Legal

Privacy Policy

Questions about this policy? Email us at privacy@rundown.be

About This Policy

This Privacy Policy explains how Rundown ("we", "us", "our") collects, uses, shares and protects personal data when you visit rundown.be, use our application, or otherwise interact with us. Rundown is operated by placeholder_legal_entity_name, registered at placeholder_legal_entity_address, company number placeholder_company_registration_number.

This policy is written to comply with the EU General Data Protection Regulation (GDPR) and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data. It applies to the Rundown platform, our marketing site, and our communications with you. It does not cover third-party services you connect to Rundown (for example, Atlassian Jira), which are governed by their own privacy policies.

Effective date: placeholder_policy_effective_date.

What Data We Collect

We collect and receive the following categories of data:

  • Account information. Name, email address, hashed password, profile picture, workspace and role, set when you sign up or are invited to a workspace.
  • Workspace content. Data you and your colleagues create inside Rundown: projects, tasks, plans, time entries, comments, charts, reports, and files uploaded to our storage.
  • Usage and log data. IP address, browser type, device information, pages visited, actions taken, and timestamps, collected automatically through our servers and standard web logs.
  • Cookies and similar technologies. Strictly necessary cookies for authentication and session handling, and optional preference cookies (e.g. theme) that we set only with your consent. See our Cookie Policy for the full list and to change your choices.
  • Third-party integration data. When you connect Atlassian Jira to Rundown using OAuth 2.0, we receive the Jira issues, users and projects you authorize us to access, in order to keep them in sync with your Rundown workspace. Jira is linked using the account you authenticate with during this flow, and we recommend connecting the Jira account whose email matches your Rundown account so your identity stays correctly mapped across both systems; if the emails differ, we notify you after connecting.
  • Communications. Messages you send us by email (e.g. privacy@rundown.be), through our contact forms, or through in-app support.
  • Billing data. When paid plans become available, billing contact details and invoice information will be processed by us and by our payment provider, which we will add to the sub-processor list in our Data Processing Agreement before any payment is taken. We do not store full payment card numbers.

How and Why We Use Your Data

We use the data described above for the following purposes:

  • To provide the service — create and authenticate your account, host your workspace data, sync with Jira, and make the product work (legal basis: performance of a contract).
  • To support you — respond to your questions and troubleshoot issues you report (contract / legitimate interest).
  • To secure and improve the service — monitor for abuse, debug errors, analyze usage in aggregate, and improve features (legitimate interest).
  • To communicate with you — send service notices, security alerts and product updates. Marketing emails are only sent with your consent and you can unsubscribe at any time.
  • To comply with the law — meet legal, accounting, and tax obligations (legal obligation).

We do not sell personal data and we do not use your workspace content to train machine-learning models. That includes the AI Reporting Studio: the language model provider we use is contractually barred from training on anything we send it, as described in the AI Reporting Studio section below.

Rundown Tracker Browser Extension

The Rundown Tracker browser extension lets you start and stop your Rundown time tracker directly on Jira issue pages, without installing anything inside Jira.

  • Data processed. When you sign in through the extension, your email address and password are sent over an encrypted connection to the Rundown API to authenticate you. We store only the resulting session token locally in your browser's extension storage — never your password. On Atlassian (*.atlassian.net) issue pages, the extension reads the issue key from the page URL so that tracked time is linked to the correct ticket. No other page content is read or collected.
  • How it is used. Solely to provide the extension's features: signing you in, starting and stopping timers, and showing your own tracked time.
  • Storage and sharing. The session token and your preferences are stored locally in your browser. Time-tracking data is sent to the Rundown API as part of your Rundown account. We do not sell this data, do not use it for advertising, and do not share it with third parties beyond what is necessary to provide the service.
  • Removal. Signing out of the extension, or removing it from your browser, clears the locally stored token. Your Rundown account data continues to be governed by this policy.

AI Reporting Studio

The AI Reporting Studio lets you describe a report in your own words instead of assembling it by hand. To do that, Rundown sends your request to Anthropic PBC, a language model provider acting as our sub-processor. The model returns the configuration of a report — which figures to show, for which period, grouped how. Rundown then runs that report itself, against your own workspace data.

