Last updated: 29.09.2026
Previous version (06.09.2026)
Visual Dependencies is a Jira app published on the Atlassian Marketplace under the trading name Uption.
The data controller is:
Vitalii Bobak
Via Carlo Bonino 5, 29122 Piacenza (PC), Italy
VAT / Partita IVA: 01935490332
Email: [email protected]
We are established in Italy. Our lead supervisory authority is the Garante per la protezione dei dati personali (garanteprivacy.it).
Visual Dependencies renders dependency relationships between Jira work items as an interactive graph. It is built on Atlassian Forge and runs inside Atlassian’s own infrastructure.
When you use the app it reads work item data from your Jira site in order to draw the graph. This can include:
Display names and avatars are resolved at the moment they are drawn on screen and are not retained. The app does not read work item descriptions, comments, attachments, worklogs, or change history.
The app also writes. At your direction it creates and deletes links between work items. It does not create, edit, or delete work items themselves, or any of their fields. Changes made through the app are your organisation’s changes.
The app stores your presets — saved filters, graph layout positions, and view configuration — together with your last-used preset and your graph colour preferences, using Forge storage (KVS).
The one piece of personal data we store is your Atlassian account identifier. It is used as the key under which your presets and preferences are held, so that they are yours and not someone else’s, and it is recorded as the owner of each preset you create. We do not store your name, email address, avatar, or any other profile attribute. Saved layouts hold node positions only — no work item content and no assignee data.
The app also stores, against your account identifier, the random analytics identifier described under External connections, whether you have opted out of it, and whether you have seen the analytics notice.
A saved filter is text your users write, and filter text can name a person. The app rejects a filter that names someone by user name or display name, and steers you to currentUser() instead. It permits a literal Atlassian account identifier, because that is the one form of reference we can report to Atlassian and therefore erase — see §10.
Except as described below, this data does not leave Atlassian’s infrastructure, other than the content-free analytics events described under External connections. It is stored within your Atlassian organisation’s selected data residency region. We do not copy it to servers of our own, and the app does not transmit work item data to any external service.
External connections: product analytics (PostHog). From version 4 onward — the release your site’s administrators approve — the app sends content-free usage events to the product-analytics service PostHog, operated by PostHog Inc. on PostHog Cloud EU. Sites still running an earlier version send none. An event says which app feature was used, how long an action took, whether it succeeded, and coarse context such as the surface the app was opened on and your Jira colour mode. It never contains work item content, keys or names, project names, your name, e-mail address or Atlassian account identifier, page addresses, or your browser, device or location; PostHog discards the connecting IP address on receipt.
Events carry a random identifier so that use across visits can be related. The app creates it in Forge storage for your account on your Jira site, it is never derived from your account, it is held in your browser’s memory only while the app is open, it is replaced after one year, and it is deleted when you opt out or your Atlassian account is closed. Because nothing is stored on or read from your device, the app sets no cookie and needs no cookie consent.
We process this under our legitimate interest in understanding and improving the app and investigating errors (GDPR Art. 6(1)(f)); our assessment is available on request. The app tells you about this once, the first time it runs for you, and you can object at any time: open the help menu (?) in the app and choose Analytics preferences, or use the Analytics preferences on the app’s admin page. Objecting deletes your identifier and its analytics data (see §10). Your organisation’s site administrators can also switch analytics off for the whole site, by blocking the app’s analytics data egress in Atlassian Administration; the app keeps working without it. For this processing we are the controller; PostHog is our sub-processor (§6). What we treat as in scope and out of scope for data residency is published separately, as Atlassian requires, at https://uption.company/data-residency. The app sends nothing to any third-party error-reporting service; its only diagnostic logging is written to Atlassian’s own Forge logs and never leaves Atlassian’s platform.
| Permission | Why |
|---|---|
read:jira-work |
Read work items and their links to build the graph |
read:jira-user |
Show assignee and reporter names and avatars on graph nodes, resolved at the moment of display |
storage:app |
Store filter presets and display preferences in Forge hosted storage |
write:jira-work |
Create and delete links between work items at your direction |
manage:jira-configuration |
Read your Jira site’s licence (free or paid plan) to decide which features the app offers; reads instance configuration only, changes nothing |
report:personal-data |
Report stored account identifiers to Atlassian so your data is deleted when your account is closed |
For this processing we act as a data processor. Your organisation is the data controller. Our obligations are set out in our Data Processing Addendum, which applies to every customer automatically, with no request or signature needed.
For the following we act as a data controller.
