We hold none of your quality data
The apps run on Atlassian Forge. Documents, records, approvals, and audit trails stay in your Atlassian Cloud site, under your admin controls and your data residency setting.
The apps run on Atlassian Forge. Documents, records, approvals, and audit trails stay in your Atlassian Cloud site, under your admin controls and your data residency setting.
Code, dependencies, and cloud configuration are scanned continuously through Aikido. The audit report is public, and you can request a current copy at any time.
Qity relies on Atlassian AI only, including Rovo and Forge LLM. Customer data is not used to train AI models unless a customer explicitly opts in where applicable.
Qity apps run on Atlassian Forge. Your quality records stay in your own Atlassian Cloud site. Qity does not operate a separate backend that holds them.

Documents, records, approvals, and audit trails are Jira and Confluence data in your tenant, under your admin controls and your data residency setting.

The apps run inside Atlassian's platform and read and write your data there. Qity has no separate copy of your quality records.
Contact requests, support tickets, and commercial correspondence. Qity is the controller for this, and the privacy policy sets out the detail.
The full list of sub-processors used to deliver the apps and the services, with the purpose and processing location of each.
Qity notifies customers of changes to this list before a new sub-processor starts processing.
Generated on request, no NDA
Version 1, effective 19 June 2026
Published on this page
Architecture, access control, and secure development
Template for the services engagements
Summarised below, full procedure on request
Qity has a named data protection officer. Requests and questions go to dpo@qity.be, and the privacy policy sets out the full detail, including your rights.
Qity maintains an incident and breach procedure. Incidents are recorded, assessed for personal data impact, and escalated to the data protection officer. Where a personal data breach is confirmed and notification is required, the controller notifies the supervisory authority within 72 hours of becoming aware, and Qity notifies affected customers without undue delay where Qity acts as processor. The full procedure is available on request.
Built for regulated industries
ISO 9001
ISO 13485
ISO 27001
EU MDR / IVDR
GDPR
FDA