Privacy Policy

Last Updated: 10 August 2026

DailyMind LTD ("we," "us," or "our"), the company behind Compliance Glossary for Confluence ("the App"), is committed to protecting user privacy. This policy describes Marketplace production version 4 (v4). It does not authorise or describe customer use of internal staging beta capabilities.

Data Controller Identity

DailyMind is the controller for this marketing website. For App data, the customer organisation is the controller and DailyMind processes that data on its documented instructions.

DailyMind LTD
Registration number: HE 439959
Registered address: Idaliou 19, GALAXIA COURT, Flat/Office 201, 3021 Limassol, Cyprus
VAT: CY10439959M
Email: [email protected]

Legal Basis for Processing

For App data, the customer organisation determines the applicable GDPR legal basis. DailyMind processes App data only to provide and support the service under the customer’s documented instructions. For website data, DailyMind uses the legal bases stated in the relevant sections below.

Data Storage and Processing

In v4, the App stores data exclusively within Atlassian Forge's Entity Store, which is hosted and managed by Atlassian. Data is isolated per installation — no installation can access another's data. DailyMind does not operate an external database or server for this App.

The App stores the following data:

How We Access Confluence Content

The App reads Confluence page content solely for compliance scanning — checking pages for deprecated terms, unapproved terminology, and synonym enforcement. This access is read-only. The App does not modify, delete, or create Confluence pages.

The App's Confluence permissions are limited to:

Page content is processed in-memory during scans. We do not store full page content — only scan findings (which term was flagged, on which page, and why).

Automatic Scanning

The App automatically scans pages when they are created or updated in Confluence. This is handled by Atlassian Forge's event trigger system. Scan results are stored in the Entity Store as described above.

Data Isolation

All data is scoped to your Atlassian installation. Each installation operates in a completely isolated environment provided by the Forge platform. No data is shared between installations.

No External Data Transmission

Marketplace production v4: the App does not send app data to external servers, third-party services, or DailyMind's own infrastructure. It makes no external API calls and contains no app analytics, telemetry, or tracking calls.

Internal staging v5 beta: AI-assisted curation, terminology-manifest import, and the GitHub connector are not enabled for customers or publicly available. The Git beta workflows are default off. Before DailyMind enables any beta capability for a customer, it will approve the specific data flow, retention, access, processor/transfer terms, and Marketplace/privacy disclosures for that version and customer use.

Terminology Packets (Lead Magnets)

Some pages on this website offer free terminology packets for AI Act, SOC 2, ISO 27001, FDA, DORA, NIS2, and HIPAA. To receive a packet, you provide your email address and explicit consent. Your email is:

Resend processes data under their Privacy Policy. As Resend is a US-based processor, this constitutes an international data transfer from the EEA to the US, covered by Resend's Standard Contractual Clauses (SCCs) with their infrastructure providers.

Website Infrastructure

This marketing website (compliance-glossary.teamkit.dev) is served via Cloudflare, Inc. (USA), which acts as a processor for site hosting, edge CDN, TLS termination, and DDoS mitigation. When you visit this website, Cloudflare processes your IP address, user-agent, request path, and TLS fingerprint to deliver pages and protect against attacks.

Chat Assistant (Marketing Website)

This marketing website includes an in-page chat assistant for pre-sales support and product questions. The widget is loaded on every public page. If you choose to interact with it, the following processing occurs:

Cookies and Tracking

The Confluence App does not use cookies, local storage, or any client-side tracking mechanisms. There is no analytics or telemetry in the app itself.

This marketing website (compliance-glossary.teamkit.dev) uses the following privacy-friendly, cookieless analytics:

No cookie consent banner is required for these three cookieless analytics tools.

Data Retention

Data persists in the Entity Store for as long as the App is installed. When you uninstall the App, all per-installation data in the Forge Entity Store is removed per Atlassian’s published Forge data lifecycle and Standard Data Retention and Disposal policy (see Atlassian Forge data lifecycle). We recommend exporting any needed compliance reports before uninstalling.

Audit Export

Exported CSV files are generated on-demand and delivered directly to the requesting user's browser — they do not pass through any external server.

Personal Data Reporting and GDPR

For Marketplace production v4, the App uses Atlassian's Personal Data Reporting API as part of its account-data lifecycle handling:

This describes application controls, not a representation that the App alone ensures a customer’s GDPR compliance or determines the customer’s controller obligations. Customer beta use of v5 requires a completed data-flow and processing record before enablement.

Your Rights

Rights re: App data (DailyMind as Processor)

For data processed by the Compliance Glossary app inside your Atlassian Confluence instance, your organisation is the controller. Exercise GDPR Art. 15–22 rights (access, rectification, erasure, restriction, portability, objection) via your organisation’s Atlassian site administrator. DailyMind acts on the customer’s documented instructions and cannot independently fulfil data subject requests for Forge-stored data.

Your Atlassian site administrator can:

Rights re: website and marketing data (DailyMind as Controller)

For data we collect as controller on this marketing website (template-request emails, chat transcripts, contact enquiries), you have the following rights under GDPR:

Contact [email protected] to exercise any of the above rights. We will respond within one month of receipt (GDPR Art. 12(3)).

Children and Minors

The App and this website are B2B tools intended for use by business professionals. We do not knowingly process personal data of individuals under 16. If you believe a minor has interacted with our services, contact [email protected] for immediate deletion.

Right to Lodge a Complaint

If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent supervisory authority. The supervisory authority for DailyMind LTD is:

Office of the Commissioner for Personal Data Protection (Cyprus)
1 Iasonos Street, 1082 Nicosia, Cyprus
Email: [email protected]
Website: https://www.dataprotection.gov.cy

You may also lodge a complaint with the supervisory authority of your EEA Member State of habitual residence or place of the alleged infringement (GDPR Art. 13(2)(d)).

No DPO Appointed

DailyMind LTD is not required to appoint a Data Protection Officer under GDPR Art. 37, as we do not carry out large-scale systematic monitoring or process special categories of data as a core activity. For privacy inquiries, contact [email protected].

Automated Decision-Making

We do not use automated decision-making or profiling as defined in GDPR Art. 22. No decisions with legal or similarly significant effects are made solely by automated processing.

Consent Withdrawal

You may withdraw your consent at any time by contacting [email protected]. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be reflected on this page with an updated date.

Contact

Questions? Contact us at [email protected].