Privacy policy
- 1 1. Scope
- 2 2. Who we are
- 3 3. Why we collect data and the legal bases we rely on
- 4 4. The data we process in our Confluence apps
- 5 5. Cookies on our websites
- 6 6. Children
- 7 7. Automated decision-making and profiling
- 8 8. Subprocessors
- 9 9. International data transfers
- 10 10. Personal data breach notification
- 11 11. Your rights
- 11.1 Submitting a request
- 12 12. Data Processing Agreement (DPA)
- 13 13. How to raise a complaint
- 14 14. Notice and changes to this policy
- 15 15. Version history
1. Scope
This Privacy Policy describes how Purde Software processes personal data in connection with our Confluence apps and our customer-facing services (service desk, email support, public issue trackers).
It supplements Atlassian's Privacy Policy, which applies to your use of Atlassian's platforms; where our processing differs from or adds to Atlassian's, this policy controls.
Where we process personal data on a customer's behalf in our Cloud apps, our Data Processing Agreement (DPA) applies in addition to this policy.
2. Who we are
Whenever we use "we", "us", or "our", we mean:
Purde Software
Max-Friedlaender-Bogen 17
80339 München, Germany
Owner / responsible person: Andreas Purde
2.1 Our role under GDPR
For data we collect about visitors to our service desk, email correspondents, and people creating tickets in our public Bitbucket repositories, we act as data controller.
For Customer Data processed by our Cloud apps on behalf of a customer's Atlassian instance, we act as data processor, governed by our DPA.
2.2 Contact for privacy matters
For all privacy-related requests (access, rectification, erasure, restriction, objection, portability, withdrawal of consent, complaints), contact us via:
Service Desk (preferred): https://purde-software.atlassian.net/servicedesk/customer/portal/2
Email: support@purde.de
Postal: Purde Software, Max-Friedlaender-Bogen 17, 80339 München, Germany
2.3 Data Protection Officer
Given the nature, scope, and purposes of our processing, we are not required to appoint a Data Protection Officer under Art. 37 GDPR or §38 BDSG. Andreas Purde is the responsible person for privacy matters and can be reached via the channels above.
3. Why we collect data and the legal bases we rely on
We collect personal data only to the extent necessary to provide, secure, and support our apps and services, and to comply with legal obligations. For each processing activity in §4 we identify the legal basis under Art. 6(1) GDPR:
(b) Performance of a contract — for installing, operating, and supporting our apps under the EULA.
(c) Legal obligation — for tax, accounting, and statutory record-keeping.
(f) Legitimate interests — for security logging, troubleshooting, fraud prevention, and product improvement, balanced against the interests and rights of data subjects.
(a) Consent — only where explicitly opted in (e.g., AI-assisted answers; public Bitbucket bug reports).
4. The data we process in our Confluence apps
Affected apps | Use case | Data collected | Purpose | Legal basis (Art. 6(1) GDPR) | Retention period | Subprocessors involved |
|---|---|---|---|---|---|---|
All | Creating a ticket in our service portal | Name, email address, descriptions, attachments, and any other data you provide | Process and resolve your support case | (b) contract; (f) legitimate interest in providing support | 12 months after the ticket is closed (to enable re-opening if the issue recurs) | Atlassian |
All | Contacting us via email | Name, email address, descriptions, attachments, and any other data you provide | Process and resolve your support case | (b) contract; (f) legitimate interest | 12 months after the issue has been resolved | Google (Gmail) |
All | Creating a ticket directly in the Bitbucket repository | Name, email address, descriptions, attachments, and any other data you provide. Note: this data is publicly visible. Use the service portal if you prefer a private channel. | Track public bug reports and feature requests for the benefit of all users | (a) consent (you choose to post publicly); (f) legitimate interest in transparent issue tracking | Retained for as long as the repository exists, given the public-record nature of the report | Atlassian |
All | Usage of apps (CDN access) | Your IP address as visible to the CDN when downloading static assets | Efficient and reliable content delivery | (f) legitimate interest | Subject to subprocessor's policy | Cloudflare (CDNJS), jsDelivr, Google |
All Connect-based Cloud apps | Installation of Cloud apps | Connection metadata (AddOnKey, ProductType, ClientKey, BaseUrl, ServiceEntitlementNumber, SharedSecret, OauthClientId) | Connect our apps to your Atlassian instance — required for the apps to function | (b) contract | Deleted at the latest 12 months after termination of the service | Heroku, AWS, Betterstack |
