Joinwell for Jira Service Management: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Joinwell app for Jira Service Management Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- It stores your playbooks, settings and a record of each onboarding, offboarding or role change run (which tasks were created, their due dates and states) in Atlassian's app storage for your site.
- Great Work LLC cannot see your playbooks, your requests or who they are about.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Playbooks: names, request types, field ids, conditions (department, location, role values), JQL, task templates, assignee account ids, escalation account ids | To decide which tasks to create and for whom | Forge app storage for your site, until deleted or uninstall |
| Runs: request id and key, space id, playbook name, the employee name, department, location and role read from the request, the start or last day, state and dates | Progress, the dashboard and reminders | Forge SQL for your site, until uninstall |
| Run tasks: title, team, target space and work type, created work item id and key, due date, assignee account id, state, error text, reminder and escalation times | Progress, dependencies and reminders | Forge SQL for your site, until uninstall |
Work items the App creates, links, comments, the jw-run and jw-task issue properties, and transitions it makes | The onboarding work itself | Your Jira site, like other Jira content |
| Overdue reminders and escalations | Sent through Jira's own notification email to people who can see the task | Jira |
| Activity log: what started, finished, failed or escalated | Troubleshooting for admins | Forge app storage, deleted after 30 days |
| Account ids, display names and permissions of the person using the App | To check what they may do and show names | In memory only |
The App does not collect email addresses, IP addresses, passwords, API tokens, payment card data or analytics. It sets no cookies and loads no third-party scripts or images. The employee name, department, location and role are whatever your request fields contain; do not put sensitive HR data (salary, health) in fields a playbook reads.
3. Where data is stored
All App data is stored by Atlassian in Forge app storage, Forge SQL or your Jira site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
4. Who can see what
- Requesters (portal customers): for requests Jira lets them view, the number of steps done and each step's title, team, due date and state for steps the playbook marks "Show on the portal". No assignee names, no internal keys.
- People who can see the request in Jira: its progress panel (task titles, owners, due dates, states). Editing the run (retry, cancel) needs permission to edit the request.
- The dashboard: runs on requests in spaces the viewer can browse.
- Jira admins: playbooks, settings, activity, dry runs.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
5. Retention and deletion
Playbooks stay until an admin deletes them. Run records stay until uninstall so finished onboardings can still be reviewed. Uninstalling removes the App's Forge storage according to Atlassian's Forge data deletion process. Work items, links, comments and issue properties the App created stay in your Jira like any other Jira content.
6. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.
7. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; your admins can delete playbooks, cancel runs or uninstall the App. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
8. Security
The App uses only Atlassian-hosted compute and storage. Admin features are only reachable from the Jira admin page, run changes are checked against the right to edit the request, the dashboard only lists requests in spaces the viewer can browse, and portal customers only see progress on requests Jira lets them view. It keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.
9. Children
The App is a business tool and is not directed to children under 16.
10. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
11. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company