Data Processing Agreement
Last updated August 22, 2026.
Overview
This page summarises how Taskzin processes the personal data you upload, enter, import, connect, or otherwise process through the Taskzin platform.
When you use Taskzin, you are generally the controller of the data you provide through the platform, including user information, team-member information, tasks, projects, comments, attachments, activity records, workspace information, and related business data. Taskzin processes this information on your behalf as your data processor.
This Data Processing Agreement (“DPA”) forms part of the Taskzin Terms of Service.
Customers who require additional information or a signed DPA can contact us through our general support or legal channel.
Our Commitments
We process your data only according to your instructions and as necessary to provide, maintain, secure, and improve the Taskzin services you have configured.
We do not sell your workspace data, task information, project information, team-member information, files, communications, or other customer-controlled personal data.
Security
We apply appropriate technical and organisational measures designed to protect your information, including:
- Encryption in transit
- Protection of sensitive credentials
- Account and workspace isolation
- Role-based access controls
- Authentication controls
- Session and access management
- Monitoring and security logging
- Infrastructure protection
- Vulnerability management
- Regular security testing
- Backup and recovery measures
- Protection against unauthorised access, alteration, disclosure, or destruction
Sub-processors
Taskzin may use trusted third-party service providers to help operate, maintain, secure, and support the platform.
These providers may support areas such as:
- Cloud hosting
- Databases
- File storage
- Authentication
- Email and notification delivery
- Payment processing
- Monitoring
- Analytics
- Customer support
- Security
- Backup services
- Integrations
- Infrastructure management
We require providers that process customer information on our behalf to follow appropriate confidentiality, security, and data-protection obligations.
Where required by applicable law or contractual commitments, we will provide reasonable notice before material changes to sub-processors that process customer personal data.
International Transfers
Taskzin and its service providers may process information in different countries or regions.
Where personal data is transferred internationally, we take reasonable steps to use appropriate safeguards required by applicable data-protection laws.
These safeguards may include:
- Contractual data-protection obligations
- Data Processing Agreements
- Standard Contractual Clauses
- Approved transfer mechanisms
- Other legally recognised safeguards
User and Workspace Data
When you create or manage a Taskzin account or workspace, we may process information such as:
- User names
- Email addresses
- Profile information
- User roles
- Workspace information
- Organisation or company information
- Login and authentication information
- Account preferences
- Membership information
- Permission settings
- Account activity
- Device and session information
This information is processed to provide account management, authentication, collaboration, security, and administrative functionality.
Task and Project Data
When you use Taskzin to organise work, projects, or activities, we may process information such as:
- Task names
- Task descriptions
- Project information
- Assigned users
- Due dates
- Priorities
- Status information
- Labels and categories
- Subtasks
- Checklists
- Comments
- Notes
- Work updates
- Activity history
- Time-related information
- Attachments
- Uploaded files
- Custom fields
- Project milestones
- Workspace records
You determine what information is entered into Taskzin and remain responsible for determining the purpose and lawful basis for processing that information.
Collaboration and Communication Data
Where Taskzin provides collaboration or communication functionality, we may process information such as:
- Comments
- Mentions
- Internal messages
- Notifications
- Task discussions
- Project discussions
- User activity
- File-sharing activity
- Assignment information
- Status updates
This information is processed to provide collaboration, communication, notification, and activity-tracking functionality.
Connected Services
If you connect Taskzin to another supported application or service, we process only the information reasonably necessary to provide the functionality you authorise.
Depending on the integration, this may include:
- Account identifiers
- User information
- Authorisation credentials or tokens
- Workspace information
- Calendar information
- Tasks
- Projects
- Files
- Notifications
- Integration configuration
- Activity information
We do not sell information obtained through connected services for advertising purposes.
You may disconnect supported integrations through the available account or workspace settings where applicable.
Files and Attachments
Taskzin may allow users to upload or attach documents, images, files, or other materials to tasks, projects, comments, or workspaces.
We process these files only as necessary to:
- Store the files
- Make them available to authorised users
- Provide collaboration functionality
- Maintain backups
- Protect platform security
- Provide requested platform features
Customers are responsible for ensuring that files uploaded to Taskzin are lawful and appropriate for processing through the platform.
Notifications
Taskzin may process contact and account information to provide service-related notifications, including:
- Task assignments
- Due-date reminders
- Project updates
- Mentions
- Comments
- Workspace invitations
- Security notifications
- Account notifications
- Administrative messages
Notification preferences may be configurable depending on the functionality available within the platform.
Usage and Activity Information
Taskzin may process technical and activity information necessary to operate, secure, monitor, and improve the service.
This may include:
- Login activity
- User actions
- Task activity
- Project activity
- Workspace activity
- IP address
- Device information
- Browser information
- Session information
- Error logs
- Security logs
- Performance information
- Feature usage information
Where this information relates to identifiable users, it will be handled according to applicable privacy and data-protection requirements.
