Privacy policy
Version 2.0, effective 09.09.2026. What Oktul does with information about you: the enquiry you send us, the licence detail Atlassian passes on when you install an application, and what this website measures if you let it. This notice covers the company and oktul.com.
Last updated · Oktul OÜ · Registry code 17589681What an application stores in your Atlassian site, which scopes it declares and whether anything leaves are answered per application, in its own documentation. Go straight there:
Who we are
Oktul OÜ is an Estonian company and the controller for the information described below. A request under this notice goes to the address here, where a person reads it rather than a queue receives it.
We have not appointed a data protection officer. The GDPR requires one only for large-scale monitoring or large-scale special category processing, and we do neither; saying so is more useful than leaving a reviewer to guess from an absent field.
- Controller
- Oktul OÜ (English rendering Oktul LLC)
- Registry code
- 17589681
- Registered office
- Seebi tn 1-703, 11316 Tallinn, Harjumaa, Estonia
- Contact
- hello@oktul.com
- This version
- 2.0, effective 09.09.2026
What we collect, why, and on what legal basis
Four kinds of information, each with the Article 6 ground it rests on. A notice that describes processing without naming the ground has left out the part that decides whether the processing is lawful, so each row states it.
Where we rely on legitimate interests, the interest is our own and it is this: answering a person who contacted us, keeping the software licensed to you working, and finding out about a vulnerability before somebody else does. We have weighed each against your interests, and none of them involves profiling, advertising, or any use of your data that you would not expect from the act of contacting a software vendor. You can object to any of them, and the section on your rights says how.
- An enquiry you send us
- Your name, your email address and your message, whether it arrives by the contact form, by email or as a request in the Help Center. Article 6(1)(f), legitimate interests: we cannot answer an enquiry we have not kept, and you sent it in order to be answered.
- Licence and contact detail from Atlassian
- Passed to us by Atlassian when you install or subscribe. Article 6(1)(b) where it is needed to perform the licence, and Article 6(1)(f) for keeping our own records of who is licensed. The section below covers it in full, because you did not give it to us.
- A vulnerability report
- What you sent, who sent it, and what we did about it. Article 6(1)(f), legitimate interests in the security of software other organisations rely on.
- Analytics, and the support widget
- Article 6(1)(a), consent. Neither loads until you accept it, and refusing costs you nothing on this site. Consent is also the ePrivacy ground for storing anything on your device that is not strictly necessary.
What Atlassian tells us, which you did not send us
When you install or subscribe to one of our applications through the Atlassian Marketplace, Atlassian passes us the licence record: the organisation, the Atlassian site it is installed on, the tier and user count, the licence status and dates, and a technical contact name and email address for the installation. We do not choose what is in that record and we cannot ask Atlassian for more.
This is set out separately because you did not give it to us, so it is Article 14 rather than Article 13 information. The source is Atlassian, the categories are the ones listed above, and if we ever obtain personal data about you this way without you having heard from us, we will tell you within one month of obtaining it, or at the latest when we first write to you.
We use it to know who is licensed, to answer a support request from an installation that has one, and to tell you about a change to an application you have installed. We do not use it to market unrelated products and we do not pass it on.
Atlassian is the controller of your relationship with the Marketplace itself, including your payment details, which we never receive. Atlassian’s own privacy policy governs that part.
What the website itself collects
Which pages get read, and nothing more, using Google Analytics 4, and only if you accept it. Before you answer, no request is made to Google: the script is not loaded rather than loaded and told to behave. Refusing changes nothing about how the site works for you.
Google Ireland Limited is the processor. Advertising features, Google Signals and data sharing with other Google products are off, and we hold no advertising identifier and build no profile of you across visits. Google Analytics 4 does not record IP addresses: your address is used in transit to derive a coarse location and is then discarded rather than stored. That is Google’s documented behaviour of the product rather than a setting we switched on, and the distinction matters, because a claim that we anonymise addresses would imply a control we do not hold.
There is no session recording, no heatmap, no A/B testing and no tag manager. Analytics goes straight to Google Analytics rather than through a container, so nothing else can be added to the page through it without this notice changing.
One cookie is set regardless of your answer, and it is the one holding the answer. Everything else on this site that stores anything on your device waits to be asked: analytics, and the support widget in the corner of every page. Until 09.09.2026 that widget loaded on every page and set an identifier before anyone was asked, which was wrong and is fixed; the cookie notice dates the change rather than absorbing it. That notice lists every cookie, every local storage entry, and every third-party script this site runs at all.
How long we keep it
A period rather than a description, because "as long as necessary" is not something you can hold us to. Where a period is tied to a law, the law is named.
