---
title: "Data Security & Privacy Statement"
canonical: "https://support.55degrees.se/space/SP/4138074121/Data%20Security%20%26%20Privacy%20Statement"
format: markdown
---
> Macro (refined-tabs)
> 
> > Macro (refined-tab)
> 
> [jira cloud & data center]
> 
> **Overview** 
> 
> This document is in addition to the [55 Degrees Privacy](https://www.55degrees.se/legal/privacy) document and the Customer Agreements for Jira [Cloud](https://www.55degrees.se/agreement-cloud-products) or [OnPrem](https://www.55degrees.se/legal/customer-agreements/onpremise-products) products (including the [DPA](https://www.55degrees.se/legal/customer-agreements/atlassian-cloud-products#DPA)) provided by 55 Degrees. It explains how ActionableAgile™️ Analytics for Jira stores the data it captures. This document will be updated as new features are added.
> 
> **Data Storage Terms & Location**
> 
> The app retrieves data from the customer Jira instance (for example [yourinstance.atlassian.net](http://yourinstance.atlassian.net)) using the Atlassian provided rest API. Once retrieved, a subset data is stored in the local browser using DOM localStorage in order to improve any future data retrievals. The end-user can at any time empty the localStorage through the User Interface.
> 
> **Configurations:**
> 
> - **Jira Cloud: **
>   - App settings specific to the individual user are stored in the user’s user properties in Jira.
>   - For data set and data set views, we store the configuration data in AWS. We only store minimal configuration information for creating queries and never any of your Jira issue data. [https://support.55degrees.se/space/SP/3925246386](https://support.55degrees.se/space/SP/3925246386)
> - **Jira Data Center: **all configurations, user or collaborative, are stored within your Jira instance.
> 
> > ℹ️ We **DO NOT** export and store your Jira issue data - EVER.
> 
> Please read the [product documentation](https://support.55degrees.se/page/guides) for further details.
> 
> **Hosting Vendors**
> 
> **Jira Cloud: **At this time, 55 Degrees utilizes two vendors to host the functionality within ActionableAgile Analytics for Jira:
> 
> - DigitalOcean (utilizing the Frankfurt and Amsterdam DataCenters)
> - Amazon AWS (S3 Global)
> 
> **Jira Data Center:** All actions happen on your local instance and the user's browser.
> 
> **Logging Vendors**
> 
> **Jira Cloud:** 
> 
> - We have logs in AWS and DigitalOcean to support operations there.
> - We make use of [http://sentry.io](http://sentry.io)  to collect any javascript errors in the browser.
> - We are aggregating logs in DataDog.
> 
> **Jira Data Center**: At this time, we do not collect any logs in an automated fashion and rely on the user to assist in any troubleshooting.
> 
> **Product Analytics Vendors**
> 
> **Jira Cloud:** 
> 
> - We make use of [http://mixpanel.com](http://mixpanel.com)  to gather anonymous, aggregate product usage analytics.
>   - If a user consents, we may gather user-specific product usage analytics.
>   - Even when a user consents, we store a hashed version of their Jira User ID as we have no need to identify the specific user, only to know that the actions resulting from that user belong to an individual.
>   - All the data collected is subject to our [privacy policies](https://55degrees.se/privacy).
> 
> **Jira Data Center:** At this time, we do not collect product usage analytics.
> 
> **In-App Messaging Vendors**
> 
> **Jira Cloud:** 
> 
> - We utilize a vendor called [Product Fruits](https://productfruits.com/) (EU-based) to provide in-app messaging and help. The service gathers pseudonymized information to count unique monthly active users and interactions with the messaging provided via the service.
>   - If a user consents, we may gather additional information in order to create user segments that allow us to give more targeted messaging to the right users in the right place at the right time in order to help them achieve the most value out of the app.
>   - All the data collected is subject to our [privacy policies](https://55degrees.se/privacy).
> 
> **Jira Data Center:** At this time, all messaging done in OnPrem instances is hard coded into our app.
> 
> **Account Removal & Data Retention**
> 
> This section explains how a customer can close an account and completely remove their data from our service.
> 
> - **Jira Cloud: **A customer can uninstall the app from their Jira instance. Any data stored on the user object will continue to persist on the user entity in Jira Cloud’s database. Configuration data stored in AWS will be deleted according to our data retention policies.
