ScrumDo GDPR & International Transfers Addendum
Version: 1.8
Effective Date: January 1, 2025
Last Restated: July 11, 2026
This GDPR & International Transfers Addendum (“Addendum”) supplements ScrumDo’s Privacy Policy, Terms of Use, and (where applicable) our Data Processing Agreement (“DPA”). It explains how ScrumDo addresses requirements under the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”), and related European data protection laws, including UK GDPR where applicable.
This Addendum is provided for transparency. Where ScrumDo processes personal data as a processor/service provider for an organizational customer, the DPA governs the parties’ processing relationship.
1. Scope
1.1 Who this applies to. This Addendum applies to personal data processed by ScrumDo in connection with:
the offering of goods or services to individuals in the European Economic Area (EEA) and/or the United Kingdom (UK); and/or
the monitoring of behavior within the EEA/UK, to the extent governed by applicable law.
1.2 Definitions. Capitalized terms not defined in this Addendum have the meanings in the Terms of Use, Privacy Policy, and DPA (as applicable). “Personal Data” has the meaning set forth in GDPR.
1.3 Controller vs Processor.
Organization Accounts: the organizational Account Owner is typically the Controller for Personal Data within its Rooms, Boards, contribution routes, and connected services; ScrumDo acts as Processor/Service Provider under a DPA where applicable.
Direct individual relationships: ScrumDo may act as Controller for Personal Plan account, billing, support, security, and service-usage data, as described in the Privacy Policy.
This Addendum is a transparency document. It does not authorize a Customer to collect or route Personal Data without the notices, consent, lawful basis, safeguards, and Enterprise review required by the Agreement and applicable law.
2. Lawful Bases for Processing (Controller Context)
Where ScrumDo acts as a Controller, we process Personal Data based on one or more lawful bases under GDPR Article 6, including:
2.1 Performance of a Contract (Art. 6(1)(b)). For example:
creating and administering an account,
providing and maintaining the Services,
processing transactions related to subscriptions or purchases (if applicable),
providing user-requested functionality.
2.2 Legitimate Interests (Art. 6(1)(f)). For example:
securing and protecting the Services,
preventing fraud and abuse,
improving reliability and performance,
communicating service-related notices,
where our legitimate interests are not overridden by your rights and interests.
2.3 Consent (Art. 6(1)(a)). For example:
optional marketing communications (where required),
non-essential cookies and tracking (where required),
optional feature enablement where consent is the appropriate basis.
2.4 Legal Obligation (Art. 6(1)(c)). For example:
compliance with applicable laws,
responding to lawful requests from authorities,
maintaining records required by law.
Note: Where ScrumDo acts as a Processor, the organizational Controller determines the lawful basis for processing under that Controller’s responsibilities. ScrumDo processes Personal Data under the Controller’s instructions as described in the DPA, subject to the Agreement.
3. Data Subject Rights
Individuals in the EEA/UK have rights under GDPR Articles 15–22, subject to conditions and exceptions under applicable law, including:
Right of access (Art. 15)
Right to rectification (Art. 16)
Right to erasure (Art. 17)
Right to restrict processing (Art. 18)
Right to data portability (Art. 20)
Right to object (Art. 21)
Rights related to automated decision-making (Art. 22)
3.1 How to exercise rights
If ScrumDo is the Controller for the data at issue, you may submit a request by emailing: privacy@scrumdo.com.
If you are an Authorized User or Customer Contributor in an Organization Account, the organizational Account Owner is typically the Controller for the relevant Content. In that case, you should direct requests to the Account Owner. ScrumDo will assist the Controller as required by the DPA.
3.2 Identity verification
We may request information sufficient to verify your identity before fulfilling a request, to protect Personal Data from unauthorized disclosure.
3.3 Response timing
We aim to respond within GDPR timeframes (typically one month), subject to lawful extensions for complex requests.
4. Automated Decisions, Transcription, Translation, and PII Redaction
4.1 No solely automated decisions with legal/significant effects. ScrumDo does not use solely automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of GDPR Article 22, for core account eligibility or access.
