Privacy and data handling
Draft. This notice takes effect when SignPlus is published on the Atlassian Marketplace.
1. Scope
1.1 This notice describes the processing of personal data by SignPlus for Confluence (the “Application”). It forms part of the application licence and is read with the data processing addendum (the “Addendum”). Terms defined in the licence have the same meaning here.
1.2 It does not cover oktul.com or the personal data Oktul processes as a company, which are described in Oktul’s privacy policy.
1.3 The Application sends data outside the Atlassian platform. A signature is made by the signer on the signing service of Dokobit, a qualified trust service provider, to which the Application sends the document being signed and each signer’s name and email address. Every destination is listed in clause 5.
2. Roles and contact
2.1 For Customer Data processed by the Application, the customer is the controller and Oktul OÜ is the processor within the meaning of Regulation (EU) 2016/679 (the “GDPR”). Oktul processes it only to provide the Application, on the customer’s documented instructions, as set out in the Addendum.
2.2 Oktul, and not Atlassian, is responsible for the privacy, security and integrity of the personal data the Application processes.
2.3 Dokobit’s role depends on the signing mode:
- Your own token: signings run on the customer’s own Dokobit account, under the customer’s own agreement with Dokobit. Dokobit is not Oktul’s sub-processor. This is the only mode that produces a legally binding signature.
- Test: signings run on Oktul’s account in Dokobit’s test environment, under Oktul’s own contract with Dokobit, and Dokobit is Oktul’s sub-processor. The documents are watermarked and have no legal effect. Oktul has no access to the documents or the signing details on that account and sees only the number of signings. Test mode is for trying the Application, and the customer should not use it for confidential pages.
2.4 In Test mode, Dokobit notifies Oktul of each completed signing by email, to Oktul’s mailbox hosted by Zoho Corporation Pvt. Ltd. The notice carries the document name and each signer’s name and email address, and Zoho is Oktul’s sub-processor for it. A mailbox rule deletes each notice on arrival, unread. No notice is kept.
2.5 Atlassian Pty Ltd hosts the Application on the Forge platform on Oktul’s behalf and is Oktul’s sub-processor for that hosting, under the Forge Data Processing Addendum and the standard contractual clauses it incorporates.
2.6 For the licence record Atlassian provides when the Application is installed or ordered, and for support correspondence, Oktul is the controller. Oktul’s privacy policy governs that processing.
2.7 Contact details:
- Processor: Oktul OÜ, registry code 17589681, Seebi tn 1-703, 11316 Tallinn, Harjumaa, Estonia
- Data protection requests and legal notices: legal@oktul.com
- Support and vulnerability reports: the Oktul Help Center or support@oktul.com
3. Data processed
3.1 The Application stores a record of each signing in Forge storage. The record holds:
- the page’s space id, page id, version number and title, and the SHA-256 hash computed from the first three;
- the Dokobit document token and the Dokobit environment the document was sent to;
- the request’s name, format, document digest, deadline and message;
- the name, id and role of each Confluence group the signing was sent to;
- each participant’s name, email address, role, status, signing time and Dokobit token, in a record of its own per participant;
- the page restrictions in force before the signing, so they can be restored;
- the times the record was created and last updated.
3.2 A signing started from the page, through the REST API or by an automation flow for a group or more than 100 people is first stored as a job, which holds the request, its participants included, until the signing has been sent, and is then reduced to its outcome. A job record is deleted automatically after 7 days.
3.3 The record does not hold the document. The copy sent to Dokobit is excluded from the stored record, and the signed document is stored as an attachment on the Confluence page.
3.4 The Application also stores the settings, any uploaded font or logo, and the site’s activity log in Forge storage, and a Dokobit token entered by the customer in Forge’s encrypted secret storage. A saved token is not displayed again.
3.5 The Application keeps two logs:
| Forge logs | The site’s activity log | |
|---|---|---|
| Read by | Oktul, to diagnose a fault | The customer’s site administrators, under Logs |
| Page and account ids | No | Yes |
| Signer names, email addresses and personal codes | No | No |
| Page content and document content | No | No |
| Tokens | No | No |
A test that reads every logging call in the source fails the build on any identifier written to the Forge logs.
3.6 The Application reads a page as the person who started the signing, including when the signing runs in the background, using Forge’s offline user impersonation, so that the document contains what that person may see and nothing else. A signing started through the REST API reads the page as the service account that made the request. A signing or export started by an automation flow reads it as the Application.
3.7 The Application carries out no automated decision-making or profiling within the meaning of Article 22 of the GDPR. A signer decides whether to sign.
4. Where the data is stored
4.1 Data the Application stores in the customer’s site is stored on the Atlassian platform:
| Data | Where it is stored |
|---|---|
| Signing records, settings, font, logo and activity log | Forge storage |
| A Dokobit token | Forge encrypted secret storage |
| Signed documents and exported PDFs | Attachments on the Confluence page |
| The document during and after signing | Dokobit, for the period in clause 7.4 |
4.2 The location of data on the Atlassian platform is determined by Atlassian. Where the customer has configured data residency for Confluence, Atlassian stores the Application’s Forge storage in the same location as the customer’s Confluence data.
