Taskbase Sales Coach
Trust, security and privacy at Taskbase.
Sales Coach handles real customer conversations. This page sets out where that data lives, who can reach it, what our models are and are not allowed to do with it, and the contractual commitments behind all of it.
Every processing location, listed per sub-processor in Annex 8.
Maximum time to notify you of a personal data breach.
Customer content used to train or fine-tune models.
Advance notice before any sub-processor is added or replaced.
Security
How customer data is protected.
Each statement below is a measure from Annex 7, our Technical and Organizational Measures. The control reference under every card points at the exact entry.
EU and Swiss data residency
Customer data is processed and stored in the EU/EEA and Switzerland. All processing countries are listed in Annex 8, per sub-processor.
Annex 7 · D3 | Annex 6 · 2.1
Encrypted at rest and in transit
Encryption at rest for all persistent storage holding customer data, including databases and object storage. TLS 1.2 or higher for all external traffic carrying customer data, with no plaintext protocols. Backups are encrypted and integrity-protected by cryptographic signing.
Annex 7 · D1, D2, N1
Multi-factor access control
Multi-factor authentication is enforced on all business systems and administrative interfaces. Product user authentication runs through a central identity provider (ZITADEL) supporting enforced multi-factor authentication. Administrative access to production requires the company VPN.
Annex 7 · IA1, IA2, IA6, N2
Your content does not train models
Customer content is not used to train, fine-tune or otherwise adapt Taskbase models. Sub-processed model providers are contractually excluded from training on customer data. Inference runs in EU regions, and the primary inference path is configured for zero data retention at the provider.
Annex 7 · AI1, AI2
Tenant isolation
Customer tenants are logically separated, with the tenant identifier enforced at the data access layer. Production, staging and development environments are separated.
Annex 7 · D4, S1
Bounded retention and real deletion
Live customer data including traces is kept until end of contract plus 30 days, backups 65 days, operational and security logs up to 12 months. Deletion on termination is executed rather than left to expiry; data export is available to the customer before deletion on request.
Annex 7 · D5, D6 | Annex 6 · 1.3
Privacy & GDPR
Processing on your instructions, and nothing else.
You are the Controller; Taskbase is the Processor. Annex 6 is our Data Processing Agreement and forms part of the Service Agreement.
GDPR and Swiss nDSG
The Parties comply at all times with applicable data protection laws, in particular the Swiss Data Protection Act (nDSG) and the EU GDPR. The customer acts as Controller and Taskbase as Processor under a separate Data Processing Agreement (Annex 6).
GTC · 12.3 | Annex 6 · 1
Breach notice within 36 hours
Taskbase notifies the customer without undue delay, and at the latest within 36 hours of becoming aware of a personal data breach — so the customer retains time to meet the 72-hour deadline under Art. 33 GDPR.
Annex 6 · Notification of Data Breaches
Data subject requests and DPIAs
Taskbase assists the customer in responding to data subject requests, and forwards any request addressed to it directly rather than responding on its own account. It also assists with data protection impact assessments and prior consultation.
Annex 6 · Assistance to the Controller | Annex 7 · C4
No automated decisions about people
The Service produces coaching guidance for human use. It performs no automated decision-making producing legal effects or similarly significant effects on a data subject.
Annex 7 · AI3
Sub-processors under contract
A data processing agreement is in place with each sub-processor, with Standard Contractual Clauses and Swiss addendum where required, and a transfer impact assessment where the importer is established outside the EEA and Switzerland.
Annex 7 · SU2 | Annex 6 · 2.2
14 days notice on sub-processor changes
Taskbase informs the customer at least 14 days in advance of intended additions or replacements to the sub-processor list, giving the customer time to raise objections before the relevant sub-processor is commissioned.
Annex 6 · 2.3 | Annex 7 · SU3
Control framework
Eleven control domains, published in full.
Annex 7 lists every measure with its current status — Implemented, Partial or Planned. Select a domain to jump straight to its table.
Certifications & assurance
Where we stand today.
Our current certification and assurance status, each entry linked to the Annex 7 control behind it.
| Assurance | Status | Reference |
|---|---|---|
| GDPR & Swiss nDSG data processing agreement Art. 28 GDPR processor terms, available as Annex 6. |
Implemented | Annex 6 |
| Technical and organizational measures Published control set, reviewed at least annually and on material change. |
Implemented | Annex 7 · G5, C2 |
| Sub-processor DPAs, SCCs and transfer impact assessments In place with each sub-processor, with Swiss addendum where required. |
Implemented | Annex 7 · SU2 |
| ISO 27001 certification | PlannedFirst steps initiated | Annex 7 · C7 |
| Independent external penetration test With tracked remediation. |
Planned | Annex 7 · S8 |
Physical and environmental security of all processing facilities is provided by AWS (EU) and cloudscale.ch (CH) under their ISO 27001 and SOC 2 certifications. Taskbase operates no own server or data-centre infrastructure.
Sub-processors
Who else touches the data.
The full list, with the personal data each one processes and the transfer safeguard that applies, is Annex 8.
| Sub-processor | Service | Processing location |
|---|---|---|
| Amazon Web Services | Cloud infrastructure and application hosting; LLM inference via Amazon Bedrock | Germany (EU) |
| Supabase | Application platform: PostgreSQL database, object storage, authentication, realtime, edge functions | Switzerland (CH) |
| cloudscale.ch AG | IaaS hosting for parts of the application | Switzerland (CH) |
| Anthropic | Claude large language models, accessed through Amazon Bedrock | Germany (EU) — Bedrock EU region, zero-day retention |
| Microsoft Azure | EU-region LLM inference (Azure OpenAI / Azure AI) | Germany (EU) |
| Google Cloud | Gemini Enterprise Agent Platform (formerly Vertex AI) — agent hosting and inference | Belgium (EU) |
| Recall.ai* (* only relevant if Taskbase Recording Tool is used) | Meeting capture, transcription and meeting metadata | Germany (EU) |
| bliro GmbH* (* only relevant if Bliro is used as part of a partnership agreement) | AI meeting transcription and summarisation; no audio or video recording is stored | Germany (EU) |
| ZITADEL | Identity and access management for Service users | Switzerland (CH) |
| iWay AG | Outbound transactional email (SMTP relay) | Switzerland (CH) |
| PostHog | Product analytics. | Germany (EU) |
Documents
Read the contract itself.
The documents that govern Sales Coach.
General Terms and Conditions
The terms governing every service Taskbase AG provides: scope, fees, warranty, liability, intellectual property, confidentiality, term and governing law.
Read the GTC →Annex 6 – Data Processing Agreement
Purpose and duration of processing, categories of data and data subjects, instructions, sub-processors, assistance to the controller and breach notification.
Read the DPA →Annex 7 – Technical & Organizational Measures
The full control set across eleven domains, each measure with a status, plus the mapping to the statutory categories of the Swiss DSV and Art. 32 GDPR.
Read the TOM →Annex 8 – Sub-processors
Every sub-processor engaged by Taskbase, the personal data it processes, its processing location and the transfer safeguard in place.
Read Annex 8 →Contact
Questions, or a vulnerability to report?
Security questionnaires, DPA requests and vulnerability reports all reach a monitored inbox.
Security
Vulnerability reports, security questionnaires and architecture questions.
Data protection
Our data protection contact point, for DPA and privacy matters.
EU representative
Jetro Capiaghi, Hammerweg 8, 83022 Rosenheim, Germany — for supervisory authorities and data subjects on EU data protection law.