Data Processing Addendum: Specpane: OpenAPI Viewer for Confluence
Effective date: September 29, 2026
This Data Processing Addendum ("DPA") forms part of the agreement under which you use the App, the Bonterms Standard End User Agreement with our Provider-Specific Terms (see Terms), between Brain Static Threads ("Processor", "we") and the customer using Specpane: OpenAPI Viewer for Confluence (the "App") ("Controller", "you"). It applies when we process Personal Data on your behalf through the App, as defined in the EU General Data Protection Regulation 2016/679 ("GDPR") or the UK GDPR.
1. Scope of processing
| Subject matter | Displaying API specifications on Confluence pages, and managing Git connections |
| Duration | While the App is installed, plus the deletion periods in section 7 |
| Nature and purpose | Retrieving, briefly caching and rendering specs; storing Git connection details |
| Types of Personal Data | Any Personal Data within specs you display (for example, names or emails in example values), and the optional Bitbucket account email on a Git connection |
| Data subjects | Your personnel, and any individuals whose data appears in your specs |
The App doesn't process special categories of Personal Data unless you put them in a spec. You shouldn't do that.
2. Instructions
We process Personal Data only on your documented instructions. These Terms and your configuration of the App (the sources, connections and settings you choose) are those instructions. We'll tell you if we believe an instruction breaks data protection law.
3. Confidentiality
Anyone we authorize to process Personal Data is bound by confidentiality.
4. Security
We maintain appropriate technical and organizational measures, including:
- hosting the App only on Atlassian Forge, with no servers of our own
- storing access tokens as encrypted Forge secrets that are never sent to the browser
- reading Confluence content with the viewing user's permissions
- limiting Git connection management to Confluence administrators, with space restrictions enforced on the server
- caching Git-sourced specs for no more than 5 minutes
- logging errors only, never spec contents or tokens
5. Sub-processors
You authorize the following sub-processor:
| Sub-processor | Purpose | Location |
|---|---|---|
| Atlassian (Forge platform) | Hosting, storage and logging for the App | Per your Atlassian data residency settings |
GitHub, GitLab and Atlassian Bitbucket aren't our sub-processors. The App contacts them only on your instruction, using credentials you supply, and your agreements with those providers govern that data.
We'll give at least 30 days' notice at https://brainstaticthreads.com/specpane/privacy/ before adding or replacing a sub-processor. You may object on reasonable data protection grounds, and if we can't resolve the objection, you may stop using the App.
6. Assistance
Taking into account the nature of the processing, we'll reasonably help you:
- respond to data subject requests, most of which you can handle directly by editing specs, connections and pages
- carry out data protection impact assessments
- meet your security obligations
7. Deletion
- Cached specs: deleted automatically within 5 minutes.
- Connection data: deleted when an administrator deletes the connection.
- Everything else: when you uninstall the App, Atlassian deletes the App's stored data under Forge's data retention practices.
We keep no copies outside Forge.
8. Personal data breaches
We'll notify you without undue delay, and where feasible within 72 hours, after becoming aware of a Personal Data breach affecting your data. We'll include the information reasonably available to us.
9. Audits
We'll make available the information reasonably needed to show compliance with this DPA, including answers to security questionnaires. Because the App runs entirely on Atlassian Forge, audits of the hosting environment rely on Atlassian's published certifications and reports.
10. International transfers
Where processing involves a transfer of Personal Data out of the EEA, UK or Switzerland to a country without an adequacy decision, the EU Standard Contractual Clauses (Module 2 or 3, as applicable) and the UK Addendum are incorporated by reference.
11. Liability and precedence
Liability under this DPA is subject to the limitations of liability in the Standard End User Agreement. If this DPA conflicts with that agreement, this DPA prevails for Personal Data processing.
Contact
Brain Static Threads support@brainstaticthreads.com