---
title: "Sync - Security & Privacy (App)"
canonical: "https://helpcenter.mindproapps.com/space/sync/1948024854/Sync%20-%20Security%20%26%20Privacy%20(App)"
format: markdown
---
> ℹ️ **Summary: **In addition to the information available in our [Company Privacy Policy](https://mindproapps.com/privacy-policy/), our [Company Security Measures](https://mindproapps.com/security-measures/), and the details provided on the [Marketplace Privacy & Security Tab](https://marketplace.atlassian.com/apps/1226659/sync-azure-ad-entra-okta-onelogin-attributes-for-jira?hosting=cloud&tab=privacy-and-security), this page provides an overview of how this app accesses, manages, and protects your data, security, and privacy.

### **Data & Security Statement**

| ##### **Question** | ##### **Answer** |
| --- | --- |
| What permissions does the app require to work with my Atlassian Products? | Mindpro Sync integrates with your Atlassian product and requires the permissions below:<br>- View email addresses of users
- Act on a user's behalf, even when the user is offline
- Administer the host application
- Administer Jira spaces
- Delete data from the host application
- Write data to the host application
- Read data from the host application |
| What data does the app access / process? | The app processes the following types of Data:<br>- IdP's connection credentials
- IdP's fields' ids
- Jira Issues' id
- Jira Spaces' name and id
- Jira User emails
- IdP's user attributes data
- Jira Issue Fields' name and id |
| What data does the app store? | The app stores the following types of End-User Data:<br>- IdP's connection credentials
- Jira Spaces' name and id
- Jira Issues' id
- Jira Issue Fields' name and id |
| Where are the data stored? | Mindpro Sync is built with Atlassian’s latest development technology <u>[Atlassian’s latest development technology Forge.](https://developer.atlassian.com/platform/forge/)</u><br>That means that all data is stored and managed directly in <u>[Atlassian's Forge Storage environment](https://developer.atlassian.com/platform/forge/runtime-reference/storage-api/)</u>.<br>No customer-specific data is retrieved and stored in the Mindpro infrastructure. |
| How does the app use this collected data? | See below what each data group is used for:<br>- IdP's secret is used to establish the connection.
- Jira's user email is used to retrieve matching IdP's user email.
- IdPs' users data are used to update Jira Issues' fields values and display user information in Hierarchy.
- Jira Spaces, Jira Issues and Jira Issue Fields are used to update Jira Issues' fields values. |
| Does the app stores any sensitive (personal or non-personal) information? | Mindpro Sync stores your “IdP's connection credentials”, which can be considered a non-personal sensitive information.<br>This data is of course encrypted in the database, and access to it is highly controlled and restricted. |
| Does the app encode all data in transit and at rest? | Yes, all data is encrypted at rest and in transmission to prevent any unauthorized access and prevent data. |
| Who have access to the app data? | Mindpro Sync uses Atlassian's Forge platform, so all customer data is stored directly in Atlassian's cloud structure.<br>That is, the stored data of this app is not saved in any Mindpro infrastructure/database.<br>Due to this architecture, the Mindpro team cannot access any app data outside of when the tool is utilized through the UI. |
| Does the app support data residency? | Yes, this app supports Data Residency in all currently available regions:<br>- Global - All Atlassian cloud across AWS regions
- Australia - Consists of Australia (Sydney) region
- Canada - Consists of Canada (Central) region
- EU - Consists of Europe (Frankfurt) and Europe (Dublin) regions
- Germany - Consists of Europe (Frankfurt) region
- India - Consists of Asia Pacific (Mumbai) regions
- Japan - Consists of Asia Pacific (Tokyo) region
- Singapore - Consists of Asia Pacific (Singapore) region
- South Korea - Consists of Asia Pacific (Seoul) region
- Switzerland - Consists of Europe (Zurich) region
- United Kingdom - Consists of Europe (London) region
- USA - Consists of US East (North Virginia) and US West (North California) regions<br>To learn more, please see these additional resources:<br>- <u>[App - Privacy & Security tab in the Marketplace](https://marketplace.atlassian.com/apps/1231327/lineup-queues-service-management-hub-jira-jsm?hosting=cloud&tab=privacy-and-security)</u>
- <u>[Atlassian - Understand data residency](https://support.atlassian.com/security-and-access-policies/docs/understand-data-residency/)</u>
- <u>[Atlassian - Moving your Marketplace apps data to another location](https://support.atlassian.com/security-and-access-policies/docs/moving-your-marketplace-apps-data-to-another-location/)</u> |
