Mereze Software
Data Processing Agreement
Permissions Governance for Confluence · Last updated: July 28, 2026
Parties
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) who installs or uses Permissions Governance for Confluence and Mereze Software (“Processor”, developer: Onyekachi Mbaronye).
By installing or using the App, the Controller instructs the Processor to process personal data as described below. This DPA supplements the App Terms of Service and Privacy Policy.
Subject matter and duration
The Processor provides a Forge application for Confluence Cloud that helps authorized administrators audit and manage page and folder restrictions. Processing occurs only while an authorized user actively uses the App and for the term of the customer’s subscription or until the App is uninstalled.
Nature and purpose of processing
- Display read-only audit tables of view and edit restrictions
- Detect edit restriction drift against parent content
- Apply restriction changes only after explicit admin preview and confirmation
- Export CSV reports requested by the admin in the browser
Categories of data subjects
Confluence users and groups referenced in content restriction lists (including administrators using the App).
Types of personal data
- Atlassian account IDs
- Display names and group names
- Space, page, and folder titles and identifiers
- View and edit restriction membership lists
The App does not access page body content, comments, attachments, or email addresses stored separately from Confluence API responses.
Processor obligations
- Process personal data only on documented instructions from the Controller (via use of the App)
- Ensure persons authorized to process data are bound by confidentiality
- Implement appropriate technical measures (Forge OAuth, granular scopes, preview-before-write)
- Not engage sub-processors except as listed below without informing the Controller via this published DPA
- Assist the Controller with reasonable requests regarding data subject rights, to the extent applicable and technically feasible via Atlassian APIs
- Delete or return data by ceasing processing — the App does not maintain a separate datastore; uninstalling the App ends Processor access
- Notify the Controller without undue delay if the Processor becomes aware of a personal data breach affecting the App, via [email protected]
Sub-processors
The App runs on Atlassian Forge and accesses data only through Confluence Cloud APIs. Atlassian is the infrastructure provider. No other sub-processors receive customer personal data from the Processor.
International transfers
Processing occurs within Atlassian Cloud infrastructure selected by the customer’s Confluence site. The Processor does not transfer customer data to external systems outside Atlassian.
Security
- Forge OAuth with granular Confluence scopes only
- No external network egress from the App
- Mandatory preview before any restriction write
- No persistent Processor-side storage of customer data
See also the Privacy Policy.
Audits
Upon reasonable written request, the Processor will provide information necessary to demonstrate compliance with this DPA, subject to confidentiality and frequency limits appropriate for a small software vendor.
Contact
Data protection / DPA inquiries: [email protected]
Changes
The Processor may update this DPA. Material changes will be posted on this page with an updated date. Continued use of the App after changes constitutes acceptance.