Data Security & Privacy (Mail Page Scheduler & E-Mail Newsletter CLOUD)

Data Security & Privacy (Mail Page Scheduler & E-Mail Newsletter CLOUD)

This app is the official CLOUD version of the well known Mail Page Scheduler & E-Mail Newsletter Data Center app.


Where is my data stored?

Your data is stored securely only in the Atlassian cloud infrastructure!

Mail Page Scheduler & E-Mail Newsletter (CLOUD) for Atlassian Confluence Cloud was developed using the Atlassian's development platform called Atlassian Forge and thus meets the highest standards of security and availability.

In the Mail Page Scheduler & E-Mail Newsletter (CLOUD) for Confluence App all your data is stored securely in the Atlassian cloud infrastructure with the Atlassian Storage API.

 

What data is stored?

The following data is stored in the Mail Page Scheduler & E-Mail Newsletter (CLOUD) for Confluence App

Data type

Data fields

Data type

Data fields

Storage API

  • entity storage service app

Confluence API

  • Get, create, update, and delete content, spaces, and more

  • Confluence API

External permissions

  • https://mail-bridge.kencha-software.de

Unless otherwise stated above, our Cloud Apps do not store Customer Data locally, but store Customer Data in the corresponding Atlassian Cloud Product. The Atlassian Cloud Product Security Statement can be found here.

 

What Confluence data does Mail Page Scheduler & E-Mail Newsletter (CLOUD) for Confluence access?

The following read permissions to Jira data are required for Mail Page Scheduler & E-Mail Newsletter (CLOUD) for Confluence App functionality.

Access Level

Access Right

App Reasoning

Access Level

Access Right

App Reasoning

View pages

View page content

  • Display metadata of the page

  • Macro to embed in the page content

View and download content attachments

View and download attachments of a page or blogpost that you have access to

 

View spaces

View space details

  • Configure manual fields with individual values to be used in the metadata macro

View user details

View user details

 

View groups

View details about groups including its members

  • Read page metadata and changes

Read Email Address

View email addresses of all users regardless of the user's profile visibility settings.

  • Display metadata of the page

  • Macro to embed in the page content

App Storage Scope

Read and write to app storage service

  • Runs fully on Atlassian with Data Residency compatibility

Share data with 1 domain outside of Atlassian

This allows the app to share personal data outside of Atlassian cloud via the following domains:

  • https://mail-bridge.kencha-software.de

  • Required to deliver generated e-mails through the customer-configured SMTP server. Atlassian Forge cannot open direct SMTP socket connections, therefore the app sends the prepared mail job to the HTTPS SMTP Bridge Service. The bridge converts the HTTPS request into an SMTP send operation using the customer's SMTP configuration. The bridge is not a mail relay provider and does not provide its own mail server.

Does the Mail Page Scheduler & E-Mail Newsletter (CLOUD) for Confluence App connect to external services?

For sending the mail it is technically necessary to send the prepared mail job to our HTTPS SMTP bridge service. Data sent from the Forge app to the bridge is

  • encrypted in transit via HTTPS

  • not permanently stored

  • kept only for the duration of the delivery request

The bridge is designed to process mail content, attachments and SMTP credentials only in memory and not to persist them to storage.

Mail Page Scheduler & E-Mail Newsletter for Confluence Cloud connects to an HTTPS SMTP Bridge Service.

The bridge is required because Atlassian Forge does not support direct SMTP socket connections from the Forge runtime. The Forge app prepares the e-mail from the selected Confluence page and sends the mail job to the bridge via HTTPS. The bridge then sends the e-mail through the SMTP server configured by the customer.

The bridge does not provide a kencha-owned SMTP relay. It only acts as a technical connector between Atlassian Forge and the customer's SMTP server.

How does the bridge Service works?

draw.io Diagram

What static IP address for outgoing SMTP traffic has the bridge service?

The Mail Page SMTP Bridge sends outgoing SMTP traffic from the following static IPv4 address:

31.70.67.177

Customers can allowlist this IP address in their SMTP server or firewall configuration if they restrict SMTP access by source IP.

This IP address applies to the kencha-hosted SMTP bridge endpoint “mail-bridge.kencha-software.de

 

What data might be shared in the HTTPS request?

The bridge service receives an HTTPS request from the Forge app and performs the actual SMTP delivery through the customer-configured SMTP server. The bridge is not a mail relay provider and does not provide its own SMTP infrastructure. It only acts as a technical connector between Atlassian Forge and the customer SMTP server.

Data sent to the bridge may include:

Data type

Data fields

Data type

Data fields

Mail header data

from, to, cc, bcc, subject field

Mailserver account data

server hostname, port, username and password

Confluence page

Page title and page content.
All attachments of the page, if you select this when sending.
URL to Confluence page.

Confluence instance

Site URL of your confluence instance

User data

Display name and email address of the user, who sends the mail.

The bridge processes this data only for the purpose of sending the requested e-mail. Mail content and attachments are deleted after the delivery job has finished. The bridge does not permanently store mail content, attachments, or SMTP credentials. All data is encrypted in transit, held only volatile in memory and is never saved on storage.

 

Vist our kencha Trust Center to learn more about our Security measures.