Version 1.2 — Last updated: 22 September 2026

Data Processing Agreement

The Italian text is the binding version. This English version is provided for convenience. Agreement on the processing of personal data under GDPR art. 28. This Data Processing Agreement (“DPA”) forms an integral part of the DutyTask Terms and Conditions and governs the processing of Personal Data by DutyTask on behalf of the Customer in providing the Service.

1. Parties

This DPA is entered into between:

the Customer, being the business, professional, body or organisation that uses DutyTask and determines the purposes and essential means of processing Personal Data entered into the Service, hereafter the “Customer” or “controller”;

and

GR SOLUZIONI DI GIUSEPPE RICCIO Sole proprietorship VAT: 11121011214 REA: NA-1156478 Email: hello@dutytask.com

hereafter “DutyTask” or “processor”.

The identifying details of the business appear in the Naples Companies Register.

2. Subject matter and scope

DutyTask provides the Customer with a SaaS service for operational management of company tasks, assignments, due dates, recurrences, operational areas, attachments, issue reports, notifications, reports and task history.

To the extent those functions involve processing Personal Data entered by the Customer or its users for purposes determined by the Customer, DutyTask acts as processor under GDPR art. 28.

The Customer acts as controller.

This DPA does not cover processing for which DutyTask acts independently as controller, for example managing its commercial relationship with the Customer, billing, platform security, fraud prevention and tax or legal obligations. Those processing activities are described in the DutyTask Privacy Policy.

3. Duration

This DPA is effective for the entire contractual relationship between DutyTask and the Customer and, limited to obligations that by their nature survive termination, until complete deletion or return of Personal Data processed on behalf of the Customer.

The post-cancellation retention phase provided in article 14 forms, for the purposes of this DPA only, part of the Service delivery cycle.

4. Documented Customer instructions

DutyTask processes Personal Data solely:

  • to provide DutyTask according to the Terms and Conditions;
  • according to the configurations and operations performed by the Customer through the application;
  • according to further documented instructions lawfully given by the Customer;
  • or where processing is required by applicable law.

The Terms, this DPA, the settings used by the Customer in the platform and any written communications agreed with DutyTask constitute the Customer’s documented instructions.

If DutyTask believes a Customer instruction infringes the GDPR or other applicable data-protection law, it informs the Customer without undue delay, unless prohibited by law.

5. Customer obligations

The Customer warrants that it has the right to process and to entrust to DutyTask the Personal Data entered into the Service.

The Customer is responsible, in particular, for determining the purposes and legal bases of processing; for the information to be given to its employees, contractors and other data subjects; for the accuracy of data entered; for assigning roles and permissions to users; and for the lawfulness of any attachments, photographs, notes and other uploaded content.

The Customer undertakes not to use DutyTask to process special categories of personal data or highly sensitive data where that is not necessary for its operational purposes or where the legal conditions and safeguards required by applicable law are not met.

6. Authorised personnel and confidentiality

DutyTask ensures that persons authorised to process Personal Data on its behalf are subject to appropriate confidentiality obligations and have access to the data only to the extent needed to perform their duties.

Access to data must be limited on a need-to-know basis and to the minimum privileges required.

7. Security measures

DutyTask adopts technical and organisational measures appropriate to the risk, aimed at protecting Personal Data against destruction, loss, alteration, unauthorised disclosure or unlawful access.

The main measures currently adopted are described in Annex B.

DutyTask may change or improve its technical and organisational measures over time, provided the overall level of security is not substantially reduced.

The current product operation includes, among other things, isolation of data between organisations, private attachments and separation of permissions between owner/admin and staff.

8. Sub-processors

The Customer grants DutyTask a general authorisation to appoint sub-processors necessary to provide the Service.

DutyTask imposes on its sub-processors data-protection obligations substantially equivalent, so far as applicable to the nature of the service provided, to those in this DPA.

DutyTask remains responsible to the Customer for performance of the obligations under this DPA in relation to activities delegated to its sub-processors, within the limits of applicable law.

The current list of main sub-processors is in Annex C.

New sub-processors

DutyTask will inform the Customer of material changes to the list of sub-processors, by email, in-app notice or publication on the relevant Service page, with reasonable notice where possible.

The Customer may raise a reasoned objection on documented grounds relating to the protection of Personal Data.

The Parties will cooperate in good faith to find a reasonable solution. If it is not reasonably possible to resolve the objection without compromising provision of the Service, the Customer may stop using the specific function concerned or, where that is not possible, terminate the Service under the applicable contractual conditions.

This structure is consistent with the DPA practice of the main providers used by DutyTask: Vercel, for example, uses general sub-processor authorisation and substantially similar contractual obligations; Stripe and Supabase likewise incorporate a DPA into their contracts.

9. Data-subject rights

Taking into account the nature of the processing, DutyTask assists the Customer, so far as reasonably possible, in meeting obligations relating to the exercise of data-subject rights.

