Data Processing Agreement
Last updated: 2026-08-13.
This Data Processing Agreement (“DPA”) forms part of, and is subject to, the Terms of Service between you (“Customer”) and TOTEMDEV SRL (“WikiFix”, “we”) for the WikiFix Confluence Cloud app (the “Service”). It applies whenever we process personal data on your behalf and the GDPR or UK GDPR applies to that processing. No signature is required — accepting the Terms of Service accepts this DPA. If your procurement process needs a countersigned copy, email security@wikifix.ai and we’ll send one.
You are the controller of your Confluence content. We are your processor, and we process it only to provide the Service and only on your instructions.
The terms themselves
The operative clauses of this DPA are the Common Paper DPA Standard Terms, Version 1.1, incorporated here by reference. They are an attorney-drafted open standard published under CC BY 4.0, and we use them unmodified — we’d rather you read a document your counsel may already recognise than one we wrote ourselves.
Where those terms refer to the Cover Page, this page supplies it. The Standard Terms treat any Cover Page field left undefined as “none” or “not applicable”, so the defined terms they rely on are set out here explicitly:
| Cover Page term | Value |
|---|---|
| Governing Member State | Ireland — the EEA SCCs are governed by Irish law (Clause 17) and disputes under them are heard in the Irish courts (Clause 18(b)) |
| Approved Subprocessors | The list published at wikifix.ai/subprocessors, giving each sub-processor’s identity, country and processing tasks |
| Security Policy | Our Security page, which describes the measures we apply |
| Report | None. We hold no third-party audit report today — see Audits below |
| Provider Security Contact | security@wikifix.ai |
| Special Category Data | Restricted — see Special categories below |
| Special Category Data Restrictions or Safeguards | As set out under Special categories below |
Parties
| Provider (data importer, processor) | TOTEMDEV SRL, business registration number 544423, Miron Costin 19/4, ap. 37, Chișinău MD-2068, Republic of Moldova |
| Customer (data exporter, controller) | The Atlassian organization that installs WikiFix |
| Contact | security@wikifix.ai |
What we process, and why
Data subjects. Your Confluence users — page authors and owners, people named in page content or comments, and whoever starts a scan or applies a fix.
Categories of personal data.
- Confluence page content within the spaces you scope to a scan. This is your text, and it may contain personal data of any kind your users have written into it. We don’t select what it contains.
- User and directory information — account identifiers, display names, page ownership, group membership, and whether an account is still active.
- The email address we send a scan notification to. Resolved from Atlassian at send time and never stored.
- Operational identifiers — your Atlassian site host, and the text of searches typed into the WikiFix search box. Both are deliberate exceptions to our analytics content filter, named on the Sub-processors page.
Special categories. WikiFix isn’t built for special-category personal data — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade-union membership, and genetic, biometric, health, sex-life or sexual-orientation data — or for criminal-offence data. Please don’t put it in the spaces you scan. We don’t ask for it, don’t need it and don’t process it deliberately; because the content is yours we can’t detect or filter it, so this is a restriction on how the Service is used rather than a control we apply on your behalf.
You have a practical way to honour it: a scan only ever reads the spaces you scope it to. If a space holds special-category or criminal-offence data — an HR space, say — leave it out of scope and it is never sent to us at all.
Safeguards where such data is involved anyway. Because we can’t rule it out, these apply to everything we process and are the safeguards we rely on for sensitive data: scope confined to the spaces you choose; storage of short excerpts and derived vectors rather than page bodies; encryption in transit and at rest; EU-only processing; access limited to a single authorised person under a duty of confidentiality; and deletion within 30 days of uninstall.
Purpose. Reading pages in the spaces you scope; deriving embeddings and extracted facts from them; sending page text to AI models to find contradictions and author fix text; storing findings and the short excerpts that evidence them; writing fixes you approve; posting a comment when you ask a page owner to decide; sending scan notifications.
Frequency. Continuous for as long as you use the Service — on each scheduled or on-demand scan, and each time you apply a fix.
Duration. For as long as you use the Service, plus up to 30 days after uninstall, after which a daily job deletes your tenant’s data automatically. Deletion reaches our backups too, just not instantly: database backups are kept on a rolling 7-day window, so deleted data ages out of them within a week. We keep no long-lived snapshots.
