AgentGate privacy policy

Last updated: 10 October 2026

This policy explains how Elektraset, s.r.o. ("we", "us") processes data in AgentGate, the AI access gateway for Jira Cloud and Confluence Cloud ("the app"). The app consists of a Forge app installed in your Atlassian site and the gateway service at https://agentgate-ai-governance.apps.elektraset.com.

Contact: help@elektraset.com ยท Website: https://elektraset.com/

Roles

For the content of your Atlassian site that passes through the gateway, you (the customer) are the controller and we are the processor. For the contact data that you send to our support, we are the controller.

What data the app processes

DataWhyWhere it is kept
Site identifiers (cloud id, site URL, installation id)To connect the gateway to your siteGateway database
Atlassian app tokens issued by Forge (lifetime at most 4 hours)To call the Jira and Confluence REST APIs for your agentsGateway database, encrypted with AES-256-GCM, replaced with each new token from Forge
Atlassian account ids of administrators and credential ownersOwnership, approvals and auditGateway database, AES-256-GCM encrypted (a keyed hash is kept to filter the audit log by person)
Client registrations, policies, settingsTo enforce your governance rulesGateway database
Gateway credentialsTo authenticate AI clientsOnly a SHA-256 hash and a 10-character prefix are stored; the owner's account id is encrypted
Audit events: time, account id, client, tool, target (issue key, page id, project or space), decision, outcome, source IP, redacted request and responseEvidence for security reviewsGateway database; account id, target, project or space, reason, source IP, request and response encrypted with AES-256-GCM; deleted after the retention you set (default 90 days, plan maximum 90 or 400 days)
Atlassian license state of each installation (active, trial, edition)To apply the plan you boughtGateway database
Client organizations (name, status, IP ranges)To approve or block AI vendor organizationsGateway database
Optional: organization API key for the Atlassian organization audit log (scope read:events:admin)To show organization audit events in the admin pageGateway database, AES-256-GCM encrypted; organization events are fetched on request and not stored
Queued changes waiting for approvalTo apply an approved changeGateway database; account id, target, arguments, preview and result encrypted with AES-256-GCM; arguments deleted when decided

Content of issues and pages (for example summaries, descriptions, page bodies) passes through the gateway to answer your agents. It is not stored, except in redacted and shortened form in audit events and approval previews (secrets removed, e-mail addresses masked, text cut at the length you configure).

We do not sell data, do not use it for advertising, and do not use it to train AI models. The app does not use cookies or trackers on the pages it serves.

Where data is processed

The gateway runs on a server operated by Elektraset. Ask us for the current hosting region. Atlassian processes data of the Forge part of the app under Atlassian's own terms. Your AI clients (for example Anthropic, GitHub, Cursor) receive the answers of the tools that they call; their processing is governed by your agreements with them.

Sub-processors

Retention and deletion

Audit events are kept for the retention that you set (7 to 400 days, default 90). When you uninstall the app, Forge stops sending tokens and stored tokens expire within 4 hours. To delete all data of your site immediately, write to help@elektraset.com from an administrator account; we delete it within 30 days and confirm.

Security

Transport is HTTPS only. Every call from Atlassian is verified with the Forge Invocation Token (signature, issuer and audience). Atlassian tokens, account ids, audit targets and payloads, IP addresses and queued changes are encrypted in the application with AES-256-GCM before they are stored; gateway credentials are hashed. Existing records are encrypted automatically when the gateway is updated. Access to the server is limited to Elektraset staff who need it.

Your rights

Under the GDPR you have the right to access, correct, delete, restrict and port your personal data and to object to its processing. Write to help@elektraset.com. You can also complain to the Czech Office for Personal Data Protection (uoou.cz).

Changes

We publish changes on this page and update the date at the top. Material changes are announced to administrators by e-mail or in the app.