Exportelier Exportelier
Home
  • EN English
  • DE Deutsch
  • ES Español
  • FR Français
  • IT Italiano
  • JA 日本語
  • NL Nederlands
  • PT Português
Privacy Policy EULA Data Processing Agreement Legal Notice
Legal

Privacy Policy

Version 1.0 · Effective 26 July 2026

This policy distinguishes the Exportelier marketing website from the Exportelier apps on Atlassian Forge. The English version is the authoritative version; translations are provided for convenience.

Contents

  1. Who we are
  2. Scope & our two roles
  3. The marketing website
  4. The Exportelier apps (Forge)
  5. Marketplace & billing data
  6. Support & communication
  7. Legal bases
  8. Service providers & transfers
  9. Retention
  10. Your rights
  11. Security
  12. Changes
  13. Contact

1. Who We Are

This Privacy Policy is issued by Exportelier (“Exportelier”, “we”, “us”), a sole proprietorship operated by Julia Röhling, Keisershoop 9, 38442 Wolfsburg, Germany. Full contact details are in our Legal Notice. We are the operator of the website at exportelier.com and the publisher of the Exportelier apps on the Atlassian Marketplace.

2. Scope & Our Two Roles

We act in two distinct capacities under data-protection law:

  • As a controller — for personal data we decide the purposes of: visitors to our marketing website, Marketplace customer and billing contacts, and people who contact our support.
  • As a processor — for the Jira content and personal data we process inside the Atlassian environment on behalf of the customer who installed our apps. For that processing, the customer is the controller and the terms of our Data Processing Agreement apply.

3. The Marketing Website

When you visit our website, our hosting provider automatically processes server log data (IP address, date and time, requested page, referrer, user agent) to deliver and secure the site. Legal basis: our legitimate interest in a secure, functional website (Art. 6 (1)(f) GDPR).

What the site uses today:

  • Local storage — we store your selected language in your browser's localStorage (key exportelier-lang) so the site remembers your choice. It holds only the language code, contains no personal identifier, is not transmitted to us, and remains until you clear your browser storage.
  • Web fonts — all fonts are served from our own infrastructure. No font request is made to Google Fonts or any other third-party font service, so no data is transmitted to such a provider when you load a page.

Analytics and marketing. We do not currently use analytics or marketing cookies, tracking pixels, or a cookie banner. If we introduce non-essential cookies or similar technologies, we will first add a consent banner and set them only with your consent (Art. 6 (1)(a) GDPR; § 25 (1) TDDDG), withdrawable at any time, and update this policy beforehand.

4. The Exportelier Apps (Atlassian Forge)

The main Exportelier app runs entirely on Atlassian Forge. It declares no external fetch and no web triggers — your Jira data is processed inside Atlassian's infrastructure and is not sent to our own servers. Documents are generated on Forge, streamed to the requesting user and not retained by us.

Within the Atlassian environment the app processes, on the customer's behalf:

  • Jira content you choose to export (issue fields, comments, worklogs, history, attachments and embedded images), strictly to render the requested document.
  • An audit log of export and admin events, stored in Forge storage on the customer's instance. It records metadata only (event type, timestamp, template, pseudonymous Atlassian account IDs) — never document content. In Free, the app shows and exports only the latest 30 days; this visibility window does not delete older entries. Standard and Pro let admins configure physical retention from 30 to 730 days (default: 365 days). The daily purge always uses the stored retention value, regardless of edition. Older entries hidden in Free may become visible again after an upgrade unless the purge has already removed them.

The optional Exportelier Automation app is the only component that sends data outside Atlassian, and only for actions the customer configures (scheduled exports, email, Slack incoming webhooks, Teams Workflows, REST API). It applies SSRF protection and stores provider URLs as encrypted secrets. If you do not install it, no such egress occurs. This processing is governed by the DPA.

5. Marketplace & Billing Data

Our apps are distributed and billed through the Atlassian Marketplace. Atlassian operates the Marketplace and processes your payment under the Atlassian Marketplace Partner Agreement and Atlassian's own terms; we do not receive or store full payment-card details. From Atlassian we receive limited Marketplace data needed to provide, license and support the apps — for example instance/SEN identifiers, license tier, and the name and email of the technical or billing contact. Atlassian's own handling of your data is governed by Atlassian's privacy policy.

6. Support & Communication

If you contact us, we process your contact details and the content of your message to handle your request. Support runs by email only — we do not operate a help-desk or ticketing system. The support form on our website does not transmit anything: it prepares a message in your own email client, which you send yourself. Our mailboxes are hosted with Google (Gmail); inbound mail for our domain is routed by Cloudflare.

7. Legal Bases

PurposeLegal basis (GDPR)
Providing and securing the websiteLegitimate interests — Art. 6 (1)(f)
Analytics / marketing cookies (only if introduced)Consent — Art. 6 (1)(a)
Providing, licensing and supporting the appsContract — Art. 6 (1)(b)
Processing Jira data inside the appsOn behalf of the customer (processor) — see DPA
Accounting and tax recordsLegal obligation — Art. 6 (1)(c)

8. Service Providers & International Transfers

We use carefully selected providers acting as our processors under Art. 28 GDPR:

ProviderPurpose
AtlassianForge app platform and Marketplace distribution, licensing and billing
CloudflareCDN, DNS, TLS termination and inbound email routing for exportelier.com
Amazon Web ServicesWebsite and documentation hosting (Amazon S3, Frankfurt and Ireland regions)
GoogleEmail hosting (Gmail) for our contact and support mailboxes
BrevoOptional managed email delivery, used only by the separately installable Exportelier Automation app and only after an administrator explicitly enables it

We use no analytics provider, no marketing or advertising services, no CRM and no newsletter tool. Where data is transferred outside the EEA (for example to the United States), we rely on an EU adequacy decision or the European Commission's Standard Contractual Clauses with supplementary measures where required.

9. Retention

We keep personal data only as long as necessary: server logs for up to 30 days; Marketplace/contract and support data for the duration of the business relationship; accounting records for 10 years (§ 147 AO, § 257 HGB). We store no analytics data. App audit-log data is stored on the customer's instance. Free shows and exports the latest 30 days without deleting older entries. Standard and Pro allow physical retention from 30 to 730 days (default: 365 days). The daily purge uses the stored retention value regardless of edition; older entries hidden in Free may reappear after an upgrade unless they have already been purged.

10. Your Rights

Subject to applicable law, you have the right to access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interests, as well as to withdraw consent at any time. To exercise these rights, contact us (Section 13). Where we act as processor for app data, please direct requests to the relevant customer (controller); we will assist them as required. You may also lodge a complaint with a supervisory authority — for us, the Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany.

No automated decision-making. We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). The apps render documents from data you select; they do not evaluate or score individuals.

11. Security

We apply appropriate technical and organisational measures, including encryption in transit (TLS), least-privilege access and the Forge platform's security model. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

12. Changes

We may update this policy; the current version is always available here with the date above. Material changes will be communicated by appropriate means.

13. Contact

For privacy matters: [email protected], or by post at the address in our Legal Notice. We have not appointed a Data Protection Officer, as we are not required to do so under Art. 37 GDPR / § 38 BDSG.

© 2026 Exportelier. Not affiliated with Atlassian. Jira is a trademark of Atlassian. exportelier.com