Privacy Policy
This policy explains how the TaskFly portal — both the website and the mobile app — handles personal data. It is written plainly: what we collect, why, and what you can do about it.
1. Who processes your data
The portal is operated by TaskFly. For any privacy question, write to [email protected].
One important distinction: this portal is an internal tool for companies. Your employer adds you to a workspace and decides what tasks, comments and files are created there. So for work content your employer is the controller and we process it on their behalf. For your account itself (name, email, sign-in records) we are the controller.
2. What we collect
Only what the portal needs to work:
- Account data — first and last name, email address, username, phone (if you add one), profile picture, role.
- Work content — tasks, comments, projects, notes, messages and files you create or take part in.
- Media comments — if you record a voice or video comment in the mobile app, that recording is stored as a file. The camera and microphone are accessed only when you press that button; nothing is recorded in the background.
- Technical records — the date and IP address of your last sign-in, your device push token, server logs.
- Crash reports — when the app fails unexpectedly, the error message and its technical trace are sent. Screen contents, what you typed, and form data are NOT sent.
3. Why we process it, and on what legal basis
- To provide the service — identify your account, show your tasks, deliver notifications. Basis: performance of the contract with you and your employer.
- Security and abuse prevention — sign-in records, audit log. Basis: legitimate interest.
- Service reliability — fixing faults using crash reports and server logs. Basis: legitimate interest.
- Optional integrations — Google Calendar, Gmail, Microsoft 365 mail and similar run only if you connect them. Basis: your consent, which you can withdraw at any time.
4. Who we share it with
We do not sell your data and never hand it over for advertising. We use the following service providers to run the portal:
- core.digix.az — sign-in and password management. Your password is not stored in the portal's own database.
- Anthropic — AI features (assistant, report explanations). Relevant text is sent only at the moment you use such a feature.
- Expo — delivery of mobile push notifications (device token and notification text).
- Google — “Sign in with Google”, plus Gmail and Calendar if you connect them.
- Microsoft — your Microsoft 365 mailbox, if you connect it.
- Meta (Facebook) — only if you use “Sign in with Facebook”.
- PagerDuty — on-call schedule sync (only where that module is enabled).
- Cloudflare — bot protection.
- We may also disclose data to competent authorities where the law requires it.
5. Where your data is stored
The portal's servers and file storage are located in a data centre in the European Union. Files you upload are kept in our own object storage (MinIO) and served through a CDN — they are not moved to a third-party cloud storage provider.
Some of the providers listed above (for example Anthropic, Expo, Google, Microsoft) may process data outside the European Economic Area. Such transfers rely on those companies' standard contractual clauses.
6. How long we keep it
- Work content (tasks, comments, files) is a company work record and remains after your account is closed, so the team's work is not left broken. Deleting it is your employer's decision.
- Account data is kept until the account is closed, and afterwards as a deactivated record for audit and security purposes.
- Push tokens are deleted the moment you sign out or close your account.
- Server logs are kept for a limited period and then deleted automatically.
7. How to delete your account
You can close your account yourself at any time — no email, no permission from anyone required:
- In the mobile app: Profile → Danger zone → “Delete account”.
- On the web: Profile settings → Profile tab → “Delete account”.
- If you have already uninstalled the app or cannot sign in, write to [email protected].
8. What deletion actually does — plainly
Deletion closes access to your account PERMANENTLY: from that moment you cannot sign in to the portal and your devices receive no notifications. Only your company's administrator can reopen access.
However, the tasks, comments and files you created are not deleted — they are your employer's work record and their fate is your employer's decision. Your name and email also remain in the audit log and in the deactivated account record, so past actions can still be attributed.
If you want every trace removed, write to [email protected] and we will assess the request together with your employer.
9. Your rights
- Find out what data is held about you and obtain a copy.
- Ask for incorrect data to be corrected (you can change your name and phone yourself in your profile).
- Ask for erasure or restriction of processing.
- Withdraw consent for processing that relies on it (integrations).
- Lodge a complaint with a supervisory authority.
- To exercise these rights: [email protected].
10. Security
All traffic runs over an encrypted channel (HTTPS). Your session lives only in an httpOnly cookie — no script in the browser or the app can read it. Personal notes are stored encrypted on the server. Sign-ins are written to an audit log.
No system is perfectly secure; if you notice anything suspicious, tell us immediately.
11. Children
The portal is a work tool and is not intended for anyone under 16. If such an account is found, it will be removed.
12. Changes
If this policy is updated, the date on this page will change. We will announce significant changes inside the portal as well.