Privacy Policy
Last Updated: 10 August 2026
DailyMind LTD ("we," "us," or "our"), the company behind Compliance Glossary for Confluence ("the App"), is committed to protecting user privacy. This policy describes Marketplace production version 4 (v4). It does not authorise or describe customer use of internal staging beta capabilities.
Data Controller Identity
DailyMind is the controller for this marketing website. For App data, the customer organisation is the controller and DailyMind processes that data on its documented instructions.
DailyMind LTD
Registration number: HE 439959
Registered address: Idaliou 19, GALAXIA COURT, Flat/Office 201, 3021 Limassol, Cyprus
VAT: CY10439959M
Email: [email protected]
Legal Basis for Processing
For App data, the customer organisation determines the applicable GDPR legal basis. DailyMind processes App data only to provide and support the service under the customer’s documented instructions. For website data, DailyMind uses the legal bases stated in the relevant sections below.
Data Storage and Processing
In v4, the App stores data exclusively within Atlassian Forge's Entity Store, which is hosted and managed by Atlassian. Data is isolated per installation — no installation can access another's data. DailyMind does not operate an external database or server for this App.
The App stores the following data:
- Glossary terms — term names, definitions, categories, synonyms, notes, and status (draft, review, approved, deprecated)
- Version history — a record of every change to each term, including previous definitions, timestamps, and the type of change
- Scan results — compliance scan findings per Confluence page, including page ID, page title, space key, scan timestamp, and identified issues
- User account IDs — Atlassian account IDs of users who create, edit, approve, submit for review, or resolve compliance findings. They support the App’s audit trail. We do not store names, emails, or other profile data.
How We Access Confluence Content
The App reads Confluence page content solely for compliance scanning — checking pages for deprecated terms, unapproved terminology, and synonym enforcement. This access is read-only. The App does not modify, delete, or create Confluence pages.
The App's Confluence permissions are limited to:
- Reading page content and summaries
- Reading space information
- Searching content for scanning purposes
Page content is processed in-memory during scans. We do not store full page content — only scan findings (which term was flagged, on which page, and why).
Automatic Scanning
The App automatically scans pages when they are created or updated in Confluence. This is handled by Atlassian Forge's event trigger system. Scan results are stored in the Entity Store as described above.
Data Isolation
All data is scoped to your Atlassian installation. Each installation operates in a completely isolated environment provided by the Forge platform. No data is shared between installations.
No External Data Transmission
Marketplace production v4: the App does not send app data to external servers, third-party services, or DailyMind's own infrastructure. It makes no external API calls and contains no app analytics, telemetry, or tracking calls.
Internal staging v5 beta: AI-assisted curation, terminology-manifest import, and the GitHub connector are not enabled for customers or publicly available. The Git beta workflows are default off. Before DailyMind enables any beta capability for a customer, it will approve the specific data flow, retention, access, processor/transfer terms, and Marketplace/privacy disclosures for that version and customer use.
Terminology Packets (Lead Magnets)
Some pages on this website offer free terminology packets for AI Act, SOC 2, ISO 27001, FDA, DORA, NIS2, and HIPAA. To receive a packet, you provide your email address and explicit consent. Your email is:
- Sent to Resend, Inc. (US-based email delivery service) to deliver the packet to your inbox
- Sent to DailyMind's founder mailbox as a lead notification for one direct follow-up about the packet and terminology governance
- Not added to any bulk newsletter or automated marketing campaign
Resend processes data under their Privacy Policy. As Resend is a US-based processor, this constitutes an international data transfer from the EEA to the US, covered by Resend's Standard Contractual Clauses (SCCs) with their infrastructure providers.
Website Infrastructure
This marketing website (compliance-glossary.teamkit.dev) is served via Cloudflare, Inc. (USA), which acts as a processor for site hosting, edge CDN, TLS termination, and DDoS mitigation. When you visit this website, Cloudflare processes your IP address, user-agent, request path, and TLS fingerprint to deliver pages and protect against attacks.