All Cloud apps | Usage of Cloud apps (request logs) | Request URL (which contains IP address, BaseUrl, user name, page ID, etc.) | Investigate and resolve operational issues | (f) legitimate interest in operating, securing, and supporting the service | Logs are kept for 30 calendar days and automatically deleted | Betterstack, AWS |
Simple Cite Server (prior to v1.15.0) | Rendering BibTeX citations | Logs containing IP address, BibTeX entry, requested format | Diagnose service issues | (f) legitimate interest | Logs kept for 7 calendar days and automatically deleted | Betterstack |
Smart Q&A Cloud, Tree View Cloud | Access to email addresses | We do not store email addresses. We only access them when sending notifications. | Deliver notifications you have configured | (b) contract | N/A | None |
Smart Q&A Cloud | Slack integration access tokens | OAuth tokens and Slack workspace identifiers | Send notifications and welcome messages required by the Slack integration | (b) contract — required to provide the Slack integration the customer has explicitly enabled | Stored for as long as the Slack integration remains active. Tokens are revoked and deleted within 30 days of the integration being uninstalled, the app being uninstalled from the workspace, or the customer requesting deletion — whichever occurs first. | AWS |
Smart Q&A Cloud | Providing answers (rich-text editor) | Your IP address as visible to Tiny | Operate the rich-text editor used for answer composition | (b) contract | Subject to Tiny's policy | Tiny Technologies Inc. |
Smart Q&A Cloud | AI-assisted answer support (opt-in) | Question title and question body submitted by the user | Generate suggested answers via the configured LLM provider | (a) consent — opt-in by an admin | Subject to the LLM provider's policy | OpenAI |
4.1 Slack integration — additional details
The Slack integration in Smart Questions and Answers for Confluence Cloud does not collect or store any data beyond what is listed below.
Topic | Logging data | Connection data |
|---|---|---|
Storage location | AWS (Frankfurt) | Stored as a content property inside Confluence — fully under the customer's control; we do not hold this data |
Retention | Logs kept for 7 days, then automatically deleted | Retained as long as the notification channel exists |
Removal | Automatic after 7 days | When the customer deletes the notification channel |
5. Cookies on our websites
Our Confluence-hosted documentation and service desk are operated by Atlassian and use cookies under Atlassian's cookie policy. We do not set additional tracking cookies of our own and do not use website analytics, advertising, or marketing trackers.
6. Children
Our apps are intended for use in business contexts and are not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
7. Automated decision-making and profiling
We do not engage in automated decision-making producing legal or similarly significant effects on data subjects within the meaning of Art. 22 GDPR. The optional AI features (currently OpenAI-powered answer suggestions in Smart Questions and Answers) generate suggested content for human review and do not autonomously make decisions about data subjects.
8. Subprocessors
Last updated: YYYY-MM-DD. We engage the following subprocessors to provide our services. We give customers at least 30 days' advance notice before adding or replacing a subprocessor that processes Customer Data; customers may object on reasonable data-protection grounds, and the parties will then discuss alternatives in good faith.
Subprocessor | Purpose | Data categories | Processing location | Transfer mechanism (if applicable) | Privacy/security info |
|---|---|---|---|---|---|
Atlassian | Hosting of service desk, repositories, and Marketplace; identity for Cloud app installation | Support correspondence, license data, app installation metadata | EU and US | EU SCCs / EU–US DPF | |
Amazon Web Services (AWS) | Cloud app hosting | Installation metadata, request logs | EU (Frankfurt; Ireland) | None required (EU-only processing) | |
Heroku (Salesforce) | Cloud app hosting (legacy; being migrated to Atlassian Forge between end of 2025 and mid 2026, after which most data will be processed within Atlassian's cloud infrastructure) | Installation metadata, request logs | EU (Ireland) | None required (EU-only processing) | |
Betterstack (Logtail) | Application logging | Request logs (IP address, URL, app metadata) | US | EU SCCs | |
Google (Gmail) | Email correspondence | Email content from customers contacting us by email | US | EU–US DPF | |
Cloudflare (CDNJS) | Static asset delivery | Visitor IP address | Global CDN | EU SCCs | |
jsDelivr | Static asset delivery | Visitor IP address | Global CDN | EU SCCs | |
Tiny Technologies Inc. | Rich-text editor for answer composition (Smart Q&A) | Visitor IP address | US | EU SCCs / EU–US DPF | |
OpenAI | AI-assisted answer suggestions (opt-in) | Question title and body submitted by the user | US | EU SCCs |
We do not give your data to anyone outside the subprocessors listed above.
