AgileHero

Privacy Policy of the AgileHero Application

This Privacy Policy is a document related to the Terms of Use of the AgileHero Application for the Users available here (“Terms of Use”). Definitions of the terms used in the Privacy Policy were included in the Terms of Use. The provisions of the Terms of Use are applied accordingly.

The Privacy Policy is for information purposes and serves satisfaction of the disclosure requirements imposed on the data controller under the GDPR, i.e. Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), in particular Article 13 of the Regulation.

Please be advised that the Privacy Policy contains information related to the processing of personal data through AgileHero, in particular in connection with the provision of the Services for the Users, maintenance of the Account, use of a Workspace, handling Orders, Subscriptions, payments, reports, and functionalities available in the Application.

1. Personal Data Controller

1.1 The Controller of personal data is the Service Provider, i.e. AgileHero spółka z ograniczoną odpowiedzialnością with its registered office in Warsaw at ul. Złota 75A lok. 7, 00-819 Warszawa, entered in the register of entrepreneurs of the National Court Register (KRS) under number KRS: 0001246514, Tax Identification Number NIP: 5273222340 (EU VAT number: PL5273222340), National Business Registry number REGON: 544961646, share capital in the amount of PLN 5,000.00

1.2 Contact details of the data controller: e-mail [email protected], mailing address as indicated above.

2. Data Processing Method

2.1. The scope, purposes, and legal grounds for the processing of personal data are presented in the table below.

Purpose:Scope of data:Legal basis:Processing period:

providing access to AgileHero

IP address

Article 6(1)(b) of the GDPR – statutory authorisation to process data necessary to perform an agreement (in the scope of providing access to AgileHero and enabling the use of its functionalities)

until lapse of the period of limitation of claims connected with access AgileHero

In the absence of a reasonable premise that the data need to be processed to protect against claims or to pursue claims, the data will be deleted no later than 24 hours after being obtained.

correct display and operation of the Application

IP address, technical identifiers, device data, browser data, connection-related technical data, system logs

Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in ensuring security and stability of the Application

until lapse of the period of limitation of claims connected with the use of the Application.

technical logs are retained for the period necessary to ensure the security, diagnostics, and stability of the Application, for no longer than 6 months, unless longer retention is necessary due to an incident, a claim, or a legal obligation

enabling the User to create an Account, maintaining the User Account, and using the Services provided to the Users

first and last name, e-mail address, phone number, if it is provided or required for a given functionality, Account identifier, IP address, other data provided by the User in the Account

Article 6(1)(b) of the GDPR – statutory authorisation to process data necessary to perform an agreement (in the scope of creating an Account and maintaining it in AgileHero)

until lapse of the period of limitation of claims connected with the creation and maintenance of the Account.

In the absence of a reasonable premise that the data need to be processed to protect against claims or to pursue claims, the data will be deleted upon termination of the agreement whose subject matter covers the maintenance of the Account on the Application.

Where the Account is deleted, the data is blocked or removed from active systems as prescribed in clause 2.7 of the Privacy Policy

handling invitations to a Workspace

e-mail address of the invited person, the Workspace data, data of the inviting person, status of the invitation

Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in enabling the Workspace administrator to invite a third person to use the Workspace; if the invitation is accepted – Article 6(1)(b) of the GDPR

until the invitation is accepted or revoked or expires unless further retention is necessary to protect against claims or raise claims.

In the absence of a reasonable premise that the data needs to be processed to protect against claims or to pursue claims, the data will be deleted within a reasonable time upon the end of the processing of the invitation, but no later than 1 year after that.

providing the Services within a Workspace, Projects, boards, tasks, and other functionalities of the Application

the User’s data, data related to the Workspace, Projects, tasks, statuses, comments, the User’s activity, and other personal data voluntarily entered by the User into the Application

Article 6(1)(b) of the GDPR – processing necessary to perform the agreement related to the provision of the Services to the User;

Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in ensuring the correct operation of the Application, security, and protection against claims

for the term of the agreement for the provision of the Services, and thereafter for the period specified in clause 2.7 below, and until the lapse of the period of limitation of claims if further retention is necessary to defend against or pursue claims.

