Version 1.0 · Effective date: 2026-07-17 · Last updated: 2026-07-17
This DPA is entered into between:
This DPA applies only to our processing of Customer Personal Data in connection with the App. It does not apply to personal data for which we act as a controller (for example billing records and support correspondence), which is governed by the Privacy Policy.
The parties agree that, with respect to Customer Personal Data processed through the App, the Customer is the data controller and VelociBit is the data processor within the meaning of Article 4 GDPR. The Customer determines the purposes and essential means of processing, including which storage provider and region to use, which files are uploaded, who may access them, and how long they are retained.
Where the Customer is itself a processor acting on behalf of a third-party controller, the Customer warrants that it has the necessary authority to instruct us as a sub-processor on that controller's behalf.
The subject matter, duration, nature, purpose, types of personal data, and categories of data subjects are set out in Annex I below.
We shall process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do so by Union or Member State law to which we are subject. In that case, we shall inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
The Customer's instructions are constituted by: (a) this DPA; (b) the licence agreement for the App; (c) the Customer's configuration of the App (including the storage provider, region, permission model, and feature toggles selected by the Customer's administrators); and (d) the Customer's use of the App's functionality.
We shall inform the Customer if, in our opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
We do not use Customer Personal Data for our own purposes, and in particular we do not use it for advertising, profiling, resale, or to train machine-learning models.
We ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, and that access is limited to those personnel who require it in order to provide, maintain, and support the App.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Those measures are described in Annex II below and, in more detail, in our Security Policy.
The Customer acknowledges that it is responsible for the security configuration of its own cloud storage account, including access controls, encryption settings, network restrictions, and the scope of the credentials it supplies to the App. We recommend configuring least-privilege, scoped credentials.
The Customer grants us general written authorisation to engage sub-processors, subject to this section.
Our current sub-processor is:
| Sub-processor | Role | Location |
|---|---|---|
| Atlassian Pty Ltd | Provider of the Atlassian Forge platform, on which the App runs and where App data at rest resides | Per Atlassian's own infrastructure and data residency arrangements |
We shall inform the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, giving the Customer the opportunity to object on reasonable data protection grounds. Notification will be given by updating this page and the Marketplace listing. If the Customer objects and the parties cannot agree a resolution, the Customer may terminate its use of the App in accordance with the termination provisions of the licence agreement.
Where we engage a sub-processor, we impose on it data protection obligations no less protective than those set out in this DPA, and we remain fully liable to the Customer for the performance of that sub-processor's obligations.
The Customer's own storage provider is not our sub-processor. The bucket or container configured in the App belongs to the Customer, at a provider the Customer selects, under the Customer's own agreement with that provider. That provider acts as the Customer's own processor or sub-processor, not ours. We never receive, copy, cache, or retain the contents of files stored there.
Taking into account the nature of the processing, we shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests for exercising a data subject's rights under Chapter III GDPR.
The App is designed so that the Customer can satisfy most such requests directly, without our involvement: attachment metadata is visible and deletable through the Jira issue view, and file contents reside in the Customer's own storage, to which the Customer has direct and independent access. If we receive a request directly from a data subject in relation to Customer Personal Data, we shall not respond to it substantively but shall refer the data subject to the Customer and inform the Customer without undue delay.
Taking into account the nature of processing and the information available to us, we shall assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR, including security of processing, personal data breach notification, data protection impact assessments, and prior consultation.
We shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event within 72 hours of becoming aware. Our notification shall describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. We shall provide further information as it becomes available and shall cooperate with the Customer in its own notification obligations under Articles 33 and 34 GDPR.
The Customer acknowledges that, because file contents never reside on systems we control, a compromise of the Processor could not expose the contents of the Customer's files. A breach affecting the Customer's own storage account is outside our control and is the Customer's responsibility to assess and notify.
At the Customer's choice, we shall delete or return all Customer Personal Data after the end of the provision of services relating to processing, and delete existing copies, unless Union or Member State law requires storage.
In practice:
Because we operate no storage of our own, there is no Processor-held copy of Customer Personal Data to return or delete.
We shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
In the first instance, we shall satisfy such requests by providing our Security Policy, our Privacy Policy, and written responses to reasonable security questionnaires. Where those are insufficient for the Customer's demonstrable compliance needs, an audit may be conducted no more than once in any 12-month period, on at least 30 days' prior written notice, during normal business hours, in a manner that does not unreasonably disrupt our operations, and subject to appropriate confidentiality obligations. Each party bears its own costs, save that where an audit reveals a material breach by us of this DPA, we shall bear the reasonable costs of that audit.
We do not carry out any international transfers of Customer Personal Data of our own. All App data at rest resides within Atlassian's infrastructure. Where personal data is transferred outside the European Economic Area, such transfers are covered by the safeguards operated by our sub-processor Atlassian, which relies on the European Commission's Standard Contractual Clauses for cross-border transfers.
File contents are transferred by the end user's browser directly to the storage location the Customer selects. The Customer determines that location and is responsible for any transfer implications arising from its choice of provider and region.
Each party's liability arising out of or in connection with this DPA is subject to, and counts towards, the limitations and exclusions of liability set out in the licence agreement (including the Bonterms Standard End User Agreement and any Provider-Specific Terms). Nothing in this DPA excludes or limits either party's liability to the extent such exclusion or limitation is not permitted by applicable law, including a data subject's right to compensation under Article 82 GDPR.
This DPA takes effect on the date the Customer first installs the App and continues for as long as we process Customer Personal Data on the Customer's behalf. Sections that by their nature should survive termination shall survive.
This DPA is governed by the laws of Poland, excluding its conflict of laws rules, consistent with the governing law of the Provider-Specific Terms. The Polish courts having territorial jurisdiction over the Processor's registered seat shall have exclusive jurisdiction over any dispute arising out of or in connection with this DPA. Where the Standard Contractual Clauses apply to a particular transfer, the governing law and forum provisions of those Clauses prevail in respect of that transfer.
In the event of a conflict between this DPA and the licence agreement, this DPA prevails with respect to the processing of Customer Personal Data. In the event of a conflict between this DPA and the Standard Contractual Clauses (where applicable), the Standard Contractual Clauses prevail.
This DPA is incorporated by reference into the licence agreement and is accepted by the Customer when the Customer installs or uses the App. Where a Customer requires a countersigned copy for its own records, one is available on request at support@velocibit.io.
Provision of the Blobify – Cloud Attachments for Jira app, which stores Jira issue attachments in the Customer's own cloud storage and manages the associated metadata within Atlassian.
For as long as the Customer has the App installed.
Storing, listing, uploading, downloading, and deleting attachments; indexing attachment metadata for search in JQL; and enforcing access permissions. Processing is carried out solely to provide and operate the App.
| Data | Category | Where stored |
|---|---|---|
| Attachment filenames, file sizes, MIME types, upload timestamps | May contain personal data | Jira issue properties |
Uploader account ID (accountId) | Personal data (user reference) | Jira issue properties |
| Aggregate index for JQL — total size, count, filenames, last uploader account ID | May contain personal data | Jira issue properties |
| Blob object paths per issue (paths include filenames) | May contain personal data | Forge Custom Entity Store |
Not processed by us: attachment file contents. Files are transferred directly from the end user's browser to the Customer's own cloud storage using short-lived signed URLs. We operate no backend egress and never receive, copy, cache, or retain the bytes of the Customer's files.
The App stores no user profile data. Display names are resolved from Atlassian at the moment of rendering and are never persisted.
The App is not designed for, and we do not knowingly process, special categories of personal data within the meaning of Article 9 GDPR. The Customer determines what files its users upload; those file contents are not processed by us in any event.
The App's availability derives from the Atlassian Forge platform and from the Customer's own storage provider. We operate no infrastructure whose failure could affect availability independently of those two.
Related documents: Privacy Policy · Terms of Use · Security Policy
T&J Małgorzata Ośródka (brand: VelociBit)
NIP: 7262479786
Jozefow 14B, Jozefow 95-002, Poland
Email: support@velocibit.io