Extension Privacy
This is the compact privacy notice for the Chrome extension TrustTroiAI Inspector. It addresses the requirements of the Chrome Web Store. The complete data protection information for the Platform to which the extension connects is available at /plattform-datenschutz and prevails on any overlapping topic.
What the extension does
The TrustTroiAI Inspector adds a side-panel to Atlassian Jira. Inside a Jira issue it shows you which EU compliance obligations apply to the work described in the issue (AI Act, GDPR, Cyber Resilience Act and further EU regulation). It lets you record signed evidence against those obligations and hand over the result as compliance documentation to your team.
Which data the extension handles
- Jira issue content that you actively select — title, description, comments, status, attachments. Retrieved via the Jira API of your Atlassian account after you have authorised the connection.
- Your Atlassian account data — email address, name, account identifier, Cloud ID of your Jira instance — received from Atlassian during the OAuth 2.0 (3LO) login.
- Access and refresh tokens to your Atlassian account, stored encrypted on our server (Fernet).
- Locally in the extension: the session token (lifetime 30 days), your email address, the site name. Stored in your browser's local extension storage, remains on your device.
- What we do NOT read: no page content outside Jira, no browsing history, no keystrokes, no other tabs. The content script is scoped to Atlassian domains only.
Where the data goes
- Our server at Hetzner Online GmbH, Germany. Hosting, database, session state.
- Mistral AI SAS (Paris, France · EU) for the AI-assisted analyses. Personal identifiers are pseudonymised before transmission — see /plattform-datenschutz §10.2. The exception for the dialogue-based chat is disclosed inside the extension on first use.
- Atlassian is the source from which you make Jira data available to us, not a sub-processor.
- No transmission to advertising networks, analytics vendors, or LLM providers outside the EU. No re-use for model training — contractually excluded with Mistral.
Legal basis · retention
Legal basis: Article 6(1)(b) GDPR (provision of the extension you have requested and the Platform contract). Where you enter personal data of third parties into the Platform, you are the controller and we process on your behalf under Article 28 GDPR.
Retention: Account data — for the duration of the contract. Session token — 30 days, invalidated immediately on sign-out. Jira caches — 90 days after last access. Full retention schedule in /plattform-datenschutz §16.
Disconnecting
You can end the connection at any time in three places:
- In the extension: click "Sign out" in the menu. The session token is invalidated on the server immediately.
- In Chrome: remove the extension via
chrome://extensions. Local extension storage is cleared by Chrome on removal. - In Atlassian: revoke access under "Connected apps" in your Atlassian account settings. All stored access tokens and Jira caches are then deleted on our side.
Your rights
Access · rectification · erasure · restriction · portability · objection · complaint to a supervisory authority under Articles 15–21 and 77 GDPR. Full description in /plattform-datenschutz §17. Requests to privacy@trusttroiai.eu — response within one month.
Security
TLS/HTTPS on all connections. Session tokens stored as SHA-256 hashes. Access tokens for third-party systems stored encrypted (Fernet). Pseudonymisation before transmission to the AI model. Server location Germany. Full security section in /plattform-datenschutz §19.
Changes
Material changes to this notice are announced in advance inside the extension and on this page. The current version applies.