If DutyTask receives a request directly relating to Personal Data processed solely on behalf of the Customer, DutyTask may direct the data subject to the Customer or forward the request to the Customer, except where other legal obligations apply.

DutyTask does not respond independently on behalf of the Customer to data-subject requests, except for specific instructions or legal obligations.

10. Data breach

DutyTask informs the Customer without undue delay after becoming aware of a Personal Data breach processed on behalf of the Customer.

The notice will contain, to the extent the information is available:

  • the nature of the breach;
  • the categories of data and data subjects involved;
  • the possible consequences of the breach;
  • the measures taken or proposed to remedy it or limit its effects.

If not all information is immediately available, it may be provided progressively.

DutyTask cooperates reasonably with the Customer so that the Customer can meet its notification obligations to the supervisory authority or to data subjects.

11. Impact assessments and supervisory authorities

DutyTask, taking into account the nature of the processing and the information available to it, provides reasonable assistance to the Customer in relation to:

  • data-protection impact assessments;
  • prior consultation with authorities;
  • security measures;
  • handling of data breaches;
  • other obligations under GDPR articles 32–36.

Assistance involving extraordinary and significant activity beyond ordinary Service delivery may be the subject of a separate agreement, to the extent permitted by law.

12. Audit and compliance information

DutyTask makes available to the Customer the information reasonably necessary to demonstrate compliance with the obligations in GDPR art. 28.

The Customer may request relevant information or documentation relating to the measures adopted.

If the available information is not sufficient, the Customer may request an audit with reasonable notice.

Audits must be carried out so as not to compromise security, confidentiality, operation of the Service or data belonging to other customers.

Except in exceptional situations, well-founded suspicion of a breach, or requests of the competent authority, no more than one audit may be requested in any twelve-month period.

Any extraordinary and reasonable costs incurred by DutyTask for audits requested solely by the Customer may be charged by prior agreement.

13. International transfers

DutyTask’s primary database infrastructure is configured in the West EU (Ireland) region, AWS eu-west-1.

Some sub-processors may nevertheless process Personal Data outside the European Economic Area.

DutyTask ensures that such transfers are made on the basis of a mechanism provided by the GDPR, where necessary, including adequacy decisions, applicable Data Privacy Frameworks or the European Commission’s Standard Contractual Clauses.

The European Commission recognises SCCs as one of the instruments that can provide appropriate safeguards for transfers to third countries.

OpenAI, for example, provides in its DPA for the role of processor for Customer Data; for a customer established in the EEA the DPA is entered into with OpenAI Ireland Ltd.

14. Termination of the Service, return and deletion

On termination of the subscription, DutyTask stops ordinary operational access to the Service.

Retention period for reactivation

Unless the Customer instructs otherwise, the Customer authorises DutyTask to keep the organisation’s Personal Data for a maximum of 6 months from termination of the subscription, solely to allow possible reactivation of the account and recovery of the previously existing history.

During that period DutyTask does not use the Personal Data for purposes incompatible with that retention.

Early deletion

The Customer may, at any time during the six-month period, instruct DutyTask to proceed with early deletion of the data.

The request may be sent to:

hello@dutytask.com

DutyTask may carry out reasonable checks on the requester’s identity and authority.

Return of data

Before definitive deletion, the Customer may request return of the Personal Data by a reasonably usable export, taking into account the nature of the data and the technical functions of the Service.

Deletion after 6 months

After 6 months, if the account is not reactivated and unless different instructions or legal obligations apply, operational data are deleted.

Deletion covers, as applicable:

  • organisation accounts and profiles;
  • tasks and recurrences;
  • notes and history;
  • attachments;
  • operational areas;
  • associations between users and the organisation;
  • other data processed on behalf of the Customer.

Residual copies in backups may remain until overwritten according to the providers’ ordinary technical backup and disaster-recovery cycles, remaining protected and not used for other purposes.

This obligation does not cover data that DutyTask must keep independently as controller to meet legal, accounting or tax obligations or to protect its own rights.

15. Artificial intelligence

DutyTask uses OpenAI as a sub-processor for specific Service functions.

Dictation

When a manager uses voice dictation, the audio is transmitted for the transcription and interpretation needed to prepare the task.

DutyTask does not keep the audio after processing.

Daily AI Brief

To generate the Daily AI Brief, information relating to tasks and their statuses is transmitted to OpenAI, to the extent needed to produce the summary.

DutyTask uses OpenAI services intended for businesses and developers. OpenAI’s current DPA governs processing of Customer Data as processor, and OpenAI states that business/API data are not used to train models by default.

The Customer authorises that processing as part of the AI functions it chooses to use.

16. Liability of the Parties

Each Party is responsible for meeting the obligations that apply to it under the GDPR and other applicable rules.

