Legal & Trust

Data Processing Agreement

Last updated: 31 July 2026

Working draft. TaskForce is pre-launch. This document is provided for transparency and is pending final legal review — it is not yet a binding agreement. Questions? hello@taskforce.dev

When you use TaskForce to process personal data about your own users or team, you are the controller and TaskForce is a processor acting on your instructions. This page summarizes the terms; a signable Data Processing Agreement is available to customers on request.

Roles & scope

We process personal data only to provide the Service and on your documented instructions. We don't use it for our own purposes, and we don't sell it.

Security

We apply technical and organizational measures appropriate to the risk — encryption in transit and at rest, access controls, and tested infrastructure. Details are on the Trust Center.

Subprocessors

We use the subprocessors listed on our subprocessors page, each bound by equivalent data-protection obligations. We'll give notice of changes so you can object. On a self-hosted deployment with local models, no third-party subprocessor need handle your data.

Your rights & data-subject requests

We help you meet data-subject requests and your own GDPR obligations. On termination, we delete or return personal data as you instruct, subject to any legal retention.

International transfers

Where processing occurs outside your region, we rely on appropriate safeguards such as the EU Standard Contractual Clauses. Our hosting is in the EU (Hetzner, Germany). Self-hosting keeps data in a region you choose.

Request a DPA

To sign a DPA (available to customers on request), contact hello@taskforce.dev. Final terms are pending legal review.


Questions about this document? Write to hello@taskforce.dev.