Last updated: 14 August 2026
This Data Processing Agreement ("DPA") governs the processing of personal data by the Space Access app for Confluence Cloud ("the app"), supplied by Kauê Natan Gonçalves Bidim, trading as Saoirse Software, in Ireland ("we", "us", "the Processor"). It forms part of the Terms of Service and should be read with the Privacy Policy.
How this DPA is entered into. This DPA applies automatically between us and your organisation from the moment the app is installed on your Confluence site, for as long as it remains installed. No signature is required for it to be binding. If your legal team needs a countersigned copy, or needs it attached to your own paper, email support@saoirsesoftware.com and we will sign and return it.
Your organisation — the Atlassian customer that installed the app — is the data controller. It decides who has access to which Confluence space, who reviews that access, and which changes are made. We are the data processor: we process data only to make the app work, and only on your instructions.
Your instructions are given through the app itself and through this DPA. We will not process data from your Confluence site for any other purpose — not for our own analytics, not for product research, not for marketing, and not for training any machine-learning or AI model. We do not sell personal data and receive no payment from anyone for access to it.
This app was designed to hold as little as possible, and the table below is the whole of it. The distinction that matters: what the app reads live and forgets, and what it writes down.
| Subject matter | Reviewing who can reach each Confluence space, exporting that review, and removing a person or group from several spaces at once. |
|---|---|
| Duration | For as long as the app is installed on your Confluence site. |
| Nature and purpose | Reading space permissions and displaying them; producing a spreadsheet of what is on screen; removing space permissions when an administrator confirms it; and keeping a log of the changes the app itself made. |
| Categories of data subject | People who hold a user account on your Confluence site and appear in the permissions of a space, and the administrators who use the app. |
| Read live, never stored |
|
| Written down (the only stored data) |
A change history record, written only after an administrator confirms a
bulk removal. Each record contains:
|
| Never stored | No names — not of people, not of groups, and not of spaces. No email addresses, phone
numbers or profile pictures. No page, blog, comment or attachment content. No passwords,
tokens or payment details. No analytics, no tracking, no cookies of ours.
Why space names are excluded on purpose: a personal space is named after its owner, so storing space names would have meant storing people's names without meaning to. |
| Special category data | The app has no field for health, ethnicity, beliefs or any other special category of data, and no free-text field of any kind. Nothing a person types travels into a stored record. |
Technical error lines. When a call to Confluence fails, the app writes a short diagnostic line into Atlassian's own app logging for your site (for example "the group name lookup was refused (401)"). Account IDs, group IDs and email addresses are stripped out of those lines before anything is written, and the line is truncated. Those logs are held and deleted by Atlassian, not by us.
Everything the app stores is held in Atlassian Forge storage, within the Atlassian cloud region of your own Confluence site. The app is built on Atlassian's Forge platform and declares no external network access in its manifest, which means the platform itself prevents the app from sending data to any address outside Atlassian. There is no server of ours anywhere in the path.
We carry out no international transfer of your data, because we never receive it. Any transfer that occurs is Atlassian's own, under Atlassian's terms with you and Atlassian's own transfer safeguards.
We use one sub-processor for the data in the app:
| Sub-processor | What it does | Where |
|---|---|---|
| Atlassian Pty Ltd (and its group companies) | Provides the Forge platform, the compute that runs the app and the storage that holds the change history described in section 2. | The Atlassian cloud region of your own Confluence site. |
Atlassian is already your own data processor for Confluence, under the agreement you hold directly with Atlassian. We add no other sub-processor: no analytics provider, no error-reporting service, no hosting provider of ours, no AI service.
One thing to be aware of separately: if you or your staff email our support address, that correspondence sits in a Google-hosted mailbox, which processes it as a sub-processor of that correspondence only. It never contains data pulled out of your Confluence site unless you choose to put it in the email yourself.
If we ever intend to add or replace a sub-processor, we will publish the change on this page and update the date at the top at least 30 days before it takes effect. If you object on reasonable data-protection grounds within that period, you may uninstall the app and end this DPA; billing stops under Atlassian's rules.
The app's security rests mainly on a deliberate design decision: it holds almost nothing and has nowhere to send anything. Concretely:
Being straight about the limits: we hold no security certification — no ISO 27001, no SOC 2 — and we do not claim one. We do not run a bug bounty programme or commission penetration tests. What we offer instead is a much smaller attack surface than an app with its own servers, and the platform-level assurances Atlassian publishes for Forge.
Because the app is designed so that we hold no copy of your data, everything you need you can do yourself, immediately, inside the app. We will assist where you cannot.
When a Confluence administrator uninstalls the app, Atlassian deletes the app's storage for your site as part of its normal uninstall process. We keep no copy anywhere, because we never had one, so there is nothing further for us to return or destroy. If you require written confirmation of deletion, ask and we will provide it.
Permissions that were already removed through the app stay removed — uninstalling the app does not put access back. That is a change to your Confluence site, not data of ours.
If we become aware of a personal data breach affecting personal data processed through the app, we will notify you without undue delay and in any event within 72 hours of becoming aware. The notice will describe what we know, the likely consequences and what is being done. We will assist you with your own notification duties under Articles 33 and 34 GDPR.
Two honest points about how that notice reaches you. First, the app deliberately stores no email addresses, so we will contact you using the technical contact Atlassian provides to us for your licence, and any address you have written to us from. If you want breach notices to reach a specific mailbox — a security team, a DPO — email that address to us and we will record it against your licence. Second, because the data lives in Atlassian's infrastructure and not ours, a breach of the underlying platform would be detected and notified by Atlassian under your agreement with them, and we would very likely learn of it at the same time you do.
On reasonable written request, and no more than once a year unless a breach or a supervisory authority requires otherwise, we will provide the information you need to verify our compliance with this DPA — what the app stores, which permissions it holds, and how the access rules work. Being straight again: as a sole trader we cannot host an on-site audit, and there is no infrastructure of ours to inspect. For the platform layer, Atlassian's own published compliance material is the applicable evidence.
This DPA takes effect on installation and ends when the app is uninstalled and any remaining data is deleted, whichever is later. Where its terms conflict with the Terms of Service on a matter of data protection, this DPA prevails. The liability limits in the Terms of Service apply to this DPA, except where the GDPR does not permit them to. This DPA is governed by the laws of Ireland.
If this DPA changes, the date at the top changes and the new version is published here. For changes that reduce your protections, or that add or replace a sub-processor, we give 30 days' notice on this page before they take effect.
Space Access is supplied by Kauê Natan Gonçalves Bidim, trading as Saoirse Software, in Ireland. Data protection questions, requests under this DPA and security reports all go to support@saoirsesoftware.com. Emails reach the person who writes the code.