Version 1.0 · Effective date: 2026-07-17 · Last updated: 2026-07-17
This Privacy Policy explains how T&J Małgorzata Ośródka (operating under the brand “VelociBit”) (“we”, “us”, the “Vendor”) processes personal data in connection with the Blobify – Cloud Attachments for Jira app (the “App”) distributed through the Atlassian Marketplace. Our full contact and registration details are in the Contact section below.
Contact for privacy matters: support@velocibit.io.
For the personal data processed through the App, the Atlassian customer (the organization that installs Blobify) is the data controller, and we act as a data processor on that customer's behalf, processing data only to provide the App's functionality. In relation to our own business records (e.g. billing, support correspondence), we act as a controller.
This Policy is complemented by our Data Processing Addendum (DPA) where one applies. Where the App is licensed through the Atlassian Marketplace, Atlassian's own terms and privacy notices also apply to the purchase and billing relationship.
Attachment file contents are written directly from your browser to your configured storage bucket/container using short-lived signed URLs. The Vendor operates no backend egress and never receives, copies, caches, or retains the bytes of your files.
The App stores the following within Atlassian's Forge platform (Forge-hosted storage and/or Jira issue properties — both are Atlassian infrastructure):
| Data | Category | Where stored | Purpose |
|---|---|---|---|
| Attachment filenames, sizes, timestamps | May contain personal data | Jira issue properties | List and manage attachments on an issue |
Uploader account ID (accountId) | Personal data (user reference) | Jira issue properties | Show who uploaded a file; enforce delete permissions |
| Blob paths / index per issue | App metadata | Forge Custom Entity Store | Track which blobs belong to which issue; cleanup |
| Your storage credentials (e.g. SAS token / access keys) | Confidential secret | Forge encrypted secret storage | Generate signed URLs so your browser can reach your storage |
| Admin configuration | App settings | Forge storage | App configuration |
We store only what is listed above. In particular, we never log secrets.
The bucket/container you configure belongs to you, at a provider you choose (e.g. Microsoft Azure, Amazon Web Services, or another S3-compatible provider). That provider processes your files as your own sub-processor under your agreement with them, not ours. We recommend configuring least-privilege, scoped credentials for the App.
We process the above data solely to provide and operate the App (storing, listing, uploading, downloading, and deleting attachments; and enforcing permissions). Under the GDPR, the relevant legal bases are:
We do not use your data for advertising, profiling, or resale, and we do not use it to train machine-learning models.
We do not share personal data with any other third parties except where required by law.
App data at rest is held in Atlassian Forge storage, which is within scope of Atlassian's data residency program. Where your organization has configured data residency for its Atlassian products, Forge-hosted App data follows the applicable residency arrangements. File contents reside in the region you select at your storage provider.
Where personal data is transferred outside the European Economic Area (EEA), such transfers are covered by the safeguards operated by our infrastructure sub-processor Atlassian, which relies on the European Commission's Standard Contractual Clauses (SCCs) for cross-border transfers. We do not carry out any separate international transfers of App data of our own.
For our full security practices — including architecture, encryption, vulnerability management, incident response, and how to report a vulnerability — see our Security Policy.
Depending on your jurisdiction (including under the GDPR), you may have rights to access, rectify, erase, restrict, or port your personal data, and to object to processing. Because we act as a processor for data processed through the App, please direct such requests to your organization's Jira administrator (the controller); we will assist them as required. For data we hold as a controller (e.g. support correspondence), contact us at support@velocibit.io. You also have the right to lodge a complaint with a supervisory authority (in Poland, the President of the Personal Data Protection Office / UODO).
The App does not carry out automated decision-making or profiling that produces legal or similarly significant effects concerning individuals within the meaning of Article 22 GDPR.
We are established in the European Union (Poland). Accordingly, we are not required to appoint an EU representative under Article 27 GDPR. Given the limited scale of our processing (we do not process special-category data, and we do not carry out large-scale monitoring), we are not required to appoint a Data Protection Officer under Article 37 GDPR. Privacy enquiries can be sent to the contact in the “Contact” section below.
The App is a business tool not directed to children and is not intended for use by anyone under the age required to hold an Atlassian account.
We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, via the Marketplace listing.
Related documents: Terms of Use · Data Processing Agreement · Security Policy
T&J Małgorzata Ośródka (brand: VelociBit)
NIP: 7262479786
Jozefow 14B, Jozefow 95-002, Poland
Email: support@velocibit.io