Data Security and Privacy Statement

Data Security and Privacy Statement

Overview

DocuSign for Jira is Atlassian Forge app, fully built and hosted on Atlassian Forge platform. The app uses Forge Storage, which is the Atlassian-recommended mechanism for storing application data. All data is stored securely within Atlassian Cloud infrastructure, scoped per tenant and aligned with Atlassian’s data residency and compliance standards.

We do not use any external databases or third-party storage systems. No customer data is stored outside of Atlassian Cloud.

Data Storage

In order to work properly, DocuSign for Jira need to store the following information:

·      DocuSign credentials + RSA key

·      DocuSign default envelope configuration

·      DocuSign user’s ids

·      Basic information about signing documents (not whole documents)

DocuSign credentials

In order for DocuSign for Jira to be able to authenticate with DocuSign platform, we need to store credentials such as API Account ID, Integration Key, Account’s Base URL, OAuth URL and RSA Key.

DocuSign default envelope configuration

We store user preferences about envelope configuration such as Anchor String, OffsetX and OffsetY, which identify default place of signature in documents. This is not mandatory to provide this information, it is kind of simplification of signature procedure.

DocuSign user’s ids

In order to that every Jira user should have unique DocuSign account, we need to have some kind of bridge between these two types of accounts. Therefore, we store combination of Jira’s user id and DocuSign’s user id to identify signer.

Basic information about signing documents

The most important is that we don’t store signed documents in our database at all. We are some kind of proxy between Jira Attachments, where all documents are placed and DocuSign platform. After finishing signature procedure, we collect only basic information for signing history feature such as document name, signer id, signature date and status.