Data Processing Addendum
Last updated: Version 1.0 (Draft) — Effective Date: [To Be Determined]
This Data Processing Addendum ("DPA") is incorporated into and forms part of the Tasskel, LLC Terms of Use (the "Agreement") between Tasskel, LLC ("Tasskel," "we," "us") and the Organization that has accepted the Agreement ("Customer," "you"). This DPA applies automatically, without any further action by either party, to the extent Tasskel processes Personal Data that is subject to European Data Protection Law on Customer's behalf. Capitalized terms not defined in this DPA have the meaning given in the Agreement.
Article 1. Definitions
In this DPA:
- "European Data Protection Law" means, as applicable: the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"); the GDPR as incorporated into UK law under the UK European Union (Withdrawal) Act 2018 ("UK GDPR"); and the Swiss Federal Act on Data Protection.
- "Personal Data," "Processing," "Controller," "Processor," "Data Subject," "Supervisory Authority," and "Personal Data Breach" have the meanings given in the GDPR, applied correspondingly under UK GDPR and Swiss law.
- "Standard Contractual Clauses" or "SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries approved by the European Commission (Commission Implementing Decision (EU) 2021/914), as may be updated or replaced.
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office.
- "Sub-processor" means any third party engaged by Tasskel to Process Personal Data on Tasskel's behalf in connection with the Services.
- "Customer Personal Data" means Personal Data contained within Customer Data that Tasskel Processes on Customer's behalf in connection with the Services.
Article 2. Roles of the Parties
The parties agree that, with respect to Customer Personal Data, Customer is the Controller (or, where applicable, a Processor acting on behalf of a third-party Controller) and Tasskel is the Processor. Tasskel will Process Customer Personal Data only as a Processor acting on behalf of Customer, and this DPA does not apply to Personal Data for which Tasskel is a Controller, such as Customer's own account, billing, and administrative contact information, which is governed by Tasskel's Privacy Policy.
Article 3. Processing of Customer Personal Data
3.1 Instructions
Tasskel will Process Customer Personal Data only in accordance with Customer's documented instructions, including those set out in the Agreement, this DPA, and Customer's use of the Services' features and settings, unless Processing is required by law applicable to Tasskel, in which case Tasskel will inform Customer of that legal requirement before Processing, unless the law prohibits such notice.
3.2 Details of Processing
The subject matter, duration, nature, and purpose of Processing, and the categories of Data Subjects and Personal Data, are described in Annex I to this DPA.
3.3 Confidentiality of Personnel
Tasskel will ensure that personnel authorized to Process Customer Personal Data are subject to a binding written confidentiality obligation.
3.4 Compliance with Instructions
Tasskel will promptly inform Customer if, in Tasskel's opinion, an instruction from Customer infringes European Data Protection Law.
Article 4. Sub-processors
4.1 General Authorization
Customer authorizes Tasskel to engage Sub-processors to Process Customer Personal Data, provided Tasskel imposes data protection obligations on each Sub-processor that are substantially similar to those in this DPA, and remains liable to Customer for each Sub-processor's performance.
4.2 Current Sub-processors
A current list of Tasskel's Sub-processors is set out in Annex II and is also available at tasskel.com or upon written request.
4.3 Notice of New Sub-processors
Tasskel will provide Customer with notice (by posting an update at tasskel.com or by email) of any new Sub-processor at least 10 days before that Sub-processor begins Processing Customer Personal Data. Customer may object to a new Sub-processor on reasonable data protection grounds by written notice within 10 days of that notice. If the parties cannot resolve the objection, Customer may terminate the affected Services by written notice, as its sole remedy.
4.4 Downstream Sub-processing
Some of Tasskel's Sub-processors, including its payment processors, may themselves engage further sub-processors (for example, underlying card-network processing infrastructure) to perform their services to Tasskel. Tasskel will require each such Sub-processor to impose data protection obligations on its own downstream sub-processors that are no less protective of Customer Personal Data than the obligations in this DPA, and Tasskel remains responsible for each Sub-processor's compliance with this DPA regardless of the number of tiers of sub-processing involved.
