Data Processing Agreement
Last updated: September 25, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Customer", the controller) and Taskpend, operated by Elinatan Cohen ("Taskpend", the processor). It applies whenever Taskpend processes personal data on the Customer's behalf. To receive a countersigned copy, email privacy@taskpend.com.
1. Scope and roles
The Customer is the controller of personal data it or its users put into Taskpend. Taskpend processes that data as a processor, only to provide the service described in the Terms.
Categories of data: names, email addresses, profile details, and any personal data contained in tasks, documents, comments and connected sources. Data subjects: the Customer's users and people mentioned in its content.
2. Processing on instructions
Taskpend processes personal data only on the Customer's documented instructions — the Terms, this DPA and the Customer's use of the service — unless the law requires otherwise, in which case Taskpend will tell the Customer first where allowed.
3. Confidentiality
Anyone authorized by Taskpend to process personal data is bound by confidentiality.
4. Security
Taskpend applies appropriate technical and organizational measures, including encryption in transit and at rest, workspace isolation and restricted access to credentials, as described on the Security page.
5. Sub-processors
The Customer authorizes the sub-processors listed on the Security page. Taskpend imposes data-protection obligations on each of them and remains responsible for their performance. Taskpend will update that list before adding or replacing a sub-processor, and the Customer may object on reasonable grounds.
6. Data subject requests
Taskpend will help the Customer, as far as reasonably possible, to answer requests from data subjects to access, correct, delete, restrict or port their data.
7. Personal data breaches
Taskpend will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, with the information reasonably available, and will help the Customer meet its own notification duties.
8. International transfers
Where personal data is transferred outside the European Economic Area to a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses or another lawful mechanism.
9. Deletion and return
When the Customer's account ends, Taskpend deletes or anonymizes the Customer's personal data within 30 days, unless the law requires it to be kept. The Customer may ask for a copy before deletion.
10. Audits and information
Taskpend will make available the information reasonably necessary to demonstrate compliance with this DPA, and will answer reasonable security questionnaires.
11. Liability and precedence
Liability under this DPA is governed by the Terms. If this DPA and the Terms conflict on the processing of personal data, this DPA prevails.