Taskora Data Processing Agreement
Last updated: 29 September 2026
Between: you (the "Customer") and Taskora Ltd, a company incorporated in England and Wales (company number 16736403), whose registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("Taskora", "we" or "us").
In plain English. Taskora is a work management service — workspaces, boards, projects, sprints, tasks and comments. When your organisation uses it, some of what sits in your workspaces is personal data: your members' names and email addresses, and anything your team writes that identifies a person. You decide what goes in. You are the controller. We process that data for you, on your instructions. This Data Processing Agreement ("DPA") sets the rules for that relationship, in the form Article 28 of the UK GDPR requires. Where the EU GDPR applies to you instead, this agreement works under that law as well.
1. Definitions
- Customer Personal Data — personal data that we process for you through the Services.
- Data Protection Laws — the UK GDPR and the Data Protection Act 2018, as amended from time to time (including by the Data (Use and Access) Act 2025), and where EU law applies to you, the EU GDPR.
- Services — the Taskora work management app at taskora.ai: workspaces, boards, projects, sprints, tasks and comments, as described in the Terms of Use.
- Subprocessor — any business we use to help us process Customer Personal Data.
- Standard Contractual Clauses (SCCs) — the European Commission's standard contractual clauses (Decision 2021/914), Module Two (controller to processor) and Module Three (processor to processor).
- UK Addendum — the UK International Data Transfer Addendum (version B1.0) issued by the Information Commissioner's Office, which adapts the SCCs for transfers regulated by UK law.
- Terms of Use — the Taskora Terms of Use, as updated from time to time.
"Controller", "processor", "personal data", "processing" and "data subject" carry the meanings Data Protection Laws give them.
2. How this DPA applies
This DPA applies to every customer who uses the Services for a workspace, whether you are a business or an individual. If you create a workspace and invite members, you are the controller of their personal data, and Article 28 requires a written contract for that. This is it. You accept it when you accept the Terms of Use — in practice, when you sign up or first use the Services for your organisation. No separate signature is needed.
- When you accept, you confirm you are authorised to contract for the organisation you act for, if you act for one. The account owner who accepts is the signatory we rely on.
- This DPA forms part of the Terms of Use. If the Terms of Use and this DPA disagree about the processing of personal data, this DPA wins.
- Where the SCCs or the UK Addendum apply to a transfer (Annex III), they take priority over this DPA.
- If you need a countersigned copy — because your own customer or a regulator asks for one — email privacy@taskora.ai and we will return one. This is the normal route for business customers, not something you have to know to ask for. If we countersign a version for you, that version governs, and we record it on your account.
3. Our roles
- You are the controller of Customer Personal Data. You decide what goes into your workspaces and the purposes it serves.
- We are your processor. We act on your behalf, not for our own purposes.
- If you are a processor acting for another controller, we act as your subprocessor. You promise that the controller you act for has authorised your instructions to us.
- One exception: if you email our support team, that correspondence is our own record and we act as its controller under our privacy policy. This DPA covers what you and your members put into the Services.
- Each of us meets its own obligations under Data Protection Laws.
4. Scope
- Subject matter: personal data that you and your workspace members put into the Services, or that the Services generate about their use of it.
- Duration: the life of your account, plus the deletion period in section 11.
- Nature and purpose: hosting, storing, transmitting and displaying your data. Running, securing, updating, monitoring and supporting the Services. Handling your requests. Meeting our legal duties.
- Annex I lists the categories of personal data and the people it covers.
5. Your instructions
We process Customer Personal Data only on your documented instructions. Your instructions are, exhaustively:
- provide the Services as described in the Terms of Use and this DPA, for the purposes in section 4
- act on what you and your members do in the product — the features and settings you use
- anything else you instruct in writing.
New processing outside these needs new written instructions or an update under section 14.
- We do not process your data for our own purposes. We do not sell it, share it with advertisers, or use it to train machine-learning models.
- If, in our opinion, an instruction from you infringes Data Protection Laws, we will tell you without undue delay. We may suspend the affected processing until the instruction is confirmed, amended or withdrawn, and we will not be liable for doing so. We will not take a step that would put us in breach of Data Protection Laws.
