This Privacy Policy is a document related to the Terms of Use of the AgileHero Application for the Users available here (“Terms of Use”). Definitions of the terms used in the Privacy Policy were included in the Terms of Use. The provisions of the Terms of Use are applied accordingly.
The Privacy Policy is for information purposes and serves satisfaction of the disclosure requirements imposed on the data controller under the GDPR, i.e. Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), in particular Article 13 of the Regulation.
Please be advised that the Privacy Policy contains information related to the processing of personal data through AgileHero, in particular in connection with the provision of the Services for the Users, maintenance of the Account, use of a Workspace, handling Orders, Subscriptions, payments, reports, and functionalities available in the Application.
1. Personal Data Controller
1.1 The Controller of personal data is the Service Provider, i.e. AgileHero spółka z ograniczoną odpowiedzialnością with its registered office in Warsaw at ul. Złota 75A lok. 7, 00-819 Warszawa, entered in the register of entrepreneurs of the National Court Register (KRS) under number KRS: 0001246514, Tax Identification Number NIP: 5273222340 (EU VAT number: PL5273222340), National Business Registry number REGON: 544961646, share capital in the amount of PLN 5,000.00
1.2 Contact details of the data controller: e-mail [email protected], mailing address as indicated above.
2. Data Processing Method
2.1. The scope, purposes, and legal grounds for the processing of personal data are presented in the table below.
| Purpose: | Scope of data: | Legal basis: | Processing period: |
|---|---|---|---|
providing access to AgileHero | IP address | Article 6(1)(b) of the GDPR – statutory authorisation to process data necessary to perform an agreement (in the scope of providing access to AgileHero and enabling the use of its functionalities) | until lapse of the period of limitation of claims connected with access AgileHero In the absence of a reasonable premise that the data need to be processed to protect against claims or to pursue claims, the data will be deleted no later than 24 hours after being obtained. |
correct display and operation of the Application | IP address, technical identifiers, device data, browser data, connection-related technical data, system logs | Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in ensuring security and stability of the Application | until lapse of the period of limitation of claims connected with the use of the Application. technical logs are retained for the period necessary to ensure the security, diagnostics, and stability of the Application, for no longer than 6 months, unless longer retention is necessary due to an incident, a claim, or a legal obligation |
enabling the User to create an Account, maintaining the User Account, and using the Services provided to the Users | first and last name, e-mail address, phone number, if it is provided or required for a given functionality, Account identifier, IP address, other data provided by the User in the Account | Article 6(1)(b) of the GDPR – statutory authorisation to process data necessary to perform an agreement (in the scope of creating an Account and maintaining it in AgileHero) | until lapse of the period of limitation of claims connected with the creation and maintenance of the Account. In the absence of a reasonable premise that the data need to be processed to protect against claims or to pursue claims, the data will be deleted upon termination of the agreement whose subject matter covers the maintenance of the Account on the Application. Where the Account is deleted, the data is blocked or removed from active systems as prescribed in clause 2.7 of the Privacy Policy |
handling invitations to a Workspace | e-mail address of the invited person, the Workspace data, data of the inviting person, status of the invitation | Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in enabling the Workspace administrator to invite a third person to use the Workspace; if the invitation is accepted – Article 6(1)(b) of the GDPR | until the invitation is accepted or revoked or expires unless further retention is necessary to protect against claims or raise claims. In the absence of a reasonable premise that the data needs to be processed to protect against claims or to pursue claims, the data will be deleted within a reasonable time upon the end of the processing of the invitation, but no later than 1 year after that. |
providing the Services within a Workspace, Projects, boards, tasks, and other functionalities of the Application | the User’s data, data related to the Workspace, Projects, tasks, statuses, comments, the User’s activity, and other personal data voluntarily entered by the User into the Application | Article 6(1)(b) of the GDPR – processing necessary to perform the agreement related to the provision of the Services to the User; Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in ensuring the correct operation of the Application, security, and protection against claims | for the term of the agreement for the provision of the Services, and thereafter for the period specified in clause 2.7 below, and until the lapse of the period of limitation of claims if further retention is necessary to defend against or pursue claims. In the absence of a reasonable premise that the data needs to be processed to protect against claims or to pursue claims, the data will be deleted upon termination of the agreement covering the provision of the Services unless all or part of data have already been deleted by the authorised User. |
processing Orders, Plans, Subscription Fees, changes of a Plan, and access to payable Services | the User’s identification data, Account data, Workspace data, selected Plan, Order details, Subscription status, payment status, details necessary to issue an invoice if such is requested by the User | Article 6(1)(b) of the GDPR – processing necessary for concluding and performing the Agreement; Article 6(1)(c) of the GDPR – in the scope of accounting and tax obligations; Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in processing billings and protecting against claims | for the term of the Agreement, and thereafter for the period required by the law, in particular by tax and accounting regulations, or until the lapse of the period of limitation of claims. In the absence of a reasonable premise that the data needs to be processed to protect against claims or to pursue claims, the data will be deleted upon termination of the agreement or upon the lapse of a period prescribed by the law (usually, 5 years from the end of the year in which the accounting document was issued). |
processing payments through the Payment Operator | data necessary to identify a payment, payment status, subscription or Subscription Fee status, technical identifiers of a transaction, and information provided to the Service Provider by the Payment Operator | Article 6(1)(b) of the GDPR – performance of the Agreement in the scope of processing payments and providing payable Services; Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in processing billings and protecting against claims | for the period necessary to process payments, billing, and the Subscription Fees, and thereafter until the lapse of the period of limitation of claims or for the period required by the law. In the absence of a reasonable premise that the data needs to be processed to protect against claims or to pursue claims, the data will be deleted within a reasonable time upon the end of the processing of payment, but no later than 1 year after that. |
