# Privacy Policy

> How Strategy Hub collects, uses, stores, and protects personal data — an Atlassian Forge app that runs entirely on Atlassian's infrastructure.

Canonical: https://docs.caskcode.io/strategy-hub/privacy/

**End User Privacy Policy · Version 1.0 · June 1, 2026**

This End User Privacy Policy (Privacy Policy) applies to Strategy Hub: OKRs, Goals,
KPIs & Strategy Planning for Jira (Strategy Hub or App), an Atlassian Forge
application provided by caskcode (caskcode, we, us, or our) and available on the
Atlassian Marketplace.

This Privacy Policy describes which personal data Strategy Hub collects, how we
store, process, and use it, and what happens when you use the App.

> **Important – Runs on Atlassian architecture.** Strategy Hub is built entirely on
> Atlassian's Forge infrastructure (Runs on Atlassian). All application logic runs
> within Atlassian's secure runtime environment, and all data is stored in
> Atlassian-managed Forge Storage. Caskcode does not operate any external servers
> or databases and has no direct access to your data or the data of your Jira
> instance.

## 1. About us

Strategy Hub is provided by **caskcode**, the trading name of Bartosz Wyszkowski,
a sole trader (_jednoosobowa działalność gospodarcza_) established in Poland
(NIP: 7732489961, REGON: 383238029). In this Privacy Policy, "caskcode", "we", "us",
and "our" refer to this business.

- Email: support@caskcode.io — for general enquiries
- Email: contact@caskcode.io — for general and privacy-related enquiries

**Our role under data protection law.** We are the **controller** for the limited
personal data we collect to operate, support, and improve the App — technical and
usage data (section 3.3), feedback you submit (section 3.5), and commercial and
licensing data (section 3.6) — meaning we determine the purposes and means of that
processing. For the **strategic content you create within the App** (objectives, key
results, KPIs, comments, and related configuration — section 3.4), the **customer
organisation that installed Strategy Hub is the controller** and we act as a
**processor** on its behalf, with Atlassian providing the underlying Forge
infrastructure as a sub-processor. Where required, that processing is governed by a
Data Processing Agreement between us and the customer. A Data Processing Agreement
is available to customers on request at contact@caskcode.io.

## 2. About you

When you install and use Strategy Hub, you become our end user (End User).

We categorise End Users so you can easily find the details relevant to your
personal data. Please note that you may fall into more than one category depending
on how you use the App.

| Type of End User      | Description                                                                                  |
| --------------------- | -------------------------------------------------------------------------------------------- |
| End User              | Any person who installs and uses the App.                                                    |
| Strategy Hub End User | End User who creates and manages OKRs, KPIs, Goals, or other strategic items within the App. |
| Feedback provider     | End User who submits feedback, a support request, or an enquiry via our JSM customer portal. |

**Please note!** We do not knowingly process the personal data of End Users under
the age of 16. If you are such an End User, or are a legal representative of such an
End User, please contact us using the details in section 1.

## 3. Personal data

### 3.1 Sources of data

We receive data when you install the App and interact with it, depending on your
actions and your Jira instance configuration.

Because Strategy Hub operates on the Runs on Atlassian (Forge) architecture, the
data we receive is limited to what Atlassian's platform exposes to Forge apps.
Caskcode does not have direct access to your Jira instance data beyond what is
explicitly passed to the App through Atlassian's Forge APIs.

You may update your personal data through the App's functionality or by exercising
your right to rectification. The same lawful bases and storage terms apply to
updated data.

We may also receive data from third parties, as described in section 3.6.

### 3.2 Lawful bases for processing

To process your personal data, we rely on the following lawful bases:

- **Performance of the contract** — for processing personal data necessary for
  negotiating, concluding, and performing a contract (primarily, the End Users
  Terms) with you.
- **Legitimate interest** — for processing necessary for the development of our
  services, taking into account your interests, rights, and expectations.
- **Legal obligation** — for processing required by applicable law (for example, to
  comply with tax regulations) or when requested by a law enforcement agency,
  court, supervisory authority, or other state-authorised public body.

