Security Policy

Our commitment to protecting your data and maintaining security standards.

Effective Date: January 1, 2025  ·  Last Updated: July 23, 2026  ·  Company: DataPingo

Security at a Glance

DataPingo builds exclusively on Atlassian's Forge platform. All infrastructure, hosting, encryption, and runtime security is provided and managed by Atlassian. DataPingo does not operate independent servers, databases, or cloud infrastructure. We do not hold any third-party security certifications (such as SOC 2, ISO 27001, or PCI-DSS) independently — our security posture is inherited from and governed by Atlassian's platform.

1. Platform & Infrastructure

1.1 Atlassian Forge

All DataPingo apps are built on Atlassian Forge — Atlassian's hosted serverless platform. This means:

  • No external servers: DataPingo does not run or manage any servers, databases, or cloud infrastructure outside of Atlassian.
  • No data egress: App code runs inside Atlassian's infrastructure. Data never leaves Atlassian's environment to reach DataPingo systems.
  • Atlassian-managed security: Encryption, network security, runtime isolation, and infrastructure hardening are all handled by Atlassian.
  • Automatic updates: The Forge runtime receives security patches from Atlassian automatically.

For full details on Atlassian's infrastructure security, see atlassian.com/trust/security.

2. Data Handling

2.1 What Data Each App Accesses

Bulk Page Cloner for Confluence

  • Read scope: Reads the selected template page (content, formatting, images, video, macros, labels, and attachments) only at the moment of cloning. No page data is retained by the app after the operation completes.
  • Write scope: Creates new Confluence pages in the destination space/parent chosen by the user.
  • App storage: Uses Forge KV Storage for app state (e.g. UI preferences). This storage is isolated per Atlassian tenant and not accessible outside of Atlassian.
  • No personal data stored: The app does not collect, log, or store Confluence page content, user identifiers, or metadata on any external system.

Bulk Comments for Jira

  • Scopes requested: read:jira-work, write:jira-work, read:jira-user and storage:app. No others.
  • Read scope: Reads Jira issue and comment details — including existing comment content and media — to populate ticket search results and the source comment being copied.
  • Write scope: Posts comments to the Jira issues you select and uploads their attachments. Comment text and media move between tickets entirely inside Atlassian's infrastructure.
  • Acts as you, not as itself: The two Jira scopes are granted with impersonation, so every comment and file is created under your own Atlassian account and is subject to your existing Jira permissions. The app cannot reach an issue you could not reach yourself.
  • Attachment staging: Files you attach are uploaded to Atlassian's Forge Object Store, copied into each selected issue, and deleted. Uploads that are never sent expire automatically within one hour. Object Store is Atlassian infrastructure, isolated per Atlassian site.
  • App storage: Apart from those staged files, stores only per-ticket job status for the send queue in Forge storage — isolated per Atlassian tenant and not accessible outside of Atlassian.
  • No external transmission: No Jira issue data, comment content, or media is sent to DataPingo or any third party.

2.2 Data Minimization

Each app requests only the Atlassian API scopes necessary to deliver its core functionality. Scopes are listed in each app's Marketplace listing under the Privacy & Security tab.

2.3 GDPR & Personal Data

DataPingo apps run entirely on Atlassian Forge and declare no external egress, so no end-user data is processed or stored outside Atlassian's infrastructure. On each app's Marketplace listing we have declared, and Atlassian has approved, that DataPingo is neither a data controller nor a data processor under the GDPR with reference to that app. Those declarations are public on the Privacy & Security tab of every listing.

An app may read personal data in the course of doing its job — resolving a name for an @mention, for example — but it does not retain it. What each app keeps in Atlassian's own storage is itemised in its documentation, and uninstalling removes it.

Customer contact details reach us only through the Atlassian Marketplace. We do not sell, distribute or share that information. See our Privacy Policy for what we hold and your rights over it.

3. Atlassian Marketplace Trust & Compliance

All DataPingo apps are reviewed and listed on the Atlassian Marketplace. By listing on the Marketplace, apps must comply with:

DataPingo does not hold independent certifications such as SOC 2 Type II, ISO 27001, or PCI-DSS. Security assurances are provided through Atlassian's platform compliance.

4. Access & Permissions

DataPingo team members do not have access to your Atlassian data. App code runs in an isolated Forge sandbox within Atlassian's infrastructure — DataPingo cannot query or extract tenant data outside of what the app surfaces to the authenticated user.

5. Incident Response

If you discover a security vulnerability or data concern related to a DataPingo app:

  • Email security@datapingo.com with a description of the issue. Please do not open a public ticket or post details anywhere public until we have had a chance to fix it.
  • A confirmed security issue is treated as Critical, so you will hear from a person within 1 business day and we will give you a resolution timeline then. Response targets live in one place — the table in our Service Level Agreement.
  • For platform-level security issues (Forge infrastructure, Atlassian APIs), please also report to Atlassian's bug bounty program.
  • Not sure whether something is a security issue? Raise a ticket on the support portal and we will route it. If it turns out to be a vulnerability, please move the conversation to security@datapingo.com rather than leaving details in a portal ticket.

6. Policy Updates

This page is updated when DataPingo's data handling practices change. Material changes will be announced via our website. Continued use of our app constitutes acceptance of the current policy.

Contact

Last updated: July 23, 2026