Last updated: 22 September 2026

DutyTask Privacy Policy

The Italian text is the binding version. This English version is provided for convenience.

1. Controller

DutyTask is a service offered by:

GR SOLUZIONI DI GIUSEPPE RICCIO Sole proprietorship VAT: 11121011214 REA: NA-1156478 Email: hello@dutytask.com

Below, “DutyTask”, “we” or the “Controller” mean GR SOLUZIONI DI GIUSEPPE RICCIO.

2. Scope

This Privacy Policy describes the processing of personal data carried out through the DutyTask website and application.

It applies to website visitors, owners and administrators of registered companies, employees and other users authorised to use the service, and people who contact DutyTask for support, commercial information or other requests.

DutyTask is designed primarily for professional and business use.

3. Privacy roles

For data relating to account registration, the commercial relationship, billing, service security, support and platform administration, GR SOLUZIONI DI GIUSEPPE RICCIO generally acts as controller.

When a company uses DutyTask to manage data relating to its employees, contractors, operational tasks, attachments and related history, the customer company generally determines the purposes of processing and acts as controller, while DutyTask processes that information on its behalf as processor.

Processing by DutyTask on behalf of customer companies must be governed by an agreement under GDPR art. 28.

The customer company remains responsible for the lawfulness of data entered into DutyTask and for informing its own employees and contractors.

4. Categories of data

DutyTask may process the following categories of data.

Account and identifiers: first name, last name, email, role, organisation and technical authentication credentials.

Company data: organisation name, sector, country, settings, subscribed plan, operational areas and invited users.

Operational data: task titles and contents, due dates, assignments, recurrences, priorities, statuses, reported problems and solutions, notes, involvements, date and time of operations.

Attachments: files, images or photographs uploaded by users in connection with tasks.

Operational history: information about who performed an action and when.

Technical data: IP address, session data, browser or device information, technical logs and information needed for security and operation of the service.

Notification data: technical identifiers needed to send push notifications when the user enables this function.

Commercial and payment data: subscribed plan, subscription status, Stripe identifiers, billing data and any tax information required.

Communications: data in support or other contact requests.

5. Operational history

DutyTask is designed to keep a history of work carried out inside the organisation.

Ordinary users cannot arbitrarily rewrite or delete history events through the product’s normal functions. This lets the customer reconstruct what happened.

Keeping a history does not mean data are stored indefinitely. Retention follows the dedicated section of this notice.

6. Voice dictation

Managers can use dictation to create tasks by voice.

When this function is used, the audio is sent to the AI service used by DutyTask to transcribe and interpret the request.

The AI may propose, for example, title, assignee, due time, recurrence or an attachment requirement.

DutyTask does not keep the audio recording after processing.

The AI proposal is shown to the manager, who can review it before the task is created.

7. Daily AI Brief

DutyTask may use AI systems to generate an operational summary for managers.

To generate the Daily AI Brief, information about tasks and their statuses is sent to the AI provider to the extent needed for the summary.

The service currently used for these functions is OpenAI.

OpenAI provides a Data Processing Addendum for business and developer services and states that it acts as processor of Customer Data processed on the customer’s behalf; company/API data are not used to train models by default.

DutyTask does not use AI functions to take solely automated decisions producing legal or similarly significant effects on users.

8. Purposes and legal bases

Data are processed to:

  • create and manage accounts and organisations;
  • authenticate users;
  • provide DutyTask’s operational functions;
  • manage tasks, recurrences, attachments, notifications, reports and history;
  • provide requested dictation and AI functions;
  • manage the free trial, subscriptions and payments;
  • provide support;
  • protect accounts, data and infrastructure;
  • prevent abuse, fraud and unauthorised access;
  • comply with administrative, tax, accounting and legal obligations;
  • establish, exercise or defend rights.

Depending on the case, processing is based on performance of a contract or pre-contractual steps, legal obligations, or legitimate interest in the security and proper operation of the service.

9. Providing data

Data needed to create the account and provide DutyTask are required to use the service.

Failure to provide them may prevent registration or use of some functions.

Functions that need device permissions, such as the microphone or push notifications, remain optional.

10. Providers

DutyTask currently uses these main technical providers:

Supabase

Authentication, database and file storage.

The main DutyTask project is configured in West EU (Ireland), eu-west-1. Supabase confirms that the chosen region determines the primary location of project data.

