# Privacy policy

**Last updated: 09.09.2026**

Version 2.0, effective 09.09.2026. What Oktul does with information about you: the enquiry you send us, the licence detail Atlassian passes on when you install an application, and what this website measures if you let it. This notice covers the company and oktul.com.

> **This is not an application’s privacy policy** What a specific application stores inside your Atlassian instance, which scopes it declares and whether anything leaves are decided per application and published in that application’s own documentation. Each one is linked directly below. This notice is about Oktul and this website.

## Who we are

Oktul OÜ is an Estonian company and the controller for the information described below. A request under this notice goes to the address here, where a person reads it rather than a queue receives it.

We have not appointed a data protection officer. The GDPR requires one only for large-scale monitoring or large-scale special category processing, and we do neither; saying so is more useful than leaving a reviewer to guess from an absent field.

- **Controller:** Oktul OÜ (English rendering Oktul LLC)
- **Registry code:** 17589681
- **Registered office:** Seebi tn 1-703, 11316 Tallinn, Harjumaa, Estonia
- **Contact:** hello@oktul.com
- **This version:** 2.0, effective 09.09.2026

## What we collect, why, and on what legal basis

Four kinds of information, each with the Article 6 ground it rests on. A notice that describes processing without naming the ground has left out the part that decides whether the processing is lawful, so each row states it.

Where we rely on legitimate interests, the interest is our own and it is this: answering a person who contacted us, keeping the software licensed to you working, and finding out about a vulnerability before somebody else does. We have weighed each against your interests, and none of them involves profiling, advertising, or any use of your data that you would not expect from the act of contacting a software vendor. You can object to any of them, and the section on your rights says how.

- **An enquiry you send us:** Your name, your email address and your message, whether it arrives by the contact form, by email or as a request in the Help Center. Article 6(1)(f), legitimate interests: we cannot answer an enquiry we have not kept, and you sent it in order to be answered.
- **Licence and contact detail from Atlassian:** Passed to us by Atlassian when you install or subscribe. Article 6(1)(b) where it is needed to perform the licence, and Article 6(1)(f) for keeping our own records of who is licensed. The section below covers it in full, because you did not give it to us.
- **A vulnerability report:** What you sent, who sent it, and what we did about it. Article 6(1)(f), legitimate interests in the security of software other organisations rely on.
- **Analytics, and the support widget:** Article 6(1)(a), consent. Neither loads until you accept it, and refusing costs you nothing on this site. Consent is also the ePrivacy ground for storing anything on your device that is not strictly necessary.

## What Atlassian tells us, which you did not send us

When you install or subscribe to one of our applications through the Atlassian Marketplace, Atlassian passes us the licence record: the organisation, the Atlassian site it is installed on, the tier and user count, the licence status and dates, and a technical contact name and email address for the installation. We do not choose what is in that record and we cannot ask Atlassian for more.

This is set out separately because you did not give it to us, so it is Article 14 rather than Article 13 information. The source is Atlassian, the categories are the ones listed above, and if we ever obtain personal data about you this way without you having heard from us, we will tell you within one month of obtaining it, or at the latest when we first write to you.

We use it to know who is licensed, to answer a support request from an installation that has one, and to tell you about a change to an application you have installed. We do not use it to market unrelated products and we do not pass it on.

Atlassian is the controller of your relationship with the Marketplace itself, including your payment details, which we never receive. Atlassian’s own privacy policy governs that part.

## What the website itself collects

Which pages get read, and nothing more, using Google Analytics 4, and only if you accept it. Before you answer, no request is made to Google: the script is not loaded rather than loaded and told to behave. Refusing changes nothing about how the site works for you.

Google Ireland Limited is the processor. Advertising features, Google Signals and data sharing with other Google products are off, and we hold no advertising identifier and build no profile of you across visits. Google Analytics 4 does not record IP addresses: your address is used in transit to derive a coarse location and is then discarded rather than stored. That is Google’s documented behaviour of the product rather than a setting we switched on, and the distinction matters, because a claim that we anonymise addresses would imply a control we do not hold.

There is no session recording, no heatmap, no A/B testing and no tag manager. Analytics goes straight to Google Analytics rather than through a container, so nothing else can be added to the page through it without this notice changing.

One cookie is set regardless of your answer, and it is the one holding the answer. Everything else on this site that stores anything on your device waits to be asked: analytics, and the support widget in the corner of every page. Until 09.09.2026 that widget loaded on every page and set an identifier before anyone was asked, which was wrong and is fixed; the cookie notice dates the change rather than absorbing it. That notice lists every cookie, every local storage entry, and every third-party script this site runs at all.

## Who else sees it

Named rather than described, because a category is not something you can assess. Each is a processor acting on our instructions, except where the row says otherwise. This is the whole list, and it changes only by changing this notice.

We do not sell your information, and we do not share it for advertising. There is no data broker, no enrichment against a third-party database, and no audience list anywhere.

