This policy explains what the TrustTroiAI Inspector browser extension collects, why, and who it is shared with. It supplements the full TrustTroiAI Platform privacy policy at trusttroiai.eu/plattform-datenschutz, which is published in German and describes the entire processing chain in detail. Where a rule here is more specific to the extension, this policy prevails.
TrustTroiAI
Grünewalder Straße 29–31
coworkit (SG-Grünewald)
42657 Solingen
Germany
Data protection contact: [email protected]
General contact: [email protected]
We have not appointed a data protection officer. See Section 03 of the master policy for the reasoning.
The Inspector helps you identify which EU compliance obligations — from the AI Act, GDPR, Cyber Resilience Act and Data Act — apply to the work described in an Atlassian Jira issue, and record evidence against those obligations. It performs no other function. It does not track your browsing, it does not read tabs other than the Jira issue you are actively working on, and it does not run outside Jira.
Stored locally in the extension (browser's chrome.storage.local):
This local storage remains on your device and is cleared when you sign out or remove the extension.
Sent to our backend when you use the extension:
The extension does not send data from tabs other than the Jira issue you are actively interacting with.
Our platform sets one cookie required to keep you signed in:
trusttroiai_session — HttpOnly, Secure, SameSite=None, 30-day lifetime. SameSite=None is required so that the extension can recognise you as signed in when you use it inside Jira.In our database we store only the SHA-256 hash of this token, together with its expiry and revocation status. On sign-out the session is invalidated on the server. We do not use tracking or advertising cookies.
The Inspector connects to your Atlassian account via OAuth 2.0 (3LO) with the scopes read:jira-work, read:jira-user, write:jira-work, read:me, and offline_access. Access and refresh tokens are stored encrypted on our server using symmetric encryption (Fernet). You can disconnect the integration at any time inside the extension or by revoking access under "Connected apps" in your Atlassian account. When you disconnect, the stored tokens are deleted.
For classification, evidence assessment, template generation and the compliance assistant, we use language models from Mistral AI SAS (Paris, France). Processing takes place on servers in the European Union. A data processing agreement under Article 28 GDPR is in place; a written exclusion of the use of your content for model training is part of that agreement.
Pseudonymization before transmission. Before content leaves our server for Mistral — for language-model calls and for embedding calls used in similarity search — our backend replaces detected personal identifiers (names, email addresses, phone numbers, account and customer numbers, technical identifiers) with placeholders such as [PERSON_A]. Mistral sees only the placeholders. Placeholders are resolved back to the original values in your browser for display.
Chat exception. Text sent to the compliance assistant during a chat is currently not pseudonymized, because the assistant calls follow-up tools mid-conversation and a mixed placeholder/plaintext dialog produces incorrect legal statements. We disclose this transparently: a dialog before your first use of the assistant explains the exception, and each answer displays which personal-data categories were included in the message.
AI outputs are proposals, not decisions. Every output shows a confidence value and the underlying legal source and must be confirmed by a human before it counts as evidence. No automated decision-making within the meaning of Article 22 GDPR takes place.
In line with the Chrome Web Store User Data Policy, we commit to the following:
We use the following processors:
Atlassian is not a processor of ours; it is the source from which you make Jira data available to us via OAuth (see Section 05).
We do not share your data with advertising networks, data brokers, or analytics services outside the ones described above.
Humans in our team access your data only in the following cases:
Administrative access is limited to an explicitly maintained list of authorised accounts and is logged.
On account deletion or on request, we anonymise your identifying data immediately and delete the remaining records within 30 days, except where a statutory retention obligation applies (commercial and tax records: 6 or 10 years under §§ 257 HGB, 147 AO).
Under the GDPR you have the rights of access, rectification, erasure, restriction of processing, data portability, objection to processing based on our legitimate interest, and withdrawal of any consent given. An informal message to [email protected] is sufficient to exercise them. We respond without undue delay and at the latest within one month.
You also have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR). The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.
The Inspector requests the minimum permissions required for its single purpose. It reads content only from the Atlassian domain of the Jira issue you are actively interacting with. It does not request permissions for browsing history, downloads, other tabs, or unrelated sites.
The Inspector is intended for professional use by employees and contractors of organisations using the TrustTroiAI Platform. It is not directed at children under 16 and we do not knowingly collect data from children.
We update this policy when the extension's data handling changes, when the master platform policy changes materially, or when legal requirements make it necessary. The version published at this URL applies in each case. Material changes are announced in advance.
This website uses only strictly necessary cookies and privacy-friendly, cookieless analytics. Privacy