TELCOMA Global / License Audit for Confluence / Privacy policy
What the app reads, what it keeps, and what it never does.
This policy describes what License Audit for Confluence does with your data.
1
What the app is
License Audit for Confluence ("the app") is an Atlassian Marketplace app that helps a Confluence Cloud administrator identify licensed users who have contributed nothing in Confluence over a chosen period. It runs entirely on Atlassian's Forge platform.
2
What data the app processes
The app reads the following from your Confluence Cloud site, using only the read-only permissions granted at installation:
- User directory data: the list of accounts that can use your Confluence site, and for each one the account ID, account type, account status and guest flag while a scan lists users; display name and email address (where the user's Atlassian profile makes it visible) only when a report is displayed or exported. None of these except the account ID are written to storage.
- Content activity metadata: for recently modified pages, blog posts, comments and attachments, the author and timestamp of the latest version and of creation; for pages and blog posts that other people edited, the author and timestamp of earlier versions. The app reads this to determine who contributed and when. It does not read page text, comment text, attachment contents, titles or labels.
3
What data the app stores
The app stores, in Forge's Atlassian-hosted storage within your site's data residency region:
- Scan progress (cursors, counters, timestamps).
- For each dormant user: the Atlassian account ID and a dormancy band derived by the app. Display names and email addresses are not stored; they are read from Confluence each time you open or export the report.
The app never stores page content, comment text, attachments, or any text authored by your users. Every stored value is regenerated by each scan and is deleted when the app is uninstalled.
4
Where data goes
Nowhere. The app makes no network requests outside Atlassian and has no servers of its own. Data does not leave your Atlassian site's hosting region.
5
What the app does not do
- It does not remove access from, deactivate, modify or delete users, and holds no permission that could.
- It does not change any setting, page, or configuration on your site.
- It does not use your data for any purpose other than producing the report you request.
- It does not sell, share, or transmit your data to any third party.
6
Legal basis and roles
You (the customer) are the data controller for the personal data on your site. TELCOMA Global is a data processor acting on your instructions, which consist of installing the app and running a scan. Where the GDPR applies, the app's processing is performed under your instructions and on Atlassian's infrastructure.
7
Retention and deletion
Report data persists on your site until the next scan overwrites it or the app is uninstalled, at which point Forge deletes all app storage for your site. You may also request deletion by contacting us.
8
Security
The app runs on Atlassian Forge, which enforces the app's permissions at the platform level, hosts its storage, and isolates it from other apps. The app requests only read scopes. Security issues may be reported to [email protected]; please do not post them publicly.
10
Changes
We will update this policy when the app's data handling changes and note the effective date above.