In the absence of a reasonable premise that the data needs to be processed to protect against claims or to pursue claims, the data will be deleted upon termination of the agreement covering the provision of the Services unless all or part of data have already been deleted by the authorised User.

processing Orders, Plans, Subscription Fees, changes of a Plan, and access to payable Services

the User’s identification data, Account data, Workspace data, selected Plan, Order details, Subscription status, payment status, details necessary to issue an invoice if such is requested by the User

Article 6(1)(b) of the GDPR – processing necessary for concluding and performing the Agreement;

Article 6(1)(c) of the GDPR – in the scope of accounting and tax obligations;

Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in processing billings and protecting against claims

for the term of the Agreement, and thereafter for the period required by the law, in particular by tax and accounting regulations, or until the lapse of the period of limitation of claims.

In the absence of a reasonable premise that the data needs to be processed to protect against claims or to pursue claims, the data will be deleted upon termination of the agreement or upon the lapse of a period prescribed by the law (usually, 5 years from the end of the year in which the accounting document was issued).

processing payments through the Payment Operator

data necessary to identify a payment, payment status, subscription or Subscription Fee status, technical identifiers of a transaction, and information provided to the Service Provider by the Payment Operator

Article 6(1)(b) of the GDPR – performance of the Agreement in the scope of processing payments and providing payable Services;

Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in processing billings and protecting against claims

for the period necessary to process payments, billing, and the Subscription Fees, and thereafter until the lapse of the period of limitation of claims or for the period required by the law.

In the absence of a reasonable premise that the data needs to be processed to protect against claims or to pursue claims, the data will be deleted within a reasonable time upon the end of the processing of payment, but no later than 1 year after that.

sending e-mails and notifications in the Application, including system notifications necessary for the operation of the Application

e-mail address, Account identifier, data related to the notification settings, data related to the events in the Application covered by the notification

Article 6(1)(b) of the GDPR – in the scope of notifications necessary for the performance of the Agreement and the operation of the Application;

Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in providing communication connected with the use of the Services

for the term of use of the Application, and thereafter for a term necessary for protecting against claims or raising claims.

In the absence of a reasonable premise that the data need to be processed to protect against claims or to pursue claims, the data will be deleted upon termination of the Agreement.

handling support reports, complaints, and communication with the User

first and last name, e-mail address, Account identifier, content of the report, technical data related to the operation of the Application, other data voluntarily provided in the report

Article 6(1)(b) of the GDPR – if a report refers to the performance of the agreement;

Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in handling reports and improving the quality of the Services;

Article 6(1)(c) of the GDPR – if the obligation to process a report is prescribed by the law

for the period necessary to process the report and thereafter until the lapse of the period of limitation of claims connected with the report.

In the absence of a reasonable premise that the data needs to be processed to protect against claims or to pursue claims, the data will be deleted within a reasonable time upon the end of the processing of the report, but no later than 1 year after that.

processing claims connected with the violations of the Terms of Use, illegal content, complaints, and appeals

data of the reporting person, e-mail address, content of the report, indication of the content or action covered by the report, technical data, information necessary to process the report

Article 6(1)(c) of the GDPR – processing is necessary to satisfy the Service Provider’s legal obligations;

Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in protecting the rights of the Service Provider, the Users, and third persons, and preventing abuses

for the period necessary to process the report, complaint, or appeal, and thereafter until the lapse of the period of limitation of claims or for the period required by the law.

In the absence of a reasonable premise that the data needs to be processed to protect against claims or to pursue claims, the data will be deleted within a reasonable time upon the end of the processing of the report, but no later than 1 year after that.

conducting correspondence in electronic form, including processing queries directed at the Service Provider

e-mail address, first and last name, other personal data voluntarily provided by the data subject

Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in responding to queries and correspondence provided directly by the data subjects

until correspondence ends or the data subject objects.

Personal data are deleted in line with the retention policy applicable at the Service Provider.

using the MCP Server

the User’s Account data, data regarding generated MCP tokens, the scope of the User’s authorisations, information about active tokens, data on operations performed via the MCP Server, and data stored in the Application that is made available to external AI tools to the extent resulting from the User’s actions

Article 6(1)(b) of the GDPR – processing data necessary to perform the Agreement in the scope of providing the MCP Server functionality;

Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in ensuring security and accountability of operations and preventing abuses

for the term of use of the MCP Server, and thereafter for a term necessary for ensuring security and accountability of operations, protecting against claims, or raising claims.

