QuinTek

Legal

Privacy Policy

Last updated August 26, 2026

QuinTek LLC (“QuinTek”, “we”, “us”) builds apps for Atlassian Cloud. This policy explains what personal data we handle, in the two very different contexts where that question arises: this website, and the apps we publish on the Atlassian Marketplace.

The distinction matters more than it usually does, so it is worth stating up front:

  • On this website, we run no analytics, set no cookies, and load nothing from a third party. The only record of your visit is the server log that serving a page produces.
  • In our apps, we collect nothing at all. Our apps are Atlassian Forge apps that run entirely inside Atlassian’s infrastructure. Your Atlassian data does not reach QuinTek, because we operate no server that could receive it. The one narrow exception — a diagnostic log that Atlassian holds and that you control — is described in section 2.
Controller. QuinTek LLC, a limited liability company organised under the laws of [STATE OF FORMATION], with a registered address at [REGISTERED ADDRESS]. Contact: support@quintek.com.

1. This website

What we collect

Very little, and none of it about you specifically.

No analytics, no cookies, no trackers. This site runs no analytics product, sets no cookies, and loads no third-party scripts — no tag manager, no advertising pixel, no session recording. It ships no JavaScript at all. Nothing on the page reports your visit to anyone.

Every asset is served from this domain. Fonts included: they are compiled into the site rather than fetched from a font CDN, so loading a page does not disclose your IP address to anyone beyond the server that sends you the page.

Hosting logs. The site is hosted on Amazon Web Services (AWS), which records ordinary server request logs — including IP addresses — as part of delivering and protecting it. That is an unavoidable property of serving a website over the internet, not a choice we made to collect data. We do not query those logs to build a picture of individual visitors, and AWS retains them under its own schedule.

Email you send us. If you email us, we hold that message and your address for as long as we need to answer you and to keep a reasonable record of the exchange.

Cookies

This site sets none. There is no consent banner because there is nothing to consent to.

Where the UK GDPR or EU GDPR applies, our legal basis for hosting log data is legitimate interests in delivering and securing the site, and for correspondence it is legitimate interests in answering you.

We do not rely on consent for anything, because we do nothing that requires it.

Retention

Hosting logs are retained by AWS under its own schedule. Correspondence is retained for as long as it is useful for support, and no longer than is reasonable.

2. Our Atlassian apps

This section is the one that matters for a security review, so it is stated plainly.

We do not receive your Atlassian data

Our apps are pure Forge apps. Their code runs on infrastructure Atlassian operates, and the data they read and store stays inside Atlassian’s infrastructure, within your own installation.

QuinTek operates no backend service in the path. There is no QuinTek server that receives your Jira configuration, your permission data, your issues, or your users’ personal data — because there is no QuinTek server at all.

Who is responsible

Under the Atlassian Marketplace terms, QuinTek — not Atlassian — is responsible for the processing our apps perform. Atlassian requires us to say so, and it is also simply true: the design that keeps your data inside Atlassian is our decision and our responsibility, and questions about what an app does with data come to us, not to Atlassian.

What the apps store, and where

Our apps store their working data in Forge hosted storage — Forge SQL, Atlassian’s managed database, and Atlassian’s key-value store — isolated to your installation. For Permission Audit, that means the resolved report, its scan metadata, the app’s settings and, on the Advanced edition, the record of changes between scans: derived results, not a copy of your configuration.

Where that is, geographically: in the same Atlassian location as the site the app is installed on. Forge hosted storage is pinned to the site’s location, in every location Atlassian offers — at the time of writing Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the United Kingdom, and the United States — and if you move your site between locations, Atlassian moves the app’s data with it. QuinTek does not choose where your data is stored and cannot change it.

That data is subject to your agreement with Atlassian and to Atlassian’s own privacy and security commitments. It is not subject to any transfer to us.

