Privacy Policy
Privacy Policy of Cascading Custom Fields for Jira (Multilevel Select List)
We are delighted that you have shown interest in our product “Cascading Custom Fields for Jira (Multilevel Select List)” (the “App”) and our enterprise. Data protection is of a particularly high priority for the management of CraftCoders eGbR (hereinafter referred to as “we” or “CraftCoders”).
This Privacy Policy applies only to the Cloud version of the App for Jira Cloud, built on the Atlassian Forge platform.
The processing of personal data shall always be in line with the General Data Protection Regulation (GDPR) and in accordance with applicable country-specific data protection regulations. By means of this Privacy Policy, we would like to inform data subjects of the nature, scope, and purpose of personal data we process in connection with the App, and of the rights to which they are entitled.
Our Privacy Policy is based on the terms used by the European legislator for the adoption of the GDPR. Terms used in this Privacy Policy shall have the meaning as defined in the GDPR.
As the controller, CraftCoders has implemented technical and organizational measures to ensure an appropriate level of protection of personal data processed. However, internet-based data transmissions may in principle have security gaps, so absolute protection may not be guaranteed.
The App integrates with Jira Cloud, a product provided by Atlassian (hereinafter referred to as “Atlassian”), and uses services provided by Atlassian through the Forge platform.
1. Name and address of the controller (and data protection contact)
Controller for the purposes of the GDPR and other data protection laws:
CraftCoders eGbR
Alter Schlachthof 39 D2 76131
Karlsruhe Germany
phone: +49 721 95944575
email: mail@craftcoders.de
Data protection contact / DPO (if applicable):
Jan Hendrik Winter
Alter Schlachthof 39 D2 76131
Email: dpo@craft-coders.de
Phone: +49 721 95944575
2. Collection of general data and information
2.1 Marketplace and licensing data
If you acquire a license of the App via the Atlassian Marketplace, Atlassian provides us with transaction and licensing details (e.g., technical identifiers related to the installation, licensing status, and billing-related metadata). Where Atlassian processes data on its own behalf, Atlassian acts as controller.
Further information about Atlassian’s privacy practices can be found in Atlassian’s privacy policy.
2.2 Technical and usage data in Atlassian Cloud
When you use the App, Atlassian services may collect general technical information (e.g., log data necessary to deliver and operate the app functionality). This information is used to:
deliver the functionality of the App correctly,
ensure security and long-term viability of the App, and
support troubleshooting in case of incidents.
Where we receive operational signals (e.g., error information) in support cases, we use them only to diagnose and resolve issues.
3. Processing of Jira data by the App
3.1 What the App does
The App provides advanced custom field types for Jira, including:
deep cascading select lists,
editable to-do lists,
validated short text fields.
3.2 Categories of data processed
Depending on how you configure and use the App, the App may process:
Jira work item/issue data, including custom field values entered by users
Project and configuration data, such as custom field contexts and options/hierarchies you define
User information available in Jira, such as display names, account IDs, avatars, and (where permitted by Atlassian and your settings) additional user attributes
Operational metadata required to provide the functionality (e.g., identifiers of projects, contexts, and configuration entities)
The App processes this data to provide the core functionality you configure (e.g., rendering a cascading select list, validating short text input, and storing/reading the configured option hierarchy).
3.3 Where data is stored and processed (Forge / Atlassian services)
The App is built on Atlassian Forge. As a result:
The App stores and processes data within Atlassian apps and services, consistent with the App’s Marketplace “Data Management” statement.
End-user data is stored exclusively within Atlassian apps and services that support data residency options, consistent with the App’s Marketplace “Data residency” statement.
We do not operate separate, customer-facing infrastructure for the App that stores end-user data outside Atlassian services, except where optional analytics/log settings may apply (if enabled).
4. Support communications (JSM portal and email)
If you contact us for support, we will process the information you provide, which may include:
contact information (name, email),
issue descriptions and reproduction steps,
screenshots/log excerpts you choose to share,
Jira site/app installation context necessary to support you.
Support requests may be handled through:
our Jira Service Management portal, and/or
support email communication.
We recommend avoiding unnecessary sensitive personal data in support tickets where possible.
5. Legal basis for the processing
Where the processing of personal data is necessary for the performance of a contract (providing the App’s functionality and support), the processing is based on Art. 6(1)(b) GDPR.
Where processing is necessary for our legitimate interests (e.g., ensuring security, preventing abuse, debugging and improving reliability), and where such interests are not overridden by the interests or fundamental rights and freedoms of the data subject, the processing is based on Art. 6(1)(f) GDPR.
Where we are subject to legal obligations (e.g., tax or compliance obligations), processing may be based on Art. 6(1)(c) GDPR.
6. Period for which the personal data will be stored
We store personal data only as long as necessary for the purposes described above, including providing the service and fulfilling legal obligations.
Support communications are retained as long as necessary to handle the request and for reasonable follow-up, and may be retained longer where required for legal or contractual reasons.
Where and as long as legal retention obligations apply, we store the data for the duration of the relevant periods and delete it thereafter.
7. Data residency
The App stores End-User Data exclusively within Atlassian apps and services that support data residency options. Data residency controls are provided by Atlassian for eligible services.
8. Automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
9. Your rights as a data subject
As a data subject, you have rights under the GDPR, including:
Right of access (Art. 15 GDPR)
Right to rectification (Art. 16 GDPR)
Right to erasure (Art. 17 GDPR)
Right to restriction of processing (Art. 18 GDPR)
Right to data portability (Art. 20 GDPR), where applicable
Right to object (Art. 21 GDPR) where processing is based on legitimate interests
Right to withdraw consent (Art. 7 GDPR), where processing is based on consent
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
Exercising these rights is subject to legal prerequisites and, in certain circumstances, rights may be limited due to legal exceptions.
To exercise your rights, please contact us using the details in Section 1.
10. Changes to this privacy policy
From time to time it may be necessary to amend the content of this Privacy Policy. We therefore reserve the right to change it at any time. We will publish the amended version of the Privacy Policy. The current version applies at the time you use the App.
Version: 1
Date: Jan 26, 2026