In the absence of a reasonable premise that the data needs to be processed to protect against claims or to pursue claims, the data will be deleted within a reasonable time upon the end of the use of the MCP Server, but no later than 1 year after that.

detecting errors, debugging, ensuring security, preventing abuses, and improving the performance of the Application

IP address, technical identifiers, system logs, data regarding requests sent to the Application, error data, data related to the Application response time and activity, device and browser data

Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in ensuring security, stability, continuity, diagnostics and improving the performance of the Application

for the period necessary to accomplish this goal but no longer than 6 months, unless further retention is necessary due to a security incident or an obligation prescribed by the law.

protecting against claims, raising claims

e-mail address, first and last name, Account identifier, data regarding the use of the Application, data regarding the Agreement, Orders, payments, and reports, other data voluntarily provided by the data subject, and other data collected in connection with the mitigation of threats, attacks, and vulnerabilities in the Application.

Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in protecting against claims and raising claims

until lapse of the period of limitation of claims related to access to the Application, use of the Services, the Agreement, Orders, payments, or Users’ actions within the Application (which is typically 2 years from the end of the year in which the event giving rise to the claims occurred).

Personal data will be processed for that purpose only if it actually becomes necessary to pursue claims or defend against claims

providing information about the Application, upcoming changes and new features

e-mail address

Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in informing Users about new features and changes of the Application

until the User loses his/her status, until the data is no longer required, or until the data subject objects

statistics and audience measurement of the AgileHero website

IP address, information about the browser and device, address of the visited page, address of the referring page — processed transiently and immediately aggregated into anonymous statistics

Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in measuring the audience of the website and improving its content and effectiveness

personal data is not retained — the data is anonymised and aggregated immediately upon collection; only anonymous, aggregated statistics are stored

2.2. The Service Provider may transfer the Users’ personal data to a third country, i.e., the United States of America, if the use of certain tools, AI tools, communication tools, analytics tools, marketing tools, or the Payment Operator involves such a transfer. The Service Provider ensures that such transfer is secure, and before transferring personal data to a third country, the Service Provider will verify the safeguards applied by the data recipient to confirm that the recipient ensures the security and integrity of such data. All the transfers will be based on standard contractual clauses (SCC) or Data Privacy Framework.

2.3. The Service Provided analyses the Application logs for errors using AI systems. If the logs contain personal data (and the Service Provider takes all reasonable steps to ensure that this is not the case), they may be entrusted for processing to the AI tool provider, Anthropic. In some situations that personal data may be transferred to the USA. In such a case, the transfer is made to the abovementioned supplier of such a system on the basis SCC.

2.4. If the User uses the MCP Server, this may involve transferring data collected in the Application, including personal data of other Users or third persons, to external suppliers of AI services selected by the User. In such a case, the Service Provider is not a party in the relations between the User and such AI supplier, and the rules for data processing applied by that supplier are determined in its terms of service and documents related to data protection. The User should ensure that the use of such an AI provider and the transfer of data are lawful and consistent with the User’s authorisations.

2.5. With regard to personal data entered by the Users into Workspaces, Projects, tasks, comments, or other features of the Application, the scope of the Service Provider’s role under the GDPR may depend on the nature of the data and the purpose for which it is entered into the Application. To the extent that the User independently decides upon the purposes and manners of processing the personal data of third parties entered into the Application, the User is responsible for the lawfulness of such processing, in this for ensuring an appropriate legal basis, satisfying the disclosure requirement, and obtaining the required consents or authorisations. Where the Service Provider acts as the processor of personal data upon commission of the User, such processing is subject to the rules for transferring data for processing prescribed in the Terms of Use unless a separate agreement has been concluded between the User and the Service Provider.

2.6. If the agreement for the provision of the Services is terminated, the Account or a Workspace is deleted, data will be stored by an additional, maximum period of 30 days to enable the User to revoke the deletion order, to restore the Account, or to download the data (whereby the Service Provider does not guarantee that such functionalities will be available). Upon the lapse of that period, the data is deleted from the Service Provider’s active systems unless the provisions of the Privacy Policy state otherwise.

2.7. The Service Provider may store personal data in backup copies. Backup copies are created through the provider of cloud services and are deleted or overwritten in line with the technical policies of that provider and the settings applied by the Service Provider. The data contained in the backup copies is not used for the day-to-day operation of the Application and is restored only in justified cases, in particular, in order to ensure the Application’s operational continuity, to restore data following a failure, or to address a security incident. Backup copies are retained for no longer than 90 days.