Ask us to delete any of it and we will, unless a law requires us to keep it, in which case we will tell you which one and for how long.
- An enquiry
- For as long as the conversation is live, and two years afterwards, so we can pick up a thread a customer returns to.
- A vulnerability report
- Five years from the day it is closed. It is evidence of what we knew and when, and it has to outlast the three-year general limitation period in §146 of the Estonian General Part of the Civil Code Act.
- Licence and contact detail
- For as long as the licence is active, and three years afterwards, which is that same limitation period.
- Your consent decision
- Six months, in the cookie holding it, after which you are asked again.
How it is protected
Not something the GDPR requires this notice to say, and every reviewer asks it, so it is here rather than in an answer to a questionnaire.
There is no Oktul server and no Oktul database. Our applications run on Atlassian Forge, so what they touch stays inside your own Atlassian tenancy; the little that reaches us, which is an enquiry and a licence record, sits in Atlassian and Zoho on their EU infrastructure. Access is limited to named personnel, each with multi-factor authentication, full-disk encryption and automatic screen lock, and there is no shared account.
A personal data breach that is likely to be a risk to you is reported to the Estonian Data Protection Inspectorate within 72 hours of us becoming aware of it, and to you without undue delay where the risk is high. What we publish about all of this, including our CSA STAR self-assessment, is on the trust page.
Your rights
Access, rectification, erasure, restriction, portability and objection, under the GDPR. Write to hello@oktul.com and we will not ask you to prove your identity beyond what is necessary to be sure we are answering the right person.
You will have an answer within one month, as Article 12(3) requires. If a request is complex we may extend that by up to two further months, and we will tell you inside the first month if we do. Support has a faster clock and it is deliberately not attached to this: a one-day promise on a rights request would be a target to miss rather than a protection for you.
Where we rely on your consent, you may withdraw it at any time, and withdrawing is as easy as giving it: the cookie settings link in the footer of every page reopens the same choice. Withdrawal does not affect what was lawfully done before it.
We make no automated decisions about you and carry out no profiling within the meaning of Article 22. Nothing on this site or in our applications produces a decision about a person without a person making it.
This site and our applications are sold to organisations and are not directed at children. We do not knowingly collect anything from a child under 13, which is the age Estonia sets in §8 of the Personal Data Protection Act for information society services. If you believe a child has sent us something, write to us and we will delete it.
If you are not satisfied with how we handled a request you may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), or to the supervisory authority where you live.
Transfers outside the EU
Oktul is in Estonia and so is the information we hold. Four processors may move some of it outside the EEA, and each rests on a named mechanism rather than on a general assurance. "Appropriate safeguards" is not a mechanism, and a reviewer is right to reject it.
- Google LLC processes analytics data in the United States under the European Commission’s adequacy decision for the EU-US Data Privacy Framework, of which Google is a certified participant, with Google’s standard contractual clauses applying in addition.
- Cloudflare
- Cloudflare, Inc. operates on the same adequacy decision and on its own standard contractual clauses.
- Atlassian
- Atlassian Pty Ltd is an Australian company, and Australia has no adequacy decision. Transfers rest on the EU standard contractual clauses in Commission Implementing Decision (EU) 2021/914, which Atlassian’s own data processing addendum incorporates, at Module Two for controller to processor and Module Three for processor to processor. The service desk itself has EU data residency, so a request is stored in the EU and this mechanism covers access to it rather than its storage.
- Zoho
- Zoho Corporation Pvt. Ltd is an Indian company, and India has no adequacy decision. Our account is on Zoho’s EU data centre, so mail is stored in the EU, and support access from outside the EEA rests on the same 2021/914 standard contractual clauses, incorporated in Zoho’s data processing addendum at Module Two.
When this notice changes
The version and the date at the top change with it. A change that alters what we collect, who receives it or what we rely on to process it is dated in the text where it happened rather than folded silently into a new version, which is why this document names dates in the middle of sentences.
Version 2.0 on 09.09.2026 stated the legal basis for each purpose, added the Article 14 section on licence detail from Atlassian, named Atlassian Pty Ltd and Zoho Corporation Pvt. Ltd with their transfer mechanisms, gave retention a number instead of a description, and recorded that the support widget now waits to be asked. Version 1.0 ran from 03.09.2026 to 09.09.2026.
Write to hello@oktul.com. A person reads it. Support has its own address and a response target measured against it; this one is for the document you are reading.
For what a specific application does with the data in your Atlassian instance, see the privacy policy in its own documentation. Every application is listed on the applications page. Those answers are decided per application, so this document does not attempt to give them.