- **Cloudflare, Inc.:** Serves the site, and receives the enquiry in transit if you use the contact form. It also runs the Turnstile check that tells a person from a script. What we can verify is what we receive and what we observed: Turnstile returns us a pass or fail and no personal data, and on a clean browser on 06.09.2026 it set no cookie. Cloudflare does process your IP address and browser signals in order to make that judgement, which is what the check is; Cloudflare’s own documentation governs what it does with them.
- **Google Ireland Limited:** Google Analytics 4, only if you accepted it. Google LLC may process outside the EEA.
- **Atlassian Pty Ltd:** Our Help Center, the support widget, and the Marketplace licence records described above. Requests are stored in the EU under the service desk’s EU data residency. If you accept the support widget it also sends its own usage events from your browser to Atlassian, which we do not receive and cannot see.
- **Sentry:** Error reporting for the support widget, sent from your browser, and only if you accepted that widget. It is Atlassian’s arrangement rather than ours: the reports go to Atlassian’s own project, we hold no account, receive nothing from it and cannot see what it collects.
- **Zoho Corporation Pvt. Ltd:** Zoho ZeptoMail carries the mail our contact form sends, and the hello@oktul.com mailbox it arrives in. The account is on Zoho’s EU data centre, so an enquiry is stored in the EU.

## How long we keep it

A period rather than a description, because "as long as necessary" is not something you can hold us to. Where a period is tied to a law, the law is named.

Ask us to delete any of it and we will, unless a law requires us to keep it, in which case we will tell you which one and for how long.

- **An enquiry:** For as long as the conversation is live, and two years afterwards, so we can pick up a thread a customer returns to.
- **A vulnerability report:** Five years from the day it is closed. It is evidence of what we knew and when, and it has to outlast the three-year general limitation period in §146 of the Estonian General Part of the Civil Code Act.
- **Licence and contact detail:** For as long as the licence is active, and three years afterwards, which is that same limitation period.
- **Your consent decision:** Six months, in the cookie holding it, after which you are asked again.

## How it is protected

Not something the GDPR requires this notice to say, and every reviewer asks it, so it is here rather than in an answer to a questionnaire.

There is no Oktul server and no Oktul database. Our applications run on Atlassian Forge, so what they touch stays inside your own Atlassian tenancy; the little that reaches us, which is an enquiry and a licence record, sits in Atlassian and Zoho on their EU infrastructure. Access is limited to named personnel, each with multi-factor authentication, full-disk encryption and automatic screen lock, and there is no shared account.

A personal data breach that is likely to be a risk to you is reported to the Estonian Data Protection Inspectorate within 72 hours of us becoming aware of it, and to you without undue delay where the risk is high. What we publish about all of this, including our CSA STAR self-assessment, is on the trust page.

## Your rights

Access, rectification, erasure, restriction, portability and objection, under the GDPR. Write to hello@oktul.com and we will not ask you to prove your identity beyond what is necessary to be sure we are answering the right person.

You will have an answer within one month, as Article 12(3) requires. If a request is complex we may extend that by up to two further months, and we will tell you inside the first month if we do. Support has a faster clock and it is deliberately not attached to this: a one-day promise on a rights request would be a target to miss rather than a protection for you.

Where we rely on your consent, you may withdraw it at any time, and withdrawing is as easy as giving it: the cookie settings link in the footer of every page reopens the same choice. Withdrawal does not affect what was lawfully done before it.

We make no automated decisions about you and carry out no profiling within the meaning of Article 22. Nothing on this site or in our applications produces a decision about a person without a person making it.

This site and our applications are sold to organisations and are not directed at children. We do not knowingly collect anything from a child under 13, which is the age Estonia sets in §8 of the Personal Data Protection Act for information society services. If you believe a child has sent us something, write to us and we will delete it.

If you are not satisfied with how we handled a request you may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), or to the supervisory authority where you live.

## Transfers outside the EU

Oktul is in Estonia and so is the information we hold. Four processors may move some of it outside the EEA, and each rests on a named mechanism rather than on a general assurance. "Appropriate safeguards" is not a mechanism, and a reviewer is right to reject it.

- **Google:** Google LLC processes analytics data in the United States under the European Commission’s adequacy decision for the EU-US Data Privacy Framework, of which Google is a certified participant, with Google’s standard contractual clauses applying in addition.
- **Cloudflare:** Cloudflare, Inc. operates on the same adequacy decision and on its own standard contractual clauses.
- **Atlassian:** Atlassian Pty Ltd is an Australian company, and Australia has no adequacy decision. Transfers rest on the EU standard contractual clauses in Commission Implementing Decision (EU) 2021/914, which Atlassian’s own data processing addendum incorporates, at Module Two for controller to processor and Module Three for processor to processor. The service desk itself has EU data residency, so a request is stored in the EU and this mechanism covers access to it rather than its storage.
- **Zoho:** Zoho Corporation Pvt. Ltd is an Indian company, and India has no adequacy decision. Our account is on Zoho’s EU data centre, so mail is stored in the EU, and support access from outside the EEA rests on the same 2021/914 standard contractual clauses, incorporated in Zoho’s data processing addendum at Module Two.

## When this notice changes

The version and the date at the top change with it. A change that alters what we collect, who receives it or what we rely on to process it is dated in the text where it happened rather than folded silently into a new version, which is why this document names dates in the middle of sentences.

Version 2.0 on 09.09.2026 stated the legal basis for each purpose, added the Article 14 section on licence detail from Atlassian, named Atlassian Pty Ltd and Zoho Corporation Pvt. Ltd with their transfer mechanisms, gave retention a number instead of a description, and recorded that the support widget now waits to be asked. Version 1.0 ran from 03.09.2026 to 09.09.2026.

---

## Published by

- Oktul OÜ (Oktul LLC)
- Oktul OÜ · Reg. nr 17589681 · Tallinn, Harjumaa, Estonia
- Email: hello@oktul.com
- Web: https://oktul.com/
- Atlassian Marketplace: https://marketplace.atlassian.com/vendors/534484195
- Estonian: https://oktul.com/et/