sending e-mails and notifications in the Application, including system notifications necessary for the operation of the Application | e-mail address, Account identifier, data related to the notification settings, data related to the events in the Application covered by the notification | Article 6(1)(b) of the GDPR – in the scope of notifications necessary for the performance of the Agreement and the operation of the Application; Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in providing communication connected with the use of the Services | for the term of use of the Application, and thereafter for a term necessary for protecting against claims or raising claims. In the absence of a reasonable premise that the data need to be processed to protect against claims or to pursue claims, the data will be deleted upon termination of the Agreement. |
handling support reports, complaints, and communication with the User | first and last name, e-mail address, Account identifier, content of the report, technical data related to the operation of the Application, other data voluntarily provided in the report | Article 6(1)(b) of the GDPR – if a report refers to the performance of the agreement; Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in handling reports and improving the quality of the Services; Article 6(1)(c) of the GDPR – if the obligation to process a report is prescribed by the law | for the period necessary to process the report and thereafter until the lapse of the period of limitation of claims connected with the report. In the absence of a reasonable premise that the data needs to be processed to protect against claims or to pursue claims, the data will be deleted within a reasonable time upon the end of the processing of the report, but no later than 1 year after that. |
processing claims connected with the violations of the Terms of Use, illegal content, complaints, and appeals | data of the reporting person, e-mail address, content of the report, indication of the content or action covered by the report, technical data, information necessary to process the report | Article 6(1)(c) of the GDPR – processing is necessary to satisfy the Service Provider’s legal obligations; Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in protecting the rights of the Service Provider, the Users, and third persons, and preventing abuses | for the period necessary to process the report, complaint, or appeal, and thereafter until the lapse of the period of limitation of claims or for the period required by the law. In the absence of a reasonable premise that the data needs to be processed to protect against claims or to pursue claims, the data will be deleted within a reasonable time upon the end of the processing of the report, but no later than 1 year after that. |
conducting correspondence in electronic form, including processing queries directed at the Service Provider | e-mail address, first and last name, other personal data voluntarily provided by the data subject | Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in responding to queries and correspondence provided directly by the data subjects | until correspondence ends or the data subject objects. Personal data are deleted in line with the retention policy applicable at the Service Provider. |
using the MCP Server | the User’s Account data, data regarding generated MCP tokens, the scope of the User’s authorisations, information about active tokens, data on operations performed via the MCP Server, and data stored in the Application that is made available to external AI tools to the extent resulting from the User’s actions | Article 6(1)(b) of the GDPR – processing data necessary to perform the Agreement in the scope of providing the MCP Server functionality; Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in ensuring security and accountability of operations and preventing abuses | for the term of use of the MCP Server, and thereafter for a term necessary for ensuring security and accountability of operations, protecting against claims, or raising claims. In the absence of a reasonable premise that the data needs to be processed to protect against claims or to pursue claims, the data will be deleted within a reasonable time upon the end of the use of the MCP Server, but no later than 1 year after that. |
detecting errors, debugging, ensuring security, preventing abuses, and improving the performance of the Application | IP address, technical identifiers, system logs, data regarding requests sent to the Application, error data, data related to the Application response time and activity, device and browser data | Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in ensuring security, stability, continuity, diagnostics and improving the performance of the Application | for the period necessary to accomplish this goal but no longer than 6 months, unless further retention is necessary due to a security incident or an obligation prescribed by the law. |
protecting against claims, raising claims | e-mail address, first and last name, Account identifier, data regarding the use of the Application, data regarding the Agreement, Orders, payments, and reports, other data voluntarily provided by the data subject, and other data collected in connection with the mitigation of threats, attacks, and vulnerabilities in the Application. | Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in protecting against claims and raising claims | until lapse of the period of limitation of claims related to access to the Application, use of the Services, the Agreement, Orders, payments, or Users’ actions within the Application (which is typically 2 years from the end of the year in which the event giving rise to the claims occurred). Personal data will be processed for that purpose only if it actually becomes necessary to pursue claims or defend against claims |
providing information about the Application, upcoming changes and new features | e-mail address | Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in informing Users about new features and changes of the Application | until the User loses his/her status, until the data is no longer required, or until the data subject objects |
statistics and audience measurement of the AgileHero website | IP address, information about the browser and device, address of the visited page, address of the referring page — processed transiently and immediately aggregated into anonymous statistics | Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller that consists in measuring the audience of the website and improving its content and effectiveness | personal data is not retained — the data is anonymised and aggregated immediately upon collection; only anonymous, aggregated statistics are stored |
2.2. The Service Provider may transfer the Users’ personal data to a third country, i.e., the United States of America, if the use of certain tools, AI tools, communication tools, analytics tools, marketing tools, or the Payment Operator involves such a transfer. The Service Provider ensures that such transfer is secure, and before transferring personal data to a third country, the Service Provider will verify the safeguards applied by the data recipient to confirm that the recipient ensures the security and integrity of such data. All the transfers will be based on standard contractual clauses (SCC) or Data Privacy Framework.