Article 5. Assistance with Data Subject Requests
Taking into account the nature of the Processing, Tasskel will provide reasonable assistance to Customer, by appropriate technical and organizational measures, to help Customer respond to requests from Data Subjects to exercise their rights under European Data Protection Law (including access, rectification, erasure, restriction, portability, and objection). If Tasskel receives a request directly from a Data Subject concerning Customer Personal Data, Tasskel will not respond directly, other than to direct the Data Subject to submit the request to Customer, unless legally required to respond.
Article 6. Security of Processing
6.1 Technical and Organizational Measures
Tasskel will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex III.
6.2 Updates to Security Measures
Tasskel may update the measures described in Annex III from time to time, provided the updates do not materially reduce the overall level of security.
Article 7. Personal Data Breach
Tasskel will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Tasskel's notice will describe, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach. Tasskel will provide reasonable cooperation and information to help Customer meet any obligation to notify a Supervisory Authority or affected Data Subjects under European Data Protection Law.
Article 8. Data Protection Impact Assessments
Tasskel will provide Customer with reasonable cooperation and information necessary for Customer to carry out a data protection impact assessment or prior consultation with a Supervisory Authority, to the extent required under European Data Protection Law and to the extent such information is reasonably available to Tasskel.
Article 9. International Data Transfers
9.1 Transfer Mechanism
To the extent Tasskel's Processing of Customer Personal Data involves a transfer of Personal Data protected by European Data Protection Law to a country that has not received an adequacy decision from the European Commission (or, as applicable, the UK government), the parties agree that the Standard Contractual Clauses are incorporated into this DPA by reference and will apply to that transfer, with Customer as "data exporter" and Tasskel as "data importer."
9.2 Module Selection
For transfers subject to the SCCs, Module Two (Controller to Processor) applies where Customer is a Controller, and Module Three (Processor to Processor) applies where Customer is a Processor acting on behalf of a third-party Controller.
9.3 UK and Swiss Transfers
For transfers subject to UK GDPR, the UK Addendum is incorporated by reference and applies in place of, or in addition to, the SCCs as required. For transfers subject to Swiss law, the SCCs apply with the amendments necessary to reflect Swiss legal requirements, including recognizing the Swiss Federal Data Protection and Information Commissioner as the competent Supervisory Authority where applicable.
9.4 Conflicts
If there is a conflict between this DPA and the SCCs or UK Addendum, the SCCs or UK Addendum will prevail to the extent of the conflict.
Article 10. Audits & Records
Tasskel will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, which may include summaries of relevant third-party audit or certification reports. Where such information is not sufficient, Customer may request an audit of Tasskel's relevant Processing activities, to be conducted during business hours, on reasonable prior notice of at least 30 days, no more than once per year (unless required by a Supervisory Authority or following a Personal Data Breach), subject to reasonable confidentiality restrictions, and at Customer's expense.
Article 11. Return or Deletion of Data
On termination or expiration of the Agreement, Tasskel will, at Customer's election, delete or return all Customer Personal Data, and delete existing copies, within the retention period described in the Agreement, unless applicable law requires Tasskel to retain some or all of the Customer Personal Data, in which case Tasskel will isolate and protect that data from further Processing except as required by that law.
Article 12. Liability
Each party's liability arising out of or in connection with this DPA, whether in contract, tort, or otherwise, is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits either party's liability to a Data Subject or Supervisory Authority under European Data Protection Law.
Article 13. General
13.1 Order of Precedence
This DPA forms part of the Agreement. If there is a conflict between this DPA and the Agreement regarding the Processing of Customer Personal Data, this DPA prevails to the extent of the conflict.
13.2 Governing Law
This DPA is governed by the same governing law and jurisdiction provisions as the Agreement, except that the SCCs and UK Addendum are governed by the law specified within them.
13.3 Term
This DPA remains in effect for as long as Tasskel Processes Customer Personal Data on Customer's behalf under the Agreement.
Annex I — Details of Processing
A. List of Parties
Data Exporter: Customer, as identified in its Tasskel account. Role: Controller (or Processor acting on behalf of a third-party Controller). Contact: the Organization's designated account administrator.
