PlexarisTASQTASQ
Sign in
PRIVACY

Privacy statement

Last changed:

TASQ is a workspace for tasks, projects and meetings. To be that, TASQ processes data about you. Below you will find which data that is, why we hold it, how long it stays and what you can do about it. This statement describes what the app does today, not what it might one day do.

Who is responsible

The controller is Plexaris African AI Co. Ltd, established at Kampala, Uganda, registered with URSB (Uganda Registration Services Bureau) under registration number 80034434671963.

For anything to do with privacy, reach us at info@plexaris.ai. Requests for access, correction, erasure and objection arrive there too. We have no data protection officer; we are not required to appoint one.

Who this statement applies to

TASQ is a closed environment. You only get in through an invitation from someone who is already a member of a workspace. There is no open registration and there is no public part of the app where you leave data behind.

This statement applies to everyone with an account: employees, team members and guests invited to a specific workspace.

What data we hold about you

We collect no data that you do not provide yourself or that does not follow from your use of the app. There are no purchased lists, no external enrichment and no data from other sources.

Your account
Your email address, your name, your language and your time zone. Optionally: a reference to a profile picture, your own name for the AI team member, and the identity of your SPEAQ ID if you linked one.
What you create in the app
Tasks and subtasks with their title, description, status and deadline; comments you post; documents you upload, with their versions and file names; and voice notes you record. Such a voice note is an audio recording: it holds your voice and everything you say. It is filed with the workspace's documents and can therefore be heard by anyone with access there.
Where you belong
Which workspaces you are in, in which role, since when, and which tasks you are assigned to.
Notifications
The notifications you received and whether you read them, plus your preferences per notification type and per channel. If you turn on push notifications, we keep the subscription your browser issues for that: an address at your browser vendor's push service and two keys used to encrypt the message to your device.
Signing in
Six-digit one-time codes if you sign in by email, and one-time invitation tokens. We do not store passwords, because TASQ does not have any.
A record of actions
For actions that matter we record who did what and when, along with your IP address and an identifier for your session. What exactly is in there, and why it stays, is explained below under the audit chain.

What we use it for, and on what basis

To run the app itself: showing your tasks, sending your notifications, storing your documents and letting your colleagues see who is working on what. The basis is performance of the agreement with you or with your employer, and our legitimate interest in being able to work together internally.

For security and accountability: the audit chain, the record of sign-in attempts and the limit on requests. The basis is our legitimate interest in a system where it can be established after the fact what happened, and where this touches a statutory retention duty, that legal obligation.

For the AI team member: turning what you say or type into a task, a list or an answer. That happens with a Google language model and only at the moment you use that button. The basis is the same performance of the agreement; the button is there, and whoever does not use it sends nothing.

What we do not do: no profiling, no automated decisions about you, no advertising, and no sale or rental of data. We also do not use your content ourselves to train models.

That applies to what you say to the AI team member as well. That text goes to Google, and the service we use for it runs on a paid tier; on that tier Google does not use the input to train or improve its own models. What does still apply is that the processing region of that one service is not guaranteed; see above, under where your data is stored.

Where your data is stored

Everything we STORE of yours is in the European Union. The app runs on Google Cloud Run in region europe-west1 (Belgium). The database and file storage are with Supabase in eu-west-1 (Ireland). Your tasks, comments, documents and voice notes never leave it.

There is ONE thing that may leave the EU, and only at the moment you set it in motion yourself: the instruction you give the AI team member. That goes to Google's language model, and that service gives no hard guarantee about the region it processes in. Unlike the rest of TASQ, we therefore cannot promise it stays within the EU. If you do not use that button, nothing leaves the EU.

Documents you upload are converted to pdf for display. That happens in our own service, in our own project, with a converter that is not allowed to fetch anything from the internet. No document goes to Microsoft, Google Docs or any conversion service.

In storage there is a separation between files of European workspaces and those of the Uganda team. That separation is about access, retention and administration. It is explicitly not a different country: that second set is in Ireland as well.

Who else processes it

We use a small number of suppliers who process data on our behalf. They may only use it for what we instruct them to do.

Google Cloud
Runs the app and our own document converter, in Belgium. Google does not see the content of your tasks; it is the machine our code runs on.
Supabase
The database and file storage, in Ireland.
Resend
Sends our email: invitations, sign-in codes and notifications. Receives your email address and the content of that one message for that purpose.
Sentry
Receives our error reports, in the European region (Frankfurt). What is and is not included is described in the next section.
Your browser's push service
Apple, Google or Mozilla, depending on your browser. Delivers the push notification to your device. Only applicable if you turn on push notifications yourself. The content of the notification is encrypted in transit with the keys from your subscription.
SPEAQ ID
Our own sign-in service, for those who want to sign in without a password. Part of Plexaris, not a third party.
Google (Gemini)
The language model behind the AI team member. Only if you use that button. What you say or type then goes to Google, together with your name and the names of your workspaces, so the model knows who it is speaking to and where to file a task. This is a DIFFERENT service from the Google Cloud above, with different terms and no guaranteed European location. We use that service on a paid tier, where Google does not use the input to train its models.

