Legal
Privacy Policy
This Privacy Policy explains how personal data is handled by the services AB Apps provides:
- Atlassian Forge apps distributed through the Atlassian Marketplace — Team Reminders for Jira, Approval Chaser for Jira Service Management, Recurring Work for Jira, and any future AB Apps Forge app that links to this policy (Sections 1–6).
- Daria, a WhatsApp assistant for clinics, which connects to a clinic's own WhatsApp Business account through Meta's WhatsApp Business Platform (Section 7).
Sections 1, 2 and 8–15 apply to everything we do. Sections 3 to 6 describe the Forge apps; Section 7 describes Daria, including how to request deletion of your data.
Independence. AB Apps is an independent software vendor. We are not affiliated with, endorsed by, or sponsored by Atlassian, Meta or Anthropic. "Jira", "Jira Service Management", and "Forge" are trademarks of Atlassian Pty Ltd; "WhatsApp" is a trademark of Meta Platforms, Inc.; "Claude" is a trademark of Anthropic PBC. AB Apps is a registered Meta Tech Provider for the WhatsApp Business Platform, which is a technical role, not an endorsement.
The short version
- Our Jira apps run entirely on Atlassian's Forge platform. Your Jira data never leaves your Atlassian instance.
- The Jira apps make no external network calls and send no data to any third party.
- They store only the minimal configuration and state each app needs (reminder settings, escalation cadence, and timestamps of past reminders/nudges) in Atlassian-hosted Forge storage, in the data residency region of your host Atlassian product. When you uninstall an app, that data is deleted by the platform.
- Daria is a separate service for clinics. It processes WhatsApp messages between a clinic and its patients on the clinic's instructions: the clinic is the controller, AB Apps is its processor (Section 7).
- For Daria we use three processors: Meta (the WhatsApp Business Platform), Cloudflare (an edge relay with a database in the EU) and Anthropic (the Claude API, which generates the replies). No Platform Data is used to train AI models, sold, or used for advertising.
- To have your data removed from Daria, see how to request deletion of your data.
- We use no third-party analytics, advertising, or tracking — in the apps or on this website. This site sets no cookies.
- We never see or store payment details for the Jira apps — Atlassian is the merchant of record and handles all billing and tax.
1. Who we are
The AB Apps establishment responsible for these apps, and your point of contact for any privacy matter, is:
- Trading name: AB Apps
- Operated by: Aninda Bhattacharyya, an individual software developer. AB Apps is his trading name, not a separately registered company.
- Location: Spain (European Union)
- Support & privacy contact: support@abapps.dev
- Website: abapps.dev
2. Roles under the GDPR
Because our Forge apps operate inside your Atlassian products, responsibilities are shared:
- You (the Atlassian product administrator / your organisation) are the data controller of the personal data held in your Jira or Jira Service Management site — for example account identifiers, issue metadata, and approval records.
- AB Apps acts as a data processor for that data. We process it only to provide the app's functionality, only within your Atlassian environment, and only in line with each app's declared permissions.
- The apps run on the Atlassian Forge platform, which Atlassian operates and on which the app data resides. Your relationship with Atlassian, and Atlassian's own privacy and security commitments, govern that platform.
- AB Apps acts as an independent data controller only for the limited personal data you send us directly and outside the apps — for example, the contents of a support email you choose to send us (see Section 9).
The same split applies to Daria: the clinic is the data controller for its patients' data and AB Apps acts as its processor, with Meta, Cloudflare and Anthropic as sub-processors (Section 7).
3. What data our Jira apps access, and why
Our apps request the minimum Atlassian permission scopes needed to work. They access data within your Atlassian product only and process it in real time to deliver the feature you configured. The scopes below are declared in each app's Forge manifest and shown to you before installation.
