AgentGate privacy policy
Last updated: 10 October 2026
This policy explains how Elektraset, s.r.o. ("we", "us") processes data in AgentGate, the AI access gateway for Jira Cloud and Confluence Cloud ("the app"). The app consists of a Forge app installed in your Atlassian site and the gateway service at https://agentgate-ai-governance.apps.elektraset.com.
Contact: help@elektraset.com ยท Website: https://elektraset.com/
Roles
For the content of your Atlassian site that passes through the gateway, you (the customer) are the controller and we are the processor. For the contact data that you send to our support, we are the controller.
What data the app processes
| Data | Why | Where it is kept |
|---|---|---|
| Site identifiers (cloud id, site URL, installation id) | To connect the gateway to your site | Gateway database |
| Atlassian app tokens issued by Forge (lifetime at most 4 hours) | To call the Jira and Confluence REST APIs for your agents | Gateway database, encrypted with AES-256-GCM, replaced with each new token from Forge |
| Atlassian account ids of administrators and credential owners | Ownership, approvals and audit | Gateway database, AES-256-GCM encrypted (a keyed hash is kept to filter the audit log by person) |
| Client registrations, policies, settings | To enforce your governance rules | Gateway database |
| Gateway credentials | To authenticate AI clients | Only a SHA-256 hash and a 10-character prefix are stored; the owner's account id is encrypted |
| Audit events: time, account id, client, tool, target (issue key, page id, project or space), decision, outcome, source IP, redacted request and response | Evidence for security reviews | Gateway database; account id, target, project or space, reason, source IP, request and response encrypted with AES-256-GCM; deleted after the retention you set (default 90 days, plan maximum 90 or 400 days) |
| Atlassian license state of each installation (active, trial, edition) | To apply the plan you bought | Gateway database |
| Client organizations (name, status, IP ranges) | To approve or block AI vendor organizations | Gateway database |
Optional: organization API key for the Atlassian organization audit log (scope read:events:admin) | To show organization audit events in the admin page | Gateway database, AES-256-GCM encrypted; organization events are fetched on request and not stored |
| Queued changes waiting for approval | To apply an approved change | Gateway database; account id, target, arguments, preview and result encrypted with AES-256-GCM; arguments deleted when decided |
Content of issues and pages (for example summaries, descriptions, page bodies) passes through the gateway to answer your agents. It is not stored, except in redacted and shortened form in audit events and approval previews (secrets removed, e-mail addresses masked, text cut at the length you configure).
We do not sell data, do not use it for advertising, and do not use it to train AI models. The app does not use cookies or trackers on the pages it serves.
Where data is processed
The gateway runs on a server operated by Elektraset. Ask us for the current hosting region. Atlassian processes data of the Forge part of the app under Atlassian's own terms. Your AI clients (for example Anthropic, GitHub, Cursor) receive the answers of the tools that they call; their processing is governed by your agreements with them.
Sub-processors
- Our hosting provider for the gateway server.
- Atlassian (Forge platform) for the parts of the app that run in your site.
Retention and deletion
Audit events are kept for the retention that you set (7 to 400 days, default 90). When you uninstall the app, Forge stops sending tokens and stored tokens expire within 4 hours. To delete all data of your site immediately, write to help@elektraset.com from an administrator account; we delete it within 30 days and confirm.
Security
Transport is HTTPS only. Every call from Atlassian is verified with the Forge Invocation Token (signature, issuer and audience). Atlassian tokens, account ids, audit targets and payloads, IP addresses and queued changes are encrypted in the application with AES-256-GCM before they are stored; gateway credentials are hashed. Existing records are encrypted automatically when the gateway is updated. Access to the server is limited to Elektraset staff who need it.
Your rights
Under the GDPR you have the right to access, correct, delete, restrict and port your personal data and to object to its processing. Write to help@elektraset.com. You can also complain to the Czech Office for Personal Data Protection (uoou.cz).
Changes
We publish changes on this page and update the date at the top. Material changes are announced to administrators by e-mail or in the app.