If you contact us through our support portal at https://uption.atlassian.net/servicedesk/customer/portal/3 or by email, we collect your name, email address, and whatever you include in your message. We use this only to answer you and to fix the problem you reported.
Legal basis: legitimate interests (Art. 6(1)(f) GDPR) in supporting our product, and performance of a contract (Art. 6(1)(b)) where you are a paying customer.
Every basis we rely on is listed together in §13.
Retention: 24 months after the enquiry is closed.
Atlassian is the merchant of record for paid Marketplace apps. Atlassian handles all payment processing — we never see your payment card or bank details. Atlassian provides us with licence records containing the name, business email address, organisation, and licence status of the technical and billing contacts for each paid licence.
We use this to provide support and to notify customers about material changes to the app.
Legal basis: performance of a contract (Art. 6(1)(b)).
Retention: see §14.
Our marketing website at https://uption.company uses Google Analytics (provided through Firebase) to count visits and see which pages are useful. It is off by default. Nothing is loaded and no analytics cookies are set unless you choose “Yes, I Accept” on the banner shown on your first visit.
If you accept, Google Analytics sets two cookies in your browser:
Your choice itself is stored in your browser’s local storage under cookiesAccepted. That is not a cookie and is never transmitted to us or to anyone else; it only tells the page what you picked last time. You can change your mind at any time using the “Opt-Out of Analytics” link in the footer, which appears once you have accepted.
We serve our own web fonts, so the website makes no third-party requests before you have made a choice.
The app sets no cookies and stores nothing on your device.
From version 4 onward the app sends content-free product-analytics events to PostHog, as described in §3; sites running an earlier version send none. You can opt out at any time from the app’s help menu.
As the platform operator and Marketplace host, Atlassian collects operational and usage data about the app — installation and active-user counts, function invocation counts, error rates and latency — and makes it available to us through the Forge developer console and Marketplace partner reporting. We receive it as aggregate statistics about the app, not as records about identifiable individuals. Separately from this, from version 4 onward the app sends its own content-free usage events to PostHog (§3). Atlassian’s platform reporting is produced by Atlassian, not by code we wrote, and does not leave Atlassian’s infrastructure. Atlassian’s collection of it is governed by Atlassian’s agreement with your organisation and by Atlassian’s privacy policy.
Atlassian (Atlassian Pty Ltd and affiliates) hosts the app, stores its data, operates our support portal, and processes payments. Because the configuration the app stores is held in Atlassian’s Forge hosted storage, Atlassian acts as the app’s sub-processor for that data under the Forge Data Processing Addendum (§1.2). PostHog Inc. (United States) provides product analytics for the app on PostHog Cloud EU; the analytics data described in §3 is stored in the European Union. PostHog acts as our sub-processor under a data-processing agreement signed on 10 September 2026, which incorporates the Standard Contractual Clauses for any access from outside the EEA. Atlassian and PostHog are the app’s only sub-processors. Atlassian’s privacy policy: atlassian.com/legal/privacy-policy
Zoho (Zoho Corporation B.V.) provides our business email hosting. Email correspondence, including support enquiries, is stored in Zoho’s European data centres in Amsterdam and Dublin.
Our team. Visual Dependencies is built by a small team. Team members located in Ukraine and Canada may access support correspondence and licence contact details in order to provide support and fix bugs. They are bound by written confidentiality and data-processing commitments and act only on our documented instructions.
Google provides hosting (Firebase) and website analytics for https://uption.company. Google has no access to app data, support enquiries, or customer licence information. Analytics cookies are set only where you consent. Transfers to the United States rely on the EU-US Data Privacy Framework.
We do not disclose personal data to anyone else, except where required by law.
Ukraine is not covered by a European Commission adequacy decision. Transfers of personal data to our team members in Ukraine are made under the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), together with supplementary technical and organisational measures including access controls, multi-factor authentication, and minimisation of the data made available.
Canada benefits from a partial adequacy decision. We nonetheless apply the same Standard Contractual Clauses to transfers to our team member in Canada.
Analytics data (§3) is stored by PostHog in the European Union. PostHog Inc. is a United States company; its data-processing agreement with us incorporates the Standard Contractual Clauses for any access to that data from outside the EEA.
A copy of the clauses is available on request from [email protected].
Under the GDPR you have the right to access, rectify, erase, restrict, or object to our processing of your personal data, and the right to data portability.
If you are a user of a Jira site where Visual Dependencies is installed, your employer or the organisation operating that site is the controller of your work item data. Please direct your request to them; we will assist them in responding. The configuration the app stores about you — your account identifier, presets, and preferences — can be erased at any time; see §10.
