Privacy Policy

RenWare, Inc. is a (“Company”, “we”, “us”, or “our”), that provides a portfolio of software applications that extend the functionality of Atlassian's Jira and Confluence products.

RenWare, Inc. is the company, legal entity, and data processor for our software applications (“products”, “applications”), and as such, any legal agreements required for the usage of our products will be with RenWare. 

Data Controller Identity
The Data Controller is RenWare, Inc., a company registered in the state of Colorado in the United States of America.

Your Data is Safe with Us
At RenWare, we take data privacy seriously and strive to maintain a secure environment with the appropriate technical and procedural controls in place to help protect our customers data. 

Except where explicitly stated in this privacy policy or the respective terms of use, user data collection is limited to only the necessities for our software applications to function correctly. User data will never be sold or shared outside of RenWare, Inc.

Please take the time to read through this Privacy Policy carefully as it will help you make more informed decisions and provide insights into having a relationship with RenWare, Inc.. If there are any terms in this Privacy Policy that you do not agree with, please discontinue using our website, services, and/or software applications.


RenWare Website
When you visit this website (www.renwareinc.com) and use our services, you agree to trust us with your personal and/or corporate information. This Privacy Policy seeks to explain to you, in the clearest possible way, what information we collect, how we use it, and what rights you have in relation to it. 

This section of the Privacy Policy applies to the information collected through this website (www.renwareinc.com), and/or any related services, sales, marketing, or events (we refer to them collectively in this policy as the “Services”).

What information do we collect?
Personal information you disclose to us

We collect personal and/or corporate information that you provide to us such as name, address, contact information, passwords and security data, and payment information.

We collect personal information that you voluntarily provide to us when registering for the Services, expressing an interest in obtaining information about us or our products and services, when participating in activities for the Services, or otherwise contacting us.

The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make and the products and features you use. The personal information we collect can include the following:

Publicly Available Personal Information: We collect first name, maiden name, last name, nickname, email addresses, phone numbers, and other similar data that will help us identify you as a real person.

Credentials: We collect passwords, password hints, and similar security information used for authentication and account access. This helps us to identify and protect you to the best of our ability by avoiding impersonators.

All personal information you provide to us must be true, complete and accurate, and you must notify us of any changes to such personal or corporate information. If you information becomes stale or is deemed inaccurate, RenWare, Inc. reserves the right to terminate your account immediately. 

Information automatically collected

Some information – such as IP address and/or browser and device characteristics – is collected automatically when you visit our Services.

We automatically collect certain information when you visit, use or navigate the Services. This information does not reveal your specific identity, such as your name or contact information, but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services and other technical information. 

This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.

How do we use your information?
We process your information for purposes based on legitimate business interests, the fulfillment of our contract obligations with you, compliance with our legal obligations, and/or your consent. Please note that some information may be collected under your agreement with Atlassian via our partnership with Atlassian.

We use personal information collected via our Services for a variety of business purposes described below. We process your personal information for these purposes in reliance on our legitimate business interests, in order to enter into or perform a contract with you, with your consent, and/or for compliance with our legal obligations. We indicate the specific processing grounds we rely on next to each purpose listed below.

We use the information we collect or receive:

To send you marketing and promotional communications: We and/or our third-party marketing partners may use the personal information you send to us for marketing purposes, if this is in accordance with your marketing preferences. You can opt-out of our marketing emails at any time (see “What are your privacy rights” below).

Will your information be shared with anyone?
We only share information with your consent, to comply with laws, to provide you with services, to protect your rights, or to fulfill legitimate business obligations.

We may process or share data based on the following legal basis:

Consent: We may process your data if you have given us specific consent to use your personal information in a specific purpose.

Legitimate Business Interests: We may process your data when it is reasonably necessary to achieve our legitimate business interests.

Performance of a Contract: Where we have entered into a contract with you, we may process your personal information to fulfill the terms of our contract.

Legal Obligations: We may disclose your information where we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process, such as in response to a court order or a subpoena (including in response to public authorities to meet national security or law enforcement requirements).

Vital Interests: We may disclose your information where we believe it is necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, situations involving potential threats to the safety of any person and illegal activities, or as evidence in litigation in which we are involved.

Specifically, we may need to process your data or share your personal information in the following situations:

Vendors, Consultants and Other Third-Party Service Providers:

We may share your data with third party vendors, service providers, contractors or agents who perform services for us or on our behalf and require access to such information to do that work. Examples include: payment processing, data analysis, email delivery, hosting services, customer service and marketing efforts. We may allow selected third parties to use tracking technology on the Services, which will enable them to collect data about how you interact with the Services over time. This information may be used to, among other things, analyze and track data, determine the popularity of certain content and better understand online activity. Unless described in this Policy, we do not share, sell, rent or trade any of your information with third parties for their promotional purposes. We have contracts in place with our data processors. This means that they cannot do anything with your personal information unless we have instructed them to do it. They will not share your personal information with any organization apart from us. They will hold it securely and retain it for the period of time defined in our contractual agreements or in a manner that RenWare, Inc. instructs.

Business Transfers:

We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

Who will your information be shared with?
RenWare, Inc. will only share information with the following third parties.

