Privacy Policy
AIMS-in-a-Box
- Effective date: 9 September 2026
- Last reviewed: 9 September 2026
- Version: 1.0
1. Who we are
This Privacy Policy explains how ITSM Ltd (“we”, “us”, “our”), a company registered in England and Wales under company number 17339600 with its registered office at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, handles personal data in connection with AIMS-in-a-Box (the “App”), an application distributed through the Atlassian Marketplace.
| Data protection contact | support@itsm-ltd.com |
| Support contact | support@itsm-ltd.com |
| ICO registration number | ZC207852 |
| Postal address | 167-169 Great Portland Street, 5th Floor, London, W1W 5PF |
We are not required to appoint a Data Protection Officer. Enquiries about this policy should be sent to the data protection contact above.
Statement required by Atlassian. ITSM Ltd, and not Atlassian, is responsible for the privacy, security and integrity of any End User Data processed by us or by the App.
2. Scope of this policy
This policy applies to the App only. It does not apply to:
- Atlassian’s own products and services (Jira, Atlassian account and related services), which are governed by the Atlassian Privacy Policy;
- our public website, which is governed by a separate website privacy notice; or
- any other application we publish, each of which has its own policy.
3. How the App is hosted — and why this matters
The App is built entirely on Atlassian Forge, Atlassian’s serverless application platform, and runs in Jira Service Management. This has a direct and material consequence for your privacy:
- The App runs on compute infrastructure operated by Atlassian. We do not operate any servers, databases or hosting infrastructure for the App.
- All data the App stores is held in Forge hosted storage inside Atlassian’s cloud environment.
- The App declares no external egress domains in its manifest and uses no Forge remotes. The Forge platform blocks outbound network traffic to undeclared destinations by default. Consequently, the App does not transmit your data to us or to any third party.
- The App holds four read-only permissions and writes nothing to Jira.
- We have no routine access to your data. We cannot browse, export or query the contents of your Atlassian site or the App’s stored data. The only circumstances in which we see your data are set out in section 5.4 below.
4. Our role under data protection law
Our role differs depending on the data concerned.
4.1 Where we act as a processor. In respect of personal data within the App’s records and within your Atlassian site that the App reads (see sections 5.1 to 5.3), you — the Atlassian customer whose site the App is installed on — are the controller and we act as a processor on your instructions. Atlassian acts as a sub-processor in that chain, because it provides the hosting and storage on which the App depends. Our processing on your behalf is governed by our Data Processing Agreement, available at https://aims.itsm-ltd.com/legal/data-processing-agreement and incorporated into the End User Terms.
4.2 Where we act as a controller. We act as a controller in our own right for:
- support correspondence you send to us (section 5.4);
- licence and subscription records supplied to us by Atlassian (section 5.5); and
- business contact records relating to your organisation.
4.3 What we are not. The App records information about AI systems you operate. Recording them here does not make us a provider, deployer, importer, distributor or authorised representative of those systems, and we do not become a controller of any personal data those systems themselves process. See clause 9.4 of the End User Terms.
5. Personal data we process
5.1 Atlassian account identifiers
The App handles Atlassian account IDs (AAIDs) — opaque identifiers assigned by Atlassian — in order to attribute App records to the correct user, apply permissions and render user references in the App’s interface.
Where the App displays a user’s name or avatar, it ordinarily retrieves that information from Atlassian at the point of display and does not retain a copy. There are two exceptions, where a display name is written into a permanent record: audit entries recording the grant or revocation of access to the App, and the named role holders inside a generated document snapshot. In both cases the name forms part of a record that is intended to remain accurate as at the moment it was made.
The App stores no email addresses. It does not hold the Atlassian permission required to read one.
5.2 What the App reads from your Atlassian products
To function, the App makes four read-only calls to Jira, all made as the person using it, so it can see nothing they could not see themselves:
- a permission check, to ask Jira whether the current user administers the site, and whether they administer the project whose settings page they are on;
- two user look-ups, returning an account ID, a display name and whether the account is active, so that people appear by name rather than as identifiers, and to power the user picker; and
- a project look-up, returning a project’s name and key.
The App reads no issue content, no comments, no attachments and no project configuration, and it writes nothing to any Atlassian product. It holds no write permission. It runs no background job: every action it takes happens because a person opened one of its pages.
5.3 App records
The App stores its own records in Forge hosted storage, scoped to your installation. These are: the AI system register; ISO/IEC 42001 control states; evidence references; evidence-to-control links; generated document versions; access grants; the audit trail; readiness assessments; and a single organisation profile record.
These records contain Atlassian account IDs, timestamps, and free text your users type — for example an AI system’s name and purpose, a control note, or an evidence title and description. They may therefore contain personal data where your users choose to enter it. Section 3.4 of the Cloud Security Statement and Annex 1 of the Data Processing Agreement give the complete field-by-field inventory.
