Agile Gauge for Azure DevOps: Privacy Policy
Last updated: 9 October 2026
Overview
Agile Gauge ("the Extension") is an Azure DevOps extension published by ALESTA SOFTWARE BİLGİSAYAR YAZILIM TASARIM SANAYİ VE TİCARET LİMİTED ŞİRKETİ ("Alesta Software", "we", "us"). It processes Azure DevOps data inside the customer's browser to render dashboards and reports. This policy explains what data the Extension touches, where it goes, and what Alesta Software stores on its own systems.
1. Data the Extension reads from Azure DevOps
The Extension uses read-only Azure DevOps scopes (vso.project, vso.work, vso.graph). With those scopes, the Extension reads, on demand:
- project, team, sprint, and iteration metadata
- work item fields and revision history needed for analytics
- group and membership info needed for Access Control
This data stays in the customer's browser. It is not sent to Alesta Software.
2. Alerts to Microsoft Teams or Slack
Not available. Agile Gauge does not currently send alerts to Microsoft Teams, Slack or any other webhook. If this is ever offered, it will be off by default, and this policy will be updated before it ships.
3. Data persisted in the customer's Azure DevOps tenant
Configuration and per-user preferences are persisted via Microsoft's Azure DevOps Extension Data Service. This storage is hosted by Microsoft and scoped to the customer's organization. Alesta Software does not host or have access to it. This includes:
- extension configuration (access control, notification settings)
- per-user UI preferences
- license activation token and license summary (cached locally so the Extension can revalidate)
4. Data Alesta Software stores on its own systems
Alesta Software operates a licensing service at api.agilegauge.com, hosted on Microsoft Azure in the Central US region. Agile Gauge's data lives in its own isolated database schema: never mixed with any other product's records. The following data is stored on Alesta Software-controlled systems:
- License records: the Azure DevOps organization ID, a reference we generate for the organization (it starts with
ORG-), the license's seats, status and paid-through date, and a one-way hash of the license key (the key itself is never stored). We do not store the organization's name. - Trial records: when the organization's trial started and ends.
- Seat roster: for each person given a seat, only a keyed one-way hash of their Azure DevOps identity and a reference we generate from that hash (it starts with
USR-), so seats can be enforced. We never store their name, email address or Azure DevOps identity ID. The hash cannot be turned back into the identity, and without our secret key it cannot be matched to anyone. - Agile Gauge admin list: the people and groups your organization made Agile Gauge admins, as reported by the Extension, so they can manage seats. A person is stored the same way as on the seat roster; a group is stored by its Azure DevOps group ID. No names.
- Audit trail: who changed seats, activated a license or started a trial, and when. The person is recorded by their
USR-reference only. - Payment records from our reseller Paddle: transaction and subscription references, amounts, currency, tax and country, used to keep the license in step with the subscription and answer billing questions. We do not keep the buyer's name, email address or postal address.
- License-key email address: to send a license key after a purchase, we ask Paddle for the buyer's email address and language when the email is sent. The address is deleted from our database as soon as the email has been sent.
- Support tickets: when someone opens a ticket from the Extension's Support page, we keep its subject, category and messages; the
USR-reference of the person who opened it and of each person who wrote in it; the Extension version, display language and license state when it was opened; and when it was opened, last updated and closed. Tickets are text only, with no attachments, and the form asks you not to write personal data, such as names or email addresses, in them. A ticket is seen only by the person who opened it, your organization's Agile Gauge admins and Project Collection Administrators, and us. - Usage counts: how many times each screen was opened, how long screens took to load, error categories (never error text), the Extension version, display language and license state, summed per day. These counts carry no organization, no person and no work item content.
Names stay with you. Agile Gauge shows the names of seat holders and admins by asking your own Azure DevOps when the page opens. They are never sent to us. The Extension shows your organization's and your own reference, so you can quote them when you contact support.
To check a seat, the Extension sends the viewer's Azure DevOps sign-in token with each request. The licensing service uses it to verify the viewer with Azure DevOps, then lets it go: nothing from the token is stored or logged. Our service logs do not keep client IP addresses.
When a ticket needs our answer, we send an email to our own support address that names only the ticket and the organization, by their references, never the ticket's subject or messages. We never email you about a ticket: we hold no email address for you.
