Data Processing Addendum
Last updated: August 13, 2026
This Data Processing Addendum ("DPA") is part of the Terms of Service and applies when TaskGeniusAIprocesses personal data on a customer's instructions in the growth operations platform. A signed order form or separate processing agreement controls where it conflicts with this page. The Privacy Policy describes processing where we act as a controller (for example account, billing, and security events).
Roles
The customer is the controller (or processor acting for its own customer) of workspace content and connected-source records. TaskGeniusAI is the processor of that customer data. We are the controller of operator account, authentication, billing, and product-security data needed to run the service.
Subject matter, nature, and purpose
We process customer data to provide the service: authenticate operators; sync connected advertising, analytics, CRM, call, lead, job, and website sources; normalize facts; generate dashboards, reports, and recommendations; send transactional notices the customer enables; and secure, support, and bill the workspace. Processing lasts for the subscription and the retention periods below.
Categories of data and people
- Operators and invited users: names, emails, roles, preferences, and authentication events.
- End customers, leads, and callers whose records a workspace imports: contact details, job and invoice facts, call metadata, and—until redaction—transcript or recording URLs.
- Advertising and analytics identifiers the customer grants from connected providers.
The customer is responsible for the lawful basis, notices, and permissions required for personal data it places in the service or authorizes us to pull.
Instructions
We process customer data only on documented instructions: the Terms, this DPA, in-product settings, connected-account grants, and written support requests from an authorized operator. We will tell the customer if we believe an instruction violates applicable data-protection law, unless the law forbids that notice.
Confidentiality and security
People who handle customer data are under confidentiality obligations. We use access controls, encryption in transit, encrypted secret storage, tenant authorization, audit logging, and operational monitoring. No system is perfectly secure. Vulnerability reports go to the security policy.
Subprocessors
The customer authorizes the vendors listed on /subprocessors, including optional processors that receive data only when configured or consented, and customer-directed connectors the workspace installs. We remain responsible for those platform subprocessors. Material additions to the platform list will be reflected on that page with an updated date. Customers who need advance notice of a specific vendor change can email taskgeniusai@gmail.com.
International processing
Data may be processed where we and our providers operate, including the United States. Where a transfer requires additional safeguards, we rely on the mechanisms our providers publish (for example their own standard contractual clauses or equivalent). This page is not itself a signed SCC pack.
Assistance, incidents, and deletion
We will reasonably assist with data-subject requests, DPIAs, and supervisory inquiries that relate to customer data we process, using the product export and admin tools where possible. Operators can download a privacy export and delete an account from Profile.
We will notify the customer without undue delay after becoming aware of a personal-data breach affecting that customer's data, and provide the facts we have at the time.
Normalized raw ingest payloads are purged after 180 days. Call transcripts and recording URLs are redacted after 180 days; call and lead rows may remain for attribution. After account deletion we cancel Stripe billing for that operator when no shared workspace remains and remove the operator identity, subject to limited legal, fraud-prevention, backup, and dispute records.
Audits and questions
On written request from a workspace owner or admin, we will provide reasonable information about our processing and security measures, including answers to a security questionnaire. On-site audits and third-party certification reports are available only if a signed order says so. Questions: taskgeniusai@gmail.com.