Privacy Policy — Approve & Lock for Confluence
Last updated: 29 July 2026
Provider: DAPDEV Software Solutions OÜ ("we"), a company registered in Estonia (VAT EE102391086), [email protected]
Summary
Approve & Lock runs entirely on Atlassian's Forge platform. It has no servers of its own, sends no data to any third party, and performs no external network requests. Your data never leaves Atlassian's infrastructure.
What the app stores
For each page placed under approval, the app stores in Atlassian-hosted Forge storage:
| Data | Purpose |
|---|---|
| Confluence content ID | identifies the page under approval |
| Approval status and the page version it was bound to | detects edits made after approval |
| Atlassian account IDs of requesters and approvers | records who requested and who decided |
| Decisions, optional comments, timestamps | the audit trail |
| Optional re-review date | expiry reminders |
| Space-level defaults | prefills the approval form |
What the app does not do
- No data is transmitted outside Atlassian. The app declares no external egress and is eligible for Atlassian's Runs on Atlassian programme, which requires exclusive use of Atlassian-hosted compute and storage.
- No analytics, telemetry, tracking, advertising or profiling.
- No third-party processors or sub-processors.
- No page content is stored. The app records *that* a page changed and at which version — never the text of the page.
- No email addresses, names or profile data are stored. Only Atlassian account identifiers, which are resolved for display by Confluence itself.
Data residency
Data is held in Forge storage and follows the data residency of the host Atlassian site.
Retention and deletion
Approval records live for as long as the app is installed. Uninstalling the app removes its Forge storage, deleting all approval records and audit history. To request deletion while installed, contact us at [email protected].
Permissions
The app requests only what it needs:
- read page content details and versions — to detect edits after approval
- write content restrictions — to apply and release the edit lock
- app storage — to hold approval records and the audit log
Your rights
Approval records are your data. Contact [email protected] to access, export or delete them. We respond within one business day.
GDPR
For processing subject to the GDPR or UK GDPR, you are the controller and we are the processor. The terms required by Article 28 are set out in our Data Processing Agreement, which takes effect automatically on installation and needs no signature.
Changes
Material changes to this policy will be reflected here with a revised date.