Blobify – Cloud Attachments for Jira · Version 1.0 · Effective date: 2026-07-17 · Last updated: 2026-07-17
| Provider | T&J Małgorzata Ośródka (operating under the brand VelociBit) |
|---|---|
| Registration | NIP 7262479786, Poland |
| Address | Jozefow 14B, Jozefow 95-002, Poland |
| Notices | support@velocibit.io |
| Product | Blobify – Cloud Attachments for Jira, as described in the Documentation and distributed through the Atlassian Marketplace |
The following complete or vary the corresponding provisions of the Standard Agreement.
| Term | Value | Standard Agreement reference |
|---|---|---|
| Governing Law | The laws of Poland, excluding its conflict of laws rules and the UN Convention on Contracts for the International Sale of Goods. This replaces the default of the State of California. | §19.2 |
| Courts | The Polish court having territorial jurisdiction over the Provider's registered seat shall have exclusive jurisdiction over any dispute arising out of or in connection with this Agreement — currently the Sąd Rejonowy w Zgierzu (District Court in Zgierz), or, for claims within the competence of a regional court, the Sąd Okręgowy w Łodzi (Regional Court in Łódź). This replaces the default of the federal and state courts located in San Francisco, California. | §19.2 |
| Data Protection Addendum (our Data Processing Agreement) | https://velocibit.io/blobify-dpa.html | §3.3 |
| Security Measures | https://velocibit.io/blobify-security.html — the technical and organisational measures described there apply in place of the default standard. | §3.2 |
| Support Policy | Section 3 below. | §5.1 |
| Service Level Agreement | None. No SLA is offered for the Product, and no uptime or availability commitment is made. Availability of the Product depends on the Atlassian Forge platform and on Customer's own cloud storage provider. | §5.2 |
| Usage Data | The Provider does not collect Usage Data from the Product. The Product contains no analytics, error-tracking, or telemetry components, and the Provider does not exercise the rights available to it under §3.4. | §3.4 |
The Provider provides support for the Product through its support portal at velocibit.atlassian.net, and by email at support@velocibit.io, in English and Polish, on a commercially reasonable efforts basis during ordinary Polish business days.
The Provider aims, on a reasonable-efforts basis, to provide a first response to support requests within two business days, counted Monday to Friday, 9:00–17:00 Central European Time (CET/CEST), excluding public holidays in the Republic of Poland. This response time is a best-effort target, not a guarantee or a service level commitment, and no response time, resolution time, or availability level is contractually committed. Support does not include configuration, administration, or troubleshooting of Customer's own cloud storage account, network, or credentials, which remain Customer's responsibility under Section 4.
The following reflect how the Product operates and supplement the Standard Agreement.
The Product stores attachment file contents in cloud storage owned and controlled by Customer, at a provider and in a region that Customer selects and configures. Customer is solely responsible for the configuration, security, availability, durability, cost, and retention of that storage account, and for the scope and safekeeping of the credentials it supplies to the Product. The Provider recommends configuring least-privilege, scoped credentials.
Customer's storage provider is Customer's own vendor. The Provider is not a party to, and has no rights or obligations under, Customer's agreement with that provider.
The Product's backend does not receive, process, cache, or retain the contents of Customer's files. The Product generates a short-lived signed URL within the Atlassian Forge platform, and the end user's browser transfers the file directly to Customer's storage. Accordingly, the Provider cannot access, recover, restore, or produce Customer's file contents, and Customer should not rely on the Provider for backup, recovery, or retention of those files.
Uninstalling the Product does not delete files from Customer's storage. This is intentional, so that removing the Product never destroys Customer's data. Customer retains full and direct control of those files and may delete them at any time through its storage provider. Metadata held within Customer's Atlassian instance is removed in accordance with Atlassian's platform data lifecycle.
Customer has direct and independent access to its own storage account at all times and may export file contents from it without the Provider's involvement. Attachment metadata resides within Customer's Atlassian instance and is exportable through Atlassian's own facilities. The Provider holds no copy of Customer's file contents to export or delete. The Provider's deletion obligation under §12.4 of the Standard Agreement extends only to the attachment metadata held by the Product, which is removed as described in Section 4.3.
Where Customer configures a self-hosted or otherwise arbitrary S3-compatible storage endpoint, Customer is responsible for approving that endpoint for its own installation and for the security, encryption, and availability of that infrastructure.
The Product runs on the Atlassian Forge platform and interacts with Customer's own external or self-hosted storage. Without limiting or expanding the liability provisions of the Standard Agreement, the Provider is not responsible for latency, unavailability, downtime, or data loss arising from outages, deprecations, rate limits, or changes to the Atlassian platform or APIs, or from the unavailability, misconfiguration, or failure of Customer's storage provider, network, or self-hosted infrastructure — including any VPN, firewall, DNS, proxy, or other connectivity failure between Customer's environment and its storage. The allocation of liability and the liability caps set out in the Standard Agreement continue to apply unchanged.
The Standard Agreement (§7.2) restricts the submission of Sensitive Data through the Product. Because of how the Product operates, the following clarifies how that restriction applies.
The Product does not receive, inspect, scan, classify, or filter the contents of Customer's files, and therefore applies no content-based controls to them — it cannot detect, block, or treat differently any Sensitive Data a file may contain. File contents are transferred by the end user's browser directly into storage owned and controlled by Customer (Section 4.1). The Provider's backend processes only the metadata described in the Privacy Policy and never the file contents.
Accordingly, Customer decides whether to submit Sensitive Data — including data such as payment card information, health or medical information, government-issued identifiers, or the special categories of personal data under Article 9 GDPR — and is solely responsible for ensuring that its chosen storage provider, region, configuration, and credentials are appropriate and lawful for that data. Customer must not rely on the Product to provide any safeguard, control, certification, or regulatory compliance specific to Sensitive Data (for example PCI DSS or HIPAA controls) at the metadata layer, and the Provider makes no representation that the Product is designed for such data. This Section does not waive or expand the restriction at §7.2 of the Standard Agreement; it describes the division of responsibility for it.
In the event of a conflict, the following order applies: (1) the Data Protection Addendum, with respect to the processing of personal data; (2) these Provider-Specific Terms; (3) the Standard Agreement.
Related documents: Privacy Policy · Data Processing Agreement · Security Policy
T&J Małgorzata Ośródka (brand: VelociBit)
NIP: 7262479786
Jozefow 14B, Jozefow 95-002, Poland
Email: support@velocibit.io