BoomiSight Data Handling Disclosure
Last updated: 2026-07-14 Owner: BoomiSight Product and Security Applies to app: BoomiSight for Confluence Review cadence: Quarterly and before Marketplace submission Status: Publication-ready for Marketplace submission
Data Categories
Section titled “Data Categories”| Data category | Examples | Source | Storage | Retention |
|---|---|---|---|---|
| Space configuration | Boomi account ID, Boomi username, sync interval, dataset flags, configured-space registry entry and marker | Confluence space admin and BoomiSight | Forge app storage and a Confluence space property marker | Until changed, disconnected, or the app is uninstalled |
| Credential material | Boomi API token | Confluence space admin | Forge secret storage | Until rotated, removed, or app uninstalled |
| Cached Boomi operational data | Environments, runtimes, environment attachments, deployed packages, component metadata, deployment history, execution records, API/APIM metadata where available, connector inventory, safe Process Property/XREF structure, and verified current-Build relationship facts | Customer-configured Boomi account | Forge app storage | Replaced by refreshes and cleared when authentication context changes, cache is cleared, or the space is disconnected |
| Page-context and Documentation Health cache | Compact page metadata, macro/link counts, configuration signals, freshness, scan totals, and review findings | Current-page reads and explicit space-admin Documentation Health scans | Forge app storage | Replaced by later page reads or scans and cleared when cache is cleared or the space is disconnected |
| Macro configuration | Selected process, runtime, environment, API, Process Property or XREF component, date window, display label, source URL, and relationship display choice | Confluence author | Confluence macro configuration | Follows Confluence page retention |
| Rovo action projection | Bounded, sanitized current-page or current-space facts, freshness, totals, truncation state, and confirmed action inputs | BoomiSight cache and trusted Forge/Rovo context | Returned to Atlassian Rovo; BoomiSight does not create a separate conversation archive | Subject to Atlassian Rovo and customer retention settings |
| Operational diagnostics | Feature-probe status, failure class, timestamps, cache freshness | BoomiSight runtime | Forge app storage and operational logs | Used for support and deleted/rotated according to operational policy |
Processing Notes
Section titled “Processing Notes”BoomiSight is designed for per-space configuration. One Confluence space can connect to a different Boomi account or enable different datasets than another space. The app does not intentionally store Boomi API token values outside Forge secret storage.
APIM data is optional enrichment. If the configured Boomi identity cannot read APIM objects, BoomiSight continues to use core runtime and deployment data where available and reports reduced feature readiness.
The Boomi Architecture and Boomi APIs bylines read the current Confluence page to derive page-local context. A current-page refresh rereads that page only. Documentation Health reads a bounded set of pages only when a space admin starts Scan Space Pages. BoomiSight stores compact page facts and findings, not full Confluence page bodies as scan or byline cache records.
Process Property and XREF projections retain only the structural facts needed for documented views. Raw defaults, allowed values, password values, environment overrides, XREF rows and cells, raw XML, and source payloads are not returned to the UI or Rovo. The app may retain technical source identifiers needed for trusted cache keys, routing, and macro configuration; these are not displayed as customer-facing labels or warnings.
BoomiSight Specialist reads safe cached facts for the trusted current page or current space. Passive questions do not contact Boomi. Confirmed relationship refreshes can contact Boomi for the one trusted page-associated process.
When a customer opens a Process Property or XREF component link, the browser necessarily receives a dedicated validated Boomi navigation URL. BoomiSight accepts only the expected HTTPS Boomi Build route on the exact platform.boomi.com host and keeps raw account, component, and URL values out of visible cell text and warnings.
Minimization Controls
Section titled “Minimization Controls”- The app stores the Boomi username needed for customer-configured API access.
- Tokens are stored in Forge-managed secret storage, not in general app configuration storage.
- Configuration changes that affect Boomi auth clear runtime caches for the space.
- Boomi API response caches are bounded so the app stores only the operational data needed for configured views.
- Documentation Health scans are bounded, skip inaccessible or bodyless pages, and keep only compact findings rather than full page bodies.
- Rovo responses use safe field projections, deterministic result windows, nested bounds, and truthful total/truncation metadata.
- Process Property, XREF, and relationship views exclude raw values and payloads before cache-backed UI or Rovo projection.
- The app does not collect Atlassian user API tokens.
Data Subject and Deletion Requests
Section titled “Data Subject and Deletion Requests”Requests can be sent to privacy [at] flowdence.io or Flowdence Support. For customer-controlled Boomi content, the customer remains responsible for source-system correction and deletion. Space admins can clear cached data while keeping the connection, or use Disconnect and purge space data to remove that space’s credential, configuration, sync metadata, caches, registry entry, and configured-space marker. Flowdence can assist with removal requests.
Data Handling Assurance
Section titled “Data Handling Assurance”| Area | Public assurance |
|---|---|
| Configuration and credentials | Space configuration and Boomi credentials are stored in Forge-managed services, with credentials protected as secrets. |
| Cache lifecycle | Cached Boomi operational data is refreshed, replaced, or cleared when configuration changes affect the Boomi authentication context. |
| Boomi REST access | BoomiSight sends configured requests to the Boomi REST API endpoint needed to display customer-selected operational data. |
| Confluence page context | Current-page reads and explicit bounded scans derive compact documentation facts without editing pages or storing full page bodies as results. |
| Rovo | BoomiSight returns bounded safe facts to Atlassian Rovo and requires confirmation before the supported page or process refresh actions. |
| Atlassian data | BoomiSight does not intentionally collect Atlassian user API tokens and uses Confluence context only as needed to provide configured app features. |