Version 1.2 — Last updated: 22 September 2026
Data Processing Agreement
The Italian text is the binding version. This English version is provided for convenience. Agreement on the processing of personal data under GDPR art. 28. This Data Processing Agreement (“DPA”) forms an integral part of the DutyTask Terms and Conditions and governs the processing of Personal Data by DutyTask on behalf of the Customer in providing the Service.
1. Parties
This DPA is entered into between:
the Customer, being the business, professional, body or organisation that uses DutyTask and determines the purposes and essential means of processing Personal Data entered into the Service, hereafter the “Customer” or “controller”;
and
GR SOLUZIONI DI GIUSEPPE RICCIO Sole proprietorship VAT: 11121011214 REA: NA-1156478 Email: hello@dutytask.com
hereafter “DutyTask” or “processor”.
The identifying details of the business appear in the Naples Companies Register.
2. Subject matter and scope
DutyTask provides the Customer with a SaaS service for operational management of company tasks, assignments, due dates, recurrences, operational areas, attachments, issue reports, notifications, reports and task history.
To the extent those functions involve processing Personal Data entered by the Customer or its users for purposes determined by the Customer, DutyTask acts as processor under GDPR art. 28.
The Customer acts as controller.
This DPA does not cover processing for which DutyTask acts independently as controller, for example managing its commercial relationship with the Customer, billing, platform security, fraud prevention and tax or legal obligations. Those processing activities are described in the DutyTask Privacy Policy.
3. Duration
This DPA is effective for the entire contractual relationship between DutyTask and the Customer and, limited to obligations that by their nature survive termination, until complete deletion or return of Personal Data processed on behalf of the Customer.
The post-cancellation retention phase provided in article 14 forms, for the purposes of this DPA only, part of the Service delivery cycle.
4. Documented Customer instructions
DutyTask processes Personal Data solely:
- to provide DutyTask according to the Terms and Conditions;
- according to the configurations and operations performed by the Customer through the application;
- according to further documented instructions lawfully given by the Customer;
- or where processing is required by applicable law.
The Terms, this DPA, the settings used by the Customer in the platform and any written communications agreed with DutyTask constitute the Customer’s documented instructions.
If DutyTask believes a Customer instruction infringes the GDPR or other applicable data-protection law, it informs the Customer without undue delay, unless prohibited by law.
5. Customer obligations
The Customer warrants that it has the right to process and to entrust to DutyTask the Personal Data entered into the Service.
The Customer is responsible, in particular, for determining the purposes and legal bases of processing; for the information to be given to its employees, contractors and other data subjects; for the accuracy of data entered; for assigning roles and permissions to users; and for the lawfulness of any attachments, photographs, notes and other uploaded content.
The Customer undertakes not to use DutyTask to process special categories of personal data or highly sensitive data where that is not necessary for its operational purposes or where the legal conditions and safeguards required by applicable law are not met.
6. Authorised personnel and confidentiality
DutyTask ensures that persons authorised to process Personal Data on its behalf are subject to appropriate confidentiality obligations and have access to the data only to the extent needed to perform their duties.
Access to data must be limited on a need-to-know basis and to the minimum privileges required.
7. Security measures
DutyTask adopts technical and organisational measures appropriate to the risk, aimed at protecting Personal Data against destruction, loss, alteration, unauthorised disclosure or unlawful access.
The main measures currently adopted are described in Annex B.
DutyTask may change or improve its technical and organisational measures over time, provided the overall level of security is not substantially reduced.
The current product operation includes, among other things, isolation of data between organisations, private attachments and separation of permissions between owner/admin and staff.
8. Sub-processors
The Customer grants DutyTask a general authorisation to appoint sub-processors necessary to provide the Service.
DutyTask imposes on its sub-processors data-protection obligations substantially equivalent, so far as applicable to the nature of the service provided, to those in this DPA.
DutyTask remains responsible to the Customer for performance of the obligations under this DPA in relation to activities delegated to its sub-processors, within the limits of applicable law.
The current list of main sub-processors is in Annex C.
New sub-processors
DutyTask will inform the Customer of material changes to the list of sub-processors, by email, in-app notice or publication on the relevant Service page, with reasonable notice where possible.
The Customer may raise a reasoned objection on documented grounds relating to the protection of Personal Data.