How we protect it
| Measure | What we do |
|---|---|
| Encryption | TLS 1.2 or higher in transit; AES-256 via AWS KMS at rest |
| Credentials | Your Atlassian tokens and any AI key you bring are envelope-encrypted (KMS data key plus local AES-256-GCM) with automatic rotation. Plaintext never crosses a wire boundary and is never logged. |
| Tenant isolation | Every database query is filtered by PostgreSQL row-level security. One customer’s data is not reachable from another’s queries. |
| Access control | WikiFix is operated by one person, and that is the entire list of people who can reach production data. Access to our cloud account is through single sign-on only; the database is Amazon Aurora inside that account, encrypted at rest, with database authentication tied to the same identity system rather than to a shared password. |
| Audit logging | Administrative actions in our production account are recorded to a tamper-evident audit log — written continuously, integrity-validated, retained for seven years, with a searchable one-year copy. |
| Data minimisation | We keep a derived index and the short excerpts behind each finding — not a copy of your wiki. Full page bodies are dropped at the database layer and re-read live from Confluence on each scan. One exception, so a merge can be undone: the previous body of a page merged away by a duplicate-pages consolidation. |
| Region | Storage, compute and default AI inference in AWS Frankfurt (eu-central-1), with cross-continent inference blocked in code and every sub-processor pinned to its EU region |
| AI | Default inference runs on AWS Bedrock; per Bedrock’s terms your prompts and completions are not used to train base models and the model provider has no access to them |
| Telemetry | Analytics and error tracking receive metadata only — page titles, excerpts and content are stripped by an allow-list enforced in code before any event leaves |
| Deletion | Automatic within 30 days of uninstall, whether or not you ask; sooner on request |
The Security page has the full detail.
Other commitments
- Confidentiality. Everyone authorised to process your data is bound by a duty of confidentiality. Today that is one person.
- Unlawful instructions. If we believe an instruction from you breaches data-protection law, we will tell you rather than quietly carry it out.
- Return instead of deletion. At the end of the Agreement, deletion is the default — but the choice is yours. Ask us and we will return your data instead.
Breach notification
If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and no later than 72 hours after becoming aware — with what we know at the time, and updates as we learn more. We’ll also take prompt steps to contain and investigate it.
Your own 72-hour deadline under Art. 33 runs from the point we tell you, not from when the incident happened.
Audits
We hold no SOC 2 or ISO 27001 certification today; the Security page sets out what would trigger one. That is why the Report field above reads “none” — there is no third-party audit summary for us to send you.
In its place:
- Security due diligence. We answer information-security, due-diligence and audit questionnaires in writing, and provide documentation of the measures above. Send them to the Provider Security Contact; the Standard Terms set the cadence at once a year.
- Audit. We will give you the information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits as the Standard Terms provide. Where a supervisory authority or applicable law requires more, we will meet that requirement.
- Records. We keep records of our compliance with this DPA for three years after it ends.
Sub-processors
We use the sub-processors listed at wikifix.ai/subprocessors, each with its purpose, the data it receives, and its location. That page is the authoritative list, and this DPA constitutes your general written authorisation for them under Art. 28(2).
We publish a change there at least 10 business days before a new or replacement sub-processor begins processing your data. Every change is published to our sub-processor feed at the same moment — follow it and you’ll be told without having to watch the page.
You then have 30 days from publication to object on reasonable data-protection grounds; if you do, we’ll work with you in good faith to resolve it. Email security@wikifix.ai to raise an objection.
International transfers
Your content is stored and processed in the EU. We are, however, established in the Republic of Moldova, which is not covered by an EU adequacy decision — and our administering the Service from Moldova is itself a transfer under Chapter V of the GDPR. We’d rather state that plainly than leave you to discover it.
That transfer is covered by the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914), Module 2, controller to processor, incorporated into this DPA by reference. You are the data exporter and we are the data importer; the sections above supply the information required by SCC Annexes I and II, and the Sub-processors page supplies Annex III. For customers subject to the UK GDPR, the UK Addendum to the SCCs applies on the same basis.
The Clauses are governed by the law of Ireland, and disputes under them go to the Irish courts — the SCCs require an EU member state for both, so this sits alongside rather than replaces the governing law of our Terms. Nothing in that choice narrows your rights: under the Clauses, a data subject may also bring proceedings in the courts of the member state where they live.
Alongside the clauses, these facts are relevant to your own transfer assessment: your data is stored at rest in the EU rather than exported in bulk; it is encrypted in transit and at rest; Moldova is bound by Council of Europe Convention 108+; and Moldovan Law No. 195/2024 transposes the GDPR into national law.
Questions
security@wikifix.ai — a person answers.