4.3 Dokobit states in its privacy policy that it stores and processes data within the EU/EEA and does not transfer customer data outside it, and on its compliance page that data is encrypted with TLS and AES-256 and that its information security is certified to ISO/IEC 27001 and ISO/IEC 27018. Its data processing agreement and list of sub-processors are published there too.
4.4 Dokobit identifies the provider as Dokobit, UAB (registry code 301549834) in its terms of service.
5. Recipients and transfers
5.1 The Application sends data to the following destinations and no others. The first five are declared in its Forge manifest. Adding one requires a new version that each administrator must approve.
| Destination | Data received | Purpose |
|---|---|---|
Dokobit, *.dokobit.com |
The rendered document, with the page’s attachments where the user includes them; each participant’s name and email address; the document name, message and deadline | Creation of the qualified electronic signature |
The customer’s Confluence site, *.atlassian.net |
None | Retrieval of emoji images in headings, which Atlassian’s API proxy cannot reach. An image is retrieved only from the site the page belongs to |
Atlassian’s avatar service, *.atl-paas.net |
None | Retrieval of profile pictures for display in the document |
Atlassian’s API gateway, api.atlassian.com |
The token presented with a REST API request | Validation of the token for the site |
Atlassian’s image library, hosted by Orange Logic, dam-cdn.atl.orangelogic.com |
None | Retrieval of the pictures Atlassian’s own page templates use. Only this exact host is reached |
| A webhook address configured by the customer | An edit notice: identifiers and version numbers. A completion notice: the signed document and each signer’s name and signing time, without email addresses or personal codes | Notification of the customer’s own systems. Sent only after the customer’s administrator approves the host in Atlassian’s dialog |
5.2 Jira Assets objects, and the Jira work items selected in an Oktul Work Item Selector field, are read through Atlassian’s API proxy and are not sent outside the Atlassian platform.
5.3 The Application uses no analytics, telemetry, error-reporting service or third-party script. No Oktul server or database is in the data path.
5.4 Atlassian’s sub-processors are listed at atlassian.com/legal/sub-processors.
6. Permissions
6.1 The Application requests the following scopes, each for the stated purpose:
| Scope | Purpose |
|---|---|
read:page:confluence |
Read the page being signed or exported |
read:confluence-content.all |
Read the page body to render it |
read:confluence-content.summary |
Receive the page-edited event, so a change to a signed page can be reported. Forge requires it by name |
write:confluence-content |
Record a signing against the page, and set and lift its restrictions |
read:confluence-content.permission |
Check that the user or account making a request may view or edit the page |
read:space:confluence |
Identify the page’s space and apply that space’s settings |
readonly:content.attachment:confluence |
List the attachments on a page |
read:attachment:confluence |
Read an attachment to include it in the document |
write:confluence-file |
Attach the signed document or an exported PDF to the page |
read:confluence-user |
Display who started a signing and who the participants are |
read:email-address:confluence |
Read the email address of a participant the user selects, which Dokobit uses to identify the signer |
read:content-details:confluence |
Match a participant named by email address to their Confluence account, by searching users by name and confirming the address |
read:confluence-groups |
Offer the groups a user belongs to as signers, and list a group’s members when the signing is sent |
search:confluence |
Search a space’s pages by title for the page picker in the automation actions |
read:jira-work |
Read the work items selected in an Oktul Work Item Selector field, to draw them in the document. Requires a connected Jira site |
read:cmdb-object:jira |
Read the objects behind a Jira Assets table on a page, to include them in the document. Requires a connected Jira site |
storage:app |
Store signing records and settings |
6.2 The scopes the Application uses to read a page and its attachments, users, Assets objects and
work items are marked for offline user impersonation, for the reason in clause 3.6. Atlassian does
not allow impersonation for personal-data scopes, so read:email-address:confluence is read as the
Application.
7. Retention
7.1 A signing record is kept until it is deleted or the Application is uninstalled. No automatic retention period applies. A running signing can be cancelled by the user who started it or by a user who can edit the page, which deletes its record. A finished signing’s record can be deleted by a Confluence administrator, and by the users the customer’s administrator allows in the Application’s settings. The REST API applies the same rules. Deleting a record also removes the page’s signing state.
7.2 The activity log keeps the most recent 500 entries. The settings are kept until the Application is uninstalled.
7.3 Signed documents and exported PDFs are page attachments and are governed by the customer’s Confluence retention. Uninstalling the Application does not remove them.
7.4 According to Dokobit’s documentation of its signing API, Dokobit keeps a document for the signing period and no longer than 30 days, whether or not it is signed. Cancelling or deleting a signing in the Application removes it from Dokobit sooner, for every signer.
