Link Steward for Confluence / Release 1.0

Data processing addendum

Version 1.0, prepared 7 September 2026. This page completes the DPA Details for Link Steward for Confluence and incorporates the Bonterms Data Protection Addendum Version 2.0, Attachment Version, including Exhibits A and B, into the customer's product agreement. The standard DPA is © 2026 Bonterms, Inc., available under CC BY 4.0. The completed details and additional terms below are specific to this product.

Key terms

ItemCompleted detail
Main AgreementThe customer's Link Steward for Confluence Marketplace order, the Bonterms Standard End User Agreement Version 1.0 and the provider-specific terms.
DPA effective dateThe date the customer accepts the product agreement incorporating this DPA.
ProviderMikhail Eshchenko, Marketplace vendor 923094361.
Provider privacy contactsupport@misheno.com.
Provider addressGreenfield Villas 3, 311/30, moo 6, Bang Lamung, Chonburi 20150, Thailand.
Customer identity, address and contactThe customer and administrator identified in the Marketplace order and installation records; a different privacy contact may be designated by written notice.
Customer roleController, or processor acting on the instructions of its controller where applicable.
Provider roleProcessor.
Designated EU governing law and member stateIreland, solely for the EU Standard Contractual Clauses where applicable.
Competent EU supervisory authorityDetermined under Clause 13 of the applicable EU Standard Contractual Clauses.

Processing details

The customer's activities are operating its Confluence workspace and managing knowledge pages. The provider's activities are supplying and supporting the app. Processing consists of reading page ADF and permissions, extracting and checking links, presenting results to authorized users, storing scan metadata and work states, and executing customer-requested replacements and optional reminders.

Data subjects are Confluence users, page owners, employees, contractors, customers and other people whose information the customer includes in selected pages or URLs. Data categories are account identifiers and display names, page and space identifiers, access and ownership information, user-generated page content, destinations and any personal data embedded in those destinations, and app configuration or work-state metadata. Page content and user profiles are processed transiently; they are not copied into app KVS storage.

The service is not designed to process special-category data. Customers must not enable spaces or destinations for checking when doing so would expose special-category data, authentication secrets or confidential material to external recipients. Ordinary Confluence access controls continue to apply.

Processing occurs when a customer runs a check, opens a result, saves a change or enables a scheduled check. It continues during the subscription and as needed for permitted return/deletion and platform retention after termination. Results and work states expire after 30 days; settings persist until cleared; reminder suppression records expire after seven days. Detailed retention and customer deletion controls are in the privacy notice.

Subprocessors and customer-directed recipients

ServiceFunction and processing location
Atlassian ForgeApp hosting, compute, storage, queues, identity and operational diagnostics on Atlassian's global infrastructure. Atlassian's applicable Forge terms and subprocessor information govern its services. This app does not promise a particular residency region.

Cloudflare's public DNS resolver receives administrator-enabled hostnames, without page bodies, owner profiles, link paths or query strings. Websites on enabled hostnames receive requests to the destinations selected by the customer. These are customer-directed external recipients operating their services under their own terms, not a separate database operated for Link Steward. The customer instructs these disclosures by enabling external checking after reviewing the description in Settings. The app sends no Confluence credentials.

The provider's support mailbox handles information a person voluntarily sends to support, as described in the privacy notice. Do not send page exports, special-category data, passwords or tokens to support. Support contact and correspondence used for the provider's own business administration are separate from processing customer content on the customer's behalf.

Security measures and additional terms

The security measures are incorporated as the technical and organizational measures. They cover current-user authorization, installation-scoped storage, minimized retained data, bounded external requests, version checks, and diagnostic redaction. Operational access is limited to what is needed to provide support, with confidentiality requirements and multifactor protection for administrative accounts.

The customer can export visible results as CSV and delete a space's app data in Settings, including after license expiry. Customer-owned Confluence pages, page history and native reminder comments are not deleted by clearing app storage. Atlassian applies its documented platform backup, retention and recovery policies after uninstallation. Retained records remain subject to the DPA.

No other modifications to the incorporated standard DPA are made. Its incident notification, assistance, audit, subprocessor notification and cross-border transfer provisions apply where relevant. This page does not claim that the provider is certified under the Data Privacy Framework or that a contractual document replaces an applicable transfer assessment.