The Parties will cooperate in good faith to find a reasonable solution. If it is not reasonably possible to resolve the objection without compromising provision of the Service, the Customer may stop using the specific function concerned or, where that is not possible, terminate the Service under the applicable contractual conditions.
This structure is consistent with the DPA practice of the main providers used by DutyTask: Vercel, for example, uses general sub-processor authorisation and substantially similar contractual obligations; Stripe and Supabase likewise incorporate a DPA into their contracts.
9. Data-subject rights
Taking into account the nature of the processing, DutyTask assists the Customer, so far as reasonably possible, in meeting obligations relating to the exercise of data-subject rights.
If DutyTask receives a request directly relating to Personal Data processed solely on behalf of the Customer, DutyTask may direct the data subject to the Customer or forward the request to the Customer, except where other legal obligations apply.
DutyTask does not respond independently on behalf of the Customer to data-subject requests, except for specific instructions or legal obligations.
10. Data breach
DutyTask informs the Customer without undue delay after becoming aware of a Personal Data breach processed on behalf of the Customer.
The notice will contain, to the extent the information is available:
- the nature of the breach;
- the categories of data and data subjects involved;
- the possible consequences of the breach;
- the measures taken or proposed to remedy it or limit its effects.
If not all information is immediately available, it may be provided progressively.
DutyTask cooperates reasonably with the Customer so that the Customer can meet its notification obligations to the supervisory authority or to data subjects.
11. Impact assessments and supervisory authorities
DutyTask, taking into account the nature of the processing and the information available to it, provides reasonable assistance to the Customer in relation to:
- data-protection impact assessments;
- prior consultation with authorities;
- security measures;
- handling of data breaches;
- other obligations under GDPR articles 32–36.
Assistance involving extraordinary and significant activity beyond ordinary Service delivery may be the subject of a separate agreement, to the extent permitted by law.
12. Audit and compliance information
DutyTask makes available to the Customer the information reasonably necessary to demonstrate compliance with the obligations in GDPR art. 28.
The Customer may request relevant information or documentation relating to the measures adopted.
If the available information is not sufficient, the Customer may request an audit with reasonable notice.
Audits must be carried out so as not to compromise security, confidentiality, operation of the Service or data belonging to other customers.
Except in exceptional situations, well-founded suspicion of a breach, or requests of the competent authority, no more than one audit may be requested in any twelve-month period.
Any extraordinary and reasonable costs incurred by DutyTask for audits requested solely by the Customer may be charged by prior agreement.
13. International transfers
DutyTask’s primary database infrastructure is configured in the West EU (Ireland) region, AWS eu-west-1.
Some sub-processors may nevertheless process Personal Data outside the European Economic Area.
DutyTask ensures that such transfers are made on the basis of a mechanism provided by the GDPR, where necessary, including adequacy decisions, applicable Data Privacy Frameworks or the European Commission’s Standard Contractual Clauses.
The European Commission recognises SCCs as one of the instruments that can provide appropriate safeguards for transfers to third countries.
OpenAI, for example, provides in its DPA for the role of processor for Customer Data; for a customer established in the EEA the DPA is entered into with OpenAI Ireland Ltd.
14. Termination of the Service, return and deletion
On termination of the subscription, DutyTask stops ordinary operational access to the Service.
Retention period for reactivation
Unless the Customer instructs otherwise, the Customer authorises DutyTask to keep the organisation’s Personal Data for a maximum of 6 months from termination of the subscription, solely to allow possible reactivation of the account and recovery of the previously existing history.
During that period DutyTask does not use the Personal Data for purposes incompatible with that retention.
Early deletion
The Customer may, at any time during the six-month period, instruct DutyTask to proceed with early deletion of the data.
The request may be sent to:
hello@dutytask.com
DutyTask may carry out reasonable checks on the requester’s identity and authority.
Return of data
Before definitive deletion, the Customer may request return of the Personal Data by a reasonably usable export, taking into account the nature of the data and the technical functions of the Service.
Deletion after 6 months
After 6 months, if the account is not reactivated and unless different instructions or legal obligations apply, operational data are deleted.
Deletion covers, as applicable:
- organisation accounts and profiles;
- tasks and recurrences;
- notes and history;
- attachments;
- operational areas;
- associations between users and the organisation;
- other data processed on behalf of the Customer.
Residual copies in backups may remain until overwritten according to the providers’ ordinary technical backup and disaster-recovery cycles, remaining protected and not used for other purposes.
