ScrumDo Data Subprocessors
Version: 1.8
Effective Date: January 1, 2025
Last Restated: July 11, 2026
This page lists subprocessors that may process personal data on ScrumDo’s behalf to provide the Services.
For enterprise customers, subprocessors are governed by the applicable Data Processing Agreement (DPA) and this list may be updated from time to time.
This list describes service providers that may process data when an applicable feature, workflow, or integration is enabled under the ScrumDo Terms package and any Order Form. Inclusion on this list does not authorize a Customer to collect or route Personal Information without the notices, consent, lawful basis, safeguards, and Enterprise review required by the Agreement and applicable law.
The location column describes typical or provider-available processing locations. Actual hosting and processing locations depend on the applicable service configuration, enabled features, subprocessor operations, and any Order Form, DPA, proposal, or security review commitments.
1. Core Infrastructure and Service Providers
| Subprocessor | Services Used | Typical Data Categories | Primary Purpose | Typical Processing Location |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, storage, networking, infrastructure security tooling | Account metadata, application data, logs, backups | Platform hosting and availability | Configured AWS region(s), subject to applicable account/project setup |
| Stripe Payments | Payment processing and billing workflows | Payment metadata, billing details, transaction records | Subscription and payment processing | United States |
| Google Cloud / Google Translate | Translation APIs | Text submitted for translation, language metadata | Translation and multilingual support | Global |
| Sonix | Transcription, translation, and optional PII redaction workflows | Audio files, transcription text, translation output, redaction metadata | Transcription, translation, and optional PII redaction workflows | EU/EEA and/or global |
| Ably | Realtime messaging and presence | Realtime message payloads, presence metadata, connection data | Collaboration and realtime facilitation features | Global |
| PostHog | Product analytics and telemetry | Usage events, feature interaction data, diagnostic metadata | Product analytics and troubleshooting | United States |
| Sentry | Error monitoring and performance telemetry | Error traces, performance metrics, runtime diagnostics | Reliability monitoring and incident triage | United States |
| GitHub Actions | CI/CD automation | Source code, build logs, deployment metadata | Build, test, and deployment automation | Global |
| GitLab (Optional Add-on) | Optional source hosting and CI/CD | Source code, build logs, deployment metadata | Optional enterprise integration | Global |
| Bitbucket (Optional Add-on) | Optional source hosting and CI/CD | Source code, build logs, deployment metadata | Optional enterprise integration | Global |
| Tremendous | Reward/incentive fulfillment | Team member contact details for rewards, redemption metadata | Incentive delivery where enabled | United States |
| Plausible | Privacy-focused web analytics | Aggregated website metrics (designed to avoid personal identifiers) | Website analytics | European Union |
| OpenAI, L.L.C. (when operational support AI is enabled) | AI-assisted support-ticket summaries and suggested replies under ScrumDo's own account | Support ticket subject, body, and reply thread | AI-assisted support-ticket summaries and suggested replies | United States |
Connected AI providers (customer-configured): for optional Connected AI features, the provider is the one you configure and authenticate with your own key. It operates under your account and provider agreement and is not engaged by ScrumDo as a Subprocessor for that connection, so it is not listed above. The Customer remains responsible for determining the provider's role under applicable law.
Customer-configured notification providers: when an Account Owner connects email, SMS, WhatsApp, Slack, Microsoft Teams, push, or webhook delivery using the Customer's own provider account or credentials, that provider operates under the Customer's agreement and is not ScrumDo's subprocessor. If ScrumDo supplies or contracts for a delivery provider, the provider must be listed above before that processing is enabled for Customer Data.
2. Legacy/Deprecated Provider
| Subprocessor | Status | Notes |
|---|---|---|
| New Relic | Deprecated | Legacy performance monitoring provider being phased out in favor of Sentry. |
3. Transfer and Security Safeguards
ScrumDo applies contractual and technical safeguards appropriate to applicable law, which may include:
- Standard Contractual Clauses (SCCs) and related transfer mechanisms where required.
- Subprocessor agreements with confidentiality and security obligations.
- Access controls, encryption in transit, and monitoring controls appropriate to the service.
4. Changes to This List
ScrumDo may update this list from time to time as subprocessors are added, removed, or changed.
If you are an enterprise customer under a DPA and need notice or objection workflow details, contact legal@scrumdo.com.
5. Contact
- Legal: legal@scrumdo.com
- Privacy: privacy@scrumdo.com
- Support: support@scrumdo.com
