Data Processing Addendum
This Data Processing Addendum applies when a business customer uses Task Machine to process personal data on its behalf. It forms part of the Terms of Service or another agreement between the customer and Task Machine.
Version and last updated: 31 August 2026
Parties and effect
The customer that accepted the Terms or a written order is the Customer. Fabian Schucht, C. General Vives 1 6E, 35006 Las Palmas de Gran Canaria, Spain, NIE Z1096165J, is Task Machine. This Addendum takes effect when Customer uses the service to process Customer Personal Data and remains effective while Task Machine processes that data.
This Addendum supplements the Terms of Service. A separately signed data processing agreement controls if it expressly replaces this Addendum. If this Addendum conflicts with the Terms on protection of Customer Personal Data, this Addendum controls for that conflict.
Definitions
Customer Personal Data means personal data contained in workspace content, prompts, transcripts, files, connectors, workflows, support material, or other data Task Machine processes on Customer's behalf. Data Protection Law means the EU GDPR, UK GDPR and UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, applicable EEA or member-state law, applicable United States State Privacy Laws, and other mandatory privacy law governing the processing. Restricted Transfer means a transfer that requires an adequacy decision, the 2021 European Commission Standard Contractual Clauses, the UK Transfer Addendum, or another lawful transfer mechanism. Security Incident means a breach of Task Machine security that accidentally or unlawfully destroys, loses, alters, discloses, or permits unauthorized access to Customer Personal Data. Controller, processor, processing, personal data, data subject, and personal data breach have the meanings given by Data Protection Law.
Roles and scope
Customer is the controller or a processor authorized by the relevant controller. Task Machine is Customer's processor for Customer Personal Data. Each party is responsible for the duties Data Protection Law assigns to its role.
Task Machine remains an independent controller for account administration, authentication, public commercial inquiries, direct billing and commercial records, service security, legal compliance, and its bounded product analytics as described in the Privacy Policy. Link acts as an independent controller and merchant of record for Managed Payments. This Addendum does not make either independent-controller activity processing on Customer's behalf.
Customer instructions
Task Machine will process Customer Personal Data only on Customer's documented instructions, including the Terms, this Addendum, workspace configuration, prompts, workflows, permissions, selected models, connected services, support requests, and other written instructions accepted by Task Machine. Task Machine may also process when required by law and will inform Customer before doing so unless the law prohibits notice.
Task Machine will notify Customer if it believes an instruction infringes Data Protection Law. Task Machine may pause the affected processing while the parties clarify the instruction. Customer is responsible for the lawfulness, accuracy, and scope of its instructions and for providing required notices and obtaining required rights, consents, and authorizations.
Confidentiality
Task Machine limits Customer Personal Data access to people who need it for service operation, security, support, or legal compliance. Anyone authorized to process the data is bound by confidentiality obligations or an appropriate statutory duty and receives privacy and security instructions appropriate to their responsibilities.
Technical and organizational measures
Task Machine implements technical and organizational measures appropriate to the risk, including HTTPS, managed database encryption at rest, private object storage for customer data, signed production sessions, cross-site request forgery protection, role-based and domain access control, encrypted Vault secrets, purpose-bound worker credentials, production access restriction, security logging, backup configuration, dependency maintenance, and incident response.
Local runs are not an operating-system or filesystem sandbox. Customer controls the local host, operating-system user, files, credentials, connectors, and network access available to local coding tools. The Security page describes this shared-responsibility boundary and the current managed-execution boundary. Read the Security page .
Customer security responsibilities
Customer is responsible for using the service in a manner appropriate to the risk, managing workspace membership and permissions, protecting account and daemon credentials, configuring connectors and selected providers, maintaining suitable backups, and securing the local machines, operating-system users, repositories, networks, and other systems it makes available to local execution. These responsibilities do not reduce Task Machine's obligations for the service controls it operates.
Subprocessors
Customer gives Task Machine general written authorization to use the providers in the Subprocessor Schedule. Task Machine imposes data-protection obligations appropriate to the processing on each subprocessor and remains responsible for its subprocessor's performance to the extent required by Data Protection Law.
Task Machine will update the public schedule and give active DPA customers at least 15 days' advance notice through their recorded contact before a material new subprocessor begins processing Customer Personal Data, unless urgent security, legal, or service-continuity circumstances require a shorter period. Customer may object during the notice period on reasonable data-protection grounds. The parties will try in good faith to resolve the objection. If no reasonable alternative is available, either party may end the affected service without penalty beyond charges already incurred.
European transfer terms
Task Machine will not make a Restricted Transfer of Customer Personal Data without an applicable lawful transfer mechanism. Task Machine may rely on an adequacy decision, the European Commission Standard Contractual Clauses, the UK Transfer Addendum, the Swiss adaptations to the Standard Contractual Clauses, or another mechanism permitted by Data Protection Law, together with supplementary measures where appropriate.
Where the Standard Contractual Clauses are required between Customer and Task Machine, Module Two applies when Customer is a controller and Module Three applies when Customer is a processor. The optional docking clause applies. Clause 9 uses general written authorization with the notice period in this Addendum. The competent supervisory authority follows Customer's relevant EEA establishment or representative where the clauses permit. Spanish law and the courts of Spain apply to the clauses where that choice is permitted.
