-
Scrumpacity’s application functions and app-managed data use Atlassian Forge services. MayaTech Solutions does not operate a separate customer-facing Scrumpacity database.
-
Scrumpacity uses declared Forge permissions to access the Jira information required for its features. Requested permissions are presented during installation or upgrade.
-
Scrumpacity does not send Jira data, sprint information, issue content, or user information to OpenAI or another generative AI provider.
-
Customer data is not sold, rented, or used for advertising, behavioral profiling, or unrelated marketing.
-
Depending on the features used, Scrumpacity may access:
Jira sites, projects, boards, and sprint configuration
Work item estimates, statuses, assignments, and sprint membership
User names and Atlassian account identifiers required for capacity planning
Project roles and permissions needed to control administrative features
Installation, licensing, and technical metadata
Sprint commitments, scope changes, completion results, and related delivery measurements
Security at MayaTech Solutions
Built for Responsible Jira Data Handling
Scrumpacity is designed to help teams plan, track, and learn from their sprints without introducing unnecessary systems or data transfers.
The app is built on Atlassian Forge and operates through declared permissions within the Atlassian Cloud environment. Scrumpacity does not require your Jira password or API token, and customer data is not sent to generative AI services.
-
Information Scrumpacity stores
Scrumpacity may store app-specific information such as:
App and project configuration
Team capacity profiles and availability adjustments
Sprint baselines captured when a sprint begins
Completed sprint outcomes and trend history
User-specific settings and preferences
Atlassian account identifiers needed to associate saved settings with users
Technical records required to operate, troubleshoot, and maintain the app
Scrumpacity does not require customers to provide Atlassian passwords, personal API tokens, payment-card information, government identification numbers, or medical information.
Customers should not intentionally enter highly sensitive personal information into Scrumpacity.
-
Authentication and authorization
Scrumpacity relies on Atlassian for user authentication. MayaTech Solutions does not create or manage separate Scrumpacity passwords.
Access to Scrumpacity begins with access to the customer’s Atlassian site. Administrative and configuration functions are additionally limited through Jira permissions and app-level authorization checks.
Only authorized Jira administrators can install the app or approve changes to its requested permissions.
-
Data location and infrastructure
Scrumpacity is built using Atlassian Forge. App functions communicate with Jira through authenticated Atlassian APIs, and app-managed information is stored using Forge-hosted services.
Atlassian is responsible for securing the underlying Forge and Atlassian Cloud infrastructure. MayaTech Solutions is responsible for Scrumpacity’s application code, requested permissions, configuration, and secure development practices.
Customers remain responsible for:
Managing Jira users, groups, and project permissions
Reviewing requested app permissions before installation
Removing access when it is no longer required
Determining what information is appropriate to place in Jira
Maintaining their organization’s endpoint, identity, and account security
-
Secure development practices
Secure development practices
MayaTech Solutions applies security-focused practices throughout Scrumpacity’s development and maintenance, including:
Reviewing application permissions and limiting them to required functions
Separating development, staging, and production environments
Testing changes before production deployment
Avoiding hard-coded credentials and secrets
Reviewing third-party dependencies
Limiting sensitive information in application logs
Maintaining privacy-reporting and account-erasure workflows required for stored personal data
Triaging reported vulnerabilities according to their potential impact
Security controls and processes will continue to evolve as Scrumpacity and MayaTech Solutions mature.
-
Vulnerability and incident response
Security reports are reviewed to determine their scope, severity, and potential customer impact. When a confirmed issue affects customer data or app security, MayaTech Solutions will work to contain the issue, remediate it, and communicate with affected customers when required.
Please do not publicly disclose a suspected vulnerability before MayaTech Solutions has had a reasonable opportunity to investigate and address it.
-
Report a security concern
To report a suspected vulnerability or security incident, email:
support@mayatechsolutionsllc.com
Use the subject line:
Security Report — Scrumpacity
Please include:
A description of the issue
The affected feature or page
Steps needed to reproduce it
The potential security impact
Relevant screenshots or sanitized logs
Your preferred contact information
Do not send passwords, API tokens, authentication cookies, private keys, or unnecessary customer data.