Contractual liability between DutyTask and the Customer remains subject to the limitations in the Terms and Conditions, to the extent permitted by law.

Nothing in this DPA limits data-subject rights or liabilities that cannot be excluded under the GDPR.

17. Precedence

In case of conflict between this DPA and the DutyTask Terms and Conditions relating to processing of Personal Data by DutyTask as processor, this DPA prevails.

For every other matter the Terms and Conditions continue to apply.

18. Governing law

This DPA is governed by Italian law and the GDPR.

For contractual matters not governed by the GDPR or mandatory provisions, the governing-law and venue provisions in the DutyTask Terms and Conditions apply.

Annex A — Details of processing

A.1 Subject matter

Processing of Personal Data necessary to provide the DutyTask SaaS service to the Customer.

A.2 Duration

For the duration of the subscription and, after termination, for the maximum 6-month retention period provided to allow reactivation, unless early deletion is requested, the account is reactivated, or applicable legal obligations apply.

A.3 Nature of operations

Processing may include:

  • collection;
  • recording;
  • organisation;
  • structuring;
  • storage;
  • consultation;
  • display;
  • updating;
  • transmission;
  • processing;
  • generation of notifications and reports;
  • processing through AI functions;
  • export;
  • restriction;
  • deletion.

A.4 Purposes

To provide the DutyTask functions requested by the Customer, including management of users, tasks, assignments, recurrences, operational areas, due dates, problem reports, attachments, notifications, reports, history and AI functions.

A.5 Categories of data subjects

Those who may be concerned by the processing include:

  • the Customer’s employees;
  • contractors;
  • administrators;
  • managers of teams, departments or sites;
  • the organisation owner;
  • other users invited by the Customer;
  • any people whose data are lawfully entered by the Customer in attachments, notes or tasks.

A.6 Categories of Personal Data

The following may be processed:

  • first name and last name;
  • email address;
  • role and organisational belonging;
  • operational area;
  • data relating to assigned tasks;
  • dates, due dates and times;
  • task status;
  • information on reported problems and related solutions;
  • notes;
  • history of operations;
  • attachments and photographs;
  • data relating to involvements and assignments;
  • technical identifiers;
  • data relating to notifications;
  • content transmitted to AI functions.

Product tasks and their histories are designed so that staff cannot arbitrarily rewrite events already recorded.

A.7 Special categories of data

DutyTask is not designed specifically for systematic processing of special categories of personal data under GDPR art. 9.

The Customer must avoid entering such data except where strictly necessary and, if it processes them, remains responsible for having an adequate legal basis and the further safeguards required.

Annex B — Technical and organisational measures

The measures currently implemented or provided for by the DutyTask architecture include:

AreaMeasure
Encryption in transitHTTPS/TLS connections
AuthenticationAccounts managed through Supabase Auth
Access controlOwner, admin and staff roles with differentiated permissions
Tenant separationData associated with and isolated by organisation
DatabaseSupabase, primary region West EU (Ireland), eu-west-1
FilesPrivate storage; attachment access via authorisation and signed URLs
PasswordsUser passwords are not chosen by the owner on behalf of invitees
HistoryAppend-only operational history relative to ordinary user functions
PaymentsFull card data are not stored by DutyTask; payments are handled by Stripe
VoiceAudio used for dictation is not kept by DutyTask after processing
PermissionsStaff cannot access the global dashboard, billing, reports, people or administration
Backup/infrastructureRelies on the mechanisms and services of the applicable infrastructure providers
Push notificationsEnabled by the user and handled through dedicated technical identifiers
Internal operational accessLimited to authorised personnel as needed
DeletionDeletion after 6 months, or earlier on request

DutyTask may progressively add further measures, including stronger authentication functions, monitoring and additional security controls.

Annex C — Authorised sub-processors

ProviderService / purposeLocation / transfers
SupabaseAuthentication (including invite and password-reset email), database, file storagePrimary DutyTask project: West EU (Ireland), eu-west-1; any further processing according to Supabase’s DPA and sub-processor list
VercelHosting, deployment and delivery of the applicationMay involve international processing according to Vercel’s DPA and transfer mechanisms
StripePayments and subscriptionsMay act as processor or independent controller under Stripe’s DPA; transfers under DPF and SCCs
OpenAIVoice transcription, task interpretation, Daily AI BriefFor EEA customers, DPA relationship with OpenAI Ireland Ltd.; possible processing by OpenAI sub-processors according to the relevant DPA and transfer mechanisms

Supabase also publishes in its DPA the list of its own sub-processors, including AWS for hosting. Vercel publishes and updates its sub-processor list and provides substantially similar contractual obligations for them. Stripe publishes a DPA and the applicable transfer safeguards. OpenAI likewise publishes the current list of sub-processors used for API and business services. Push notifications use the Web Push protocol (VAPID) to the user’s browser and are not an email service.