Data Processing Agreement

Updated June 16, 2026

Roles

For personal data you submit to the Service, you are the Controller and Taskspro is the Processor under the GDPR.

Scope of processing

We process personal data solely to provide the Service per your documented instructions. Categories: identifiers, account data, content you submit.

Security measures

Encryption at rest (AES-256) and in transit (TLS 1.3), least-privilege access, audit logging, vulnerability scanning, annual penetration testing.

Sub-processors

A current list is published at /legal/subprocessors with 14 days' notice before adding new entities.

International transfers

Standard Contractual Clauses (SCCs) are in place for transfers outside the EEA. Supplementary measures are documented in our TIA.

Data subject requests

We assist you in responding within statutory timelines via self-serve tooling in account settings or by email at dpo@taskspro.ai.

Audit rights

You may request our SOC 2 Type II report and annual penetration test summary under NDA.

Breach notification

We notify affected customers within 72 hours of confirming a personal data breach, with details and remediation plan.

Term & termination

This DPA is effective for the duration of the master agreement. On termination, personal data is deleted within 30 days or returned at your request.