# Privacy and data handling

**Draft. This notice takes effect when Oktul Work Item Macro for Confluence is published on the Atlassian Marketplace.**

**Version 1.0, effective 29.09.2026.**

## 1. Scope

1.1 This notice describes the processing of personal data by Oktul Work Item Macro for Confluence (the
“Application”). It forms part of the [application licence](/legal/app-terms/) and is read with
the [data processing addendum](/legal/dpa/) (the “Addendum”). Terms defined in the licence have
the same meaning here.

1.2 It does not cover oktul.com or the personal data Oktul processes as a company, which are
described in Oktul’s [privacy policy](/legal/privacy/).

## 2. Roles and contact

2.1 For Customer Data processed by the Application, the customer is the controller and Oktul
OÜ is the processor within the meaning of Regulation (EU) 2016/679 (the “GDPR”). Oktul
processes it only to provide the Application, on the customer’s documented instructions, as
set out in the Addendum.

2.2 Oktul, and not Atlassian, is responsible for the privacy, security and integrity of the
personal data the Application processes.

2.3 For the licence record Atlassian provides when the Application is installed or ordered,
and for support correspondence, Oktul is the controller. Oktul’s privacy policy governs that
processing.

2.4 Contact details:

- **Processor:** Oktul OÜ, registry code 17589681, Seebi tn 1-703, 11316 Tallinn, Harjumaa,
  Estonia
- **Data protection requests and legal notices:** legal@oktul.com
- **Support and vulnerability reports:** the [Oktul Help Center](https://oktul.atlassian.net/servicedesk/customer/portals)
  or support@oktul.com

## 3. Data processed

3.1 The Application stores the following in the customer’s Confluence Cloud site:

| Data | Where it is stored | Purpose |
|---|---|---|
| The configuration of each macro: JQL query, results per page, columns with their headings and display options, and the inline editing settings | The macro’s parameters, in the Confluence page that holds it, stored by Confluence | Configuration |

3.2 The Application has no Forge storage and keeps nothing else. It does not cache.

3.3 When a page is viewed, the Application reads work items, Assets objects and Jira fields
from the customer’s site, as the viewing user, and displays them in that user’s browser.
When a page is exported, the Application does the same as the user the export is made for,
in its export function on Atlassian Forge, and returns the table to Confluence. That data
may include personal data held in work items, such as account identifiers, display names
and anything written in a field. It is used within that request only and stored nowhere by
the Application. A JQL query may name a person, and is stored as written, in the page.

3.4 In the Advanced edition, a change made in the table is sent to Jira as the user making
it, and Jira stores it as it would a change made in Jira.

3.5 The Application carries out no automated decision-making or profiling within the meaning of
Article 22 of the GDPR.

## 4. Where the data is stored

4.1 All data the Application stores is stored on the Atlassian platform, in the customer’s
Confluence Cloud site. Oktul operates no server or database for the Application and holds no
copy of the data.

4.2 The location of the data is determined by Atlassian. The macro configuration is part of the
Confluence page, so it is stored wherever Atlassian stores that page, including under any data
residency the customer has configured for Confluence Cloud.

## 5. Recipients and transfers

5.1 The Application’s Forge manifest declares no `permissions.external` and no `remotes`. The
Application therefore sends no data outside the Atlassian platform, and uses no analytics,
telemetry, error-reporting service or third-party script.

5.2 Atlassian Pty Ltd hosts the Application on the Forge platform on Oktul’s behalf and is
Oktul’s only sub-processor for the Application, under the Forge Data Processing Addendum and
the standard contractual clauses it incorporates. Atlassian’s own sub-processors are listed at
[atlassian.com/legal/sub-processors](https://www.atlassian.com/legal/sub-processors).

