PlexarisTASQTASQ
Sign in
PRIVACY

Privacy statement

Last changed:

TASQ is a workspace for tasks, projects and meetings. To be that, TASQ processes data about you. Below you will find which data that is, why we hold it, how long it stays and what you can do about it. This statement describes what the app does today, not what it might one day do.

Who is responsible

The controller is Plexaris African AI Co. Ltd, established at Kampala, Uganda, registered with URSB (Uganda Registration Services Bureau) under registration number 80034434671963.

For anything to do with privacy, reach us at info@plexaris.ai. Requests for access, correction, erasure and objection arrive there too. We have no data protection officer; we are not required to appoint one.

Who this statement applies to

TASQ is a closed environment. You only get in through an invitation from someone who is already a member of a workspace. There is no open registration and there is no public part of the app where you leave data behind.

This statement applies to everyone with an account: employees, team members and guests invited to a specific workspace.

What data we hold about you

We collect no data that you do not provide yourself or that does not follow from your use of the app. There are no purchased lists, no external enrichment and no data from other sources.

Your account
Your email address, your name, your language and your time zone. Optionally: a reference to a profile picture, your own name for the AI team member, and the identity of your SPEAQ ID if you linked one.
What you create in the app
Tasks and subtasks with their title, description, status and deadline; comments you post; documents you upload, with their versions and file names.
Where you belong
Which workspaces you are in, in which role, since when, and which tasks you are assigned to.
Notifications
The notifications you received and whether you read them, plus your preferences per notification type and per channel. If you turn on push notifications, we keep the subscription your browser issues for that: an address at your browser vendor's push service and two keys used to encrypt the message to your device.
Signing in
Six-digit one-time codes if you sign in by email, and one-time invitation tokens. We do not store passwords, because TASQ does not have any.
A record of actions
For actions that matter we record who did what and when, along with your IP address and an identifier for your session. What exactly is in there, and why it stays, is explained below under the audit chain.

What we use it for, and on what basis

To run the app itself: showing your tasks, sending your notifications, storing your documents and letting your colleagues see who is working on what. The basis is performance of the agreement with you or with your employer, and our legitimate interest in being able to work together internally.

For security and accountability: the audit chain, the record of sign-in attempts and the limit on requests. The basis is our legitimate interest in a system where it can be established after the fact what happened, and where this touches a statutory retention duty, that legal obligation.

What we do not do: no profiling, no automated decisions about you, no advertising, no sale or rental of data, and no use of your content to train models.

Where your data is stored

Everything is in the European Union. The app runs on Google Cloud Run in region europe-west1 (Belgium). The database and file storage are with Supabase in eu-west-1 (Ireland).

Documents you upload are converted to pdf for display. That happens in our own service, in our own project, with a converter that is not allowed to fetch anything from the internet. No document goes to Microsoft, Google Docs or any conversion service.

In storage there is a separation between files of European workspaces and those of the Uganda team. That separation is about access, retention and administration. It is explicitly not a different country: that second set is in Ireland as well.

Who else processes it

We use a small number of suppliers who process data on our behalf. They may only use it for what we instruct them to do.

Google Cloud
Runs the app and our own document converter, in Belgium. Google does not see the content of your tasks; it is the machine our code runs on.
Supabase
The database and file storage, in Ireland.
Resend
Sends our email: invitations, sign-in codes and notifications. Receives your email address and the content of that one message for that purpose.
Sentry
Receives our error reports, in the European region (Frankfurt). What is and is not included is described in the next section.
Your browser's push service
Apple, Google or Mozilla, depending on your browser. Delivers the push notification to your device. Only applicable if you turn on push notifications yourself. The content of the notification is encrypted in transit with the keys from your subscription.
SPEAQ ID
Our own sign-in service, for those who want to sign in without a password. Part of Plexaris, not a third party.

Error reports and screen recordings on failure

When something goes wrong in TASQ, we send an error report to Sentry so we can fix it. Those reports arrive in Sentry's European region. We deliberately do not attach personal data: no email address and no name is sent along with an error by default.

For a portion of errors, roughly five in a hundred, a short recording is also made of what happened on screen just before the failure. We state this explicitly, because it is the least expected part of this statement.

