1. Scope and responsibility
This Security Policy describes the technical and organisational measures Intranel Consulting Services Ltd ("Intranel", "we", "us", or "our") applies to PDF and Word Document Import for Confluence (the "App") and its support service. It sits alongside the PDF and Word Document Import for Confluence - Privacy Policy, which describes what information we handle and why.
Security is shared. We are responsible for the App and the processing pipeline behind it. You remain responsible for your Confluence Cloud site, your user accounts and permissions, and for confirming you are authorised to import the documents you submit.
2. Encryption
All data transfers are encrypted in transit on every hop, using TLS 1.2 or higher. This covers traffic between your Confluence Cloud site and the App, and between the App and the document processing service. At no stage does document content travel over an unencrypted connection.
During the short processing window, data held at rest in Microsoft Azure is encrypted under Microsoft's standard encryption-at-rest controls using platform-managed keys.
3. Data minimisation and retention
The App is built to hold as little as possible for as short a time as possible. We do not operate a document archive and we do not build customer profiles.
Submitted documents and any intermediate content generated during conversion are retained only for the time required to complete processing, and are deleted from systems controlled by Intranel in less than one hour. The only information we keep beyond that point is what is needed to maintain context around a support request you have raised with us.
Microsoft states that Document Intelligence input data and results may be temporarily stored for up to 24 hours for asynchronous processing and are then deleted, and that customer data is not used to train its models. See Microsoft's Document Intelligence data, privacy, and security guidance.
4. Platform providers
We use Atlassian services to deliver the App within Confluence Cloud, and Microsoft Azure services, including Azure AI Document Intelligence, to process documents. No other provider handles document content.
Both providers operate independently audited security programmes and publish their own certifications and compliance coverage. Data may be processed outside New Zealand or Australia where those providers operate infrastructure, subject to applicable safeguards.
5. Architecture and tenancy separation
The App is built on Atlassian Forge and runs on Atlassian-managed infrastructure. Forge applies Atlassian's platform controls, including invocation in the authenticated context of the requesting site, and requires any external network egress to be declared in the app manifest and reviewed by Atlassian.
Each import is processed in the context of the Confluence site that requested it. We do not maintain a shared persistent store of customer document content, so content from one customer's site is not commingled with another's.
6. Access control
Administrative access to the App's configuration and processing environment is limited to authorised Intranel personnel, granted on a least-privilege basis, and protected by multi-factor authentication. Access is reviewed when roles change and removed when it is no longer required.
Our personnel do not access customer document content in the ordinary course of operating the App. Where a support request requires us to examine something specific, we ask you to provide only what is necessary to resolve it.
7. Secure development and change management
Changes to the App are reviewed before release and tested outside the production environment. Releases are distributed through the Atlassian Marketplace and are subject to Atlassian's app review and security requirements for listed apps.
8. Logging and monitoring
We retain non-identifying operational telemetry, such as timestamps, error codes, processing duration, and service health information, to secure, maintain, and improve the App. Document content is not written to our logs, and we do not use telemetry to reconstruct document content.
9. Incident response
We investigate suspected security incidents once we become aware of them, take steps to contain and remediate the cause, and assess what information may have been affected.
Where an incident amounts to a notifiable privacy breach, we will notify affected customers and the relevant regulator without undue delay, as required by the New Zealand Privacy Act 2020 and, where applicable, the Australian Privacy Act 1988. Customer notifications are sent to the contact associated with the affected Confluence site.
10. Reporting a vulnerability
If you believe you have found a security vulnerability in the App, email appsupport@intranel.com with enough detail for us to reproduce it. We will acknowledge your report and keep you updated while we investigate.
Please report privately and allow us a reasonable opportunity to remediate before any public disclosure. Do not test against data belonging to another customer and do not attempt to degrade the service for others.
11. Contact and changes
We review this policy as the App, our providers, or applicable legal requirements change. The effective date above identifies the current version. Questions about this policy may be sent to appsupport@intranel.com.