Legal
eXtensi Privacy Policy
Version 2.0. Effective September 2nd, 2026. Supersedes the Privacy Policy of October 18, 2019.
1. Who we are and how to contact us
This Privacy Policy explains how eXtensi Chudziński Jędryka spółka jawna, with its registered office in Wrocław, at ul. Rysia 1A/362, 53-656 Wrocław, Poland, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court for Wrocław-Fabryczna in Wrocław, VI Commercial Division of the National Court Register, under KRS number 0000807163, NIP (VAT ID): PL8943146425, REGON: 384560483 (“eXtensi”, “we”, “us”) processes personal data, on what legal grounds, for how long, and what rights you have.
For every privacy matter (questions, requests, complaints) write to support.no-spam@spam-trap.invalid@extensi.io.invalid. That address is our single contact point for privacy, support, and legal notices. We have not designated a data protection officer; privacy inquiries are handled directly by eXtensi through the address above.
Capitalized terms such as “Customer”, “App(s)”, “Cloud Apps”, “Self-Managed Apps”, “End User Data”, and “DPA” have the meanings given in our End User Terms and Data Processing Addendum.
2. Who this policy covers
This is a layered notice: read the section that matches your relationship with us. Sections 7 through 12 apply to everyone.
- Section 3: Website visitors. You browse extensi.io or contact us through the website.
- Section 4: Customers and their contacts. You are, or act for, a Customer of our Apps, for example as a billing or technical contact.
- Section 5: App end users. You use one of our Apps inside your organization’s Atlassian products.
- Section 6: Job applicants. You apply to work with us.
3. Website visitors
When you visit extensi.io, eXtensi is the controller of your personal data.
| Purpose | Personal data | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Operating and securing the website, and investigating abuse or unauthorized access | Server logs: IP address, browser type and version, operating system, referring and exit pages, date and time, language and locale settings, pages viewed and search terms used | Art. 6(1)(f): our legitimate interest in running a secure, reliable website | Up to 12 months; longer only where needed for a specific security investigation |
| Website analytics (see the cookies section below) | Pseudonymous online identifiers, device and browser information, approximate location, pages visited and interactions | Art. 6(1)(a): your consent | Up to 14 months, per the Google Analytics 4 retention setting |
| Advertising measurement through Google Ads (see the cookies section below) | Pseudonymous online identifiers, device and browser information, approximate location, pages visited, and advertising interactions | Art. 6(1)(a): your consent | Per Google’s retention for this service: log data anonymized after 9 months, cookie information after 18 months |
| Answering messages you send us by email, through the website, or through our support portal | Name, email address, and the content of your message | Art. 6(1)(f): our legitimate interest in responding; Art. 6(1)(b) where your inquiry leads to a contract | Until the matter is closed, then up to the limitation period for related claims |
Cookies and similar technologies
Our website uses cookies and similar technologies through a Google Tag Manager container. The container loads Google Analytics 4 and Google Ads (both services provided by Google). You can grant or refuse each of them separately. The container runs Google Consent Mode v2 in its basic configuration: the container loads only after you give consent through the cookie banner shown on your first visit, and each tag inside it is additionally gated on its own consent signal, so a tag you have not consented to does not load at all and no Google script runs before you choose.
- Strictly necessary cookies and storage are required to deliver the website and to remember your consent choices. We use them without consent under the strictly-necessary exemption in Article 399 of the Polish Electronic Communications Law of July 12, 2024 (PKE).
- Analytics cookies (Google Analytics 4) require your consent (Article 6(1)(a) GDPR and Article 399 PKE). They are set only after you give consent through the cookie banner; until then the analytics tag does not load and nothing is stored on or read from your device for analytics. Declining is as easy as accepting, and the website works fully if you decline.
- Advertising cookies (Google Ads) require your consent (Article 6(1)(a) GDPR and Article 399 PKE) and are switched off unless you turn them on. Until you consent, the advertising tag does not load at all: nothing is stored on or read from your device for advertising, and no advertising identifier is sent to Google. The website works fully if you decline.
You can change or withdraw your consent at any time using the “Privacy settings” button in the website footer; withdrawal does not affect the lawfulness of processing carried out before it. We store your consent choice for up to 12 months, after which we ask again.