2.3. The Service Provided analyses the Application logs for errors using AI systems. If the logs contain personal data (and the Service Provider takes all reasonable steps to ensure that this is not the case), they may be entrusted for processing to the AI tool provider, Anthropic. In some situations that personal data may be transferred to the USA. In such a case, the transfer is made to the abovementioned supplier of such a system on the basis SCC.
2.4. If the User uses the MCP Server, this may involve transferring data collected in the Application, including personal data of other Users or third persons, to external suppliers of AI services selected by the User. In such a case, the Service Provider is not a party in the relations between the User and such AI supplier, and the rules for data processing applied by that supplier are determined in its terms of service and documents related to data protection. The User should ensure that the use of such an AI provider and the transfer of data are lawful and consistent with the User’s authorisations.
2.5. With regard to personal data entered by the Users into Workspaces, Projects, tasks, comments, or other features of the Application, the scope of the Service Provider’s role under the GDPR may depend on the nature of the data and the purpose for which it is entered into the Application. To the extent that the User independently decides upon the purposes and manners of processing the personal data of third parties entered into the Application, the User is responsible for the lawfulness of such processing, in this for ensuring an appropriate legal basis, satisfying the disclosure requirement, and obtaining the required consents or authorisations. Where the Service Provider acts as the processor of personal data upon commission of the User, such processing is subject to the rules for transferring data for processing prescribed in the Terms of Use unless a separate agreement has been concluded between the User and the Service Provider.
2.6. If the agreement for the provision of the Services is terminated, the Account or a Workspace is deleted, data will be stored by an additional, maximum period of 30 days to enable the User to revoke the deletion order, to restore the Account, or to download the data (whereby the Service Provider does not guarantee that such functionalities will be available). Upon the lapse of that period, the data is deleted from the Service Provider’s active systems unless the provisions of the Privacy Policy state otherwise.
2.7. The Service Provider may store personal data in backup copies. Backup copies are created through the provider of cloud services and are deleted or overwritten in line with the technical policies of that provider and the settings applied by the Service Provider. The data contained in the backup copies is not used for the day-to-day operation of the Application and is restored only in justified cases, in particular, in order to ensure the Application’s operational continuity, to restore data following a failure, or to address a security incident. Backup copies are retained for no longer than 90 days.
2.8. AgileHero does not process or store the data of the Users’ payment cards. Payments are processed by the Payment Operator stated in the AgileHero functionalities, in particular, Stripe, including in the Merchant of Record model. With regard to processing payments, billings, taxes, preventing abuses, chargebacks, and compliance with legal obligations related to payments, the Payment Operator may act as a separate controller of personal data or as a processor, in line with the Payment Operator’s applicable policies and documentation. Detailed information about what personal data the Payment Operator collects, for what purposes it uses and discloses such data, what rights are vested in data subjects, and in what capacity the Payment Operator processes the data can be found in the Payment Operator’s privacy policy, including the privacy policy of above-mentioned Stripe. The Service Provider may receive from the Payment Operator technical information related to the status of payments, subscription, or access to the Services, in a scope necessary for the provision of the Services.
2.9. Statistics concerning the use of the AgileHero website are prepared using the Plausible Analytics tool provided by Plausible Insights OÜ with its registered office in Estonia. The tool does not use Cookies and does not store or read any information on the User’s device. The IP address and browser information are processed transiently for the sole purpose of preparing anonymous, aggregated statistics and are not retained. The data processed by this tool is hosted exclusively within the European Union and is not transferred to a third country.