Data-Subject Requests
We provide reasonable assistance when customers need to respond to requests from individuals whose personal information is processed through Taskzin.
These requests may include:
- Access
- Correction
- Deletion
- Restriction
- Portability
- Objection
Where required and technically feasible, Taskzin will assist customers in responding to these requests within applicable legal timeframes.
Customers remain responsible for determining whether a request is valid and for responding to the individual as the relevant data controller.
Breach Notification
If Taskzin becomes aware of a confirmed personal-data breach affecting customer-controlled information, we will notify affected customers without undue delay where required by applicable law.
Where reasonably available, we will provide information necessary to help affected customers understand the incident and meet their own legal obligations.
Information may include:
- The nature of the incident
- Categories of information affected
- Known or reasonably anticipated impact
- Measures taken or planned in response
- Recommended actions where appropriate
Confidentiality
Personnel authorised to access or process customer information are subject to appropriate confidentiality obligations.
Access to customer-controlled information is restricted according to legitimate operational requirements and appropriate access controls.
Taskzin personnel should only access customer-controlled information where reasonably necessary for purposes such as:
- Providing customer support
- Investigating technical issues
- Maintaining platform security
- Preventing abuse
- Complying with legal obligations
- Maintaining or improving authorised platform functionality
Access Controls
Taskzin may provide workspace administrators with functionality to manage access to workspace information.
Depending on the applicable subscription plan and available features, controls may include:
- User roles
- Workspace permissions
- Project permissions
- Task permissions
- Administrative privileges
- Membership controls
Customers are responsible for assigning appropriate permissions to their users and protecting administrator accounts.
Data Retention
Taskzin retains customer-controlled personal data for as long as reasonably necessary to provide the service or fulfil legitimate legal, security, contractual, or operational requirements.
Retention periods may vary depending on:
- The type of information
- Account status
- Workspace configuration
- Applicable laws
- Security requirements
- Backup procedures
- Fraud-prevention requirements
- Financial obligations
- Dispute-resolution requirements
Return & Deletion
When your Taskzin account or service agreement ends, you should export any information you wish to retain where export functionality is available.
After termination, Taskzin will delete or anonymize customer-controlled personal data according to applicable retention procedures, except where information must be retained for legitimate purposes such as:
- Legal obligations
- Security
- Financial records
- Fraud prevention
- Dispute resolution
- Enforcement of agreements
- Backup and disaster recovery
Information stored in backups may remain temporarily until those backups are securely overwritten or expire according to normal backup-retention procedures.
Sensitive Data
Taskzin is a general task, project, productivity, and work-management platform.
Unless Taskzin specifically states otherwise, customers should avoid storing highly sensitive, regulated, or special-category personal information unless they are legally authorised to process that information and have independently determined that Taskzin is appropriate for the intended use.
Examples include:
- Medical or health information
- Government identification documents
- Biometric information
- Complete payment-card information
- Bank-account credentials
- Financial account credentials
- Passwords for unrelated third-party services
- Highly sensitive authentication credentials
- Criminal-record information
- Special-category personal information
- Other information subject to heightened legal protections
Customers remain responsible for determining whether information entered into Taskzin is appropriate for processing through the platform.
Customer Responsibilities
As the controller of information processed through Taskzin, you are responsible for:
- Having an appropriate lawful basis for processing personal information
- Collecting personal information lawfully
- Providing required privacy notices
- Obtaining consent where required
- Ensuring users are authorised to access workspace information
- Managing account and workspace permissions
- Removing access when users no longer require it
- Protecting account credentials
- Maintaining appropriate data-retention practices
- Responding to applicable data-subject requests
- Ensuring uploaded files and information are lawful
- Configuring integrations appropriately
- Ensuring your use of Taskzin complies with applicable privacy, employment, communications, and data-protection laws
- Avoiding unnecessary collection of sensitive personal information
Compliance
Taskzin will take reasonable steps to process customer-controlled personal data in accordance with applicable data-protection requirements relevant to its role as a data processor.
Customers remain responsible for identifying the laws and regulatory requirements that apply to their specific organisation, industry, users, employees, projects, and use of Taskzin.
Nothing in this DPA should be interpreted as legal advice or as a guarantee that use of Taskzin automatically makes a customer compliant with any particular law or regulation.
Changes to This DPA
We may update this Data Processing Agreement from time to time to reflect:
- Changes to Taskzin services
- Changes to our infrastructure or service providers
- Security improvements
- Operational changes
- Changes in applicable laws or regulatory requirements
Where appropriate, the updated version will be published with a revised “Last updated” date.
Material changes may also be communicated through reasonable channels where required.
Contact
For questions about data processing, privacy, legal requests, security, sub-processors, or obtaining a signed DPA, contact:
Questions about this document? Get in touch — a human will answer.
Your team already has the work. Give it a home.
Set up a workspace in under two minutes. Import from ClickUp, Jira, Asana or Trello in one click.
No credit card • Free 14 days • Cancel anytime