4. Customers, billing contacts, and technical contacts
When a Customer buys or evaluates our Apps, eXtensi is the controller of the related contact and contract data. If your organization obtains our Apps through the Atlassian Marketplace, Atlassian shares certain information with us as the Marketplace partner: the technical and billing contact details your organization provided to Atlassian (name, email address, company name, and country) and license details (such as the license or support entitlement number (SEN), license tier, host product, and maintenance dates). We may also receive your contact details from the organization you represent (our Customer or a prospective Customer) or from an authorized reseller, when it provides them in connection with an offer or a contract; alongside the data above, we keep the related order and renewal history.
| Purpose | Personal data | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Concluding and performing the agreement: provisioning, licensing, renewals, notices | The contact and license details listed above | Art. 6(1)(b); Art. 6(1)(f): our legitimate interest in concluding and performing the agreement with the corporate Customer you act for, where you are a contact person for a corporate Customer | Term of the agreement, then per the legal-claims row below |
| Providing support and handling complaints | Contact details, ticket content, and attachments you choose to share | Art. 6(1)(b); Art. 6(1)(f): our legitimate interest in providing support to the Customer you act for | Life of the ticket, then per the legal-claims row below |
| Tax, accounting, and settlement duties | Billing and invoice data | Art. 6(1)(c): obligations under Polish tax and accounting law | The statutory retention period, generally 5 years from the end of the relevant tax year |
| Establishing, exercising, or defending legal claims | Contract, billing, and correspondence records | Art. 6(1)(f): our legitimate interest in establishing, exercising, and defending legal claims | Until the applicable Polish statutory limitation periods expire: generally 3 years, up to 6 years where a longer statutory period applies |
| Direct marketing of our own products, including requests for feedback or product input | Contact details and product usage context | Art. 6(1)(f): our legitimate interest in marketing our own products; you may object at any time (see the limits below the table) | Until you object or 2 years after the end of the customer relationship (or, where no agreement was concluded, 2 years after our last contact with you), whichever is earlier |
| Newsletters and mailing lists | Name and email address | Art. 6(1)(a): your consent | Until you unsubscribe (every message contains an unsubscribe link, or write to support.no-spam@spam-trap.invalid@extensi.io.invalid) |
| Publishing testimonials with your name | Name, role, and testimonial content | Art. 6(1)(a): your consent | Until you withdraw consent or ask us to update or remove the testimonial |
Two limits apply to direct marketing. First, we send marketing communications to electronic addresses (such as email) only with your prior consent, as Article 398 PKE requires; the legitimate-interest basis in the table covers only marketing channels that do not require that consent. Second, where we received your contact details from Atlassian, we use them for marketing communications only as the Atlassian Marketplace Partner Agreement and applicable law permit, with your consent where required.
Providing this data is voluntary, but without it we cannot conclude or perform the agreement or answer your request.
5. End User Data in our Apps
The Apps are provided by eXtensi, not Atlassian. eXtensi, not Atlassian, is responsible for the Apps and for the collection, processing, and protection of End User Data as described in this policy; Atlassian is not responsible for our Apps’ data practices.
Self-Managed Apps (for Atlassian Data Center and Server products) run entirely on the Customer’s own infrastructure. eXtensi has no access to, and does not process, End User Data from Self-Managed Apps: all content and user data stays on the Customer’s systems, under the Customer’s control. Self-Managed Apps do not connect to eXtensi servers: they perform no license checks or update checks against eXtensi and retrieve no remote content from eXtensi. Where a Self-Managed App feature retrieves external content, it retrieves it from a third-party service chosen by the Customer, never from eXtensi. The only data that reaches us is the support and diagnostic data described below, and only when the Customer sends it.
Cloud Apps. For Cloud Apps, the Customer organization that installs the App is the controller of End User Data (or, where it acts on behalf of another controller, the processor, in which case eXtensi acts as sub-processor); eXtensi processes that data only as a processor, on the Customer’s documented instructions, under the Data Processing Addendum that forms part of our agreement with the Customer. If you are an end user, please direct requests about your data in the Apps to your organization first; we assist it as the DPA requires.
