Privacy Policy

Last updated: August 2026

1. Introduction

ScrumDesk ("we", "us", "our") operates FlowAnalyzer. This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our service and the choices you have associated with that data.

2. Data We Collect

Account Information

When you create an account, we collect:

  • Email address
  • First and last name
  • Organization/company name
  • Password (encrypted)

Jira Data

When you connect your Jira instance via OAuth, we read (but never write to):

  • Issue history and changelog
  • Issue metadata (summaries, descriptions, status, assignees)
  • Custom field values
  • Workflow transitions and timing
  • Worklog entries and time tracking

We minimize stored issue content: narrative fields are stripped per allow-list. In webhook mode, payloads are processed in real time; in API mode, data is cached briefly (up to 24 hours) with encryption.

Usage Data

We may collect technical information:

  • IP address
  • Browser type and version
  • Pages visited and time spent
  • Clicks and interactions
  • Error logs and diagnostics

Org structure & workforce roster

When you use Org structure, workspace configuration may store:

  • Display names or stable codes you choose for roster people
  • FTE allocations, employment type, and sharing scope
  • Work-tracker account identifiers used to join roster rows to snapshot metrics
  • Identity mode (named, pseudonymous codes, or structure-only) and org-admin acknowledgment when storing real names

Pseudonymous mode reduces displayed and stored legal names but may still process account identifiers from snapshots for capacity analysis. Your organization is the data controller for workforce data; Flow Analyzer acts as processor under your contract and DPA.

Derived collaboration metrics

When enabled on Org structure, we derive collaboration links from pairs of people who share work items in your workspace snapshot (counts of shared issues). This uses the same work-tracker data already ingested for flow analysis.

Collaboration metrics are part of snapshot processing under your contract with us as processor. Flow Analyzer does not collect separate employee consent for this feature; you remain responsible for informing staff as required by your policies.

3. How We Use Your Data

  • To provide and improve the FlowAnalyzer service
  • To analyze your Jira data and generate findings
  • To send service updates and support communications
  • To prevent fraud and ensure security
  • To comply with legal obligations

4. Data Retention

  • Account information: Retained while your account is active. Deleted upon request within 30 days.
  • Jira analysis metadata (findings, timestamps): 90 days
  • Usage logs and diagnostics: 30 days
  • Backups: 90 days (encrypted, automatic purge)

5. Third-Party Services

We use:

  • AWS - Cloud infrastructure and data storage
  • Hubspot - CRM for sales inquiries (contact form data only)
  • Calendly - Demo scheduling
  • Language-model provider (optional) - Advisory AI suggestions when your operator configures AI assist and you opt in per workspace

For the current subprocessor registry and processing locations, see our Subprocessor list.

AI-assisted features (EU AI Act transparency)

Flow Analyzer includes optional AI-assisted coaching (AI Agents hub and Issue detail "What to do next" summaries). These features are off until you intentionally enable AI assist for a workspace. They are advisory only — suggestions are labeled as AI-generated where applicable, and Flow Analyzer does not write back to Jira, ClickUp, or other work trackers automatically.

  • Per-workspace opt-in: each member enables AI assist explicitly in the product; the server stores consent in an HttpOnly cookie (not readable by page scripts).
  • Organization admins can disable AI Agents for their organization; operators can disable agents deployment-wide.
  • You review every suggestion before pasting or acting in your work tracker.
  • AI-generated summaries and rewrites are marked in the UI and API responses (aiGenerated).
  • When a language-model provider is configured, limited issue text and rule finding context may be sent to that provider only after your opt-in.
  • We do not use AI features to profile individuals for employment decisions or sell personal data.

6. Data Residency

By default, data is stored in the US (AWS us-east-1). Enterprise customers can request EU data residency (AWS eu-west-1) at no additional cost.

7. GDPR Rights

If you are in the EU, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate information
  • Deletion: Request deletion of your data (right to be forgotten)
  • Portability: Export your data in a structured format
  • Object: Opt-out of certain processing

To exercise these rights, contact: privacy@scrumdesk.com

8. Data Processing Agreement (DPA)

Enterprise customers receive a fully executed DPA covering GDPR Article 28 processor obligations. Contact security@scrumdesk.com.

9. Security

Your data is protected by TLS encryption in transit and AES-256-GCM encryption at rest. Passwords are hashed with bcrypt. Integration credentials are encrypted at rest—never stored in plaintext and never logged.

10. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of any significant changes by email or by posting the new policy on this page.

11. Contact

For privacy questions, contact: privacy@scrumdesk.com