEA. Where Vivid Insight or its subprocessors transfer personal data outside the EEA to a country without an applicable adequacy decision, an appropriate lawful safeguard, such as the European Commission's Standard Contractual Clauses, will be used where required. Customers should assess Telegram's terms, locations, and configuration for their own use case because Telegram is a service selected and administered by the customer.
7. Retention
Notification idempotency/outbox rows expire after 14 days.
Recent Activity stores only the latest 10 outcomes; they remain until overwritten by later outcomes or installation deletion.
Channel/filter configuration remains until an administrator deletes it or the App is uninstalled.
Bot and webhook secrets remain until replaced, deleted by an administrator, or the installation is removed.
Atlassian currently documents Forge-hosted storage retention for 28 days after uninstall, subject to Atlassian's current platform policy.
Telegram copies follow customer/Telegram retention and are not controlled by App uninstall.
The temporary migration service's application logs and backups are retained for 14 days, and the service and its retained data are scheduled for deletion no later than 31 August 2026.
Support, security, legal, and business records are retained only as long as reasonably necessary for the relevant request, contract, dispute, security purpose, or legal obligation, and are then deleted or anonymized where feasible.
We may retain limited records longer where required for security, disputes, legal obligations, or establishment/exercise/defence of claims.
8. Security
Measures include least-privilege read-only Jira scopes, Forge installation isolation, secret storage, authenticated and size-limited Telegram webhook ingress, TLS egress to fixed domains, parameterized SQL, bounded input/filter handling, HTML escaping, idempotency and rate limiting, dependency review, and logs designed to exclude customer content, identifiers, and secrets.
No system is perfectly secure. Customers must protect their Atlassian administration access and Telegram bot token, configure appropriate Telegram chat access, and promptly revoke/replace credentials they suspect are compromised.
9. Individual rights
Subject to applicable law, individuals may request access, correction, deletion, restriction, portability, or objection and may withdraw consent where processing relies on consent. Where we process data solely for a customer, requests should normally be directed to that customer; we will assist as required by contract and law.
Send requests to info@vividinsight.xyz. We may verify identity/authority. We aim to respond within 30 days, subject to extensions permitted by applicable law. Individuals may complain to Portugal's Comissão Nacional de Proteção de Dados (CNPD) or another competent supervisory authority.
10. Children
The App is a business service and is not directed to children. Customers must not use it to process children's data unless they have a lawful basis and appropriate safeguards.
11. Changes
We may update this Policy to reflect product, legal, or operational changes. We will update the effective date and provide additional notice where required. Material changes will not retroactively reduce contractual protections without a lawful basis.
12. Contact
VIVID INSIGHT UNIPESSOAL LDA NIF: 517951371 Rua Victor de Sá, 33, 4715-586 Braga, Portugal Privacy: info@vividinsight.xyz DPO/privacy lead: no formal Data Protection Officer has been appointed; use the privacy contact above Security: info@vividinsight.xyz Support: info@vividinsight.xyz or Telegram @JTNSupport
VIVID INSIGHT