Privacy policy

Privacy policy

1. Scope

This Privacy Policy describes how Purde Software processes personal data in connection with our Confluence apps and our customer-facing services (service desk, email support, public issue trackers).

It supplements Atlassian's Privacy Policy, which applies to your use of Atlassian's platforms; where our processing differs from or adds to Atlassian's, this policy controls.

Where we process personal data on a customer's behalf in our Cloud apps, our Data Processing Agreement (DPA) applies in addition to this policy.

2. Who we are

Whenever we use "we", "us", or "our", we mean:

Purde Software
Max-Friedlaender-Bogen 17
80339 München, Germany
Owner / responsible person: Andreas Purde

2.1 Our role under GDPR

  • For data we collect about visitors to our service desk, email correspondents, and people creating tickets in our public Bitbucket repositories, we act as data controller.

  • For Customer Data processed by our Cloud apps on behalf of a customer's Atlassian instance, we act as data processor, governed by our DPA.

2.2 Contact for privacy matters

For all privacy-related requests (access, rectification, erasure, restriction, objection, portability, withdrawal of consent, complaints), contact us via:

2.3 Data Protection Officer

Given the nature, scope, and purposes of our processing, we are not required to appoint a Data Protection Officer under Art. 37 GDPR or §38 BDSG. Andreas Purde is the responsible person for privacy matters and can be reached via the channels above.

3. Why we collect data and the legal bases we rely on

We collect personal data only to the extent necessary to provide, secure, and support our apps and services, and to comply with legal obligations. For each processing activity in §4 we identify the legal basis under Art. 6(1) GDPR:

  • (b) Performance of a contract — for installing, operating, and supporting our apps under the EULA.

  • (c) Legal obligation — for tax, accounting, and statutory record-keeping.

  • (f) Legitimate interests — for security logging, troubleshooting, fraud prevention, and product improvement, balanced against the interests and rights of data subjects.

  • (a) Consent — only where explicitly opted in (e.g., AI-assisted answers; public Bitbucket bug reports).

4. The data we process in our Confluence apps

Affected apps

Use case

Data collected

Purpose

Legal basis (Art. 6(1) GDPR)

Retention period

Subprocessors involved

Affected apps

Use case

Data collected

Purpose

Legal basis (Art. 6(1) GDPR)

Retention period

Subprocessors involved

All

Creating a ticket in our service portal

Name, email address, descriptions, attachments, and any other data you provide

Process and resolve your support case

(b) contract; (f) legitimate interest in providing support

12 months after the ticket is closed (to enable re-opening if the issue recurs)

Atlassian

All

Contacting us via email

Name, email address, descriptions, attachments, and any other data you provide

Process and resolve your support case

(b) contract; (f) legitimate interest

12 months after the issue has been resolved

Google (Gmail)

All

Creating a ticket directly in the Bitbucket repository

Name, email address, descriptions, attachments, and any other data you provide. Note: this data is publicly visible. Use the service portal if you prefer a private channel.

Track public bug reports and feature requests for the benefit of all users

(a) consent (you choose to post publicly); (f) legitimate interest in transparent issue tracking

Retained for as long as the repository exists, given the public-record nature of the report

Atlassian

All

Usage of apps (CDN access)

Your IP address as visible to the CDN when downloading static assets

Efficient and reliable content delivery

(f) legitimate interest

Subject to subprocessor's policy

Cloudflare (CDNJS), jsDelivr, Google

All Connect-based Cloud apps

Installation of Cloud apps

Connection metadata (AddOnKey, ProductType, ClientKey, BaseUrl, ServiceEntitlementNumber, SharedSecret, OauthClientId)

Connect our apps to your Atlassian instance — required for the apps to function

(b) contract

Deleted at the latest 12 months after termination of the service

Heroku, AWS, Betterstack

All Cloud apps

Usage of Cloud apps (request logs)

Request URL (which contains IP address, BaseUrl, user name, page ID, etc.)

Investigate and resolve operational issues

(f) legitimate interest in operating, securing, and supporting the service

Logs are kept for 30 calendar days and automatically deleted

Betterstack, AWS

Simple Cite Server (prior to v1.15.0)

Rendering BibTeX citations

Logs containing IP address, BibTeX entry, requested format

Diagnose service issues

(f) legitimate interest

Logs kept for 7 calendar days and automatically deleted

Betterstack

Smart Q&A Cloud, Tree View Cloud

Access to email addresses

We do not store email addresses. We only access them when sending notifications.

