CRA Reporting Copilot / Privacy policy

Privacy Policy

Last updated: 20 July 2026

1. Scope

This Privacy Policy explains how the Atlassian Forge app CRA Reporting Copilot (the "App"), provided by Kazunari Itagaki, handles data. The App is a compliance-support tool that assists manufacturers in meeting the reporting obligations under Article 14 of Regulation (EU) 2024/2847 (the Cyber Resilience Act, "CRA"). It is not legal advice, and the customer (the manufacturer) remains solely responsible for determining whether and when to report, for preparing submissions, and for meeting statutory deadlines.

2. Data-handling model: processing stays inside your Atlassian tenant

The App runs entirely on the Atlassian Forge platform inside your own Atlassian Cloud tenant. As a result:

3. What the App accesses

The App requests only the following Forge scopes, and nothing more:

The App does not request access to user account credentials, email contents, billing information, or any scope beyond the two listed above.

4. Reference data (KEV and similar) is a bundled static snapshot

Reference datasets used for analysis (for example, a Known Exploited Vulnerabilities / "KEV"-type catalog) are shipped inside the App as a static snapshot. The App does not make any live external connection to fetch or refresh this data. Because the snapshot is fixed at the time of each App release, it may not reflect the most current published state of the source; the snapshot's as-of date is always shown in the App so its freshness is never overstated.

5. Measurement / usage metrics stay inside Forge Storage

Any usage measurement the App performs (for example, counts of analyses run, feature usage, or error events) is written only to storage:app inside your Atlassian tenant. Metrics are not transmitted to us or to any external analytics provider. We do not have a mechanism to read your in-tenant metrics remotely.

** Separately from in-App metrics: as an Atlassian Marketplace vendor, the Provider receives from Atlassian** certain Marketplace-level information about installations and licenses (e.g., licensing/transaction reports used for billing and support). That information originates in Atlassian's Marketplace systems, not inside your tenant, and does not include your Jira content or the App's in-tenant metrics.

6. Retention

7. No personal data sale; no advertising

We do not sell, rent, or share your data, and we do not use it for advertising. Because the App does not transmit your data out of your tenant, there is no data for us to sell or share.

8. Your role as data controller

Because processing occurs inside your Atlassian tenant, you (the customer) act as the controller of any personal data contained in your Jira work items that the App reads. The App is a tool operating within your environment rather than a service to which you transfer data.

8-bis. Personal data received via support

When you contact support, information you choose to share with us (e.g., screenshots, exported files, log excerpts) may contain personal data. We process such information solely to handle your support request, and delete it after 90 days after the request is resolved. This is separate from in-product processing, in which we do not receive your tenant content.

9. Contact

Questions about this Policy: support@complydraft.com.

10. Changes

We may update this Policy when the App changes. Material changes will be reflected in the version and date above.

---