- Where the law requires us to process differently — for example a binding order from a court or regulator — we will do only what the law requires. Unless the law forbids it, we will tell you before we comply.
6. Confidentiality
Everyone at Taskora and its subprocessors who can access Customer Personal Data is bound by confidentiality, is given access only where their work needs it, keeps those duties after they leave, and loses access as soon as they no longer need it.
7. Security
We use appropriate technical and organisational measures, judged against the risk and the state of the art (Article 32 UK GDPR). What that means today:
- Data is encrypted in transit (TLS) and encrypted at rest by the managed infrastructure we rely on — including Supabase's managed authentication, database and file storage, hosted in AWS eu-central-1 (Frankfurt, Germany).
- Access follows need-to-know. Access to production systems is limited, granted per role, and removed when someone no longer needs it.
- We log system and sign-in events, and review them when investigating problems. A monitoring provider helps us do this (Annex II, New Relic).
- We have an incident process. We investigate, fix, and report as section 10 sets out.
- We do not hold certifications such as ISO 27001 or SOC 2 today. We will not claim one before we have it. The platforms we rely on publish their own certifications — those are theirs, not ours.
- No online service is perfectly secure. We review these measures as the Services and the risks develop.
8. Subprocessors
Annex II lists them. You authorise us to use them.
- You give us general authorisation to use the subprocessors in Annex II, and others that meet this section's rules as the Services develop.
- Before we add or replace a subprocessor, we will tell you at least 30 days in advance, by email or in the product.
- You may object on reasonable data-protection grounds within 10 business days of our notice. We will work with you in good faith — for example, by changing how the subprocessor is used. If we cannot resolve your objection, you may stop the affected part of the Services or close your account early, and we will refund prepaid fees for the unused term.
- Before a subprocessor touches your data, we put a written contract in place that binds it to protect Customer Personal Data to the standard this DPA applies, so far as the law requires. We stay responsible for what our subprocessors do.
- Annex II is complete and accurate as at the date of this DPA. If we discover it is not, we will correct it and tell affected customers within 5 business days.
- AI assistance. Our AI features are built with Mistral AI, a European AI company, and are currently switched off for every account: no request reaches the provider, and no Customer Personal Data is sent to it. When we switch the features on, Mistral AI joins Annex II through this section — 30 days' notice, same flow-down. Any other AI provider joins the same way.
9. Helping you and your data subjects
Requests from your data subjects. The Services are built so you can handle most requests yourself: workspace content can be accessed and deleted from within the product, and exported through any export tools the product provides. Your data subjects should ask you first, and you can answer without us. If you cannot handle a request with the tools available, write to privacy@taskora.ai and we will assist, taking into account the nature of the processing and the information we hold. If someone asks us directly, we will redirect them to you, as far as we can tell whose data it is.
Impact assessments and regulators. On your written request, we will give reasonable assistance with data protection impact assessments, prior consultations, and contacts with the UK supervisory authority — the Information Commissioner's Office, renamed the Information Commission on 30 September 2026 — or another regulator. Again, taking into account the nature of the processing.
10. Personal data breaches
We will tell you without undue delay once we become aware that a personal data breach has affected Customer Personal Data. Our target is 48 hours from awareness.
- "Aware" means the point at which we know, or reasonably should know. That includes anything a subprocessor tells us, and anything our or their monitoring would have identified with reasonable diligence. We will pass on a subprocessor's breach notification within 48 hours of our awareness of it.
- We will give you what we know: what happened, the categories and approximate numbers of people and records involved, the likely consequences, and the measures we have taken or plan to take (the Article 33(3) information). We will update you as we learn more. That is the information you need to meet your own duty to report.
- Routine failed sign-in attempts and network scans are security events, not breaches. Only events that actually compromise Customer Personal Data are reported as breaches.
- We keep a record of breaches and what we did about them.
- We will not name you publicly in connection with a breach without asking you first.
11. Deleting or returning your data
One timeline, here and in our privacy policy and Terms of Use:
- While your account is open, you can export your data yourself through any export tools the Services provide, or ask us and we will help within a reasonable time.
- When your account closes, you can keep exporting for 30 days, or ask us to return your data in a standard format instead.
- After that window closes, we delete Customer Personal Data from the live systems within 30 days — so within 60 days of closure at the outside.
