Coming soon
Back to home Legal

Data Processing Agreement

Last updated September 12, 2026 · Version 1.0

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between Axceera (Private) Limited ("Axceera", "Processor"), company registration number PV 00252314, of 157/3 Kadawatha Road, Nadimala, Dehiwala, Sri Lanka, and the customer organisation using Sprint Track ("Customer", "Controller").

It applies where Axceera processes personal data on the Customer's behalf in the course of providing Sprint Track. It takes effect automatically when the Customer accepts the Terms and Conditions; no signature is required. A countersigned copy is available on request at hello@sprintrack.com.

1. Definitions

"GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the GDPR as incorporated into UK law by the European Union (Withdrawal) Act 2018. "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Sub-processor", and "Supervisory Authority" have the meanings given in the GDPR.

"Customer Personal Data" means Personal Data contained in Customer Content that Axceera processes on the Customer's behalf.

2. Roles

The Customer is the Controller of Customer Personal Data. Axceera is the Processor.

Axceera is an independent Controller for the account, authentication, security, billing, and service-operation data described in the Privacy Policy, which is outside the scope of this DPA.

3. Subject Matter and Details of Processing

Subject matter. Provision of the Sprint Track project and work management platform.

Duration. For the term of the Customer's subscription, plus the deletion periods in section 11.

Nature and purpose. Hosting, storing, organising, retrieving, transmitting, displaying, securing, and otherwise processing Customer Content as necessary to deliver Sprint Track and its optional features.

Categories of Data Subject. The Customer's personnel, contractors, and invited collaborators; guests who access externally shared projects; and any individual referenced within Customer Content.

Categories of Personal Data. Identification and contact data (name, email, profile image); authentication and device data (session records, IP address, user agent); organisational data (workspace role, team membership, and hourly rate where the Customer configures it); identity provider attributes where SSO or SCIM is connected; and any Personal Data the Customer chooses to place in projects, issues, comments, documents, attachments, AI conversations, or uploaded media.

Special categories. None. The Customer must not submit special-category or otherwise highly regulated data, as set out in the Acceptable Use Policy.

4. Customer Instructions

Axceera processes Customer Personal Data only on the Customer's documented instructions, which comprise the Terms and Conditions, this DPA, the Customer's configuration of the service, and any further written instruction the parties agree.

Axceera will inform the Customer if, in its opinion, an instruction infringes the GDPR or UK GDPR, unless prohibited from doing so by law.

Axceera may process Customer Personal Data where required by law to which it is subject, and will inform the Customer of that requirement before processing unless the law prohibits it.

5. Confidentiality

Axceera ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations, receive appropriate data protection training, and are granted access only to the extent necessary for their role.

6. Security Measures

Axceera implements appropriate technical and organisational measures under Article 32. Those measures are described in Annex A and on our Security page. Axceera may update them provided the level of protection is not reduced.

7. Sub-processors

The Customer grants Axceera general authorisation to engage Sub-processors.

The current list is published at sprintrack.com/sub-processors. Axceera gives at least 30 days' notice before adding or replacing a Sub-processor. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected part of the service without penalty.

Axceera imposes data protection obligations on each Sub-processor no less protective than this DPA, and remains fully liable to the Customer for each Sub-processor's performance.

Several Sub-processors are engaged only where the Customer enables the corresponding optional feature, as noted on that page.

8. Assistance to the Controller

Taking into account the nature of the processing and the information available to it, Axceera will assist the Customer:

  • In responding to Data Subject requests under Chapter III of the GDPR. Workspace administrators can already access, correct, export, and delete workspace content directly; where that is insufficient, Axceera will provide reasonable assistance on request to hello@sprintrack.com.
  • With data protection impact assessments and prior consultation with a Supervisory Authority, under Articles 35 and 36.
  • With the security obligations in Article 32 and the breach obligations in Articles 33 and 34.

If Axceera receives a Data Subject request relating to Customer Personal Data, it will not respond directly except to confirm receipt and direct the individual to the Customer, and will notify the Customer without undue delay.

9. Personal Data Breach

Axceera will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event in sufficient time to allow the Customer to meet its own notification obligations.

The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not immediately available, Axceera will provide information in phases without undue further delay.

Notifications are sent to the workspace administrators on record. Axceera notifying the Customer is not an acknowledgement of fault or liability.

10. Audits

Axceera will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.

Audits must be requested in writing with at least 30 days' notice, occur during business hours, not unreasonably disrupt the service, be subject to confidentiality, and take place no more than once in any 12-month period — except where required by a Supervisory Authority or following a Personal Data Breach.

Axceera may satisfy an audit request by providing documentation of its technical and organisational measures and answering a reasonable security questionnaire.

11. Deletion and Return

On termination, and at the Customer's choice, Axceera will delete or return Customer Personal Data, and delete existing copies, unless retention is required by law.