For the analytics identifier and its events (§3) we are the controller. You can object at any time from the app’s help menu, and you can ask us at [email protected] to access or erase that data; we will respond within one month.
For support enquiries and licence contact data, contact [email protected]. We will respond within one month.
You also have the right to lodge a complaint with the Garante per la protezione dei dati personali or with the supervisory authority where you live or work.
Because the app stores your Atlassian account identifier (§3), we participate in Atlassian’s Personal Data Reporting API. Three things follow.
When your Atlassian account is closed, your stored data is deleted automatically. For any account Atlassian reports as closed, the app deletes that account’s presets, last-used preset, and colour preferences, and removes that account identifier from any saved filter belonging to another user that referenced it. This requires no action from you.
You can also ask for it to be deleted at any time. A Jira administrator on your site erases a user’s stored data from the app’s admin page (Visual Dependencies → Data & privacy). Ask your administrator, or email [email protected] and we will guide them through it.
When the app is uninstalled from a Jira site, Forge storage associated with that installation — including all presets — is deleted by Atlassian under its platform data-lifecycle rules.
We cannot access, correct, or delete the data inside your Jira site itself — your organisation controls that. Direct those requests to your Jira administrator or to Atlassian.
Analytics data. Opting out, or the closure of your Atlassian account, deletes the app’s analytics identifier for you and queues the deletion of the matching record and events at PostHog, which completes within seven days.
To have support correspondence deleted, email [email protected].
How long we keep each kind of data, where it is not deleted on one of the triggers above, is set out in §14.
We may update this policy. Material changes will be announced on the Marketplace listing and in the release notes of the app version that introduces them. The date at the top of this policy shows when it last changed, and earlier versions remain available at dated addresses on our website.
Change of legal entity. We are in the process of incorporating a company. Where our business is transferred to a successor entity as part of a reorganisation, incorporation, merger, or sale of assets, personal data covered by this policy may be transferred to that successor, which will be bound by commitments no less protective than those in this policy. We will update this policy and notify licence contacts before any such transfer takes effect.
Vitalii Bobak — [email protected]
Security enquiries: [email protected]
Support: https://uption.atlassian.net/servicedesk/customer/portal/3
| What | Legal basis |
|---|---|
| Reading your Jira data through the app (§3) | Art. 6(1)(b) — performance of the contract, carried out on your organisation’s instructions as its processor under Art. 28 |
| Storing your Atlassian account ID to keep your presets and preferences yours | Art. 6(1)(b) — performance of the contract, on your organisation’s instructions under Art. 28. We store only the opaque account ID and no profile data, because scoping each user’s presets and preferences to them cannot be done with anything less identifying |
| Answering support requests (§4.1) | Art. 6(1)(f) — our legitimate interest in supporting our users; Art. 6(1)(b) where the request relates to your contract with us |
| Licence and billing contacts (§4.2) | Art. 6(1)(b) — performance of the contract |
| Website server logs (§4.3) | Art. 6(1)(f) — our legitimate interest in the security and integrity of the website |
| Non-essential cookies on the website (§4.3) | Art. 6(1)(a) — your consent, and art. 122 of Italian Legislative Decree 196/2003 |
| Product-usage analytics under a pseudonymous identifier (§3) | Art. 6(1)(f) — our legitimate interest in understanding how the app is used and in investigating errors. Our assessment is available on request, and you can object at any time — see §9 and §10 |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights and freedoms, taking into account that the data involved is limited, is not used to make decisions about you, and is not shared for anyone else’s purposes. You can ask us for a summary of that assessment, and you can object under §9.
| Type of data | Retention period |
|---|---|
| Jira work items and user details read by the app | Not retained. Read on demand and discarded when the graph closes |
| App configuration in Forge storage (presets, colour preferences), keyed to your account ID | Until deleted by a user or on request; when your Atlassian account is closed, detected through the Personal Data Reporting API and then deleted; or when the app is uninstalled, after Atlassian’s platform recovery window |
| Support correspondence | Life of the request plus 24 months of support history, then deleted |
| Website server logs | 30 days |
| The app’s analytics identifier, and the events carrying it | The identifier is replaced after 12 months, so no profile spans more than a year. Events are deleted when you opt out or when your Atlassian account is closed — see §10 |
| Licence and billing contact details (§4.2) | For the life of the licence, then deleted once they are no longer needed to answer questions about the lapsed subscription |
You may request earlier deletion of support correspondence at any time — see §10.