1. Roles and scope
Customer is the controller of Customer Data, and Provider is the processor. Provider processes Customer Data only to provide, secure, support, and improve the operation of IntelliGlossary in accordance with Customer's documented instructions and the Agreement. This DPA does not apply to data Provider processes as an independent controller for its own legal, security, billing, or support obligations.
2. Processing details
Subject matter and purpose
The subject matter is the provision of glossary management, discovery, review, import and export, audit, permissions, and optional AI-assisted definition features for Customer's Confluence site.
Data categories
- Confluence and glossary content, including terms, definitions, aliases, categories, translations, labels, owner references, source links, discovery candidates, and bounded page excerpts.
- Atlassian account identifiers and display names associated with glossary creators, administrators, reviewers, and audited actions.
- Language or locale settings, configuration values, usage records, timestamps, and audit events required to operate the app.
- Optional AI request data, such as a term, a limited context excerpt, and a language tag, only when an administrator enables AI and requests a suggestion.
Data subjects
Data subjects may include Customer's employees, contractors, users, collaborators, and other individuals whose information appears in Customer's Confluence content or app records.
3. Provider obligations
Provider will:
- Process Customer Data only for the purposes described in this DPA, the Agreement, or Customer's documented instructions.
- Ensure that people authorized to process Customer Data are subject to confidentiality obligations.
- Maintain appropriate technical and organizational measures designed to protect Customer Data against unauthorized access, alteration, disclosure, loss, or destruction.
- Apply app-level authorization and tenant isolation controls and use Atlassian Forge hosted storage for core app data.
- Notify Customer without undue delay after becoming aware of a security incident affecting Customer Data and provide reasonably available information needed for Customer's response.
- Provide reasonable assistance with data-subject requests, investigations, and regulatory inquiries relating to Provider's processing.
4. Subprocessors
Customer authorizes Provider to use subprocessors necessary to provide IntelliGlossary. The primary subprocessor is Atlassian, which provides the Forge runtime, hosted storage, authentication, and access to Confluence APIs under the Forge Data Processing Addendum.
When Customer enables the optional AI Definition Assistant, the selected AI provider may process the limited request data described above. If Provider offers built-in AI models, those AI providers act as Provider's subprocessors. If Customer configures a custom endpoint or supplies their own API key, that AI service acts as Customer's direct processor, and Customer should select a provider plan with appropriate data-processing and international-transfer terms for its requirements.
Provider will require subprocessors to protect Customer Data through written obligations appropriate to their role. Provider remains responsible for its subprocessors' processing to the extent required by applicable law.
5. International transfers
Atlassian's Forge processing is governed by the Forge DPA, which includes applicable Standard Contractual Clauses and related transfer provisions. For optional external AI processing, the transfer mechanism and data-protection terms depend on the provider and plan selected by Customer. Customer must not enable an external AI provider for regulated data unless the selected provider's terms satisfy Customer's transfer requirements.
6. Customer responsibilities
Customer is responsible for providing lawful instructions, giving required notices, obtaining required permissions, configuring app and AI settings appropriately, limiting access to authorized users, and determining whether particular Customer Data is suitable for processing by IntelliGlossary or an optional AI provider.
7. Return and deletion
Provider will delete or return Customer Data at Customer's direction where technically feasible, unless applicable law requires retention. On app uninstall, data stored in Forge hosted storage follows Atlassian's app data lifecycle and deletion process. Customer may also use the app's administrative features to export or delete glossary records before uninstalling. Provider also supports automated account anonymization for individual data subjects in response to Atlassian Forge workspace-forget events, as detailed in the Privacy Policy.
8. Audits and information
Provider will make available information reasonably necessary to demonstrate compliance with this DPA and will cooperate with reasonable Customer audit requests, subject to confidentiality, security, and the protection of other customers' information. Public security, privacy, and subprocessors information may be provided through the Security Policy and related documentation.
9. Priority and changes
If this DPA conflicts with the Terms of Use regarding the processing of personal data, this DPA controls for that conflict. Provider may update this DPA when IntelliGlossary, its subprocessors, or applicable requirements change. Provider will publish the updated version and update the effective date.