| Data accessed | Scope(s) | Why it is needed |
|---|---|---|
| Jira issue metadata (issue key, summary, assignee, status; for Approval Chaser, approval status and approver list) | read:jira-work, read:servicedesk-request |
To find the issues/requests you set reminders on, to identify due reminders, and to detect pending approvals that need a nudge or escalation. |
| Writing an issue or request comment | write:jira-work, write:servicedesk-request |
To deliver a reminder or approval nudge as a comment on the relevant issue or portal request, so the right people are notified inside your product. For Approval Chaser, an optional customer-visible portal comment can be posted (off by default). |
| Atlassian account IDs of the people involved (you, the current assignee, chosen recipients, pending approvers) | read:jira-user |
To @-mention the correct recipients and to send reminders to the current assignee or specific teammates. We use the opaque Atlassian account ID and do not build separate profiles of users. |
| App configuration and state (reminder date/time and recipients, timezone, escalation cadence and thresholds, timestamps of reminders/nudges already sent) | storage:app |
To remember what you asked the app to do, to fire reminders at the correct local time, and to avoid sending duplicate reminders/nudges. |
Team Reminders for Jira requests: read:jira-work, write:jira-work, read:jira-user, storage:app.
Approval Chaser for JSM requests those four plus read:servicedesk-request and write:servicedesk-request.
Recurring Work for Jira requests the same four as Team Reminders: read:jira-work, write:jira-work, read:jira-user, storage:app.
Delivery of notifications. Reminders and nudges are delivered as comments inside your Atlassian product. Any resulting email notification is generated by Atlassian's own notification system, not by AB Apps. Our apps do not send email directly and have no external email or messaging capability.
Data these apps do not collect. We do not collect or store passwords or credentials, payment or card data, marketing or behavioural profiles, cookies or device identifiers set by us, IP-based location, or any special-category (sensitive) personal data. We do not read issue content beyond the metadata needed for the feature, and we do not export any data outside Atlassian.
4. Where Jira app data is stored — and no external transfers
- All app data is stored in Forge-hosted storage operated by Atlassian, within your Atlassian product's environment.
- Its storage location follows the data residency region of your host Atlassian product, as configured by your organisation with Atlassian.
- Our apps perform no external egress: no data is transmitted to AB Apps' own servers (we operate none for app data), and none is sent to any third party. Accordingly, AB Apps initiates no international transfer of your data. Any hosting or cross-region arrangements are governed by your agreement with Atlassian.
5. Subprocessors (Jira apps)
For the Jira apps themselves, AB Apps uses no subprocessors. The apps run on the Atlassian Forge platform you already license, and no app data is sent to AB Apps or to any analytics provider, CDN, logging service, or third-party API.
The one exception is support correspondence you choose to send us: our support inbox (support@abapps.dev) is hosted by Zoho (Zoho Corporation) on its European Union data centre. Zoho processes only the email you send us, solely to deliver and store that correspondence. For Jira app data we use no other subprocessor; our website itself is served by a hosting/CDN provider that may process standard server-log data (such as IP addresses) transiently for security and reliability (see Section 8). If this ever changes, we will update this policy before the change takes effect.
Daria is a different kind of service and does use sub-processors; they are named in Section 7.
6. Data retention and deletion (Jira apps)
- We retain app configuration and state only while the app is installed and only as long as needed to provide the feature (for example, past-reminder timestamps used to prevent duplicate sends).
- When you uninstall an app, its data in Forge storage is removed by the Atlassian platform as part of the uninstall/cleanup process.
- We keep no independent backups of your app data outside Atlassian's platform, because no data ever leaves it.
- Support correspondence (Section 9) is retained only as long as needed to resolve your request and to meet any applicable legal record-keeping obligations, then deleted.
Retention and deletion for Daria are described in Section 7.
7. Daria — WhatsApp assistant for clinics
Daria is a service AB Apps provides to clinics. It answers patients on the clinic's own WhatsApp number — explaining treatments and prices, offering and booking appointment slots, sending appointment reminders and post-treatment check-ins, and handing the conversation to clinic staff whenever a person should take over.
Daria connects to the clinic's own WhatsApp Business account through Meta's WhatsApp Business Platform (Cloud API), using Meta's Embedded Signup. AB Apps is a Meta Tech Provider: the WhatsApp Business Account stays in the clinic's own business portfolio, and the clinic keeps its number on the WhatsApp Business app on the phone and can keep answering from it (coexistence).
Roles. The clinic is the data controller for the personal data of its patients. AB Apps (Daria) acts as the clinic's processor, processing that data only on the clinic's documented instructions. Meta, Cloudflare and Anthropic act as sub-processors, as described below. Meta is also an independent controller for the operation of WhatsApp itself, under its own terms and policies.
