Privacy policy
Effective date: 10 September 2026
This policy explains what personal data is involved when you use the Confluence
app Remote Content (Atlassian Marketplace app key
ovh.dwa.confluence.remote), and what we do and do not receive.
It covers the Forge version of the app only. It does not cover Confluence itself, the Atlassian Marketplace, or any website you choose to embed.
1. Who we are
| Provider | Krzysztof Bogdan |
| Trading name on the Atlassian Marketplace | Atlas Inc. |
| Address | ul. Brzozowa 7A, 96-321 Petrykozy, Poland |
| Tax identification number | PL9522090225 |
| Responsible person for privacy matters | Krzysztof Bogdan |
| Contact for all privacy requests | support@go-atlas-inc.atlassian.net |
We are established in Poland, inside the European Union, so we act through the contact above rather than through an Article 27 representative. The same contact handles requests made under the UK GDPR and under California law.
2. Summary
The app runs entirely in your browser, on infrastructure operated by Atlassian. It has no server of ours, no database of ours, and no way to send your content anywhere.
| Question | Answer |
|---|---|
| Do we receive the addresses you embed? | No. They never leave Atlassian’s platform. |
| Do we receive Confluence page content, user names, or email addresses through the app? | No. |
| Do we receive anything from the websites you embed? | No. Your browser contacts them directly; we are not in the path. |
| Do we run analytics, telemetry, or crash reporting in the app? | No. |
| Does the app set cookies or store data in your browser? | No. |
| Do we sell or share personal information? | No. We never have. |
| What do we actually receive? | Only what you send us in a support request, plus licence and installation records that Atlassian makes available to us as the app’s provider. |
3. How the app handles your data
The app stores exactly seven values per macro:
| Value | Content |
|---|---|
url | The address a page author chose to embed. |
width, height | The frame’s dimensions. |
marginLeft, marginTop | The frame’s offsets. |
alignment | Left, center, right, or unset. |
hideScrollbars | A true or false flag. |
All seven are saved by Atlassian as Confluence macro configuration, inside the body of your own Confluence page. They are transmitted to your browser by Atlassian when the page is viewed, and the app renders them there.
The app requests no Confluence API permissions, uses no app storage service, and has no backend function. It does not read the identity of the person viewing or editing a page: anonymous and unlicensed viewers are supported precisely because no identity is needed.
Consequently we hold no copy of your macro configuration and no copy of your page content. We cannot read it, export it, restore it, or delete it, because we never receive it.
4. The websites you embed
This is the part of the app with real privacy consequences, and they fall on the organisation that runs the Confluence site rather than on us.
When a reader opens a page containing a Remote Content macro, their browser requests the embedded address directly from whoever operates it. That is what an embed is. The operator of that site therefore receives, at minimum:
- the reader’s IP address;
- their browser’s user agent and similar request headers;
- any cookies that browser already holds for that site, which may identify the reader to it;
- the fact that the request came from a page on your Confluence site, if the browser sends a referrer.
Whatever that site then does with the request is governed by its own privacy policy, not by ours and not by Atlassian’s. Embedding a third-party site in a Confluence page is, in data-protection terms, equivalent to putting an image or a script from that site on a web page: you are directing your readers’ browsers to contact it.
We have no involvement in that exchange. We do not proxy it, log it, see it, or learn that it happened.
Two practical consequences for whoever administers the Confluence site:
Choose embedded sites deliberately. Consider what the target learns about your readers, and whether your own privacy notice should mention it. This matters most for pages that many people read, and for targets that track visitors.
The address itself is page content. Do not put credentials, tokens, or personal data in a macro URL. It is stored in the page, visible to everyone who can view or export that page, and sent to the target in the request.
5. What we receive directly
5.1 Support correspondence
If you contact support@go-atlas-inc.atlassian.net, we receive whatever you
choose to include: typically your name, email address, organisation, Confluence
site, and a description of the problem, along with any screenshots, macro
settings, or log extracts you attach.
Our support address is an Atlassian Jira Service Management address, so support tickets are stored in Atlassian’s systems on our behalf.
- Purpose: answering your request and fixing the reported problem.
- Legal basis: performance of a contract, or our legitimate interest in supporting and improving the app (GDPR Article 6(1)(b) and 6(1)(f)).
- Retention: two years from the last message in the conversation, then deletion.
Please do not send us personal data you do not need us to see. A redacted reproduction is usually enough.
5.2 Licence and installation records
Atlassian makes licence, installation, and evaluation records for the app available to us as its Marketplace provider. These typically include the Confluence site, the licence tier and status, and the technical or billing contact that the customer supplied to Atlassian.
Atlassian holds these records and determines how long they are kept. We view them in Atlassian’s Marketplace partner tools to administer licences and provide support. We do not maintain a separate copy of them, load them into any system of ours, or use them for advertising or profiling.
6. Roles under data protection law
| Data | Your organisation | Atlassian | Us |
|---|---|---|---|
| Macro configuration and Confluence page content | Controller | Processor to you | Neither controller nor processor, with no access |
| Requests your readers’ browsers make to embedded sites | Controller of the decision to embed | Not involved | Not involved |
| Support correspondence you send us | Not applicable | Processor to us (Jira Service Management) | Controller |
| Licence and installation records | Not applicable | Controller of its own records | Recipient with access, for licensing and support |
Under California law the equivalent statements are: we are not a service provider or contractor for your macro configuration or page content, because we never receive it; and we do not sell, share, or use for cross-context behavioural advertising any personal information at all.
