AgentGate privacy policy

Last updated: 9 October 2026

This policy explains how Elektraset, s.r.o. ("we", "us") processes data in AgentGate, the AI access gateway for Jira Cloud and Confluence Cloud ("the app"). The app consists of a Forge app installed in your Atlassian site and the gateway service at https://agentgate-ai-governance.apps.elektraset.com.

Contact: help@elektraset.com ยท Website: https://elektraset.com/

Roles

For the content of your Atlassian site that passes through the gateway, you (the customer) are the controller and we are the processor. For the contact data that you send to our support, we are the controller.

What data the app processes

DataWhyWhere it is kept
Site identifiers (cloud id, site URL, installation id)To connect the gateway to your siteGateway database
Atlassian app tokens issued by Forge (lifetime at most 4 hours)To call the Jira and Confluence REST APIs for your agentsGateway database, encrypted with AES-256-GCM, replaced with each new token from Forge
Atlassian account ids of administrators and credential ownersOwnership, approvals and auditGateway database
Client registrations, policies, settingsTo enforce your governance rulesGateway database
Gateway credentialsTo authenticate AI clientsOnly a SHA-256 hash and a 10-character prefix are stored
Audit events: time, account id, client, tool, target (issue key, page id, project or space), decision, outcome, source IP, redacted request and responseEvidence for security reviewsGateway database, deleted after the retention you set (default 90 days)
Queued changes waiting for approvalTo apply an approved changeGateway database, arguments encrypted; deleted from the queue when decided

Content of issues and pages (for example summaries, descriptions, page bodies) passes through the gateway to answer your agents. It is not stored, except in redacted and shortened form in audit events and approval previews (secrets removed, e-mail addresses masked, text cut at the length you configure).

We do not sell data, do not use it for advertising, and do not use it to train AI models. The app does not use cookies or trackers on the pages it serves.

Where data is processed

The gateway runs on a server operated by Elektraset. Ask us for the current hosting region. Atlassian processes data of the Forge part of the app under Atlassian's own terms. Your AI clients (for example Anthropic, GitHub, Cursor) receive the answers of the tools that they call; their processing is governed by your agreements with them.

Sub-processors

Retention and deletion

Audit events are kept for the retention that you set (7 to 400 days, default 90). When you uninstall the app, Forge stops sending tokens and stored tokens expire within 4 hours. To delete all data of your site immediately, write to help@elektraset.com from an administrator account; we delete it within 30 days and confirm.

Security

Transport is HTTPS only. Every call from Atlassian is verified with the Forge Invocation Token (signature, issuer and audience). Tokens and queued payloads are encrypted at rest; gateway credentials are hashed. Access to the server is limited to Elektraset staff who need it.

Your rights

Under the GDPR you have the right to access, correct, delete, restrict and port your personal data and to object to its processing. Write to help@elektraset.com. You can also complain to the Czech Office for Personal Data Protection (uoou.cz).

Changes

We publish changes on this page and update the date at the top. Material changes are announced to administrators by e-mail or in the app.