Script Studio for Jira Cloud - Subprocessors

    This page lists the third-party entities that may receive End-User Data from Script Studio for Jira. BranchCreation S.L.U. does not operate an application server or a vendor-side database for this app. Runtime, Forge SQL, and encrypted Forge key-value storage are Atlassian Forge.

    These destinations are optional and chosen by the customer. They are used only when a Jira administrator enables Source Control and pushes. If Source Control is never configured, Script Studio does not send End-User Data to any entity on this list.

    Atlassian (Jira Cloud and Forge) is the hosting platform for the app. It is not repeated as a sub-processor here.

    Sub-processors

    NameDomainCountries where End-User Data may be storedPurposeEnd-User Data that may be shared
    GitHubhttps://github.comGitHub’s published regions, including the United StatesOptional Source Control remote. Used only if a Jira administrator configures a GitHub repository and pushes.Script source (TypeScript or JavaScript the administrator wrote), commit messages, and the commit author’s display name and email taken from the administrator’s Jira profile at commit time (or a placeholder accountId@users.noreply.scriptstudio if Jira does not expose the email).
    GitLabhttps://gitlab.comGitLab’s published regionsOptional Source Control remote. Same customer-controlled condition as GitHub.Same as GitHub.
    Bitbuckethttps://bitbucket.orgAtlassian Bitbucket Cloud regionsOptional Source Control remote. Same customer-controlled condition as GitHub.Same as GitHub.

    The git access token is used in memory on Forge for that HTTPS request. The app does not store the token on the git host. The token itself remains in encrypted Forge key-value storage.

    A self-hosted or Enterprise git server is refused unless BranchCreation adds that host to the Forge manifest, redeploys, and the site upgrades the app.

    What is not shared

    Script Studio does not send End-User Data to these hosts for advertising, analytics, or payment processing. It does not share Forge function logs, run history, REST token hashes, or the git token with the entities above.

    Retention on the remote

    Commits already pushed remain in the customer’s repository. The app cannot delete or rewrite that history. The customer controls retention on that git host.

    Contact

    BranchCreation S.L.U.
    https://branchcreation.com
    Email: support@branchcreation.com

    Changes

    We may update this list when the app’s declared git hosts change. The date at the top will change. The Marketplace Privacy & Security tab should stay in sync with this page.