| Does this app have certifications or participate in advanced security programs? | Atlassian - Security Badge “Runs on Atlassian”:<br>- This is a new Marketplace security badge awarded by Atlassian for Forge apps that only use Atlassian-hosted compute and storage, provide data residency in the same regions as Atlassian apps, and allow customers to control data egress.
- Mindpro Sync has earned this badge, and all the associated security requirements are continually monitored via automation to verify that they are continuously met.
- To learn more: <u>[ Atlassian - “Runs on Atlassian”](https://www.atlassian.com/blog/developer/runs-on-atlassian-now-available)</u><br>Atlassian - Forge and “SOC 2 Compliance”:<br>- Atlassian’s Forge platform is now SOC 2 certified, which means that cloud apps built on the Forge platform can inherit advanced security controls that help satisfy up to 30% of SOC 2 requirements.
- Important: SOC 2 control inheritance only applies to cloud apps with data that resides within the Forge boundary.
- In this case, Mindpro Sync is in full compliance with this requirement.
- To learn more: <u>[Atlassian - Forge and SOC 2 Compliance](https://developer.atlassian.com/platform/forge/forge-and-soc2/)</u><br>Atlassian - “Security Programs”:<br>- To learn more about the additional Atlassian Security Programs this app adheres to, please visit this link: <u>[Mindpro - Security Measures](https://mindproapps.com/security-measures/)</u> |
| Does the app have a data retention policy? | Forge apps (including Mindpro Sync) follow Atlassian's internal Standard Data Retention and Disposal policy, and how your data is stored or deleted varies according to the scenarios below:<br>Scenario - License suspension or deactivation:<br>- If an app's license is suspended or deactivated, the app becomes inactive, but the system keeps all the stored data without changes.
- The data remains unchanged while the app is inactive. A license suspension usually occurs when a customer misses a payment, such as after the grace period for payment recovery.
- Once the payment is resolved, the license is reactivated, and the app regains access to the existing data.<br>Scenario - App uninstallation:<br>- According to Atlassian Forge policies, when an app is uninstalled, the data is only “soft deleted,” and the Forge-hosted storage retains the data for 28 days after uninstallation.<br>Scenario - App reinstallation:<br>- If a Forge app is reinstalled, it is treated as a new installation, which means your app data from the previous installation is not automatically restored.
- However, according to Atlassian Forge policies, if a request is made within 21 days of uninstallation, the new installation can be relinked to the old data.
- The data recovery process is mediated by Marketplace Vendors in coordination with Atlassian.
- Therefore, to recover your data, you must submit a recovery request in our Support Portal using this<u>[ link](https://mindpro.atlassian.net/servicedesk/customer/portal/3/group/3/create/10235)</u> within 16 days of uninstallation, granting your consent to restore the data.
- This ensures a minimum period for us to mediate your request with Atlassian and guarantee that it is processed before the 21-day request period ends. |
| Does the app have a custom data deletion policy? | Mindpro cannot remove or access data for you due to the limited access to Atlassian's Forge Infrastructure.<br>However, you can request the deletion of this data on our Support Portal, and we will forward this request to Atlassian to carry out this process.<br>Upon this request, Atlassian will delete all End User Personal Data (including copies) processed on behalf of Mindpro in compliance with the procedures and retention periods outlined in <u>[Atlassian's Forge DPA](https://developer.atlassian.com/platform/forge/resources/Forge-Data-Processing-Addendum.pdf)</u>.<br>The data deletion process occurs only on demand and via explicit user request. To request the deletion of the data stored, you can open a ticket anytime directly on our support portal <u>[using this link](https://mindpro.atlassian.net/servicedesk/customer/portal/3/group/3/create/10235)</u>, and we will forward this request to Atlassian. |


> ℹ️ Please note that this document is not a legal document nor a guarantee. It should be treated as guidance on what the Mindpro team strives to accomplish in this area.

---

### **Need any help?**

Didn’t find what you were looking for? Get in touch at [security@mindproapps.com](mailto:security@mindproapps.com) or [open a security support ticket here.](https://mindpro.atlassian.net/servicedesk/customer/portal/3/group/3/create/10235)