Data Importer: Tasskel, LLC, a North Carolina limited liability company. Role: Processor. Contact: the privacy contact designated at tasskel.com.
B. Description of Processing
- Categories of Data Subjects: Customer's customers, prospects, employees, contractors, and other individuals whose Personal Data Customer submits to the Services.
- Categories of Personal Data: Contact details (name, email, phone, address); transaction and payment records; scheduling and appointment data; support and chat communications; content of documents, messages, and files uploaded by Customer; AI prompts and generated output; and technical data such as device and usage information.
- Special categories of data (if any): Customer determines what data it submits to the Services. Customer should not submit special categories of Personal Data (e.g., health, biometric, or similar sensitive data) unless a separate written agreement with Tasskel authorizes it.
- Frequency of transfer: Continuous, for as long as Customer uses the Services.
- Nature and purpose of Processing: Hosting, storage, transmission, and processing of Customer Personal Data as necessary to provide, secure, support, and improve the Services, including CRM, invoicing, payment collection, scheduling, messaging, AI features, and related functionality selected by Customer.
- Duration of Processing: For the duration of the Agreement, plus any post-termination retention period described in the Agreement.
C. Competent Supervisory Authority
The Supervisory Authority for the EEA is determined based on Customer's establishment or the location of the relevant Data Subjects, in accordance with the SCCs. For UK transfers, the competent authority is the UK Information Commissioner's Office.
Annex II — Sub-processors
As of the Effective Date, Tasskel engages the following Sub-processors. An up-to-date list is maintained at tasskel.com.
- Hostinger (Hostinger International Ltd., headquartered in Vilnius, Lithuania) — cloud hosting and infrastructure, for storage and compute. [Data center region to be confirmed and specified here — Hostinger operates data centers both within the EU/EEA (e.g., Lithuania, Netherlands, Germany, France) and outside it (e.g., United States, Brazil, Singapore, India); the specific region selected determines whether this transfer is intra-EEA or requires the mechanism described in Article 9.]
- EzPay America — payment processing.
- Micamp Solutions — payment processing and merchant services.
- Maverick Payments — payment processing.
- Netevia — payment processing.
- NMI (Network Merchants, LLC) — payment gateway services.
- Email and SMS delivery providers, for transactional and marketing messaging features.
- Third-party AI model providers, for AI Services such as content generation and assistants.
- Customer support and ticketing tool providers, for internal support operations.
- Analytics and monitoring providers, for security, performance, and reliability monitoring.
Downstream processing networks: Tasskel's payment processors listed above settle transactions through underlying card-network processing infrastructure, which as of the Effective Date includes TSYS (a Global Payments company) and First Data (a Fiserv company). These entities are not engaged directly by Tasskel, but Personal Data submitted for payment processing may flow to them as sub-processors of Tasskel's payment processors. Tasskel's agreements with its payment processors require those processors to impose data protection obligations on their own downstream sub-processors that are no less protective than those in this DPA.
Annex III — Technical & Organizational Security Measures
Tasskel maintains a written information security program that includes measures such as:
- Encryption of Customer Personal Data in transit using industry-standard protocols (e.g., TLS), and encryption of data at rest where supported by the underlying infrastructure.
- Access controls restricting access to Customer Personal Data to authorized personnel on a need-to-know basis, with unique credentials and, where applicable, multi-factor authentication.
- Logging and monitoring of access to production systems that process Customer Personal Data.
- Regular review of access permissions and prompt revocation of access for personnel who no longer require it.
- Vulnerability management, including periodic security assessments and prompt remediation of identified critical vulnerabilities.
- A documented incident response process for identifying, investigating, and responding to security incidents, including the breach notification process described in Article 7.
- Business continuity and backup procedures designed to restore availability of Customer Personal Data in a timely manner in the event of a physical or technical incident.
- Employee security and confidentiality training and background checks consistent with applicable law.
- Physical security controls at data center facilities operated by Tasskel's infrastructure Sub-processors.
Tasskel may update these measures from time to time provided the updates do not materially reduce the overall level of protection.
