Effective Date: January 1, 2025 · Last Updated: July 23, 2026 · Company: DataPingo
Security at a Glance
DataPingo builds exclusively on Atlassian's Forge platform. All infrastructure, hosting, encryption, and runtime security is provided and managed by Atlassian. DataPingo does not operate independent servers, databases, or cloud infrastructure. We do not hold any third-party security certifications (such as SOC 2, ISO 27001, or PCI-DSS) independently — our security posture is inherited from and governed by Atlassian's platform.
1. Platform & Infrastructure
1.1 Atlassian Forge
All DataPingo apps are built on Atlassian Forge — Atlassian's hosted serverless platform. This means:
- No external servers: DataPingo does not run or manage any servers, databases, or cloud infrastructure outside of Atlassian.
- No data egress: App code runs inside Atlassian's infrastructure. Data never leaves Atlassian's environment to reach DataPingo systems.
- Atlassian-managed security: Encryption, network security, runtime isolation, and infrastructure hardening are all handled by Atlassian.
- Automatic updates: The Forge runtime receives security patches from Atlassian automatically.
For full details on Atlassian's infrastructure security, see atlassian.com/trust/security.
2. Data Handling
2.1 What Data Each App Accesses
Bulk Page Cloner for Confluence
- Read scope: Reads the selected template page (content, formatting, images, video, macros, labels, and attachments) only at the moment of cloning. No page data is retained by the app after the operation completes.
- Write scope: Creates new Confluence pages in the destination space/parent chosen by the user.
- App storage: Uses Forge KV Storage for app state (e.g. UI preferences). This storage is isolated per Atlassian tenant and not accessible outside of Atlassian.
- No personal data stored: The app does not collect, log, or store Confluence page content, user identifiers, or metadata on any external system.
Bulk Comments for Jira
- Scopes requested:
read:jira-work,write:jira-work,read:jira-userandstorage:app. No others. - Read scope: Reads Jira issue and comment details — including existing comment content and media — to populate ticket search results and the source comment being copied.
- Write scope: Posts comments to the Jira issues you select and uploads their attachments. Comment text and media move between tickets entirely inside Atlassian's infrastructure.
- Acts as you, not as itself: The two Jira scopes are granted with impersonation, so every comment and file is created under your own Atlassian account and is subject to your existing Jira permissions. The app cannot reach an issue you could not reach yourself.
- Attachment staging: Files you attach are uploaded to Atlassian's Forge Object Store, copied into each selected issue, and deleted. Uploads that are never sent expire automatically within one hour. Object Store is Atlassian infrastructure, isolated per Atlassian site.
- App storage: Apart from those staged files, stores only per-ticket job status for the send queue in Forge storage — isolated per Atlassian tenant and not accessible outside of Atlassian.
- No external transmission: No Jira issue data, comment content, or media is sent to DataPingo or any third party.
2.2 Data Minimization
Each app requests only the Atlassian API scopes necessary to deliver its core functionality. Scopes are listed in each app's Marketplace listing under the Privacy & Security tab.
2.3 GDPR & Personal Data
DataPingo apps run entirely on Atlassian Forge and declare no external egress, so no end-user data is processed or stored outside Atlassian's infrastructure. On each app's Marketplace listing we have declared, and Atlassian has approved, that DataPingo is neither a data controller nor a data processor under the GDPR with reference to that app. Those declarations are public on the Privacy & Security tab of every listing.
An app may read personal data in the course of doing its job — resolving a name for an @mention, for example — but it does not retain it. What each app keeps in Atlassian's own storage is itemised in its documentation, and uninstalling removes it.
Customer contact details reach us only through the Atlassian Marketplace. We do not sell, distribute or share that information. See our Privacy Policy for what we hold and your rights over it.
3. Atlassian Marketplace Trust & Compliance
All DataPingo apps are reviewed and listed on the Atlassian Marketplace. By listing on the Marketplace, apps must comply with:
- Atlassian Marketplace Partner Agreement
- Atlassian Privacy Policy
- Atlassian's data residency, security, and personal data reporting requirements
DataPingo does not hold independent certifications such as SOC 2 Type II, ISO 27001, or PCI-DSS. Security assurances are provided through Atlassian's platform compliance.
4. Access & Permissions
DataPingo team members do not have access to your Atlassian data. App code runs in an isolated Forge sandbox within Atlassian's infrastructure — DataPingo cannot query or extract tenant data outside of what the app surfaces to the authenticated user.
5. Incident Response
If you discover a security vulnerability or data concern related to a DataPingo app:
- Email security@datapingo.com with a description of the issue. Please do not open a public ticket or post details anywhere public until we have had a chance to fix it.
- A confirmed security issue is treated as Critical, so you will hear from a person within 1 business day and we will give you a resolution timeline then. Response targets live in one place — the table in our Service Level Agreement.
- For platform-level security issues (Forge infrastructure, Atlassian APIs), please also report to Atlassian's bug bounty program.
- Not sure whether something is a security issue? Raise a ticket on the support portal and we will route it. If it turns out to be a vulnerability, please move the conversation to security@datapingo.com rather than leaving details in a portal ticket.
6. Policy Updates
This page is updated when DataPingo's data handling practices change. Material changes will be announced via our website. Continued use of our app constitutes acceptance of the current policy.
Contact
- Questions about this policy: contact@datapingo.com
- Vulnerability reports & security incidents: security@datapingo.com
- Support portal: Raise a ticket
- Legal: Privacy Policy · Terms of Service
Last updated: July 23, 2026