Privacy Policy
How we handle personal data we control — for the data your organization controls, see the DPA.
Version 1.0 · Last updated: 2026-09-12 · Effective: 2026-09-12
We are finalizing our legal documentation ahead of general availability. These pages describe our current practices; contact legal@agily.app with any questions.
This Privacy Policy explains how [Legal entity name] (“Agily”, “we”) collects, uses, discloses, and protects personal data in connection with the Agily service at https://www.agily.app and our website at https://www.agily.app (together, the “Service”).
1. Our two roles
Agily is a B2B tool. Most people use it because their employer or another organization (“Customer”) set up an account.
When we act as a “processor”. Content that Customer and its users put into the Service — projects, work items, comments, documents, whiteboards, diagrams, sprints, releases, roadmap items, goals and key-results, check-ins, standup/retrospective responses, timesheet entries, capacity and availability data, uploaded files, and chat-integration identities (“Customer Data”) — is controlled by Customer, not by us. We process it on Customer’s instructions under our Data Processing Agreement. If you are a user and want to access, correct, or delete personal data that appears in Customer Data, contact your organization. We will support them in responding.
When we act as a “controller”. We decide how we handle:
- Account Data — name, email address, password (stored only as a hash), profile photo, optional username, and, if you sign in with Google or GitHub, the identifier from that provider.
- Member profile data — optional fields: job title, department, employee ID, phone number, location, and time zone.
- Authentication & security data — two-factor authentication secret and one-time backup codes; session and device information (browser/user-agent, IP address, sign-in and expiry times); and a login history (successful and failed sign-in attempts, with IP address and user-agent).
- Billing Data — the billing contact, invoice and payment history, a payment-processor token, and a display hint for the payment instrument (for example, a card’s last four digits or a UPI handle). We do not receive or store full payment-card numbers.
- Support Data — information you provide when you contact us for support.
- Usage & log data — request logs and metrics, and an immutable audit log of security- and configuration-relevant actions (who did what, when, from which IP).
This Policy describes how we handle data in our controller role.
2. What we collect and why (controller role)
| Category | Examples | Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|---|---|
| Account Data | name, email, password hash, avatar, username, Google/GitHub ID | Create and operate your account; authenticate you; communicate about the Service | Performance of a contract; our legitimate interest in providing and securing the Service |
| Member profile data | job title, department, employee ID, phone, location, time zone | Team directory, capacity and scheduling features, time-zone-aware behavior | Provided in the workplace context; our legitimate interest in these features |
| Authentication & security data | 2FA secret, backup codes, session/device metadata, IP, user-agent, login history | Secure the account; provide “active sessions” controls; detect and investigate abuse | Our legitimate interest in security; legal obligation to protect personal data |
| Billing Data | billing contact, invoices, payments, processor token, card last4 / UPI hint | Charge for the Service; issue invoices; handle failed payments; keep financial records | Performance of a contract; legal obligation (tax/accounting) |
| Support Data | your messages and contact details | Respond to and resolve your request | Performance of a contract; our legitimate interest in supporting users |
| Usage & log data | request logs, metrics, audit-log entries | Operate, monitor, secure, troubleshoot, and improve the Service | Our legitimate interest in a reliable and secure service |
| Cookies / local storage | see the Cookie Policy | Keep you signed in; remember interface preferences and language | Strictly necessary; functional (legitimate interest); consent for any non-essential cookies |
Where our basis is legitimate interests, we have balanced those interests against your rights and freedoms; you can object as described in Section 8. Under India’s DPDP Act, we rely on consent and/or the Act’s enumerated legitimate uses (including where you have voluntarily provided data for a purpose, and processing in an employment context). Under CCPA/CPRA, we collect the categories above for the business purposes stated; we do not “sell” or “share” personal information and have not done so in the preceding 12 months.
3. We do not use your data for advertising
We do not sell personal data, we do not share it for cross-context behavioral advertising, and the Service contains no third-party advertising or advertising trackers. We do not use Customer Data to train artificial-intelligence models (see Section 6).
4. How we share personal data
- With the Customer. If you use the Service through an organization, that organization’s administrators can access your Account Data, member profile, activity, and the Customer Data you contribute, and can manage or remove your access.
- Sub-processors / service providers. The current list, what each does, and where they process data is on the Sub-processors page. It includes our cloud/hosting provider, email provider, payment processor, error-monitoring/logging providers, and — for optional features Customer enables — chat providers (Slack, Microsoft Teams, Telegram, Discord), AI providers, and Atlassian (Jira/Confluence), used only for a one-time import an administrator explicitly starts.
- Legal and safety. To comply with law, a lawful request, or legal process; to enforce our agreements; or to protect the rights, property, or safety of Agily, our users, or the public.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to the acquirer honoring this Policy or providing notice and choice as required by law.
