SpaceSite Privacy Policy
This policy explains how SpaceSite processes personal data. It is written under Article 13 of the GDPR. It covers spacesite.dev, the SpaceSite app for Confluence Cloud, the sites that the service publishes, and the Space Exporter tool.
1. Controller
Luciano Salemme, sole trader (ditta individuale), Italy. Address: [INDIRIZZO]. VAT number: [PARTITA IVA]. Tax code: [CODICE FISCALE]. Email for privacy requests and support: info@spacesite.dev. No data protection officer has been appointed. The size and nature of the processing do not require one.
2. Who is controller of what
SpaceSite has two roles.
| Processing | Controller | SpaceSite role |
|---|---|---|
| Content of Confluence pages and attachments that a customer publishes | The customer (the organisation that installs the app) | Processor, under the Data Processing Agreement |
| Visitors of a published site (technical data needed to serve pages) | The customer | Processor |
| Admin account data, service emails, support, security logs, spacesite.dev visitors | Luciano Salemme | Controller |
If you want to exercise your rights on content published on a customer's site, contact that customer first. We help the customer respond. If you cannot identify the customer, write to us and we will forward your request.
3. What data we process
We process only the data listed here. We do not process any other category.
| Category | Data | Where it lives |
|---|---|---|
| Confluence admin | Atlassian accountId and display name of the admin who enables SpaceSite; Atlassian cloudId; space key | Forge hosted storage inside your Atlassian site; cloudId and space key also on Cloudflare (D1) as site identifiers |
| Published content | HTML export of the pages of the chosen space, attachments and images, page titles, hierarchy, labels, version numbers | Cloudflare R2 (EU jurisdiction) and D1 (EU location hint) |
| Author data | Author names, accountIds and avatars present in the Confluence export | Removed before publishing by default. Kept only if the customer opts in to show author names |
| Site visitors | IP address, user agent, requested URL, processed in memory to serve the page | Cloudflare Workers; technical logs for 7 days, without page content |
| Password-protected sites | A session cookie signed with HMAC; short-lived login attempt counters per IP for rate limiting | Cloudflare Workers |
| Service email | Email address you give us to receive an export link or service notices | Resend (USA) for delivery; our records |
| Billing | Handled by Atlassian (Marketplace) or, if activated, by Polar as merchant of record. We receive licence status and, from Polar, the purchaser email and order ID. We never receive card numbers | Atlassian or Polar |
| Support | Your email address and the content of your messages to info@spacesite.dev | Our mailbox |
| spacesite.dev visitors | Aggregated page views via Cloudflare Web Analytics, no cookies, no identifiers | Cloudflare |
| Usage events | Aggregated counters (pages synced, sites created) with no personal data | Cloudflare D1 |
Space Exporter (hosted version): if you paste an Atlassian API token to run an export, the token is used only for that export and is not stored after it ends [to confirm in implementation]. The export ZIP is available for 7 days and is then deleted.
We do not store Atlassian OAuth tokens on Cloudflare. We do not process special categories of data on purpose. If a customer publishes such data in a page, the customer is responsible for it.
4. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR art. 6) |
|---|---|---|
| Provide the app and publish your site | Admin data, published content | 6(1)(b) contract |
| Serve pages to visitors | Visitor technical data | 6(1)(b) contract with the customer; 6(1)(f) legitimate interest in delivering the site |
| Keep the service secure, detect abuse, troubleshoot | Logs (7 days), rate-limit counters | 6(1)(f) legitimate interest in security |
| Send service emails (export link, sync failure, important notices) | Email address | 6(1)(b) contract |
| Answer support requests | Support data | 6(1)(b) contract; 6(1)(f) for non-customers |
| Measure traffic on spacesite.dev | Aggregated analytics | No personal data processed |
| Comply with legal obligations (tax, lawful requests) | Billing records held by Atlassian or Polar | 6(1)(c) legal obligation |
We do not use your data for marketing without a separate consent. We do not profile you. No automated decision has legal effects on you.
5. Recipients
- Sub-processors: Cloudflare, Inc. (hosting, storage, delivery) and Resend, Inc. (email). Full list with roles and dates in Sub-processors.
- Atlassian: the platform on which the app runs. Atlassian processes your data under its own terms with you. Atlassian is not our sub-processor.
- Polar Software Inc. (only if activated): merchant of record for purchases outside the Marketplace. Polar is the seller of record and an independent controller for payment data.
- Public authorities, when the law requires it.
We do not sell personal data.
6. Transfers outside the EU
Cloudflare and Resend are US companies.
- Site content is stored in Cloudflare R2 with the EU jurisdiction setting. Metadata is stored in Cloudflare D1 with an EU location hint. Cloudflare Workers run on Cloudflare's global network, so a request is processed at the location closest to the visitor.
- Emails are sent through Resend in the us-east-1 region (United States).
Transfers rely on the EU Standard Contractual Clauses (Commission Decision 2021/914) included in the Cloudflare Customer DPA and in the Resend DPA, plus the vendors' supplementary measures. You can ask us for a copy of the clauses at info@spacesite.dev.
7. Retention
| Data | Retention |
|---|---|
| Worker technical logs | 7 days |
| Export ZIP files | 7 days |
| Published content, site metadata, admin data | For as long as the site is enabled. Deleted within 24 hours after you uninstall the app or delete the site |
| Session cookie (password-protected sites) | Session duration [OPEN: exact lifetime] |
| Service emails and support messages | [OPEN: proposed 24 months] |
| Billing records | Kept by Atlassian or Polar under their own policies. Any record we must hold under Italian tax law is kept 10 years |
| Backups | [OPEN: whether backups exist and for how long] |
8. Your rights
You have the right to access, rectify and erase your data, to restrict or object to processing, to data portability, and to withdraw consent where consent is the basis. Write to info@spacesite.dev. We reply within one month. We may ask you to confirm your identity.
For content on a customer's site, the customer is the controller. We forward requests we receive and help the customer act on them.
9. Complaints
You can lodge a complaint with the Italian supervisory authority: Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy, www.garanteprivacy.it. You can also contact the authority of the EU country where you live or work.
10. Cookies
- spacesite.dev: no cookies. Cloudflare Web Analytics measures traffic without cookies and without fingerprinting.
- Sites published by SpaceSite: no cookies and no analytics by default. If the customer enables password protection, the site sets one strictly necessary cookie that holds an HMAC-signed session. It is not used for tracking and does not need consent.
- Export previews on *.spacesite.dev: same rules as published sites.
Because no tracking cookie is used, we do not show a cookie banner.
11. Changes
We will publish any new version on this page with a new version number and date. Material changes are announced to customers through the Marketplace listing or by email.
12. Open points for the owner
- Fill in [INDIRIZZO], [PARTITA IVA], [CODICE FISCALE] once the tax regime is decided.
- Confirm which service emails exist (export link, sync failure, go-live confirmation) and who receives them.
- Decide retention for support emails (proposal: 24 months) and for backups, if any.
- Confirm the session cookie name and lifetime for password-protected sites.
- Verify that no Cloudflare security cookie (for example
__cf_bm) is set on published sites or custom domains; if it is, add it to section 10. - Confirm whether Polar is activated; if not, remove the Polar lines before publication.
- Confirm how the hosted Space Exporter handles the API token (in memory only, never logged).
- Check whether Cloudflare and Resend are certified under the EU-US Data Privacy Framework; if so, add it as an additional transfer basis.
- Have an Italian privacy lawyer review the text before it enters into force.