We hold none of your quality data
The apps run on Atlassian Forge. Documents, records, approvals, and audit trails stay in your Atlassian Cloud site, under your admin controls and your data residency setting.
TRUST AND SECURITY
Qity works inside regulated quality systems every day, as a consultancy and as an app vendor. The same discipline applies to how we build and run the apps, and to how we handle personal data.
The apps run on Atlassian Forge. Documents, records, approvals, and audit trails stay in your Atlassian Cloud site, under your admin controls and your data residency setting.
Code, dependencies, and cloud configuration are scanned continuously through Aikido. The audit report is public, and you can request a current copy at any time.
Qity relies on Atlassian AI only, including Rovo and Forge LLM. Customer data is not used to train AI models unless a customer explicitly opts in where applicable.
Qity apps run on Atlassian Forge. Your quality records stay in your own Atlassian Cloud site. Qity does not operate a separate backend that holds them.

Documents, records, approvals, and audit trails are Jira and Confluence data in your tenant, under your admin controls and your data residency setting.

The apps run inside Atlassian's platform and read and write your data there. Qity has no separate copy of your quality records.
Contact requests, support tickets, and commercial correspondence. Qity is the controller for this, and the privacy policy sets out the detail.
The full list used to deliver the apps and the services, with the purpose and processing location of each. Qity notifies customers of changes at least 30 days before a new sub-processor begins processing.
The transfer position for each is recorded in Annex 4 of the data processing agreement.
Seven are published. Two are issued on request, to customers and prospective customers under an NDA.
Qity has a named data protection officer. Requests and questions go to dpo@qity.be, and the privacy policy sets out the full detail, including your rights.
Report an actual or suspected security incident or vulnerability to security@qity.be. No NDA is required, and the procedure sets out the roles and notification timelines.
Four pages set out how Qity actually operates, rather than what it aspires to.
Qity maintains an incident and breach procedure. Incidents are recorded, assessed for personal data impact, and escalated to the data protection officer. Where a personal data breach is confirmed and notification is required, the controller notifies the supervisory authority within 72 hours of becoming aware, and Qity notifies affected customers without undue delay where Qity acts as processor. The full procedure is summarised at How Qity handles security incidents, and the complete controlled document is available on request.
Built for regulated industries
ISO 9001
ISO 13485
ISO 27001
EU MDR / IVDR
GDPR
FDA