Privacy
-
Scrumpacity Data Security and Privacy Statement
Last updated: September 17, 2026
Overview
Scrumpacity is a Jira Cloud application developed and operated by MayaTech Solutions LLC. It helps delivery teams plan sprint capacity, compare committed and completed work, monitor scope changes, and learn from delivery history.
Scrumpacity is built entirely on Atlassian Forge. App data is processed and stored within Atlassian’s Forge platform. Scrumpacity does not operate an external application server or external database and does not send Jira data to third-party analytics services.
Security and privacy at a glance
Hosting: Atlassian Forge
External data storage: None
External data egress: None
Third-party analytics or advertising: None
Authentication: Atlassian Forge and Jira authentication
Encryption: Provided by the Atlassian-hosted platform in transit and at rest
Tenant isolation: Data is stored separately for each Atlassian installation
Credentials collected: Scrumpacity does not collect Jira passwords, personal access tokens, or API tokens
Data residency: Supported through Atlassian Forge hosted storage
Security and privacy contact: support@mayatechsolutionsllc.com
Data accessed by Scrumpacity
Scrumpacity accesses Jira data only as needed to provide its planning, capacity, sprint analysis, and delivery-learning features.
Depending on the features used, the app may access:
Jira project keys and project configuration
Jira board names and board identifiers
Sprint identifiers, names, states, and dates
Jira issue keys and summaries
Issue types and workflow statuses
Story-point or estimation values
Assignee Jira account identifiers and display names
User avatar URLs
Sprint scope and completion information
Jira project roles and permissions
This information is accessed through Atlassian-provided APIs and is subject to the permissions of the Jira user and the Forge scopes granted to the app.
Data stored by Scrumpacity
Scrumpacity stores limited application configuration and sprint evidence in Atlassian Forge hosted storage.
Configuration data
The app may store:
Jira project key
Selected Jira board identifier and name
Estimation settings
Jira account identifiers for configured team members
Team-member display names and avatar URLs
Default capacity settings
Sprint-specific capacity settings
Availability and time-off adjustments
Sprint planning and delivery data
The app may store:
Sprint identifiers and names
Sprint state, start date, and end date
Issue keys and issue summaries
Story-point or other configured estimates
Issue status and issue type
Assignee account identifier and display name
Sprint baseline timestamps
Aggregate committed and completed work
Calculated delivery and planning metrics
Scrumpacity stores this information to provide capacity planning, sprint-baseline comparison, scope-change tracking, readiness checks, and delivery-learning features.
Because Jira account identifiers, names, avatar URLs, issue summaries, and assignee information can relate to identifiable individuals, Scrumpacity should be treated as storing personal data.
Information Scrumpacity does not collect
Scrumpacity does not intentionally collect or store:
Jira passwords
Atlassian account passwords
Personal access tokens
Customer API tokens
Payment-card information
Government identification numbers
Advertising identifiers
Location-tracking data
Data for targeted advertising
Data for sale to third parties
Scrumpacity does not sell personal data.
Hosting and tenant isolation
Scrumpacity uses Atlassian Forge hosted storage. Data is associated with the Atlassian site and installation where the app is installed.
Data from one customer installation is not intentionally shared with another customer installation. Scrumpacity does not copy its Forge-hosted application data into an independently operated external database.
Additional information about Forge hosted storage is available in Atlassian’s Forge storage documentation.
Authentication and access control
Authentication is handled by Atlassian. Scrumpacity does not maintain a separate customer password system.
Access to app functionality is governed by:
The user’s Atlassian identity
Jira project permissions
Jira administrator and project-administrator permissions
The Forge scopes granted to the app
Application-level authorization checks
Administrative operations, configuration changes, and Jira write operations are restricted to appropriately authorized Jira users.
MayaTech Solutions LLC personnel do not receive routine direct access to a customer’s Jira site through Scrumpacity. Authorized personnel may access Forge operational logs when necessary to investigate support requests, reliability problems, or security events.
Encryption
Scrumpacity relies on the security controls provided by Atlassian Forge. Data transmitted between the user, Jira, and Forge is protected in transit, and Forge-hosted persistent data is protected at rest as part of Atlassian’s platform controls.
Scrumpacity does not implement an external storage layer outside Atlassian Forge for Jira customer data.
External data transfers and third parties
Scrumpacity does not configure Forge remote endpoints and does not transmit Jira customer data to external application servers.