Because the app gives us no access to your content, no data processing agreement with us is needed for it. The relevant processing agreement for content in your Confluence site is the one between your organisation and Atlassian.
7. Recipients and sub-processors
| Recipient | Role | What it involves |
|---|---|---|
| Atlassian (Atlassian Pty Ltd and affiliates) | Platform, Marketplace, and support-desk provider | Hosts Confluence and the Forge app, stores macro configuration as page content, holds licence records, and stores our support tickets |
We use no other processors for the app. There is no analytics provider, no error tracking provider, no advertising network, and no data broker in this app.
Operators of the websites you choose to embed are not our sub-processors. We have no relationship with them, and no contract with them on your behalf.
8. International transfers
We are established in Poland and handle support correspondence from within the European Economic Area.
Atlassian may process data outside the EEA and the United Kingdom under its own transfer mechanisms, including the European Commission’s standard contractual clauses. Those transfers are governed by your agreement with Atlassian and by Atlassian’s privacy policy, not by us.
A website you embed may be located anywhere. Any transfer implied by your readers contacting it is a consequence of your choice to embed it.
9. Retention
| Data | Retention |
|---|---|
| Macro configuration | For as long as the macro, the page, and the page’s history exist in your Confluence site. Governed by your own Confluence retention and trash settings. |
| Support correspondence | Two years from the last message. |
| Licence and installation records | Held and retained by Atlassian. |
| Anything the app holds in browser memory | Discarded when the page or editor is closed. |
Uninstalling the app stops it from rendering macros. It does not delete the stored macro configuration, because that is part of your page content and is held by Atlassian, not by us.
10. Cookies and browser storage
The app sets no cookies and writes nothing to localStorage, sessionStorage, or
any other browser store.
Confluence and the Forge platform set their own cookies to run the page and the app frame. Those are Atlassian’s, and Atlassian’s privacy policy and cookie notice describe them.
A website displayed inside a macro may set its own cookies in your reader’s browser, under its own domain, exactly as it would if the reader visited it directly. Those cookies are that site’s, and neither we nor Atlassian control them.
11. Your rights under the GDPR
For the personal data we control, which in practice is your support correspondence, you have the right to:
- request access to it, and a copy of it;
- have inaccurate data corrected;
- have it erased;
- have its processing restricted;
- object to processing based on our legitimate interests;
- receive it in a portable, machine-readable form.
We do not rely on consent for any of this processing, and we carry out no automated decision-making or profiling.
Write to support@go-atlas-inc.atlassian.net to exercise any of these rights.
We answer within one month, and will tell you if we need longer, as Article 12
permits. We may need to confirm who you are before acting, so that we do not
disclose one person’s data to another.
You may also complain to a supervisory authority. Ours is:
Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office)
ul. Stawki 2, 00-193 Warszawa, Poland
uodo.gov.pl
You can instead complain to the authority where you live or work.
Requests about page content or embedded sites
If your request concerns personal data that appears in a Confluence page, we cannot act on it: we have no access to that content. Send the request to the organisation that operates the Confluence site, which is the controller for it. Their Confluence administrators can edit or delete the macro, the page, and its history.
If your request concerns data held by a website that was embedded in a page, send it to the operator of that website. We have no relationship with them and cannot pass a request on.
12. Your rights in California
We honour the rights below for California residents, whether or not our processing meets the thresholds that make the CCPA and CPRA mandatory for a business.
Categories of personal information involved. Through the app itself: none. Through support requests: identifiers such as your name and email address, professional information such as your organisation and role, and the contents of your messages to us. We collect no sensitive personal information, no biometric information, no precise geolocation, and no information about anyone under 16.
Sources. You, when you contact us. Atlassian, for licence and installation records.
Purposes. Providing support, administering licences, and fixing defects. Nothing else.
Disclosure. We do not sell personal information. We do not share it for cross-context behavioural advertising. We have not done either in the preceding twelve months. The only disclosure is to Atlassian in its role as our support-desk and platform provider.
Your rights. You may request to know what we hold and how we use it, request a copy, request correction, and request deletion. You may not be discriminated against for exercising these rights. Rights to opt out of sale or sharing and to limit the use of sensitive personal information have nothing to opt out of here, because we do neither.
Send requests to support@go-atlas-inc.atlassian.net. An authorised agent may
act for you if they provide your written permission; we may still ask you to
confirm the request directly. We verify requests against the information already
in the relevant support conversation, and will ask for no more than we need.
13. Children
The app is a business tool for Confluence and is not directed at children. We do not knowingly collect personal data from anyone under 16.
14. Security
The app has no backend, no credentials, and no data store of ours, so there is no system of ours holding your data to be breached.
Embedded content is loaded into a frame by your browser and is subject to the
browser’s same-origin policy: the embedded document cannot read the Confluence
page around it, the Confluence page cannot read the embedded document, and the
app can read neither. Only http and https addresses are embedded;
javascript: and data: addresses, which would execute script, are refused.
Security and limitations describes this in full.
The control that matters is Confluence page-edit permission. Whoever can edit a page decides what its readers’ browsers will contact.
15. Changes to this policy
If we change how the app or our support process handles personal data, we update this page and change the effective date at the top. Material changes will also be noted in the app’s Marketplace release notes.
16. Contact
Krzysztof Bogdan
ul. Brzozowa 7A, 96-321 Petrykozy, Poland
NIP PL9522090225support@go-atlas-inc.atlassian.net