In such a recording all text is masked, all input is masked and images are blocked. What we see is the shape of the screen and the order of the clicks, not the content of your tasks, your comments or your documents. If nothing goes wrong, nothing is recorded.

How long we keep it

Your account and what you created in the app stay for as long as you are a member of a workspace. If you request erasure, what follows below applies.

The trash and the retention period are two different things. The trash is a thirty-day undo for when someone makes a mistake; after that it is really deleted, including the file in storage. The retention period is the upper bound: how long something may exist at all, even if nobody deletes it.

Notifications
Thirteen months, after which they are removed automatically.
The trash
Thirty days, then permanently deleted, including the files.
Sign-in codes
Valid for ten minutes, unusable afterwards.
Your session
Fourteen days, after which you sign in again.
Meeting recordings and transcripts
That feature does not exist in TASQ today. Once it does, twelve months applies, configurable per workspace, and this statement will be updated before the feature is switched on.
The audit chain
Stays. Why is explained below.

The audit chain, and why something stays in it

For actions that matter we record a line: who did it, in which role, what happened, on which object, when, from which IP address and in which session. Each line is cryptographically chained to the previous one. That makes it visible afterwards whether anything was changed or removed.

Those lines contain no content. Of a changed value we keep a cryptographic fingerprint and not the text itself, so no task description and no comment is in there. The original text cannot be reconstructed from such a fingerprint.

This chain is not wiped along with an erasure request. A chain with a gap is no longer a chain and loses exactly the value it exists for: being able to show that nothing was quietly altered. Your IP address in those lines therefore stays as well. We think you should know that rather than discover it.

Your rights and how to use them

You have the right of access to your data, and rights to correction, erasure, restriction of processing, objection and portability.

Access and portability
Go to Settings, Privacy and data, and use the Download my data button. You immediately get a file in JSON format. It contains everything you are the subject of. What is deliberately not in it: comments by others, names and addresses of colleagues, the content of files, and the keys of your push subscription. Otherwise the button would be a tidy way to collect someone else's data.
Correction
You change your name, language and time zone yourself in Settings. If anything else is wrong, email us.
Erasure
Send a message to info@plexaris.ai. What happens then is described in the next section. We respond within one month.
Objection and restriction
Also via info@plexaris.ai. We will then explain our interest and weigh it against yours.

What happens if you request erasure

We do not delete you, we anonymise you. That is a deliberate choice and the difference is worth knowing.

On anonymisation your name is emptied, your email address is replaced by an address that points to nobody, a linked SPEAQ ID is detached, your profile picture is removed and your workspace memberships are ended. After that you can no longer sign in and you are no longer findable as a person in the app.

What stays are the tasks and comments themselves, without a name attached. The reason is practical: a workspace where a departed colleague's work disappears from the history leaves their colleagues with gaps in commitments they depend on. The content therefore stays usable for the business, the reference to you as a person disappears.

That the anonymisation took place is itself recorded as well, in the activity records of the workspaces you were a member of and in the audit chain. That is the only way to demonstrate later that we carried out your request.

How we protect your data

All connections are encrypted. Your session sits in a cookie that javascript cannot read and that expires after fourteen days.

You can sign in without a password, with SPEAQ ID or with a one-time code by email. We therefore store no passwords; they cannot leak either. SPEAQ ID uses signatures that resist a future quantum computer.

Access to a workspace is enforced in two places: in the app and in the database itself, per row. A mistake in one layer therefore does not immediately mean you can see data from another workspace.

Requests are rate limited, so a sign-in code cannot be guessed systematically and the app cannot be brought down with many requests at once.

Cookies

TASQ only uses cookies that are strictly necessary to function. There are no tracking cookies, no advertising cookies and no third-party cookies. That is why there is no cookie banner either.

Exactly which cookies exist, what they do and how long they last is on the cookie page.

Changes to this statement

The date at the top of this page is the date of the last change. If something material changes about what we do with your data, we announce it in the app and not only here.

Complaints

If you disagree with how we handle your data, please tell us first at info@plexaris.ai. You also always have the right to lodge a complaint with the Dutch Data Protection Authority, at autoriteitpersoonsgegevens.nl.