The app does not use third-party advertising, tracking, or product-analytics services.
Atlassian provides the infrastructure, APIs, authentication, hosted storage, and logging services used to operate Scrumpacity. Atlassian’s own privacy, security, and data-processing terms apply to those platform services.
Data residency
In-scope end-user data stored by Scrumpacity is stored exclusively in Atlassian Forge hosted storage. Scrumpacity does not independently store that data outside Atlassian apps and services.
Forge manages supported data-residency locations, data pinning, and migration for hosted app data. Availability of a particular residency region depends on Atlassian’s Forge and product support.
For additional information, see:
Operational logging
Scrumpacity uses Atlassian Forge logs for troubleshooting, security monitoring, and app reliability.
Operational logs may include limited technical information such as:
Jira project keys
Sprint identifiers or names
Aggregate issue or point counts
Timestamps
Forge invocation information
Error messages and stack traces
Scrumpacity does not intentionally place passwords, access tokens, API secrets, or payment information in logs.
Logs are hosted by Atlassian and may be reviewed by authorized MayaTech Solutions LLC personnel when reasonably necessary to investigate an incident or customer support request. Logging is designed to be limited to information necessary for operating and supporting the app.
Atlassian administrators may also have options to view or download Forge app logs according to Atlassian’s platform functionality and policies.
Retention and deletion
Scrumpacity retains configuration and sprint evidence while the app remains installed and the information is needed to provide its features.
Customers can remove or replace stored configuration by changing the applicable settings in Scrumpacity. Jira content remains subject to the customer’s Jira retention and deletion practices.
When Scrumpacity is uninstalled, Forge handles the soft deletion, retention, possible recovery, and permanent deletion of hosted application data according to Atlassian’s hosted-storage lifecycle and data-retention policies.
For more information, see Atlassian’s hosted storage data lifecycle documentation.
Customers may contact MayaTech Solutions LLC to request assistance with app-data deletion or privacy inquiries.
Atlassian account changes and deletion
Scrumpacity uses Atlassian’s Personal Data Reporting API to identify relevant Atlassian-account updates.
The app periodically processes account-status information so that:
Stored user-profile details can be refreshed when appropriate
References to closed accounts can be removed from stored capacity configuration
References to closed accounts can be removed from stored sprint baselines
Some non-identifying or aggregate delivery information may remain where needed to preserve sprint-level reporting, provided it no longer identifies the closed account.
GDPR and CCPA roles
For customer data processed through Scrumpacity:
The customer generally determines why and how its Jira data is used and ordinarily acts as the data controller under the GDPR.
MayaTech Solutions LLC processes applicable data to provide Scrumpacity and ordinarily acts as a data processor.
Under the CCPA, the customer may act as the business and MayaTech Solutions LLC ordinarily acts as a service provider for applicable personal information.
MayaTech Solutions LLC does not use customer personal information for cross-context behavioral advertising and does not sell it.
The precise legal roles can depend on the customer’s circumstances and applicable law.
Customer responsibilities
Customers are responsible for:
Configuring Jira access permissions appropriately
Providing app access only to authorized users
Determining whether Scrumpacity is appropriate for their data and regulatory requirements
Maintaining appropriate notices and lawful bases for processing employee or contractor information
Avoiding the placement of unnecessary sensitive personal information in Jira issue summaries or other fields used by the app
Reviewing Atlassian’s and MayaTech Solutions LLC’s applicable terms before installation
Security incidents
MayaTech Solutions LLC investigates suspected security incidents involving Scrumpacity and takes reasonable steps to contain, correct, and document confirmed incidents.
Where required by applicable law or contractual obligations, affected customers will be notified without undue delay after MayaTech Solutions LLC becomes aware of a confirmed incident affecting their data.
Security concerns should be reported to:
support@mayatechsolutionsllc.com
Please do not include passwords, access tokens, or unnecessary personal information in a security report.
Changes to this statement
MayaTech Solutions LLC may update this statement when Scrumpacity’s functionality, data practices, legal obligations, or Atlassian platform capabilities change.
The “Last updated” date at the top of this page identifies the latest revision.
Additional information
For information about personal-data handling, retention, and customer rights, review our Privacy Policy.
For product assistance, visit our Support page or email support@mayatechsolutionsllc.com.
Last updated: September 17, 2026