SpaceSite Data Processing Agreement
This agreement ("DPA") is part of the SpaceSite End User Licence Agreement. It applies when SpaceSite processes personal data on behalf of a customer. It follows Article 28 of the GDPR.
1. Parties and roles
- Controller: the customer, meaning the organisation that installs the SpaceSite app in its Atlassian Cloud site and enables a space for publication ("Customer").
- Processor: Luciano Salemme, sole trader, [INDIRIZZO], VAT [PARTITA IVA] ("SpaceSite").
Atlassian is not a party to this DPA and is not SpaceSite's sub-processor. Atlassian processes the Customer's data under the Customer's own agreement with Atlassian. The Forge app stores its settings in Forge hosted storage inside the Customer's Atlassian site. SpaceSite never stores Atlassian access tokens outside Atlassian.
2. Subject matter, duration, nature and purpose
| Item | Description |
|---|---|
| Subject matter | Publishing the content of one or more Confluence spaces as a static website on a domain chosen by the Customer, and keeping it in sync |
| Duration | From the moment the Customer enables a space until 24 hours after the Customer uninstalls the app or deletes the site, when deletion is complete |
| Nature | Receiving, converting, storing, hosting, serving, synchronising and deleting content; sending service emails |
| Purpose | To provide the service described in the EULA, as configured by the Customer in the app |
3. Types of personal data and data subjects
| Types of personal data | Data subjects |
|---|---|
| Any personal data contained in the pages and attachments the Customer chooses to publish (names, contact details, images, text) | Persons mentioned or shown in the content; the Customer's staff |
| Page metadata: titles, hierarchy, labels, version numbers | The Customer's authors |
| Author names, accountIds and avatars present in the Confluence export. Removed by default before publishing; processed only if the Customer opts in to show them | The Customer's authors |
| accountId and display name of the admin who enabled the space; cloudId; space key | The Customer's admin |
| Technical data of visitors of the published site (IP address, user agent, requested URL), processed transiently; logs kept 7 days without content | Visitors of the published site |
| Email address of the admin, if provided, for service emails | The Customer's admin |
The service is not designed for special categories of data (Article 9) or criminal data (Article 10). The Customer must not publish such data through SpaceSite.
4. Instructions
SpaceSite processes personal data only on the Customer's documented instructions. The instructions are: this DPA, the EULA, and the settings the Customer selects in the app (space selection, go-live confirmation, exclusion labels, author display, password protection, site deletion).
If EU or Member State law requires SpaceSite to process data otherwise, SpaceSite informs the Customer before processing, unless the law forbids it. SpaceSite informs the Customer if an instruction appears to infringe data protection law.
5. Obligations of SpaceSite
- Confidentiality. SpaceSite is operated by one person. Anyone else given access in the future will be bound by a written confidentiality duty.
- Security. SpaceSite applies the measures in Annex 1 and keeps them up to date.
- Assistance with data subject rights. SpaceSite forwards requests it receives to the Customer within 5 business days and helps the Customer respond, through deletion, re-sync or export tools.
- Assistance with Articles 32 to 36. SpaceSite supports the Customer's security assessments, breach notifications and data protection impact assessments with the information it holds.
- Personal data breach. SpaceSite notifies the Customer without undue delay after becoming aware of a breach affecting the Customer's data, and in any case within [OPEN: proposed 48 hours]. The notice contains what is known at that time and is completed as information becomes available.
- Records. SpaceSite keeps a record of processing activities and makes it available on request.
- Transparency. SpaceSite publishes its security measures at security.md and its sub-processors at subprocessors.md.
6. Sub-processors
The Customer gives general written authorisation to the sub-processors listed below and in subprocessors.md.
| Sub-processor | Service | Location | Data | Transfer basis |
|---|---|---|---|---|
| Cloudflare, Inc. | Workers (compute), D1 (metadata), R2 (content, EU jurisdiction), Cache, custom hostnames and TLS | USA; EU storage settings | All data in section 3 | Cloudflare Customer DPA with EU SCCs (module 3) |
| Resend, Inc. | Transactional email | USA, region us-east-1 | Admin email address and email content | Resend DPA with EU SCCs (module 3) |
| Polar Software Inc. (conditional, only if activated) | Merchant of record for purchases outside the Atlassian Marketplace | USA | Purchaser email, order data. Polar acts as seller of record and independent controller for payments, not as processor of Customer content | Polar privacy terms; DPA to be obtained |
Changes. SpaceSite publishes any new or replaced sub-processor on the sub-processors page at least 30 days before it starts processing Customer data, and notifies Customers who have asked to be notified by email. The Customer may object in writing within those 30 days on reasonable data protection grounds. If no solution is found, the Customer may terminate the service by uninstalling the app; deletion then follows section 8.
SpaceSite imposes on each sub-processor data protection obligations equivalent to this DPA and remains liable to the Customer for the sub-processor's performance.