Evidence is a reference, never a file. An evidence record holds a title, a description, an owner, a review date and an optional link. The App never stores an uploaded document and never retrieves the document behind a link.
5.4 Support correspondence
This is the one category of data that reaches our own systems. When you contact support@itsm-ltd.com, we receive and process your name, email address, employer or Atlassian site details, and whatever information you choose to include in your message — including any screenshots or exported documents you attach. Please do not send us personal data, credentials or confidential content that is not necessary to diagnose your issue.
5.5 Licence and billing records
Where the App is licensed through the Atlassian Marketplace, Atlassian supplies us with licence records including the Support Entitlement Number (SEN), the licensed tier, the licence status and dates, the customer organisation name and a technical or billing contact. Atlassian is the merchant of record for such transactions; we do not receive or process payment card data.
5.6 Platform logs
The Forge platform generates operational logs for the App’s functions. These logs are produced and retained by Atlassian under Atlassian’s own retention arrangements. The App is designed not to write personal data into logs, in line with Atlassian’s mandatory security requirements for cloud apps: it emits a single diagnostic line, on the unexpected-error path only, and the message shown to the user carries no internal detail.
5.7 No analytics, telemetry or tracking
The App collects no analytics of any kind. It has no telemetry, no third-party tracking, no error reporting service, and it does not record usage counts even into its own storage. Nothing about how you use the App is measured, retained or transmitted, to us or to anyone else.
Some pages display totals — the number of registered systems, for instance. Those are calculated from your own records at the moment you open the page, shown to you, and never stored or sent anywhere. They are a view of your data, not a measurement of your usage.
6. Purposes and lawful bases
| Data | Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Atlassian account IDs; App records; data read from Jira (5.1–5.3) | Delivering the App’s functionality on the customer’s instructions | Processed on behalf of the customer as controller; the customer determines the lawful basis |
| Support correspondence (5.4) | Responding to enquiries, diagnosing faults, maintaining a support record | Art. 6(1)(b) performance of a contract; Art. 6(1)(f) legitimate interests in providing and improving support |
| Licence and billing records (5.5) | Verifying entitlement, administering the licence, renewals and compliance | Art. 6(1)(b) performance of a contract; Art. 6(1)(c) legal obligation (accounting records) |
We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile individuals. The App contains no artificial intelligence or machine learning feature, and your data is never used to develop, train, fine-tune or evaluate any model. We do not knowingly process special category data; if your use of the App involves special category data within your own content, you remain the controller of that data and are responsible for identifying an Article 9 condition.
7. Where your data is stored
Data stored by the App resides in Forge hosted storage and inherits the data residency configuration of the Jira product it is installed alongside. Where you have pinned your Jira data to a particular Atlassian region, in-scope App data is pinned to that region, and Atlassian migrates it with your product data if you move regions. Section 3.4 of the Cloud Security Statement sets out exactly what the App treats as in scope and out of scope for data residency. Data residency for Forge apps is managed by Atlassian; details and the current list of supported regions are published at Atlassian’s data residency pages.
Support correspondence (5.4) and licence records (5.5) are held in our own business systems: email in Google Workspace, and support records in a support application built and operated by us, hosted on Vercel and Supabase, both configured to United Kingdom regions.
8. Sharing and sub-processors
We do not sell personal data, and we do not share it for advertising or marketing purposes.
| Recipient | Role | Purpose | Location |
|---|---|---|---|
| Atlassian Corporation / Atlassian Pty Ltd | Sub-processor | Hosting, compute and storage for the App; Marketplace licensing and billing | Per your data residency settings |
| Google Ireland Limited (Google Workspace) | Sub-processor | Delivery and storage of support email | Ireland / European Economic Area |
| Vercel Inc. | Sub-processor | Application hosting for our support application | United Kingdom region |
| Supabase Inc. | Sub-processor | Database and storage for our support application | United Kingdom region |
Atlassian is the only recipient that handles data held by the App. The other three exist solely because support email has to arrive somewhere.
Our support application is built and operated by us, not licensed from a third party, so it is not itself a sub-processor. The providers that host it are. Both are configured to United Kingdom regions, so support correspondence is stored in the UK; both are US-incorporated, and section 9 explains the safeguards applied.
We will give 30 days’ notice of any change to this list by updating this policy and the effective date. We may also disclose personal data where required by law, court order or a regulator, or to establish, exercise or defend legal claims.
9. International transfers
Because App data is held within Atlassian’s infrastructure, transfers are governed by Atlassian’s arrangements, including its Data Processing Addendum and the Standard Contractual Clauses with the UK International Data Transfer Addendum where applicable. Where we transfer support or licence data outside the United Kingdom, we rely on UK adequacy regulations or, where no adequacy decision applies, the International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses. A copy of the relevant safeguards is available on request.
