Privacy Policy — Dependency Manager for Jira Cloud

Privacy Policy — Dependency Manager for Jira Cloud

This Privacy Policy explains how Divim, Inc. ("we", "us", "the vendor") handles data when a Jira Cloud site installs and uses Dependency Manager for Jira Cloud ("the app").

Last reviewed: 2026-06-15


1. Roles

Under GDPR / UK GDPR terminology, the customer (the Atlassian site's organization) is the data controller for the Jira data the app processes. Divim, Inc. acts as a data processor, and Atlassian is the subprocessor providing the Forge runtime on which the app runs.

2. What data the app processes

To build dependency maps and calculate the critical path, the app accesses:

  • Project, board, and fix version metadata

  • Issues and their fields (issue key, summary, status, priority, assignee, estimates, resolution dates)

  • Issue links ("blocks" / "is blocked by" and related relationships)

  • Jira user identifiers and display names where required to label nodes and queued changes

The app requests only the Jira scopes needed to enable these capabilities.

3. How data is used

Data is used solely to render the dependency experience — building the interactive dependency graph, calculating the critical path, detecting dependency cycles, surfacing cross-release blockers, and applying user-initiated link changes back to Jira. We do not use customer data for advertising, and we never sell customer data.

4. Storage and data egress

  • No external egress. The app makes no outbound calls outside Atlassian's cloud; no customer data is transmitted to Divim or any third party.

  • Forge-hosted storage. Operational data (configuration, layout state, and pending-change queues — for example issue and version identifiers and the account identifier of the user who queued a change) is stored in Atlassian Forge storage within your tenant.

  • Browser storage. A limited set of UI preferences (selected page, filters, view tweaks) is stored in the browser's localStorage to restore your experience after reload.

5. Encryption

Data is encrypted in transit (HTTPS / TLS) and at rest (Atlassian-managed Forge storage). See the Security Policy for the full security posture.

6. Data residency

Persisted data follows the data-residency region of your host Jira Cloud site, inherited automatically from Atlassian Forge. Divim operates no separate data store for this app.

7. Retention and deletion

Operational data persists in Forge storage while the app is installed and in use; browser UI preferences persist in the user's browser until cleared. On uninstall, associated app data is removed as part of the standard Atlassian Forge app-removal lifecycle. Customers may request deletion of app-specific data via support@divim.io.

8. Data subject rights

Because the customer is the controller of the Jira data, data-subject requests (access, correction, deletion, restriction, portability, objection) are typically satisfied through the customer's own Jira administration tools or Atlassian's processes. For assistance with app-specific data, contact support@divim.io; we respond within the timeframes required by applicable law and within 30 days of a verified request.

9. Children

The app is a business-to-business product intended for Jira Cloud administrators and teams. It is not directed at children and does not knowingly process children's data.

10. Changes & contact

Material changes are announced through the Atlassian Marketplace listing and the Divim Trust Center. For privacy and data-subject requests: support@divim.io.


This policy applies specifically to Dependency Manager for Jira Cloud. For Divim's company-wide posture, see the Divim Trust Center.