> - **Jira DataCenter: **There is currently no data stored externally.
> - Any data stored in the browser's localStorage (for performance reasons) will persist in the browser until the user enters into the ActionableAgile app, at which point it may be expired due to timeliness **OR** the end-user may choose to clear the localStorage manually.
> - At any time, the end-user may choose to use the browser controls to clear the localStorage outside of the user interface.
> - Please read the [product documentation](https://support.55degrees.se/page/guides) for further details.
> 
> **Data Portability**
> 
> This section explains if and how a customer can extract their data from your service.
> 
> - The ActionableAgile for Jira app does not create any new data but rather analyses and visualizes it. Because of this, there is no data stored on our services. Configuration data may be stored and is possible to be migrated. Please contact us at [support@55degrees.se](mailto:support@55degrees.se) for more details.
> - Please read the [product documentation](https://support.55degrees.se/page/guides) for further details.
> 
> **Application & Infrastructure Security**
> 
> This section explains what security measures we've taken in our application and infrastructure.
> 
> - The 55 Degrees support team accesses app data only for purposes of application health monitoring, performing system updates, application maintenance, and/or upon customer request for support purposes.
> - Only authorized 55 Degrees employees to have access to customer data.
> - Customers are responsible for maintaining the security of their own Confluence and JIRA Cloud login information.
> - Communication between the Cloud products and the 55 Degrees servers is done using web requests. All web requests are digitally signed, authenticated, and authorized.
> - 55 Degrees' servers are only accessible through secure protocols (e.g. https and/or ssh).
> - Please read the [product documentation](https://support.55degrees.se/page/guides) for further details.
> 
> **Security Disclosure**
> 
> This section explains how and under what circumstances we notify our customers about security breaches or vulnerabilities and indicate how a user or security researcher should disclose a vulnerability found in our add-on to us.
> 
> - Security breaches or vulnerabilities with the proposed solution of the problem are published on the [Security Advisories](https://support.55degrees.se/space/SP/3925246495/Security+Advisories) in our documentation.
> - Critical vulnerabilities are communicated out to technical contacts of the affected products and to anyone subscribed to the Alerts, Advisories, & Policy Updates mailing list. You can sign up for this mailing list at [https://55degrees.se/subscribe](https://55degrees.se/subscribe) .
> - Customers can report security breaches or vulnerabilities via email to [support@55degrees.se](mailto:support@55degrees.se).
> - Please read the [product documentation](https://support.55degrees.se/page/guides) for further details.
> 
> **Privacy**
> 
> Data collected during the use of our add-on will not be shared with third parties except if required by law.
> 
> > Macro (refined-tab)
> 
> [azure devops]
> 
> **Overview**
> 
> This document is in addition to the <u>[55 Degrees Privacy](https://55degrees.se/privacy-policy)</u> document, the <u>[55 Degrees Order Agreement for Cloud customers](https://www.55degrees.se/agreement-cloud-products)</u> and the DPA (included in the Order Agreement) provided by 55 Degrees and explains how ActionableAgile for Azure DevOps stores the data it captures.
> 
> **Data Storage Terms & Location**
> 
> - ActionableAgile for Azure DevOps retrieves data from the systems you connect to via our wizards or via an upload of an external file. Once retrieved, the data is stored in the local browser using DOM localStorage and/or sessionStorage in order to improve any future data retrievals. The end-user can at any time empty the localStorage and SessionStorage through the ActionableAgile User Interface.
> 
> **Subscription Data & Data Storage**
> 
> - All of subscription data (PII related to the account holder) is stored in our subscription system, Recurly. 55 Degrees does not have access to the full credit card data in Recurly but does have access to see some information such as name of cardholder, last 4 digits, expiration date and billing address.
> - We map the Azure ID to the subscription and store this mapping in 55 Degrees. Azure IDs are only resolvable at the time of page request to verify access or to show the subscription owner any managed users. [How licensing works in Azure](https://support.55degrees.se/space/SP/3988717576/User+Management).
> 
> **Preferred Vendors**
> 
> At this time, 55 Degrees utilizes 2 vendors to provide the functionality within ActionableAgile for Azure DevOps:
> 
> - Google Firebase (Function-as-a-service and firestore services)
> - Recurly (subscription management)
> 
> **Logging**
> 
> We log the authenticated user ID and and the source ip for authentication and compliance reasons.