  • What is sent. The messages you type, the report configuration currently on your screen, and the names and internal identifiers of the clients, projects, teams, roles and epics you are allowed to see — so the model can match "the Acme redesign" to the right project. Where a report is about people, the names of the people already within your access scope are included for the same reason.
  • What is never sent. No time entries, hourly rates, budgets, revenue, cost or margin figures, no comments or uploaded files, and no report results. Every number you see in a generated report is computed by Rundown from your workspace database and has never left it.
  • Nothing is stored on the model provider's side. Each request is stateless — Anthropic keeps nothing between turns.
  • Your conversation is saved by Rundown, for you. So you can leave the page and come back to it, your one Studio conversation is stored in your workspace's own database rather than in your browser, along with the report it is building, so that returning to the Studio brings that report back with it. Only you can see it — not your colleagues, not your administrator. It is deleted automatically 90 days after you last use it, and you can clear it yourself at any time. Nothing about a conversation is written to our logs.
  • Report configurations. You can save the report you are building as a named configuration — a report definition, not results — so you can reopen it later and carry on with it in the conversation. Configurations are private to you and kept until you delete them. Saving a report instead is the deliberate step that makes it visible to your workspace.
  • Not used for training. We use Anthropic's commercial API under terms that prohibit using our inputs or outputs to train their models.
  • Your access rights still apply. Which data a generated report can reach is decided by Rundown's own permission and scope checks, not by the model. A request for company-wide figures from someone who may only see their own comes back narrowed, with a note saying so.
  • Availability. The feature depends on your workspace's plan. Where it is not enabled, no data is transmitted to the model provider at all, and the manual report builder works exactly as before.

Anthropic processes this data in the United States under Standard Contractual Clauses. See Annex III of our Data Processing Agreement for the full sub-processor entry.

Data Retention

Each company using Rundown can configure its own data retention period in the workspace's general settings. The default retention period is 2 years from the date workspace content (projects, tasks, plans, time entries, comments, files, etc.) is created or last modified, after which the data is automatically deleted or anonymized.

Account-level data (user account, authentication records) is retained for the duration of the contractual relationship and deleted within 30 days after the workspace is closed, except where retention is required by law (for example, invoicing records, which we retain for 7 years in accordance with Belgian accounting law).

Encrypted backups are retained for no longer than 7 days and rotated automatically. Log data is retained for no longer than 30 days.

Your conversation in the AI Reporting Studio is kept so you can come back to it, and is deleted automatically 90 days after you last use it. You can clear it yourself at any time from the Studio. Report configurations you save are kept until you delete them.

You can request earlier deletion at any time by contacting privacy@rundown.be — see "Your Privacy Rights" below.

Before a workspace is closed, an administrator can download a complete copy of everything it holds from Settings ▸ Export workspace. Closing a workspace locks it immediately, so the export needs to be taken beforehand. The generated archive is stored privately and is deleted 7 days after it is created.

How We Protect Your Data

We protect your data using, among other measures:

  • Encryption in transit using TLS 1.2 or higher for all communication between your browser and our services.
  • Encryption at rest for databases and file storage, provided by our hosting sub-processors.
  • Hashed passwords — we never store passwords in plaintext.
  • JWT-based authentication with per-environment secrets and short token lifetimes.
  • A schema-per-tenant database architecture that isolates each customer's data from every other customer's data.
  • Strict access controls — only a limited number of authorized personnel can access production systems, under written confidentiality obligations.
  • Regular dependency updates, automated security scanning, and monitoring for known vulnerabilities.
  • Workspace exports that never contain passwords or access tokens, are downloadable only by the workspace that produced them, and are deleted automatically after 7 days.

While we apply industry-standard safeguards, no method of transmission or storage over the internet is 100% secure. If we ever become aware of a personal data breach affecting you, we will notify you and the competent supervisory authority in accordance with GDPR Article 33–34.

Minimum Age

Rundown is a B2B product intended for businesses and their employees. It is not directed to children. You must be at least 16 years old to create an account or use the service. If we discover we have collected personal data from a child under 16 without verified parental consent, we will delete it as soon as reasonably possible.

Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, our practices, or applicable law. The "Effective date" at the top of this page indicates when the policy was last revised.

For material changes that affect your rights, we will notify you in advance by email or through an in-app notice. Continued use of Rundown after the changes take effect constitutes acceptance of the updated policy.

International Data Transfers

Rundown is operated from Belgium and your workspace data is stored within the European Economic Area (EEA): our application servers and database are hosted in Frankfurt, Germany, and uploaded files are stored in Stockholm, Sweden.

Some of our sub-processors are companies incorporated outside the EEA. In some cases their personnel access data from outside the EEA for support and maintenance; in others the processing itself takes place outside the EEA — our email delivery provider processes recipient addresses and message contents in the United States, and, if you use the AI Reporting Studio, our language model provider processes your requests there as well. Where either happens, we rely on the European Commission's Standard Contractual Clauses (SCCs) and apply additional safeguards as required by GDPR.

Our main sub-processors are:

  • Render — hosting of our backend APIs.
  • Vercel — hosting of our frontend application and marketing site.
  • Amazon Web Services (AWS) — file storage (S3) for files you upload to Rundown.
  • Resend — delivery of our transactional email (workspace invitations, password-reset links, service notifications). Resend receives the recipient's email address and the contents of the message, and processes them in the United States under Standard Contractual Clauses. It does not receive your workspace content.
  • Atlassian — only when you choose to connect a Jira workspace; we exchange data with Atlassian on your behalf to keep Jira issues in sync with Rundown.
  • Anthropic — only when you use the AI Reporting Studio. Anthropic receives your request and the names of the clients, projects and teams you are allowed to see, and returns the configuration of a report; it never receives your time entries, rates, budgets or financial figures. Processing takes place in the United States under Standard Contractual Clauses.

The full list of sub-processors, including the region in which each one processes data and the transfer mechanism that applies, is maintained in Annex III of our Data Processing Agreement.

Privacy Contact

We are not required to appoint a Data Protection Officer under Article 37 GDPR: we are not a public authority, our core activities do not consist of large-scale regular and systematic monitoring of individuals, and we do not process special categories of personal data on a large scale.

You can reach us about any privacy matter — including a request to exercise your rights — at privacy@rundown.be. We respond within one month, as required by Article 12(3) GDPR.

Controller and Processor Roles

Workspace content. For the data you and your colleagues upload into your Rundown workspace (projects, tasks, time entries, files, comments, etc.), your company is the data controller and Rundown acts as a data processor on your behalf, processing data according to your instructions and our Data Processing Agreement (DPA).

Account and marketing data. For data we collect directly — account registration, billing, support communications, and analytics on our marketing site — Rundown is the data controller.

Our Data Processing Agreement is published in full and forms part of our Terms & Conditions, so it is already in place for every workspace — you do not need to request or sign one separately.

Your Privacy Rights

Under GDPR, you have the following rights:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your personal data deleted, subject to retention obligations imposed by law.
  • Restriction — limit how we process your data in certain circumstances.
  • Objection — object to processing based on legitimate interests, including direct marketing.
  • Portability — receive your personal data in a structured, machine-readable format and have it transmitted to another controller. Your workspace administrator can download the whole workspace, in JSON and CSV, from Settings ▸ Export workspace; for a copy of your own records alone, email us.
  • Withdraw consent — where processing is based on consent, withdraw that consent at any time.
  • Lodge a complaint with a supervisory authority (see next section).

To exercise these rights, email us at privacy@rundown.be. If you use Rundown through your employer, please contact your workspace administrator first — for workspace content they are the controller and we will forward requests to them.

Supervisory Authority

If you believe our processing of your personal data violates GDPR, you have the right to lodge a complaint with the Belgian Data Protection Authority:

Gegevensbeschermingsautoriteit / Autorité de protection des données
Rue de la Presse 35, 1000 Brussels, Belgium
Web: www.dataprotectionauthority.be

You also have the right to lodge a complaint with the supervisory authority in the EU Member State where you live or work, or where the alleged infringement took place.

Contact Us

For any question about this Privacy Policy or about how we process your personal data, email us at privacy@rundown.be.

For postal correspondence:
placeholder_legal_entity_name
placeholder_legal_entity_address