Legal

Data Processing Agreement

Version 1.0 · Effective date: 2026-07-17 · Last updated: 2026-07-17

This Data Processing Agreement (“DPA”) applies to the Blobify – Cloud Attachments for Jira app. It supplements the agreement under which the App is licensed and sets out the Article 28 GDPR terms on which we process personal data on the Customer's behalf. For a plain-language description of what the App does with data, see the Privacy Policy; for our security practices, see the Security Policy.

1. Parties and scope

This DPA is entered into between:

  • T&J Małgorzata Ośródka (brand: VelociBit), NIP 7262479786, Jozefow 14B, Jozefow 95-002, Poland (the “Processor”, “we”, “us”); and
  • the organisation that installs and uses the App (the “Customer”, the “Controller”).

This DPA applies only to our processing of Customer Personal Data in connection with the App. It does not apply to personal data for which we act as a controller (for example billing records and support correspondence), which is governed by the Privacy Policy.

2. Roles of the parties

The parties agree that, with respect to Customer Personal Data processed through the App, the Customer is the data controller and VelociBit is the data processor within the meaning of Article 4 GDPR. The Customer determines the purposes and essential means of processing, including which storage provider and region to use, which files are uploaded, who may access them, and how long they are retained.

Where the Customer is itself a processor acting on behalf of a third-party controller, the Customer warrants that it has the necessary authority to instruct us as a sub-processor on that controller's behalf.

3. Details of processing (Article 28(3))

The subject matter, duration, nature, purpose, types of personal data, and categories of data subjects are set out in Annex I below.

4. Processing on documented instructions

We shall process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do so by Union or Member State law to which we are subject. In that case, we shall inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

The Customer's instructions are constituted by: (a) this DPA; (b) the licence agreement for the App; (c) the Customer's configuration of the App (including the storage provider, region, permission model, and feature toggles selected by the Customer's administrators); and (d) the Customer's use of the App's functionality.

We shall inform the Customer if, in our opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.

We do not use Customer Personal Data for our own purposes, and in particular we do not use it for advertising, profiling, resale, or to train machine-learning models.

5. Confidentiality

We ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, and that access is limited to those personnel who require it in order to provide, maintain, and support the App.

6. Security of processing (Article 32)

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Those measures are described in Annex II below and, in more detail, in our Security Policy.

The Customer acknowledges that it is responsible for the security configuration of its own cloud storage account, including access controls, encryption settings, network restrictions, and the scope of the credentials it supplies to the App. We recommend configuring least-privilege, scoped credentials.

7. Sub-processors

The Customer grants us general written authorisation to engage sub-processors, subject to this section.

Our current sub-processor is:

Sub-processorRoleLocation
Atlassian Pty LtdProvider of the Atlassian Forge platform, on which the App runs and where App data at rest residesPer Atlassian's own infrastructure and data residency arrangements

We shall inform the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, giving the Customer the opportunity to object on reasonable data protection grounds. Notification will be given by updating this page and the Marketplace listing. If the Customer objects and the parties cannot agree a resolution, the Customer may terminate its use of the App in accordance with the termination provisions of the licence agreement.

Where we engage a sub-processor, we impose on it data protection obligations no less protective than those set out in this DPA, and we remain fully liable to the Customer for the performance of that sub-processor's obligations.

The Customer's own storage provider is not our sub-processor. The bucket or container configured in the App belongs to the Customer, at a provider the Customer selects, under the Customer's own agreement with that provider. That provider acts as the Customer's own processor or sub-processor, not ours. We never receive, copy, cache, or retain the contents of files stored there.

8. Assistance with data subject rights

Taking into account the nature of the processing, we shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests for exercising a data subject's rights under Chapter III GDPR.

The App is designed so that the Customer can satisfy most such requests directly, without our involvement: attachment metadata is visible and deletable through the Jira issue view, and file contents reside in the Customer's own storage, to which the Customer has direct and independent access. If we receive a request directly from a data subject in relation to Customer Personal Data, we shall not respond to it substantively but shall refer the data subject to the Customer and inform the Customer without undue delay.

