Legal
Last updated: March 23, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between TaskAI (“Processor”, “we”, “us”) and the organization or individual using TaskAI services (“Controller”, “you”, “your”) for the processing of personal data in connection with the TaskAI platform.
“Personal Data” means any information relating to an identified or identifiable natural person, as defined under PIPEDA and applicable privacy legislation.
“Processing” means any operation performed on Personal Data, including collection, storage, retrieval, use, and deletion.
“Subprocessor” means any third party engaged by TaskAI to process Personal Data on behalf of the Controller.
“Data Breach” means any unauthorized access to, or disclosure of, Personal Data.
TaskAI processes Personal Data solely for the purpose of providing the TaskAI service, which includes:
| Category | Data Elements | Source |
|---|---|---|
| Identity | Name, email address, profile image URL | OAuth provider |
| Email metadata | Subject line, sender name/email, date, snippet | Microsoft Graph / Gmail API |
| Calendar metadata | Event title, start/end time, attendee names | Microsoft Graph / Google Calendar API |
| Project data | Jira issue keys/summaries, Confluence page titles | Atlassian REST API |
| User content | Tasks, projects, notes, workspace settings | User input |
TaskAI, as Processor, agrees to:
In the event of a Data Breach, TaskAI will:
TaskAI uses the following Subprocessors to deliver the service:
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting and edge deployment | United States |
| Turso (ChiselStrike) | Database hosting (libSQL) | United States |
| Stripe Inc. | Payment processing | United States |
| GitHub (Microsoft) | Source code hosting and CI/CD | United States |
TaskAI will notify the Controller of any intended changes to Subprocessors, providing the Controller with the opportunity to object.
TaskAI will assist the Controller in fulfilling data subject requests, including:
Personal Data is processed and stored in North America (primarily the United States and Canada). Where Personal Data is transferred outside the Controller's jurisdiction, TaskAI ensures appropriate safeguards are in place, including contractual obligations with Subprocessors that provide equivalent data protection.
This DPA is effective for the duration of the Controller's use of TaskAI services. Upon termination:
For questions about this DPA or to exercise data protection rights:
Security & Privacy Team
security@taskai.ca