Data Processing Agreement
Effective: 18 April 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the entity installing Compliance Glossary for Confluence ("Customer," "you," "Controller") and DailyMind LTD, a company registered in Cyprus ("Processor," "we," "us"), pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
By installing the App from the Atlassian Marketplace, you accept this DPA.
Scope of this DPA
This DPA covers only the Confluence App ("App data") — data processed by the Compliance Glossary for Confluence Forge application running inside your Atlassian instance (glossary terms, version history, scan findings, Atlassian account IDs in audit trails, and related metadata). It does not cover the separate marketing website (compliance-glossary.teamkit.dev), which has its own processors (currently Resend for template downloads and Anthropic for the in-page chat assistant). Marketing-website processing is disclosed in the Privacy Policy and is outside the scope of the controller-processor relationship established by this DPA.
1. Definitions
- "App" means Compliance Glossary for Confluence, a Forge-based application running on Atlassian's infrastructure.
- "Personal Data" means Atlassian account IDs stored by the App as part of regulatory audit trails.
- "Processing" means any operation performed on Personal Data, including storage, retrieval, and erasure.
- "Sub-processor" means a third party engaged by the Processor to process Personal Data on behalf of the Controller.
2. Scope and Purpose of Processing
The App processes Personal Data solely for the following purposes:
- Recording which user created, edited, submitted, approved, or deprecated each glossary term (audit trail)
- Recording which user resolved compliance scanner findings
- Maintaining role-based access control (administrator list)
- Reporting stored account IDs to the Atlassian platform for personal data lifecycle management
2.1 Categories of Personal Data
| Data Category | Examples | Retention |
|---|---|---|
| Atlassian account IDs | Account identifiers (e.g., 5a1234bc5678de9f01234567) | Duration of installation |
| Timestamps | ISO 8601 dates of user actions (stored as attributes of account ID records; not personal data in isolation) | Duration of installation |
The App does not store user names, email addresses, profile data, or Confluence page content. Display names are fetched on-demand from the Confluence API and are not persisted.
2.2 Categories of Data Subjects
Users of the Customer's Atlassian Confluence instance who interact with the App (create terms, approve terms, resolve findings, manage settings).
3. Processor Obligations
- Lawful processing — We process Personal Data only on your documented instructions (i.e., your use of the App's features) and as described in this DPA.
- Confidentiality — Personnel with potential access to Personal Data are bound by confidentiality obligations.
- Security measures — We implement appropriate technical measures as described in our Security Policy. The current Marketplace release runs within the Atlassian Forge sandbox with no DailyMind-operated external app infrastructure. Planned AI-assisted curation is not enabled in that release and has separate pre-release data-flow and disclosure conditions.
- Sub-processors — We will not engage additional sub-processors without prior notification (see Section 5).
- Assistance — We will assist you in fulfilling data subject requests and GDPR obligations to the extent technically feasible within the Forge platform.
- Deletion — Upon uninstall, all per-installation data is removed per Atlassian’s published Forge data lifecycle and Standard Data Retention and Disposal policy (see Atlassian Forge data lifecycle). We do not retain copies.
- Audit — We will make available information necessary to demonstrate compliance with this DPA upon reasonable request, no more than once per year, via written questionnaire.
4. Data Security
The App's architecture provides the following protections:
- Current Marketplace release: no external app servers — App data storage and processing occurs within Atlassian's Forge platform. DailyMind does not operate servers, databases, or cloud services for that release. Planned AI-assisted curation is not enabled in it.
- Data isolation — Each Atlassian installation has its own isolated data partition. No installation can access another's data.
- Encryption — Data is encrypted at rest and in transit by Atlassian's infrastructure.
- No data export — The App does not transmit data outside the Atlassian platform. CSV exports are generated in-browser and delivered directly to the requesting user.
- No credential storage — The App uses Forge platform authentication exclusively. No passwords, tokens, or secrets are stored.
5. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Atlassian Pty Ltd | Hosting (Forge runtime, Entity Store, event triggers) | Per Atlassian's data residency settings |
For the App (the subject of this DPA), Atlassian is the sole sub-processor. All App data resides within Atlassian's infrastructure, governed by Atlassian's own DPA between Atlassian and the Customer. The App itself does not transmit data to any other third party.
Note on the marketing website: the separate marketing website (compliance-glossary.teamkit.dev) uses additional processors: Cloudflare, Inc. (USA) for site hosting and CDN; Resend, Inc. (USA) for template-download email delivery; and Anthropic PBC (USA) for the in-page chat assistant. Those processors are outside the scope of this DPA and are fully disclosed in the Privacy Policy. They do not process App data (Atlassian Forge Entity Store data).
We will notify Customers of new sub-processors for the App by updating this page and, where technically feasible, by notification through the Atlassian Marketplace, at least 30 days before engagement. Customers who object to a new sub-processor may contact privacy@teamkit.dev within 30 days. If the objection cannot be resolved, the Customer may terminate the agreement by uninstalling the App. For paid customers, termination under this clause includes a pro-rata refund of any prepaid fees, in line with the exit-rights principle of DORA Art. 30(3) (termination without undue cost or disruption).
6. Data Subject Rights
The App supports the following data subject rights:
- Right to erasure — When Atlassian signals that a user account has been closed, the App automatically anonymizes all references to that account ID. Records are replaced with a "Deleted user" marker, preserving audit trail integrity without personal data.
- Right of access — Site administrators can view all stored data through the App's interface and export it via the Audit Export feature (CSV).
- Personal data reporting — The App reports all stored account IDs to the Atlassian platform weekly, enabling Atlassian's data lifecycle management.
7. International Data Transfers
The App does not independently transfer Personal Data outside the EEA. Data residency is governed by Atlassian's platform and the Customer's Atlassian configuration. For Atlassian's transfer mechanisms, see Atlassian's Data Transfer Impact Assessment.
8. Data Breach Notification
In the event of a Personal Data breach affecting the App, we will:
- Notify the affected Customer without undue delay and, where feasible, within 72 hours of becoming aware of the breach
- Provide a description of the nature of the breach, categories of data affected, and remediation measures taken
- Cooperate with the Customer to fulfil their notification obligations under GDPR Art. 33 and Art. 34
For breaches originating in the Atlassian platform itself, Atlassian's incident response and notification processes apply.
9. Term and Termination
This DPA is effective from the date you install the App and terminates when the App is uninstalled. Upon termination, all Personal Data is removed per Atlassian’s published Forge data lifecycle and Standard Data Retention and Disposal policy (see Atlassian Forge data lifecycle). We do not retain copies of Customer data.
10. Limitation of Liability
DailyMind's liability under this DPA is subject to the limitations set forth in the Terms of Service, except that liability for GDPR obligations cannot be limited to the extent prohibited by applicable law (GDPR Art. 82–83).
11. Contact
For DPA-related inquiries: privacy@teamkit.dev
DailyMind LTD
Limassol, Cyprus
VAT: CY10439959M