Vercel

Hosting and delivery of the application.

Supabase Auth (email)

Invites and password resets are sent through Supabase Auth. DutyTask does not use Resend or another separate transactional-email vendor.

Push notifications

Device notifications use the Web Push protocol (VAPID) to the user’s browser. This is not an email service.

OpenAI

Dictation transcription and generation of the Daily AI Brief.

Stripe

Payments and subscriptions.

Stripe may act, depending on the processing, as processor or as independent controller and provides its own Data Processing Agreement.

The list of providers may be updated if the technical architecture of the service changes.

11. Payments

DutyTask subscription payments are handled through Stripe.

DutyTask does not collect or store full payment-card data.

Stripe may process, among other information, name, email, billing address, tax identifiers, payment data and payment-method data needed for the transaction.

DutyTask keeps the information needed to know the subscribed plan, subscription status and the technical identifiers required for the Stripe integration.

12. International transfers

DutyTask’s primary database is hosted in Ireland, in the European Union.

Some providers used by DutyTask are international organisations and may process data outside the European Economic Area.

Where required, those transfers are governed by the mechanisms provided by applicable law, including the Data Privacy Framework, adequacy decisions and Standard Contractual Clauses.

Vercel, for example, provides in its DPA for use of the 2021 SCCs for transfers subject to those clauses. Stripe uses DPF and SCCs under applicable conditions. Supabase uses SCCs and other mechanisms in its DPA for extra-EEA transfers.

13. Retention

While a subscription is active, organisation data are kept to provide DutyTask.

After cancellation

When the Customer cancels the subscription, DutyTask keeps the organisation’s operational data for a maximum of 6 months after the service ends.

This retention is so the Customer can reactivate DutyTask within that period and find previously present tasks, users and history.

After 6 months, the organisation’s operational data are deleted, except information DutyTask must keep longer for legal, administrative, tax, accounting obligations or to protect its rights.

Early deletion on request

The organisation owner or a duly authorised person may request early deletion without waiting for the 6 months by writing to:

hello@dutytask.com

DutyTask may carry out reasonable checks on the requester’s identity and authority before proceeding.

Once definitive deletion is completed, the organisation and its operational history cannot be recovered.

Data that must be kept by law or to protect rights in legal proceedings are excluded from deletion.

The GDPR recognises the right to erasure where the conditions are met and specifically governs return or deletion of data in processor relationships.

Any technical copies in backup systems may be removed according to the providers’ normal backup and disaster-recovery cycles.

The audio recording used for dictation is not kept by DutyTask after processing.

14. Cookies and technical technologies

DutyTask does not currently use Google Analytics, Meta Pixel or other advertising or profiling systems.

DutyTask stores first-party product events internally (for example first task created, first invite, trial converting to a paid plan) to see whether the service is used. These events stay in DutyTask’s database, are not shared with advertising platforms and do not profile people outside the company.

Only technologies needed to run the service are used, including tools to keep the authenticated session and language/locale preferences.

Strictly technical cookies and tools do not require prior consent when used solely for purposes necessary to the service; the Italian Data Protection Authority distinguishes these from profiling or tracking tools.

If DutyTask later introduces analytics or marketing tools that require consent, the consent collection methods and this notice will be updated before they are activated.

15. Security

DutyTask adopts technical and organisational measures to protect processed data.

These include user authentication, HTTPS, logical separation of data between organisations, role-based access controls and private storage of attachments.

Supabase also provides a DPA and tools for projects with GDPR requirements.

No computer system can guarantee absolute security.

16. Data-subject rights

Where applicable law so provides, the data subject may exercise the rights of:

  • access;
  • rectification;
  • erasure;
  • restriction of processing;
  • portability;
  • objection.

Where processing is based on consent, consent may be withdrawn at any time.

Requests may be sent to:

hello@dutytask.com

When the request concerns data processed by DutyTask on behalf of a customer company, DutyTask may forward the request to the company acting as controller or cooperate with it so it can respond.

The data subject may also lodge a complaint with the Garante per la protezione dei dati personali.

17. Changes to this Privacy Policy

DutyTask may update this Privacy Policy following legal, technical, organisational or provider changes.

The updated version will be made available on the site, with the update date.

In case of material changes, DutyTask may also inform users by email or in-app notice.