We only share and disclose your information with the following third parties. We have categorized each party so that you can easily understand the purpose of our data collection and processing practices. If we have processed your data based on your consent and you wish to revoke your consent, please contact us.

Advertising, Direct Marketing and Lead Generation
Google Adwords, Google Tag Manager, HubSpot, Bing Ads and Freshworks

Google Privacy Policy – https://policies.google.com/privacy?hl=en-GB
Google Tag Manager – https://marketingplatform.google.com/about/analytics/tag-manager/use-policy/
HubSpot Privacy Policy – https://legal.hubspot.com/product-privacy-policy 
Bing Ads – https://about.ads.microsoft.com/en-gb/resources/policies/microsoft-advertising-privacy-policy
Freshworks – https://www.freshworks.com/privacy/

Email Communication and User Messaging
SendGrid, SendinBlue

SendGrid – https://www.twilio.com/legal/privacy
SendinBlue (now called Brevo) – https://www.sendinblue.com/legal/privacypolicy/

Web and Mobile Analytics

Google Analytics
Google Privacy Policy – https://policies.google.com/privacy?hl=en-GB
Google provides additional privacy options relating to the use of Analytics. You can view these here – http://www.google.com/policies/privacy/partners/

LinkedIn, Twitter/X
LinkedIn Insight Tag – https://www.linkedin.com/legal/cookie_policy
Twitter/X – https://help.twitter.com/en/rules-and-policies/twitter-cookies

Do we use cookies and other tracking technologies?
RenWare, Inc. may use cookies and other tracking technologies to collect and store your information.

We may use cookies and similar tracking technologies from LinkedIn, Twitter/X, Google AdWords, and Freshworks to access or store information such as website visits. These enable us to personalize and measure the effectiveness of advertising on our site, in our products and on other websites such as social media platforms. For example, we may serve you a personalized advert based on the pages you visit on our websites. We may share limited aspects of this strictly anonymized data with third parties for advertising purposes.

For more information about the information these third parties collect, or cookies they use, please access the respective links above.

How long do we keep your information?
We keep your information for as long as necessary to fulfill the purposes outlined in this privacy policy unless otherwise required by law. By default, the laws of the state of Colorado will take precedence unless otherwise specified by legal documentation provided to RenWare, Inc.

We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy policy, unless a longer retention period is required or permitted by law (such as tax, accounting or other legal requirements). No purpose in this policy will require us keeping your personal information for longer than (3) years past the start of idle period of the user’s account.

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.

How do we keep your information safe?
RenWare, Inc. aims to protect your personal information through a system of organizational and technical security measures.

We have implemented appropriate technical and organizational security measures designed to protect the security of any personal information we process. However, please also remember that we cannot guarantee that the internet itself is 100% secure. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the services within a secure environment.

Do we collect information from minors?
We do not knowingly collect data from or market to children under 18 years of age.

We do not knowingly solicit data from or market to children under 18 years of age. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we have collected from children under age 18, please contact us at dataprotection@appfox.io.

What are your privacy rights?
In some regions, you may have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time.

In some regions, you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; and (iv) if applicable, to data portability. In certain circumstances, you may also have the right to object to the processing of your personal information. To make such a request, please use the contact details provided below. We will consider and act upon any request in accordance with applicable data protection laws as long as they do not conflict with US laws.

If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time. Please note however that this will not affect the lawfulness of the processing before its withdrawal.

If you have questions or comments about your privacy rights, you may email us at dataprotection@renwareinc.com.

Account Information
If you would at any time like to review or change the information in your account or terminate your account, you can:

Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. RenWare, Inc. is not responsible for any unforeseen impacts to the business you work for, such as data loss or data locks owned by the requested deactivation account. However, some information may be retained in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our Terms of Use and/or comply with legal requirements.

Cookies and similar technologies: Most web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove cookies and to reject cookies. If you choose to remove cookies or reject cookies, this could affect certain features or services of our Services.

Opting out of email marketing: You can unsubscribe from our marketing email list at any time by clicking on the unsubscribe link in the emails that we send. You will then be removed from the marketing email list. You may also contact us directly via email (dataprotection@renwareinc.com) to request you be removed from our email marketing list. Please note, these requests may take up to thirty (30) business days to process. However, we will still need to send you service-related emails that are necessary for the administration and use of your account. To otherwise opt-out, you may access your account settings and update your preferences accordingly.

Data Breach
A privacy breach occurs when there is unauthorized access to or collection, use, disclosure or disposal of personal information. 

You will be notified about data breaches when RenWare, Inc. believes you are likely to be at risk of serious harm. For example, a data breach may be likely to result in serious financial harm or harm to your mental or physical well-being or that of your organization. 

In the event that RenWare, Inc. becomes aware of a security breach which has resulted or may result in unauthorized access, use or disclosure of personal information, we will promptly investigate the matter and notify the applicable Supervisory Authority not later than (72) hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.

Controls for do-not-track features
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (“DNT”) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected.

No uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online.

If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this privacy policy.

