Privacy notice and terms of use for the Jira Platform at Hochschule München
Privacy Notice
When using the Jira platform, personal data is processed as described in the privacy notices below.
1. Data controller
HM Hochschule München University of Applied Sciences
Lothstraße 34
D-80335 München
Telephone: +49 89 12 65 - 0
Fax: +49 89 12 65 - 3000
Email: kommunikation@hm.edu
is the data controller within the meaning of Article 4(7) of the GDPR.
Hochschule München is a public-law body. It is legally represented by its President, Prof. Dr Martin Leitner.
2. Data Protection Officer
The Data Protection Officer at Hochschule München can be contacted by email at datenschutzbeauftragter@hm.edu or dsbvertraulich@insidas.de , or by telephone on +49 871 205494 - 0.
3. Content of these notes
Wherever we use the term ‘data’ in this text, we refer exclusively to personal data as defined by the GDPR.
4. Accessing Jira via a web browser
The system environment is based on a database in which Jira data and user data are stored, as well as a web server that hosts the programme code and manages uploaded files. Jira is accessed via a web browser and requires users to log in with a personal user account.
5. Server log data and cookies
When using Jira, server log data is collected and cookies are set to ensure the platform operates smoothly and is user-friendly.
5.1 What is logged?
The following data is automatically collected and stored in log files:
- The device’s IP address
- Username
- Date and time of access
- Browser type and version
- Operating system
- Pages viewed and actions taken within Jira
We store this data for technical security reasons, in particular to defend against and investigate attempted attacks on our web server. After seven days at the latest, the data is anonymised by truncating the IP address to the domain level, so that it is no longer possible to link it to individual users.
Those responsible for the technical management of Jira and for the administration of the database and web servers have access to all data stored in the system. They may process this data only to the extent necessary to ensure the security and operation of Jira.
5.2 Which cookies are set?
- JSESSIONID: A session cookie used to identify and manage your session.
- seraph.rememberme.cookie: A cookie used for automatic login when the ‘Stay logged in’ feature is used.
- atlassian.xsrf.token: A security cookie used to prevent cross-site request forgery attacks.
- jira.issue.navigator.type: Stores the most recently used view of the search navigator
- AJS.conglomerate.cookie: Tracks the status of tabs and extensions, such as the most recently opened or closed items
- UNSUPPORTED_BROWSER_WARNING: Stores whether the user has acknowledged the warning about an unsupported browser.
- AJS.thisPage: Indicates whether the user’s browser does not support local storage.
- ccm_consent: manages users’ consent to data processing and the use of cookies
- JiraSDSamlssoLoginV2: enables single sign-on (SSO) for Jira Service Desk via the SAML 2.0 protocol
6. Purpose and legal basis
We process the information described in more detail above solely to ensure the secure and proper operation of Jira, as well as for the technically necessary logging of connection data. The Jira platform at Hochschule München is used for the purposes of project management, task management and quality management. The legal basis for the processing of data relating to non-HM members is Article 4(1) of the Bavarian Data Protection Act (BayDSG), Article 6(2) and (3), and Article 6(1), first sentence, point (e) of the GDPR; and for the processing of data relating to HM members, Article 4(1) of the Bavarian Data Protection Act (BayDSG), Article 6(2) and (3), Article 6(1), first sentence, point (e) of the GDPR in conjunction with Article 88 of the GDPR in conjunction with the service agreement on the use of a trouble-ticket system based on Atlassian Jira dated 16 July 2021.
The legal basis for placing technically necessary cookies on your device is Section 25(2)(2) of the TTDSG.
7. Registration and login
To access the Jira platform, you need an individual account within Jira. For users at Hochschule München, this user account is created automatically. For users at other institutions within the DFN-AAI federation, the account is only created when they log in for the first time. The Shibboleth authentication procedure of the respective institution is used for this.
Jira therefore does not process any confidential login details (such as passwords); these are processed exclusively on the individual universities’ systems. All other external individuals who are not members of a university must apply to the IT department for a guest account, which is then managed within the Hochschule München’s authentication system.
8. Mandatory details and information in the profile
Each time a user logs in, the following data is processed on the Jira platform:
- Name
- Email address
- Room
- Telephone number
- Organisational unit
- assigned roles or permissions
- You can add or remove optional details, such as a profile picture, at any time.
9. Retention period for personal data
Jira profiles are not automatically deleted; this is to ensure the traceability of ticket processing in Jira. Upon leaving Hochschule München (or, for non-university members, upon completion of a project), a request to anonymise user data may be submitted to Hochschule München’s Data Protection Officer. In this case, the username will be converted into an anonymous alias and the profile data will be anonymised in such a way that the profile appears to be that of a new user.
