WarrantySync
Privacy Policy
What personal data the app processes, why a device serial number can be personal data, who receives one, our role under UK GDPR, retention and your rights.
1. Who we are
This Privacy Policy explains how ITSM Ltd (“we”, “us”, “our”), a company registered in England and Wales under company number 17339600 with its registered office at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, handles personal data in connection with WarrantySync (the “App”), an application distributed through the Atlassian Marketplace.
| Data protection contact | support@itsm-ltd.com |
| Support contact | support@itsm-ltd.com |
| ICO registration number | ZC207852 |
| Postal address | 167-169 Great Portland Street, 5th Floor, London, W1W 5PF |
We are not required to appoint a Data Protection Officer. Enquiries about this policy should be sent to the data protection contact above.
Statement required by Atlassian. ITSM Ltd, and not Atlassian, is responsible for the privacy, security and integrity of any End User Data processed by us or by the App.
2. Scope of this policy
This policy applies to the App only. It does not apply to:
- Atlassian’s own products and services (Jira, Jira Service Management, Atlassian account and related services), which are governed by the Atlassian Privacy Policy;
- the warranty services operated by Dell, Lenovo and HP, each of which is governed by that manufacturer’s own privacy policy and by your own agreement with it — see section 8;
- our public website, which is governed by a separate website privacy notice; or
- any other application we publish, each of which has its own policy.
3. How the App is hosted — and what leaves
The App is built entirely on Atlassian Forge, Atlassian’s serverless application platform. What that means in practice:
- The App runs on compute infrastructure operated by Atlassian. We do not operate any servers, databases or hosting infrastructure for the App.
- All data the App stores is held in Forge hosted storage inside Atlassian’s cloud environment.
- We have no routine access to your data. We cannot browse, export or query the contents of your Atlassian site or the App’s stored data. The App transmits nothing to us. The only circumstances in which we see your data are set out in section 5.5.
- One thing does leave Atlassian, and it is the purpose of the product: a device serial number. To find out when a device’s warranty ends, the App sends that device’s serial number to its own manufacturer — Dell, Lenovo or HP. Section 5.4 sets out exactly what is sent, to whom, and when.
The App’s manifest declares three external destinations, one per manufacturer, and the Forge platform blocks outbound traffic to anywhere else. There are no others: no analytics endpoint, no error-reporting service, no content delivery network, and nothing belonging to us.
4. Our role under data protection law
Our role differs depending on the data concerned.
4.1 Where we act as a processor. In respect of personal data within your Atlassian site that the App reads, writes or stores (sections 5.1 to 5.3), you — the Atlassian customer whose site the App is installed on — are the controller and we act as a processor on your instructions. Atlassian acts as a sub-processor in that chain, because it provides the hosting and storage on which the App depends. Our processing on your behalf is governed by our Data Processing Agreement, available at https://warranty.itsm-ltd.com/legal/data-processing-agreement and incorporated into the End User Terms.
4.2 Where the manufacturers act. When you connect a manufacturer, the App discloses serial numbers to it on your instruction, using the credential you obtained from that manufacturer. The manufacturer is an independent controller of what it receives, not our sub-processor: we have no agreement with Dell, Lenovo or HP, and each determines its own purposes for the data under its agreement with you. Clause 2.5 of the Data Processing Agreement sets this out in full.
4.3 Where we act as a controller. We act as a controller in our own right for:
- support correspondence you send to us (section 5.5);
- licence and installation records supplied to us by Atlassian (section 5.6); and
- business contact records relating to your organisation.
5. Personal data we process
5.1 What the App reads from your site
To perform its function, the App reads the records that represent hardware in your Atlassian site — either JSM Assets objects or Jira issues, whichever you configure. From each it reads only the fields you map: a serial number, a model or manufacturer field, and a warranty end date field. It also reads Jira project, issue type, priority and field metadata so that the settings page can offer real choices during mapping, and reads issues the App itself created so that it does not raise a duplicate.
The App never resolves a user. It does not request Jira’s user-reading scope, displays no name or avatar, and sets no reporter on the issues it creates.
