Legal

Privacy Policy

Version 1.0 · Effective date: 2026-07-17 · Last updated: 2026-07-17

This Privacy Policy explains how T&J Małgorzata Ośródka (operating under the brand “VelociBit”) (“we”, “us”, the “Vendor”) processes personal data in connection with the Blobify – Cloud Attachments for Jira app (the “App”) distributed through the Atlassian Marketplace. Our full contact and registration details are in the Contact section below.

This policy covers the Blobify – Cloud Attachments for Jira app, where we act as a data processor. For personal data we process as a controller for our website and contact form, see the Website Privacy Policy.

Contact for privacy matters: support@velocibit.io.

1. Summary (the short version)

  • Blobify stores your Jira attachments in your own cloud storage (Azure Blob Storage or an S3-compatible provider that you configure). The contents of your files never pass through our systems — the App generates signed URLs and your browser uploads/downloads directly to your storage.
  • We process a small amount of metadata (such as filenames, file sizes, and the Atlassian account ID of the person who uploaded a file) needed to make the App work.
  • We store data only within Atlassian's Forge platform (Forge-hosted storage and Jira issue properties). We do not copy your data to servers of our own, we do not sell it, and we do not use it for advertising or analytics profiling.

2. Our role (controller vs. processor)

For the personal data processed through the App, the Atlassian customer (the organization that installs Blobify) is the data controller, and we act as a data processor on that customer's behalf, processing data only to provide the App's functionality. In relation to our own business records (e.g. billing, support correspondence), we act as a controller.

This Policy is complemented by our Data Processing Addendum (DPA) where one applies. Where the App is licensed through the Atlassian Marketplace, Atlassian's own terms and privacy notices also apply to the purchase and billing relationship.

3. What the App does and does NOT store

3.1 We do not store your file contents

Attachment file contents are written directly from your browser to your configured storage bucket/container using short-lived signed URLs. The Vendor operates no backend egress and never receives, copies, caches, or retains the bytes of your files.

3.2 Data the App stores to function

The App stores the following within Atlassian's Forge platform (Forge-hosted storage and/or Jira issue properties — both are Atlassian infrastructure):

DataCategoryWhere storedPurpose
Attachment filenames, sizes, timestampsMay contain personal dataJira issue propertiesList and manage attachments on an issue
Uploader account ID (accountId)Personal data (user reference)Jira issue propertiesShow who uploaded a file; enforce delete permissions
Blob paths / index per issueApp metadataForge Custom Entity StoreTrack which blobs belong to which issue; cleanup
Your storage credentials (e.g. SAS token / access keys)Confidential secretForge encrypted secret storageGenerate signed URLs so your browser can reach your storage
Admin configurationApp settingsForge storageApp configuration

We store only what is listed above. In particular, we never log secrets.

3.3 Your storage provider

The bucket/container you configure belongs to you, at a provider you choose (e.g. Microsoft Azure, Amazon Web Services, or another S3-compatible provider). That provider processes your files as your own sub-processor under your agreement with them, not ours. We recommend configuring least-privilege, scoped credentials for the App.

4. How we use data and legal bases

We process the above data solely to provide and operate the App (storing, listing, uploading, downloading, and deleting attachments; and enforcing permissions). Under the GDPR, the relevant legal bases are:

  • Performance of a contract (Art. 6(1)(b)) — providing the App you or your organization installed;
  • Legitimate interests (Art. 6(1)(f)) — securing the App, preventing abuse, and providing support.

We do not use your data for advertising, profiling, or resale, and we do not use it to train machine-learning models.

5. Sub-processors and third parties

  • Atlassian Pty Ltd — the App runs on Atlassian Forge; all App data at rest resides in Atlassian's infrastructure. Atlassian acts as our (and the customer's) sub-processor / infrastructure provider.
  • Your chosen storage provider — processes your file contents under your own account and agreement (see §3.3).

We do not share personal data with any other third parties except where required by law.

6. International transfers and data residency

App data at rest is held in Atlassian Forge storage, which is within scope of Atlassian's data residency program. Where your organization has configured data residency for its Atlassian products, Forge-hosted App data follows the applicable residency arrangements. File contents reside in the region you select at your storage provider.

Where personal data is transferred outside the European Economic Area (EEA), such transfers are covered by the safeguards operated by our infrastructure sub-processor Atlassian, which relies on the European Commission's Standard Contractual Clauses (SCCs) for cross-border transfers. We do not carry out any separate international transfers of App data of our own.

7. Data retention

  • Attachment metadata persists for the life of the associated Jira issue and is removed as issues/attachments are deleted (including via the App's orphan-cleanup on issue deletion).
  • Storage credentials are retained until an administrator changes or removes them.
  • On app uninstallation, App-controlled data in Forge storage is removed in accordance with Atlassian's app-lifecycle handling.

8. Security

  • No file contents transit or reside on Vendor systems — the design eliminates that exposure entirely.
  • Signed URLs are short-lived and generated locally within Forge.
  • Storage credentials are held in Forge encrypted secret storage and are never written to logs.
  • Access controls follow Jira's own permission model (browse/create/delete checks are enforced server-side).

For our full security practices — including architecture, encryption, vulnerability management, incident response, and how to report a vulnerability — see our Security Policy.

9. Your rights

Depending on your jurisdiction (including under the GDPR), you may have rights to access, rectify, erase, restrict, or port your personal data, and to object to processing. Because we act as a processor for data processed through the App, please direct such requests to your organization's Jira administrator (the controller); we will assist them as required. For data we hold as a controller (e.g. support correspondence), contact us at support@velocibit.io. You also have the right to lodge a complaint with a supervisory authority (in Poland, the President of the Personal Data Protection Office / UODO).

10. No automated decision-making

The App does not carry out automated decision-making or profiling that produces legal or similarly significant effects concerning individuals within the meaning of Article 22 GDPR.

11. Our establishment, representative, and Data Protection Officer

We are established in the European Union (Poland). Accordingly, we are not required to appoint an EU representative under Article 27 GDPR. Given the limited scale of our processing (we do not process special-category data, and we do not carry out large-scale monitoring), we are not required to appoint a Data Protection Officer under Article 37 GDPR. Privacy enquiries can be sent to the contact in the “Contact” section below.

12. Children

The App is a business tool not directed to children and is not intended for use by anyone under the age required to hold an Atlassian account.

13. Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, via the Marketplace listing.


Related documents: Terms of Use · Data Processing Agreement · Security Policy

14. Contact

T&J Małgorzata Ośródka (brand: VelociBit)
NIP: 7262479786
Jozefow 14B, Jozefow 95-002, Poland
Email: support@velocibit.io