Deliver notifications you have configured

(b) contract

N/A

None

Smart Q&A Cloud

Slack integration access tokens

OAuth tokens and Slack workspace identifiers

Send notifications and welcome messages required by the Slack integration

(b) contract — required to provide the Slack integration the customer has explicitly enabled

Stored for as long as the Slack integration remains active. Tokens are revoked and deleted within 30 days of the integration being uninstalled, the app being uninstalled from the workspace, or the customer requesting deletion — whichever occurs first.

AWS

Smart Q&A Cloud

Providing answers (rich-text editor)

Your IP address as visible to Tiny

Operate the rich-text editor used for answer composition

(b) contract

Subject to Tiny's policy

Tiny Technologies Inc.

Smart Q&A Cloud

AI-assisted answer support (opt-in)

Question title and question body submitted by the user

Generate suggested answers via the configured LLM provider

(a) consent — opt-in by an admin

Subject to the LLM provider's policy

OpenAI

4.1 Slack integration — additional details

The Slack integration in Smart Questions and Answers for Confluence Cloud does not collect or store any data beyond what is listed below.

Topic

Logging data

Connection data

Topic

Logging data

Connection data

Storage location

AWS (Frankfurt)

Stored as a content property inside Confluence — fully under the customer's control; we do not hold this data

Retention

Logs kept for 7 days, then automatically deleted

Retained as long as the notification channel exists

Removal

Automatic after 7 days

When the customer deletes the notification channel

5. Cookies on our websites

Our Confluence-hosted documentation and service desk are operated by Atlassian and use cookies under Atlassian's cookie policy. We do not set additional tracking cookies of our own and do not use website analytics, advertising, or marketing trackers.

6. Children

Our apps are intended for use in business contexts and are not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

7. Automated decision-making and profiling

We do not engage in automated decision-making producing legal or similarly significant effects on data subjects within the meaning of Art. 22 GDPR. The optional AI features (currently OpenAI-powered answer suggestions in Smart Questions and Answers) generate suggested content for human review and do not autonomously make decisions about data subjects.

8. Subprocessors

Last updated: YYYY-MM-DD. We engage the following subprocessors to provide our services. We give customers at least 30 days' advance notice before adding or replacing a subprocessor that processes Customer Data; customers may object on reasonable data-protection grounds, and the parties will then discuss alternatives in good faith.

Subprocessor

Purpose

Data categories

Processing location

Transfer mechanism (if applicable)

Privacy/security info

Subprocessor

Purpose

Data categories

Processing location

Transfer mechanism (if applicable)

Privacy/security info

Atlassian

Hosting of service desk, repositories, and Marketplace; identity for Cloud app installation

Support correspondence, license data, app installation metadata

EU and US

EU SCCs / EU–US DPF

Atlassian Privacy Policy

Amazon Web Services (AWS)

Cloud app hosting

Installation metadata, request logs

EU (Frankfurt; Ireland)

None required (EU-only processing)

AWS Security

Heroku (Salesforce)

Cloud app hosting (legacy; being migrated to Atlassian Forge between end of 2025 and mid 2026, after which most data will be processed within Atlassian's cloud infrastructure)

Installation metadata, request logs

EU (Ireland)

None required (EU-only processing)

Heroku Security

Betterstack (Logtail)

Application logging

Request logs (IP address, URL, app metadata)

US

EU SCCs

Betterstack Privacy

Google (Gmail)

Email correspondence

Email content from customers contacting us by email

US

EU–US DPF

Google Privacy

Cloudflare (CDNJS)

Static asset delivery

Visitor IP address

Global CDN

EU SCCs

Cloudflare Privacy

jsDelivr

Static asset delivery

Visitor IP address

Global CDN

EU SCCs

jsDelivr Privacy

Tiny Technologies Inc.

Rich-text editor for answer composition (Smart Q&A)

Visitor IP address

US

EU SCCs / EU–US DPF

Tiny Privacy

OpenAI

AI-assisted answer suggestions (opt-in)

Question title and body submitted by the user

US

EU SCCs

OpenAI Privacy

We do not give your data to anyone outside the subprocessors listed above.

