Effective date: 29 August 2026
Last reviewed: 29 August 2026
Publication URL: https://peztechsoftware.co.uk/legal/bulk-approvals-for-jsm-privacy
1. Who we are
Will Perry trading as PezTech Software is responsible for this notice. PezTech Software is a trading name of Will Perry, a sole trader in the United Kingdom.
Privacy contact: support@peztechsoftware.co.uk
Website: https://peztechsoftware.co.uk
Business correspondence address: [The Bristol Office, 2nd Floor, 5 High Street, Westbury-on-Trym, Bristol, BS9 3BY, England]
This notice covers Bulk Approvals for Jira Service Management (“the app”), customer and Marketplace administration connected with the app, direct support communications, and the current PezTech Software website implementation described below.
2. How the app processes Jira Service Management data
What the app does
The app lets a signed-in Jira Service Management approver find, review and decide native approvals. A human approver chooses Approve or Decline. Jira remains authoritative for request visibility, approval authority, workflow consequences and audit history.
Information processed
To provide the feature, the app processes customer-visible Jira/JSM information. This may include request and issue references and summaries, request type, requester display information, submission time, native approval status, signed-in Atlassian user context, customer-configured portal-visible context fields, and related project, service-desk and request-type metadata.
A customer project administrator chooses the supported request types and up to three eligible portal-visible context fields displayed by the app.
Purpose, authority and storage
The app processes this information to discover approvals for the signed-in approver, show useful decision context, submit the human approver’s chosen native Jira decision and refresh the result.
The app uses supported Atlassian APIs in the signed-in customer context. Jira applies server-side permissions and records the native workflow and audit result.
Request, approval, requester, context, search, selection, processing and result information is transient and is not intentionally retained by PezTech Software. Forge-hosted storage contains configuration metadata only.
PezTech Software does not operate an external backend or database containing Jira Service Management request or approval data. Request and approval information is processed within Atlassian’s platform and is not copied to PezTech Software infrastructure. No external PezTech analytics or telemetry service receives Jira request or approval data.
Controller and processor roles
The customer controls its Jira/JSM end-user data and determines why and how that data is used. The customer is therefore the controller for that processing. PezTech Software acts as processor to the extent it processes that data solely to provide the app. Atlassian Forge acts as PezTech Software’s processor or sub-processor as applicable under the Forge terms and Forge Data Processing Addendum.
The customer is responsible for its lawful basis, Jira/JSM content and configuration, and any privacy information it must provide to its users, workforce or customers.
Security and logging
The app uses signed-in customer context, supported Atlassian APIs, least-privilege access, Jira server-side authorisation, project-admin checks and Forge-hosted configuration.
The app uses technical logging designed to exclude Jira request and approval content and personal information. It does not use an external Jira-data analytics or telemetry service.
3. Marketplace and customer administration
For the intended Paid-via-Atlassian model, customers evaluate and purchase the app through Atlassian. Atlassian handles Marketplace subscription and payment processing and may provide PezTech Software with licensing, sales and evaluation information.
Marketplace information may include licence or evaluation details, customer organisation and transaction information, and technical, billing or other customer contact details, including email addresses. It is obtained from Atlassian rather than always directly from the individual.
PezTech Software uses this information to administer evaluations and licences, provide customer service, reconcile Marketplace payments, maintain business records, prevent misuse and respond to security or legal matters.
PezTech Software does not require customers to provide card details or payment credentials directly to the app or PezTech Software for a normal Paid-via-Atlassian purchase.
Depending on the activity, PezTech Software relies on:
- contract or steps before contract, where processing is necessary for an agreement with the individual;
- legitimate interests, for proportionate customer administration, support, fraud or abuse prevention and service security; and
- legal obligation, for records required by tax, accounting or other applicable law.
The legitimate interests are operating and supporting the product, administering customer relationships and protecting the app, customers and business systems. PezTech Software does not currently use Marketplace or support data for direct marketing.
