Privacy Policy
Privacy Policy — Hullspark Forge Apps
1. What this policy covers.
This policy applies to every Atlassian Forge app published by Hullspark (each an "App", together "the Apps"). At the time of writing these are Label Sweep for Confluence, Attachment Sweep for Confluence and Page Review Reminders for Confluence. Each App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). We operate no servers of our own for any App.
2. Data the Apps process.
Each App reads and changes Confluence content only through Atlassian's APIs, only with the Confluence permissions of the user who started the job, and only within the scope of that job.
Label Sweep for Confluence lists, renames, merges and deletes labels in your Confluence Cloud site. It reads label names and the IDs, titles and space of pages and blog posts that carry those labels. It changes labels on pages and blog posts only when you start a rename, merge or delete job.
Attachment Sweep for Confluence finds and cleans up attachments in your Confluence Cloud site. It reads attachment metadata (file name, size, media type, dates, IDs and the page or blog post each attachment belongs to). It reads page bodies only to detect whether an attachment is still referenced; page bodies are not stored. When you start a job it moves the selected attachments to Confluence's trash, from which your Confluence administrators can restore them. It never purges attachments permanently.
Page Review Reminders for Confluence lets you set a review date and a reviewer on pages in your Confluence Cloud site and reminds the reviewer when a review is due. It reads page metadata (IDs, titles, space, last-modified date and version number). It writes and reads the review policy as a content property on the page (review date, the reviewer's Atlassian account ID, review interval and status) — never the page body. It keeps an index of pages that have a policy in Forge storage (page IDs, dates and status). When a review is due or overdue it posts a footer comment on the page that @mentions the reviewer, at most one per page per 30 days; Confluence then sends its own notification email under your site's notification settings. To decide whether to show the administrator dashboard it checks whether the current user is a site administrator by reading that user's group memberships; the result is cached for 10 minutes and not stored beyond that.
3. Data the Apps store.
Each App stores only job state in Forge Key-Value Storage, which is hosted and operated by Atlassian inside your site's Atlassian data region: job type, job parameters (for example source and target label names, or attachment selection criteria), IDs and titles of affected content, progress counters, error messages, timestamps, an execution log, and the Atlassian account ID of the user who started the job (so the job can run with that user's permissions and be attributed in the log). In addition, Page Review Reminders for Confluence stores in the same Forge storage: its settings; an index of pages that carry a review policy (page IDs, review dates, status and the reviewer's Atlassian account ID, as a copy of the policy on the page), kept for as long as the policy exists on the page and removed when the policy is cleared or the page is deleted; scan snapshots (page IDs, titles, space keys, last-modified dates, review dates, reviewer account IDs and status), deleted 30 days after the scan finishes; a per-page record that a reminder was posted (page ID, date and kind — not the recipient), kept for up to one year so the 30-day limit can be enforced; and a 10-minute cache of whether a user is a site administrator. The review policy itself lives on the page as a Confluence content property, not in Forge storage. We do not store page bodies, comments, attachment file contents, names, email addresses, passwords or API tokens.
4. Where data goes.
Nowhere outside Atlassian. The Apps declare no external endpoints, send nothing to us or to any third party, and contain no analytics, tracking or advertising. Atlassian may collect platform-level metrics as described in its own privacy policy.
5. How we use data.
Only to perform the job you requested and show you its progress and log. We do not sell, share, profile or use the data for any other purpose. We (the developer) cannot read your site's storage; only your site's Confluence users with access to an App can.
6. Retention.
Job records are kept so you can review the log. A weekly scheduled task inside each App deletes each job record (state, log and index entry) 30 days after the job finishes. As a backstop, every job and log record is also written with a Forge storage TTL of 365 days from its last update, so nothing outlives that even if the weekly task fails. Uninstalling an App deletes all of that App's storage for your site, as handled by Atlassian. You may delete individual job records from the App's Jobs tab at any time.
