ProjectBalm

Data security and privacy

Jira data residency and privacy overview

How Risk Register handles Jira site information, application configuration, customer risk data, technical logs, access, backups, and tenant data when service ends.

Data storage

What data is stored?

Risk Register for Jira Server

Risk Register for Jira Server does not transfer your data from the machine that hosts Jira Server. All data remains in the database management system configured for Jira Server.

Risk Register for Jira Cloud

Risk Register for Jira Cloud stores specified Jira site and app configuration information on ProjectBalm systems.

Jira Cloud site and app configuration information

  • Jira Cloud instance identifier
  • Jira Cloud base URL
  • Support Entitlement Number (SEN)
  • Jira Cloud version
  • Atlassian app framework version
  • OAuth 2.0 client ID for Risk Register
  • Risk Register app status
  • Risk model definitions, including model element names, IDs, and descriptions
  • Project-specific configuration, including project ID, risk issue type ID, and risk register name

Customer-controlled information

Customer risk data remains in Jira

ProjectBalm does not store the following customer risk data. This information remains in the customer’s Jira Cloud instance.

Risk issue keys
Risk names
Risk details
Impact values
Probability values
Risk assessments

For troubleshooting, Risk Register for Jira Cloud stores technical logs for up to 30 days.

Data residency

Where is the data stored?

Data stored by ProjectBalm is hosted on a secure server in Frankfurt, Germany. The ProjectBalm database is not exposed directly to the internet and is located in a network-isolated environment accessible only to the Risk Register application and authorised administrators.

People and access

Authorised access only

Only authorised ProjectBalm staff can access logs and database-stored configuration data.

Backups

Protected backup data

ProjectBalm regularly backs up data stored by Risk Register for Jira Cloud. Backup protections are at least as comprehensive as the protections applied to the live database.

Privacy

Data used only to operate Risk Register

ProjectBalm stores data only as a direct consequence of operating the Risk Register for Jira Cloud app and only for that purpose. ProjectBalm will not sell or release that data to anyone, except where disclosure is required by law.

Service exit

Tenant data is sanitised after uninstall

When a customer uninstalls Risk Register for Jira Cloud, ProjectBalm automatically sanitises its computing resources of tenant data.

Questions about security, privacy, or data handling?