Data processing agreement
These terms apply where we process personal data on your behalf under Article 28 GDPR. If you need a signed copy or your own paper, write to contact@bavetic.com.
Last updated TODO: date
TODO: Draft — pending legal review. Not binding in this form.
1. Parties and scope
Controller: the customer operating the Atlassian Confluence site on which the app is installed.
Processor: bavetic, c/o COCENTER, Koppoldstr. 1, 86551 Aichach, Germany.
These terms apply to processing carried out by Storage Optimizer for Confluence and by any other bavetic app you install, and supplement the end-user agreement applicable to that app.
2. Subject matter and duration
Subject matter: analysis of Confluence attachment storage consumption and, on your instruction, deletion of attachment versions. Duration: for as long as the app is installed on your site.
3. Nature and purpose of processing
Reading attachment metadata and page content within your Confluence site in order to calculate storage consumption, and deleting objects you select. Processing takes place within Atlassian’s Forge platform.
4. Categories of data and data subjects
Categories of data: attachment metadata (file name, size, version number, timestamps, uploading user), page content in so far as it is scanned for attachment references, and Confluence space and page identifiers.
Data subjects: your users who upload, edit or are named in Confluence content.
5. Instructions
We process personal data only on your documented instructions. Your use of the app’s functions constitutes such an instruction. We will inform you if, in our opinion, an instruction infringes the GDPR or other data protection law.
6. Confidentiality
Persons authorised to process personal data are bound to confidentiality, either contractually or by statute.
7. Security of processing (Art. 32 GDPR)
The app runs on Atlassian Forge and declares no outbound network access. Personal data is not transmitted to, stored on, or accessible from infrastructure operated by us. Platform-level technical and organisational measures — encryption in transit and at rest, access control, logging, and physical security — are those of the Atlassian Forge platform.
TODO: List our own organisational measures — device encryption, credential handling, access to Marketplace and Forge accounts, MFA.
8. Sub-processors
We engage Atlassian Pty Ltd as a sub-processor, as the operator of the Forge platform on which the app runs and of the Confluence site holding your data.
We engage Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as a sub-processor for email. Our support mailbox runs on Google Workspace, so any personal data you include in a message to us — a screenshot, an attachment name, a user name — is processed there. This is the only processing on our behalf that happens outside your Confluence site. Google’s Cloud Data Processing Addendum applies to it.
We engage no other sub-processors. In particular, the app transmits nothing to our website host, which serves static files only and receives no data from your Confluence site. We will inform you of any intended change and you may object.
9. Assistance to the controller
Taking into account the nature of the processing, we assist you in responding to requests from data subjects under Chapter III GDPR, and in meeting your obligations under Articles 32 to 36. Because the app holds no copy of your data outside your own Confluence site, most such requests are answered directly in Confluence.
10. Personal data breaches
We notify you without undue delay after becoming aware of a personal data breach affecting data processed on your behalf, with the information needed for your notification under Art. 33 GDPR.
11. Deletion and return
We hold no copy of your Confluence content and the app persists no data on any server, so there is nothing for us to return or delete at the end of processing. On uninstallation the app’s access ends and processing ceases. The only value the app writes anywhere is a single interface preference in the browser’s local storage, which contains no personal data and is removed by clearing site data.
Support correspondence is the exception: messages you send us remain in our mailbox so that we can follow up on the request. We delete them on your request and otherwise once they no longer serve that purpose.
12. Audits
We make available the information necessary to demonstrate compliance with Art. 28 GDPR and allow for audits, including inspections, conducted by you or an auditor you mandate. Information about the Forge platform is published by Atlassian.
13. International transfers
The app carries out no transfer of your personal data to a third country. Where Atlassian does so as part of operating your Confluence site, the transfer mechanisms are those set out in your agreement with Atlassian.
Our support mailbox is contracted with Google Ireland Limited in the EU, but Google may involve affiliates outside the EEA. Those transfers are governed by the Standard Contractual Clauses incorporated into Google’s Cloud Data Processing Addendum, and Google LLC is certified under the EU-U.S. Data Privacy Framework.