Terms of Service

Last updated: 1 March 2026

1. Acceptance

By installing, accessing, or using MetaFrazo (“Service”), you agree to be bound by these Terms. If you do not agree, you must not install or use the Service.

If you use the Service on behalf of an organization, you represent that you have authority to bind that organization.

2. Service Description

MetaFrazo provides a Jira Cloud application that processes Jira events and metadata to deliver analytics, compliance support insights, and operational resilience support aligned with regulatory frameworks such as NIS2, GDPR, and DORA.

The Service supports compliance efforts but does not guarantee regulatory compliance.

3. License Grant

Subject to these Terms, MetaFrazo grants you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to use the Service solely within Jira instances you are authorized to administer and solely for internal business purposes.

You may not:

  • Reverse engineer, decompile, or attempt to access source code
  • Resell, sublicense, or distribute the Service
  • Use the Service for unlawful purposes
  • Interfere with or disrupt the Service

All intellectual property rights remain exclusively with MetaFrazo.

4. Customer Responsibilities

You are responsible for:

  • Maintaining appropriate Jira configurations
  • Ensuring lawful processing of personal data in your Jira environment
  • Compliance with applicable laws
  • Internal compliance decisions

MetaFrazo is not responsible for regulatory interpretations or decisions made based on Service output.

5. Data & Privacy

Use of the Service is subject to the MetaFrazo Privacy Policy, incorporated by reference.

MetaFrazo acts:

  • As Data Controller for account and billing data
  • As Data Processor for Jira content data processed on your behalf

Data Processing Agreement (DPA)

Our Data Processing Agreement (DPA) is incorporated into and forms part of these Terms and governs our processing of your data where we act as your processor. A counter-signed copy is available on request — you can request one below and we will follow up via a support ticket.

6. Availability & Modifications

The Service may be modified, updated, suspended, or discontinued at any time.

We do not guarantee uninterrupted or error-free availability.

6.1 Discontinuation & Cessation of Business

If MetaFrazo ceases business operations, or otherwise decides to permanently discontinue the Service, we may terminate the Service in whole or in part. Where reasonably practicable, we will provide advance notice through the Service, the Atlassian Marketplace listing, or email so that you may export or preserve any data you require before access ends.

Upon such discontinuation, your right to access and use the Service terminates, any customer data is handled in accordance with Section 7 (Data Retention) of the Privacy Policy, and — except for obligations that cannot be excluded under applicable law or under the Atlassian Marketplace Agreement (such as any refund of pre-paid fees administered by Atlassian) — MetaFrazo shall have no further obligation, liability, or continuing commitment to you arising from the discontinuation.

7. Disclaimer of Warranties

The Service is provided “as is” and “as available”.

To the maximum extent permitted by applicable law, MetaFrazo disclaims all warranties, including merchantability, fitness for a particular purpose, and non-infringement.

We do not guarantee that:

  • The Service will be uninterrupted or error-free
  • The Service ensures regulatory compliance
  • The Service will meet specific operational or legal requirements

8. Limitation of Liability

To the fullest extent permitted by applicable law:

  • MetaFrazo shall not be liable for indirect, incidental, special, consequential, or punitive damages, including loss of profits, revenue, data, or business interruption.
  • MetaFrazo's total aggregate liability under these Terms shall not exceed the total fees paid by you for the Service during the six months preceding the claim.
  • For free installations, liability is limited to 100 EUR.

Nothing in these Terms excludes liability where exclusion is prohibited by law.

9. Force Majeure

MetaFrazo shall not be liable for failure or delay caused by events beyond reasonable control, including cloud provider outages, cyber incidents, acts of government, regulatory changes, natural disasters, or third-party platform modifications.

10. Termination

  • You may uninstall the Service at any time.
  • MetaFrazo may suspend or terminate access if these Terms are violated or if continued provision poses security, legal, or compliance risks.

11. Governing Law and Jurisdiction

  • These Terms are governed by the laws of Greece, excluding conflict-of-laws principles.
  • The competent courts of Thessaloniki, Greece, shall have exclusive jurisdiction.

12. Severability

If any provision of these Terms is held invalid or unenforceable, the remaining provisions remain in full force and effect.

13. Entire Agreement

These Terms, together with the Privacy Policy and the Data Processing Agreement (DPA), constitute the entire agreement between you and MetaFrazo regarding the Service.

14. Contact

For questions about these Terms, contact us at support [at] metafrazo.cloud

Privacy Policy

Last updated: 1 March 2026

1. Introduction

MetaFrazo provides a Jira Cloud application that processes Jira events and metadata to enable analytics, compliance monitoring, and operational resilience support.

We process personal data in accordance with the General Data Protection Regulation and applicable EU and Greek data protection laws.

