ChangeGuard Data Handling Disclosure
Last updated: 2026-08-05
| Category | Examples | Purpose |
|---|---|---|
| Jira context | Site, project, issue, work type, status, resolution, labels, Fix Versions, workflow/transition identifiers | Policy evaluation, simulation, guidance, compliance, and enforcement |
| Policy data | Names, scope, requirements, mode, immutable revisions/events/releases | Author, test, publish, restore, and prove policy state |
| Governance | Findings, waivers, reasons, status provenance, scan summaries | Review drift and controlled exceptions |
| Evidence | Simulation summaries, compliance values, Audit events, bounded CSV/JSON exports | Reporting and review |
| Account registry | Atlassian account ID plus random actor reference | Personal-data reporting and unlinkable immutable provenance after erasure |
| Support | Minimized details a customer submits | Diagnose and resolve support requests |
Storage and egress
Section titled “Storage and egress”ChangeGuard uses Atlassian Forge hosted storage and Jira app properties. The manifest declares no remotes or external egress. Flowdence operates no separate ChangeGuard database or object store.
Access
Section titled “Access”Jira administrator authorization protects policy administration, Governance, Health details, and exports. Regular issue users receive a bounded guidance projection. Paid-license checks reduce/stop app behavior for an explicitly inactive subscription, and validators permit Jira operations rather than trapping users.
Retention and deletion
Section titled “Retention and deletion”Audit events use a 30-day TTL/filter; async simulation jobs use a 7-day TTL. Raw account-ID mappings are reported weekly and erased on Atlassian closed/updated responses. Policy and governance retention follows documented product lifecycle and protected-reference rules. Contact https://flowdence.io/support for a customer deletion request.
Do not include secrets, passwords, PATs, or unrestricted personal data in policies, waiver reasons, JQL, screenshots, exports, or support requests.