7.1 What we receive from Meta (Platform Data)
Through the WhatsApp Business Platform we receive, for the clinic's account only:
- the messages patients send to the clinic's WhatsApp number (text and any media they attach);
- echoes of messages clinic staff send from the WhatsApp Business app on the phone, so that Daria can see what a colleague has already answered;
- delivery and read statuses for messages sent from the number;
- contact display names and phone numbers of the people who write to the clinic;
- a one-time history of existing chats on the number, if the clinic chooses to share it when it connects;
- WhatsApp Business Account and phone-number metadata (the account and number identifiers, display name, quality rating and messaging limits);
- message templates created for the clinic and their approval status; and
- the access token Meta issues for the clinic's account, which is the credential Daria uses to send and receive on that number.
7.2 Why we process it
- To reply to patients on the clinic's behalf: answering questions, offering and confirming appointments, sending appointment reminders and post-treatment check-ins, and alerting the practitioner when a patient's reply needs their attention.
- To keep the clinic's conversation inbox, so staff can read the full thread and take over at any time.
- To avoid double-replying when staff answer a patient from the phone.
We do not use Platform Data for advertising, we do not sell or otherwise share it, and we do not use it to train AI models. It is not used for any purpose other than providing the service to the clinic.
7.3 Who else processes it, and where
- Meta Platforms — operates the WhatsApp Business Platform through which the messages travel. Data held by Meta/WhatsApp is governed by Meta's own terms and privacy policy.
- Cloudflare, Inc. — hosts the edge relay that receives Meta's webhooks and a short-lived event queue holding those events until the clinic's server retrieves them. The database is in the European Union (Western Europe region).
- Anthropic PBC — the text of a conversation is sent to the Claude API to generate the assistant's reply. Anthropic processes it as a service provider and does not use API data to train its models; processing takes place in the United States, with transfers made under the standard contractual clauses in Anthropic's data processing terms.
- The clinic's own Daria server, where the conversations, appointments and patient records are stored, runs on hardware the clinic operator controls, in Spain (European Union).
No other third party receives Platform Data.
7.4 How long it is kept
- Events at the edge (the Cloudflare relay) are held only until the clinic's Daria server has retrieved them, and are then purged.
- Conversations and patient records in the clinic's Daria server are retained by the clinic for as long as it needs them to provide care and to meet its own legal record-keeping obligations, under the clinic's retention schedule; after that they are deleted or anonymised.
- Access tokens issued by Meta are deleted when a clinic disconnects its WhatsApp Business account from Daria.
- Data sent to the Claude API is subject to Anthropic's own API retention (30 days by default) and is not used for training.
7.5 How to request deletion of your data
If you have messaged a clinic on WhatsApp and want your data removed, you can ask the clinic directly — it is the data controller and can delete your messages and anonymise your record from inside Daria — or you can write to us and we will action it with the clinic.
- Where to write: support@abapps.dev, with "Data deletion request" in the subject.
- What to include: the phone number you used on WhatsApp (in international format) and the name of the clinic you messaged. We need both to find your data; please do not send any other personal or health information.
- What happens: we verify the request with the clinic, delete your messages and personal data from Daria's systems and from the edge relay, and confirm by email within 30 days (one month) of receiving the request. If a deletion has to be delayed — for example, because the clinic must keep a clinical record by law — we will tell you what is being kept and why.
- Data held by Meta/WhatsApp itself — for instance the copy of the conversation in WhatsApp on your own phone or on Meta's systems — is governed by Meta's policies, not by ours; you would need to exercise those rights with Meta and WhatsApp.
Your other rights (access, rectification, restriction, objection and portability) are exercised in the same way: with the clinic as controller, or via support@abapps.dev. See also Section 11.
7.6 Security
- All traffic runs over HTTPS.
- Every webhook from Meta is signature-verified before it is accepted.
- Access tokens and other credentials are stored as secrets, never logged and never returned by the application.
- Access to the clinic's conversations is restricted to the clinic's own staff, who sign in with individual accounts, and to the AB Apps developer only for support and incident handling at the clinic's request.
