Terms and privacy
Tavle is an open source tool for Kanban and Scrum teams, one of the tools in the Haij family. This page is two things at once: the agreement between you and us when you use the edition we run, and the information about personal data the GDPR says you must be given before you hand us anything. If you run the code yourself, only the licence applies.
What Tavle is
A tool for keeping a team's work visible: boards, cards, sprints and the numbers that can be computed from them. We make no promise that it fits the way you work; try the demo first.
Who is behind it
The service at tavle.haij.dk is run by Vinther Consulting, Jens Bornøs Vej 1, company registration number (CVR) 30769201, martin@vintherconsulting.dk. We have two roles and they are not the same. For your account and your application — name, e-mail, IP address, browser — we are the controller: we are the ones who decided that information should exist. For everything your team writes on the board you are the controller and we are the processor: we store it, show it to you, take an encrypted backup at night, and send it to a language model in the cases the AI section describes — and otherwise nothing. We do not read along, and we use none of it for anything of our own. The frame around that part is a data processing agreement; the template is in the code repository and we are glad to sign it.
Accounts and access
You create an account with a name, an e-mail and a password, or you apply for access and are invited. The password is stored hashed, you can add a passkey and two-step verification, and a session expires after seven days. We set no cookies for measurement or marketing; the ones there keep you signed in, remember whether you read Danish or English, and remember whether you have folded away the menu on the left. We sell nothing, and Tavle sends no mail at all — not even marketing mail.
What we may do, and why
Three purposes, each with its own basis. Running the service — account, sign-in, boards, export — is to perform the agreement with you (Article 6(1)(b)). Handling an application for access is the same basis, at your own request. Keeping the installation safe and free of abuse — the audit trail, the sign-in lines, the counters behind the limits on forms and AI calls — is our legitimate interest in being able to see what happened and stop what should not have (Article 6(1)(f)). There is no fourth purpose, and nothing here rests on consent, because there is nothing to consent to: no tracking, no statistics, no marketing.
How long we keep things
What stands here is what the code actually does, including where the answer is that nothing expires. A period we do not enforce would be a period we made up.
- The account: as long as you have it. Deleting your workspace takes the workspace and everything in it at once, but the account itself stays until you ask us to remove it. There is no button for that yet; write to us and we will do it.
- Abandoned workspaces: they do not expire on their own today. A workspace nobody has touched for years stays until somebody asks for it to be deleted. That is a gap rather than a decision, and the day it is closed something else will stand here.
- The audit trail: for as long as the workspace exists. It can be neither edited nor deleted along the way — that is the whole point of it — and when the workspace is deleted the trail goes with it. The few lines that belong to no workspace, that an account was created or signed in, stay; they hold nothing from a board.
- The AI call lines: one per call with who, what kind and when, never the content. They do not expire on their own; they follow the workspace out on the day it is deleted.
- Applications for access: kept with no expiry, declined ones included, as a note of what was decided. Ask for yours to be deleted and we delete it.
- Backups: the nightly encrypted copies roll off after 30 days, on the server and in the EU storage they are copied to. Something you deleted may therefore sit in a copy for another month.
- Demo workspaces: 24 hours, the account included, and then there is nothing left.
Your data
Everything a workspace puts in — cards, comments, sprints and the names of the people work is assigned to — belongs to the workspace. It can be downloaded as a spreadsheet and JSON with one click and deleted entirely again, audit trail included. We do not look at it unless you ask us for help, and we never pass it on. If you write other people's personal data into it — a colleague's name on a card, a customer's name in a comment — you are the controller for those, and the data processing agreement is the frame around what we do with them.
AI
With a language model set up, text from the board is sent to the model provider. Eight of the ten things the model can do happen only when somebody presses a button, and then the card, the sprint or the item being asked about is what is sent. Two send more than that. While you type the title of a new card, Tavle suggests by itself where it belongs and whether it looks like something that already exists — 800 milliseconds after you stop typing, with no button pressed — and for that the titles of up to two hundred of the board's cards are sent. And when you ask the assistant for a proposal for the backlog, the whole open decomposition goes: every open epic and feature with its title, its area, its themes and whether it has a “done when”. No field holding a person's name is sent — not who a card is assigned to, not your roster of people — and comments are never sent. But titles, descriptions and “done when” are free text, so if you name a colleague or a customer there, the name goes with them. Who the provider is stands under Settings → AI and in the list of subprocessors; a workspace that picks its own provider has chosen its own processor. The model proposes; nothing is saved without a person saying yes, and with no model nothing is sent while everything else works.
Invitations
An invitation link is for one address and expires after two days. You send it; we send no mail.
Leaving
You can delete your workspace immediately, without writing to anyone and without waiting. The export is one click away and readable without Tavle. We keep no copy afterwards beyond the nightly encrypted backups, which roll off after 30 days — on the server and in the EU storage they are copied to.
Your rights
Over the data we are the controller for, you have the rights below. Two of them are buttons in the tool itself; the rest cost an email to martin@vintherconsulting.dk, and we answer within a month. If it is what your team wrote on the board you want access to or deleted, the workspace itself is the controller — ask them, and we will help them answer.
- Access: you can be told what we hold about you, and get a copy of it.
- Rectification: if something is wrong, we correct it. Name and email cannot be changed from the settings yet, so that way runs through us.
- Erasure: the workspace's owner deletes it with everything in it, at once and without asking anybody. If you are not the owner, ask the owner — or us. We remove an account or an application when you ask; there is no button for that yet.
- Portability: Settings → Data gives you all of it as a spreadsheet and JSON, readable without Tavle.
- Restriction: you can ask us to leave the data untouched while we disagree about something.
- Objection: you can object to what we do under legitimate interest — the security log and the abuse protection — and we will consider it and answer you.
Complaints
If you are unhappy with the way we handle your data, tell us first; it is faster than anything else. You may also complain to Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark, dt@datatilsynet.dk, which is the supervisory authority here.
Running and guarantees
Tavle is new, and there is no uptime guarantee. We look after your data with encrypted backups every night, but take an export now and then if the project matters. The service is provided as it is, without warranties beyond what the law requires.
Licence
The code is AGPL-3.0. You may use it, change it and run it yourself; if you change it and offer it to others over a network, your changes must be available too. What you write in the tool is not covered by the licence — that is yours.
The demo
A demo workspace is created without e-mail or sign-up and deleted entirely after 24 hours, account included. Do not put real personal data in it. We keep only the technical log data needed to keep the demo running.
Contact
Write to Vinther Consulting at martin@vintherconsulting.dk. That is also the address for anything about personal data. If you have found a security problem, SECURITY.md in the repository says how to report it; use that rather than an ordinary email.