Updated 26.08.26

Privacy policy

This policy explains what personal data we process when you use Tasqin, why we do it, who we share it with, and what rights you have under the General Data Protection Regulation (EU) 2016/679 (GDPR).

1. Controller

The controller of personal data is Perfekti SIA, reg. no. 40203678637, registered address: Madonas nov., Madona, Raiņa iela 6, LV-4801. Write to tasqin.com@gmail.com about data processing. We will reply within a reasonable time and may ask for extra details to confirm your identity.

If you use Tasqin for your employer or a client, that company may be the controller of work data entered in the team. In that case we process the data as a processor on the company's behalf under the applicable agreement.

2. What data we process

Account data: first and last name, email address, password (stored only as a hash), language choice, time zone, date/time display preferences, MFA settings and notification preferences.

Team and work data: team name and settings, user names, emails and roles, lists, tasks, subtasks, statuses, due dates, notes, activity history, attachment names and content that you or your team enter in the system.

Billing data (paid plans): Stripe customer and subscription identifiers, paid seat count, billing cycle dates and subscription status. Payment card and invoice details are stored by Stripe, not in our database.

Integration data (if enabled): encrypted OAuth access and refresh tokens, Google/Microsoft account email, Google Drive / OneDrive folder metadata, Gmail connection status for the Chrome extension, calendar subscription tokens.

Technical and security data: sign-in time, IP address, browser and device information, error logs (with PII redaction), bot check results (Cloudflare Turnstile), cookie consent choice and rate limiting records.

Feedback: bug reports, feature requests and feedback submitted via the sidebar, with your email and free-text message.

3. Purposes and legal basis

Account creation, sign-in, team collaboration and providing the service - performance of a contract (GDPR Art. 6(1)(b)).

System security, abuse prevention, error analysis and service maintenance - legitimate interests (GDPR Art. 6(1)(f)), unless consent is required by law.

Optional cookies and anonymous usage statistics (Umami) - your consent (GDPR Art. 6(1)(a)), which you may withdraw at any time.

Payment and subscription processing, accounting and other legal duties - performance of a contract and compliance with a legal obligation (GDPR Art. 6(1)(b) and (c)).

Email notifications about tasks, invitations and reminders - performance of a contract; some notifications can be limited in profile settings.

4. Recipients and processors

Data is visible to authorised users in your team according to their permissions. For technical operations we use trusted processors bound by data processing agreements or EU Standard Contractual Clauses.

Main processors: Supabase (database and authentication), Vercel (app hosting), Resend (transactional email), Stripe (payments), Google (OAuth, Drive, Gmail API for the extension), Microsoft (OAuth, OneDrive), Cloudflare (Turnstile bot protection), Sentry (error monitoring, if enabled) and Umami (anonymous analytics, if enabled and you consent).

We do not sell data or share it with third parties for advertising. Processors may handle data only on our instructions.

5. International transfers

Data is mainly stored in the European Economic Area (EEA). Some processors (e.g. Stripe, Google, Microsoft, Cloudflare, Sentry) may also process data outside the EEA, for example in the USA, when you use the related integration.

In those cases we rely on European Commission adequacy decisions, EU Standard Contractual Clauses or other GDPR-approved mechanisms provided by the processor.

6. How long we keep data

We keep account and team data while the account is active. After a deletion request the account is deactivated for 30 days; after that period data is permanently deleted, unless a longer period is required by law.

If you sign in again during deactivation, the account is automatically restored. Deleting a team leader’s account may affect team data according to the account deletion flow.

Cookie consent is kept for up to 180 days. A Remember me sign-in session is kept for up to 30 days. Technical logs and security records are kept only as long as needed for security and legal requirements.

7. Your rights

You have the right to access your data, correct it, delete it, restrict processing, object to processing based on legitimate interests, and receive your data in a portable format.

You can delete your account under Personal settings (/settings/profile). To request a copy of your data, write to the legal email shown in the controller section of this policy. We will reply within a reasonable time.

If processing is based on consent (optional cookies), you may withdraw it at any time in cookie settings. You may lodge a complaint with the Data State Inspectorate (www.dvi.gov.lv).

8. Cookies

We use necessary cookies to store your consent, keep your sign-in session and keep the site working. Preference and analytics cookies are enabled only with your consent. The full list and controls are in the cookie policy.

9. Integrations and third-party services

If you connect Google Drive, OneDrive, the Gmail extension or a calendar subscription, the relevant provider processes data under its own privacy policy. We store only the tokens and metadata needed for the integration to work.

The Gmail Chrome extension works only after you sign in and grant access. The extension may read email metadata and content to attach emails to tasks or create subtasks.

10. Security

We use reasonable technical and organisational measures: encrypted connections (HTTPS), access control, password hashes, encrypted OAuth tokens in the database and row-level security policies. Absolute security on the internet cannot be guaranteed, so please also protect your account password.

11. Changes

If this policy changes in a material way, we will update this page and the date. Continuing to use Tasqin after a change means you accept the updated policy to the extent allowed by applicable law.