Scope and roles
This Data Processing Agreement (“DPA”) is part of the Terms of Service between Taskshire (“Provider”, “we”) and the organisation that owns a Taskshire workspace (“Customer”, “you”). It applies whenever you, as controller, put personal data about other people into the service and we process it on your instructions as processor, as required by Article 28 of the UK GDPR. It takes effect when you create a workspace; no signature is needed. If you need a countersigned copy, email privacy@taskshire.co.uk.
Terms such as personal data, controller, processor, data subject and personal data breach have the meanings in the UK GDPR and the Data Protection Act 2018. Our own use of account, billing and website data as a controller is covered by the Privacy Policy, not this DPA.
Details of the processing
- Subject matter
- Providing the Taskshire project management service to the Customer’s workspace.
- Duration
- While the workspace exists, plus the deletion periods below.
- Nature and purpose
- Storing, displaying, searching, notifying about, exporting and backing up the Customer’s projects; sending email and chat notices; running integrations and AI features the Customer turns on.
- Types of personal data
- Names, email addresses, avatars and role information; the content of tasks, comments, documents, time entries and uploaded files, which may contain whatever the Customer’s users write; request-form submissions from the public; activity logs.
- Data subjects
- The Customer’s employees and contractors; its clients and approvers invited by link; people who submit its request forms; anyone mentioned in its project content.
- Special category data
- Not intended. The Customer must not put health, biometric, criminal or similar data into the service without agreeing extra safeguards with us first.
Our obligations as processor
- Instructions. We process personal data only on your documented instructions, which are these terms, the features you use and the settings you choose. We will tell you if we think an instruction breaks data protection law.
- Confidentiality. Only people who need production access to run the service have it, and they are bound by confidentiality.
- Security. We apply the measures on the Security page (Annex 2 for the purposes of this DPA): encryption in transit, encrypted secrets at rest, hashed passwords, two-step sign-in, role-based access, audit logging and rate limiting.
- Sub-processors. We use only the sub-processors listed below, each under a written contract with equivalent obligations. We remain responsible for them.
- Data subject requests. The service lets you export, correct and delete data yourself. If a data subject contacts us directly about your workspace, we will pass the request to you and help you respond.
- Assistance. We will give reasonable help with your security, breach-notification, impact-assessment and regulator obligations, taking into account what we know.
- Breach notification. We will tell the workspace owner about a personal data breach affecting your data without undue delay and no later than 72 hours after we become aware of it, with what we know at the time and updates as we learn more.
- Deletion. At the end of the service we delete or return the data as described below.
- Information. We will make available the information needed to show we meet Article 28, as described under Information and audits.
Sub-processors
Current as of 11 October 2026. We will update this page and email workspace owners at least 30 days before adding or replacing a sub-processor that handles workspace content. If you object on reasonable data-protection grounds and we cannot resolve it, you may delete the workspace and we will refund any prepaid period that remains.
| Sub-processor | Purpose | Location | When it processes your data |
|---|---|---|---|
| [hosting provider] | Hosting, database, file storage, queues and backups | United Kingdom | Always |
| Resend | Sending email (notices, invitations, verification, support replies) | United States | Always |
| Stripe | Payments, invoices and the customer billing portal | Ireland and United States | When the workspace subscribes to Town Planner (owner’s billing details only) |
| Anthropic | AI assistant features (Claude API). No training on your data under its commercial terms. | United States | Only when the workspace owner turns AI features on, and only the text a user asks it to work on |
| Slack | Notices, slash commands and account linking | United States | When the workspace connects Slack |
| Discord | Notices and commands | United States | When the workspace connects Discord |
| Sign in with Google; Google Chat notices; Google Drive import; YouTube publishing | United States | When a user signs in with Google or the workspace connects one of these | |
| Microsoft | Sign in with Microsoft; Microsoft Teams notices | United States and EU | When a user signs in with Microsoft or the workspace connects Teams |
Services you connect for your own purposes, such as X, LinkedIn, Meta, TikTok, Zapier, Make or any webhook endpoint, receive the data you choose to send them. They are independent recipients chosen by you, not our sub-processors.
International transfers
Workspace content is stored in United Kingdom. Where a sub-processor above processes data outside the UK, the transfer is covered by the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the UK–US Data Bridge where the recipient is certified, together with the recipient’s own security commitments. Details are available on request.
Return and deletion
- At any time a workspace owner can export the whole workspace (Workspace settings → Export) and each project’s tasks as CSV.
- A deleted project can be restored for 30 days, then is permanently purged by a daily job. Deleting a workspace deletes its projects the same way.
- Activity logs are deleted after 365 days. Backups expire on the rolling schedule set at our hosting provider (see Security), after which deleted data is gone from them too.
- We keep only what the law obliges us to keep (for example invoices), and only for that purpose.
Information and audits
On request, no more than once a year unless a regulator or a breach requires it, we will answer reasonable written questions about our processing and share the security information we hold. Where that is not enough to meet your legal obligations, you may audit us, or appoint an independent auditor bound by confidentiality to do so, at your cost, on 30 days’ notice, during working hours and without disrupting the service. We do not currently hold third-party certifications such as ISO 27001 or SOC 2 and will not claim to.
General
Liability under this DPA is subject to the limits in the Terms of Service. If this DPA conflicts with the Terms on a data-protection point, this DPA wins. We may update this DPA to reflect changes in the law or the service; material changes are notified to workspace owners in advance. It is governed by the law of England and Wales.
Contact
- Provider
- Taskshire
- Address
- [registered address]
- Privacy and data requests
- privacy@taskshire.co.uk
- Security reports
- security@taskshire.co.uk
- ICO registration
- [ICO registration number]
Signed in? You can also read the help centre or open a request from Help & support in the app.