# Privacy and data handling

**Draft. This notice takes effect when SignPlus is published on the Atlassian Marketplace.**

## 1. Scope

1.1 This notice describes the processing of personal data by SignPlus for Confluence (the
“Application”). It forms part of the [application licence](/legal/app-terms/) and is read with
the [data processing addendum](/legal/dpa/) (the “Addendum”). Terms defined in the licence have
the same meaning here.

1.2 It does not cover oktul.com or the personal data Oktul processes as a company, which are
described in Oktul’s [privacy policy](/legal/privacy/).

1.3 The Application sends data outside the Atlassian platform. A signature is made by the signer
on the signing service of Dokobit, a qualified trust service provider, to which the Application
sends the document being signed and each signer’s name and email address. Every destination is
listed in clause 5.

## 2. Roles and contact

2.1 For Customer Data processed by the Application, the customer is the controller and Oktul
OÜ is the processor within the meaning of Regulation (EU) 2016/679 (the “GDPR”). Oktul
processes it only to provide the Application, on the customer’s documented instructions, as
set out in the Addendum.

2.2 Oktul, and not Atlassian, is responsible for the privacy, security and integrity of the
personal data the Application processes.

2.3 Dokobit’s role depends on the [signing mode](../configure/#signing-mode):

- **Your own token:** signings run on the customer’s own Dokobit account, under the customer’s
  own agreement with Dokobit. Dokobit is not Oktul’s sub-processor. This is the only mode that
  produces a legally binding signature.
- **Test:** signings run on Oktul’s account in Dokobit’s test environment, under Oktul’s own
  contract with Dokobit, and Dokobit is Oktul’s sub-processor. The documents are watermarked
  and have no legal effect. Oktul has no access to the documents or the signing details on that
  account and sees only the number of signings. Test mode is for trying the Application, and
  the customer should not use it for confidential pages.

2.4 In Test mode, Dokobit notifies Oktul of each completed signing by
email, to Oktul’s mailbox hosted by Zoho Corporation Pvt. Ltd. The notice carries the document
name and each signer’s name and email address, and Zoho is Oktul’s sub-processor for it. A
mailbox rule deletes each notice on arrival, unread. No notice is kept.

2.5 Atlassian Pty Ltd hosts the Application on the Forge platform on Oktul’s behalf and is
Oktul’s sub-processor for that hosting, under the Forge Data Processing Addendum and the
standard contractual clauses it incorporates.

2.6 For the licence record Atlassian provides when the Application is installed or ordered,
and for support correspondence, Oktul is the controller. Oktul’s privacy policy governs that
processing.

2.7 Contact details:

- **Processor:** Oktul OÜ, registry code 17589681, Seebi tn 1-703, 11316 Tallinn, Harjumaa,
  Estonia
- **Data protection requests and legal notices:** legal@oktul.com
- **Support and vulnerability reports:** the [Oktul Help Center](https://oktul.atlassian.net/servicedesk/customer/portals)
  or support@oktul.com

## 3. Data processed

3.1 The Application stores a record of each signing in Forge storage. The record holds:

- the page’s space id, page id, version number and title, and the SHA-256 hash computed from
  the first three;
- the Dokobit document token and the Dokobit environment the document was sent to;
- the request’s name, format, document digest, deadline and message;
- the name, id and role of each Confluence group the signing was sent to;
- each participant’s name, email address, role, status, signing time and Dokobit token, in a
  record of its own per participant;
- the page restrictions in force before the signing, so they can be restored;
- the times the record was created and last updated.

3.2 A signing started from the page, through the REST API or by an automation flow for a group or
more than 100 people is first stored as a job, which holds the request, its participants included,
until the signing has been sent, and is then reduced to its outcome. A job record is deleted
automatically after 7 days.

3.3 The record does not hold the document. The copy sent to Dokobit is excluded from the
stored record, and the signed document is stored as an attachment on the Confluence page.

3.4 The Application also stores the settings, any uploaded font or logo, and the site’s
activity log in Forge storage, and a Dokobit token entered by the customer in Forge’s
encrypted secret storage. A saved token is not displayed again.