Depending on the App, End User Data is hosted on eXtensi’s dedicated server in an OVHcloud data center in France (EU), encrypted at rest, and/or, for Apps or App features built on the Atlassian Forge platform, within Atlassian’s cloud infrastructure, where its location follows your organization’s Atlassian hosting and data-residency settings. The data processed comprises the content end users post, receive, or share in an App (which may include contact details, such as a phone number, where a user chooses to provide them in content or forms), the Atlassian account identifiers needed to provide the App’s functions, and transient request data such as IP addresses and signed Atlassian context identifiers. Each App’s specifics (hosting model, storage location, and data categories) are published on its Atlassian Marketplace Privacy & Security tab and described generically in Annex 3 to the DPA.
Support, error, and diagnostic data. eXtensi is the controller for the support relationship. This covers the contact details of the person who raises a ticket, the ticket metadata (the App and hosting type concerned, dates, and the status of the ticket), the description of the problem, error details and the App’s technical configuration at the time of the error, and, for Self-Managed Apps, the license SEN and Server ID together with the name and email address of the Customer’s technical contact, where provided. We use this data solely to diagnose and fix issues and to improve the Apps (Article 6(1)(b) and (f) GDPR) and retain it for the life of the ticket and then per the legal-claims row in Section 4 (until the applicable Polish statutory limitation periods expire: generally 3 years, up to 6 years where a longer statutory period applies). Where a Customer of a Cloud App includes End User Data in a ticket (for example a screenshot or an export of App content), eXtensi processes that End User Data as the Customer’s processor under the DPA; the support desk and business email systems that hold such tickets are therefore listed as sub-processors in Annex 2 to the DPA.
6. Job applicants
If you apply to work with us, eXtensi is the controller of your application data. For employment applications, we process the data listed in Article 22¹ of the Polish Labour Code on the basis of Article 6(1)(b) and (c) GDPR in connection with that provision; any additional information you volunteer (for example in a CV or portfolio), and applications for civil-law collaboration, are processed on the basis of your consent (Article 6(1)(a) GDPR), which you may withdraw at any time without affecting earlier processing. Providing data is voluntary, but we cannot consider your application without it.
We keep application data for the duration of the recruitment process and delete it when the recruitment ends. The only exception is your consent to being considered for future openings, in which case we keep your application for up to 18 months after the recruitment ends. Recruitment decisions are made by people, not algorithms.
7. Recipients of personal data and legally required disclosures
We never sell personal data. We share it only with:
- Service providers (processors) acting on our documented instructions under Article 28 GDPR contracts: our hosting and infrastructure provider OVH SAS (OVHcloud), Roubaix, France, transactional email delivery (Mailjet SAS, Paris, France), our business email and productivity suite (Google Workspace, provided by Google Ireland Limited: see Section 9 for the transfer consequences), accounting and invoicing services (iFirma SA, Wrocław, Poland), our support desk platform (Jira Service Management, provided by Atlassian Pty Ltd and its affiliates: see Section 9 for the transfer consequences), and the analytics provider described in Section 3 (Google Analytics 4, provided by Google Ireland Limited). The current list of sub-processors for Cloud App End User Data is set out in Annex 2 (Approved Sub-processors) to the DPA; it includes the support desk and business email systems, because End User Data that a Customer of a Cloud App includes in a support ticket is held there (see Section 5).
- Atlassian, which operates the Atlassian Marketplace and the Atlassian platform as a separate controller under its own privacy policy (see Atlassian’s privacy program (opens in a new tab)).
- Google Ireland Limited, as a separate controller for advertising measurement through Google Ads, where you have consented to advertising cookies (Section 3). Google processes the advertising measurement data for its own purposes under Google’s privacy policy (opens in a new tab) and the Google Ads controller-to-controller data-protection terms; it is not our processor for this purpose.
- Professional advisers and public authorities, where the law requires or permits it.
We may also disclose personal data to third parties where disclosure is reasonably necessary to: (a) comply with applicable law, regulation, legal process, or a binding governmental request (Article 6(1)(c) GDPR); (b) enforce our agreements and establish, exercise, or defend legal claims (Article 6(1)(f): our legitimate interest in protecting our legal position); (c) protect the security or integrity of our products and services, or protect eXtensi, our Customers, or the public from harm or illegal activity (Article 6(1)(f): our legitimate interest in securing our services and preventing abuse); or (d) respond to an emergency involving danger to a person’s life or health (Article 6(1)(d): protection of vital interests).
8. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy of it (Article 15);
- rectify inaccurate or incomplete data (Article 16);
- erase your data in the cases provided by law (Article 17);
- restrict processing (Article 18);
- data portability: receive the data you provided to us, where processed by automated means on the basis of consent or contract, in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible (Article 20);
- object to processing based on our legitimate interests, on grounds relating to your particular situation, and object at any time, without giving reasons, to processing for direct marketing (Article 21);
- withdraw consent at any time, where processing is based on consent, without affecting processing carried out before withdrawal.
To exercise any of these rights, email support.no-spam@spam-trap.invalid@extensi.io.invalid. We may need to verify your identity. We respond within one month; for complex or numerous requests we may extend this by up to two further months and will tell you if we do. Exercising your rights is free of charge, except that for manifestly unfounded or excessive requests, in particular because of their repetitive character, we may charge a reasonable fee or refuse to act, as Article 12(5) GDPR allows.
If you believe we process your personal data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.
For End User Data processed in the Cloud Apps on behalf of a Customer, please address your request to that organization (it is the controller) and we will assist it as required by the DPA.
9. International data transfers
We process personal data in the European Union / European Economic Area by default. All eXtensi-operated infrastructure, including the dedicated server in an OVHcloud data center in France that hosts our Cloud Apps and every eXtensi-operated system on which we store Customer data, is located in the EU (EEA); we operate no US infrastructure. Per-App storage locations are also listed on each App’s Atlassian Marketplace Privacy & Security tab.
Three categories of processing can involve recipients outside the EEA:
- The Atlassian platform and our support desk. For Cloud Apps or App features built on the Atlassian Forge platform, End User Data is stored in Atlassian’s cloud infrastructure, and its location follows your organization’s Atlassian hosting and data-residency settings. In addition, our support portal runs on Atlassian’s Jira Service Management, so support-ticket data, including any End User Data that a Customer of a Cloud App includes in a ticket, is processed on Atlassian’s platform, which under Atlassian’s terms may involve Atlassian affiliates outside the EEA (including in Australia and the United States). These transfers rely on Atlassian’s data-processing terms, which incorporate the European Commission’s 2021 Standard Contractual Clauses (Implementing Decision (EU) 2021/914), with EU-US Data Privacy Framework verification where applicable, consistent with the sub-processor annex to the DPA.
- Business email (Google Workspace). Messages sent to our contact addresses (including support.no-spam@spam-trap.invalid@extensi.io.invalid), including any End User Data that a Customer of a Cloud App includes in a support email, are processed in Google Workspace, provided by Google Ireland Limited, which under Google’s data-processing terms may involve processing outside the EEA. These transfers rely on the EU-US Data Privacy Framework (Google LLC is certified) and, in the alternative, on the 2021 Standard Contractual Clauses incorporated in Google’s terms.
- Website analytics and advertising measurement. Google may process analytics and advertising measurement data outside the EEA. This transfer relies on the European Commission’s adequacy decision for the EU-US Data Privacy Framework, under which Google LLC is certified, and, in the alternative, on the 2021 Standard Contractual Clauses incorporated in Google’s data-processing terms, which apply if the adequacy decision ceases to be valid.
For any current or future sub-processor established outside the EEA, we transfer personal data only under Chapter V GDPR safeguards: an adequacy decision (including the EU-US Data Privacy Framework for certified US entities) or the European Commission’s 2021 Standard Contractual Clauses (Implementing Decision (EU) 2021/914), combined with supplementary measures where a transfer impact assessment shows they are needed. You can obtain a copy of the safeguards used for a given transfer by writing to support.no-spam@spam-trap.invalid@extensi.io.invalid.
10. Security
We protect personal data with technical and organizational measures proportionate to the risk, including encryption in transit (TLS) and at rest, access controls based on least privilege, isolated per-customer environments for eXtensi-hosted Cloud App services, backups, logging, and regular patching. The contractually binding description of these measures for Cloud App processing is the technical and organizational measures annex to the DPA. No system is perfectly secure; if we become aware of a personal data breach affecting you, we will act as the GDPR requires.
11. No automated decision-making or profiling
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).