### 3.3 Technical End Users data

We collect limited technical data about End Users to optimise performance, debug
issues, and improve the overall user experience. Because the App runs on
Atlassian's Forge infrastructure, most technical data is handled within Atlassian's
environment.

We process the following personal technical data for **performance optimisation,
debugging, feature improvement, and App analytics**, on the basis of our **legitimate
interest**:

- Coarse location (country derived from IP address)
- Identifiers (Atlassian user ID) — shared with our analytics and error-monitoring processors (see section 4)
- Subscription and licence details
- Usage data (App install and usage dates)
- Technical information (default settings, HTTP user agent)

**Data storage:** We store this data for 3 years from its collection.

### 3.4 Strategy Hub End Users data

We process certain data when you create and manage strategic items (OKRs, KPIs,
Goals, and related content) within Strategy Hub.

**Note on data residency:** Data created within the App (objectives, key results,
KPIs, comments, and related configuration) is stored exclusively in Atlassian Forge
Storage and is not accessible to Caskcode.

We process the following data **to provide you with the App's core functionality**,
on the basis of **performance of the contract**:

- Strategic item data (names, descriptions, types, hierarchy)
- Progress and status values
- Period and date configurations
- Team and ownership assignments
- Comments and activity history
- Linked Jira work items
- Labels and custom settings

**Data storage:** Data is stored until you delete the strategic item or uninstall
the App.

### 3.5 Feedback providers data

We collect certain data when you voluntarily submit feedback, a support request, or
any other enquiry about the App. Feedback is collected via our Jira Service
Management (JSM) customer portal. When you submit a request through the portal, we
receive and process the data you provide.

We process the following data **to respond to your feedback, support request, or
enquiry, and to use aggregated feedback for product improvement**, on the basis of
our **legitimate interest**:

- Email address of the submitter
- Text of the feedback, request, or message
- Any additional data you voluntarily provide in the submission

**Data storage:** We store this data for 6 years from the date of submission or
from the last communication regarding it.

### 3.6 Data received from third parties

We may receive limited personal data from third parties. The scope, purposes, and
lawful bases for such processing are governed by the respective privacy documents
of those third parties.

| Third party           | Privacy documents                                |
| --------------------- | ------------------------------------------------ |
| Atlassian Marketplace | <https://www.atlassian.com/legal/privacy-policy> |

We receive data from Atlassian Marketplace to place the App within the platform and
provide you with its functionality. We process the following data **to provide you
with the App's functionality**, on the basis of **performance of the contract**:

- Company and representative data
- Hosting and instance data
- Number of users in the Jira instance
- Subscription period (start and end dates)
- Atlassian licence ID and entitlement number

**Data storage:** We store this data for the duration of your use of the App.

Where a paid subscription is purchased, Atlassian Marketplace processes payment on
our behalf. The data may include payment confirmation, transaction date, purchased
subscription details, and billing contacts. We store this data for 6 years from the
date you cancel your subscription.

### 3.7 Cookies and tracking technologies

Strategy Hub sets no cookies through its own application code. The analytics and
error-monitoring tools it uses (PostHog and Sentry — see section 4) store nothing on
your device: no cookies, and no data in your browser's local storage.

The App does use your browser's local storage, but for strictly necessary,
first-party purposes only — remembering your view settings (filters, columns,
sorting), preserving your unsaved work, and caching your own preferences. This
storage holds no tracking identifiers and no personal data beyond your own settings,
is never shared with third parties, and is exempt from consent as strictly necessary
storage. Because the App stores no tracking or analytics data on your device, it does
not require a cookie consent banner.

Any cookies present in the Atlassian interface are set by Atlassian as part of its
platform and are governed by Atlassian's Privacy Policy.