7. International transfers and data residency
- Cloudflare and Resend are established in the United States. Transfers are covered by the EU Standard Contractual Clauses (Decision 2021/914) incorporated in each vendor's DPA, plus the vendors' supplementary measures.
- Content is stored in Cloudflare R2 with the EU jurisdiction setting. Metadata is stored in D1 with an EU location hint. Cloudflare Workers run on Cloudflare's global network: a visitor's request is processed at the Cloudflare location closest to that visitor.
- Emails are processed in the Resend us-east-1 region.
- Atlassian data residency. SpaceSite stores published content outside Atlassian. In its current version the app does not use region-specific remote endpoints. The app is therefore not eligible for Atlassian's "PINNED" data residency status, and the Marketplace listing states that data residency is not supported. The Customer must not rely on Atlassian data residency for data processed by SpaceSite. [NOT VERIFIED: wording to be aligned with the Atlassian listing after Phase 0]
- The Customer decides which data is in scope. Pages with view restrictions are never exported. Pages labelled
spacesite-excludeare never exported.
8. Deletion and return
- When the Customer uninstalls the app or deletes a site, SpaceSite deletes the site's objects in R2, its rows in D1 and its custom hostname within 24 hours.
- Export ZIP files are available for 7 days and are then deleted.
- Technical logs expire after 7 days.
- Service emails and support messages follow the retention stated in the privacy policy.
- Backups: [OPEN: state whether backups exist, where, and the deletion delay].
- Return. The Customer's content remains in Confluence at all times. On request, SpaceSite provides a ZIP export of the published site before deletion.
- SpaceSite confirms deletion in writing on request.
9. Audit
SpaceSite makes available the information needed to demonstrate compliance with Article 28: this DPA, the security page, the sub-processor list, and the compliance reports of its sub-processors (for example Cloudflare's SOC 2 and ISO 27001 reports, available under Cloudflare's terms).
The Customer may audit SpaceSite's own systems once per 12 months, with 30 days' written notice, during business hours, at the Customer's cost, and without disrupting the service. SpaceSite has no physical premises dedicated to the service; audits of cloud providers are satisfied through their reports and certifications. Extra audits are allowed after a breach or on request of a supervisory authority.
10. Liability, term and law
- The liability rules of the EULA apply to this DPA.
- This DPA lasts as long as SpaceSite processes Customer data and until deletion is complete.
- Italian law applies. Jurisdiction: [OPEN: court chosen in the EULA]. Mandatory GDPR rules prevail over anything in this DPA.
Annex 1. Technical and organisational measures
| Area | Measure |
|---|---|
| Transport encryption | TLS 1.2 or higher on all connections: Atlassian to Forge, Forge to api.spacesite.dev, Cloudflare to visitors, custom domains with automatic certificates |
| Encryption at rest | R2 and D1 data is encrypted at rest by Cloudflare |
| Authentication between app and API | Every request from the Forge app to api.spacesite.dev is signed with HMAC-SHA256 over a timestamp and the body. Requests with a stale timestamp or an invalid signature are rejected and logged |
| Secrets | HMAC secret stored as an encrypted Forge variable, separate per environment, rotation procedure documented. No secrets in the app bundle, verified before each release |
| Least privilege | Read-only Confluence scopes plus app storage. No write scopes. Egress allowed only to api.spacesite.dev |
| No credentials outside Atlassian | Atlassian OAuth tokens never leave Atlassian. Cloudflare holds no Atlassian credentials |
| Data minimisation | Author names, accountIds and avatars stripped by default. Pages with view restrictions and pages labelled spacesite-exclude never exported. Private preview before go-live, explicit confirmation required |
| Access to published sites | Public by design, or protected by a per-site password with an HMAC-signed session cookie and rate limiting on login attempts |
| Logging | Worker logs kept 7 days, no page content, no tokens. Usage events aggregated, no personal data |
| Deletion | Automatic purge within 24 hours after uninstall or site deletion. ZIP files deleted after 7 days |
| Account security | Multi-factor authentication on Cloudflare, Atlassian developer, Resend and domain registrar accounts |
| Software supply chain | Dependencies pinned and updated; passive scanning by Atlassian Ecoscanner accepted |
| Vulnerability handling | Responsible disclosure at info@spacesite.dev, first response within 5 business days |
11. Open points for the owner
- Fill in [INDIRIZZO] and [PARTITA IVA].
- Decide the breach notification deadline to customers (proposal: 48 hours after awareness).
- Decide whether backups of R2 and D1 exist; if yes, state location and deletion delay in section 8.
- Choose the court for disputes (same as the EULA).
- Confirm the Atlassian data residency wording after the Phase 0 verdict (13/10/2026) and the listing text.
- Confirm whether Polar is activated; if not, remove the Polar row. If yes, obtain Polar's DPA link.
- Decide whether to offer email notification of sub-processor changes, and how customers subscribe.
- Ask for a lawyer's review before the DPA enters into force.