Alesta Software does not receive Azure DevOps work item content, AI prompts, AI responses, or AI provider API keys.
This website (agilegauge.com) uses no cookies, analytics or trackers of its own. The light/dark theme choice is kept in your own browser. The only third-party script is Paddle's, loaded on two pages only: the checkout page, for the payment form, and the billing page, where Paddle Retain helps a customer whose renewal payment failed to update their card. On those two pages Paddle's script works under Paddle's own privacy notice, and Retain may record that the page was visited.
5. AI integrations
Not available in v1. Agile Gauge does not currently offer any AI-powered features or third-party AI integrations. A future bring-your-own-key (BYOK) AI capability is under discussion: if built, this policy will be updated before that feature ships. Customer-supplied API keys would stay in the customer's own environment and would never be stored by Alesta Software.
6. Sub-processors
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Microsoft Azure (Central US) | Hosts the licensing service and its database, and this website | License, seat, admin, audit, payment and support ticket records described above; standard web request logs |
| Paddle | Reseller and Merchant of Record: checkout, payment, tax, invoicing and failed-payment recovery (Paddle Retain) | Everything needed to take the order; card details go to Paddle only |
| Resend | Sends the license-key email, and tells our support team that a ticket needs an answer | Recipient email address and the license email: the key, its seats, paid-through date and reference number. For a ticket, only the ticket and organization references, sent to our own support address |
| Cloudflare | DNS for agilegauge.com | None beyond the DNS lookup itself |
Microsoft Azure DevOps hosts your own tenant and the Extension Data Service; you control that data. The sub-processors page keeps this list current.
7. Data retention
Each kind of record is kept for the period below, then deleted, or stripped of anything that points to a person.
- License and trial records: kept for 2 years after the license or trial ends, then deleted, except a note that the organization has used its trial (its ID and the trial dates), kept up to 5 years after the trial ends, and the few details that our payment records and audit trail still refer to.
- Seat roster and Agile Gauge admin list: a person's entry is deleted 30 days after they are removed, and the whole list 90 days after both the license and the trial have ended. If an organization never starts a trial or a license, each entry is deleted 90 days after it was recorded.
- Audit trail: the history of license, seat and trial changes is kept for 10 years after the end of the year of each change, and the person references in it are removed 3 years after the end of that year, leaving only a role such as customer or staff.
- Payment records: the records we receive from Paddle are kept for 10 years after the end of the year of the payment, as Turkish commercial and tax law requires, then deleted.
- Support tickets: a ticket's subject, its messages and the reference of the person who opened it are deleted 90 days after it is closed, leaving only its reference, organization, category, dates and number of messages.
- License-key emails: the recipient's email address and the key are deleted from our database as soon as the email has been sent, or when we stop retrying if sending keeps failing, and the rest of the sending record 30 days later. Resend, which sends the email, keeps its own log of sent emails, recipient included, for 30 days.
- Usage counts: the daily usage totals hold no person and no organization, so we keep them while they are useful and review that every year.
Deletion runs automatically every day, and each run is logged without the deleted data. Deleted data leaves our backups within 35 days.
A legal hold can pause deletion for one organization while a dispute or an authority's request about it is open; deletion resumes when the hold is lifted.
We answer requests about your personal data within 30 days.
8. Security controls
- HTTPS required for all outbound traffic
- Read-only Azure DevOps scopes: the Extension cannot modify work items, pipelines, or repository content
- License activation tokens are bearer credentials and are not logged
- Licenses are signed by the licensing service and checked every time Agile Gauge opens: not just a client-side screen
9. Your rights and choices
You can:
- ask what we hold about you, or ask for it to be corrected or deleted, by emailing support
- have the seat assigned to you removed by your organization's Agile Gauge admin
- uninstall the Extension; this removes it from your Azure DevOps organization. License records are kept for the periods above
10. Contact
- Email: [email protected]
- Company: Alesta Software
- See our support page and the İletişim / Contact page for our registered company details
11. Data protection rights (GDPR / CCPA)
If you are in the EU/EEA, UK, or California, you have rights under GDPR, UK GDPR, and CCPA, including access, rectification, erasure, restriction, portability, and objection. Most of these can be exercised by uninstalling the Extension or emailing support for deletion of any Alesta Software-held license record. Alesta Software responds to verified requests within 30 days as required by applicable law.