## 4. Data sharing with third parties

We may share your personal data with third parties without harm to you and in full
compliance with applicable law. We have implemented organisational and technical
measures to ensure the security of personal data during such transfers.

We rely on the following lawful bases for sharing data, depending on the
circumstances: consent, compliance with legal obligations, and performance of a
contract.

| Third parties                                               | Description                                                                                                                                                                                                                                                                                           |
| ----------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Error monitoring — Sentry (<https://sentry.io/privacy/>)    | We use Sentry to capture technical error diagnostics so we can debug and improve the App.                                                                                                                                                                                                             |
| Product analytics — PostHog (<https://posthog.com/privacy>) | We use PostHog to understand aggregate usage patterns and improve the App.                                                                                                                                                                                                                            |
| Contractors and service providers                           | We work with service providers and contractors to operate, develop, and improve the App, fulfil support requests, and manage the Atlassian Marketplace listing.                                                                                                                                       |
| Internal organisational tools                               | We use CRM systems, communication tools, and similar services within our organisation to provide you with our services.                                                                                                                                                                               |
| State authorities and law enforcement                       | We may be required to transfer certain data to tax authorities, courts, law enforcement agencies, or other governmental bodies: to comply with a legal obligation or court order; to prevent unlawful use of the App; to protect against third-party claims; or to help prevent or investigate fraud. |

**What we send to Sentry and PostHog.** We send these tools a limited set of
technical identifiers and aggregate metrics: your Atlassian account ID (a pseudonymous
identifier), your site (cloud) ID and URL, installation and environment identifiers,
licence and usage counts, and a coarse country derived from your IP address (your raw
IP address is discarded). Where you voluntarily submit your name and email through the
in-App support widget (see section 3.5), we send those so we can respond. We do
**not** send the strategic content you create, the contents of your Jira instance, or
any free-text you or your colleagues author — session replays mask all on-screen text,
and error diagnostics contain identifiers and technical codes only. Both providers
host EEA data within the European Union (see section 6).

To obtain a detailed list of third-party recipients of your personal data, please
contact us at contact@caskcode.io.

## 5. Atlassian Forge data lifecycle and Rovo

### 5.1 Forge-hosted storage data lifecycle

Because all Strategy Hub data is stored exclusively in Atlassian's Forge-hosted
storage, the retention and deletion of that data is governed by Atlassian's data
lifecycle policies — not by caskcode. The key stages are summarised below. For full
details, please refer to the Atlassian developer documentation at:
<https://developer.atlassian.com/platform/forge/storage-reference/hosted-storage-data-lifecycle/>

| Stage                               | What happens to your data                                                                                                                                                                 |
| ----------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| App installation                    | Atlassian provisions dedicated Forge storage for the App within your Jira site's Atlassian app partition. No data exists before installation.                                             |
| App in active use                   | Data is stored within Atlassian's Forge infrastructure for as long as the App is installed and your Atlassian subscription is active.                                                     |
| App uninstallation                  | Data is soft-deleted by Atlassian and retained for a period defined by Atlassian's internal Standard Data Retention and Disposal policy. Caskcode does not control this retention period. |
| App reinstallation within 21 days   | If the App is reinstalled within 21 days of uninstallation, the new installation can be relinked to the previous data on request.                                                         |
| App reinstallation after 21 days    | Reinstallation is treated as a new installation. Previously stored data may no longer be recoverable.                                                                                     |
| Atlassian subscription cancellation | When your Jira subscription is cancelled, Atlassian schedules all associated app data for deletion in accordance with its data retention policy.                                          |
| Site deletion                       | When an Atlassian site is permanently deleted, all associated app data is deleted immediately once the soft-delete period has elapsed.                                                    |

**Please note:** The retention periods described above are set and controlled by
Atlassian. Caskcode is not able to recover data that has been deleted by Atlassian
in accordance with its policies. If you require data export before uninstalling the
App, please use the Data export functionality within Strategy Hub settings before
uninstalling.