2.8. AgileHero does not process or store the data of the Users’ payment cards. Payments are processed by the Payment Operator stated in the AgileHero functionalities, in particular, Stripe, including in the Merchant of Record model. With regard to processing payments, billings, taxes, preventing abuses, chargebacks, and compliance with legal obligations related to payments, the Payment Operator may act as a separate controller of personal data or as a processor, in line with the Payment Operator’s applicable policies and documentation. Detailed information about what personal data the Payment Operator collects, for what purposes it uses and discloses such data, what rights are vested in data subjects, and in what capacity the Payment Operator processes the data can be found in the Payment Operator’s privacy policy, including the privacy policy of above-mentioned Stripe. The Service Provider may receive from the Payment Operator technical information related to the status of payments, subscription, or access to the Services, in a scope necessary for the provision of the Services.

2.9. Statistics concerning the use of the AgileHero website are prepared using the Plausible Analytics tool provided by Plausible Insights OÜ with its registered office in Estonia. The tool does not use Cookies and does not store or read any information on the User’s device. The IP address and browser information are processed transiently for the sole purpose of preparing anonymous, aggregated statistics and are not retained. The data processed by this tool is hosted exclusively within the European Union and is not transferred to a third country.

3. Recipients of Data

3.1. The Service Provider may entrust the processing of personal data to third parties for the purpose of performance of certain activities. In such a case, the recipients of data of particular persons may involve in particular: the provider of hosting and cloud services for the Service Provider, the provider of instant messenger, the company providing technical support, the provider of a system for sending e-mails and SMS, the Payment Operator, a law firm, an accounting firm, the provider of AI tools for the provision or development of the Services, the providers of marketing tools, the providers of analytic tools, and other entities supporting the Service Provider in providing the Services.

3.2. The personal data collected by the Service Provider may also be disclosed to competent state bodies upon their request on the basis of relevant provisions of the law or other persons and entities – in the cases prescribed in the law.

3.3. Each entity to which the Service Provider transfers the personal data for processing on the basis of a personal data transfer agreement (further referred to as “Data Transfer Agreement”) guarantees an adequate level of security and confidentiality of the processing of personal data. An entity processing the personal data of data subjects on the basis of the Data Transfer Agreement may process the personal data of those persons through another entity only on the terms prescribed in that agreement or relevant documents of that service provider.

3.4. Disclosing personal data to unauthorised entities under this Privacy Policy may only take place upon prior consent of the data subject unless such obligation to disclose data is prescribed by the law.

4. Rights of the Data Subjects

4.1. Each data subject has the right to:

  • request that the collected personal data referring to him/her is removed from the Service Provider’s systems, in particular, from AgileHero;
  • restrict the processing of his/her personal data;
  • portability of the personal data collected by the Service Provider, including the right to receive them in a structured form;
  • request the Service Provider to provide access to his/her personal data and rectify them;
  • raise an objection against personal data processing;
  • revoke the consent to the personal data processing at any time without affecting the legality of the data processing carried out on the basis of the consent before it is revoked;
  • file a complaint against the Service Provider to the supervisory authority (President of the Polish Personal Data Protection Office [Urząd Ochrony Danych Osobowych]).

4.2. In order to exercise the rights discussed above, the data subject may contact the Service Provider using the contact details stated in clause 1.2 of the Privacy Policy.

5. Other Data

5.1. The Service Provider may store http enquiries, therefore the files containing web server logs may store certain data, including the IP address of the computer sending the enquiry, date and system time of registration in the Application or receipt of the enquiry, number of bytes sent by the server, the URL address of the site visited by the data subject before if he/she has entered the Application through a link, information concerning the browser, information concerning errors occurred by realization of the http transaction. Web server logs may be collected as the material for the proper administration of the Application. Only persons authorised to administer the IT system have access to the data. The files containing web server logs may be analysed for the purpose of preparing statistics concerning traffic in the Application and occurring errors. A summary of such details does not enable identification of a natural person.

6. Security

6.1. The Service Provider applies technological and organisational means in order to secure the processing of personal data adequately to the threats and category of data to be secured, in particular, through technical and organisational means the Service Provider secures data against being disclosed to unauthorised persons, taken over by an unauthorised person, processed in violation of the law, and changed, lost, damaged, or destroyed. In particular, this may involve SSL certificates, access control mechanisms, event logging, backups, cloud infrastructure safeguards, and other measures appropriate to the type of data being processed.