4. Direct support communications
If you contact support@peztechsoftware.co.uk, PezTech Software receives your email address, message, technical context and any other information you voluntarily include. This is used to respond, diagnose the app, maintain necessary support records, protect the service and establish, exercise or defend legal claims.
Do not send passwords, credentials, API tokens, recovery codes, Jira request or approval content, sensitive custom-field values or unnecessary personal data. If Jira content is genuinely needed, PezTech Software will first seek a safer and minimised method.
Depending on the circumstances, support processing relies on contract, legitimate interests or legal obligation.
5. Recipients and service providers
Information may be made available only where necessary to:
- Atlassian, including Jira Service Management, Marketplace and Forge, for app operation, distribution and licensing;
- Microsoft 365, for direct support/privacy communications and controlled business records;
- professional advisers such as accounting or legal advisers where needed; and
- regulators, courts or public authorities where required by law.
Customer Jira/JSM request and approval data is not intentionally placed in Microsoft 365, GitHub, the PezTech Software website or a PezTech external database.
6. Retention and deletion
PezTech Software does not intentionally retain transient Jira/JSM request, approval, requester, context, search, selection, processing or result information.
Forge-hosted configuration data is subject to Atlassian’s current Forge storage retention and deletion lifecycle. PezTech Software does not maintain a separate copy.
Normal support correspondence is retained for two years after the case closes. Security and privacy incident records are retained for six years after closure. Customer contracts, DPA/EULA acceptance evidence and related contractual records are retained for six years after the customer relationship ends.
PezTech Software does not routinely export Marketplace customer or licensing data. A necessary ad-hoc export is deleted within 12 months unless a documented continuing business or legal need applies. Atlassian Marketplace is preferred as the system of record.
Accounting and tax records are retained for six years, subject to any longer or otherwise overriding statutory or HMRC requirement.
7. International processing and transfers
The app uses Atlassian-hosted Jira Service Management and Forge services. Atlassian’s hosting, data residency, sub-processors and international-transfer arrangements are governed by the applicable Atlassian terms and Forge DPA. PezTech Software does not claim that all processing remains in the United Kingdom.
Microsoft 365 support and business-record services may involve international processing under Microsoft’s applicable contractual safeguards.
The PezTech Software website is built as a static site. Its current source does not add analytics, advertising trackers, contact forms, non-essential cookies, third-party embeds, remote fonts or marketing automation. Email links open the visitor’s chosen email service, and external links lead to third-party sites under those providers’ terms. The production hosting provider and any server access-logging arrangements will be identified before publication; no claim is made that hosting remains solely in the United Kingdom.
8. Your rights
Where PezTech Software is controller, you may have rights to request access, rectification, erasure, restriction, objection and data portability. These rights depend on the circumstances and lawful basis and are not all absolute. If processing relies on consent, you may withdraw consent without affecting processing carried out before withdrawal.
Send requests to support@peztechsoftware.co.uk. PezTech Software will respond without undue delay and normally within the applicable one-month UK GDPR period, subject to lawful identity checks, clarification and extensions.
For Jira/JSM information processed on a customer’s behalf, the customer is normally the appropriate first contact. PezTech Software will assist the customer as required by the applicable processing terms.
You may complain to PezTech Software at support@peztechsoftware.co.uk. You also have the right to complain to the Information Commissioner’s Office: ico.org.uk/make-a-complaint or 0303 123 1113.
9. Required information and automated decisions
Jira/JSM information is required for the app to display and action native approvals. Without it, the feature cannot operate. Contact and licensing information may be required to administer a purchase, evaluation or support request.
The app does not profile users and does not make automated approval decisions. It does not use AI to determine approval outcomes. A human approver chooses Approve or Decline, and native Jira workflow consequences are determined by the customer’s Jira/JSM configuration.
10. Changes
PezTech Software will review this notice when processing purposes, data access, storage, service providers or legal requirements materially change. The published notice will state its effective date and current version.
_Last reviewed: 29 August 2026._