Privacy Policy — ReadProof for Confluence

Effective date: 7 July 2026 · Provider: Atınç Yurdakul, Netherlands (EU) · Contact: support@readproof.net

1. Summary

ReadProof for Confluence ("ReadProof") is an Atlassian Forge app that helps your organization record read-confirmations, document reviews, and audit evidence for policies stored in Confluence. ReadProof is Forge-native: in v1 it stores all data inside your own Atlassian Cloud environment and does not transmit any data to external (non-Atlassian) servers.

2. Who is the controller

Your organization (the Atlassian customer that installs ReadProof) is the data controller. ReadProof, as the app provider, and Atlassian, as the Forge platform host, act as processors on your behalf.

3. What data ReadProof stores

ReadProof stores, in Atlassian Forge storage within your Atlassian Cloud instance, only the records you create by using it:

To power version-aware confirmations, ReadProof reads page metadata (title, current version number) via the Atlassian API. It does not copy or store page body content in v1.

4. What ReadProof does NOT do

5. Where data lives / data residency

All ReadProof data is stored on Atlassian's Forge platform, co-located with your Atlassian Cloud instance. Data residency follows your Atlassian instance's configuration.

6. Retention & deletion

Data persists in your instance's Forge storage until you delete it or uninstall the app, after which the app's storage is removed per Atlassian's data lifecycle. You can export your records at any time via the built-in evidence-pack export.

7. Sub-processors

Atlassian — Forge platform hosting and storage. (Future, optional — AI features only) If you enable ReadProof's optional AI features (planned for a later version), they use a Bring-Your-Own-Key model: you provide your own LLM provider API key, and page content analyzed by AI is sent directly from your Atlassian environment to the LLM provider you choose, governed by your agreement with that provider — not routed through ReadProof. AI features are off by default.

8. Your rights (GDPR/EU)

Because ReadProof stores personal data (account IDs, timestamps) on behalf of your organization, data-subject requests (access, rectification, erasure) are handled by your organization as controller, using ReadProof's export and deletion features. For questions, contact support@readproof.net.

9. Security

ReadProof runs entirely on Atlassian's Forge infrastructure, inheriting Atlassian's platform security controls. It requests only the minimum Confluence scopes needed (read:page:confluence) plus app storage.

10. Compliance disclaimer

ReadProof produces evidence and helps keep documents current. It does not determine or guarantee compliance with any standard (e.g., ISO 27001, SOC 2); certification decisions are made by your auditor. ReadProof is not legal advice.

11. Changes

We may update this policy; material changes will be reflected on the listing and at this URL with a new effective date.

12. Contact

support@readproof.net · Atınç Yurdakul, Netherlands.

This policy is provided in good faith and describes ReadProof's data practices; it is not legal advice. If your organization has specific regulatory obligations, consult your legal counsel.

← readproof.net