> 
> **Account Removal & Data Retention**
> 
> This section explains how a customer can close an account and remove their data from our service.
> 
> - A customer can [Cancel a Subscription](https://support.55degrees.se/space/SP/3989045257/Subscription+Management)  to ActionableAgile  and [Change your Billing Information](https://support.55degrees.se/space/SP/3989569541/Billing+Managment). Canceling your subscription sets it to expire at the end of your current billing period. Your account stays open in Recurly, our subscription management system, to allow for easy future subscription purchasing and access to your billing documents. We can close accounts if all business is concluded with a customer. Even for closed accounts we maintain required information for tax and accounting purposes according to Swedish law.
> - Any data stored in the browsers localStorage (for performance reasons) will persist in the browser until the user enters into the ActionableAgile app at which point it may be expired due to timeliness **OR** the end-user may choose to manually clear the localStorage.
> - At any time the end-user may choose to use the browser controls to clear the localStorage outside of ActionableAgile’s user interface.
> 
> **Data Portability**
> 
> This section explains if and how a customer can extract their data from your service.
> 
> - The ActionableAgile Analytics app does not create any new data but rather analyses and visualizes it. Because of this there is no Azure work data stored on our services.
> 
> **Application & Infrastructure Security**
> 
> This section explains what security measures we've taken in our application and infrastructure.
> 
> - The 55 Degrees support team accesses app data only for purposes of application health monitoring, performing system updates, application maintenance, and/or upon customer request for support purposes.
> - Only authorized 55 Degrees employees to have access to customer subscription data and usage logs.
> - Customers are responsible for maintaining the security of their own login information.
> - Communication between the Cloud products and the 55 Degrees servers are done using web requests. All web requests are digitally signed, authenticated, and authorized.
> - All deployments are handled through a central CI/CD change and are only accessible through secure protocols (e.g. https and/or ssh).
> 
> **Security Disclosure**
> 
> This section explains how and under what circumstances we notify our customers about security breaches or vulnerabilities and indicate how a user or security researcher should disclose a vulnerability found in our add-on to us.
> 
> - Security breaches or vulnerabilities with the proposed solution of the problem are published on our website.
> - Customers can report security breaches or vulnerabilities using <u>[support@55degrees.se](mailto:support@55degrees.se)</u> e-mail address.
> 
> **Privacy**
> 
> Data collected during the use of ActionableAgile will not be shared with third parties except if required by law.
> 
> > Macro (refined-tab)
> 
> [standalone]
> 
> **Overview**
> 
> This document is in addition to the <u>[55 Degrees Privacy](https://55degrees.se/privacy-policy)</u> document, the <u>[55 Degrees Cloud Products Agreement](https://www.55degrees.se/agreement-cloud-products)</u>, and the <u>[DPA](https://www.55degrees.se/dpa-cloud-products)</u> provided by 55 Degrees and explains how ActionableAgile Analytics stores the data it captures. This document will be updated as new features are added to ActionableAgile.
> 
> **Data Storage Terms & Location**
> 
> Your company's subscription data
> 
> - All subscription data (including PII related to the account holder) is stored in our subscription system, Recurly.
> - 55 Degrees does not have access to the full credit card data in Recurly but does have access to see some information such as the name of the cardholder, last four digits, expiration date, and billing address.
> - We keep data on your subscription, including information about the subscriber and any additional billing contacts, so we can administer your account.
> - Information about this subscription is also sent to our CRM and our Customer Success tools so that we can manage the relationship with current and prospective subscribers.
> 
> Please read the <u>[product documentation](https://support.55degrees.se/page/guides)</u> and our [55 Degrees Sub-Processors and Suppliers](https://support.55degrees.se/space/SP/4442488836) for further details.
> 
> **End-User Authentication**
> 
> We use Google Firebase for user authentication and authorization. We have access to the following for each account created at [https://analytics.actionableagile.com](https://analytics.actionableagile.com)  in order to provide service to our users:
> 
> - Identifier (Email Address)
> - Authentication Provider (User/Password or Google Authentication) but no access to actual user passwords
> - Created Date
> - Last logged in date
> - Unique User ID
> 
> We map the Firebase user ids to the subscription and store this mapping in our database. This is how we connect a subscription to an authorized user.