Service desk tickets are generally deleted two years after they are created. In the case of management projects, the entire project, including all tickets, is deleted once the project has been completed, provided there are no statutory retention requirements to the contrary.
10. Operating the Jira platform
The Jira platform is hosted on the university’s internal servers. All data is stored and processed in accordance with the applicable data protection standards.
11. Disclosure of profile details and other information
Your profile details (e.g. name, email address, room) are visible to project members within the Jira platform.
The access rights of users from other institutions within the DFN-AAI Federation are restricted to the project to which they have been granted access. They do not have access to the full HM user list or to other Jira helpdesks at HM.
All data and artefacts are processed in a manner that is traceable by the system administration; in particular, it is possible to trace which users have stored which data.
Authorised staff members from the relevant department at Hochschule München, or authorised project members, are granted access to the content of the tickets and projects. Other individuals are granted access to this content if they are added to the tickets or projects by authorised persons.
12. Your rights as a data subject
You are entitled to all the data subject rights set out in the GDPR. In particular, you have the right to access, rectification, erasure, restriction of processing, data portability and the right to object. You can find further information on your data subject rights via the following link: https://hm.edu/datenschutz .
13. Other information regarding our Privacy Policy
Hochschule München is updating its privacy policy to ensure that it complies with current requirements. When using Jira, please refer to the latest version of the policy.
If you have any questions regarding the processing of personal data, please feel free to contact the Data Protection Officer (datenschutzbeauftragter@hm.edu ). If you have any questions about Jira, please email Information Technology Services (zentrale-it@hm.edu ).
Terms of Use
1. Scope
These Terms of Use govern the use of the Jira platform at Hochschule München.
2. Purpose of use
The Jira platform is made available to members of Hochschule München for the organisation, management and tracking of projects and tasks. In addition, staff members from external partners, such as other universities or companies, may be granted access if they are collaborating with members of Hochschule München on joint projects.
The Jira platform must be used exclusively for work-related, study-related or academic purposes.
3. Registration and access
Use of the service requires registration, which is carried out during the initial login via a single sign-on service. User accounts are personal and must not be shared with third parties. Login details must be kept secure and must not be shared with third parties. In the event of loss or misuse, the Jira platform administrator must be notified immediately at information-technology-services@hm.edu .
Access for external partners is limited to the duration of the relevant project. Once the project has been completed, access will be deactivated.
For members of Hochschule München, use of the service is linked to their affiliation with the institution and ceases upon leaving the university.
4. Data protection and data security
The processing of personal data in the course of the Munich University of Applied Sciences’ operations, as well as in connection with users’ use of the Jira platform, is carried out in accordance with the applicable data protection regulations (GDPR, BayDSG, etc.) and the university’s internal guidelines.
Hochschule München takes technical and organisational measures to protect the data processed on the platform.
Users undertake to treat personal data and other information accessible to them via the Jira Platform as confidential and not to disclose it without authorisation.
5. Users’ obligations
Users undertake to use the Jira instance solely for its intended purposes. No content may be posted that contravenes applicable law, in particular copyright law. Hochschule München reserves the right to review content and remove it where necessary.
6. Availability and support
Hochschule München provides the Jira platform in a fully functional state and in accordance with the applicable security standards. Due to maintenance work, Jira will be unavailable for short periods at irregular intervals. Furthermore, we cannot guarantee that Jira will be available at all times.
Technical support is provided at information technology services@hm.edu to ensure the platform functions correctly.
7. Duration of data processing
Data in Jira is deleted when it is no longer required for the specified purpose (e.g. when a project has been completed).
User accounts are suspended upon termination of employment or the end of the working relationship. To ensure traceability within Jira, accounts are not automatically deleted. A request for the deletion of data may be submitted to the Data Protection Officer at Hochschule München.
Further information on this can be found in the Privacy Policy .
8. Termination of use
Access will be deactivated upon leaving the authorised user group.
Users may also be barred from using Jira if they:
- repeatedly or seriously breach these Terms of Use,
- use or disclose confidential data without authorisation,
- manipulate the system or impair its functionality.
9. Amendments to these Terms of Use
Hochschule München reserves the right to amend these Terms of Use as necessary. Users will be notified of any changes in good time. By continuing to use Jira, you agree to the updated terms.
10. Severability clause
Should any individual provisions of these Terms of Use be or become invalid, this shall not affect the validity of the remaining provisions. The invalid provision shall be replaced by a legally permissible provision that comes as close as possible to the original purpose.
11. Acknowledgement of the Terms of Use
By using Jira, you confirm that you have read, understood and accepted these Terms of Use.
Date of last amendment: 26 March 2025
The information on this page was translated into English for your convenience. In case of any discrepancies between the English and German versions, the German version shall prevail.