Data Protection and Privacy

Table of Contents

SoftComply is established in Estonia (member state of the European Union) and processes personal data in accordance with the EU General Data Protection Regulation and other applicable data-protection requirements. Privacy and data protection are considered throughout the design, development and operation of our products and business processes.

The information processed, its location and the allocation of responsibilities depend on the SoftComply product and deployment model. Most SoftComply Cloud applications, including Risk Manager Plus Cloud, are built on Atlassian Forge. SoftComply Document Manager has a different architecture that includes backend services hosted in Google Cloud. Data Center applications run within infrastructure operated by the customer.

This page provides an overview of SoftComply’s data-processing practices. For more detailed information, please refer to the SoftComply Privacy Policy or contact privacy@softcomply.com.


What Data We Process

SoftComply may process different categories of information depending on the product used and the customer’s interaction with us. Not every category applies to every product or customer.

Customer application data

Customer application data may include risk records, document information, compliance records, control libraries, asset information, configuration data and other content entered or generated through a SoftComply application.

For Forge-based applications, relevant application data is processed within the Atlassian environment using Atlassian APIs and, where applicable, Forge-hosted storage. Access is governed by the application scopes approved by the customer’s Atlassian administrator. SoftComply does not routinely copy customer application content from Forge-hosted applications into separate SoftComply-controlled databases.

This architecture does not mean that SoftComply has no responsibility for the application data it processes. Under Atlassian’s shared-responsibility model, Atlassian operates the Forge platform while SoftComply remains responsible for its application code, permissions, configuration and applicable privacy obligations.

SoftComply Document Manager uses a different architecture that includes backend services hosted in Google Cloud. Its data flows, storage locations and retention arrangements should therefore be assessed separately from those of Forge-only applications.

Business contact and licensing data

SoftComply processes business contact information such as names, business email addresses, company details, job roles and correspondence records. This information may be used to manage customer relationships, support and other business communications.

Where an application is purchased through the Atlassian Marketplace, relevant licensing and transaction information is also processed by Atlassian under Atlassian’s applicable terms and privacy practices. SoftComply does not receive or store payment-card information used for Marketplace purchases.

Support data

When customers contact SoftComply for support, we process the information included in the request. This may include contact details, ticket content, screenshots, diagnostic information, attachments and other material voluntarily supplied by the customer.

Customers should avoid including passwords, access tokens, special-category personal data or unrelated confidential information in support requests. Where sensitive supporting material is necessary, SoftComply may provide or agree an appropriate method for sharing it.

Support information is retained in accordance with SoftComply’s retention requirements and may be retained after a case is resolved where necessary for security, legal, contractual, service-improvement or record-keeping purposes.

Product usage and technical information

SoftComply may process limited technical, diagnostic or usage information to operate, secure and improve its products. Depending on the product and configuration, this may include application version, licence status, error information, performance data and aggregated feature-usage information.

SoftComply does not sell personal data. Detailed information about analytics or telemetry applicable to a specific application should be provided in that application’s Atlassian Marketplace Privacy and Security tab and related product documentation.


Our Role Under Data-Protection Law

SoftComply’s role depends on the processing activity.

SoftComply generally acts as a data controller for personal data used to manage its own business activities, including customer and prospect contacts, licensing administration, support communications, procurement, marketing and website interactions. In these situations, SoftComply determines why and how the relevant personal data is processed.

For Forge-based applications, Atlassian also plays a significant role as the operator of the underlying cloud and Forge infrastructure. The precise relationship between the customer, Atlassian and SoftComply depends on the product, data involved and applicable contractual arrangements.


Data Residency

Data residency depends on the product architecture, the type of data involved and the customer’s selected configuration.

For eligible Forge applications that use persistent Forge-hosted storage for in-scope end-user data, Atlassian supports data-residency pinning. Where the customer’s Atlassian product and the installed application are eligible and pinned, in-scope Forge-hosted data is stored in the location selected by the customer’s Atlassian administrator.

Not all information processed by Atlassian or a Forge application is necessarily covered by data-residency pinning. Certain operational, account, support, logging or out-of-scope data may be processed in other locations. Forge may also execute application invocations outside the selected storage location where necessary to support platform capabilities, reliability, security or fraud prevention.

Customers should verify the current residency status of each application through their Atlassian administration interface and the application’s Marketplace Privacy and Security information. Further information is available in Atlassian’s Forge data-residency documentation.

SoftComply Document Manager includes backend services hosted in Google Cloud. Information about its applicable storage and processing locations should be stated in its product-specific documentation and Marketplace Privacy and Security information.