- With your direction. When you connect an Integration or otherwise instruct us to share data with a third party.
5. International data transfers
We and our sub-processors may process personal data in countries other than the one where you are located, including [AWS region — to confirm] and the United States (for example, some AI and error-monitoring providers). Where we transfer personal data out of the EEA, the UK, or another region with transfer restrictions, we use a lawful transfer mechanism — for example, the European Commission’s Standard Contractual Clauses (and the UK Addendum) — and apply supplementary measures where needed. For transfers from India, we transfer only to countries not restricted by the Central Government. Contact privacy@agily.app for information about the safeguards in place.
6. Artificial-intelligence features
The Service offers AI-assisted features (for example, summarizing standup responses and an editor writing assistant). When such a feature runs, text derived from Customer Data is sent to a third-party AI provider — in “Managed” mode a provider we select, or in “bring-your-own-key” mode the provider whose API key the Customer supplies. We retain metadata about these requests (feature, provider, token counts, timing, cost) for metering and troubleshooting. We do not use Customer Data or AI prompts/outputs to train our own or third parties’ models, and our Managed AI provider contracts prohibit the providers from doing so. AI output can be wrong; review it before relying on it. The AI providers we use are on the Sub-processors page.
7. How long we keep data
| Data | Retention |
|---|---|
| Account Data | For the life of your account. After your account is closed, we anonymize your user record (removing name, email, avatar, and provider identifiers); we may retain the anonymized record where needed for referential integrity of Customer Data you contributed. |
| Member profile data | For the life of the membership; deleted when the membership is removed. |
| Authentication tokens & sessions | Expired sign-in, verification, and challenge tokens are deleted automatically on a recurring basis. Active sessions persist until they expire or you revoke them. |
| Connected integration credentials | A connected Jira/Confluence (Atlassian) API token is retained, encrypted, until an administrator disconnects it or the organization is deleted — disconnecting permanently removes the stored token from our database immediately; the record that a connection was made or removed is kept in the audit log below. |
| Login history / audit log | [24 months — decide]. Audit-log entries are immutable and retained for security and accountability. |
| Billing Data | [7 years — confirm per tax law], to meet tax and accounting obligations. |
| Support Data | For as long as needed to handle the request and for a reasonable period afterward. |
| Customer Data | Retained per Customer’s instructions and the DPA; on termination, deleted or returned within [30 days], except for backups and records we must keep by law. |
8. Your rights
Depending on where you are, you may have rights to: access your personal data; correct inaccurate data; delete your data; restrict or object to processing; withdraw consent; receive your data in a portable format; and not be discriminated against for exercising a right. India’s DPDP Act also gives you the right to a grievance-redressal process and to nominate another person to exercise rights on your behalf.
How to exercise:
- In the Service. You can update your profile and email, manage sessions and connected accounts, and set up or remove two-factor authentication directly in your account settings.
- By contacting us. To export a copy of your account and membership data, or to close and anonymize your account, email privacy@agily.app — this is not yet a self-service action in the interface, so we process these requests manually. For any other request, email the same address. For India, this is also our grievance-redressal contact: [Grievance officer name], privacy@agily.app. We will verify your identity and respond within the period required by applicable law.
- For data inside Customer Data. Because your organization controls that content, send your request to your organization; we will assist them.
If you believe we have not handled your request properly, you can complain to a data protection authority — for the EEA/UK, your local supervisory authority; for India, the Data Protection Board. You may use an authorized agent to submit a CCPA request; we may require proof of authorization and verification of your identity.
9. Security
We maintain administrative, technical, and organizational measures designed to protect personal data, including: encryption of data in transit; encryption at rest for credentials and designated sensitive fields; role-based access control and tenant isolation; support for multi-factor authentication; an immutable audit log; secure software-development practices including dependency and secret scanning; malware scanning of uploaded files; and vendor security diligence. A fuller description is on the Security Overview page. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Breach notification. If a personal-data breach affecting your data occurs, we will notify the affected Customer and, where we are the controller and the law requires, affected individuals and the relevant authority, within the timeframes the law prescribes.
10. Children
The Service is a workplace tool and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact privacy@agily.app and we will delete it.
11. Cookies
See the Cookie Policy. In summary, the Service uses cookies and browser local storage that are strictly necessary (to keep you signed in and to protect sign-in flows) and functional (to remember language and interface preferences). It does not use advertising cookies or third-party trackers.
12. Changes to this Policy
We may update this Policy. For material changes we will give notice (for example, by email to account administrators or an in-app notice) and update the “Last updated” date.
13. Contact
- Privacy / data-protection requests: privacy@agily.app
- India grievance officer: [Grievance officer name], privacy@agily.app
- Postal: [Legal entity name], [Registered office address]
Questions? Email legal@agily.app. Privacy requests: privacy@agily.app. Report a security issue: security@agily.app.