- Processor: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA
- Purpose: Site hosting, edge content delivery, TLS termination, DDoS mitigation (compliance-glossary.teamkit.dev marketing site)
- Legal basis: Art. 6(1)(f) — legitimate interest in website availability, performance, and security
- Data retention: Raw request logs: typically up to 7 days; aggregated analytics data: up to 13 months. See Cloudflare Privacy Policy.
- International transfer: Data transfers to Cloudflare, Inc. (United States) rely on Standard Contractual Clauses (SCCs, Commission Implementing Decision (EU) 2021/914, Module 4). EU-US Data Privacy Framework status independently verifiable at https://www.dataprivacyframework.gov/list.
- DPA: Cloudflare Customer DPA
Chat Assistant (Marketing Website)
This marketing website includes an in-page chat assistant for pre-sales support and product questions. The widget is loaded on every public page. If you choose to interact with it, the following processing occurs:
- Purpose — Pre-sales support: answering questions about features, pricing, compliance scope, and onboarding; and improving support quality by reviewing past conversations.
- Processors (two) —
- Anthropic PBC (United States) — processes each message in real time to generate the assistant's reply, using the claude-haiku-4-5 model. See Anthropic's Privacy Policy, Commercial Terms, and Data Processing Addendum.
- Resend, Inc. (United States) — when you close the chat panel or leave the page, the full conversation transcript is sent via Resend to DailyMind's support inbox ([email protected]) so our team can review it for support quality and product improvement. See Resend's Privacy Policy and Data Processing Addendum.
- Data sent to Anthropic — The most recent conversation turns (capped at 10 messages, max 1000 characters per message) plus a fixed system prompt. Inputs are sanitized to strip prompt-injection patterns before transmission.
- Data sent to Resend & emailed to DailyMind — The full conversation transcript (your messages and the assistant's replies), the page path you were on, the question count, and a timestamp. Do not paste personal, confidential, or regulated data into the chat — it will be emailed to and read by our support team.
- Retention —
- Anthropic: subject to Anthropic's retention terms for commercial API traffic (commercial API inputs are excluded from training).
- Resend: email delivery logs are retained per Resend's plan-based log retention (see https://resend.com/legal/dpa).
- DailyMind support inbox: transcripts are retained for up to 90 days for support quality and continuous improvement, then deleted. We do not use chat transcripts to train any models.
- Legal basis — Legitimate interest (GDPR Art. 6(1)(f)) in (a) providing pre-sales information to website visitors via Anthropic, and (b) reviewing chat transcripts via Resend/email for support quality and product improvement. You can object to this processing simply by not using the chat.
- International transfer — Both Anthropic and Resend are US-based, so use of the chat involves transfer of your inputs from the EEA to the United States. Transfers to Anthropic PBC and Resend, Inc. rely on Standard Contractual Clauses (SCCs) per Commission Implementing Decision (EU) 2021/914, Module 2 (controller-to-processor), as set out in each provider’s Data Processing Addendum. EU-US Data Privacy Framework status independently verifiable at https://www.dataprivacyframework.gov/list.
- User control — The widget never sends data unless you type a message and submit it. The transcript email is sent only after at least one user message has been exchanged. If you do not want any of this processing to occur, do not interact with the chat.
Cookies and Tracking
The Confluence App does not use cookies, local storage, or any client-side tracking mechanisms. There is no analytics or telemetry in the app itself.
This marketing website (compliance-glossary.teamkit.dev) uses the following privacy-friendly, cookieless analytics:
- Umami for anonymous page view statistics. Umami is self-hosted within the EU, does not use cookies, does not collect personal data, and does not track individual users.
- GoatCounter for lightweight, cookieless page view counting. GoatCounter is self-hosted within the EU (Hetzner, Germany), open-source, does not use cookies, does not collect personal data, and does not track individual users.
- Cloudflare Web Analytics for aggregated page-performance metrics. It is cookie-free and does not track visitors across websites.
No cookie consent banner is required for these three cookieless analytics tools.