For a UK Restricted Transfer, the Standard Contractual Clauses apply as modified by the mandatory UK Transfer Addendum. For a Swiss Restricted Transfer, references are adapted to the Swiss Federal Act on Data Protection and the Federal Data Protection and Information Commissioner, without limiting the rights of people in Switzerland. The processing details, technical and organizational measures, and Subprocessor Schedule provide the corresponding annex information.
United States state privacy terms
Where applicable State Privacy Laws treat Customer as a business or controller and Task Machine as its service provider, contractor, or processor, Customer discloses Customer Personal Data only for the limited and specified purposes in the agreement and its documented instructions. Task Machine will not sell or share Customer Personal Data, use it for targeted advertising, retain or use it outside the direct business relationship except as permitted by those laws, or combine it with personal data from another source except as needed to provide the service and where legally permitted. Task Machine will notify Customer if it determines it can no longer meet these obligations and will reasonably support steps to stop and remediate unauthorized processing.
Artificial intelligence and automated processing
Task Machine does not use Customer Personal Data to train Task Machine's own general-purpose models. Customer instructs processing by selected model, search, coding-tool, and connector providers when it configures or invokes those services. Their use of submitted data is governed by the available provider terms and configuration described in the Subprocessor Schedule, Privacy Policy, and Customer's direct agreement where it selected the provider.
Task Machine provides workflow, approval, permission, and history controls but does not itself make solely automated decisions that produce legal or similarly significant effects about data subjects. If Customer configures the service for such processing, Customer remains responsible for the lawful basis, notices, safeguards, human review, and rights required by Data Protection Law, and Task Machine will provide reasonable assistance concerning processing it controls.
Data subject requests
Taking account of the nature of the processing, Task Machine will provide reasonable assistance for Customer to respond to requests to access, correct, delete, restrict, object to, or port Customer Personal Data. If Task Machine receives a request concerning data Customer controls, Task Machine will direct the person to Customer where practical and will not respond substantively unless Customer authorizes it or law requires it. Customer is responsible for verifying the requester and deciding the response.
Breach, assessments, and regulator assistance
Task Machine will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include information reasonably available about the nature of the breach, affected data and people, likely consequences, mitigation, and a contact point. Task Machine may provide information in stages and will take reasonable steps to contain, investigate, and remediate the breach. Notice is not an admission of fault.
Task Machine will provide reasonable information and assistance for Customer's data protection impact assessment, prior consultation, security assessment, or regulator inquiry relating to the service, taking account of the processing and information available to Task Machine. Customer remains responsible for its assessment and regulatory duties.
Return and deletion
During the service term, Customer may request an available copy of Customer Personal Data by written request. On termination or Customer's written request, Task Machine will return or delete Customer Personal Data according to Customer's instruction where reasonably possible, unless retention is required by law, necessary for legal claims or security, or technically limited to backup copies that remain protected and expire through the normal backup cycle.
Archiving a workspace is not deletion. Local files remain under Customer's control on its machines. Deletion does not require Task Machine to erase independent-controller records that must be kept for tax, accounting, payment, fraud, security, dispute, or legal purposes.
Information and audits
Task Machine will make information reasonably necessary to demonstrate compliance with Article 28 GDPR available to Customer. Customer may request an audit no more than once per year, or more often after a relevant breach or regulator request. The parties will first use current policies, provider evidence, and written responses. Any further audit must use an independent qualified auditor, protect other customers and confidential systems, avoid service disruption, give reasonable advance notice, and be at Customer's cost unless the audit identifies a material breach by Task Machine.
Processing details
Subject matter and duration: processing needed to provide Task Machine during the account, workspace, subscription, support, and deletion period described in the agreement and Privacy Policy.
Nature and purpose: hosting and organizing work, running local or managed agents, storing transcripts, files, browser action logs, and workspace-enabled masked viewport history, carrying out Customer screenshot-disable and deletion instructions, routing model, search, and connector requests, supporting approvals and collaboration, securing the service, troubleshooting, support, and carrying out Customer instructions.
Data subjects: Customer users, members, personnel, contractors, applicants, leads, customers, suppliers, website visitors, communication participants, and other people whose data Customer submits or connected services return.
Data categories: identity and contact information, account and role data, professional information, communications, tasks, chats, comments, documents, prompts, transcripts, browser action logs, optional masked viewport frames, third-party page content, tool inputs and outputs, source files, repository data, connector content, public-web search data, usage metadata, and other data selected by Customer.
Sensitive data: Task Machine is not designed to require special-category or criminal-offence data. Customer must not submit such data unless it has confirmed a lawful basis, appropriate safeguards, suitable provider configuration, and any required written agreement with Task Machine.
Liability and governing terms
The liability limitations, governing law, venue, termination, and notice provisions in the Terms or signed agreement apply to this Addendum unless Data Protection Law or the Standard Contractual Clauses require otherwise.
Contact
For DPA questions, instructions, requests, or a signed copy, email [email protected] .