---
title: "Data Security and Data Privacy Statement"
canonical: "https://support.covectors.io/space/SA/533102695/Data%20Security%20and%20Data%20Privacy%20Statement"
format: markdown
---
# Privacy Policy

## Introduction

This Privacy Policy explains what information Vectors collects about you and why, if you contact us in any form, use this website, our cloud services, or our apps for Atlassian products (together, "Services"), what we do with that information, how we share it, and how we handle the content you place in our products and services.

By using these Services, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, do not access or use our Services or interact with any other aspect of our business.

## Scope and Definitions

This Privacy Policy sets out our commitment to protecting the privacy of personal information provided to us, or otherwise collected by us, offline or online, from our website, Vectors website, or Marketplace vendor pages from visitors, registered users, or licensed users using our products.

In this Privacy Policy, "we," "us," or "our" means CoVectors LLC (a UAE limited liability company with license number 2429042.01) and all of its affiliated companies (together, known as "Vectors").

When we collect, store, and use your personal information, we do so in accordance with the rules set down by the European Union General Data Protection Regulation (EU) 2016/679 (the GDPR). We do not give away collected personal information. We may use the collected information to improve our services.

For the purposes of this policy:

- "Customer" means the entity that purchases our Service or Product
- "Customer data" means the electronic data uploaded into the Service by or for Customer or its Users
- "User" means an individual authorized by the Customer to access and use the Subscription

## What Information We Collect

### Data Provided Through Our Products

When using our products, we collect data about usage and the environment in which our products run.

### Data Provided by Atlassian

We distribute our products via Atlassian and get information about who uses and who purchases our products. The provided information can change over time, and Vectors cannot control this data or change it. Make sure to check Atlassian's Privacy Policy to get more information about how your data is sourced and handled.

### Atlassian Marketplace Data

In order to test or when purchasing one of our apps via the Atlassian Marketplace, you are requested to indicate your contact information and geographic location. This information is stored by Atlassian and is exposed to us via a report interface. We use this information to improve our services and analyze the market trends.

The information collected via the Atlassian marketplace includes:

CUSTOMER INFORMATION

- Company
- Country
- Region

CUSTOMER BILLING CONTACT

- Billing contact name
- Billing contact Email Address
- City
- Phone
- Postcode

CUSTOMER TECHNICAL CONTACT

- Technical contact name
- Technical contact email
- Address
- City
- Phone
- Postcode

PARTNER INFORMATION [When Client Is a Partner]

- Partner name
- Partner type
- Partner contact name
- Partner contact email

LICENSE DETAILS

- Host entitlement number
- App entitlement number
- Cloud ID
- Addon key
- Addon name
- License level
- License type
- Status
- Hosting
- Tier

MAINTENANCE PERIOD

- Start date
- End date


### Website Data

Any data that is entered into any form on [http://covectors.io](http://covectors.io)  or [http://support.covectors.io](http://support.covectors.io) websites is only used for the indicated purposes. With the exceptions listed below, we will never give away any personal information, including your email address, to any third party.

We collect anonymous website usage statistics. We also use HTTP cookies to collect information about how you navigate through our website. We use that information to improve our website usability, and the cookies are anonymous, meaning they are not linked with the data that you enter into forms on the website. You can safely disable cookies on our website.

We use Google Analytics to collect detailed statistics and help us understand how you use our websites. Google Analytics uses cookies and other means to transfer information about how you are using our websites to Google servers.

### Service and Support Data

All information that is provided during the support process is saved for later references, product enhancements and fixes. 

### Server Logs

When using our infrastructure, it generates server logs that may contain customer data, including personal data. We strive to anonymize data where possible. We also store and manage error logs.

## Data Types and Detailed Purposes

### Account Data

Our Cloud Apps store data provided and generated by Atlassian, which are required for license validation, contract administration, and communication with the customer instance.

### Session Data

Our Cloud Apps store data resulting from each customer's use of the service and is distinguished from Customer-Uploaded Data.

### Error Log Data

Our Cloud Apps track errors in our Cloud Apps' resources. This includes, for example, AppKey, ClientId, Instance URL, and error messages. It is exclusively used in order to improve our service.

### Update and License Checks

Our products may periodically check for available updates or verify license validity by connecting to our servers. As part of update and license checks, some information may be transferred to us:

- Versions of the product, platform, operating system, or host product (such as JIRA)
- Details of the currently used license for our product and some details of the license for the host product (this may include SEN and Server ID for JIRA license)
- The number of active users as measured by our products

The license keys are never transferred, so your license cannot be recreated or used elsewhere. We may use this information for analysis, verification, and support of the end users. We may contact a technical contact person in your company with advisories regarding application support and licensing, based on this information.

