Rechtliches

Privacy Policy

AnyLLM for Jira & Confluence · maplee GmbH · Last updated: 12 August 2026

1. Overview

This Privacy Policy describes how maplee GmbH ("we", "our", "us") processes personal data in connection with the Atlassian Marketplace app AnyLLM for Jira & Confluence(the "App"). The App is built on the Atlassian Forge platform and runs entirely within your Atlassian Cloud environment. We are committed to handling your data transparently and in compliance with the EU General Data Protection Regulation (GDPR) and applicable data protection law.

2. Data Controller

The controller responsible for data processing is:

maplee GmbH
Wolfseggerstraße 23
93138 Lappersdorf, Germany

E-Mail: kontakt@maplee.de

3. Data We Collect and Process

The App processes the following categories of data solely to provide its functionality:

  • Jira issue content: summary, description, and comments of issues on which the App is explicitly invoked by a user action. This data is submitted to the LLM provider you have configured.
  • Confluence page content: body text of pages on which the App is explicitly invoked. This data is submitted to the configured LLM provider.
  • Atlassian account identifiers: the Atlassian account ID of the user who triggered a request, used only for audit logging within your Atlassian environment.
  • App configuration: the LLM provider endpoint and API key you supply in the App settings. API keys are stored encrypted in Atlassian Forge's secure storage and are never transmitted to maplee GmbH servers.
  • Usage metadata: anonymised request counts (no content) stored in Forge storage for licence enforcement purposes only.

We do not collect names, e-mail addresses, or any other personal data beyond what is listed above. We do not use cookies or tracking technologies on the App surfaces inside Jira and Confluence.

4. Purpose and Legal Basis for Processing

  • Contract performance (Art. 6 para. 1 lit. b GDPR): Processing issue and page content is strictly necessary to deliver the AI-assisted functionality you or your organisation have contracted for.
  • Legitimate interests (Art. 6 para. 1 lit. f GDPR): Anonymised usage metadata is processed to enforce fair use of the licence and to monitor App stability.
  • Legal obligation (Art. 6 para. 1 lit. c GDPR): We retain basic transaction records to comply with commercial and tax law obligations.

5. Transfer of Data to Third-Party LLM Providers

When you configure a third-party LLM provider (e.g. OpenAI, Anthropic, Azure OpenAI, or a self-hosted model endpoint), the content you submit through the App is transmitted to that provider's API. You are responsible for reviewing and accepting the privacy policy and data processing terms of any LLM provider you choose. maplee GmbH has no influence over how third-party LLM providers process or retain submitted content.

We recommend configuring only providers that offer a Data Processing Agreement (DPA) and, where applicable, an EU data residency option — especially if your Jira or Confluence data includes personal data subject to GDPR.

6. Data Storage and Security

  • All App data — configuration, audit logs, and usage metadata — is stored in Atlassian Forge's managed storage, which is subject to Atlassian's own security controls and data residency settings. No data is stored on maplee GmbH servers.
  • API keys are stored using Atlassian Forge's encrypted secret storage and are never readable by maplee GmbH at any point.
  • All communication between the App, Atlassian APIs, and configured LLM endpoints uses TLS 1.2 or higher.
  • Access to App settings and invocation is restricted by standard Atlassian permission controls in your Jira and Confluence instance.

7. Data Retention

  • Issue and page content is only held in memory for the duration of a single LLM request and is never persisted by the App beyond that request.
  • Audit log entries (account ID + timestamp + action type) are retained for 90 days in Forge storage, after which they are automatically deleted.
  • Usage metadata is retained for the duration of the active licence and deleted within 30 days of licence termination.
  • Configuration data (including encrypted API keys) is deleted immediately upon uninstallation of the App from your Atlassian site.

8. Your Rights as a Data Subject

Under the GDPR you have the following rights regarding personal data we process:

  • Access (Art. 15 GDPR): Right to obtain confirmation of and access to your data.
  • Rectification (Art. 16 GDPR): Right to have inaccurate data corrected.
  • Erasure (Art. 17 GDPR): Right to request deletion of your data.
  • Restriction (Art. 18 GDPR): Right to restrict processing in certain circumstances.
  • Portability (Art. 20 GDPR): Right to receive your data in a machine-readable format.
  • Objection (Art. 21 GDPR): Right to object to processing based on legitimate interests.
  • Complaint: Right to lodge a complaint with a data protection supervisory authority (in Germany: Bayerisches Landesamt für Datenschutzaufsicht, BayLDA).

To exercise any of these rights, please contact us at kontakt@maplee.de. We will respond within 30 days.

9. Atlassian Marketplace and Platform Terms

The App is distributed through the Atlassian Marketplace and is subject to the Atlassian Marketplace Vendor Agreement and Atlassian's Privacy Policy. Atlassian acts as an independent controller for data processed through its platform infrastructure. For data processed by Atlassian as a processor on your behalf, the terms of your Atlassian agreement apply.

10. Changes to This Policy and Contact

We may update this Privacy Policy from time to time. The current version is always available at https://www.maplee.de/legal/anyllm/privacy. Material changes will be announced via the Atlassian Marketplace listing. Continued use of the App after a policy update constitutes acceptance of the revised terms.

For any questions, data subject requests, or concerns regarding this Privacy Policy, please contact us:

maplee GmbH
Wolfseggerstraße 23
93138 Lappersdorf, Germany

E-Mail: kontakt@maplee.de