7.7 Legal basis
AB Apps processes this data on the clinic's documented instructions as its processor, under a data processing agreement meeting Article 28 GDPR. The clinic, as controller, determines its own lawful basis: typically performance of a contract (Art. 6(1)(b)) for bookings and service messages, or its legitimate interests (Art. 6(1)(f)), and consent (Art. 6(1)(a)) for marketing templates such as recalls and review requests, which the patient can withdraw at any time.
8. This website
This website (abapps.dev) is a set of static pages. It sets no cookies, runs no analytics, and loads no third-party scripts, fonts, or tracking pixels. We do not build a profile of visitors. Standard, transient server logs may be produced by our hosting provider for security and reliability, but we do not use them to identify or track you.
9. Support communications
If you contact us at support@abapps.dev, we receive whatever information you choose to include (such as your email address, your Atlassian site URL, and a description of the issue). We use it solely to respond to and resolve your request. Please do not send us sensitive personal data or credentials. For this correspondence AB Apps is the controller; the lawful basis is our legitimate interest in providing support (Art. 6(1)(f) GDPR) or performance of our service to you (Art. 6(1)(b)).
10. Legal bases for processing (GDPR)
Where we act as processor, we process your data on your (the controller's) documented instructions and lawful basis. Where we act as controller (support communications and running the service), our lawful bases are:
- Performance of a contract / provision of the service (Art. 6(1)(b)) — to deliver the app features you installed and configured.
- Legitimate interests (Art. 6(1)(f)) — to provide support, keep the apps working reliably, and prevent misuse, balanced against your rights.
For Daria we are always a processor acting on the clinic's instructions under Article 28 GDPR; the clinic's own lawful bases are described in Section 7.7.
We do not process personal data for advertising, profiling, or automated decision-making that produces legal or similarly significant effects.
11. Your rights
Subject to applicable law (including the GDPR), you may have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and to data portability.
Because our apps store data inside your own Atlassian product and we hold no independent copy — and generally cannot identify individual data subjects on our own — the most effective route for most requests is:
- Data inside the apps: contact your organisation's Atlassian administrator, who is the controller and can change configuration, remove data, or uninstall the app (which deletes the app's stored data). Atlassian can also action platform-level data-subject requests.
- Support correspondence you sent us directly: contact us at support@abapps.dev and we will action your request.
- Data in Daria (WhatsApp conversations with a clinic): contact the clinic, which is the controller, or write to support@abapps.dev. Deletion requests are described step by step in Section 7.5.
You also have the right to lodge a complaint with your local data protection supervisory authority in the EU/EEA.
12. Security
Jira apps.
- They run on Atlassian's Forge platform and inherit its platform-level security controls, tenant isolation, and hosted storage.
- We follow the principle of least privilege, requesting only the scopes listed in Section 3.
- They make no external network calls, which removes an entire class of data-exfiltration and third-party-breach risk.
- We store no secrets or credentials of yours; authentication and authorisation are handled by the Atlassian/Forge platform.
No method of processing is ever completely risk-free, but the "no egress, minimal storage" design of the Jira apps is intended to keep exposure as low as possible.
Daria necessarily communicates with Meta's and Anthropic's APIs; the measures that protect it — HTTPS, verified webhook signatures, tokens held as secrets, and staff-only access behind a login — are listed in Section 7.6.
13. Children's data
Our services are business tools not directed at children and are not intended for use by anyone under the age of 16. We do not knowingly process children's personal data. Clinics using Daria are responsible for the age rules that apply to their own treatments and patients.
14. Changes to this policy
We may update this policy to reflect new apps, changed functionality, or legal requirements. When we do, we will revise the "Last updated" date above and, for material changes, provide reasonable notice (for example, on this website or in the Marketplace listing). Your continued use of an app after an update takes effect constitutes acceptance of the revised policy.
15. Contact
For any question about this policy or your personal data:
- AB Apps — trading name of Aninda Bhattacharyya, individual software developer based in Spain
- Email: support@abapps.dev
- Web: abapps.dev
AB Apps is an independent developer and is not affiliated with or endorsed by Atlassian. This policy describes our current data practices in good faith; it is not legal advice.