Trust centre
Everything a security, privacy or procurement review needs, in one place. If something you need is not here, write to [email protected] and we will send it.
Documentation
Security
Our controls, hosting model, encryption, patch timeframes, incident response and vulnerability disclosure process, covering all five service lines.
Privacy policy
How we handle personal data on our website and in our business operations, the legal bases we rely on, retention periods and your rights under the GDPR.
Subprocessors
The service providers we use, what each is used for, where it processes data, and the transfer mechanism that applies.
Customer agreement
Our commercial terms, covering all five service lines.
Legal notice
Company details, registration and responsible persons.
Available on request
- Data processing agreement, in German as an Auftragsverarbeitungsvertrag or in English
- Completed security questionnaire, or we will complete yours
- Transfer documentation summary for our Tunisian delivery partner, under a non disclosure agreement
- Evidence for any specific control described on our security page
Write to [email protected] and tell us which of these you need.
At a glance
| Question | Answer |
|---|---|
| Where is app data processed? | Inside Atlassian's platform under the Forge hosting model |
| Is customer data used to train AI models? | No, never |
| Do you hold ISO 27001 or SOC 2? | Not today. Certification is on our roadmap and we publish our status on the security page |
| Where do you deliver from? | Germany and Tunisia, with an EEA only option on request |
| Which controller entity? | ONE T.E.E.M. GmbH, Altötting, Germany |
| How do I report a vulnerability? | [email protected], details on the security page |
| How do I exercise a data subject right? | [email protected], details in the privacy policy |
Contact
General enquiries: [email protected]
Privacy and data protection: [email protected]
Security and vulnerability reports: [email protected]