Data Processing Addendum

This Data Processing Addendum applies when a business customer uses Task Machine to process personal data on its behalf. It forms part of the Terms of Service or another agreement between the customer and Task Machine.

Version and last updated: 7 August 2026

Parties and effect

The customer that accepted the Terms or a written order is the Customer. Fabian Schucht, C. General Vives 1 6E, 35006 Las Palmas de Gran Canaria, Spain, NIE Z1096165J, is Task Machine. This Addendum takes effect when Customer uses the service to process Customer Personal Data and remains effective while Task Machine processes that data.

This Addendum supplements the Terms of Service. A separately signed data processing agreement controls if it expressly replaces this Addendum. If this Addendum conflicts with the Terms on protection of Customer Personal Data, this Addendum controls for that conflict.

Definitions

Customer Personal Data means personal data contained in workspace content, prompts, transcripts, files, connectors, workflows, support material, or other data Task Machine processes on Customer's behalf. Data Protection Law means the GDPR, applicable EEA or member-state data-protection law, the UK GDPR where applicable, and other mandatory privacy law governing the processing. Controller, processor, processing, personal data, data subject, and personal data breach have the meanings given by Data Protection Law.

Roles and scope

Customer is the controller or a processor authorized by the relevant controller. Task Machine is Customer's processor for Customer Personal Data. Each party is responsible for the duties Data Protection Law assigns to its role.

Task Machine remains an independent controller for account administration, authentication, direct billing and commercial records, service security, legal compliance, and its bounded product analytics as described in the Privacy Policy. Link acts as an independent controller and merchant of record for Managed Payments. This Addendum does not make either independent-controller activity processing on Customer's behalf.

Customer instructions

Task Machine will process Customer Personal Data only on Customer's documented instructions, including the Terms, this Addendum, workspace configuration, prompts, workflows, permissions, selected models, connected services, support requests, and other written instructions accepted by Task Machine. Task Machine may also process when required by law and will inform Customer before doing so unless the law prohibits notice.

Task Machine will notify Customer if it believes an instruction infringes Data Protection Law. Task Machine may pause the affected processing while the parties clarify the instruction. Customer is responsible for the lawfulness, accuracy, and scope of its instructions and for providing required notices and obtaining required rights, consents, and authorizations.

Confidentiality

Task Machine limits Customer Personal Data access to people who need it for service operation, security, support, or legal compliance. Anyone authorized to process the data is bound by confidentiality obligations or an appropriate statutory duty and receives privacy and security instructions appropriate to their responsibilities.

Security measures

Task Machine implements technical and organizational measures appropriate to the risk, including HTTPS, managed database encryption at rest, private object storage for customer data, signed production sessions, cross-site request forgery protection, role and domain authorization, encrypted Vault secrets, purpose-bound worker credentials, production access restriction, security logging, backup configuration, dependency maintenance, and incident response.

Local runs are not an operating-system or filesystem sandbox. Customer controls the local host, operating-system user, files, credentials, connectors, and network access available to local coding tools. The Security page describes this shared-responsibility boundary and the current managed-execution boundary. Read the Security page .

Subprocessors

Customer gives Task Machine general written authorization to use the providers in the Subprocessor Schedule. Task Machine imposes data-protection obligations appropriate to the processing on each subprocessor and remains responsible for its subprocessor's performance to the extent required by Data Protection Law.

Task Machine will update the public schedule before a material new subprocessor begins processing Customer Personal Data and will give active DPA customers reasonable advance notice through their recorded contact where required. Customer may object on reasonable data-protection grounds by contacting support promptly after notice. The parties will try in good faith to resolve the objection. If no reasonable alternative is available, either party may end the affected service without penalty beyond charges already incurred.

View the current Subprocessor Schedule .

International transfers

Task Machine will not transfer Customer Personal Data from the EEA to a country without an applicable lawful transfer mechanism. Task Machine may rely on an adequacy decision, the European Commission Standard Contractual Clauses, or another mechanism permitted by Data Protection Law and will implement supplementary measures where appropriate.

Where the Standard Contractual Clauses are required between Customer and Task Machine, the 2021 controller-to-processor module applies when Customer is a controller and the processor-to-processor module applies when Customer is a processor. The optional docking clause applies, subprocessor authorization is general, the supervisory authority and governing law are determined by Customer's EEA establishment where the clauses permit, and the courts designated by the clauses have jurisdiction. This Addendum and the Subprocessor Schedule provide the Annex information.

Data subject requests

Taking account of the nature of the processing, Task Machine will provide reasonable assistance for Customer to respond to requests to access, correct, delete, restrict, object to, or port Customer Personal Data. If Task Machine receives a request concerning data Customer controls, Task Machine will direct the person to Customer where practical and will not respond substantively unless Customer authorizes it or law requires it. Customer is responsible for verifying the requester and deciding the response.

Breach, assessments, and regulator assistance

Task Machine will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include information reasonably available about the nature of the breach, affected data and people, likely consequences, mitigation, and a contact point. Task Machine may provide information in stages and will take reasonable steps to contain, investigate, and remediate the breach. Notice is not an admission of fault.

Task Machine will provide reasonable information and assistance for Customer's data protection impact assessment, prior consultation, security assessment, or regulator inquiry relating to the service, taking account of the processing and information available to Task Machine. Customer remains responsible for its assessment and regulatory duties.

Return and deletion

During the service term, Customer may request an available copy of Customer Personal Data by written request. On termination or Customer's written request, Task Machine will return or delete Customer Personal Data according to Customer's instruction where reasonably possible, unless retention is required by law, necessary for legal claims or security, or technically limited to backup copies that remain protected and expire through the normal backup cycle.

Archiving a workspace is not deletion. Local files remain under Customer's control on its machines. Deletion does not require Task Machine to erase independent-controller records that must be kept for tax, accounting, payment, fraud, security, dispute, or legal purposes.

Information and audits

Task Machine will make information reasonably necessary to demonstrate compliance with Article 28 GDPR available to Customer. Customer may request an audit no more than once per year, or more often after a relevant breach or regulator request. The parties will first use current policies, provider evidence, and written responses. Any further audit must use an independent qualified auditor, protect other customers and confidential systems, avoid service disruption, give reasonable advance notice, and be at Customer's cost unless the audit identifies a material breach by Task Machine.

Processing details

Subject matter and duration: processing needed to provide Task Machine during the account, workspace, subscription, support, and deletion period described in the agreement and Privacy Policy.

Nature and purpose: hosting and organizing work, running local or managed agents, storing transcripts and files, routing model, search, and connector requests, supporting approvals and collaboration, securing the service, troubleshooting, support, and carrying out Customer instructions.

Data subjects: Customer users, members, personnel, contractors, applicants, leads, customers, suppliers, website visitors, communication participants, and other people whose data Customer submits or connected services return.

Data categories: identity and contact information, account and role data, professional information, communications, tasks, chats, comments, documents, prompts, transcripts, tool inputs and outputs, source files, repository data, connector content, public-web search data, usage metadata, and other data selected by Customer.

Sensitive data: Task Machine is not designed to require special-category or criminal-offence data. Customer must not submit such data unless it has confirmed a lawful basis, appropriate safeguards, suitable provider configuration, and any required written agreement with Task Machine.

Liability and governing terms

The liability limitations, governing law, venue, termination, and notice provisions in the Terms or signed agreement apply to this Addendum unless Data Protection Law or the Standard Contractual Clauses require otherwise.

Contact

For DPA questions, instructions, requests, or a signed copy, email support@taskmachine.io .