4.2 Transcription, translation, PII redaction, and AI processing. Some features may use automated or third-party processing to deliver functionality you request. ScrumDo does not train a proprietary foundation model on Customer Content. How Content reaches a model or automated provider depends on the feature:
Local agents (BYOA). For an agent that runs on infrastructure you control under your own provider account and keys, ScrumDo does not call the model or transmit Content to the model provider. Your agent makes that connection.
Customer-configured AI. If you enable an optional feature that uses a provider and credentials you configure, ScrumDo sends the Content and feature inputs selected by that configuration to the provider on your instruction. Depending on the feature, this may include card specifications, related-card summaries, or a read-only repository snapshot. You are responsible for the provider agreement, the lawfulness of the instruction, any required transfer safeguards, and determining the parties' roles under applicable law. These features are off until you enable them.
ScrumDo operational AI. ScrumDo may use an AI provider under its own account for limited operational functions, such as support-ticket assistance. For that processing, the provider is a ScrumDo Subprocessor and must be identified on the Subprocessors List.
For Customer-configured AI, ScrumDo does not independently choose or add Personal Data to the Content you direct to the provider. You remain responsible for the Content you submit, including Personal Data or sensitive information included inadvertently. AI-assisted and automated outputs may be inaccurate or incomplete and are not a substitute for human review. Additional processing details appear in the Privacy Policy, DPA, Subprocessors List, and feature notices.
4.3 Notifications and connected destinations. If you or an Account Owner enables delivery to email, SMS, WhatsApp, Slack, Microsoft Teams, push, or a webhook, selected notification content, routing metadata, and delivery status may be transmitted to the configured provider or destination. The Account Owner is responsible for authorizing the destination, choosing what may be sent, maintaining recipient and workspace mappings, and obtaining any consent required for the selected channel. Providers engaged by ScrumDo are identified on the Subprocessors List. A provider configured under the Customer's own account operates under the Customer's agreement with that provider.
4.4 Optional processing controls. Where feasible and appropriate, optional processing may be controlled through account settings or feature toggles. In organizational contexts, those choices may be controlled by the Account Owner as Controller.
5. Security Measures
ScrumDo maintains reasonable technical and organizational measures designed to protect Personal Data, including access controls and monitoring. Additional enterprise security features may be available for certain deployments as specified by Order Form or enterprise addenda.
No system can be guaranteed 100% secure; you are responsible for safeguarding credentials and devices.
6. International Transfers
6.1 Transfer locations. ScrumDo may process Personal Data in the United States and other jurisdictions depending on service configuration, enabled features, subprocessor operations, and applicable customer agreements.
6.2 Transfer safeguards. Where GDPR/UK GDPR requires safeguards for international transfers, ScrumDo relies on appropriate mechanisms, which may include:
Standard Contractual Clauses (SCCs) approved by the European Commission,
UK International Data Transfer Addendum and/or UK IDTA as applicable,
and supplemental technical and organizational measures, as appropriate.
6.3 Documentation. Transfer mechanisms and applicable subprocessors are addressed in the DPA (where applicable) and referenced in the Subprocessors List.
7. Data Retention
ScrumDo retains Personal Data for periods consistent with:
the purposes described in the Privacy Policy,
contractual obligations,
instructions and configurations of Controllers (for Organization Accounts),
and legal requirements.
Where deletion is requested, ScrumDo may retain limited information as required by law or to protect platform integrity (e.g., security, fraud prevention, or dispute resolution).
8. Complaints and Supervisory Authorities
If you have concerns about our processing, please contact privacy@scrumdo.com first so we can attempt to resolve your concern.
You may also have the right to lodge a complaint with your local supervisory authority in the EEA/UK.
9. Contact
**ScrumDo, LLC ** Privacy: **privacy@scrumdo.com ** Legal: legal@scrumdo.com
10. Relationship to DPA
If you are an organizational customer and a DPA applies, the DPA governs the processor/service provider obligations between the parties. This Addendum is a transparency document and does not override the DPA.
