AgentGate privacy policy
Last updated: 9 October 2026
This policy explains how Elektraset, s.r.o. ("we", "us") processes data in AgentGate, the AI access gateway for Jira Cloud and Confluence Cloud ("the app"). The app consists of a Forge app installed in your Atlassian site and the gateway service at https://agentgate-ai-governance.apps.elektraset.com.
Contact: help@elektraset.com ยท Website: https://elektraset.com/
Roles
For the content of your Atlassian site that passes through the gateway, you (the customer) are the controller and we are the processor. For the contact data that you send to our support, we are the controller.
What data the app processes
| Data | Why | Where it is kept |
|---|---|---|
| Site identifiers (cloud id, site URL, installation id) | To connect the gateway to your site | Gateway database |
| Atlassian app tokens issued by Forge (lifetime at most 4 hours) | To call the Jira and Confluence REST APIs for your agents | Gateway database, encrypted with AES-256-GCM, replaced with each new token from Forge |
| Atlassian account ids of administrators and credential owners | Ownership, approvals and audit | Gateway database |
| Client registrations, policies, settings | To enforce your governance rules | Gateway database |
| Gateway credentials | To authenticate AI clients | Only a SHA-256 hash and a 10-character prefix are stored |
| Audit events: time, account id, client, tool, target (issue key, page id, project or space), decision, outcome, source IP, redacted request and response | Evidence for security reviews | Gateway database, deleted after the retention you set (default 90 days) |
| Queued changes waiting for approval | To apply an approved change | Gateway database, arguments encrypted; deleted from the queue when decided |
Content of issues and pages (for example summaries, descriptions, page bodies) passes through the gateway to answer your agents. It is not stored, except in redacted and shortened form in audit events and approval previews (secrets removed, e-mail addresses masked, text cut at the length you configure).
We do not sell data, do not use it for advertising, and do not use it to train AI models. The app does not use cookies or trackers on the pages it serves.
Where data is processed
The gateway runs on a server operated by Elektraset. Ask us for the current hosting region. Atlassian processes data of the Forge part of the app under Atlassian's own terms. Your AI clients (for example Anthropic, GitHub, Cursor) receive the answers of the tools that they call; their processing is governed by your agreements with them.
Sub-processors
- Our hosting provider for the gateway server.
- Atlassian (Forge platform) for the parts of the app that run in your site.
Retention and deletion
Audit events are kept for the retention that you set (7 to 400 days, default 90). When you uninstall the app, Forge stops sending tokens and stored tokens expire within 4 hours. To delete all data of your site immediately, write to help@elektraset.com from an administrator account; we delete it within 30 days and confirm.
Security
Transport is HTTPS only. Every call from Atlassian is verified with the Forge Invocation Token (signature, issuer and audience). Tokens and queued payloads are encrypted at rest; gateway credentials are hashed. Access to the server is limited to Elektraset staff who need it.
Your rights
Under the GDPR you have the right to access, correct, delete, restrict and port your personal data and to object to its processing. Write to help@elektraset.com. You can also complain to the Czech Office for Personal Data Protection (uoou.cz).
Changes
We publish changes on this page and update the date at the top. Material changes are announced to administrators by e-mail or in the app.