Skip to content

Taskbase Sales Coach

Trust, security and privacy at Taskbase.

Sales Coach handles real customer conversations. This page sets out where that data lives, who can reach it, what our models are and are not allowed to do with it, and the contractual commitments behind all of it.

EU & CH

Every processing location, listed per sub-processor in Annex 8.

36h

Maximum time to notify you of a personal data breach.

Zero

Customer content used to train or fine-tune models.

14 days

Advance notice before any sub-processor is added or replaced.

Security

How customer data is protected.

Each statement below is a measure from Annex 7, our Technical and Organizational Measures. The control reference under every card points at the exact entry.

EU and Swiss data residency

Customer data is processed and stored in the EU/EEA and Switzerland. All processing countries are listed in Annex 8, per sub-processor.

Annex 7 · D3  |  Annex 6 · 2.1

Encrypted at rest and in transit

Encryption at rest for all persistent storage holding customer data, including databases and object storage. TLS 1.2 or higher for all external traffic carrying customer data, with no plaintext protocols. Backups are encrypted and integrity-protected by cryptographic signing.

Annex 7 · D1, D2, N1

Multi-factor access control

Multi-factor authentication is enforced on all business systems and administrative interfaces. Product user authentication runs through a central identity provider (ZITADEL) supporting enforced multi-factor authentication. Administrative access to production requires the company VPN.

Annex 7 · IA1, IA2, IA6, N2

Your content does not train models

Customer content is not used to train, fine-tune or otherwise adapt Taskbase models. Sub-processed model providers are contractually excluded from training on customer data. Inference runs in EU regions, and the primary inference path is configured for zero data retention at the provider.

Annex 7 · AI1, AI2

Tenant isolation

Customer tenants are logically separated, with the tenant identifier enforced at the data access layer. Production, staging and development environments are separated.

Annex 7 · D4, S1

Bounded retention and real deletion

Live customer data including traces is kept until end of contract plus 30 days, backups 65 days, operational and security logs up to 12 months. Deletion on termination is executed rather than left to expiry; data export is available to the customer before deletion on request.

Annex 7 · D5, D6  |  Annex 6 · 1.3

Privacy & GDPR

Processing on your instructions, and nothing else.

You are the Controller; Taskbase is the Processor. Annex 6 is our Data Processing Agreement and forms part of the Service Agreement.

GDPR and Swiss nDSG

The Parties comply at all times with applicable data protection laws, in particular the Swiss Data Protection Act (nDSG) and the EU GDPR. The customer acts as Controller and Taskbase as Processor under a separate Data Processing Agreement (Annex 6).

GTC · 12.3  |  Annex 6 · 1

Breach notice within 36 hours

Taskbase notifies the customer without undue delay, and at the latest within 36 hours of becoming aware of a personal data breach — so the customer retains time to meet the 72-hour deadline under Art. 33 GDPR.

Annex 6 · Notification of Data Breaches

Data subject requests and DPIAs

Taskbase assists the customer in responding to data subject requests, and forwards any request addressed to it directly rather than responding on its own account. It also assists with data protection impact assessments and prior consultation.

Annex 6 · Assistance to the Controller  |  Annex 7 · C4

No automated decisions about people

The Service produces coaching guidance for human use. It performs no automated decision-making producing legal effects or similarly significant effects on a data subject.

Annex 7 · AI3

Sub-processors under contract

A data processing agreement is in place with each sub-processor, with Standard Contractual Clauses and Swiss addendum where required, and a transfer impact assessment where the importer is established outside the EEA and Switzerland.

Annex 7 · SU2  |  Annex 6 · 2.2

14 days notice on sub-processor changes

Taskbase informs the customer at least 14 days in advance of intended additions or replacements to the sub-processor list, giving the customer time to raise objections before the relevant sub-processor is commissioned.

Annex 6 · 2.3  |  Annex 7 · SU3

Certifications & assurance

Where we stand today.

Our current certification and assurance status, each entry linked to the Annex 7 control behind it.

AssuranceStatusReference
GDPR & Swiss nDSG data processing agreement
Art. 28 GDPR processor terms, available as Annex 6.
Implemented Annex 6
Technical and organizational measures
Published control set, reviewed at least annually and on material change.
Implemented Annex 7 · G5, C2
Sub-processor DPAs, SCCs and transfer impact assessments
In place with each sub-processor, with Swiss addendum where required.
Implemented Annex 7 · SU2
ISO 27001 certification PlannedFirst steps initiated Annex 7 · C7
Independent external penetration test
With tracked remediation.
Planned Annex 7 · S8

Physical and environmental security of all processing facilities is provided by AWS (EU) and cloudscale.ch (CH) under their ISO 27001 and SOC 2 certifications. Taskbase operates no own server or data-centre infrastructure.

Sub-processors

Who else touches the data.

The full list, with the personal data each one processes and the transfer safeguard that applies, is Annex 8.

Sub-processorServiceProcessing location
Amazon Web ServicesCloud infrastructure and application hosting; LLM inference via Amazon BedrockGermany (EU)
SupabaseApplication platform: PostgreSQL database, object storage, authentication, realtime, edge functionsSwitzerland (CH)
cloudscale.ch AGIaaS hosting for parts of the applicationSwitzerland (CH)
AnthropicClaude large language models, accessed through Amazon BedrockGermany (EU) — Bedrock EU region, zero-day retention
Microsoft AzureEU-region LLM inference (Azure OpenAI / Azure AI)Germany (EU)
Google CloudGemini Enterprise Agent Platform (formerly Vertex AI) — agent hosting and inferenceBelgium (EU)
Recall.ai*
(* only relevant if Taskbase Recording Tool is used)
Meeting capture, transcription and meeting metadataGermany (EU)
bliro GmbH*
(* only relevant if Bliro is used as part of a partnership agreement)
AI meeting transcription and summarisation; no audio or video recording is storedGermany (EU)
ZITADELIdentity and access management for Service usersSwitzerland (CH)
iWay AGOutbound transactional email (SMTP relay)Switzerland (CH)
PostHogProduct analytics.Germany (EU)
Full Annex 8 with transfer safeguards

Contact

Questions, or a vulnerability to report?

Security questionnaires, DPA requests and vulnerability reports all reach a monitored inbox.

Security

Vulnerability reports, security questionnaires and architecture questions.

security@taskbase.com

Data protection

Our data protection contact point, for DPA and privacy matters.

privacy@taskbase.com

EU representative

Jetro Capiaghi, Hammerweg 8, 83022 Rosenheim, Germany — for supervisory authorities and data subjects on EU data protection law.

jetro@taskbase.com