Worklogs & Timesheet

Data security and privacy statement

App: Worklogs & Timesheet · Vendor: Ontologi · Last updated: 29 July 2026

This statement describes how the Worklogs & Timesheet app for Jira Cloud processes data. It is provided for Atlassian Marketplace customers and is not a substitute for legal advice. For contracting (EULA / DPA), use the agreements attached to your Marketplace purchase or contact us.

1. Who we are

Ontologi provides the Worklogs & Timesheet app (“the App”). For personal data in your Jira Cloud site, your organisation (typically the Atlassian site admin / customer) acts as the controller. Ontologi processes limited App configuration data as a processor on Atlassian’s Forge platform when you install and use the App.

Contact: atlassian-support@ontologi.app

2. Where the App runs

The App is built on Atlassian Forge for Jira Cloud. It does not call Ontologi-owned application servers or custom remotes for its core features. Compute and Forge-hosted storage are provided by Atlassian.

3. Data we access in Jira

Using Atlassian APIs (with the scopes granted at install), the App may read and/or write:

Primary worklog and issue data remain stored in your Jira Cloud site, under Atlassian’s and your organisation’s controls.

4. Data stored by the App (Forge storage)

In addition to Jira data, the App may store the following in Forge-hosted app storage (KVS) for your installation:

Category Examples
Site configuration Daily maximum hours setting
Access control Allowlist of Atlassian account IDs and display names for Reports access
User preferences Date/time/duration display preferences per user
Saved reports Report presets (filters, grouping, relative date ranges, private/shared flags)
Branding Optional company logo used on Print / PDF exports

5. Permissions (scopes)

The App requests these Forge / Jira scopes:

6. Purposes of processing

7. Sharing and subprocessors

Ontologi does not sell customer data. The App relies on Atlassian as the platform/hosting and Marketplace billing provider. Data is not sent to Ontologi marketing or unrelated third-party analytics systems by the App itself.

8. Data residency

Because the App uses Forge-hosted storage and has no separate Ontologi remote backend for storing End-User Data, placement of Forge-hosted data follows Atlassian Forge / Jira Cloud data residency capabilities for your site. For current Atlassian region options and migration behaviour, see Atlassian’s Forge and Cloud data residency documentation. If your compliance programme requires PINNED residency, confirm suitability against Atlassian’s Privacy & Security details for Forge apps and your Admin Hub settings.

9. Retention

Forge-stored App configuration remains while the App is installed on your site (or until an admin deletes or overwrites those settings). Uninstalling the App typically removes Forge app storage for that installation, subject to Atlassian platform behaviour. Jira worklogs and issue data follow your Jira retention policies.

10. Security

Security for Forge compute and storage is provided by the Atlassian platform. The App is designed for least-privilege scopes and does not require outbound HTTP remotes for core features. Customer admins should manage access using Jira administration and the App’s allowlist.

11. Your rights and requests

End users should contact their organisation’s Atlassian / Jira administrators first for access or deletion of Jira data. For requests related to App-stored allowlist entries, preferences, logos, or saved reports, contact atlassian-support@ontologi.app from an authorised admin address and include your cloud site URL.

12. Children

The App is intended for workplace use with Atlassian Cloud products and is not directed at children.

13. Changes

We may update this statement when the App or platform behaviour changes. The “Last updated” date at the top will be revised accordingly. Material changes may also be noted in Marketplace release notes.