### 5.2 Atlassian Rovo integration

Strategy Hub may integrate with Atlassian Rovo, Atlassian's AI-powered assistant
platform, to provide AI-enhanced features such as intelligent search, goal
suggestions, or conversational interaction with your strategy data.

When the Rovo integration is active, certain data from your Strategy Hub instance —
such as objective names, key results, or KPI data — may be accessed by Rovo to
generate responses or surfaces within the Atlassian platform. The following applies
to such processing:

- Data accessed by Rovo is processed within Atlassian's own infrastructure and is
  subject to Atlassian's Privacy Policy and AI usage policies.
- Rovo respects your existing Jira permissions model — it will only surface data to
  users who already have access to it within Strategy Hub.
- Rovo may use third-party large language model providers (such as OpenAI, Anthropic,
  and Google) to generate responses. Atlassian states that these providers do not
  retain your inputs and outputs or use them to train their models.
- Atlassian states that Rovo retains inputs and outputs for a limited period
  (currently 30 days) for safety and security purposes.
- The specific scope of data accessed depends on how the Rovo integration is
  configured. We will update this section as the integration is developed and
  scoped.

Use of Atlassian Rovo is governed by your Atlassian Customer Agreement and
Atlassian's Privacy Policy. For full details of how Rovo processes data, please
refer to:
<https://support.atlassian.com/rovo/docs/rovo-data-privacy-and-usage-guidelines/>

## 6. Data sharing outside the European Economic Area

Because Strategy Hub runs on the Runs on Atlassian (Forge) architecture, data
stored within the App resides in Atlassian's infrastructure and is subject to
Atlassian's data residency commitments under your Atlassian Customer Agreement.

To the extent that caskcode processes any personal data outside the App (such as
support communications or analytics), such data may be stored on servers within the
European Union for EEA End Users and in the USA for US End Users.

Where we share personal data with recipients in the USA or other non-EEA countries,
we ensure it is protected in accordance with the General Data Protection Regulation.
We rely on the adequacy decision of the European Commission or the recipient's
participation in the Data Privacy Framework.

If a recipient does not participate in the Data Privacy Framework and their country
is not deemed adequate, we adopt Standard Contractual Clauses, based on appropriate
data protection assessments.

## 7. Data protection

We apply security measures appropriate to the risks involved in processing your
personal data. In addition, because the App runs on Atlassian's Forge
infrastructure, your in-App data benefits from Atlassian's own enterprise-grade
security controls.

**Organisational measures**

- Staff training and awareness
- Internal policies and procedures
- Non-disclosure agreements (NDA)
- Access controls and least-privilege principles

**Technical measures**

- Two-factor authentication
- Encrypted data transmission (TLS)
- Firewalls and network controls
- Regular backups
- Atlassian Forge runtime isolation
- Forge Storage encryption at rest

## 8. Data subjects rights

As a data subject, you have the right to interact with your personal data directly
or by submitting a request to us. The sections below describe your rights depending
on your country of residence.

### 8.1 European Economic Area and United Kingdom residents

| Right                        | Description                                                                                             |
| ---------------------------- | ------------------------------------------------------------------------------------------------------- |
| Right to access              | You may request an explanation of how your personal data is processed.                                  |
| Right to rectification       | You may request correction of inaccurate or incomplete data.                                            |
| Right to erasure             | You may request deletion of your personal data. We will comply unless retention is required by law.     |
| Right to restrict processing | You may partially or fully restrict our processing of your personal data.                               |
| Right to data portability    | You may request a copy of the data you provided and ask for it to be transferred to another controller. |
| Right to object              | You may object to the processing of your personal data.                                                 |
| Right to withdraw consent    | Where processing is based on consent, you may withdraw it at any time.                                  |
| Right to file a complaint    | If your request is not satisfied, you may file a complaint with the relevant supervisory authority.     |

To exercise your rights, contact us at contact@caskcode.io.

**EEA residents:** We will respond to your request within one month. If not
satisfied, you may submit a complaint to your local Data Protection Authority. A
list is available at <https://edpb.europa.eu/about-edpb/about-edpb/members_en>.

