Skip to main content

Overview

Scrums.com takes data protection seriously. All client data processed through the platform is handled in accordance with applicable data protection law and our contractual obligations.

What data we process

Delivery data — Sprint records, task assignments, velocity metrics, code quality reports, and delivery performance data generated during engagements. User data — Names, email addresses, and role information for workspace users. This includes both client-side users and Scrums.com engineers deployed in your workspace. Integration data — Data synced from connected tools (Jira, GitHub, Slack, Azure DevOps) within the authorised scope configured at integration setup. Infrastructure data — Usage metrics for cloud services managed through Scrums.com, where applicable (AWS, GCP, Azure).

Data security measures

MeasureDetails
Encryption in transitTLS 1.2 or higher for all data in transit
Encryption at restAES-256 for stored data
Access controlRole-based access control limits data access to authorised users
Security assessmentsRegular penetration testing and vulnerability assessments
Incident responseDefined procedures with notification timelines per GDPR/POPIA requirements

AI and data

Client code and delivery data processed by AI Agents remains within Scrums.com’s secure infrastructure. Data is not used to train external AI models without explicit client consent. Enterprise clients can specify data residency requirements. See AI Usage Boundaries & Controls for full details on how AI Agents interact with client data.

Your rights and our obligations

Scrums.com processes client data as a data processor. Clients act as data controllers for workspace user data. Our Data Processing Agreement (DPA) — available through your Enablement Partner — sets out the obligations of both parties under GDPR, POPIA, and applicable data protection law. For more information, visit the Scrums.com Privacy Policy.

Data retention and deletion

Delivery data is retained for the duration of the engagement and for a defined period thereafter, as specified in your MSA. Upon request, data can be exported and deleted at engagement close. Contact legal@scrums.com for data export or deletion requests.
Last modified on March 13, 2026