Who is responsible
The customer determines why and how its tenant registry data is used, and Ing. Martin Pristaš, trading as Qentra Technologies, processes that data to provide the service. Qentra independently determines the purposes of its account, entitlement, support, fraud-prevention, security and legal records. Exact roles depend on the customer use and applicable law; the applicable order and DPA control. Privacy enquiries: support@qentra.tech.
What we deliberately do not store
The registry does not store Atlassian account IDs, user names, email addresses or Jira user profiles. It does not read or store Jira issue content, comments, descriptions, attachments or conversations. It never invokes MCP tools and does not collect tool inputs, tool results or chat transcripts. Raw MCP JSON input schemas are hashed in memory and discarded. Free-form owner contacts, evidence summaries, source references and artifact URLs are rejected. Contact details and URLs are rejected in display labels, and tool identifiers must be machine-readable.
Necessary operational data and purpose
The remote service stores a random Forge installation identifier, Jira API route and configured project key; an authorized organizational MCP endpoint and non-personal server/tool identifiers; a controlled responsible-function value; environment and data classification; schema hashes; evidence signals and artifact digests; trust assessments, findings and audit metadata; and Jira remediation issue IDs or keys. Customers must not enter personal data or human contact details in registry fields. Credentials and short-lived Forge system tokens are encrypted before database storage. These records support inventory, assessment, drift detection, requested Jira remediation and service security. They are not sold, used for advertising or used for cross-customer model training. Marketplace billing is handled by Atlassian.
Logs and abuse protection
Application request logging is disabled. Authorization headers, OAuth tokens and request bodies are never written to application logs, and unexpected errors are recorded only as a fixed internal category. Network addresses are converted immediately to a secret-keyed one-way digest used only for a short rate-limit window. The app does not share end-user log data with analytics or advertising providers.
Retention and deletion
Primary tenant records remain until customer deletion or app uninstall. Cached Forge tokens expire within 90 minutes, replay identifiers at signed-invocation expiry, completed queue jobs within one hour and failed queue jobs within 24 hours. Encrypted Azure Recovery Services backups retain 14 daily and 4 weekly recovery points. Deleted data may remain in protected recovery points until scheduled expiry; backups are not used for ordinary processing. The isolated restore and deletion-replay procedure remains a release gate.
Location and service providers
The single-region Qentra remote runs in Microsoft Azure Poland Central on a shared Qentra-managed virtual machine. Microsoft provides compute, managed disks, secrets storage and encrypted recovery backups. Atlassian provides Jira Cloud, Forge invocation and Marketplace licensing or billing. The app does not offer customer-selectable residency, Forge PINNED status or realm migration. Qentra received an external legal review on 31 August 2026; reviewer verification and binding that approval to exact document versions remain in progress. Contracting entities, transfer safeguards and the notice period for material changes are confirmed in the applicable customer agreement and DPA.
Security and choices
Traffic uses HTTPS, tenant access is isolated at the application and database layers, credentials use authenticated application-layer encryption, outbound endpoints are restricted and administrative Jira actions require a live project-admin permission check. The shared VM is not a dedicated customer environment. Depending on applicable law, individuals may have rights of access, correction, deletion, restriction, objection and portability through the customer or Qentra. Contact support@qentra.tech for privacy requests and vulnerability reports. See also Security and Support.