Legal

Provider-Specific Terms

Blobify – Cloud Attachments for Jira · Version 1.0 · Effective date: 2026-07-17 · Last updated: 2026-07-17

These Provider-Specific Terms supplement the Bonterms Standard End User Agreement (Version 1.0) (the “Standard Agreement”), available at atlassian.com/licensing/marketplace/end-user-agreement-v1. Together they form the agreement under which Blobify – Cloud Attachments for Jira is licensed. Capitalised terms not defined here have the meaning given in the Standard Agreement.

1. Provider

ProviderT&J Małgorzata Ośródka (operating under the brand VelociBit)
RegistrationNIP 7262479786, Poland
AddressJozefow 14B, Jozefow 95-002, Poland
Noticessupport@velocibit.io
ProductBlobify – Cloud Attachments for Jira, as described in the Documentation and distributed through the Atlassian Marketplace

2. Key Terms

The following complete or vary the corresponding provisions of the Standard Agreement.

TermValueStandard Agreement reference
Governing Law The laws of Poland, excluding its conflict of laws rules and the UN Convention on Contracts for the International Sale of Goods. This replaces the default of the State of California. §19.2
Courts The Polish court having territorial jurisdiction over the Provider's registered seat shall have exclusive jurisdiction over any dispute arising out of or in connection with this Agreement — currently the Sąd Rejonowy w Zgierzu (District Court in Zgierz), or, for claims within the competence of a regional court, the Sąd Okręgowy w Łodzi (Regional Court in Łódź). This replaces the default of the federal and state courts located in San Francisco, California. §19.2
Data Protection Addendum (our Data Processing Agreement) https://velocibit.io/blobify-dpa.html §3.3
Security Measures https://velocibit.io/blobify-security.html — the technical and organisational measures described there apply in place of the default standard. §3.2
Support Policy Section 3 below. §5.1
Service Level Agreement None. No SLA is offered for the Product, and no uptime or availability commitment is made. Availability of the Product depends on the Atlassian Forge platform and on Customer's own cloud storage provider. §5.2
Usage Data The Provider does not collect Usage Data from the Product. The Product contains no analytics, error-tracking, or telemetry components, and the Provider does not exercise the rights available to it under §3.4. §3.4

3. Support Policy

The Provider provides support for the Product through its support portal at velocibit.atlassian.net, and by email at support@velocibit.io, in English and Polish, on a commercially reasonable efforts basis during ordinary Polish business days.

The Provider aims, on a reasonable-efforts basis, to provide a first response to support requests within two business days, counted Monday to Friday, 9:00–17:00 Central European Time (CET/CEST), excluding public holidays in the Republic of Poland. This response time is a best-effort target, not a guarantee or a service level commitment, and no response time, resolution time, or availability level is contractually committed. Support does not include configuration, administration, or troubleshooting of Customer's own cloud storage account, network, or credentials, which remain Customer's responsibility under Section 4.

4. Product-Specific Terms

The following reflect how the Product operates and supplement the Standard Agreement.

4.1 Customer-controlled storage

The Product stores attachment file contents in cloud storage owned and controlled by Customer, at a provider and in a region that Customer selects and configures. Customer is solely responsible for the configuration, security, availability, durability, cost, and retention of that storage account, and for the scope and safekeeping of the credentials it supplies to the Product. The Provider recommends configuring least-privilege, scoped credentials.

Customer's storage provider is Customer's own vendor. The Provider is not a party to, and has no rights or obligations under, Customer's agreement with that provider.

4.2 No Provider access to file contents

The Product's backend does not receive, process, cache, or retain the contents of Customer's files. The Product generates a short-lived signed URL within the Atlassian Forge platform, and the end user's browser transfers the file directly to Customer's storage. Accordingly, the Provider cannot access, recover, restore, or produce Customer's file contents, and Customer should not rely on the Provider for backup, recovery, or retention of those files.

4.3 Effect of uninstallation

Uninstalling the Product does not delete files from Customer's storage. This is intentional, so that removing the Product never destroys Customer's data. Customer retains full and direct control of those files and may delete them at any time through its storage provider. Metadata held within Customer's Atlassian instance is removed in accordance with Atlassian's platform data lifecycle.

4.4 Data export

Customer has direct and independent access to its own storage account at all times and may export file contents from it without the Provider's involvement. Attachment metadata resides within Customer's Atlassian instance and is exportable through Atlassian's own facilities. The Provider holds no copy of Customer's file contents to export or delete. The Provider's deletion obligation under §12.4 of the Standard Agreement extends only to the attachment metadata held by the Product, which is removed as described in Section 4.3.

4.5 Customer-managed egress

Where Customer configures a self-hosted or otherwise arbitrary S3-compatible storage endpoint, Customer is responsible for approving that endpoint for its own installation and for the security, encryption, and availability of that infrastructure.

4.6 Reliance on external infrastructure

The Product runs on the Atlassian Forge platform and interacts with Customer's own external or self-hosted storage. Without limiting or expanding the liability provisions of the Standard Agreement, the Provider is not responsible for latency, unavailability, downtime, or data loss arising from outages, deprecations, rate limits, or changes to the Atlassian platform or APIs, or from the unavailability, misconfiguration, or failure of Customer's storage provider, network, or self-hosted infrastructure — including any VPN, firewall, DNS, proxy, or other connectivity failure between Customer's environment and its storage. The allocation of liability and the liability caps set out in the Standard Agreement continue to apply unchanged.

5. Sensitive Data

The Standard Agreement (§7.2) restricts the submission of Sensitive Data through the Product. Because of how the Product operates, the following clarifies how that restriction applies.

The Product does not receive, inspect, scan, classify, or filter the contents of Customer's files, and therefore applies no content-based controls to them — it cannot detect, block, or treat differently any Sensitive Data a file may contain. File contents are transferred by the end user's browser directly into storage owned and controlled by Customer (Section 4.1). The Provider's backend processes only the metadata described in the Privacy Policy and never the file contents.

Accordingly, Customer decides whether to submit Sensitive Data — including data such as payment card information, health or medical information, government-issued identifiers, or the special categories of personal data under Article 9 GDPR — and is solely responsible for ensuring that its chosen storage provider, region, configuration, and credentials are appropriate and lawful for that data. Customer must not rely on the Product to provide any safeguard, control, certification, or regulatory compliance specific to Sensitive Data (for example PCI DSS or HIPAA controls) at the metadata layer, and the Provider makes no representation that the Product is designed for such data. This Section does not waive or expand the restriction at §7.2 of the Standard Agreement; it describes the division of responsibility for it.

6. Order of precedence

In the event of a conflict, the following order applies: (1) the Data Protection Addendum, with respect to the processing of personal data; (2) these Provider-Specific Terms; (3) the Standard Agreement.


Related documents: Privacy Policy · Data Processing Agreement · Security Policy

7. Contact

T&J Małgorzata Ośródka (brand: VelociBit)
NIP: 7262479786
Jozefow 14B, Jozefow 95-002, Poland
Email: support@velocibit.io