Privacy Policy

Last updated: 6 September 2026

1. Who we are

This policy is issued by Shakamize Ltd (“Shakamize”, “we”, “us”), a company registered in Israel. Shakamize Ltd is the controller of the personal data described in this policy, except where this policy states that we act as a processor on a customer’s behalf.

This policy covers the website at shakamize.com and the products Shakamize builds and operates, including Shakamize Document Approval and Audit Trail for Confluence.

For any privacy question or request, contact us at [email protected].

2. The contact form on this website

The contact form on shakamize.com collects three pieces of information you type in: your name, your email address, and the message you write. The form also contains a hidden field used to detect automated spam submissions; a human visitor never fills it in and it collects nothing about you.

We use this data for one purpose only: to read your message and reply to it. We do not use it for marketing, we do not build a profile from it, and we do not sell or share it for advertising.

Where it goes

When you submit the form, the submitted name, email address, message and a submission timestamp are sent to an automation service running at n8n.shaham.net. This is a self-hosted n8n instance operated by the same party that operates Shakamize, not a third-party SaaS provider, and it is used to route your message to us. From there the message reaches our email. No other recipient receives the submission.

The website itself is hosted on Vercel, which processes the technical request data inherent in serving any website, such as IP address and user agent, in its operational logs. We do not use that data to identify you.

We do not use any third-party analytics, advertising or tracking on this website, and the website does not set cookies for those purposes.

How long we keep it

We keep contact form submissions and the resulting email correspondence for as long as needed to handle your enquiry and any follow-up, and in any case no longer than 24 months from the last contact, after which they are deleted. Intermediate execution records in the automation service are retained no longer than 30 days. You can ask us to delete your data sooner, as described in section 5.

Legal basis

Where the GDPR applies, our legal basis for processing contact form data is our legitimate interest in responding to enquiries addressed to us, and, where your message concerns a possible agreement, taking steps at your request prior to entering into a contract.

3. The Confluence app: Document Approval and Audit Trail

This section applies specifically to Shakamize Document Approval and Audit Trail for Confluence, distributed through the Atlassian Marketplace. It is written separately because the data relationship is different from the one for this website.

Our role

For data the app processes inside a customer’s Atlassian site, the customer is the controller and Shakamize Ltd acts as a processor, processing that data only to provide the app’s functionality.

What the app processes

The app reads Confluence pages through Atlassian’s own API in order to establish which version of a page is being approved and whether that version has since changed. It does not copy page bodies into its own storage. What it stores is:

  • References to controlled pages: the page identifier, its space, its title and the version numbers involved in an approval.
  • Approval metadata: the current state of each controlled document, the applicable workflow, the named approvers for each step, and review dates.
  • Audit trail entries: for each recorded action, the type of action, the document and version it applied to, the outcome, a reason taken from a fixed list of codes, a timestamp, and a pseudonymous key standing for the person who acted.
  • A separate mapping from each pseudonymous key to the Atlassian account identifier of the person it stands for. That mapping is deliberately held apart from the audit trail; the next subsection explains why.

Audit trail entries carry no free text. The reason an approver gives for a decision is one of a fixed set of codes, and the sentence a reader sees is generated from that code when the entry is displayed. Nobody can type prose into the record, so personal data cannot arrive in it by being written into a comment.

The app does not ask users to create an account with us and does not collect any personal data directly from end users beyond what Atlassian already holds about them in the customer’s site.

How the trail is built so that erasure stays possible

A record that must not be altered and a legal obligation to erase personal data on request cannot both apply to the same row. The app resolves that in its design rather than case by case.

Atlassian account identifiers are never written into audit trail entries. Each entry references a pseudonymous key that is stable within a single installation, and the mapping from that key to an account identifier lives in a separate table that exists in order to be deleted from. Erasing a person’s identity means deleting their row from that mapping. The audit entries themselves are untouched, the integrity of the record still verifies, and the trail then reads as an anonymous actor whose identity was erased at that person’s request, rather than either breaking or continuing to name them.

One consequence should be stated plainly to anyone relying on this app as a compliance record. The record that an approval happened is permanent. The attribution of that approval to a named person is not. If that person exercises a right of erasure, the approval stays in the trail and the name comes out of it.

Where the app stores personal data it reports that data through Atlassian’s Personal Data Reporting API, keyed by Atlassian account identifier, and acts on erasure signals received through it in the way described above.

Where the data is processed

The app is built on Atlassian Forge and executes within Atlassian infrastructure. Its data is held in Forge storage associated with the customer’s Atlassian site. The app does not transmit customer data to any external service, and there is no Shakamize-operated server in the path. The app uses no third-party analytics, telemetry, advertising or error-reporting service at this time. If that ever changes, this policy will be updated before the change takes effect.

Because the app runs on Atlassian infrastructure, Atlassian’s own handling of that data is governed by the customer’s agreement with Atlassian and by Atlassian’s privacy documentation. We do not make any independent representation about the geographic location in which Atlassian stores that data.

Retention and deletion

App data persists for as long as the app is installed on the customer’s site, because the audit trail is the record the app exists to keep. We make no promise of retention beyond the life of the installation, and cannot make one: uninstalling the app deletes what it holds, in accordance with Atlassian’s Forge platform behaviour. A reinstall is treated as a new installation and starts empty. Reconnecting a previous installation’s data is a request we have to make to Atlassian within 21 days of the uninstall, and after that it cannot be recovered by us or by anybody else. Confluence page content itself is never deleted by the app.

Customers should therefore export the register and audit trail before uninstalling if they need to keep the record. The export is a download from the browser, not a transfer to us. See the documentation.

A customer who needs specific records removed or corrected while the app remains installed should contact us at [email protected]. Deleting an identity mapping is the supported path and leaves the trail verifiable, as described above. Deleting or editing an audit entry itself is not something we will do quietly: it is detectable by verification, it would leave the customer holding a record that no longer verifies, and we will explain that effect before acting on any such request.

4. Our other products

Autolidays and Salchik are operated as separate services with their own accounts and their own data. Where a separate privacy notice applies to one of those services, it is published on that service and governs your use of it. This policy covers shakamize.com and the Confluence app described above.

5. Your rights and how to exercise them

Subject to the law that applies to you, you may have the right to request access to the personal data we hold about you, to have it corrected, to have it erased, to restrict or object to its processing, and to receive it in a portable form.

To make any of these requests, including a request for erasure, email [email protected] with enough detail for us to locate the data. For a website enquiry, that is the email address you used; for the Confluence app, your Atlassian site and the records concerned. We will respond within 30 days. We may need to verify your identity before acting, and we will only ask for what is necessary to do so.

If you are an end user of the Confluence app at an organisation that installed it, that organisation is the controller of that data. Address your request to them; if you contact us directly, we will refer the request to them and assist them in responding.

If you believe we have handled your data improperly, you may complain to your local data protection supervisory authority. We would appreciate the chance to address it first.

6. Security

We keep the number of places personal data lives as small as the job allows. The Confluence app holds its data inside Atlassian infrastructure rather than on infrastructure of ours. Website enquiry data is limited to what you type into the form, and access to it is limited to the people who need it to reply to you. No system is perfectly secure, and we do not claim otherwise.

7. Children

Our website and products are intended for business use and are not directed at children. We do not knowingly collect personal data from children.

8. Changes to this policy

We may update this policy. The date at the top of this page shows when it was last changed. Where a change materially affects how we handle personal data, we will publish the updated policy before the change takes effect.

9. Contact

Shakamize Ltd
Privacy enquiries: [email protected]
Confluence app support: [email protected]