7. Your rights (GDPR / UK GDPR and similar laws).
For data stored by the Apps, your Atlassian site's organisation is the controller and Hullspark is a processor acting on your instructions through the Apps. The only personal data involved is the Atlassian account ID of users who start jobs. You can erase it by deleting the job or uninstalling the App. We honour Atlassian's personal-data erasure and rectification requests forwarded through the Forge platform (https://developer.atlassian.com/platform/forge/user-privacy-guidelines/). Because nothing is transferred outside Atlassian, no cross-border transfer by us takes place; Atlassian's data residency for your site applies. On request we will sign a data-processing addendum consistent with GDPR Article 28.
8. Security.
Hosting, encryption at rest and in transit, tenant isolation and access control are provided by the Atlassian Forge platform (https://developer.atlassian.com/platform/forge/security/). The Apps never ask for, and cannot use, passwords, API tokens or personal access tokens. Report security issues to support@hullspark.com.
9. Children.
The Apps are business tools for Confluence users and are not directed at children.
10. Changes.
We will post changes at this URL and update the effective date. Material changes will also be noted in the affected App's Marketplace release notes.
プライバシーポリシー — Hullspark Forge アプリ
1. 本ポリシーの適用範囲.
本ポリシーは、Hullspark が公開するすべての Atlassian Forge アプリ(個別に「本アプリ」、総称して「各アプリ」)に適用されます。本書作成時点では Label Sweep for Confluence、Attachment Sweep for Confluence、Page Review Reminders for Confluence の 3 つです。各アプリは Atlassian の Forge プラットフォーム上でのみ動作します(Runs on Atlassian)。当方はいずれのアプリのためにも独自のサーバを運用しません。
2. 処理するデータ.
各アプリは、Atlassian の API を通じてのみ、ジョブを開始した利用者ご自身の Confluence 権限で、かつそのジョブの範囲内でのみ Confluence のコンテンツを読み取り・変更します。
Label Sweep for Confluence は、Confluence Cloud サイトのラベルを一覧・リネーム・統合・削除します。ラベル名と、そのラベルが付いたページ・ブログの ID・タイトル・スペースを読み取ります。ページ・ブログのラベルを変更するのは、利用者がリネーム・統合・削除のジョブを開始したときだけです。
Attachment Sweep for Confluence は、Confluence Cloud サイトの添付ファイルを検索・整理します。添付ファイルのメタデータ(ファイル名、サイズ、メディア種別、日時、ID、所属するページ・ブログ)を読み取ります。ページ本文を読むのは添付ファイルがまだ参照されているかを検出するためだけで、ページ本文は保存しません。利用者がジョブを開始すると、選択した添付ファイルを Confluence のゴミ箱へ移動します。ゴミ箱からは Confluence 管理者が復元できます。添付ファイルを完全消去(purge)することはありません。
Page Review Reminders for Confluence は、Confluence Cloud サイトのページにレビュー期日と担当者を設定し、期日が来たら担当者に知らせます。ページのメタデータ(ID、タイトル、スペース、最終更新日時、版番号)を読み取ります。レビュー方針(レビュー期日、担当者の Atlassian アカウント ID、レビュー間隔、状態)はページのコンテンツプロパティとして書き込み・読み取りします。ページ本文には一切書き込みません。方針を持つページの索引(ページ ID、日付、状態)を Forge ストレージに保持します。レビューが期限間近または期限切れになると、担当者を @メンションするフッターコメントをそのページに投稿します(同一ページにつき 30 日に 1 回まで)。その後の通知メールは Confluence 自身がサイトの通知設定に従って送ります。管理者用ダッシュボードを表示するかどうかを判定するため、操作中の利用者のグループ所属を読み取ってサイト管理者かどうかを確認します。結果は 10 分間キャッシュされ、それ以上は保持しません。
3. 保存するデータ.
