Approve & Lock for Confluence

Data Processing Agreement — Approve & Lock for Confluence

Last updated: 30 July 2026

Processor: DAPDEV Software Solutions OÜ ("we", "us"), a company registered in Estonia (VAT EE102391086), [email protected]

This Data Processing Agreement ("DPA") applies where you use Approve & Lock for Confluence ("the App") to process personal data governed by the EU General Data Protection Regulation (GDPR) or the UK GDPR. It forms part of, and is subject to, the End User Terms. Where this DPA and the End User Terms conflict on the subject of personal data, this DPA prevails.

You do not need to sign or return anything. This DPA takes effect automatically when you install the App. If your organisation requires a countersigned copy, email [email protected].

1. Roles

You are the controller. You decide which pages are placed under approval, who approves them, and how long the records are kept.

We are the processor, acting only on your instructions as set out in this DPA and the App's documented functionality.

2. The unusual part, stated plainly

The App runs entirely inside your own Atlassian environment on Atlassian's Forge platform. It has no servers, no database, and no external network egress. Approval records are written to Forge storage belonging to your Atlassian site.

We hold no copy of your data and have no standing access to it. We cannot read your approval records, your page content, or your users' identifiers from our own systems, because no such systems exist. This shapes every obligation below: several of the assistance duties in Article 28 are things you can perform directly in Confluence faster than we could.

3. Subject matter and details of processing

ItemDetail
Subject matterRecording page approval decisions and binding them to a page version
DurationFor as long as the App is installed on your Atlassian site
Nature and purposeStoring approval state, decisions and an audit trail; applying and releasing Confluence edit restrictions
Categories of data subjectsYour Confluence users who request, approve, reject or are named as approvers
Types of personal dataAtlassian account IDs; optional free-text comments entered on an approval; timestamps and decision records associated with those account IDs
Special category dataNone. The App is not designed for it and you should not enter it into approval comments

The App does not store page content. It records *that* a page changed and at which version, never the text of the page.

4. Our obligations

5. Security measures (Article 32)

Because the App holds no infrastructure of its own, its security posture is principally the absence of attack surface:

6. Sub-processors

We engage no sub-processors. Your data is not transferred to us or to any third party; it remains within the Atlassian environment you already control under your own agreement with Atlassian. Atlassian's role as your platform provider is governed by your direct agreement with Atlassian, not by this DPA.

If this ever changes we will give you at least 30 days' notice by email to your Marketplace contact address before the new sub-processor begins processing, during which you may object by uninstalling the App and contacting us for a pro-rata refund of any prepaid, unused fees.

7. Data subject rights

Because approval records live in your own Atlassian site, you can satisfy most data subject requests directly:

Where you nonetheless need our help, contact [email protected]. We will respond within one business day and assist by appropriate technical and organisational measures, insofar as this is possible given that we hold no copy of the data.

8. Personal data breaches

If we become aware of a personal data breach affecting personal data processed under this DPA, we will notify you without undue delay and in any event within 48 hours of becoming aware, by email to your Marketplace contact address, with the information available to us at that time and updates as the investigation proceeds.

You may report a suspected vulnerability or breach to [email protected]. We target a first response within one business day.

Note that a breach of Atlassian's platform is a breach of your own processor and is notifiable to you by Atlassian under your agreement with them.

9. Data protection impact assessments

We will provide reasonable assistance with any data protection impact assessment or prior consultation with a supervisory authority relating to the App. In practice this DPA and the Privacy Policy contain the information a DPIA for this App requires; if you need more, ask.

10. Return and deletion

Uninstalling the App removes its Forge storage, deleting all approval records and audit history held by the App. This is the deletion mechanism at the end of the provision of services, and it is under your control rather than ours.

We hold no separate copy to return or delete. To request deletion while the App remains installed, contact [email protected].

11. Audits and information

We will make available the information necessary to demonstrate compliance with Article 28, and will contribute to audits and inspections conducted by you or an auditor you mandate.

Given that we operate no infrastructure that processes your data, an audit is necessarily documentary: we will answer written questionnaires and provide the information in this DPA, the Privacy Policy, and our Marketplace Privacy & Security questionnaire responses. Infrastructure-level assurance is available from Atlassian, whose certifications cover the environment in which the App runs.

12. International transfers

We perform no international transfers of your personal data. The App does not move data out of your Atlassian environment, so data residency follows the residency of your Atlassian site and is determined by your agreement with Atlassian.

Accordingly, no Standard Contractual Clauses are required for processing by us. If that ever changes, the EU Commission's Standard Contractual Clauses (Module Two, controller to processor) will be incorporated into this DPA by reference and will prevail over any conflicting term.

13. Liability

Liability under this DPA is subject to the limitations and exclusions in the End User Terms.

14. Governing law

This DPA is governed by the laws of Estonia, without regard to conflict of law rules, and is subject to the jurisdiction of the Estonian courts.

15. Changes

We may update this DPA to reflect changes in the App or in applicable law. Material changes will be posted here with a revised date and, where the change reduces your protections, notified by email to your Marketplace contact address at least 30 days in advance.