3.5 The Application keeps two logs:

| | Forge logs | The site’s activity log |
|---|---|---|
| Read by | Oktul, to diagnose a fault | The customer’s site administrators, under **Logs** |
| Page and account ids | No | Yes |
| Signer names, email addresses and personal codes | No | No |
| Page content and document content | No | No |
| Tokens | No | No |

A test that reads every logging call in the source fails the build on any identifier written
to the Forge logs.

3.6 The Application reads a page as the person who started the signing, including when the signing
runs in the background, using Forge’s offline user impersonation, so that the document contains
what that person may see and nothing else. A signing started through the REST API reads the page
as the service account that made the request. A signing or export started by an automation flow
reads it as the Application.

3.7 The Application carries out no automated decision-making or profiling within the meaning of
Article 22 of the GDPR. A signer decides whether to sign.

## 4. Where the data is stored

4.1 Data the Application stores in the customer’s site is stored on the Atlassian platform:

| Data | Where it is stored |
|---|---|
| Signing records, settings, font, logo and activity log | Forge storage |
| A Dokobit token | Forge encrypted secret storage |
| Signed documents and exported PDFs | Attachments on the Confluence page |
| The document during and after signing | Dokobit, for the period in clause 7.4 |

4.2 The location of data on the Atlassian platform is determined by Atlassian. Where the
customer has configured data residency for Confluence, Atlassian stores the Application’s Forge
storage in the same location as the customer’s Confluence data.

4.3 Dokobit states in its [privacy policy](https://www.dokobit.com/compliance/privacy-policy)
that it stores and processes data within the EU/EEA and does not transfer customer data outside
it, and on its [compliance page](https://www.dokobit.com/compliance) that data is encrypted with
TLS and AES-256 and that its information security is certified to ISO/IEC 27001 and ISO/IEC 27018.
Its [data processing agreement](https://www.dokobit.com/compliance/dpa) and
[list of sub-processors](https://www.dokobit.com/compliance/list-of-subprocessors) are published
there too.

4.4 Dokobit identifies the provider as Dokobit, UAB (registry code 301549834) in its
[terms of service](https://www.dokobit.com/compliance/terms-of-service).

## 5. Recipients and transfers

5.1 The Application sends data to the following destinations and no others. The first five are
declared in its Forge manifest. Adding one requires a new version that each administrator
must approve.

| Destination | Data received | Purpose |
|---|---|---|
| Dokobit, `*.dokobit.com` | The rendered document, with the page’s attachments where the user includes them; each participant’s name and email address; the document name, message and deadline | Creation of the qualified electronic signature |
| The customer’s Confluence site, `*.atlassian.net` | None | Retrieval of emoji images in headings, which Atlassian’s API proxy cannot reach. An image is retrieved only from the site the page belongs to |
| Atlassian’s avatar service, `*.atl-paas.net` | None | Retrieval of profile pictures for display in the document |
| Atlassian’s API gateway, `api.atlassian.com` | The token presented with a REST API request | Validation of the token for the site |
| Atlassian’s image library, hosted by Orange Logic, `dam-cdn.atl.orangelogic.com` | None | Retrieval of the pictures Atlassian’s own page templates use. Only this exact host is reached |
| A webhook address configured by the customer | An edit notice: identifiers and version numbers. A completion notice: the signed document and each signer’s name and signing time, without email addresses or personal codes | Notification of the customer’s own systems. Sent only after the customer’s administrator approves the host in Atlassian’s dialog |

5.2 Jira Assets objects, and the Jira work items selected in an Oktul Work Item Selector field, are
read through Atlassian’s API proxy and are not sent outside the Atlassian platform.

5.3 The Application uses no analytics, telemetry, error-reporting service or third-party
script. No Oktul server or database is in the data path.

5.4 Atlassian’s sub-processors are listed at
[atlassian.com/legal/sub-processors](https://www.atlassian.com/legal/sub-processors).

