Privacy Policy
Effective Date: June 9, 2026 · Last updated: July 2, 2026 (analytics disclosure, service providers, and your rights added)
This Privacy Policy explains how AI Governance Hub handles information in connection with its website and Jira app experience.
1. Information We Collect
AI Governance Hub may collect information that users voluntarily provide, such as name, email address, company details, demo requests, support messages, and feedback.
When used as a Jira app, the app may process workspace-related information required to provide governance functionality, such as Jira issue metadata, project configuration, review status, risk details, approval information, evidence references, and audit activity.
2. How We Use Information
- To provide AI governance, risk, review, compliance, audit, and reporting features.
- To respond to support, feedback, demo, and partnership requests.
- To improve product functionality, reliability, security, and usability.
- To support marketplace listing, customer onboarding, and product communications.
3. Data Storage and Security
We aim to use reasonable administrative, technical, and organizational safeguards to protect information from unauthorized access, misuse, loss, or disclosure.
For Atlassian Marketplace usage, app data handling depends on the deployed Atlassian Forge environment and the configuration selected by the customer workspace.
4. Data Sharing
We do not sell personal information. Information may be shared only when required to operate the service, comply with legal obligations, protect rights and security, or support customer-requested functionality.
5. Third-Party Platforms
AI Governance Hub may operate with platforms such as Atlassian Jira and related enterprise tools. Use of those platforms is subject to their own privacy, security, and data processing terms.
6. Customer Responsibilities
Customers are responsible for ensuring that information entered into AI Governance Hub complies with their internal policies, applicable laws, and data governance requirements.
7. Data Retention
Website assessments: We process uploaded project exports solely to deliver your assessment and reports. We do not use your assessment upload to train third-party AI models.
Website assessments — retention: Upload sessions expire within 24 hours (typically one day) if checkout is not completed. Generated reports remain recoverable for 90 days via signed recovery tokens unless you request earlier deletion.
Jira Marketplace app: Retention follows your Atlassian workspace configuration and our product data handling practices.
Information is retained only as long as needed for product functionality, support, legal, security, audit, or operational purposes, unless a longer retention period is required or permitted by law.
8. Our Responsibilities
- Protect data with reasonable administrative, technical, and organizational safeguards
- Process assessment data solely to deliver the service you requested
- Verify payments server-side before releasing reports
- Respond to privacy and deletion requests in a timely manner
9. Cookies and Analytics
We use Google Analytics 4 (Google LLC) to understand how the website is used — pages viewed, device and browser type, approximate location (country/region), and product events such as assessment steps. Advertising features are permanently disabled: we never use advertising cookies, and ad storage, ad user data, and ad personalization are always set to "denied".
In the EEA, United Kingdom, and Switzerland, analytics is off by default and activates only if you consent via the cookie banner. You can withdraw or change your choice at any time on the Cookie Policy page ("Manage cookie preferences"). The site may also send a best-effort first-party diagnostic beacon to our own infrastructure; it involves no third parties and no cross-site tracking.
10. Service Providers
We share data with a small number of processors, strictly to operate the service:
- Razorpay — payment processing for website assessments (we never store card, UPI, or banking details).
- Vercel Inc. — website hosting, serverless compute, and storage for generated reports (United States region by default).
- Google LLC — Google Analytics 4 usage analytics, only as described in Section 9 and subject to your consent where required.
- Zoho — transactional email delivery (report links, sign-in links, receipts).
- Atlassian — the Marketplace app runs on Atlassian Forge entirely inside your own Jira Cloud tenant; its data does not leave Atlassian.
See the Trust Center for sub-processor details and data-residency notes.
11. Your Rights
Depending on where you live (including under the EU/UK GDPR and India's DPDP Act), you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent at any time (without affecting processing carried out before withdrawal).
To exercise any of these rights, email support@aigovernancehub.ai from the address associated with your data. We respond to verified requests within 30 days. If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.
12. Contact
For privacy questions or requests, contact us at support@aigovernancehub.ai.