9. Assistance with Articles 32 to 36

Taking into account the nature of processing and the information available to us, we shall assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR, including security of processing, personal data breach notification, data protection impact assessments, and prior consultation.

10. Personal data breach

We shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event within 72 hours of becoming aware. Our notification shall describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. We shall provide further information as it becomes available and shall cooperate with the Customer in its own notification obligations under Articles 33 and 34 GDPR.

The Customer acknowledges that, because file contents never reside on systems we control, a compromise of the Processor could not expose the contents of the Customer's files. A breach affecting the Customer's own storage account is outside our control and is the Customer's responsibility to assess and notify.

11. Deletion and return of data

At the Customer's choice, we shall delete or return all Customer Personal Data after the end of the provision of services relating to processing, and delete existing copies, unless Union or Member State law requires storage.

In practice:

  • App-resident data (attachment metadata in Jira issue properties; blob paths and configuration in Forge storage) resides within the Customer's own Atlassian instance and Atlassian's Forge platform. On uninstallation, this data is removed in accordance with Atlassian's platform data lifecycle. We hold no separate copy.
  • File contents remain in the Customer's own cloud storage account and are unaffected by uninstallation. This is deliberate, so that removing the App never destroys the Customer's files. The Customer retains full and direct control and may delete them at any time through its storage provider.

Because we operate no storage of our own, there is no Processor-held copy of Customer Personal Data to return or delete.

12. Audits and information

We shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.

In the first instance, we shall satisfy such requests by providing our Security Policy, our Privacy Policy, and written responses to reasonable security questionnaires. Where those are insufficient for the Customer's demonstrable compliance needs, an audit may be conducted no more than once in any 12-month period, on at least 30 days' prior written notice, during normal business hours, in a manner that does not unreasonably disrupt our operations, and subject to appropriate confidentiality obligations. Each party bears its own costs, save that where an audit reveals a material breach by us of this DPA, we shall bear the reasonable costs of that audit.

13. International transfers

We do not carry out any international transfers of Customer Personal Data of our own. All App data at rest resides within Atlassian's infrastructure. Where personal data is transferred outside the European Economic Area, such transfers are covered by the safeguards operated by our sub-processor Atlassian, which relies on the European Commission's Standard Contractual Clauses for cross-border transfers.

File contents are transferred by the end user's browser directly to the storage location the Customer selects. The Customer determines that location and is responsible for any transfer implications arising from its choice of provider and region.

14. Liability

Each party's liability arising out of or in connection with this DPA is subject to, and counts towards, the limitations and exclusions of liability set out in the licence agreement (including the Bonterms Standard End User Agreement and any Provider-Specific Terms). Nothing in this DPA excludes or limits either party's liability to the extent such exclusion or limitation is not permitted by applicable law, including a data subject's right to compensation under Article 82 GDPR.

15. Term and termination

This DPA takes effect on the date the Customer first installs the App and continues for as long as we process Customer Personal Data on the Customer's behalf. Sections that by their nature should survive termination shall survive.

16. Governing law and jurisdiction

This DPA is governed by the laws of Poland, excluding its conflict of laws rules, consistent with the governing law of the Provider-Specific Terms. The Polish courts having territorial jurisdiction over the Processor's registered seat shall have exclusive jurisdiction over any dispute arising out of or in connection with this DPA. Where the Standard Contractual Clauses apply to a particular transfer, the governing law and forum provisions of those Clauses prevail in respect of that transfer.

17. Order of precedence

In the event of a conflict between this DPA and the licence agreement, this DPA prevails with respect to the processing of Customer Personal Data. In the event of a conflict between this DPA and the Standard Contractual Clauses (where applicable), the Standard Contractual Clauses prevail.

18. Acceptance

This DPA is incorporated by reference into the licence agreement and is accepted by the Customer when the Customer installs or uses the App. Where a Customer requires a countersigned copy for its own records, one is available on request at support@velocibit.io.


Annex I — Details of processing

Subject matter

Provision of the Blobify – Cloud Attachments for Jira app, which stores Jira issue attachments in the Customer's own cloud storage and manages the associated metadata within Atlassian.

