Data Processing Agreement — Approve & Lock for Confluence
Last updated: 30 July 2026
Processor: DAPDEV Software Solutions OÜ ("we", "us"), a company registered in Estonia (VAT EE102391086), [email protected]
This Data Processing Agreement ("DPA") applies where you use Approve & Lock for Confluence ("the App") to process personal data governed by the EU General Data Protection Regulation (GDPR) or the UK GDPR. It forms part of, and is subject to, the End User Terms. Where this DPA and the End User Terms conflict on the subject of personal data, this DPA prevails.
You do not need to sign or return anything. This DPA takes effect automatically when you install the App. If your organisation requires a countersigned copy, email [email protected].
1. Roles
You are the controller. You decide which pages are placed under approval, who approves them, and how long the records are kept.
We are the processor, acting only on your instructions as set out in this DPA and the App's documented functionality.
2. The unusual part, stated plainly
The App runs entirely inside your own Atlassian environment on Atlassian's Forge platform. It has no servers, no database, and no external network egress. Approval records are written to Forge storage belonging to your Atlassian site.
We hold no copy of your data and have no standing access to it. We cannot read your approval records, your page content, or your users' identifiers from our own systems, because no such systems exist. This shapes every obligation below: several of the assistance duties in Article 28 are things you can perform directly in Confluence faster than we could.
3. Subject matter and details of processing
| Item | Detail |
|---|---|
| Subject matter | Recording page approval decisions and binding them to a page version |
| Duration | For as long as the App is installed on your Atlassian site |
| Nature and purpose | Storing approval state, decisions and an audit trail; applying and releasing Confluence edit restrictions |
| Categories of data subjects | Your Confluence users who request, approve, reject or are named as approvers |
| Types of personal data | Atlassian account IDs; optional free-text comments entered on an approval; timestamps and decision records associated with those account IDs |
| Special category data | None. The App is not designed for it and you should not enter it into approval comments |
The App does not store page content. It records *that* a page changed and at which version, never the text of the page.
4. Our obligations
- Documented instructions. We process personal data only on your documented instructions, which comprise this DPA, the End User Terms, and your configuration and use of the App. We will tell you if we believe an instruction infringes the GDPR.
- Confidentiality. Any person we authorise to process personal data is bound by a duty of confidentiality.
- Security. We maintain the measures described in section 5.
- Sub-processors. See section 6.
- Assistance with data subject rights. See section 7.
- Assistance with security, breach notification and DPIAs. See sections 8 and 9.
- Deletion. See section 10.
- Demonstrating compliance. See section 11.
5. Security measures (Article 32)
Because the App holds no infrastructure of its own, its security posture is principally the absence of attack surface:
- No external network egress. The App declares no
external.fetchpermissions and is eligible for Atlassian's Runs on Atlassian programme, which requires exclusive use of Atlassian-hosted compute and storage. - No credentials, API keys, tokens or secrets are held by the App or by us.
- No authentication of our own. Identity and access control are performed by Atlassian; the App relies on the permissions of the calling Confluence user.
- Least-privilege scopes. The App requests only the scopes needed to detect edits, apply and release edit restrictions, and store approval records.
- Encryption in transit and at rest is provided by the Atlassian platform.
- No analytics, telemetry, tracking, advertising or profiling.
- Logging is limited to Forge console logs and excludes page content and personal data.
6. Sub-processors
We engage no sub-processors. Your data is not transferred to us or to any third party; it remains within the Atlassian environment you already control under your own agreement with Atlassian. Atlassian's role as your platform provider is governed by your direct agreement with Atlassian, not by this DPA.
If this ever changes we will give you at least 30 days' notice by email to your Marketplace contact address before the new sub-processor begins processing, during which you may object by uninstalling the App and contacting us for a pro-rata refund of any prepaid, unused fees.
7. Data subject rights
Because approval records live in your own Atlassian site, you can satisfy most data subject requests directly:
- Access and portability — approval history is visible on the page and on the space dashboard, and can be exported from Confluence.
- Erasure — removing a page from approval, or uninstalling the App, deletes the associated records.
Where you nonetheless need our help, contact [email protected]. We will respond within one business day and assist by appropriate technical and organisational measures, insofar as this is possible given that we hold no copy of the data.
8. Personal data breaches
If we become aware of a personal data breach affecting personal data processed under this DPA, we will notify you without undue delay and in any event within 48 hours of becoming aware, by email to your Marketplace contact address, with the information available to us at that time and updates as the investigation proceeds.
You may report a suspected vulnerability or breach to [email protected]. We target a first response within one business day.
Note that a breach of Atlassian's platform is a breach of your own processor and is notifiable to you by Atlassian under your agreement with them.
9. Data protection impact assessments
We will provide reasonable assistance with any data protection impact assessment or prior consultation with a supervisory authority relating to the App. In practice this DPA and the Privacy Policy contain the information a DPIA for this App requires; if you need more, ask.
10. Return and deletion
Uninstalling the App removes its Forge storage, deleting all approval records and audit history held by the App. This is the deletion mechanism at the end of the provision of services, and it is under your control rather than ours.
We hold no separate copy to return or delete. To request deletion while the App remains installed, contact [email protected].
11. Audits and information
We will make available the information necessary to demonstrate compliance with Article 28, and will contribute to audits and inspections conducted by you or an auditor you mandate.
Given that we operate no infrastructure that processes your data, an audit is necessarily documentary: we will answer written questionnaires and provide the information in this DPA, the Privacy Policy, and our Marketplace Privacy & Security questionnaire responses. Infrastructure-level assurance is available from Atlassian, whose certifications cover the environment in which the App runs.
12. International transfers
We perform no international transfers of your personal data. The App does not move data out of your Atlassian environment, so data residency follows the residency of your Atlassian site and is determined by your agreement with Atlassian.
Accordingly, no Standard Contractual Clauses are required for processing by us. If that ever changes, the EU Commission's Standard Contractual Clauses (Module Two, controller to processor) will be incorporated into this DPA by reference and will prevail over any conflicting term.
13. Liability
Liability under this DPA is subject to the limitations and exclusions in the End User Terms.
14. Governing law
This DPA is governed by the laws of Estonia, without regard to conflict of law rules, and is subject to the jurisdiction of the Estonian courts.
15. Changes
We may update this DPA to reflect changes in the App or in applicable law. Material changes will be posted here with a revised date and, where the change reduces your protections, notified by email to your Marketplace contact address at least 30 days in advance.