Data Processing Agreement
Updated June 16, 2026
Roles
For personal data you submit to the Service, you are the Controller and Taskspro is the Processor under the GDPR.
Scope of processing
We process personal data solely to provide the Service per your documented instructions. Categories: identifiers, account data, content you submit.
Security measures
Encryption at rest (AES-256) and in transit (TLS 1.3), least-privilege access, audit logging, vulnerability scanning, annual penetration testing.
Sub-processors
A current list is published at /legal/subprocessors with 14 days' notice before adding new entities.
International transfers
Standard Contractual Clauses (SCCs) are in place for transfers outside the EEA. Supplementary measures are documented in our TIA.
Data subject requests
We assist you in responding within statutory timelines via self-serve tooling in account settings or by email at dpo@taskspro.ai.
Audit rights
You may request our SOC 2 Type II report and annual penetration test summary under NDA.
Breach notification
We notify affected customers within 72 hours of confirming a personal data breach, with details and remediation plan.
Term & termination
This DPA is effective for the duration of the master agreement. On termination, personal data is deleted within 30 days or returned at your request.