## 6. Permissions

6.1 The Application requests the following scopes, each for the stated purpose:

| Scope | Purpose |
|---|---|
| `read:page:confluence` | Read the page being signed or exported |
| `read:confluence-content.all` | Read the page body to render it |
| `read:confluence-content.summary` | Receive the page-edited event, so a change to a signed page can be reported. Forge requires it by name |
| `write:confluence-content` | Record a signing against the page, and set and lift its restrictions |
| `read:confluence-content.permission` | Check that the user or account making a request may view or edit the page |
| `read:space:confluence` | Identify the page’s space and apply that space’s settings |
| `readonly:content.attachment:confluence` | List the attachments on a page |
| `read:attachment:confluence` | Read an attachment to include it in the document |
| `write:confluence-file` | Attach the signed document or an exported PDF to the page |
| `read:confluence-user` | Display who started a signing and who the participants are |
| `read:email-address:confluence` | Read the email address of a participant the user selects, which Dokobit uses to identify the signer |
| `read:content-details:confluence` | Match a participant named by email address to their Confluence account, by searching users by name and confirming the address |
| `read:confluence-groups` | Offer the groups a user belongs to as signers, and list a group’s members when the signing is sent |
| `search:confluence` | Search a space’s pages by title for the page picker in the automation actions |
| `read:jira-work` | Read the work items selected in an Oktul Work Item Selector field, to draw them in the document. Requires a connected Jira site |
| `read:cmdb-object:jira` | Read the objects behind a Jira Assets table on a page, to include them in the document. Requires a connected Jira site |
| `storage:app` | Store signing records and settings |

6.2 The scopes the Application uses to read a page and its attachments, users, Assets objects and
work items are marked for offline user impersonation, for the reason in clause 3.6. Atlassian does
not allow impersonation for personal-data scopes, so `read:email-address:confluence` is read as the
Application.

## 7. Retention

7.1 A signing record is kept until it is deleted or the Application is uninstalled. No
automatic retention period applies. A running signing can be cancelled by the user who started it
or by a user who can edit the page, which deletes its record. A finished signing’s record can be
deleted by a Confluence administrator, and by the users the customer’s administrator allows in the
Application’s settings. The REST API applies the same rules. Deleting a record also removes the
page’s signing state.

7.2 The activity log keeps the most recent 500 entries. The settings are kept until the
Application is uninstalled.

7.3 Signed documents and exported PDFs are page attachments and are governed by the customer’s
Confluence retention. Uninstalling the Application does not remove them.

7.4 According to Dokobit’s documentation of its signing API, Dokobit keeps a document for the
signing period and no longer than 30 days, whether or not it is signed. Cancelling or deleting
a signing in the Application removes it from Dokobit sooner, for every signer.

7.5 What Atlassian keeps after the Application is uninstalled is stated in clause 8.

## 8. Data portability and switching

SignPlus sends data outside the Atlassian platform to be processed, and stores everything you keep in your own site. Every service that receives data is listed below with what it keeps, including any copy Oktul holds.

| Data | Where it is | How to export it |
|---|---|---|
| Signing records, signed containers and PDFs | The signed page, with the signed container or PDF as a page attachment | The download button SignPlus adds to the page, the attachment itself, or Confluence's space export |
| Settings, and an uploaded font or logo | Forge storage in your site | Cannot be exported. Recreate the settings in the new product |
| The site's activity log | Forge storage in your site, shown to your site administrators under Logs | Cannot be exported. Oktul cannot see it |

**Services outside the Atlassian platform**

| Service | Receives | Keeps | Under whose contract |
|---|---|---|---|
| Dokobit | The document to be signed, and each signer’s name and email address | The document, for the signing period and no longer than 30 days, according to Dokobit. Cancelling or deleting a signing in SignPlus removes it sooner. Oktul cannot access documents on its account | Yours with "Your own token", the only mode that signs for real. Oktul’s with "Test", where Oktul sees only a count of signings |
| Zoho Corporation Pvt. Ltd (Oktul’s mailbox) | Dokobit’s notice of each completed signing on Oktul’s account: the document name and each signer’s name and email address | Nothing. A mailbox rule deletes each notice on arrival, unread | Oktul’s, with "Test" only |
| Your own webhook addresses | The signing events you configure | Decided by you | Yours |

**After uninstallation.** Signed documents stay on the page. According to Atlassian’s documentation, Forge storage is relinked if the app is reinstalled within 21 days, and Atlassian then deletes it under its data retention policy.

