PRIVACY POLICY

Last updated: 13 July 2026 · Version 1.0

This Privacy Policy explains how Revin Technologies UG (haftungsbeschränkt) (“we,” “us,” or “our”) collects, uses, stores, and shares (“processes”) personal information in connection with the Atlassian Marketplace app Security Provider for Jira (Built for Trivy) (the “App”), which connects results from the Trivy security scanner to a customer’s Jira instance.

It covers the App and its provision through the Atlassian Marketplace, not Atlassian’s own products or any third-party services with their own privacy notices.

Questions? Contact us at contact@revin-tech.com.

SUMMARY OF KEY POINTS

This summary states the key points in brief. The full sections below are authoritative.

Roles. We act as processor for the customer’s scan content under a data processing agreement (Art. 28 GDPR), and the customer is the controller. For our connection and security logs and support correspondence, we are the controller. Read more.

Data processed. Primarily technical data: metadata, findings, installation identifiers, intake keys, and configuration. Personal data is limited to IP addresses in security logs, personal data incidentally contained in scan results, and contact details from support requests. No special category data (Art. 9 GDPR) is sought. Read more.

Purposes and legal bases. Scan content is processed on the customer’s instructions to provide the App. Our own processing rests on legitimate interests (Art. 6(1)(f) GDPR) for security and support and on legal obligations (Art. 6(1)(c) GDPR). It is not used for advertising, analytics, or AI training. Read more.

Recipients. Our sub-processors, the Atlassian Forge platform on which the App partly runs and our EU hosting provider, and the customer’s own Jira instance. No sale and no disclosure for third-party purposes. Read more.

International transfers. Data on the servers we operate remains in the EU. Data handled by our Atlassian Forge sub-processor follows the customer’s data residency selection and may be transferred outside the EU under the EU-US Data Privacy Framework or the Standard Contractual Clauses (Art. 46 GDPR). Read more.

Retention. Data is kept only as long as necessary: installation data until uninstallation, connection logs no longer than 7 days, blocked IP addresses no longer than 30 days. Read more.

Rights. Data subjects may exercise the rights available under the GDPR (Art. 15 to 21), the Swiss FADP, PIPEDA, or applicable US state laws, and may lodge a complaint with the competent supervisory authority. For personal data within scan results, the customer as controller is the point of contact. Read more.

OUR ROLE

We handle information in two capacities. To deliver the App, we process the scan content a customer sends us on that customer’s behalf and instructions: here the customer is the controller and we are its processor under a data processing agreement. For our own connection and security logs and any message you send us, we decide why and how the data is used, so there we are the controller. Which role applies decides who is responsible for a given request, as explained in Section 3 and Section 10.

TABLE OF CONTENTS

  1. What information do we collect?
  2. How do we process your information?
  3. What legal bases do we rely on?
  4. Who we share your information with
  5. Where is your information stored?
  6. How long do we keep your information?
  7. How do we keep your information safe?
  8. Do we make automated decisions?
  9. Do we collect information from minors?
  10. What are your privacy rights?
  11. Do United States residents have specific privacy rights?
  12. Do we make updates to this policy?
  13. How can you contact us?

1. WHAT INFORMATION DO WE COLLECT?

The App receives the Trivy scan results a customer chooses to send and makes them available in that customer’s Jira instance. The customer determines what to send and may filter or reduce it beforehand. We do not read account, profile, or user data from Jira and do not store login credentials; authentication is handled entirely by Atlassian.

Non-personal information

Most of what the App processes is technical, describes systems rather than people, and cannot be linked to an identifiable person:

Personal information

Personal information can arise only in these limited cases:

We neither seek nor request this personal information. If it does appear in scan content, we process it solely on the customer’s behalf and instructions, in the same manner as any other scan result: storing it and transferring it to the customer’s Jira instance to deliver the App, and deleting it from our systems on the customer’s instruction. The customer is the controller of that content, determines what is submitted, and is responsible for it. We recommend removing or rotating any detected secrets without delay.

Sensitive information

We neither seek nor request special category data (Art. 9 GDPR), and the App is not designed to process it. If such data does appear incidentally in scan content, we handle it in the same manner: processing it solely to deliver the App, on the customer’s behalf, and deleting it from our systems on the customer’s instruction.