> 
> Please read the <u>[product documentation](https://support.55degrees.se/page/guides)</u> and our [55 Degrees Sub-Processors and Suppliers](https://support.55degrees.se/space/SP/4442488836) for further details.
> 
> **Your Company's Work Data**
> 
> - ActionableAgile Analytics retrieves data from the systems you connect to via our wizards or via an upload of an external file. Once retrieved, the data is stored in the local browser using DOM localStorage in order to improve any future data retrievals. The end-user can at any time empty the localStorage through the ActionableAgile User Interface.
> - If an end-user uses our OAuth wizards to connect to your work management systems, we retrieve the access token from the OAuth authentication system and store it in an encrypted form in our AWS database for the OAuth token validity time. Once it is the validation time is reached, the token is automatically purged.
> - At no point is your company's work data retrieved from connected systems and stored on any 55 Degrees servers or databases.
> 
> Please read the <u>[product documentation](https://support.55degrees.se/page/guides)</u> and our [55 Degrees Sub-Processors and Suppliers](https://support.55degrees.se/space/SP/4442488836) for further details.
> 
> **Preferred Vendors**
> 
> At this time, 55 Degrees utilizes three vendors to provide the functionality within ActionableAgile Analytics:
> 
> - Google:  Google Firebase (Function-as-a-service and Firestore services).
> - AWS: CloudFront, Lambda, Database, and API Gateway
> - Recurly (subscription management)
> 
> **Logging**
> 
> We make use of <u>[sentry.io](http://sentry.io/)</u> to collect any javascript errors in the browser. For more details about their security & legal statements - please see [https://docs.sentry.io/product/security/](https://docs.sentry.io/product/security/) 
> 
> **Account Removal & Data Retention**
> 
> This section explains how a customer can close an account and remove their data from our service.
> 
> - Customer can [Cancel a Subscription](https://support.55degrees.se/space/SP/3989045257) to ActionableAgile analytics and [Change your Billing Information](https://support.55degrees.se/space/SP/3989569541). Canceling your subscription sets it to expire at the end of your current billing period. Your account stays open in Recurly, our subscription management system, to allow for easy future subscription purchasing and access to your billing documents.
> - We can close accounts upon request if all business is concluded with a customer. Even for closed accounts, we maintain the minimum level of required information for tax and accounting purposes according to Swedish law.
> - Any data stored in the browser's localStorage (for performance reasons) will persist in the browser until the user enters into the ActionableAgile app, at which point it may be expired due to timeliness **OR** the end-user may choose to clear the localStorage manually.
> - At any time, the end-user may choose to use the browser controls to clear the localStorage outside of ActionableAgile's user interface.
> 
> **Data Portability**
> 
> This section explains if and how a customer can extract their data from your service.
> 
> - The ActionableAgile Analytics app does not create any new data but rather analyses and visualizes it. Because of this, there is no data stored on our services to extract.
> 
> **Application & Infrastructure Security**
> 
> This section explains what security measures we've taken in our application and infrastructure.
> 
> - The 55 Degrees support team accesses app data only for purposes of application health monitoring, performing system updates, application maintenance, and/or upon customer request for support purposes.
> - Only authorized 55 Degrees employees can access customer subscription data and usage logs.
> - Customers are responsible for maintaining the security of their own login information.
> - Communication between the Cloud products and the 55 Degrees servers is done using web requests. All web requests are digitally signed, authenticated, and authorized.
> - 55 Degrees' servers are only accessible through secure protocols (e.g., HTTPS and/or ssh).
> 
> Please take a look at our <u>[Trust page](https://55degrees.se/trust)</u> and read the <u>[product documentation](https://support.55degrees.se/page/guides)</u> for further details.
> 
> **Security Disclosure**
> 
> This section explains how and under what circumstances we notify our customers about security breaches or vulnerabilities and indicate how a user or security researcher should disclose a vulnerability found in our add-on to us.
> 
> - Security breaches or vulnerabilities with the proposed solution to the problem are published on our website.
> - Customers can report security breaches or vulnerabilities via our <u>[support portal](https://support.55degrees.se/)</u>.
> 
> Please read the <u>[product documentation](https://support.55degrees.se/page/guides)</u> for further details.
> 
> **Privacy**
> 
> Data collected during the use of ActionableAgile will not be shared with third parties unless required by law. Please see our <u>[privacy statement](https://55degrees.se/privacy)</u>.