7.5 What Atlassian keeps after the Application is uninstalled is stated in clause 8.
8. Data portability and switching
SignPlus sends data outside the Atlassian platform to be processed, and stores everything you keep in your own site. Every service that receives data is listed below with what it keeps, including any copy Oktul holds.
| Data | Where it is | How to export it |
|---|---|---|
| Signing records, signed containers and PDFs | The signed page, with the signed container or PDF as a page attachment | The download button SignPlus adds to the page, the attachment itself, or Confluence's space export |
| Settings, and an uploaded font or logo | Forge storage in your site | Cannot be exported. Recreate the settings in the new product |
| The site's activity log | Forge storage in your site, shown to your site administrators under Logs | Cannot be exported. Oktul cannot see it |
| Service | Receives | Keeps | Under whose contract |
|---|---|---|---|
| Dokobit | The document to be signed, and each signer’s name and email address | The document, for the signing period and no longer than 30 days, according to Dokobit. Cancelling or deleting a signing in SignPlus removes it sooner. Oktul cannot access documents on its account | Yours with "Your own token", the only mode that signs for real. Oktul’s with "Test", where Oktul sees only a count of signings |
| Zoho Corporation Pvt. Ltd (Oktul’s mailbox) | Dokobit’s notice of each completed signing on Oktul’s account: the document name and each signer’s name and email address | Nothing. A mailbox rule deletes each notice on arrival, unread | Oktul’s, with "Test" only |
| Your own webhook addresses | The signing events you configure | Decided by you | Yours |
After uninstallation. Signed documents stay on the page. According to Atlassian’s documentation, Forge storage is relinked if the app is reinstalled within 21 days, and Atlassian then deletes it under its data retention policy.
Oktul charges no fee for switching to another product or for exporting data. Clause 11 of the application licence sets out the terms.
9. Rights of data subjects
9.1 Data subjects have the rights of access, rectification, erasure, restriction of processing, data portability and objection under Articles 15 to 21 of the GDPR. For Customer Data, the controller is the customer, and requests are made to the customer, whose users can delete a signing record and its copy at Dokobit from the signing’s details and remove a signed document as any attachment.
9.2 For data at Dokobit on an account Oktul holds, Oktul acts on the customer’s instruction with Dokobit. For data on the customer’s own Dokobit account, the customer’s agreement with Dokobit governs.
9.3 Oktul assists the customer with such requests free of charge, as clause 7.1 of the Addendum provides. Requests concerning data for which Oktul is the controller are sent to legal@oktul.com and answered within one month, extendable by two further months under Article 12(3) of the GDPR.
9.4 A data subject may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, info@aki.ee) or with the supervisory authority of their habitual residence, place of work or place of the alleged infringement.
10. Security
10.1 According to Atlassian’s documentation, Forge provides tenant isolation and encryption in transit and at rest. Oktul operates no infrastructure in the data path and holds no credential for the customer’s site. Oktul’s own measures are set out in clause 5 of the Addendum.
10.2 In addition:
- the REST API issues no credentials. A caller presents an Atlassian OAuth token, which is validated for the site, and the caller’s own Confluence permissions on the page apply;
- the Application sends nothing to a webhook address until the customer’s administrator approves its host in Atlassian’s dialog. The approval can be withdrawn in Atlassian Administration;
- a completion is accepted only once the signed document has been downloaded from Dokobit, and a decline only once Dokobit confirms it;
- a participant’s email address is never sent to a browser. The REST API returns it only to an account that can view the page;
- 1359 automated tests pass on the current build, including suites for authorisation, injection and logging.
10.3 Oktul holds no audited security certification. The Application has no Cloud Security Alliance STAR self-assessment of its own.
11. Vulnerability reports and security incidents
11.1 A vulnerability is reported through the Oktul Help Center or to support@oktul.com, where it receives a reference. Oktul responds within 24 hours, Monday to Friday, and credits the reporter by name unless asked not to. Oktul does not pay bounties. Research in good faith is covered by clause 8.5 of the application licence. Security testing of a Forge application is testing of the Atlassian platform and must comply with Atlassian’s policies.
11.2 Oktul remediates vulnerabilities within the following periods, measured by CVSS score. The periods under Atlassian’s Security Bug Fix Policy for cloud apps also apply, and the shorter period governs.
| Severity | Oktul | Atlassian’s requirement |
|---|---|---|
| Critical, CVSS 9.0 or higher | 7 calendar days | 10 days |
| High, CVSS 7.0 to 8.9 | 14 calendar days | 4 weeks |
| Medium, CVSS 4.0 to 6.9 | 28 calendar days | 12 weeks |
| Low, CVSS below 4.0 | 56 calendar days | 25 weeks |
11.3 Oktul notifies the customer of a personal data breach affecting Customer Data without undue delay and in any event within 24 hours, as clause 7.3 of the Addendum provides.
12. Changes to this notice
12.1 A change is recorded in the release notes. A change to the data processed, its recipients or who can access it is stated there, and a new destination is announced before the version that introduces it. Oktul notifies the technical contacts of installations and Atlassian of a material change.