Oktul charges no fee for switching to another product or for exporting data. [Clause 11 of the application licence](/legal/app-terms/#switching) sets out the terms.

## 9. Rights of data subjects

9.1 Data subjects have the rights of access, rectification, erasure, restriction of
processing, data portability and objection under Articles 15 to 21 of the GDPR. For Customer
Data, the controller is the customer, and requests are made to the customer, whose users can
delete a signing record and its copy at Dokobit from the signing’s details and remove a signed
document as any attachment.

9.2 For data at Dokobit on an account Oktul holds, Oktul acts on the customer’s instruction
with Dokobit. For data on the customer’s own Dokobit account, the customer’s agreement with
Dokobit governs.

9.3 Oktul assists the customer with such requests free of charge, as clause 7.1 of the
Addendum provides. Requests concerning data for which Oktul is the controller are sent to
legal@oktul.com and answered within one month, extendable by two further months under Article
12(3) of the GDPR.

9.4 A data subject may lodge a complaint with the Estonian Data Protection Inspectorate
(Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, info@aki.ee) or with the supervisory
authority of their habitual residence, place of work or place of the alleged infringement.

## 10. Security

10.1 According to Atlassian’s documentation, Forge provides tenant isolation and encryption in
transit and at rest. Oktul operates no infrastructure in the data path and holds no credential
for the customer’s site. Oktul’s own measures are set out in clause 5 of the Addendum.

10.2 In addition:

- the REST API issues no credentials. A caller presents an Atlassian OAuth token, which is
  validated for the site, and the caller’s own Confluence permissions on the page apply;
- the Application sends nothing to a webhook address until the customer’s administrator
  approves its host in Atlassian’s dialog. The approval can be withdrawn in Atlassian
  Administration;
- a completion is accepted only once the signed document has been downloaded from Dokobit,
  and a decline only once Dokobit confirms it;
- a participant’s email address is never sent to a browser. The REST API returns it only to an
  account that can view the page;
- 1359 automated tests pass on the current build, including suites for authorisation,
  injection and logging.

10.3 Oktul holds no audited security certification. The Application has no Cloud Security
Alliance STAR self-assessment of its own.

## 11. Vulnerability reports and security incidents

11.1 A vulnerability is reported through the Oktul Help Center or to support@oktul.com, where
it receives a reference. Oktul responds within 24 hours, Monday to Friday, and credits the
reporter by name unless asked not to. Oktul does not pay bounties. Research in good faith is
covered by clause 8.5 of the application licence. Security testing of a Forge application is
testing of the Atlassian platform and must comply with Atlassian’s policies.

11.2 Oktul remediates vulnerabilities within the following periods, measured by CVSS score. The
periods under Atlassian’s [Security Bug Fix Policy](https://developer.atlassian.com/platform/marketplace/security-bugfix-policy/)
for cloud apps also apply, and the shorter period governs.

| Severity | Oktul | Atlassian’s requirement |
|---|---|---|
| Critical, CVSS 9.0 or higher | 7 calendar days | 10 days |
| High, CVSS 7.0 to 8.9 | 14 calendar days | 4 weeks |
| Medium, CVSS 4.0 to 6.9 | 28 calendar days | 12 weeks |
| Low, CVSS below 4.0 | 56 calendar days | 25 weeks |

11.3 Oktul notifies the customer of a personal data breach affecting Customer Data without
undue delay and in any event within 24 hours, as clause 7.3 of the Addendum provides.

## 12. Changes to this notice

12.1 A change is recorded in the [release notes](../release-notes/). A change to the data processed,
its recipients or who can access it is stated there, and a new destination is announced before
the version that introduces it. Oktul notifies the technical contacts of installations and
Atlassian of a material change.