**UK residents:** We will respond within one month. If not satisfied, you may
contact the Information Commissioner's Office at 0303 123 1113 or
<https://www.ico.org.uk/concerns>.

### 8.2 United States residents

For the purposes of US state privacy laws such as the CCPA, Caskcode acts as a
**"business"** for the personal data described in this Policy that we process for our
own purposes, and as a **"service provider"** for the strategic content we process on
behalf of a customer organisation.

Your privacy rights vary depending on your state of residence, as outlined below.

| Right                             | Description                                                              | States                                 |
| --------------------------------- | ------------------------------------------------------------------------ | -------------------------------------- |
| Right to access                   | Request an explanation of how your personal data is processed.           | CA; CO; CT; IN; IA; MT; TN; TX; UT; VA |
| Right to correct                  | Request correction of inaccurate or incomplete data.                     | CA; CO; CT; IN; MT; TN; TX; VA         |
| Right to delete                   | Request deletion of your personal data.                                  | CA; CO; CT; IN; IA; MT; TN; TX; UT; VA |
| Right to portability              | Request your data and transfer to another controller.                    | CA; CO; CT; IN; IA; MT; TN; TX; UT; VA |
| Right to opt out of sales         | Opt out of the sale of personal data to third parties.                   | CA; CO; CT; IN; IA; MT; TN; TX; UT; VA |
| Right to opt out of profiling     | Opt out of processing for targeted advertising or profiling.             | CO; CT; IN; MT; TN; TX; UT; VA         |
| Right against automated decisions | Protection against solely automated decision-making without human input. | CA; CO; CT; IN; IA; MT; TN; TX; VA     |
| Private right of action           | Seek civil damages for statutory violations.                             | CA                                     |

To exercise your rights, contact us at contact@caskcode.io. We will respond within
30 to 60 days depending on your state's legislative requirements. If your complaint
is not resolved, you may contact the Federal Trade Commission at
<https://www.ftc.gov/about-ftc/contact>.

**Please note!** Some US states do not have comprehensive privacy laws. Residents of
such states are governed by applicable federal law. If your state is not listed
above, please contact us.

### 8.3 Do not sell my personal information

California residents have the right under the California Consumer Privacy Act (CCPA)
to opt out of the sale of their personal information.

Caskcode does not sell your personal information to any third party, nor does it use
your data as a business model. However, we support the CCPA by allowing California
residents to record their preference against any future sale. To do so, please
contact us at contact@caskcode.io.

### 8.4 Do-not-track requests

California residents using the App may request that we do not automatically gather
and track information about their online browsing activities across the Internet.

Such requests are typically made through browser settings that transmit signals or
other mechanisms allowing consumers to exercise choice over the collection of
personal data across third-party websites and online services over time.

We currently do not have the ability to honour these requests. We will update this
Privacy Policy if our capabilities change.

### 8.5 Canada residents

Canadian residents have privacy rights under the Personal Information Protection and
Electronic Documents Act (PIPEDA), the Personal Information Protection Act of
British Columbia, the Personal Information Protection Act of Alberta, and the Act
respecting the protection of personal information in the private sector of Quebec.

Under these laws, you have the right to access your personal data, request
corrections, and withdraw consent for non-essential processing. To exercise any of
these rights, please contact us at contact@caskcode.io. We will respond within 30
days.

## 9. Privacy Policy updates

We may update this Privacy Policy from time to time to reflect changes in the App,
legal requirements, or our data practices. If changes are material, we will notify
you in advance via email or through the App's Atlassian Marketplace page.

The current version and effective date are shown at the top of this document.
Continued use of the App following the effective date of any update constitutes
acceptance of the revised Privacy Policy.

For any questions about this Privacy Policy or to exercise your rights, contact us
at contact@caskcode.io.

---

© 2026 Caskcode · All rights reserved · caskcode