Duration

For as long as the Customer has the App installed.

Nature and purpose

Storing, listing, uploading, downloading, and deleting attachments; indexing attachment metadata for search in JQL; and enforcing access permissions. Processing is carried out solely to provide and operate the App.

Types of personal data

DataCategoryWhere stored
Attachment filenames, file sizes, MIME types, upload timestampsMay contain personal dataJira issue properties
Uploader account ID (accountId)Personal data (user reference)Jira issue properties
Aggregate index for JQL — total size, count, filenames, last uploader account IDMay contain personal dataJira issue properties
Blob object paths per issue (paths include filenames)May contain personal dataForge Custom Entity Store

Not processed by us: attachment file contents. Files are transferred directly from the end user's browser to the Customer's own cloud storage using short-lived signed URLs. We operate no backend egress and never receive, copy, cache, or retain the bytes of the Customer's files.

The App stores no user profile data. Display names are resolved from Atlassian at the moment of rendering and are never persisted.

Categories of data subjects

  • The Customer's Jira users (agents, administrators, and other licensed users)
  • Jira Service Management portal customers, where the portal module is enabled
  • Any individuals whose personal data happens to appear in a filename chosen by an end user

Special categories of data

The App is not designed for, and we do not knowingly process, special categories of personal data within the meaning of Article 9 GDPR. The Customer determines what files its users upload; those file contents are not processed by us in any event.

Annex II — Technical and organisational measures (Article 32)

Architecture

  • The App runs entirely within Atlassian Forge. We operate no servers and no infrastructure of our own.
  • File contents never pass through or rest on any system we control. The App signs a URL inside Forge; the end user's browser transfers the file directly to the Customer's storage.
  • The App's backend declares no egress permission and is therefore prevented by the Forge platform from making outbound network calls. This is platform-enforced, not merely a policy commitment.

Encryption

  • All traffic to Atlassian and to storage endpoints uses TLS.
  • Signed URLs are generated with HMAC-SHA256 computed inside the Forge runtime; signing keys never leave Forge.
  • Encryption of file contents at rest is provided by the Customer's chosen storage provider. We neither weaken nor substitute those controls.

Access control

  • Authorisation is enforced server-side on every request, against Jira's own attachment permissions or, at the administrator's option, custom project permissions.
  • Signed URLs are issued only after the permission check for that user and operation passes, and are short-lived: 5 minutes for downloads, uploads, and deletes.
  • Jira Service Management portal access is verified against Jira Service Management's own visibility rules for the request, checked as the calling customer before any attachment data is read, written, or signed for. Portal access is read-only unless an administrator explicitly enables portal uploads, and portal customers can never delete attachments.

Secrets

  • Storage credentials are held in Forge encrypted secret storage, are never returned to the browser, and are never written to logs.

Data minimisation and pseudonymisation

  • Uploader identity is stored only as an Atlassian account ID — a pseudonymous reference containing no personal data.
  • User display names are resolved at render time and never persisted, so no profile data is cached.
  • Only the metadata necessary to operate the App is stored.

Logging

  • Diagnostic logs contain Jira issue keys, HTTP status codes, and size counts only. They contain no file contents, no filenames, no personal data, and no credentials.
  • Logs remain within Atlassian's infrastructure and are not transmitted to any third-party logging or monitoring service.

Secure development

  • Written in TypeScript with strict type checking; type checking, linting, an automated test suite, dependency vulnerability scanning (SCA), and static analysis (SAST) are run before each release.
  • The runtime dependency tree is deliberately small, consisting of Atlassian's own Forge packages, React, and a limited set of well-established open-source libraries. No analytics, error-tracking, or telemetry libraries are used.
  • Source is maintained in a private repository with access limited to authorised personnel.

Resilience and availability

The App's availability derives from the Atlassian Forge platform and from the Customer's own storage provider. We operate no infrastructure whose failure could affect availability independently of those two.


Related documents: Privacy Policy · Terms of Use · Security Policy

Contact

T&J Małgorzata Ośródka (brand: VelociBit)
NIP: 7262479786
Jozefow 14B, Jozefow 95-002, Poland
Email: support@velocibit.io