Vantelia

Document Control for Confluence
Privacy & Security

What the app stores, where it lives, how long it is kept, and why each Atlassian permission is requested.

The app runs entirely on Atlassian's infrastructure. No page content, no personal data and no approval record is ever transmitted to us or to any third party. We operate no servers and hold no copy of your data.

Provider: Vantelia

Contact: soporte@vantelia.es

Last updated: 23 September 2026

What the app stores

To do its job, the app records the following in Atlassian's Forge hosted storage, inside your own Atlassian cloud instance:

What the app does not do

Why each permission is requested

Every permission below is one the code actually calls. Each entry names the use, not the permission in general.

PermissionWhy it is needed
storage:app Stores the approval workflows, the rules that target them, the approval state of each governed page and the audit trail — all in Forge hosted storage inside your own instance.
read:page:confluence Reads a page's title, space and version number. The version is what tells the app that an approved page has been edited and must return for review.
read:space:confluence Resolves a page's space id to a space key. Rules that target a space match on the key, which the page API does not return.
read:label:confluence Reads a page's labels, so a rule can target pages by label. Label rules take precedence over space rules.
read:content-details:confluence Confirms that the calling user holds administrator rights before any configuration change, and reads the app's own account id, which Confluence requires to be present in a restriction the app writes.
write:content.restriction:confluence Applies the edit restriction that locks an approved page to its approvers, and lifts it again when the page is sent back for review, rejected, edited or expired.
read:confluence-content.summary Required by the platform in order to subscribe to the page-updated event. The app makes no call that uses it.

Where the data lives

In Atlassian's Forge hosted storage, within the Atlassian cloud environment of your own instance and subject to Atlassian's data residency arrangements for that instance. We have no access to it except where you explicitly share it with us in a support request.

Retention and deletion

App data is tied to the app installation. When the app is uninstalled, Atlassian soft deletes the data and retains it for 28 days before permanent deletion, under Atlassian's platform data lifecycle. Within 21 days of uninstallation a reinstallation can be relinked to the previous data, but only at the customer's request and with the customer's consent. After the retention window the data cannot be recovered.

Legal basis and your rights

Where the GDPR applies, the customer's Atlassian instance administrator is the data controller for the account identifiers and audit records described above. Those records are created and kept inside the customer's own Atlassian instance. We do not receive them, hold a copy of them or have any access to them, and we therefore act as neither a data controller nor a data processor in respect of them. Requests for access, correction, export or erasure are satisfied directly in your own instance, or by uninstalling the app. Contact us at soporte@vantelia.es for anything you cannot resolve there.

Support data

If you contact support, we receive whatever you choose to include in that message. Keep sensitive content out of support requests.

Changes

Material changes will be reflected here and the "Last updated" date revised. Continued use after a change constitutes acceptance.