Privacy Policy
DataForte AB · Tant Gröns väg 54, 147 60 Uttran, Sweden Contact: hello@dataforteab.com Last updated: 14 August 2026
This policy describes how the Atlassian Marketplace app Watchdesk for Jira (“the app”) handles data. The app is built on Atlassian Forge and runs on Atlassian’s infrastructure.
What the app does with your data
Watchdesk connects Datadog monitoring to a Jira Cloud site. To do that it processes:
- Datadog alert metadata received from the webhook you configure in Datadog under Integrations → Webhooks: the alert id, monitor title, alert type and severity, monitor tags, the transition (Triggered / Recovered) and the link back to Datadog.
- Jira issue data needed to create and update issues: project key, issue type, issue key and the comments the app itself writes.
- Configuration you enter: your alert rules, the Datadog site you use, and the Datadog API credentials described below.
The app does not collect analytics, does not profile users, and does not sell or share data with anyone. DataForte AB has no access to your Jira site or your Datadog account.
Where data is stored
All app data lives in Forge Key-Value Store, inside Atlassian’s cloud infrastructure, scoped to your installation. DataForte AB operates no servers and stores no copy of your data.
Stored per installation:
| Data | Purpose |
|---|---|
| Chosen Datadog site (US1, EU, US3, US5 or AP1) | knowing which regional Datadog API host to call |
| Datadog API credentials (API key and application key) | authenticating to the Datadog API — stored encrypted in Forge secret storage |
Alert rules, keyed by monitor tag (e.g. team:payments, or * for all alerts) |
deciding which Datadog alerts create issues in which Jira projects, and any default assignee |
| Link index (Datadog monitor / alert id ↔ Jira issue key, timestamps) | deduplicating a re-triggering monitor onto one issue and tracking recovery |
| Datadog snapshot per linked Jira issue (monitor title, severity, status, URL) | rendering the Datadog panel without calling Datadog on every view |
Data sent outside Atlassian
The app calls the Datadog API at the regional host for the site you selected — one of
api.datadoghq.com (US1), api.datadoghq.eu (EU), api.us3.datadoghq.com (US3),
api.us5.datadoghq.com (US5) or api.ap1.datadoghq.com (AP1). What is sent: the Datadog
monitor / alert id and your Datadog API credentials for authentication, during the reconcile and
status checks used to keep issues in step with the current monitor status. No Jira content is sent
to Datadog.
No other external service receives any data.
Personal data
The app does not intentionally process personal data. Two indirect cases are worth naming:
- A Datadog alert payload may contain personal data if your own monitors or tags put it there. The app copies the monitor title, severity and tags into a Jira issue in your own site.
- If a rule sets a default assignee, that Jira user’s Atlassian account id is stored in the rule.
DataForte AB acts as a data processor for whatever passes through the app; you remain the controller. There are no sub-processors: nothing leaves Atlassian’s infrastructure except the Datadog calls described above, and Datadog is your own provider under your own agreement with them.
Legal basis for processing
Where the GDPR or UK GDPR applies, we process data on two bases: to perform the contract under which the app is provided to you (Art. 6(1)(b)), and the legitimate interest (Art. 6(1)(f)) you and we share in operating the integration you configured — creating, deduplicating and synchronising issues — which cannot be achieved less intrusively, because the app handles only the data those functions require. As processor we act on your documented instructions as controller; you determine the legal basis for the underlying alert and issue data.
International transfers
Data is stored and processed within your Atlassian Cloud tenant, in the region Atlassian assigns to it. The only cross-border flow is to your own Datadog account, at the regional site you chose (US or EU). Any transfer of personal data outside the EEA is covered by the standard contractual clauses and safeguards that Atlassian and Datadog maintain under their own agreements with you; DataForte AB introduces no additional transfer of its own.
Retention and deletion
Data lives for as long as the app is installed. Uninstalling the app deletes its Forge storage, including the encrypted credentials. Jira issues the app created remain in your Jira site, because they are your issues.
To request information or deletion at any other time, write to hello@dataforteab.com. We answer within 30 days.
Your rights
Under the GDPR you may request access to, correction of, or deletion of personal data, and you may lodge a complaint with the Swedish data protection authority (Integritetsskyddsmyndigheten).
Security and incident notification
The Datadog API credentials are held in Forge encrypted secret storage and are never returned to the admin UI or written to logs. The incoming webhook is a per-installation Forge web trigger reached at an unguessable URL, and where you add a shared secret to the webhook payload the app checks it before acting. Because the app stores data only inside your Atlassian tenant, a breach of that stored data would be an Atlassian platform event handled under Atlassian’s incident process; where we become aware of an incident affecting data the app processes, we will notify you at the vendor contact on your installation without undue delay.
Children
The app is a business tool for software teams. It is not directed to children, and we do not knowingly process children’s data.
Changes
Material changes to this policy will be published on this page with a new “last updated” date.