6.2. The Service Provider has also implemented appropriate technical and organisational means, such as pseudonymisation, designed to effectively enforce the data protection principles, such as data minimisation, and for the purpose of providing the processing with necessary safeguards, so as to meet the GDPR requirements and protect the rights of data subjects.

6.3. At the same time, the Service Provider states that using the Internet and services provided by electronic means may pose a threat of malware breaking into the User’s ICT system and device, as well as any other unauthorised access to the User’s data, including personal data, by third parties. In order to minimise such threats, the data subject should apply appropriate technical security means, e.g. use updated antivirus programs or programs securing his/her identification on the Internet. In order to obtain detailed and professional information related to security on the Internet, the Service Provider recommends taking advice from entities specialising in such IT services.

6.4. The User is obliged to protect the Account access data, including the password, and not to share them with third persons. When using the MCP Server, the User is obliged to keep the MCP token confidential and to immediately invalidate the token where it is suspected to have been made available to an unauthorised person.

7. Cookies

7.1. For the purposes of correct operation of the Application, the Service Provider uses the Cookie support technology. Cookies are packages of information stored on the User’s device through the Service Provider, usually containing information corresponding to the intended use of a particular file, by means of which the User uses the Application. These are usually: address of the website, date of publishing, lifetime of a Cookie, unique number and additional information corresponding to the intended use of the particular file.

7.2. The Service Provider uses two types of Cookies: (a) session cookies, which are permanently deleted upon closing the session of the User’s browser; (b) permanent cookies, which remain on the User’s device after closing the session until they are deleted or until they expire.

7.3. It is not possible to identify the User on the basis of Cookie files, whether session or permanent. The Cookie mechanism prevents the collection of any personal data.

7.4. Cookies used by the Service Provider are safe for the User’s device, in particular they prevent viruses or other software from breaking into the device.

7.5. Files generated directly by the Service Provider may not be read by other websites. Third-party Cookies (i.e. Cookies provided by entities co-operating with the Service Provider) may be read by an external server.

7.6. The User may individually change the Cookie settings at any time, stating the conditions of their storage, through the Internet browser settings or configuration of the service.

7.7. First of all, the User may disable storing Cookies on his/her device in accordance with the instructions of the browser producer, but this may disable certain parts of or the entire operation of the Application.

7.8. The User may also individually remove Cookies stored on his/her device at any time in accordance with the instructions of the browser producer.

7.9. The Service Provider uses own Cookies for the following purposes: configuring the Application and adjusting the page content to the User’s preferences or activity, maintaining a session, ensuring security, saving the settings, and the correct operation of the AgileHero functionalities.

7.10. The Service Provider currently uses the following own Cookies, all of which are strictly necessary for maintaining the User’s session and the security of the Application and do not serve advertising or analytical purposes: (a) “_agile_hero.session_id” — a permanent Cookie maintaining the User’s authenticated session, stored for up to 30 days; (b) “_agile_hero.short_session_id” — a permanent Cookie confirming the User’s recent re-authentication before security-sensitive actions, stored for up to 15 minutes; (c) “_agile_hero.device_id” — a permanent Cookie enabling recognition of the User’s device for account-security purposes, in particular notifying the User of sign-ins from a new device and presenting the list of active sessions, stored for up to 2 years. These Cookies are set only in connection with signing in to the Application, are not accessible to third parties, and are not used to track the User across other websites.

7.11. The Service Provider does not use Third-party Cookies. Statistics concerning the use of the website are prepared using a cookieless analytics tool which does not store or read any information on the User’s device, as described in clause 2.9 of the Privacy Policy.

7.12. Details concerning Cookie support are available in the settings of the browser used by the data subject.

8. Final Provisions

8.1. This Privacy Policy comes into effect on 1 September 2026.

8.2. The Service Provider may amend the Privacy Policy, in particular, in the event of change in the law, change in the mode of operation of AgileHero, change in the functionalities of the Application, change of the providers of services used by the Service Provider, change in the rules for personal data processing, or the need to make the information provided to data subjects more specific.

8.3. The Users may be advised of material amendments to the Privacy Policy through the Application or an e-mail sent to the address assigned to the Account.