Data Retention
Data persists in the Entity Store for as long as the App is installed. When you uninstall the App, all per-installation data in the Forge Entity Store is removed per Atlassian’s published Forge data lifecycle and Standard Data Retention and Disposal policy (see Atlassian Forge data lifecycle). We recommend exporting any needed compliance reports before uninstalling.
Audit Export
Exported CSV files are generated on-demand and delivered directly to the requesting user's browser — they do not pass through any external server.
Personal Data Reporting and GDPR
For Marketplace production v4, the App uses Atlassian's Personal Data Reporting API as part of its account-data lifecycle handling:
- Personal data reporting — The App runs a weekly job to report stored Atlassian account IDs to the Atlassian platform.
- Right to erasure — When the platform signals that a user account has been closed, the App automatically anonymizes all references to that account ID across glossary terms, version history, finding resolutions, and access control lists. Anonymized entries are replaced with a generic "Deleted user" marker.
- Uninstall cleanup — When the App is uninstalled, all per-installation data in the Forge Entity Store is removed per Atlassian’s published Forge data lifecycle and Standard Data Retention and Disposal policy (see Atlassian Forge data lifecycle).
This describes application controls, not a representation that the App alone ensures a customer’s GDPR compliance or determines the customer’s controller obligations. Customer beta use of v5 requires a completed data-flow and processing record before enablement.
Your Rights
Rights re: App data (DailyMind as Processor)
For data processed by the Compliance Glossary app inside your Atlassian Confluence instance, your organisation is the controller. Exercise GDPR Art. 15–22 rights (access, rectification, erasure, restriction, portability, objection) via your organisation’s Atlassian site administrator. DailyMind acts on the customer’s documented instructions and cannot independently fulfil data subject requests for Forge-stored data.
Your Atlassian site administrator can:
- View all stored glossary terms and scan results through the App’s interface
- Export data via the audit export feature
- Remove the App (and all its stored data) by uninstalling it
Rights re: website and marketing data (DailyMind as Controller)
For data we collect as controller on this marketing website (template-request emails, chat transcripts, contact enquiries), you have the following rights under GDPR:
- Art. 15 — Access: you can request a copy of the personal data we hold about you.
- Art. 16 — Rectification: you can ask us to correct inaccurate or incomplete personal data.
- Art. 17 — Erasure: you can ask us to delete your personal data where there is no overriding legitimate ground for retention.
- Art. 18 — Restriction: you can ask us to restrict processing of your data while a dispute is resolved.
- Art. 20 — Portability: you can receive your data in a structured, machine-readable format and transmit it to another controller.
- Art. 21 — Objection: you can object to processing carried out on the basis of legitimate interest (Art. 6(1)(f)).
- Art. 22 — Automated decision-making: you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not carry out such processing.
Contact [email protected] to exercise any of the above rights. We will respond within one month of receipt (GDPR Art. 12(3)).
Children and Minors
The App and this website are B2B tools intended for use by business professionals. We do not knowingly process personal data of individuals under 16. If you believe a minor has interacted with our services, contact [email protected] for immediate deletion.
Right to Lodge a Complaint
If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent supervisory authority. The supervisory authority for DailyMind LTD is:
Office of the Commissioner for Personal Data Protection (Cyprus)
1 Iasonos Street, 1082 Nicosia, Cyprus
Email: [email protected]
Website: https://www.dataprotection.gov.cy
You may also lodge a complaint with the supervisory authority of your EEA Member State of habitual residence or place of the alleged infringement (GDPR Art. 13(2)(d)).
No DPO Appointed
DailyMind LTD is not required to appoint a Data Protection Officer under GDPR Art. 37, as we do not carry out large-scale systematic monitoring or process special categories of data as a core activity. For privacy inquiries, contact [email protected].
Automated Decision-Making
We do not use automated decision-making or profiling as defined in GDPR Art. 22. No decisions with legal or similarly significant effects are made solely by automated processing.
Consent Withdrawal
You may withdraw your consent at any time by contacting [email protected]. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be reflected on this page with an updated date.
Contact
Questions? Contact us at [email protected].