Last updated 12 September 2026
Nordantis builds small apps for the Atlassian Marketplace and Google Workspace. This policy says exactly what each app does with your data. It is written to be checked against the apps' behaviour, not to be broad enough to cover anything we might do.
The controller for the purposes of the GDPR is Ede Farkas, trading as Nordantis, Germany. The full postal address is in the Impressum. Contact: privacy@nordantis.org. There is no statutory requirement for us to appoint a data protection officer, and we have not appointed one. Registration details are in the Impressum.
This app is Runs on Atlassian. Its code and its storage are inside Atlassian's infrastructure and it makes no connections to any server outside Atlassian — including ours. We cannot see your content, and there is no Nordantis server for it to be sent to.
| What it reads | Why | What it stores |
|---|---|---|
| Space names and keys | To let you pick a space | Not stored |
| Page titles and the parent/child hierarchy | View restrictions cascade down that hierarchy, so access cannot be calculated without it | Page id, title, parent id and restriction lists, in Atlassian's storage, until you re-run or uninstall |
| Page restrictions, space permissions | This is what the report is | As above |
| Group membership and account ids | So the report says which people have access, not just which group | Account ids inside findings; no names, emails or profile data |
It does not read page bodies, attachments, comments, or anything else. It requests read scopes only and cannot change a permission.
This app connects Jira to Google Sheets, so it necessarily sends data to Google — that is what you install it to do. Specifically:
Your Google authorisation is held by Atlassian's external authentication service, not by us. You can revoke it at any time in the app settings or in your Google account.
Our apps log counts, durations and error codes — never your content. This is enforced in code: the logging helper rejects any field whose name suggests it could carry customer data, and the build fails if that check is removed. Logs are held by Atlassian and retained for a short period for diagnosis.
If you email support@nordantis.org we keep the correspondence so we can pick up the thread later. If you send us a file to reproduce a problem, we use it only for that and delete it afterwards.
| Who | What for |
|---|---|
| Atlassian | Hosts the apps, their storage and their logs; handles Marketplace billing |
| Only for the Sheets sync, and only the data you configure it to send | |
| Cloudflare | Serves this website and forwards email to our inbox |
| Stripe | Payment for non-Marketplace products. Card details go to Stripe and never to us |
Under the GDPR you can ask what we hold, ask for it to be corrected or deleted, and object to processing. Email privacy@nordantis.org and you will get a reply from a person within a few days. In practice the honest answer for the Confluence app is that we hold nothing: uninstalling it removes its storage from your site.
App data lives wherever your Atlassian site lives; we do not move it. This website is served from Cloudflare's network.
If this policy changes in a way that affects what an app does with your data, the change is listed in that app's changelog as well as here. The date at the top is the last change.