10. Retention
| Data | Retention |
|---|---|
| App data in Forge hosted storage | Retained for as long as the App is installed. On uninstallation, Atlassian deletes Forge app data in accordance with its platform deletion processes; we retain no copy |
| The App’s audit trail | Retained for the life of the installation. The App has no retention window and no purge, and individual entries cannot be deleted — see section 12 |
| Support correspondence | 24 months from closure of the enquiry |
| Licence and billing records | 7 years, to meet UK statutory accounting and tax requirements |
Records within the App — AI systems, control states, evidence, access grants and the organisation profile — can be amended or deleted by your own users at any time. Deleting a record does not delete the audit entries recording that it existed and was changed.
11. Security
App data is encrypted in transit and at rest by the Atlassian platform, is isolated per tenant, and is accessible to the App only through the minimum permissions it declares. Our security measures are described in full in the Cloud Security Statement at https://aims.itsm-ltd.com/legal/cloud-security-statement, which is the authoritative account of them. Where we act as your processor, the same measures are set out as technical and organisational measures in Annex 2 of the Data Processing Agreement.
Where a security incident affects personal data we hold or process, we will notify the technical contact on your licence without undue delay and in any event within 72 hours of becoming aware, and will assist you in meeting your own regulatory notification obligations. Incident handling is described in section 8 of the Cloud Security Statement.
We are not ourselves certified to SOC 2, ISO/IEC 27001, ISO/IEC 42001 or comparable standards. The Atlassian infrastructure on which the App runs is independently certified; those certifications belong to Atlassian and may be verified at the Atlassian Trust Center.
12. Your rights
Where we act as a controller (support correspondence, licence records), you have the right under UK GDPR to: request access to your personal data; request rectification of inaccurate data; request erasure, where a ground applies; request restriction of processing; object to processing carried out on the basis of legitimate interests; request portability of data you provided to us; and withdraw consent, where processing is based on consent, without affecting prior processing.
To exercise a right, email support@itsm-ltd.com. We will respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies. There is normally no charge.
Where we act as a processor (data inside the App and your Atlassian site), please direct your request to the Atlassian customer whose site holds the data — normally your own organisation’s administrator. We will assist that customer in responding.
12.1 One limitation you should know about: the audit trail
The App keeps an append-only audit trail of who changed what and when. There is no facility to edit or delete an individual audit entry — not for a Jira site administrator, not for any user, and not for us. That is the point of it: a governance record whose owner can quietly amend it is not evidence.
For anyone whose actions are recorded, this means:
- The trail permanently records an Atlassian account ID, which is an opaque identifier. No email address is held.
- Entries recording the grant or revocation of App access also store a display name as text.
- A summary line may include text a user typed, such as the name of an AI system.
- Erasing an individual’s details from the trail entry by entry is not possible. All App data, including the trail, is deleted when the App is uninstalled.
If you are an individual and this concerns you, raise it with the organisation whose Jira site holds the record; they are the controller. If you are that organisation, clause 9.5 of the Data Processing Agreement sets out how we will assist you, and what determination remains yours.
Complaints. If you are dissatisfied with how we have handled your personal data, please tell us first at support@itsm-ltd.com; we operate a complaints procedure and will acknowledge your complaint within 5 business days and respond substantively within 30 days. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post to Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
13. Notice to residents of California
If you are a California resident, you have rights under the California Consumer Privacy Act as amended, including rights to know, delete, correct and opt out. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not process personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes requiring an opt-out. To exercise a right, contact support@itsm-ltd.com; we will not discriminate against you for doing so.
14. Children
The App is a business tool licensed to organisations and is not directed at children. We do not knowingly process the personal data of anyone under 18 in connection with the App.
15. What the App is, and is not
AIMS-in-a-Box is a working aid for organising an AI Management System. It does not certify compliance with ISO/IEC 42001 or the EU AI Act, and it is not legal advice. Its readiness score is an indicative signal, its classification output is a structured aid for organising obligations under Regulation (EU) 2024/1689 rather than a legal determination, and its generated documents are drafts to be reviewed before they are relied upon. Section 9 of the End User Terms sets this out in full.
16. Changes to this policy
We may update this policy from time to time. Material changes will be notified by updating the effective date above and, where the change materially affects your rights, by email to the technical contact on your licence at least 30 days before the change takes effect. Previous versions are available on request.
This Privacy Policy is published in accordance with the Atlassian Marketplace Partner Agreement. It should be read alongside the End User Terms, the Cloud Security Statement and the Support and Maintenance Description for AIMS-in-a-Box.