GxP Seal ← gxpseal.com

Legal

Privacy Policy

Effective date: 22 September 2026
Provider: GxP Seal, LLC — a Delaware limited liability company (file no. 7890123), registered agent 1201 North Orange Street, Suite 700, Wilmington, DE 19801, USA (“we”, “us”).
Governing law: Delaware, USA. Where we process personal data of individuals in the EU/UK, the GDPR also applies (see §§9 and 11).
EU Representative (GDPR Art. 27): EU Verify (Euverify Ltd), Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, Ireland. Individuals in the EU/UK may contact our EU representative on GDPR matters.
Contact: [email protected]

1Scope

This policy covers (1) the GxP Seal app — a Confluence Cloud app on Atlassian Forge that adds electronic signatures and audit evidence to Confluence pages — and (2) the GxP Seal website, gxpseal.com. We handle data very differently in each, so they are described separately.

2Our role

3What the app processes

The minimum needed to produce a compliant signature and its audit trail:

DataWhyStored?
Atlassian account ID of the signerSigner identityYes, in the signature record
Signer printed name and emailTo manifest who signedYes
Signing credential you setSecond signature componentOnly as a salted scrypt hash — never plaintext, never logged
Hash of the page content at signingBind a signature to an exact versionYes (the SHA-256 hash only — not the page body)
Signature records and audit chainThe tamper-evident audit trailYes, append-only
Group memberships of the callerVerify admin/authority at action timeRead transiently; not stored
Account IDs you notify, and who triggered a notificationApproval-flow notifications and their audit logYes, in the flow-event log

The app reads a page’s body at signing time to compute its hash; it does not store the page body.

4What the app does not do

5Where app data is stored

All app data is stored in Atlassian-hosted Forge storage. Because storage is Atlassian-hosted, it inherits your Atlassian site’s data-residency controls — we add no storage location of our own.

6Sub-processors

Beyond Atlassian (the platform on which the app runs and stores data), the app uses no sub-processors. There is no third party in the data path.

7Retention and deletion

8The website (gxpseal.com)

9Your rights

Requests to access, correct, export or delete personal data held in the app are directed to your organisation (the controller), which we support as processor. For website contact data (where we are the controller):

To exercise any of these, email [email protected].

10Security

How we protect data — credential hashing, tamper-evidence, and the no-egress architecture — is described in our Security Statement.

11International transfers

We are a US (Delaware) company. Where we process personal data of EU/UK individuals, the GDPR applies and any EU→US transfer relies on an appropriate safeguard such as the Standard Contractual Clauses. In practice the app introduces no cross-border transfer of its own — all app data is stored in Atlassian-hosted storage and inherits your site’s residency, so transfer exposure is limited to Atlassian’s arrangements. Our only sub-processor is Atlassian.

12Changes

We may update this policy; we will change the effective date above and, for material changes, provide reasonable notice.

13Contact

[email protected] · GxP Seal, LLC — 1201 North Orange Street, Suite 700, Wilmington, DE 19801, USA.