## Data Storage and Infrastructure

### Cloud Hosting

Vectors uses Amazon AWS for hosting Cloud apps to comply with all local laws. AWS has numerous security certifications, and Vectors implements many further security controls to safeguard data.

Our hosting region is<span style="color: #ffbdad">*** ***</span>EU-West.

### Personally Identifiable Information Storage

Unless explicitly and differently specified in the app documentation, we do not permanently store PII (Personally Identifiable Information; for example, name, email, address). We store the unique ID of your Atlassian Cloud products and the necessary secret keys to act on behalf of the currently logged-in user as is necessary for core app functions.

### Data Backups

- Our backup data is securely stored, and unauthorized access to backup data is not possible.
- We back up at least once a day, and we keep the backups for at least 7 days.

## Data Retention

We retain data and information when we have a reasonable functional and business need to do so. This is to ensure the quality, readiness, and traceability.  
The following table defines the data types along with their respective retention periods:

| Category | Data Type | Retention Period |
| --- | --- | --- |
| Error Logging (Frontend) | Customer log files | 90 days |
| Incident Management | Server log files | 365 days |
| Contact / Information | Customer email addresses | Indefinite |
| Support | Customer email addresses and shared data within tickets | Indefinite |

## Access and Security

### Personnel Access

Within Vectors, only a few trusted and named members of our Cloud Team have access to the production environment for the purposes of maintaining our cloud services and assisting our customers.

Customers are responsible for maintaining the security of their own login information.

### Access to Customer Data

Only authorized Vectors Software employees from our support and development teams have access to Customer Data sent for debugging or support purposes. Information related to licenses or the company can be viewed by authorized Vectors employees on the Marketplace interface.

### Support Management Service

All our support actions are handled via our support portal at [http://support.covectors.io](http://support.covectors.io)  (Jira Service Management portal for raising tickets and Confluence for documentation).

We may also request your contact email through intercom in special cases.

Connecting to those instances requires our users to create an account in order to interact with our Support agents. We may use the email indicated for the account to contact our users to provide adequate support if needed.

Raised tickets can only be shared with users in the same organization. They are not public and only JSM agents can consult them.

#### Log Files and Server Information Provided

You may be requested to provide a log file in order to check for a possible log trace due to an issue related to our apps. Sending those log files may be done via our JIRA Support instance or via private email, based on the sensitivity of the data contained.

## Third-Party Services

### Mailing Lists

We use MailChimp service for maintaining mailing lists and sending out newsletters. It is therefore essential to transfer to MailChimp your email, first name, and last name (if the latter are provided).

## Data Disclosure

The collected information may be disclosed only in the following cases:

- If we are required to do so by law
- If Vectors is merged or sold to another company


# Security Policy

#### Introduction

At Vectors, security is a core part of how we build and operate our Atlassian Marketplace apps. This page describes our approach to keeping your data and our systems secure.

#### Infrastructure and Hosting

Our Cloud apps are hosted on Amazon AWS (EU-West region) and Atlassian's Forge platform, both of which carry extensive security certifications. Access to production environments is restricted to a small number of named team members. No other employees have access to production systems or customer data.

Data backups are performed daily, retained for a minimum of 7 days, and encrypted at rest.

#### Secure Development

Security is built into every stage of how we develop our apps, not treated as an afterthought. We run automated security scanning on every build, conduct annual internal penetration testing, and participate in Atlassian's official Marketplace bug bounty program on Bugcrowd, where independent security researchers continuously test our apps.

#### Compliance

Vectors is currently undergoing a SOC 2 Type II examination covering the infrastructure and controls used across all our Marketplace apps, with a planned report around July 2026. Customers who require a letter of intent confirming the ongoing examination can request one through our [Help Center](https://support.covectors.io).

#### Vulnerability and Incident Response

We take security issues seriously. When a vulnerability or incident is identified, we act quickly to contain and resolve it. Affected customers are notified within 72 hours where applicable, and we conduct a post-incident review to prevent recurrence.

To report a security issue, please reach out through our [Help Center](https://support.covectors.io).


## Policy Changes

By making use of our services, you agree to be bound by the terms and conditions of this Privacy Policy.  
Vectors reserves the right to update or change this Privacy Policy when deemed necessary.  
If we make material changes to this Privacy Policy, we will notify our customers through an appropriate online notice (and obtain their consent where required by applicable law).