The displayed domain email addresses have not yet been confirmed as reachable mailboxes. Email links activate after setup and a delivery test.
1. Controller
Ludwig MunzigVireltix — trading nameCottaer Straße 1901159 DresdenGermanylegal@vireltix.comPrivacy contact: legal@vireltix.com
2. Scope and sources of data
This policy covers the public Vireltix website and Handoff Pulse. Website processing and Marketplace-app processing are described separately below. Atlassian accounts, Jira, the Atlassian Marketplace and other customer-selected services are also subject to their providers’ privacy information.
Website data arises from a technical request or information you choose to send by email. App data originates from authorised-user input, app workflow events and—where required for display—from Jira. The website currently provides no user account, newsletter or form that pretends to submit a request.
3. Website delivery and log data
When the website is requested, the hosting infrastructure may process technically necessary information such as IP address, timestamp, requested URL, transferred volume, referrer, browser/device information, response status and security logs. The purposes are delivery, stability, attack and abuse detection, and troubleshooting. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is secure, available and reliable operation.
The website is delivered through ChatGPT Sites. We have not installed our own analytics, advertising or marketing trackers, social-media pixels or newsletter tracking. Visible app filters operate in the browser and currently create no vendor profile of the visitor.
Hosting infrastructure may generate access and security logs independently. We state a concrete technical retention period only when it has been verified and can be reliably committed to.
4. Contact and support requests
When you contact us by email, we may process the sender address, name, organisation, message, affected app, Atlassian product, issue category, technical details, attachments and subsequent communication—only to the extent you provide them and they are relevant to the request.
Depending on context, the legal basis is Article 6(1)(b) GDPR for pre-contractual or contractual communication, Article 6(1)(c) for legal duties, or Article 6(1)(f) for handling other legitimate enquiries, fraud prevention and legal defence. Statutory retention duties remain unaffected.
Do not send passwords, API tokens, secret keys, full database exports or personal data that is unnecessary for support. Use the contact identified on the Security page for vulnerability reports.
5. Handoff Pulse: categories and sources of app data
Depending on customer use, Handoff Pulse processes customer-entered handover content including title, shift/type, priority, current state, impact, risks and blockers, next actions, context and tags. It may also process linked Jira issue keys, Atlassian account IDs for ownership and revision attribution, and workflow metadata such as timestamps, acknowledgement, state, carry-forward relationships and revision history.
Jira summary, status, priority, assignee, issue type, project and update time may be read for a current view. Jira remains the authoritative source for those Jira fields, and each user’s Jira permissions govern what that user can see.
The app is intended for business handover information. Customers and users determine which permitted content they enter. Article 9 special-category data, access credentials and secrets should not be entered unless exceptionally necessary, lawful and appropriately safeguarded.
6. Purposes, roles, legal bases and automated decisions
Processing supports the creation, display, search, update, acknowledgement, carry-forward and security of structured handovers and related support. In the customer relationship, the subscribing organisation will commonly determine the purpose and means of business data entered in Jira and the app. Whether Vireltix acts as a processor or, for a specific operation, as a controller depends on the agreement and actual processing.
Where Vireltix acts as controller, relevant legal bases may include Article 6(1)(b) GDPR for contract performance and support, Article 6(1)(c) for legal duties and Article 6(1)(f) for security, abuse prevention, troubleshooting and legal defence. Article 6(1)(a) is used only where processing genuinely relies on consent.
In the verified current setup, the website and app do not make decisions producing legal or similarly significant effects solely by automated means and do not conduct advertising profiling. Status and health signals are operational aids; accountable decisions remain with the customer and its users.
7. Forge architecture, permissions and recipients
The verified current release runs on Atlassian Forge and stores structured app data in Forge KVS. The verified manifest uses storage:app, read:jira-work and read:jira-user. It does not request Jira issue write access for the core workflow.
The current manifest declares no external egress and no vendor-operated remote backend. This technical statement applies only to the verified release and is reassessed before architecture or permission changes. It is not a blanket statement about all processing performed by the Atlassian platform.
Atlassian processes Marketplace, Jira and Forge platform data under applicable agreements, customer settings and privacy documentation. The public website uses ChatGPT Sites for delivery. Other confirmed external providers are published on the Subprocessors & Platform Providers page.
8. Retention, deletion and uninstallation
Website logs are processed according to the technical and contractual periods of the hosting infrastructure; we do not state an unverified fixed period. Contact and support correspondence is deleted or restricted when no longer needed for the request, contractual evidence, security or legal duties. Statutory requirements can require individual business correspondence to be kept longer.
Handoff Pulse records remain in active Forge app storage until authorised users delete them or the applicable Forge installation and hosted-storage lifecycle removes them. No fixed automatic expiry period is currently promised. Uninstallation, licence expiry and later reinstallation can affect access and platform retention under Atlassian’s then-current lifecycle.
Requests concerning customer-controlled app data should usually be directed first to the relevant organisation because it controls its users, Jira permissions and processing purpose. We assist valid requests within our actual role and technical capability.
9. International transfers
Whether a transfer outside the European Economic Area occurs depends on the platform service, customer configuration, support path and current provider terms. We therefore do not invent a single processing region.
Where an additional transfer mechanism is required, it may include an adequacy decision, appropriate safeguards such as standard contractual clauses, or another lawful basis. Current Atlassian and hosting documentation should be consulted for the relevant platform processing.
10. Your rights
- Access to personal data (Article 15 GDPR)
- Rectification of inaccurate and completion of incomplete data (Article 16 GDPR)
- Erasure where no lawful reason requires continued processing (Article 17 GDPR)
- Restriction of processing (Article 18 GDPR)
- Data portability where the statutory conditions apply (Article 20 GDPR)
- Objection to processing based on legitimate interests (Article 21 GDPR)
- Withdrawal of consent for future processing
Send a request to the privacy contact and identify the service and customer account concerned. To protect affected individuals, we may request proportionate evidence of identity or authority. Rights can be limited by statutory exceptions and the rights of others.
You may also complain to a data-protection supervisory authority, particularly where you live, work or believe an infringement occurred. This right exists independently of other remedies.
11. Security and data minimisation
We apply risk-based technical and organisational measures, limit app permissions to documented functional needs and review statements when architecture changes. Customers remain responsible for access management, Jira permissions and deciding what content may be entered. No online service can guarantee absolute security.
Report suspected vulnerabilities confidentially through the security contact. Provide only the data required for investigation and do not access or alter another user’s data.
12. Changes and version
We update this policy when functionality, providers, law, permissions or data flows change materially. The effective date above identifies the current version. Statements about the present architecture do not automatically apply to a later release with changed data flows.