5.2 What the App stores
The App keeps its own copy of each device record in Forge hosted storage, so that it can derive warranty status daily without contacting a manufacturer. Those records contain:
- the serial number of the device;
- the device or asset name — free text controlled by you, which in practice often identifies a person, because naming a laptop after the person who uses it is a common convention;
- the Jira issue key or Assets object key the device came from, and its internal identifier;
- the warranty end date, service level, ship date, manufacturer, derived status and the time it was last checked.
It also stores its own configuration and operational records: your mapping and rule settings, a log of the 100 most recent sync batches (device keys and outcomes only — no serial numbers and no names), pre-scan sample lists, and a short-lived queue of pending expiry issues.
One Atlassian account identifier may be stored: if your administrator sets an optional default assignee for the Jira issues the App raises, that identifier is stored as typed. It is the only account identifier the App holds. We report it to Atlassian weekly, as Atlassian requires of apps that store account identifiers, and we erase it when Atlassian tells us the account has been closed.
5.3 What the App writes into your site
Three things, all of which you configure: the warranty end date into the single field you mapped; Jira issues warning that a warranty is about to expire; and two labels on those issues (warranty-sync and one per device). Note that Jira labels are site-wide, so those labels appear in every label picker on your site.
A per-device expiry issue includes, in its description, the device name, manufacturer, serial number, warranty end date and service level. Digest and first-run summary issues contain no serial numbers.
5.4 What is sent to a manufacturer
A device serial number, and the credential you supplied for that manufacturer. Nothing else. No device name, no user, no account identifier, no issue key and no issue content is capable of reaching a manufacturer — the App’s manufacturer adapters accept a list of serial numbers and have no parameter through which anything more could be passed, and an automated test fails the build if that ever ceases to be true.
A manufacturer is contacted only if you have stored its credential. Before you connect anything, the App runs in pre-scan mode and makes no external call at all. Clearing a credential stops all contact with that manufacturer immediately.
| Manufacturer | Endpoint | Receives | Where |
|---|---|---|---|
| Dell Inc. | apigtwb2c.us.dell.com |
Serial numbers; your TechDirect client identifier and secret | United States |
| Lenovo Group Limited | supportapi.lenovo.com |
Serial numbers; your Support API client identifier | Not published by them; a matter between you and them under your own agreement — assume outside the UK and EEA |
| HP Inc. | css.api.hp.com |
Serial numbers; your warranty API key | Not published by them; a matter between you and them under your own agreement — assume outside the UK and EEA |
Dell publishes the region for its warranty service. Lenovo and HP do not publish one for theirs, and we cannot state it on their behalf. We have no contract with any of the three: you obtain the credential and you hold the agreement, so where a manufacturer processes what it receives is governed by your relationship with that manufacturer rather than by us. Treat every manufacturer lookup as a transfer outside the UK and EEA unless that manufacturer has told you otherwise, and take it into account when deciding which manufacturers to connect. Connect none and none is contacted.
5.5 Support correspondence
This is the one category of data that reaches our own systems. When you contact support@itsm-ltd.com, we receive and process your name, email address, employer or Atlassian site details, and whatever information you choose to include in your message — including any screenshots, log extracts or exported data you attach. Please do not send us personal data, credentials or confidential content that is not necessary to diagnose your issue. In particular, never send us a manufacturer credential.
5.6 Licence and installation records
Atlassian supplies us with records for each installation, including the Support Entitlement Number (SEN), the licence status and dates, the customer organisation name and a technical contact. The App is free, so there is no payment: Atlassian is the merchant of record for any Marketplace transaction, and we do not receive or process payment card data.
5.7 Platform logs
The Forge platform generates operational logs for the App’s functions. These logs are produced and retained by Atlassian under Atlassian’s own retention arrangements. The App writes no application logs of its own, so it writes no personal data into logs, in line with Atlassian’s mandatory security requirements for cloud apps.
5.8 No analytics and no telemetry
The App collects no usage data of any kind. There is no analytics, no telemetry, no beacon, no error reporting, no crash reporting and no third-party tracking or SDK, and no counters are kept for our benefit. We learn how the App is used from Atlassian’s Marketplace reporting, which is Atlassian’s data and contains nothing about individuals, and from what customers choose to tell us through the feedback link in the App’s footer. The App contains no artificial intelligence or machine learning feature, and your data is never used to train or evaluate a model.