9. International data transfers
Primary processing location. Customer Data processed by our Cloud apps is hosted within the European Economic Area, primarily in:
AWS (eu-central-1, Frankfurt; eu-west-1, Ireland)
Heroku (EU region, Ireland) — being migrated to Atlassian Forge between end of 2025 and mid 2026.
Transfers outside the EEA. Some subprocessors listed in §8 are located in or transfer data to third countries, primarily the United States. For each such transfer we rely on one of the following safeguards under Chapter V GDPR:
Adequacy decision under Art. 45 GDPR, including the EU–US Data Privacy Framework where the recipient is certified;
Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) under Art. 46(2)(c) GDPR, supplemented by transfer impact assessments and additional technical/organizational measures where required by Schrems II.
Documentation. Customers may request the relevant transfer documentation (SCCs, DPF certifications, transfer impact assessments) by contacting us via the channels in §2.2.
10. Personal data breach notification
If we become aware of a personal data breach affecting Customer Data that we process on a customer's behalf, we will notify the affected customer without undue delay and in any event within 72 hours of becoming aware. The notification will include, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate adverse effects (Art. 33(3) GDPR).
11. Your rights
You have the following rights regarding your personal data:
Access — obtain confirmation whether we process personal data about you and a copy of that data (Art. 15 GDPR).
Rectification — have inaccurate data corrected and incomplete data completed (Art. 16 GDPR).
Erasure — have your data deleted, subject to the limits in Art. 17(3) GDPR (we may need to retain certain records to comply with legal obligations or to defend legal claims, and we cannot remove information required to continue providing a service you have actively requested) (Art. 17 GDPR).
Restriction — restrict our processing in defined circumstances (Art. 18 GDPR).
Objection — object to processing based on legitimate interests (Art. 21 GDPR).
Data portability — receive your data in a structured, commonly used, machine-readable format and transmit it to another controller (Art. 20 GDPR).
Withdrawal of consent — withdraw consent for any processing based on consent (Art. 6(1)(a) GDPR), without affecting the lawfulness of processing carried out before withdrawal.
Submitting a request
Use the channels in §2.2. We aim to acknowledge requests within 5 business days and to complete them within 30 calendar days, extendable by a further two months for complex or numerous requests (Art. 12(3) GDPR), in which case we will inform you of the extension and the reasons.
12. Data Processing Agreement (DPA)
If you require a DPA for one of our Cloud apps, you may use our template or send us yours for review.
13. How to raise a complaint
If you have a concern about how we handle your personal data, please contact us first via the channels in §2.2 — we aim to acknowledge complaints within 5 business days and resolve them within 30 calendar days.
You also have the right to lodge a complaint with a data-protection supervisory authority. The competent authority for our establishment is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
https://www.lda.bayern.de
Data subjects in other EU/EEA member states may alternatively lodge a complaint with their local supervisory authority or with the authority of their habitual residence or place of work.
14. Notice and changes to this policy
At installation. Atlassian's consent dialog clearly lists the data scopes we request when you install or grant permissions to our apps.
In-app documentation. We link to this Privacy Policy from each app's documentation.
Material changes. If we make material changes to how we collect or process personal data, we will post a prominent notice in the service portal and, where feasible, notify active administrators by email at least 30 days before the change takes effect.
15. Version history
Version | Date | Changes |
|---|---|---|
1.0 | prior to May 9, 2026 | Earlier versions. |
2.0 | May 9, 2026 | Restructured to align with Art. 13 GDPR. Added controller/processor dual-role statement, DPO statement, and dedicated privacy contact. Added legal-basis column to processing-activities table. Corrected Slack integration access-token retention (was "Unlimited"; now bounded to integration lifecycle plus 30 days). Replaced free-text subprocessor list with dated Subprocessor Register and 30-day change-notification commitment. Added 72-hour breach-notification commitment. Added withdrawal-of-consent right. Added sections on cookies, children, and automated decision-making. Named BayLDA as competent supervisory authority. Consolidated previously duplicated rights/notice sections. |