2. HOW DO WE PROCESS YOUR INFORMATION?

We process information for the purposes below. Where these concern the customer’s scan content, we pursue them on the customer’s behalf and instructions, not for our own ends:

Scan content is required to use the App; without it, the App cannot produce results. Providing it is a technical requirement, not a statutory obligation, and the sole consequence of not providing it is that the App cannot be delivered.

We do not process personal information for advertising, cross-product analytics, or training AI models.

Our legal footing depends on which role applies (see Our role).

As a processor. We process the scan content, metadata, installation identifiers, intake keys, and configuration needed to deliver the App on the customer’s behalf and documented instructions, under a data processing agreement (Art. 28 GDPR). The customer is the controller and is responsible for the legal basis and for informing the individuals concerned.

As the controller. For information we process for our own purposes, we rely on:

For individuals in Canada, where PIPEDA requires consent and we are the controller, we rely on your consent, express where appropriate or implied through your use of the App, for the purposes above. Where we process a customer’s scan content for that customer, the customer obtains any consent PIPEDA requires. You can withdraw consent you gave us at any time by contacting us, subject to legal or contractual limits and reasonable notice.

4. WHO WE SHARE YOUR INFORMATION WITH

We do not sell your personal information, share it for advertising, or disclose it to third parties for their own purposes. As noted in Section 1, most information here is technical and identifies no one; personal information arises only in the limited cases described there.

The customer’s own Jira instance. We transfer the scan results back to the customer’s own Jira instance through the Atlassian platform, so that they are available within it.

Providers we rely on (our sub-processors). The App runs partly on the Atlassian Forge platform and partly on servers we operate at a hosting provider in the EU. Both act only on our instructions and do not use your information for their own purposes; where we act as a processor, they are our sub-processors, engaged with the customer’s authorization under our data processing agreement. We run part of the App on Atlassian Forge under Atlassian’s Forge Data Processing Addendum, under which Atlassian processes data on our behalf. This is separate from the customer’s own, direct relationship with Atlassian for its Jira instance and the Atlassian Cloud products, which the customer uses under its own agreement with Atlassian and which is governed by Atlassian’s own terms and privacy policy (linked below). In the rare case that scan results contain personal information, which we neither request nor deliberately collect, it may pass through these sub-processors as part of running the App:

Sub-processor Role Privacy information
Atlassian (Atlassian Pty Ltd) Provides the Atlassian Forge platform on which the App partly runs, including its hosted storage, under the Forge Data Processing Addendum https://www.atlassian.com/legal/privacy-policy
Hetzner Online GmbH Hosts the servers we operate within the EU https://www.hetzner.com/legal/privacy-policy/

Support correspondence. When you contact us for support, we use your message and contact details solely to receive and answer your request, and for no other purpose.

Business transfers. In a merger, acquisition, financing, or sale of assets, information may be transferred as part of the deal. We will require any recipient to keep protecting it consistent with this policy.

5. WHERE IS YOUR INFORMATION STORED?

The App runs in two parts, so your information is held in two locations.

On the servers we operate (EU). The scan results, metadata, installation identifiers, and the IP addresses in our security logs are held on servers we operate at a hosting provider in the EU (see Section 4). Of these, only the IP addresses and any personal data a customer’s scan results happen to contain (see Section 1) relate to an identifiable person; the rest is technical.

On the Atlassian platform. The intake keys and configuration are held on the Atlassian Forge platform, our sub-processor (see Section 4), through which scan content also passes in transit. Their location depends on the Atlassian data residency the customer selects, not on us. Because Atlassian is a US provider, this data may be located outside the EU, including in the United States, relying, under Atlassian’s Forge Data Processing Addendum, on Atlassian’s safeguards: the EU-US Data Privacy Framework adequacy decision, under which Atlassian is certified (verifiable at dataprivacyframework.gov), or the Standard Contractual Clauses (Art. 46 GDPR). For people in Switzerland, the transfers rely on the Swiss equivalents, the Swiss-US Data Privacy Framework and the Standard Contractual Clauses recognised by the Swiss Federal Data Protection and Information Commissioner; transfers to our EU servers are covered by Switzerland’s recognition of the EEA as adequate. You may obtain further information on these safeguards, or a copy where one is available, by contacting us.

6. HOW LONG DO WE KEEP YOUR INFORMATION?

We keep personal information only as long as needed for the purposes in this policy:

We may keep information longer where the law requires or allows it, for example to meet tax or accounting obligations or to establish, exercise, or defend legal claims. Where we cannot delete something at once, for example because it remains in backups, we isolate it from further processing until deletion is possible.