6. Purposes and lawful bases
| Data | Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Device records, configuration and operational records (5.1–5.3) | Delivering the App’s functionality on the customer’s instructions | Processed on behalf of the customer as controller; the customer determines the lawful basis |
| Serial numbers sent to a manufacturer (5.4) | Retrieving the warranty end date for that device | Disclosed on the customer’s documented instruction; the customer determines the lawful basis and is responsible for its own transfer assessment |
| Support correspondence (5.5) | Responding to enquiries, diagnosing faults, maintaining a support record | Art. 6(1)(b) performance of a contract; Art. 6(1)(f) legitimate interests in providing and improving support |
| Licence and installation records (5.6) | Verifying entitlement and administering the licence | Art. 6(1)(b) performance of a contract; Art. 6(1)(c) legal obligation (accounting records) |
We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile individuals. We do not knowingly process special category data; if your use of the App involves special category data within your device records, you remain the controller of that data and are responsible for identifying an Article 9 condition.
7. Where your data is stored
Data stored by the App resides in Forge hosted storage, within Atlassian’s infrastructure. The App does not support Atlassian’s data residency pinning. It declares outbound access to three manufacturer hosts as handling in-scope end-user data, and Atlassian treats an app that does so as ineligible for pinned status. If you have pinned your Jira data to a particular Atlassian region, App data is therefore not guaranteed to remain in that region or to move with your product data if you change regions. Details of Atlassian’s data residency programme are published at Atlassian’s data residency pages.
Serial numbers sent to a manufacturer leave your region. Dell operates its service in the United States; the table in section 5.4 records what is known about each. Data residency cannot apply to a disclosure made to a third party outside Atlassian, and you should take that into account when deciding which manufacturers to connect.
Support correspondence (5.5) and licence records (5.6) are held in our own business systems: email in Google Workspace, and support records in a support application built and operated by us, hosted on Vercel and Supabase, both configured to United Kingdom regions.
8. Sharing, sub-processors and manufacturer recipients
We do not sell personal data, and we do not share it for advertising or marketing purposes.
Sub-processors — parties processing data on our behalf:
| Recipient | Role | Purpose | Location |
|---|---|---|---|
| Atlassian Corporation / Atlassian Pty Ltd | Sub-processor | Hosting, compute and storage for the App; Marketplace distribution | Atlassian Forge hosting; the App does not support data residency pinning (section 7) |
| Google Ireland Limited (Google Workspace) | Sub-processor | Delivery and storage of support email | Ireland / European Economic Area |
| Vercel Inc. | Sub-processor | Application hosting for our support application | United Kingdom region |
| Supabase Inc. | Sub-processor | Database and storage for our support application | United Kingdom region |
Our support application is built and operated by us, not licensed from a third party, so it is not itself a sub-processor. The providers that host it are. Both are configured to United Kingdom regions, so support correspondence is stored in the UK; both are US-incorporated, and section 9 explains the safeguards applied.
Manufacturer recipients — independent controllers, contacted only where you have connected them. The table in section 5.4 lists them and what each receives. They are not our sub-processors: you obtain the credential, you hold the agreement with the manufacturer, and it decides its own purposes for what it receives. We have no contract with Dell, Lenovo or HP and cannot act on your behalf against them.
We will give 30 days’ notice of any change to the sub-processor list by updating this policy and the effective date. Adding a manufacturer requires a new version of the App, which Atlassian re-reviews and your administrator approves, and it does not become active until you enter a credential for it. We may also disclose personal data where required by law, court order or a regulator, or to establish, exercise or defend legal claims.
9. International transfers
Because App data is held within Atlassian’s infrastructure, transfers of stored data are governed by Atlassian’s arrangements, including its Data Processing Addendum and the Standard Contractual Clauses with the UK International Data Transfer Addendum where applicable. Where we transfer support or licence data outside the United Kingdom, we rely on UK adequacy regulations or, where no adequacy decision applies, the International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses. A copy of the relevant safeguards is available on request.
Serial numbers sent to a manufacturer are a separate case. That disclosure is made by you, to an independent controller, under your own agreement with that manufacturer, and the transfer mechanism for it is a matter between you and them. Dell’s service is operated in the United States, so connecting Dell involves a transfer outside the United Kingdom. We are neither exporter nor importer for that disclosure and cannot provide a mechanism for it; you should address it in your own transfer risk assessment before connecting a manufacturer.