Diagnostic logs — the one thing we can see, and how to switch it off

Every Forge app writes a diagnostic log, and Atlassian stores it. By default, Atlassian lets an app’s developer read that log for the sites the app is installed on, so that we can diagnose a fault you report.

What ours contains: scan identifiers, timings, counts, group names, and error text. It does not contain the report, and it is written to avoid names and email addresses. We read it when diagnosing a problem and for no other purpose. Where the log contains any personal data at all, our legal basis for reading it is our legitimate interest in keeping the app working.

You control this. In Atlassian Administration, under Apps → Connected apps, each app has a “Logs access” setting. Turn it off and the log stops being shared with us; the app works exactly the same, and support works from what you choose to send us. The log itself is held by Atlassian, in Atlassian’s logging infrastructure, and is retained under Atlassian’s schedule, not ours.

No telemetry

Our apps make no outbound calls to third parties. There is no analytics SDK, no error reporting service, and no usage telemetry. Nothing about your site, your users, or your usage is transmitted to us or to anyone else.

What we can see

Beyond the diagnostic log above, nothing about your installation. We have no console into it, no database to query, and no access to your data.

If you contact us for support, we work from what you choose to tell us. Anything you send us — a description, a screenshot, an exported file — we hold as correspondence under section 1, and we ask you to redact what you do not want us to have.

Platform limits

Because our apps run on Atlassian’s Forge platform, they are subject to Forge’s platform quotas and to the rate limits of the Atlassian product they read from. Those limits are Atlassian’s and can change; when a scan reaches one, the app pauses and resumes rather than failing, and reports anything it could not read rather than presenting a partial result as complete. Each app’s documentation describes what its work costs against those limits — for Permission Audit, see Scan cost and quota.

Uninstalling

When you uninstall an app, its Forge storage is removed by Atlassian along with the installation, on Atlassian’s schedule. Because nothing was ever held outside your tenant, there is nothing at QuinTek to request the deletion of.

Our role under the GDPR and the CCPA

For this website and for correspondence with you, QuinTek is a data controller (and, under the CCPA, a business) for the small amount of personal data described in section 1.

For our apps, QuinTek is neither a controller nor a processor of the data the app reads and stores in your installation, and neither a business nor a service provider for it under the CCPA: the app does not disclose that data to us. It stays under your agreement with Atlassian, where it was before you installed anything. For that reason we do not offer a Data Processing Agreement — there is no processing on our side for one to govern — and we will confirm that in writing if your procurement process needs it. Nothing the app does transfers your data out of the location your site is in, so no cross-border transfer mechanism is needed for it.

Sub-processors

For the apps: none. There is no third party in the path.

For this website: Amazon Web Services, for hosting only. AWS serves the pages and keeps the request logs described in section 1. No other third party receives anything.

3. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to our processing of your personal data, to data portability, and to withdraw consent. If you are in California, you have rights under the CCPA/CPRA, including to know what we collect and to opt out of any sale or sharing of personal information — we do not sell or share personal information, and we do not use it for cross-context behavioural advertising.

To exercise any right, email support@quintek.com. We will respond within the time the applicable law requires.

In practice, for our apps there is very little for us to act on, because we hold nothing about your installation. A request about app data is a request to Atlassian, and we will say so and point you in the right direction rather than pretend otherwise.

You also have the right to complain to your local data protection authority.

4. Children

Our apps and this site are business tools. They are not directed at children, and we do not knowingly collect personal data from anyone under 16.

5. Security

This site is served over HTTPS under a content security policy that permits no scripts, styles, fonts, images, or connections from any origin other than this one. Our apps inherit Atlassian’s platform security by construction — see our security page for the architectural detail, and our vulnerability disclosure commitments for how to report a problem and what happens when you do.

6. Changes

If we change this policy we will update the date at the top of this page. Material changes will be described here rather than made silently.

7. Contact

support@quintek.com

QuinTek LLC · [REGISTERED ADDRESS]