Applied in the product: deleting a workspace or project suspends it and creates a recovery export; the data remains restorable for 30 days and is then permanently purged, including files held in object storage. Residual copies may persist in backups and infrastructure logs for a limited further period, subject to the security measures in Annex A, and are deleted on expiry of those cycles.

Customers should export any Customer Content they require before terminating. Axceera will provide reasonable assistance with export on request.

12. International Transfers

Axceera is established in Sri Lanka, which is not the subject of a European Commission adequacy decision, and engages Sub-processors in the United States and the European Union.

For transfers of Customer Personal Data from the EEA, the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), are incorporated into this DPA by reference and apply, with:

  • Clause 7 (docking clause): applicable;
  • Clause 9: Option 2, general written authorisation, with the 30-day notice period in section 7;
  • Clause 11: the optional independent dispute resolution body is not used;
  • Clause 17: governed by the law of Ireland;
  • Clause 18(b): the courts of Ireland;
  • Annex I, II, and III: populated by sections 3, 7, and Annex A of this DPA respectively.

For transfers subject to UK GDPR, the UK International Data Transfer Addendum (version B1.0) to the Standard Contractual Clauses is incorporated by reference, with Tables 1 to 3 populated by this DPA and Table 4 selecting "neither party".

For transfers from Switzerland, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, and the competent authority is the Federal Data Protection and Information Commissioner.

Where a conflict arises between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in section 18 of the Terms and Conditions, except where applicable law does not permit that limitation.

14. Order of Precedence

In the event of a conflict, the order of precedence is: the Standard Contractual Clauses and UK Addendum; this DPA; any separate written agreement between the parties; the Terms and Conditions.

15. Contact

Axceera (Private) Limited 157/3 Kadawatha Road, Nadimala, Dehiwala Sri Lanka Company registration number: PV 00252314

Email: hello@sprintrack.com


Annex A — Technical and Organisational Measures

These are the measures Axceera has implemented. They describe what the service actually does, not aspirational targets.

A.1 Encryption

  • In transit: TLS for all connections to Sprint Track and to every Sub-processor.
  • At rest: encryption provided by the infrastructure platform for the database, object storage, and vector store.
  • Third-party credentials: stored under envelope encryption. Each credential has its own AES-GCM key, wrapped by a versioned root key. The additional authenticated data binds every ciphertext to its workspace, purpose, provider, and owning record, so a stored credential cannot be replayed into another scope. Rotation re-encrypts to the current key version without decrypting into the clear.

A.2 Access Control and Authentication

  • Email one-time-password and Google sign-in; optional TOTP two-factor authentication with encrypted backup codes; workspace-level enforcement of two-factor authentication.
  • Step-up re-verification required for sensitive actions, with a short validity window.
  • Enterprise SSO over OIDC and SAML with domain verification, and SCIM 2.0 provisioning with hashed tokens and group-to-role mapping.
  • Authentication tokens, OAuth client secrets, API tokens, and SCIM tokens are stored hashed, never in plain text.
  • Role-based access control composed from a permission catalogue, enforced server-side on every request.

A.3 Tenant Isolation

Every request is scoped to a workspace and re-authorised against current database state. Semantic search results are re-authorised against live permissions before being returned, and AI citations are revalidated on every read, with redaction where a source has become inaccessible.

A.4 Integrity of Outbound Actions

  • Every outbound write to a connected source-code provider requires a matching approval record; the payload is hash-checked against what was approved, and the approval is claimed atomically. There is no unapproved outbound write path.
  • Requests from the local coding runner require an Ed25519 signature over the timestamp, nonce, method, path, and body hash, within a two-minute window with single-use nonces.
  • Payment webhooks are signature-verified with key rotation support.

A.5 Logging and Accountability

  • Workspace audit logs record actor, action, target, status, and outcome.
  • Security events record authentication, SSO, SCIM, and integration anomalies.
  • Platform administrator actions are recorded in a separate audit trail.
  • AI spend is recorded in an append-only, HMAC-chained ledger holding model, rate, and unit counts only — no prompt content.
  • Retention and redaction periods for each of these are published in section 10 of the Privacy Policy.

A.6 Resilience and Recovery

Deletion is two-phase: suspension with a recovery export, a 30-day restore window, then permanent purge including object storage. Durable job, lease, and outbox state is held in the primary datastore so that in-flight work survives restarts.

A.7 Organisational Measures

Personnel access is limited to what each role requires and is subject to confidentiality obligations. Changes are reviewed before release, and automated checks enforce configuration, contract, and schema invariants in the build pipeline.

A.8 Vulnerability Reporting

Suspected vulnerabilities should be reported to hello@sprintrack.com. We acknowledge reports and work with reporters on remediation and coordinated disclosure.