LEGAL

Data Processing Agreement

Last updated: 10 August 2026

This Data Processing Agreement ("DPA") applies where Precision Systems, operator of Sprint Buddy, processes personal data on behalf of a customer as a processor under Article 28 of the GDPR. It supplements and forms part of the Terms of Service. Where this DPA conflicts with the Terms of Service on processing of personal data, this DPA prevails.

Parties

  • Processor: Precision Systems (operator of Sprint Buddy), Kukucinova 52/2, 831 03 Bratislava, Slovakia, company registration number 56305117
  • Controller: the customer entity that created the workspace and uses Sprint Buddy
  • Contact for data protection matters: privacy@sprintbuddy.app

No signature is required. This DPA takes effect automatically when you accept the Terms of Service and start using Sprint Buddy. If your organization needs a countersigned copy, email privacy@sprintbuddy.app.

1. Roles of the parties

The customer is the controller and determines the purposes and means of processing. Sprint Buddy is the processor and processes personal data only on documented instructions from the controller, including the instructions inherent in using the Service and its configured integrations. Where Sprint Buddy processes account, billing and security-log data for its own purposes, it acts as an independent controller under the Privacy Policy.

2. Subject matter and duration

The subject matter is the provision of the Sprint Buddy platform: synchronizing sprint and issue data from connected tools, generating reports, retrospectives and analytics, and supporting collaboration within a workspace. Processing lasts for the duration of the subscription and any wind-down period described in section 11.

3. Nature and purpose of processing

Collection, storage, structuring, retrieval, analysis, generation of derived content with AI models, display within the workspace, transmission to the connected tools you authorize, backup, and deletion.

4. Categories of data subjects

  • the customer's users, administrators and workspace members;
  • individuals named in synchronized issues, sprints, comments and reports (for example assignees and reporters);
  • individuals mentioned in meeting transcripts or other content the customer submits.

5. Types of personal data

  • identity and contact data: name, display name, email address, account and user identifiers;
  • workspace data: roles, memberships and invitations;
  • project data from connected tools: issue keys, summaries, descriptions, statuses, story points, assignee and reporter names, sprint metadata;
  • content submitted by the customer: retrospective notes, comments, meeting transcripts and generated reports;
  • technical data: IP address, device and browser information, timestamps, error and security logs.

6. Special categories of data

The Service is not designed for special categories of personal data under Article 9 GDPR or for criminal-offence data. The customer must not submit such data, and remains responsible if it does so.

7. Processor obligations

  • process personal data only on the controller's documented instructions, unless required otherwise by EU or member-state law;
  • ensure that persons authorized to process personal data are bound by confidentiality;
  • implement the technical and organizational measures described in section 8;
  • respect the conditions for engaging sub-processors in section 9;
  • assist the controller with data-subject requests, security incidents, data protection impact assessments and prior consultations, taking into account the nature of processing and the information available;
  • make available the information necessary to demonstrate compliance with Article 28 GDPR;
  • inform the controller if an instruction appears to infringe data protection law.

8. Security measures

  • encryption in transit (TLS) and encryption of stored integration credentials and access tokens;
  • row-level access control so workspace data is only reachable by authorized members;
  • authentication through a managed identity provider, with OAuth 2.0 for tool integrations instead of stored personal API tokens;
  • least-privilege access for staff, logging and monitoring of security-relevant events;
  • managed, backed-up infrastructure with recovery procedures;
  • review of measures as the Service and the threat landscape evolve.

9. Sub-processors

The controller gives general authorization for the sub-processors listed below. We impose data protection obligations on each sub-processor that are no less protective than this DPA and remain fully liable for their performance. We give reasonable notice before adding or replacing a sub-processor; the controller may object on reasonable data protection grounds and, if we cannot resolve the objection, may terminate the affected subscription.

  • Supabase - database, authentication and backend infrastructure;
  • Cloudflare - application hosting, delivery and protection;
  • Lovable AI Gateway (Google Gemini models) - AI generation features;
  • Atlassian - Jira integration, only where the customer connects it;
  • Stripe - payment and subscription processing;
  • email delivery provider - transactional and authentication emails.

10. International transfers

Personal data is primarily processed in the EU. Where a sub-processor processes data outside the EEA, the transfer relies on an adequacy decision or on the European Commission's Standard Contractual Clauses together with supplementary measures where required.

11. Return and deletion

The controller can export or delete workspace data at any time in the application. On termination, and at the controller's choice, we delete or return personal data processed on its behalf within 30 days, except where EU or member-state law requires longer retention. Backups are overwritten on their normal rotation cycle.

12. Personal data breaches

We notify the controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting personal data processed on its behalf, providing the information available to us and updates as the investigation progresses.

13. Audit

On reasonable written request, and no more than once per year unless required by a supervisory authority, we provide the information reasonably necessary to demonstrate compliance with this DPA. Audits must respect confidentiality, security and the rights of other customers.

14. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of Service, to the extent permitted by law. This DPA prevails over conflicting provisions of the Terms of Service in matters of personal data processing.

15. Contact

Questions about this DPA, sub-processor changes or a signed copy: privacy@sprintbuddy.app.