7. HOW DO WE KEEP YOUR INFORMATION SAFE?

We use appropriate technical and organizational measures to protect the data we process from loss, misuse, and unauthorized access. Transmissions to our servers are encrypted in transit. Data at rest is protected by access controls limited to authorized personnel, logical separation of each installation’s data by its installation identifier, and the physical and infrastructure security of our EU data centres. However, no method of transmission or storage can be guaranteed to be completely secure.

8. DO WE MAKE AUTOMATED DECISIONS?

We do not make decisions with legal or similarly significant effects about you by solely automated means. Automatically blocking abusive IP addresses serves only IT security and is not an automated decision in an individual case under Art. 22 GDPR.

9. DO WE COLLECT INFORMATION FROM MINORS?

The App is intended for businesses and their staff, not for children, and we do not knowingly collect children’s information. If you believe a child has given us information, contact us using the details in Section 13 and we will delete it.

10. WHAT ARE YOUR PRIVACY RIGHTS?

Which rights apply, and who handles them, depends on our role for the information (see Section 3). For information we hold as the controller, in particular our connection and security logs and any message you send us, you can ask us, wherever you are located, to access, correct, or delete it, to restrict how we process it, or to object to that processing.

In several places these rights are also guaranteed by law. In the EEA and the UK, they arise under the GDPR: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), and objection (Art. 21); for automated processing based on consent or a contract, you also have data portability (Art. 20). In Switzerland, equivalent rights arise under the Federal Act on Data Protection (FADP), notably access and rectification. In Canada, they arise under PIPEDA, notably access and correction. In the United States, they may arise under state privacy laws (see Section 11).

Your right to object (Art. 21 GDPR). Where we process personal data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), in particular the IP addresses in our connection and security logs, you have the right to object to that processing at any time on grounds relating to your particular situation. To exercise it, contact us using the details in Section 13.

How to exercise them. An informal message to the contact in Section 13 suffices. Where the law grants these rights, we honour them in accordance with applicable data protection law; where it does not, we act on your request as a matter of good practice. We may need to verify your identity first.

Personal data inside a customer’s scan results. Here we are a processor and the customer is the controller; the same content also resides in the customer’s own Jira instance. The customer is your primary contact for requests about this data. If you contact us, we will forward your request to the customer without undue delay and, on the customer’s instruction, remove the content from our systems and from the customer’s Jira instance, into which the App had written it. We do not erase it on our own decision.

Complaints. You may also lodge a complaint with your data protection authority: in the EEA, the supervisory authority where you are located or where the alleged infringement occurred (Art. 77 GDPR); in the UK, the Information Commissioner’s Office (ICO); in Switzerland, the Federal Data Protection and Information Commissioner; in Canada, the Office of the Privacy Commissioner of Canada. The authority that supervises us is the Unabhängiges Datenschutzzentrum Saarland (Die Landesbeauftragte für Datenschutz und Informationsfreiheit), Fritz-Dobisch-Straße 12, 66111 Saarbrücken, Germany.

11. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

Depending on your state, US privacy laws may grant you the rights in Section 10, plus the right to know whether we process your personal information and the right not to be discriminated against for exercising your rights.

We do not sell personal information or share it for targeted advertising, and the App does not track you across websites, so “Do-Not-Track” signals do not apply. To exercise a right, use the contact details in Section 13; if we decline, you may appeal by contacting us and, where applicable, complain to your state attorney general.

12. DO WE MAKE UPDATES TO THIS POLICY?

We update this policy when changes to the App or the law make it necessary. The version on this page applies, and material changes are marked by a new “Last updated” date at the top.

Version Date Change
1.0 13 July 2026 Initial version

13. HOW CAN YOU CONTACT US?

For the information we process as the controller (see Section 3), the responsible party is:

Revin Technologies UG (haftungsbeschränkt) St. Wendeler Str. 2 A 66640 Namborn, Germany Email: contact@revin-tech.com

The person accountable for how we handle personal information, including for Canada’s PIPEDA, is reachable at the contact details above.

We are not required to appoint a data protection officer under Art. 37 GDPR or § 38 BDSG, and we have not appointed one; for any data protection matter, please use the contact details above.


This policy also covers what the Atlassian Marketplace requires: the data the App collects and processes (Section 1), why (Section 2), who it is shared with (Section 4), where it is stored (Section 5), and users’ rights (Sections 10 and 11).