Privacy Policy

Liquid Solutions · LiquidJira platform

Last updated: 27 May 2026

Data controller

The data controller for personal data processed through the LiquidJira platform (commercial brand Liquid Solutions) is OHTIC SOLUTIONS SL (NIF B67573360), with registered office at C/ Viver 30, 08150 Parets del Vallès, Barcelona, Spain.

For privacy-related requests, contact us at info@ohtic.com.

What the service is

LiquidJira is a multi-tenant software-as-a-service (SaaS) that connects to your organisation's Atlassian Jira Cloud, synchronises Jira data into dedicated storage per instance, and provides dashboards and metrics (KGI, KPI, KMI) for business decision-making.

We do not modify, delete, or create Jira issues on your behalf; synchronisation is read-only toward Jira.

Personal data we process

Account data: email address, display name, password (stored only as a secure hash), login and security metadata (e.g. failed login attempts, lockout timestamps).

Organisation and workspace data: tenant and instance names, membership roles, configuration you provide in the product.

Jira connection data: Jira site URL, account email used for API access, and API token — stored only in encrypted form; never shown in full in the user interface after saving.

Usage and operational data: logs and technical events needed to run, secure, and support the service (without logging credentials or authentication secrets).

Billing data: where applicable, billing contact details and payment references processed through our payment provider; we do not store full card numbers on our systems.

Purposes of processing

To provide, maintain, and improve the LiquidJira platform and related support.

To authenticate users, enforce access control, and protect accounts (including lockout after repeated failed sign-in attempts).

To fulfil contractual and legal obligations, including invoicing where applicable.

To respond to your requests and communicate about the service.

Legal basis (GDPR)

Performance of a contract when you register, subscribe, or use the service on behalf of your organisation.

Legitimate interests in securing the platform, preventing abuse, and improving reliability, balanced against your rights.

Consent where you explicitly accept the terms of service and this privacy policy during signup.

Legal obligation where we must retain or disclose data to comply with applicable law.

Recipients and subprocessors

Infrastructure and hosting are provided on Microsoft Azure (including Azure Database for PostgreSQL, Azure Container Apps, Azure Key Vault, and Azure Service Bus), with workloads deployed in the European Union (West Europe region for standard managed deployments).

To deliver the service we communicate with Atlassian Jira Cloud using credentials you supply; Atlassian processes data under its own terms as an independent provider.

Transactional email (e.g. password reset, invitations, or access requests when enabled) may be sent via our email delivery provider.

We do not sell your personal data to third parties.

Retention

We keep personal data for as long as your organisation maintains an active relationship with us and as needed to provide the service.

After termination, we delete or anonymise data within a reasonable period, except where longer retention is required by law or for the establishment, exercise, or defence of legal claims.

Your rights

If you are in the European Economic Area or UK, you may have the right to access, rectify, erase, restrict, or object to certain processing, and to data portability where applicable.

You may withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal.

You may lodge a complaint with the Spanish Data Protection Agency (AEPD) or your local supervisory authority.

To exercise your rights, email info@ohtic.com from the address associated with your account or with sufficient information for us to verify your identity.

International transfers

We design deployments so that customer data hosted by us remains in the European Union. If you use a bring-your-own-database option, database hosting is under your control and your own transfer rules apply.

Where any processor transfers data outside the EEA, we rely on appropriate safeguards as required by applicable law.

Cookies and session storage

The web application uses strictly necessary session cookies (httpOnly) managed through NextAuth to keep you signed in. These are required for the service to function.

We do not use third-party advertising or analytics cookies in the product as of the date above.

Children

The service is intended for business users and is not directed at children under 16. We do not knowingly collect personal data from children.

Changes to this policy

We may update this policy from time to time. We will post the revised version on this page and update the "last updated" date. Material changes may also be notified through the product or by email where appropriate.

Contact

Privacy enquiries: info@ohtic.com

OHTIC SOLUTIONS SL · C/ Viver 30, 08150 Parets del Vallès, Barcelona, Spain