Data Center applications operate in the customer’s own environment. The customer determines and manages the hosting location, infrastructure and associated data-residency controls for those deployments.


International Data Transfers

Where personal data is transferred outside the European Economic Area, SoftComply uses an applicable transfer mechanism and supplementary safeguards where required. Depending on the processing activity, these measures may include an adequacy decision, the European Commission’s Standard Contractual Clauses or other legally recognised safeguards.

Relevant third-party providers may process limited personal data in more than one jurisdiction. Additional information about these providers is available on the Subprocessors and Service Providers page. Customers may contact privacy@softcomply.com for further information about transfer safeguards applicable to a particular processing activity.


Encryption

Data is protected in transit using HTTPS and supported TLS protocols. For Forge-based applications, encryption of Forge-hosted data at rest and the associated infrastructure-level key-management controls are provided by Atlassian. Information about Atlassian’s current encryption controls is available through the Atlassian Trust Center.

Where SoftComply operates product backend services outside Atlassian Forge, relevant data is protected using the security and encryption capabilities of the applicable cloud provider. Access to these services and their associated credentials is restricted according to business need.

SoftComply applies measures intended to prevent secrets, credentials and access tokens from being committed to publicly accessible source code or unnecessarily exposed through application interfaces. Security controls are selected according to each product’s architecture and risk profile.


Data Retention and Deletion

Personal data is retained only for as long as reasonably necessary for the purpose for which it was collected and to meet applicable legal, contractual, security, accounting and regulatory requirements. Retention periods vary according to the type of information and the processing purpose.

Forge-hosted application data

For Forge applications using persistent Forge-hosted storage, Atlassian manages storage retention and deletion according to the Forge-hosted storage lifecycle and Atlassian’s applicable retention policies.

Following application uninstallation, data may remain recoverable during Atlassian’s applicable retention period. Atlassian’s current documentation states that, in certain circumstances, a request made within 21 days of uninstallation may allow a new installation to be relinked to the previous data. Customers should therefore not assume that Forge-hosted data is permanently erased immediately when an application is uninstalled.

Current information is available in Atlassian’s Forge-hosted storage data-lifecycle documentation.

Data stored in Jira or Confluence

Information stored as Jira issues, Confluence pages or other native Atlassian content is governed by the customer’s Atlassian configuration and Atlassian’s applicable retention and deletion processes. Removing a SoftComply application does not necessarily delete native Jira or Confluence content previously created or managed using the application.

SoftComply-controlled data

Business contact and support records held in SoftComply-controlled business systems are retained according to their purpose and applicable legal obligations. Certain accounting and transaction records may need to be retained after the end of the customer relationship.

Product-specific data stored in a SoftComply-managed backend is deleted or anonymised according to the applicable product retention process, contractual terms and legal requirements. Customers may contact privacy@softcomply.com for product-specific information or to request deletion where applicable.


GDPR and Data-Subject Rights

SoftComply processes personal data in accordance with applicable data-protection principles, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality.

Depending on the processing activity, SoftComply may rely on one or more lawful bases, including performance of a contract, compliance with a legal obligation, legitimate interests or consent. The applicable lawful basis is determined by the specific purpose and circumstances of the processing.

Where GDPR applies, individuals may have rights including:

  • Access to their personal data

  • Correction of inaccurate or incomplete personal data

  • Erasure of personal data

  • Restriction of processing

  • Data portability

  • Objection to certain processing

  • Withdrawal of consent where processing is based on consent

  • The right to lodge a complaint with a competent supervisory authority

These rights are subject to the conditions and limitations provided by applicable law. Requests may be submitted to privacy@softcomply.com. SoftComply may request information necessary to verify the requester’s identity before fulfilling a request.

SoftComply will respond without undue delay and generally within one month of receiving a valid request. Where permitted by law, this period may be extended by up to two further months where a request is complex or numerous. The requester will be informed of any extension and the reason for it.


Data Processing Agreements

Where SoftComply processes personal data on behalf of a customer as a processor, an applicable Data Processing Agreement is available. The agreement describes the relevant subject matter, duration, nature and purpose of processing, categories of personal data and data subjects, and the respective rights and obligations of the parties.

A DPA is not necessarily required for every use of every SoftComply product. Its applicability depends on whether SoftComply processes personal data on behalf of the customer in the relevant context. Requests and questions may be submitted to privacy@softcomply.com.


Privacy Contact

For privacy inquiries, data-subject requests, DPA requests or questions about product-specific data handling, contact privacy@softcomply.com.

Because this page sets out legal positions—not just security descriptions—it should receive a final review against the current SoftComply Privacy Policy and DPA before publication.