各アプリが保存するのはジョブ状態のみで、保存先は Atlassian がサイトのデータリージョン内で運用する Forge Key-Value Storage です。内容は、ジョブ種別、ジョブのパラメータ(元・先ラベル名や添付ファイルの選択条件など)、対象コンテンツの ID とタイトル、進捗、エラー、時刻、実行ログ、およびジョブを開始した利用者の Atlassian アカウント ID(その利用者の権限で実行し、ログに記録するため)です。加えて Page Review Reminders for Confluence は同じ Forge ストレージに次を保存します。アプリの設定。レビュー方針を持つページの索引(ページ ID、レビュー期日、状態、およびページ上の方針の写しとしての担当者の Atlassian アカウント ID)— ページに方針がある限り保持し、方針の解除またはページの削除で消えます。走査のスナップショット(ページ ID、タイトル、スペースキー、最終更新日時、レビュー期日、担当者のアカウント ID、状態)— 走査完了から 30 日後に削除します。ページごとの通知済み記録(ページ ID、日時、種別。宛先は含みません)— 30 日に 1 回の上限を守るため最長 1 年保持します。利用者がサイト管理者かどうかの 10 分間のキャッシュ。レビュー方針そのものは Forge ストレージではなく、ページの Confluence コンテンツプロパティとして存在します。ページ本文、コメント、添付ファイルの中身、氏名、メールアドレス、パスワード、API トークンは保存しません。
4. データの送信先.
Atlassian の外には一切送信しません。各アプリは外部エンドポイントを宣言せず、当方にも第三者にも何も送らず、解析・トラッキング・広告を含みません。Atlassian 自身によるプラットフォーム指標の収集は Atlassian のプライバシーポリシーに従います。
5. 利用目的.
利用者が依頼したジョブの実行と、その進捗・ログの表示のみ。販売・共有・プロファイリング・その他の目的には使いません。開発者である当方はサイトのストレージを読めません。読めるのは本アプリにアクセスできるサイト内の Confluence 利用者だけです。
6. 保存期間.
ジョブ記録はログ確認のために保持されます。各アプリ内の週次スケジュール処理が、ジョブ完了から 30 日後に各ジョブ記録(状態・ログ・一覧項目)を削除します。保険として、すべてのジョブ・ログ記録は最終更新から 365 日の Forge ストレージ TTL 付きで書き込まれ、週次処理が失敗してもそれを超えて残ることはありません。本アプリをアンインストールすると、Atlassian の仕組みによりサイトのそのアプリ用ストレージはすべて削除されます。個々のジョブ記録は本アプリの Jobs タブからいつでも削除できます。
7. 利用者の権利(GDPR・UK GDPR 等).
各アプリが保存するデータについて、利用者の Atlassian 組織が管理者(controller)、Hullspark は各アプリを通じて指示に従う処理者(processor)です。関係する個人データはジョブを開始した利用者の Atlassian アカウント ID のみで、ジョブの削除またはアンインストールで消去できます。Forge プラットフォーム経由で転送される Atlassian の消去・訂正要求にも対応します(https://developer.atlassian.com/platform/forge/user-privacy-guidelines/)。Atlassian の外へ出さないため当方による越境移転は発生せず、サイトの Atlassian データレジデンシーがそのまま適用されます。ご要望があれば GDPR 第 28 条に沿ったデータ処理契約(DPA)に署名します。
8. セキュリティ.
ホスティング、保存時・通信時の暗号化、テナント分離、アクセス制御は Atlassian Forge プラットフォームが提供します(https://developer.atlassian.com/platform/forge/security/)。各アプリはパスワード・API トークン・個人アクセストークンを求めず、使用もできません。脆弱性の報告は support@hullspark.com へ。
9. 子ども.
各アプリは Confluence 利用者向けの業務ツールで、子どもを対象としていません。
10. 変更.
変更はこの URL に掲載し、発効日を更新します。重要な変更は該当アプリの Marketplace リリースノートにも記載します。