9. International data transfers

Primary processing location. Customer Data processed by our Cloud apps is hosted within the European Economic Area, primarily in:

  • AWS (eu-central-1, Frankfurt; eu-west-1, Ireland)

  • Heroku (EU region, Ireland) — being migrated to Atlassian Forge between end of 2025 and mid 2026.

Transfers outside the EEA. Some subprocessors listed in §8 are located in or transfer data to third countries, primarily the United States. For each such transfer we rely on one of the following safeguards under Chapter V GDPR:

  • Adequacy decision under Art. 45 GDPR, including the EU–US Data Privacy Framework where the recipient is certified;

  • Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) under Art. 46(2)(c) GDPR, supplemented by transfer impact assessments and additional technical/organizational measures where required by Schrems II.

Documentation. Customers may request the relevant transfer documentation (SCCs, DPF certifications, transfer impact assessments) by contacting us via the channels in §2.2.

10. Personal data breach notification

If we become aware of a personal data breach affecting Customer Data that we process on a customer's behalf, we will notify the affected customer without undue delay and in any event within 72 hours of becoming aware. The notification will include, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate adverse effects (Art. 33(3) GDPR).

11. Your rights

You have the following rights regarding your personal data:

  • Access — obtain confirmation whether we process personal data about you and a copy of that data (Art. 15 GDPR).

  • Rectification — have inaccurate data corrected and incomplete data completed (Art. 16 GDPR).

  • Erasure — have your data deleted, subject to the limits in Art. 17(3) GDPR (we may need to retain certain records to comply with legal obligations or to defend legal claims, and we cannot remove information required to continue providing a service you have actively requested) (Art. 17 GDPR).

  • Restriction — restrict our processing in defined circumstances (Art. 18 GDPR).

  • Objection — object to processing based on legitimate interests (Art. 21 GDPR).

  • Data portability — receive your data in a structured, commonly used, machine-readable format and transmit it to another controller (Art. 20 GDPR).

  • Withdrawal of consent — withdraw consent for any processing based on consent (Art. 6(1)(a) GDPR), without affecting the lawfulness of processing carried out before withdrawal.

Submitting a request

Use the channels in §2.2. We aim to acknowledge requests within 5 business days and to complete them within 30 calendar days, extendable by a further two months for complex or numerous requests (Art. 12(3) GDPR), in which case we will inform you of the extension and the reasons.

12. Data Processing Agreement (DPA)

If you require a DPA for one of our Cloud apps, you may use our template or send us yours for review.

13. How to raise a complaint

If you have a concern about how we handle your personal data, please contact us first via the channels in §2.2 — we aim to acknowledge complaints within 5 business days and resolve them within 30 calendar days.

You also have the right to lodge a complaint with a data-protection supervisory authority. The competent authority for our establishment is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
https://www.lda.bayern.de

Data subjects in other EU/EEA member states may alternatively lodge a complaint with their local supervisory authority or with the authority of their habitual residence or place of work.

14. Notice and changes to this policy

  • At installation. Atlassian's consent dialog clearly lists the data scopes we request when you install or grant permissions to our apps.

  • In-app documentation. We link to this Privacy Policy from each app's documentation.

  • Material changes. If we make material changes to how we collect or process personal data, we will post a prominent notice in the service portal and, where feasible, notify active administrators by email at least 30 days before the change takes effect.

15. Version history

Version

Date

Changes

Version

Date

Changes

1.0

prior to May 9, 2026

Earlier versions.

2.0

May 9, 2026

Restructured to align with Art. 13 GDPR. Added controller/processor dual-role statement, DPO statement, and dedicated privacy contact. Added legal-basis column to processing-activities table. Corrected Slack integration access-token retention (was "Unlimited"; now bounded to integration lifecycle plus 30 days). Replaced free-text subprocessor list with dated Subprocessor Register and 30-day change-notification commitment. Added 72-hour breach-notification commitment. Added withdrawal-of-consent right. Added sections on cookies, children, and automated decision-making. Named BayLDA as competent supervisory authority. Consolidated previously duplicated rights/notice sections.