5.3 The declared permissions are shown on the Marketplace listing under **Permissions**.

## 6. Permissions

6.1 The Application requests the following scopes, each for the stated purpose:

| Scope | Why it is requested |
| --- | --- |
| `read:jira-work` | Run the macro's JQL query, read the fields a row displays and load what the inline editor offers |
| `write:jira-work` | Save an inline edit or a status transition as the viewing user, in the Advanced edition |
| `read:cmdb-object:jira` | Display an Assets object by its label and search objects in the inline editor |
| `read:cmdb-icon:jira` | Read the names of Assets' predefined icons, so each object chip displays its icon |

## 7. Retention

7.1 The macro configuration is part of the page, so Confluence keeps it for as long as it keeps
the page and its versions, whether or not the Application is installed. Removing the macro,
or deleting the page, removes it as Confluence removes any other page content. What Atlassian keeps after the
Application is uninstalled is stated in clause 8.

## 8. Data portability and switching

Work Item Macro keeps all data on the Atlassian platform, in your own site. Nothing is sent outside it, and Oktul holds no copy.

| Data | Where it is | How to export it |
|---|---|---|
| The configuration of each macro: JQL query, results per page, columns and inline editing settings | The macro’s parameters, in the Confluence page that holds it | Part of the page body, so Confluence's space export and the Confluence REST API include it |

**After uninstallation.** The macro configuration stays in the page, as any other page content does. The app has no Forge storage, so nothing else remains.

Oktul charges no fee for switching to another product or for exporting data. [Clause 11 of the application licence](/legal/app-terms/#switching) sets out the terms.

## 9. Rights of data subjects

9.1 Data subjects have the rights of access, rectification, erasure, restriction of
processing, data portability and objection under Articles 15 to 21 of the GDPR. For Customer
Data, the controller is the customer, and requests are made to the customer.

9.2 Oktul assists the customer with such requests free of charge, as clause 7.1 of the
Addendum provides. Requests concerning data for which Oktul is the controller are sent to
legal@oktul.com and answered within one month, extendable by two further months under Article
12(3) of the GDPR.

9.3 A data subject may lodge a complaint with the Estonian Data Protection Inspectorate
(Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, info@aki.ee) or with the supervisory
authority of their habitual residence, place of work or place of the alleged infringement.

## 10. Security

10.1 According to Atlassian’s documentation, Forge provides tenant isolation and encryption in
transit and at rest. Oktul’s own measures are set out in clause 5 of the Addendum.

10.2 Every request the Application makes to Jira and Assets runs as a user: on screen, from
the viewing user’s browser; in an export, as the user the export is made for. The Application
never calls Jira or Assets with its own identity, so it reads and changes only what that user
may read and change, and Jira applies its permissions, screens and validation to every
change. The Application sends no data outside the Atlassian platform and loads no image or
script from outside the Application.

10.3 Oktul holds no audited security certification.

## 11. Vulnerability reports and security incidents

11.1 A vulnerability is reported through the Oktul Help Center or to support@oktul.com, where
it receives a reference. Oktul responds within 24 hours, Monday to Friday, and credits the
reporter by name unless asked not to. Oktul does not pay bounties. Research in good faith is
covered by clause 8.5 of the application licence. Security testing of a Forge application is
testing of the Atlassian platform and must comply with Atlassian’s policies.

11.2 Oktul remediates vulnerabilities within the following periods, measured by CVSS score. The
periods under Atlassian’s [Security Bug Fix Policy](https://developer.atlassian.com/platform/marketplace/security-bugfix-policy/)
for cloud apps also apply, and the shorter period governs.

| Severity | Oktul | Atlassian’s requirement |
|---|---|---|
| Critical, CVSS 9.0 or higher | 7 calendar days | 10 days |
| High, CVSS 7.0 to 8.9 | 14 calendar days | 4 weeks |
| Medium, CVSS 4.0 to 6.9 | 28 calendar days | 12 weeks |
| Low, CVSS below 4.0 | 56 calendar days | 25 weeks |

11.3 Oktul notifies the customer of a personal data breach affecting Customer Data without
undue delay and in any event within 24 hours, as clause 7.3 of the Addendum provides.

## 12. Changes to this notice

12.1 The version and effective date at the top of this page identify the version in force. A
change is recorded in the [release notes](../release-notes/). Oktul notifies the technical
contacts of installations and Atlassian of a material change.
