Legal

Privacy Policy

Effective Date: July 9, 2026

At Managed Tasks (mtasks.io), we understand that trust is the foundation of professional services. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit our website, use our platform, or interact with our services.

This policy is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the CPRA, and the comprehensive data privacy laws of Virginia, Colorado, Texas, and other US states.

1. Our Dual Role: Controller vs. Processor

It is important to distinguish between the two ways we handle data:

  • As a Data Controller: When you visit our marketing website, create a tenant account, or pay for a subscription, we act as the Data Controller. This policy primarily applies to this data.
  • As a Data Processor: When you upload client data, tasks, files, or communications into your workspace, we process that data strictly on your behalf as a Data Processor. The Tenant is the Controller for that data. Our obligations as a Processor are governed by the Data Processing Agreement (DPA) executed during onboarding.

2. Information We Collect

We collect the following categories of information:

  • Account Information: Name, email address, organization name, and role when you create an account or are invited to a workspace.
  • Billing Information: Payment method details (processed and stored by Stripe; we never see or store full card numbers).
  • Usage Data: Pages visited, features used, session duration, and performance metrics (collected via privacy-respecting analytics with no third-party tracking pixels).
  • Device Information: Browser type, operating system, IP address (for security and rate limiting; truncated in logs after 30 days).
  • Communications: Support emails, feedback submissions, and in-app messages you send to us.

3. How We Use Your Information

We use personal information for the following purposes:

  • Providing, maintaining, and improving the Service (Legal Basis: Contract Performance).
  • Processing payments and managing subscriptions (Legal Basis: Contract Performance).
  • Sending transactional emails (password resets, workspace invitations, billing receipts) (Legal Basis: Contract Performance).
  • Sending product updates and marketing communications (only with your consent; unsubscribe at any time) (Legal Basis: Consent).
  • Detecting and preventing fraud, abuse, and security threats (Legal Basis: Legitimate Interest).
  • Maintaining immutable audit logs required by financial regulations and enforcing our Terms of Service (Legal Basis: Legal Obligation).

4. How We Share Your Information

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.

We share data only with trusted Subprocessors necessary to operate the Service:

  • Cloud Infrastructure: Microsoft Azure (hosting and database)
  • Payment Processing: Stripe
  • Email Delivery: Postmark (ActiveCampaign)
  • Error Tracking: Sentry
  • AI Features: OpenAI / Azure OpenAI (under zero-data-retention agreements; your data is never used to train their models)

All Subprocessors are bound by strict confidentiality and data protection obligations.

5. Your Privacy Rights (GDPR & US State Laws)

Depending on your jurisdiction (including the EU/EEA, UK, California, Virginia, Colorado, Texas, and other states with comprehensive privacy laws), you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion (Right to be Forgotten): Request deletion of your data. Note: due to strict financial auditing requirements, we fulfill deletion requests by permanently anonymizing your identity in our immutable audit logs (pseudonymization tombstoning) while destroying your profile data.
  • Portability: Receive your data in a structured, machine-readable format (JSON/CSV).
  • Objection/Restriction: Object to or restrict certain processing activities.
  • Appeal: Appeal our decision if we decline to take action on your request.

To exercise these rights: Email us at privacy@mtasks.io. We will respond within 30 days (or 45 days as permitted by specific US state laws). We honor Global Privacy Control (GPC) signals on our marketing website.

For Tenants: We provide a dedicated Data Subject Request (DSR) console within the platform to help you fulfill privacy requests from your own clients.

6. Data Security and Retention

We implement robust technical safeguards, including AES-256 encryption at rest, TLS 1.2+ in transit, and database-level tenant isolation. We retain your personal data only as long as necessary to provide the Service or comply with legal obligations. Upon account termination, you have a 30-day window to export your data, after which it is permanently deleted or anonymized in our backups.

7. International Data Transfers

Our primary servers are located in the United States via Microsoft Azure. If you are located in the EEA or UK, your data is transferred subject to appropriate safeguards, including Standard Contractual Clauses (SCCs) and adherence to the EU-U.S. Data Privacy Framework.

8. Children's Privacy

The Service is intended for B2B professional use. We do not knowingly collect personal information from children under 16.

9. Changes to This Policy

We may update this Privacy Policy to reflect changes in law or our practices. We will notify you of material changes via email or an in-app notice.

10. Contact Us

If you have questions about this policy or wish to exercise your rights, contact us at privacy@mtasks.io. If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local data protection supervisory authority.