RenWare, Inc. Applications
Atlassian Marketplace Apps
This part of the Privacy Policy covers your usage of our Atlassian software applications, and how your data is stored and managed. The use of our Atlassian Marketplace software applications is governed by the respective Atlassian Marketplace Applications – End User License Agreement (EULA).

Data Management
The data stored by our software applications will vary depending on your environment (e.g. Cloud or Data Center/Server), and this section of the privacy policy will provide you with more details. 

Data Residency
Data Center/Server applications – No data is stored outside of your organization’s database
Cloud applications – For our cloud-based applications, the majority of data will be stored in your organization’s Atlassian cloud environment. However, if there is data required for our application to operate, this will be stored in our secure database. Any data stored will be held in the United States of America within an Amazon Web Services (AWS) Data Center. We are planning to support data residency across multiple locations (e.g. European Union, Asia-Pacific) in the future and appropriate announcements will be available to the public.

Data Encryption (cloud-based applications only)
RenWare, Inc. cloud applications use an encrypted database with data encrypted in transit (using HTTPS) and at rest, where necessary. Firewalls are in operation between our infrastructure and other services/internet.

Data Retention (cloud-based applications only)
For organizations using our cloud-based applications, any required data will be stored for as long as the subscription is active. Once a subscription becomes inactive (i.e. the subscription has ceased), the data will be retained for up to (3) years to enable you to re-subscribe at any time during this period, and retain your data.

If required, you can request your data is removed at any time by contacting our Customer Support team. 

Software Releases / Release Management
During the lifecycle of an application we will release updates to address any bugs or security vulnerabilities that may be identified, as well as introduce improvements and new features that are required to provide a positive customer experience. The process for managing these releases is governed by Atlassian, as detailed below:

Data Center/Server applications – Once an update is released, your Jira or Confluence administrator will need to manually update our software application on your system.
Cloud applications – Once an update is released, your application will be automatically updated with no action required by your organization other than pressing the "Update" link to get rid of Atlassian's UPM messaging.

All of our releases go through an extensive quality assurance (QA) process, including successful code reviews and thorough testing before being deployed into a production environment. 

Data Recovery Process
Data Center/Server applications – The recovery process for on-premise applications is managed by your organization’s backup and recovery processes and no agent of RenWare, Inc. will assist with any recovery activities unless your organization is under a Service contract with us that includes these services.

Cloud applications – Atlassian has an established and automated backup process that are taken multiple times per day and stored for up to (3) months. Should you require a recovery of your data, you must contact Atlassian as RenWare agents do not have access to your data and associated backups.

Third-Party Providers
Some of our software applications may require AWS or similar service to operate effectively. This provider was chosen due to their certifications, reliability, and history of security compliance globally.

Data Security
Employee Training & Confidentiality
All RenWare, Inc. agents are bound by confidentiality agreements as part of their W2 employee and/or 1099 independent consulting contracts and receive routine data protection training. Agents are required to complete cyber security training on an annual basis to ensure they stay up to date on the latest cyber security issues, updates, and protections. RenWare as an organization does the same to ensure we protect our clients.

Access Controls
There are strict security procedures and controls in place to restrict access to our infrastructure and databases. Access to infrastructure and databases is strictly monitored, with an approval process in place to ensure that access is tightly controlled. We also have a strict onboarding/off-boarding process for agents and clients.

All applications and infrastructure are managed by AWS user controls and security groups, where applicable, otherwise, they are managed by Atlassian. 

Notifications in event of Security Breach
In the event of a security breach, we follow the Atlassian App Security Incident reporting process, which has a clearly defined process for communicating with Atlassian and the Information Commission Office (ICO). 

This process will be managed by our organization’s Chief Information Security Officer (CISO).

Security Audits
There are two types of security audit performed by our organization:

System-level audits – All of our AWS managed services are regularly assessed for security vulnerabilities and are independently penetration tested (PEN test).

Code-level audits – All of our applications are routinely audited to ensure a high-security level is maintained. We conduct penetration testing on a regular basis and our cloud-based applications are part of a Bug
Bounty Program. In addition, we use linting, testing, and extensive code reviews to ensure our software is thoroughly reviewed before being released for customer use.
 
If any security vulnerability is discovered during an audit, there is a defined process in place to investigate them and ensure fixes are in place in a timely manner. 

User Notifications
Where applicable, our software applications may send email notifications for events that occur inside the software application or containing application (e.g. Jira and Confluence). This only applies to our cloud-based software applications.


Our on-premise applications (Server / Data Center) operate independently from our infrastructure.


Do we make updates to this Privacy Policy?
We routinely review and update this Privacy Policy. The updated version will be indicated by an updated “Revised” date and the updated version will be effective as soon as it is accessible. 

If we make material changes to this Privacy Policy, we may notify you either by prominently posting a notice of such changes or by sending you a direct notification. We encourage you to review this Privacy Policy frequently to be informed of how we are protecting your information.

Contact Us
If you have any questions about this Privacy Policy or data privacy at RenWare, Inc., please contact our Data Protection Officer (dataprotection@renwareinc.com). 

© Copyright 2025 RenWare, Inc. - All Rights Reserved | Privacy Policy | EULA | Terms of Use | SLA