- Backups run on a rolling cycle of no more than 35 days. Anything deleted is gone from every backup within 35 days of its deletion, and we do not restore deleted data from a backup except to recover the live service.
- If the law makes us keep something — tax records, or evidence needed to defend a claim — we keep the minimum, protect it, do not process it for anything else, and delete it when the reason ends.
- This DPA stays in force until deletion under this section is complete.
12. Audits and information
- We keep the records a processor must keep: what we process, for whom, where, our subprocessors, and our transfers.
- You may ask us for information, documents, and answers to reasonable questionnaires to check we are meeting this DPA. We will respond within 30 days. You may do this once every 12 months — and more often, without counting against that, if a breach has occurred, a regulator requires it, you must comply with your own obligations to your controller or a supervisory authority, or you must pass an audit through under the SCCs or the UK Addendum.
- On your written request we will also allow an audit or inspection of the records and systems relevant to this DPA — reasonable prior notice, at your cost, no more than once every 12 months (more often after a breach or if a regulator requires it), on terms that protect other customers' data and our security.
- Each year, on request, we will send you a short written summary of our controls: transport encryption, encryption at rest, our access model, logging, and the incident process. It is a summary of what section 7 says — not a certification, and we have none of our own to offer today. When that changes, we will say so and make reports available.
13. International transfers
- Where your data sits. Your workspace content, file attachments and authentication records are stored in Frankfurt, Germany: Supabase runs the database, authentication and file storage in AWS eu-central-1. The application layer — the servers, queues and cache that run the product — sits on Northflank's platform in its Frankfurt region, so it stays in the EU next to your data. Cloudflare's network is global and operated by a US company, so traffic and security metadata — most often IP addresses — may be processed outside the UK and EEA, including in the US.
- The mechanism. Where processing involves a country outside the UK (or, for you in the EEA, outside the EEA), the transfer happens under the UK Addendum (version B1.0) to the SCCs — Module Two, and Module Three where you are a processor. This is the single mechanism this DPA uses, and Annex III completes it. For customers in the EEA, the SCCs (Modules Two and Three) apply directly to transfers out of the EEA; transfers from you to us in the UK need no separate mechanism today because the UK is covered by the EU's adequacy decision.
- The SCCs and the UK Addendum are incorporated into this DPA by reference. They take effect when this DPA does, and they prevail over it where they conflict. Annex III sets out who transfers where, and under which instrument.
- We make sure every subprocessor is covered — by UK adequacy, or by the UK Addendum or the SCCs (its own agreement or ours) — before it receives Customer Personal Data. Where a subprocessor relies on the EU-US Data Privacy Framework and its UK Extension instead, the SCCs and the UK Addendum stand as the automatic fallback.
- Government access. If a public authority demands your data, we will do what the law requires and nothing more. We will challenge requests we believe are unlawful or disproportionate, disclose the minimum the law allows, and tell you about the request unless the law forbids it. This applies to us and, so far as we can influence it, to every subprocessor, under Clause 14 of the SCCs where it applies.
- The ICO keeps the approved Addendum under review following the Data (Use and Access) Act 2025. If it issues a new approved version, we move to it within the transition period the ICO sets.
14. Records, co-operation and general terms
- Records and co-operation. We keep the records section 12 describes, and each of us gives the other reasonable help to meet Data Protection Laws.
- Notices. Notices about this DPA, countersigned-copy requests, data-protection questions and anything else legal go to privacy@taskora.ai. General contact stays hello@taskora.ai. Notices to you go to the email address on your account, or by in-product notice.
- Changes. We may update this DPA as the Services develop — new subprocessors, new features. Subprocessor changes follow section 8. Any other change that would materially reduce your protections takes effect only with your written consent. If you do not consent, you may end the DPA and the Terms of Use without penalty within 30 days of our notice, and we will refund prepaid fees for the unused term. The date and version at the top of this document change when we do.
- Liability. Liability between us follows the Terms of Use, except that nothing in the Terms of Use — including any cap — limits or excludes liability for a breach of this DPA or of the SCCs or the UK Addendum incorporated in it. Where the SCCs or the UK Addendum apply, their liability terms prevail. Nothing we agree limits the rights data subjects have under Article 82 of the UK GDPR, or either party's right to recover from the other the share of compensation matching its responsibility for the damage.