10. Retention
| Data | Retention |
|---|---|
| Device records | Held while the device exists in your site. Removed automatically once a record has been stale for twice the configured freshness period and the App has re-checked your site and confirmed the device is gone |
| Sync batch log | The 100 most recent batch records; older ones are pruned automatically |
| Pre-scan samples | Overwritten on each pre-scan |
| Pending expiry-issue queue | Cleared at the end of every run |
| Manufacturer credentials | Until your administrator clears them, or the App is uninstalled |
| Manufacturer access token (Dell) | No more than 55 minutes |
| All App data | On uninstallation, Atlassian deletes Forge app data in accordance with its published platform deletion processes; we retain no copy |
| Support correspondence | 24 months from closure of the enquiry |
| Licence records | 7 years, to meet UK statutory accounting and tax requirements |
Data a manufacturer has already received is retained under that manufacturer’s own arrangements with you. Uninstalling the App does not reach it.
11. Security
App data is encrypted in transit and at rest by the Atlassian platform, is isolated per tenant, and is accessible to the App only through the minimum permissions it declares. Manufacturer credentials are held in Forge encrypted secret storage and are never returned to any screen. Our security measures are described in full in the Cloud Security Statement at https://warranty.itsm-ltd.com/legal/cloud-security-statement, which is the authoritative account of them — including section 5.2, which explains that the App reads your site with app-level permissions rather than yours, and what that means for who can see the device list. Where we act as your processor, the same measures are set out as technical and organisational measures in Annex 2 of the Data Processing Agreement.
Where a security incident affects personal data we hold or process, we will notify the technical contact on your licence without undue delay and in any event within 72 hours of becoming aware, and will assist you in meeting your own regulatory notification obligations. Incident handling is described in section 8 of the Cloud Security Statement.
We are not ourselves certified to SOC 2, ISO/IEC 27001 or comparable standards. The Atlassian infrastructure on which the App runs is independently certified; those certifications belong to Atlassian and may be verified at the Atlassian Trust Center.
12. Your rights
Where we act as a controller (support correspondence, licence records), you have the right under UK GDPR to:
- request access to your personal data;
- request rectification of inaccurate data;
- request erasure, where a ground applies;
- request restriction of processing;
- object to processing carried out on the basis of legitimate interests;
- request portability of data you provided to us; and
- withdraw consent, where processing is based on consent, without affecting prior processing.
To exercise a right, email support@itsm-ltd.com. We will respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies. There is normally no charge.
Where we act as a processor (data inside your Atlassian site), please direct your request to the Atlassian customer whose site holds the data — normally your own organisation’s administrator. We will assist that customer in responding; clause 9.2 of the Data Processing Agreement explains the practical mechanics, including the fact that the App has no per-record delete control and removes a device record only after it has confirmed the device is gone from your site.
Where a request concerns data held by a manufacturer, it must be directed to that manufacturer.
Complaints. If you are dissatisfied with how we have handled your personal data, please tell us first at support@itsm-ltd.com; we operate a complaints procedure and will acknowledge your complaint within 5 business days and respond substantively within 30 days. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post to Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
13. Notice to residents of California
If you are a California resident, you have rights under the California Consumer Privacy Act as amended, including rights to know, delete, correct and opt out. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not process personal information for cross-context behavioural advertising. A disclosure of serial numbers to a manufacturer at your instruction is made for a business purpose and is not a sale or share. We do not use or disclose sensitive personal information for purposes requiring an opt-out. To exercise a right, contact support@itsm-ltd.com; we will not discriminate against you for doing so.
14. Children
The App is a business tool licensed to organisations and is not directed at children. We do not knowingly process the personal data of anyone under 18 in connection with the App.
15. Changes to this policy
We may update this policy from time to time. Material changes will be notified by updating the effective date above and, where the change materially affects your rights, by email to the technical contact on your licence at least 30 days before the change takes effect. Previous versions are available on request.
This Privacy Policy is published in accordance with the Atlassian Marketplace Partner Agreement. It should be read alongside the End User Terms, the Cloud Security Statement and the Support and Maintenance Description for WarrantySync.
This document names the app WarrantySync; it appears in Jira, and everywhere else on this site, as WarrantySync. They are the same product. Previous versions are available on request from support@itsm-ltd.com.