Error reports and screen recordings on failure

When something goes wrong in TASQ, we send an error report to Sentry so we can fix it. Those reports arrive in Sentry's European region. We deliberately do not attach personal data: no email address and no name is sent along with an error by default.

For a portion of errors, roughly five in a hundred, a short recording is also made of what happened on screen just before the failure. We state this explicitly, because it is the least expected part of this statement.

In such a recording all text is masked, all input is masked and images are blocked. What we see is the shape of the screen and the order of the clicks, not the content of your tasks, your comments or your documents. If nothing goes wrong, nothing is recorded.

How long we keep it

Your account and what you created in the app stay for as long as you are a member of a workspace. If you request erasure, what follows below applies.

The trash and the retention period are two different things. The trash is a thirty-day undo for when someone makes a mistake; after that it is really deleted, including the file in storage. The retention period is the upper bound: how long something may exist at all, even if nobody deletes it.

Notifications
Thirteen months, after which they are removed automatically.
The trash
Thirty days, then permanently deleted, including the files.
Sign-in codes
Valid for ten minutes, unusable afterwards.
Your session
Fourteen days, after which you sign in again.
Voice notes
Twelve months, after which they go automatically. If you delete one yourself, the thirty-day bin applies and after that it is gone for good, audio file included.
Meeting recordings and transcripts
Recording a whole meeting does not exist in TASQ yet; a voice note on a task is something else and is covered above. If it does arrive, this statement will be updated before the feature is switched on.
The audit chain
Stays. Why is explained below.

The audit chain, and why something stays in it

For actions that matter we record a line: who did it, in which role, what happened, on which object, when, from which IP address and in which session. Each line is cryptographically chained to the previous one. That makes it visible afterwards whether anything was changed or removed.

Those lines contain no content. Of a changed value we keep a cryptographic fingerprint and not the text itself, so no task description and no comment is in there. The original text cannot be reconstructed from such a fingerprint.

This chain is not wiped along with an erasure request. A chain with a gap is no longer a chain and loses exactly the value it exists for: being able to show that nothing was quietly altered. Your IP address in those lines therefore stays as well. We think you should know that rather than discover it.

Your rights and how to use them

You have the right of access to your data, and rights to correction, erasure, restriction of processing, objection and portability.

Access and portability
Go to Settings, Privacy and data, and use the Download my data button. You immediately get a file in JSON format. It contains everything you are the subject of. What is deliberately not in it: comments by others, names and addresses of colleagues, the content of files, and the keys of your push subscription. Otherwise the button would be a tidy way to collect someone else's data.
Correction
You change your name, language and time zone yourself in Settings. If anything else is wrong, email us.
Erasure
Send a message to info@plexaris.ai. What happens then is described in the next section. We respond within one month.
Objection and restriction
Also via info@plexaris.ai. We will then explain our interest and weigh it against yours.

What happens if you request erasure

We do not delete you, we anonymise you. That is a deliberate choice and the difference is worth knowing.

On anonymisation your name is emptied, your email address is replaced by an address that points to nobody, a linked SPEAQ ID is detached, your profile picture is removed and your workspace memberships are ended. After that you can no longer sign in and you are no longer findable as a person in the app.

What stays are the tasks and comments themselves, without a name attached. The reason is practical: a workspace where a departed colleague's work disappears from the history leaves their colleagues with gaps in commitments they depend on. The content therefore stays usable for the business, the reference to you as a person disappears.

That the anonymisation took place is itself recorded as well, in the activity records of the workspaces you were a member of and in the audit chain. That is the only way to demonstrate later that we carried out your request.

How we protect your data

All connections are encrypted. Your session sits in a cookie that javascript cannot read and that expires after fourteen days.

You can sign in without a password, with SPEAQ ID or with a one-time code by email. We therefore store no passwords; they cannot leak either. SPEAQ ID uses signatures that resist a future quantum computer.

Access to a workspace is enforced in two places: in the app and in the database itself, per row. A mistake in one layer therefore does not immediately mean you can see data from another workspace.

Requests are rate limited, so a sign-in code cannot be guessed systematically and the app cannot be brought down with many requests at once.

Cookies

TASQ only uses cookies that are strictly necessary to function. There are no tracking cookies, no advertising cookies and no third-party cookies. That is why there is no cookie banner either.

Exactly which cookies exist, what they do and how long they last is on the cookie page.

Changes to this statement

The date at the top of this page is the date of the last change. If something material changes about what we do with your data, we announce it in the app and not only here.

Complaints

If you disagree with how we handle your data, please tell us first at info@plexaris.ai. You also always have the right to lodge a complaint with the Dutch Data Protection Authority, at autoriteitpersoonsgegevens.nl.