Summary
- The app keeps your data inside Atlassian. Compliance in a Box runs entirely on Atlassian Forge. It calls no external services, and Auralite Solutions has no access to the data it stores.
- People are stored as Atlassian account IDs only. The app never stores names or email addresses of your users.
- This website doesn't track you. It sets no cookies, runs no analytics and loads nothing from third parties.
- We only see what you send us. If you email support, we use your message to help you.
Who we are
Compliance in a Box is made by Auralite Solutions ("Auralite", "we", "us"). This policy covers:
- the Compliance in a Box app for Confluence Cloud (the "app"),
- this website at compliance.auralitesolutions.com (the "website"), and
- emails and other messages you send us.
Atlassian's own handling of data in Confluence Cloud and the Atlassian Marketplace is covered by Atlassian's Privacy Policy, not this one.
The app
Where the app runs and stores data
The app is built on Atlassian Forge and carries the "Runs on Atlassian" designation. Its code runs on Atlassian's infrastructure, and its records are stored in Forge hosted storage that belongs to your Atlassian site's installation of the app. The app has no connections to external domains, no remote back end operated by Auralite, and uses no subprocessors other than Atlassian. Data residency is supported: app data follows the data residency location of your Confluence site.
Your policies, evidence pages and generated reports are ordinary Confluence pages in your own compliance space. Confluence stores them, not the app.
What the app stores
| Category | Examples |
|---|---|
| Atlassian account IDs | Policy and activity owners, approvers, submitters, people asked to acknowledge a policy, reminder recipients, and the people who performed each recorded action. No names, email addresses or other profile details are stored. Names are looked up live from Atlassian when a page is displayed. |
| Compliance workflow records | Policy versions (page ID, version number, content hash, change summary), approvals and rejections with the approver's comment, acknowledgements, recurring-activity periods and submissions with notes, skip reasons, and a reminder log. |
| Audit log | An append-only record of the actions above, kept as compliance evidence. |
| Settings | Confluence group IDs (employees, admins, optional auditors), company name, fiscal year, and the security contact, which is either a person's account ID or an organizational mailbox your admin enters. |
| Imported text (temporary) | When an admin imports a policy from another page, the source text is held briefly until it is written to the target page, then deleted. |
Who controls app data
Your organization decides what goes into its compliance program and is responsible for that data. Atlassian hosts it. Auralite does not receive, view or export it: there is no Auralite server for the app to send data to. The Forge logs that Atlassian makes available to us for troubleshooting contain identifiers and error codes only, never page content, names or email addresses.
Closed and deactivated accounts
The app reports the account IDs it stores to Atlassian's personal data reporting service at least once every seven days, as Atlassian requires. When Atlassian reports that an account has been closed, the app erases it: the account ID is replaced by a random placeholder everywhere it appears, including the audit log, so records stay consistent but the person can no longer be identified, and the app shows "Former user". Deactivated accounts stop being asked to acknowledge policies.
Uninstalling
App data is kept while the app is installed. When you uninstall, Atlassian deletes the app's hosted storage after its retention period. Your Confluence pages, including the generated Evidence & Reports pages, stay in your space.
This website
The website is a set of static pages. It has no sign-in, no forms, no cookies, no analytics and no advertising, and it loads no fonts, scripts or images from third parties.
The website is hosted on GitHub Pages. Like any web host, GitHub receives your IP address and basic request details when you visit, and may log them for security and operations. See the GitHub General Privacy Statement. We do not receive those logs.
Support and sales
When you email us, we receive your name, email address, the content of your message and anything you attach. We use it to answer you, fix problems and improve the app. Please don't send us passwords, API tokens or sensitive personal data. If a screenshot or export is useful, remove personal details you don't need to share.
As a Marketplace vendor, Atlassian shares some licensing information with us, such as your site's address, license tier and the technical and billing contacts on the license. We use it to manage licenses, provide support and send essential service notices. We don't use it for advertising.
Sharing
We don't sell or rent personal information and don't share it for advertising. We share information only:
- with service providers that help us run our business, such as our email provider, under confidentiality obligations;
- when required by law, or to protect the rights, safety and security of our users, Atlassian or Auralite;
- as part of a merger, acquisition or sale of assets, in which case this policy continues to apply.
Retention
- App data: kept in your Forge hosted storage while the app is installed, then deleted by Atlassian after uninstall as described above.
- Support messages: kept as long as needed to resolve your request and keep a reasonable support history, then deleted.
- Licensing information: kept while you hold a license and as long afterward as needed for accounting and legal obligations.
Security
The app checks each user's role on every request and locks the pages it manages to their owner and your Compliance Admins. Approvals and acknowledgements are bound to an exact page version and content hash. Encryption at rest and in transit is provided by Atlassian's Forge platform. To report a vulnerability, email support@auralitesolutions.com with "Security" in the subject.
Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict its use, and to complain to a data protection authority.
- For support or licensing information we hold, email support@auralitesolutions.com. We'll respond within the time required by applicable law.
- For data inside the app, contact your organization's Confluence administrator. The data is held in your organization's Atlassian site, and Auralite cannot access it.
Children
The app and website are for businesses and are not directed to children. We don't knowingly collect information from children.
Changes to this policy
We may update this policy as the app or the law changes. We'll change the effective date above, and for material changes we'll give notice on this website or by email to license contacts.
Contact
Auralite Solutions
Email: support@auralitesolutions.com