> ## Documentation Index
> Fetch the complete documentation index at: https://www.scrums.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Protection & Privacy

> How Scrums.com handles, protects, and stores client and delivery data.

## Overview

All client data processed through the platform is handled in accordance with applicable data protection law and our contractual obligations.

## What data we process

**Delivery data** — Sprint records, task assignments, velocity metrics, code quality reports, and delivery performance data generated during engagements.

**User data** — Names, email addresses, and role information for workspace users. This includes both client-side users and Scrums.com engineers deployed in your workspace.

**Integration data** — Data synced from connected tools (Jira, GitHub, Slack, Azure DevOps) within the authorised scope configured at integration setup.

**Infrastructure data** — Usage metrics for cloud services managed through Scrums.com, where applicable (AWS, GCP, Azure).

## Data security measures

| Measure               | Details                                                                    |
| --------------------- | -------------------------------------------------------------------------- |
| Encryption in transit | TLS 1.2 or higher for all data in transit                                  |
| Encryption at rest    | AES-256 for stored data                                                    |
| Access control        | Role-based access control limits data access to authorised users           |
| Security assessments  | Regular penetration testing and vulnerability assessments                  |
| Incident response     | Defined procedures with notification timelines per GDPR/POPIA requirements |

## AI and data

Client code and delivery data processed by AI Agents remains within Scrums.com's secure infrastructure. Data is not used to train external AI models without explicit client consent. Enterprise clients can specify data residency requirements.

See [AI Usage Boundaries & Controls](/docs/products/agents/ai-controls) for full details on how AI Agents interact with client data.

## Your rights and our obligations

Scrums.com processes client data as a data processor. Clients act as data controllers for workspace user data. Our Data Processing Agreement (DPA) — available through your Enablement Partner — sets out the obligations of both parties under GDPR, POPIA, and applicable data protection law.

For more information, visit the [Scrums.com Privacy Policy](https://www.scrums.com/legal/privacy-policy).

## Data retention and deletion

Delivery data is retained for the duration of the engagement and for a defined period thereafter, as specified in your MSA. Upon request, data can be exported and deleted at engagement close.

Contact [legal@scrums.com](mailto:legal@scrums.com) for data export or deletion requests.