- Assignment. Neither party may transfer this DPA without the other's consent, except that we may pass it to a buyer of our business, with notice to you, and the buyer must honour it.
- Counterparts and severability. This DPA may be accepted in paper or electronic form. If a clause is unenforceable, the rest stands, and we will replace it with something lawful that comes closest to what it meant.
- Law and courts. This DPA is governed by the law of England and Wales, and disputes go to the courts of England and Wales — the same as the Terms of Use.
Annex I — Details of the processing
Subject matter. Personal data that customers and their workspace members put into the Services, or that the Services generate about their use of it.
Duration. The life of the Customer's account, plus the deletion period in section 11.
Nature and purpose. Hosting, storing, transmitting and displaying data. Running, securing, updating, monitoring and supporting the Services. Handling requests. Meeting legal duties.
Categories of data subjects.
- Customer workspace members (the users you invite and administer)
- People invited to a workspace who have not yet joined
- Any other individual whose details you or your members choose to include in workspace content — for example, a person named in a task
Categories of personal data.
- Account and profile data — name, email address, profile settings, authentication records such as magic-link and sign-in events
- Workspace content — boards, projects, sprints, tasks, comments, documents and other content users create, including file attachments
- Invitation data — names and email addresses of invitees, and invitation status
- Usage and security data — IP addresses and other network details, device and browser information, service and monitoring logs, timestamps, kept only as long as needed to run and protect the Services
- Billing records — paid plans begin on 1 November 2026 and the payment processor is still to be determined. Card details will go directly to the processor and never reach us. From the processor we will receive only the account details needed to run the subscription (confirmed when the processor is appointed); we keep our own accounting records as controller.
Special-category data. We do not ask for it, and the product is not designed for it. If a user types it into content, it sits there under your control and your instructions.
Annex II — Subprocessors
Current at 29 September 2026. We keep this list current. Each provider's own published list governs its chain, and we review those lists when we appoint and on a regular basis.
| Provider | What it does | Where |
|---|
| Supabase Pte. Ltd. (Singapore) | Authentication, the managed Postgres database and file storage for the Services | Your data is hosted in AWS eu-central-1 (Frankfurt, Germany). The contracting entity is Singaporean, and its published list includes support access from outside the UK and EEA, including the US. Covered by Annex III. |
| Northflank Ltd (20-22 Wenlock Road, London, UK) | Runs the application — web servers, job queues and the Redis data store | The europe-west-frankfurt region on Northflank's managed platform — Frankfurt, Germany, in the EU. Covered by Annex III. |
| Cloudflare, Inc. (US) | CDN, web application firewall, bot management and DDoS protection in front of the Services | Global edge network, including the US. Processes traffic and security metadata, most often IP addresses. Covered by Annex III. |
| New Relic, Inc. (US company) | Application monitoring, error tracking and log management | EU data region: receives service logs and request metadata, which can include IP addresses, and stores them in its EU data centre. Some of its own operational and account data is kept in the US, covered by its DPA (SCCs, Modules Two and Three, plus the UK Addendum) and its certification under the EU-US Data Privacy Framework and its UK Extension. |
| Resend (Plus Five Five, Inc., US) | Transactional email: magic-link sign-ins and workspace invitations | US service. Receives email addresses and the minimum needed to deliver each message. Its own DPA gives the SCCs and the UK Addendum, and it is certified under the EU-US Data Privacy Framework and its UK Extension. |
Our AI assistance is built with Mistral AI SAS (France, EU). It is currently switched off for every account and receives no Customer Personal Data. It joins this table through section 8's notice when we switch it on. Any new subprocessor joins the same way, before it touches Customer Personal Data. Payments are different and still to be determined: paid plans begin on 1 November 2026, and the payment processor we appoint will be an independent controller of checkout and payment data under its own privacy policy — not our subprocessor. It will be disclosed to customers before it processes any payment data.
