Riskward for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Riskward app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- Risk ratings are saved on your Jira issues as an issue property; the audit trail, settings, controls and Statement of Applicability are saved in your site's Forge storage.
- Reports and exports (evidence pack, CSV files) are created in the browser and saved to the user's device. Review reminders are sent by Jira's own notification email.
- Great Work LLC cannot see your risks, ratings or reports.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Risk assessment on an issue: likelihood and impact ratings (inherent, residual, target), scores, level, treatment, category, linked control ids, last review time and reviewer (Atlassian account id), next review date | The register, heat maps, JQL and reminders | Jira issue property riskward on the issue, until the issue is deleted or the property is removed |
| Audit trail per risk: time, Atlassian account id of the person, action, ratings, treatment, level, optional note | Review log, movement over time, evidence pack | Forge app storage until uninstall |
| Settings: risk model (labels, levels, colors, appetite), review cadence, reminder options, issue types, categories, risk manager and reminder group names, per-project overrides | To run the App | Forge app storage |
| Custom controls and Statement of Applicability entries (applicability, status, justification, who and when) | Control mapping and SoA export | Forge app storage |
| Reminder stamps (issue id, time of last reminder) | So owners are not reminded more often than you chose | Forge app storage |
| Issue keys, summaries, status, assignee, reporter, project, type, created and resolved dates read while showing the register | To show and report risks | In the browser and in memory during the request |
| CSV files users import | To create risk issues | In memory during the import; the created issues are ordinary Jira issues |
| Your account id, groups and permissions | To decide what you may change | In memory only |
The App does not read issue descriptions (it writes one when you import a description), comments or attachments, and it does not collect IP addresses, passwords, API tokens, payment card details or analytics. It sets no cookies and loads no third-party scripts or fonts.
3. Where data is stored
All App data is stored by Atlassian, in your Jira site (issue properties) or in Forge app storage for your site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
4. Who can see what
- Anyone who can see an issue in Jira can see its risk assessment, as with any issue field. The register, heat maps and reports only include issues the signed-in person can see.
- Changing ratings needs permission to edit the issue. Settings, controls, the Statement of Applicability and imports are limited to Jira admins, the risk manager groups an admin names and, for their own project, project admins.
- Reminder emails go only to people who can browse the issue.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
5. Retention and deletion
Ratings stay on the issue until the issue is deleted. The audit trail is append-only so it can serve as review evidence; uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process. Files you downloaded are under your organization's control.
6. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request. Please do not send risk details unless you need to.
7. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
8. Security
The App uses only Atlassian-hosted compute and storage, reads and writes Jira as the signed-in person (reminders are sent as the App), re-checks every permission on the server, and keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.
9. Children
The App is a business tool and is not directed to children under 16.
10. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
11. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company