3. Recipients of Data
3.1. The Service Provider may entrust the processing of personal data to third parties for the purpose of performance of certain activities. In such a case, the recipients of data of particular persons may involve in particular: the provider of hosting and cloud services for the Service Provider, the provider of instant messenger, the company providing technical support, the provider of a system for sending e-mails and SMS, the Payment Operator, a law firm, an accounting firm, the provider of AI tools for the provision or development of the Services, the providers of marketing tools, the providers of analytic tools, and other entities supporting the Service Provider in providing the Services.
3.2. The personal data collected by the Service Provider may also be disclosed to competent state bodies upon their request on the basis of relevant provisions of the law or other persons and entities – in the cases prescribed in the law.
3.3. Each entity to which the Service Provider transfers the personal data for processing on the basis of a personal data transfer agreement (further referred to as “Data Transfer Agreement”) guarantees an adequate level of security and confidentiality of the processing of personal data. An entity processing the personal data of data subjects on the basis of the Data Transfer Agreement may process the personal data of those persons through another entity only on the terms prescribed in that agreement or relevant documents of that service provider.
3.4. Disclosing personal data to unauthorised entities under this Privacy Policy may only take place upon prior consent of the data subject unless such obligation to disclose data is prescribed by the law.
4. Rights of the Data Subjects
4.1. Each data subject has the right to:
- request that the collected personal data referring to him/her is removed from the Service Provider’s systems, in particular, from AgileHero;
- restrict the processing of his/her personal data;
- portability of the personal data collected by the Service Provider, including the right to receive them in a structured form;
- request the Service Provider to provide access to his/her personal data and rectify them;
- raise an objection against personal data processing;
- revoke the consent to the personal data processing at any time without affecting the legality of the data processing carried out on the basis of the consent before it is revoked;
- file a complaint against the Service Provider to the supervisory authority (President of the Polish Personal Data Protection Office [Urząd Ochrony Danych Osobowych]).
4.2. In order to exercise the rights discussed above, the data subject may contact the Service Provider using the contact details stated in clause 1.2 of the Privacy Policy.
5. Other Data
5.1. The Service Provider may store http enquiries, therefore the files containing web server logs may store certain data, including the IP address of the computer sending the enquiry, date and system time of registration in the Application or receipt of the enquiry, number of bytes sent by the server, the URL address of the site visited by the data subject before if he/she has entered the Application through a link, information concerning the browser, information concerning errors occurred by realization of the http transaction. Web server logs may be collected as the material for the proper administration of the Application. Only persons authorised to administer the IT system have access to the data. The files containing web server logs may be analysed for the purpose of preparing statistics concerning traffic in the Application and occurring errors. A summary of such details does not enable identification of a natural person.
6. Security
6.1. The Service Provider applies technological and organisational means in order to secure the processing of personal data adequately to the threats and category of data to be secured, in particular, through technical and organisational means the Service Provider secures data against being disclosed to unauthorised persons, taken over by an unauthorised person, processed in violation of the law, and changed, lost, damaged, or destroyed. In particular, this may involve SSL certificates, access control mechanisms, event logging, backups, cloud infrastructure safeguards, and other measures appropriate to the type of data being processed.
6.2. The Service Provider has also implemented appropriate technical and organisational means, such as pseudonymisation, designed to effectively enforce the data protection principles, such as data minimisation, and for the purpose of providing the processing with necessary safeguards, so as to meet the GDPR requirements and protect the rights of data subjects.
6.3. At the same time, the Service Provider states that using the Internet and services provided by electronic means may pose a threat of malware breaking into the User’s ICT system and device, as well as any other unauthorised access to the User’s data, including personal data, by third parties. In order to minimise such threats, the data subject should apply appropriate technical security means, e.g. use updated antivirus programs or programs securing his/her identification on the Internet. In order to obtain detailed and professional information related to security on the Internet, the Service Provider recommends taking advice from entities specialising in such IT services.
6.4. The User is obliged to protect the Account access data, including the password, and not to share them with third persons. When using the MCP Server, the User is obliged to keep the MCP token confidential and to immediately invalidate the token where it is suspected to have been made available to an unauthorised person.
8. Final Provisions
8.1. This Privacy Policy comes into effect on 1 September 2026.
8.2. The Service Provider may amend the Privacy Policy, in particular, in the event of change in the law, change in the mode of operation of AgileHero, change in the functionalities of the Application, change of the providers of services used by the Service Provider, change in the rules for personal data processing, or the need to make the information provided to data subjects more specific.
8.3. The Users may be advised of material amendments to the Privacy Policy through the Application or an e-mail sent to the address assigned to the Account.