2. Roles Under GDPR

MetaFrazo acts as:

  • Data Controller for account, billing, and administrative data
  • Data Processor for Jira content and event data processed on behalf of customers

3. Data We Collect

3.1 Account and Administrative Data

  • Jira Cloud site ID
  • Jira site URL
  • Installing administrator Atlassian account ID
  • Email address where permitted
  • Billing related information where applicable

3.2 Jira Metadata

  • Issue IDs and keys
  • Project IDs and names
  • Event types and payload

4. Legal Basis for Processing

We process personal data under:

  • Art. 6(1)(b) GDPR for contract performance
  • Art. 6(1)(c) GDPR for legal obligations
  • Art. 6(1)(f) GDPR for legitimate interests including security, monitoring, and service reliability

5. Purpose of Processing

  • Operate and maintain the Service
  • Provide analytics and compliance support functionality
  • Identify installing administrators for onboarding and security
  • Improve performance and resilience
  • Detect and prevent misuse or abuse

We do not sell personal data and do not use personal data for independent marketing purposes.

6. Subprocessors and International Transfers

We engage a small number of trusted, EU-based infrastructure and cloud subprocessors strictly for service delivery. Customer data is processed within the European Union / European Economic Area.

MetaFrazo's own processing — including the default MetaFrazo AI analysis — takes place within the EU/EEA, so it requires no transfer mechanism. A transfer outside the EEA arises only from the customer's own choices (for example, the region of the customer's Jira instance, or a customer-selected third-party AI provider activated under the customer's own credentials). For any transfer MetaFrazo itself makes, appropriate safeguards including Standard Contractual Clauses are implemented where required.

The current named subprocessor list and processing regions are available to signed-in customers below and on request.

Sign in to your MetaFrazo dashboard to view the current named subprocessor list and processing regions, or request it via support.

7. Data Retention

  • Administrative and billing data are retained for the duration of the contractual relationship and for up to six years, as required by accounting or legal obligations.
  • Operational logs are retained for up to twelve months unless longer retention is required for security investigations or regulatory compliance.
  • If the app is uninstalled, customer-related data is deleted or anonymized within thirty days unless legal retention obligations apply.

8. Security Measures

We implement appropriate technical and organizational measures, including encryption in transit and at rest, access controls, and monitoring.

No system can guarantee absolute security. Customers remain responsible for their Jira configuration and internal access management.

9. Your Rights Under GDPR

You may have the right to:

  • Access your personal data
  • Request rectification
  • Request erasure
  • Request restriction of processing
  • Object to processing
  • Request data portability

Requests may be submitted to: privacy [at] metafrazo.cloud

You also have the right to lodge a complaint with the Hellenic Data Protection Authority.

10. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via our website or the Atlassian Marketplace listing.

11. Contact

MetaFrazo
Thessaloniki, Greece

Security

Last updated: 10 June 2026

This section summarizes how MetaFrazo protects your data. It describes our security posture at a high level and is not an exhaustive description of our internal controls.

1. Hosting & Residency

MetaFrazo runs on managed cloud infrastructure located in the European Union (Frankfurt). Customer data is stored and processed in the EU.

2. Encryption

Customer data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest using AES-256.

3. Tenant Isolation

Each organization’s data is logically isolated. The Service is designed so that one organization cannot access another organization’s data. You can read more about how we keep tenant data separate in our data-isolation documentation.

4. No Jira Credentials

MetaFrazo never asks for or stores your Jira password or personal access token. The app authenticates through Atlassian’s secure token mechanism for installed apps.

5. AI Processing

AI-powered analysis is optional and can be disabled for your organization at any time. On the default service, requests are processed by an EU-based model. The data sent for analysis is pseudonymized — it does not include names or email addresses — and is handled under a contractual zero-data-retention and no-reuse term: inputs and outputs are not stored after the request and are never used to train models. For details on each AI option and how your data is handled, see our AI disclosure.

6. Subprocessors

We engage a small number of trusted, EU-based subprocessors strictly for service delivery. The current named list and processing regions are shown to signed-in customers in the Subprocessors section above, and are available on request.

7. Data Retention & Deletion

You can request deletion of your data by contacting support. When the app is uninstalled, tenant data is removed after a grace period; administrative and billing records may be retained where required by law. See the Privacy Policy above for the specific retention periods.

8. Vulnerability Disclosure & Security Contact

To report a security vulnerability or concern, contact us at contact [at] metafrazo.cloud. We are enrolling in a Vulnerability Disclosure Program and bug bounty; these will be listed here once active.

9. Compliance Posture

MetaFrazo is operated in line with the EU General Data Protection Regulation (GDPR). We do not currently hold or claim any security certifications (such as ISO 27001 or SOC 2); any certification will be stated here only once it is actually held.