Annex III — International transfers
This annex says where personal data may go outside the UK (and, for EEA customers, outside the EEA), and what protects it. The operative mechanism, incorporated by reference into this DPA, is the UK Addendum (version B1.0) to the EU Standard Contractual Clauses — Module Two (controller to processor), and Module Three (processor to processor) where you are a processor. Where you are in the EEA, the SCCs (Modules Two and Three) apply directly to transfers out of the EEA.
How the instruments are completed:
- SCC Annex I.A (parties). Exporter: you, the Customer. Importer: Taskora Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Contact: the account owner for you, privacy@taskora.ai for us. Roles follow section 3 of this DPA.
- SCC Annex I.B (description of the transfer). Subject matter, duration, nature, purpose and categories: as Annex I of this DPA. Frequency: continuous, for the life of the account and the deletion period after it. Transfers to subprocessors: as Annex II of this DPA. Retention: as section 11 of this DPA.
- SCC Annex I.C (competent supervisory authority). The Information Commissioner's Office (renamed the Information Commission on 30 September 2026) for UK transfers, or — for an EEA customer — the supervisory authority in your member state.
- SCC Annex II (technical and organisational measures). The measures in section 7 of this DPA.
- SCC Clause 9 (subprocessors). Option 2 — general authorisation with notice, matching section 8.
- SCC Clause 14 (local laws and government access). For subprocessors in the US, we have reviewed their published data processing agreements and government-access policies, and we are not aware of local laws that stop them honouring the SCCs. Their own agreements govern their legs, and our flow-down binds them.
- SCC Clause 15 (docking). Not used. No other entity joins the SCCs through this DPA.
- Clause 17 (governing law), Clause 18 (forum) and Addendum Table 2. The law of England and Wales, and the courts of England and Wales (SCC Clause 17, Option 2 — the UK is covered by the EU's adequacy decision). If that adequacy ever lapses, the law and courts of Ireland apply instead. This does not change the law that governs the rest of this DPA (section 14).
- Addendum Table 1 (parties). As SCC Annex I.A, with a start date of 29 September 2026.
- Addendum Table 3 (third-party rights). The Addendum's default: data subjects keep their third-party rights under Clause 3 of the SCCs as the Addendum amends it.
- Addendum Table 4 (ending). The Addendum ends when the ICO's rules say it ends — neither party may end it early on notice alone.
Where transfers actually happen today:
- Supabase Pte. Ltd. (Singapore). Your database, authentication records and file attachments sit in AWS eu-central-1 (Frankfurt, Germany). But the contracting entity is Singaporean, and access for support and administration can come from outside the UK and EEA, including the US, per Supabase's published list. Those accesses are restricted transfers, protected by Supabase's own DPA (which incorporates the SCCs, Modules Two and Three, and the UK Addendum) and by our flow-down under section 13.
- Northflank Ltd (UK). Northflank is a UK company, and our application layer runs in its europe-west-frankfurt region — Frankfurt, Germany, in the EEA. For UK customers, the UK's adequacy designation for the EEA covers that processing; for EEA customers it is in-region. Northflank's own published list governs its chain.
- Cloudflare, Inc. (US). Cloudflare's edge network processes traffic and security metadata — most often IP addresses — in US and European data centres. Its own DPA gives the SCCs (Modules Two and Three), the UK Addendum and the Swiss safeguard amendments, with Data Privacy Framework certification as its primary mechanism and the SCCs as an automatic fallback. We rely on Cloudflare's DPA, procured through our flow-down under section 13.
- New Relic, Inc. (US). Receives our service logs and request metadata, which can include IP addresses, and stores them in its EU data region. New Relic keeps some of its own operational and account data in the US; that transfer is covered by its own DPA (the SCCs, Modules Two and Three, and the UK Addendum) and its certification under the EU-US Data Privacy Framework and its UK Extension, with the SCCs as automatic fallback if that certification ever fails.
- Resend (Plus Five Five, Inc., US). Sends our magic-link and invitation emails. Its primary processing is in the US. Its own DPA gives the SCCs (Modules One to Three) and the UK Addendum, and it is certified under the EU-US Data Privacy Framework and its UK Extension.
- Payment processor (to be determined). Paid plans begin on 1 November 2026; the processor we appoint will be an independent controller of checkout and payment data, that data will never reach us, and it will be disclosed here with its transfer safeguards before it processes any payment data.