1. Data Controller Identity
TapTidy is operated by Think Tank Systems.
Email: privacy@taptidy.app
Data Protection Officer (DPO): dpo@taptidy.app
2. Types of Personal Data Collected
We collect the following types of personal data:
- Account Information: Name, email address, password (encrypted)
- Task Data: Tasks, projects, tags, notes, due dates, and related metadata
- Usage Data: Browser type, device information, pages visited, and interaction data collected with consent
- Operational Monitoring Data: Server-side request metadata, service health and performance metrics, and security or abuse-prevention logs used to operate, protect, and debug the service. These operational metrics are not used for advertising or behavioral profiling.
- Communication Data: Messages, support requests, and feedback
- Integration Data: Data from third-party services you connect (e.g., calendar providers)
- Cookies and Tracking: Session tokens, preferences, analytics data (with consent)
- ClarityScorer Telemetry: Anonymous signal names and task-scoring bucket labels used to calibrate TapTidy's task clarity algorithm. No task content or personally identifiable information is included in the event payload. Pro subscribers have this disabled by default as part of zero telemetry. Free users may opt out at any time in Settings → Account → ClarityScorer telemetry.
3. Processing Purposes and Legal Basis
Service Delivery
Legal Basis: Contract (fulfilling our agreement with you)
To provide, maintain, and improve the TapTidy task management service.
Account Management
Legal Basis: Contract
To create and manage your account, authenticate access, and communicate about your account.
Analytics and Improvement
Legal Basis: Consent / Legitimate Interest
To understand usage patterns, improve features, and enhance user experience. We've conducted a Legitimate Interest Assessment (LIA) available upon request.
ClarityScorer Product Telemetry
Legal Basis: Legitimate Interest (Free tier only)
To calibrate TapTidy's task clarity scoring algorithm, we collect anonymous signal events that indicate which task quality signals triggered and which score bucket a task fell into. No task content, task titles, or user identifiers are included in these events. This telemetry is disabled by default for all Pro subscribers as part of the zero-telemetry guarantee. Free users may receive this telemetry unless they disable it in Settings → Account → ClarityScorer telemetry. We have conducted a Legitimate Interest Assessment (LIA) for this processing, available upon request at privacy@taptidy.app.
Security and Fraud Prevention
Legal Basis: Legitimate Interest
To protect our services, prevent abuse, and ensure security.
Service Reliability and Incident Response
Legal Basis: Legitimate Interest
To monitor service health, diagnose failures, investigate incidents, enforce rate limits, and maintain reliable operation using internal operational metrics and security logs.
Legal Compliance
Legal Basis: Legal Obligation
To comply with applicable laws, regulations, and legal processes.
Marketing Communications (Optional)
Legal Basis: Consent
To send promotional emails and updates (only with your explicit consent).
4. Data Recipients and Third Parties
We may share your data with the following categories of recipients:
- Cloud Hosting Providers: For infrastructure and data storage (Data Processing Agreements in place)
- Analytics Services: Our self-hosted Plausible instance (plausible.thinktank.systems, operated by Think Tank Systems) receives page view and interaction events only when you have consented to analytics cookies and have an analytics-enabled tier (Free). Pro subscribers have all analytics and telemetry disabled by default. Anonymous ClarityScorer signal events are transmitted under Legitimate Interest for Free users only and can be disabled in Settings. All analytics data is processed exclusively on infrastructure controlled by Think Tank Systems and is not shared with third parties.
- Operational Monitoring Systems: Internal monitoring and logging systems operated by Think Tank Systems process service-health metrics, request metadata, and security event logs solely for reliability, debugging, abuse prevention, and incident response.
- Email Service Providers: For transactional and (with consent) marketing emails
- Payment Processors: For handling subscription payments (if applicable)
- Calendar Providers: If you enable calendar integrations
- Legal Authorities: When required by law or to protect our rights
All third-party processors are bound by Data Processing Agreements (DPAs) compliant with General Data Protection Regulation (GDPR) Article 28.
5. International Data Transfers
Your data may be processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure adequate safeguards are in place:
- EU Standard Contractual Clauses (SCCs)
- Adequacy decisions by the European Commission
- Additional technical and organizational measures
6. Data Retention Periods
| Data Type | Retention Period |
|---|---|
| Account Data | Duration of account + 30 days after deletion |
| Task and Project Data | Duration of account + 30 days after deletion |
| Usage and Operational Logs | 90 days |
| Support Communications | 3 years |
| Analytics Data (anonymized) | 24 months |
| Marketing Consent Records | Duration of consent + 3 years |
Automated Deletion: We have implemented automated processes to delete data in accordance with these retention periods.
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
Right of Access
Request a copy of all personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data under certain conditions.
Right to Restriction of Processing
Request limiting how we use your data in specific situations.
Right to Data Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or for direct marketing.
Rights Related to Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
How to Exercise Your Rights
To exercise any of these rights, please contact us at privacy@taptidy.app
Response Timeframe: We will respond to your request within 30 days (extendable by 60 days for complex requests).
Identity Verification: We may require proof of identity to prevent unauthorized access.
8. Complaint Procedures
If you believe we have not handled your personal data properly, you have the right to lodge a complaint:
- Internal Complaint: First, contact us at privacy@taptidy.app. We will investigate and respond within 30 days.
- Supervisory Authority: You have the right to complain to your local data protection authority. In the EU, find your authority at EDPB Member List.
9. Data Breach Notification Procedure
In the event of a data breach that affects your personal data:
- Authority Notification: We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR Article 33).
- User Notification: If the breach poses a high risk to your rights and freedoms, we will notify you without undue delay, including:
- Nature of the breach
- Likely consequences
- Measures taken or proposed
- Contact point for more information
- Documentation: All breaches are documented internally, regardless of whether notification is required.
10. Data Processing Agreements (DPAs)
We have established Data Processing Agreements with all third-party processors that handle personal data on our behalf. These agreements ensure GDPR compliance and include:
- Processing instructions and restrictions
- Confidentiality obligations
- Security measures
- Sub-processor requirements
- Data subject rights assistance
- Audit rights
- Data return or deletion procedures
List of Processors: Available upon request at privacy@taptidy.app
11. Data Protection Impact Assessment (DPIA)
We have conducted a Data Protection Impact Assessment (DPIA) for our core processing activities to ensure high-risk processing is properly evaluated and mitigated.
A summary of our DPIA findings is available upon request by contacting dpo@taptidy.app.
12. Children's Privacy
TapTidy is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately at privacy@taptidy.app.
13. Security Measures
We implement appropriate technical and organizational measures to protect your data:
- Encryption of data in transit (TLS/SSL) and at rest
- Regular security audits and vulnerability assessments
- Access controls and authentication mechanisms
- Employee training on data protection
- Incident response procedures
- Regular backups with secure storage
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Email notification to your registered address
- Prominent notice on our website
- In-app notification
Your continued use of TapTidy after changes indicates acceptance of the updated policy.
15. Contact Information
For any privacy-related questions, requests, or concerns, please contact us:
Privacy Inquiries: privacy@taptidy.app
Data Protection Officer: dpo@taptidy.app
General Support: support@taptidy.app