This obligation does not cover data that DutyTask must keep independently as controller to meet legal, accounting or tax obligations or to protect its own rights.
15. Artificial intelligence
DutyTask uses OpenAI as a sub-processor for specific Service functions.
Dictation
When a manager uses voice dictation, the audio is transmitted for the transcription and interpretation needed to prepare the task.
DutyTask does not keep the audio after processing.
Daily AI Brief
To generate the Daily AI Brief, information relating to tasks and their statuses is transmitted to OpenAI, to the extent needed to produce the summary.
DutyTask uses OpenAI services intended for businesses and developers. OpenAI’s current DPA governs processing of Customer Data as processor, and OpenAI states that business/API data are not used to train models by default.
The Customer authorises that processing as part of the AI functions it chooses to use.
16. Liability of the Parties
Each Party is responsible for meeting the obligations that apply to it under the GDPR and other applicable rules.
Contractual liability between DutyTask and the Customer remains subject to the limitations in the Terms and Conditions, to the extent permitted by law.
Nothing in this DPA limits data-subject rights or liabilities that cannot be excluded under the GDPR.
17. Precedence
In case of conflict between this DPA and the DutyTask Terms and Conditions relating to processing of Personal Data by DutyTask as processor, this DPA prevails.
For every other matter the Terms and Conditions continue to apply.
18. Governing law
This DPA is governed by Italian law and the GDPR.
For contractual matters not governed by the GDPR or mandatory provisions, the governing-law and venue provisions in the DutyTask Terms and Conditions apply.
Annex A — Details of processing
A.1 Subject matter
Processing of Personal Data necessary to provide the DutyTask SaaS service to the Customer.
A.2 Duration
For the duration of the subscription and, after termination, for the maximum 6-month retention period provided to allow reactivation, unless early deletion is requested, the account is reactivated, or applicable legal obligations apply.
A.3 Nature of operations
Processing may include:
- collection;
- recording;
- organisation;
- structuring;
- storage;
- consultation;
- display;
- updating;
- transmission;
- processing;
- generation of notifications and reports;
- processing through AI functions;
- export;
- restriction;
- deletion.
A.4 Purposes
To provide the DutyTask functions requested by the Customer, including management of users, tasks, assignments, recurrences, operational areas, due dates, problem reports, attachments, notifications, reports, history and AI functions.
A.5 Categories of data subjects
Those who may be concerned by the processing include:
- the Customer’s employees;
- contractors;
- administrators;
- managers of teams, departments or sites;
- the organisation owner;
- other users invited by the Customer;
- any people whose data are lawfully entered by the Customer in attachments, notes or tasks.
A.6 Categories of Personal Data
The following may be processed:
- first name and last name;
- email address;
- role and organisational belonging;
- operational area;
- data relating to assigned tasks;
- dates, due dates and times;
- task status;
- information on reported problems and related solutions;
- notes;
- history of operations;
- attachments and photographs;
- data relating to involvements and assignments;
- technical identifiers;
- data relating to notifications;
- content transmitted to AI functions.
Product tasks and their histories are designed so that staff cannot arbitrarily rewrite events already recorded.
A.7 Special categories of data
DutyTask is not designed specifically for systematic processing of special categories of personal data under GDPR art. 9.
The Customer must avoid entering such data except where strictly necessary and, if it processes them, remains responsible for having an adequate legal basis and the further safeguards required.
Annex B — Technical and organisational measures
The measures currently implemented or provided for by the DutyTask architecture include:
| Area | Measure |
|---|---|
| Encryption in transit | HTTPS/TLS connections |
| Authentication | Accounts managed through Supabase Auth |
| Access control | Owner, admin and staff roles with differentiated permissions |
| Tenant separation | Data associated with and isolated by organisation |
| Database | Supabase, primary region West EU (Ireland), eu-west-1 |
| Files | Private storage; attachment access via authorisation and signed URLs |
| Passwords | User passwords are not chosen by the owner on behalf of invitees |
| History | Append-only operational history relative to ordinary user functions |
| Payments | Full card data are not stored by DutyTask; payments are handled by Stripe |
| Voice | Audio used for dictation is not kept by DutyTask after processing |
| Permissions | Staff cannot access the global dashboard, billing, reports, people or administration |
| Backup/infrastructure | Relies on the mechanisms and services of the applicable infrastructure providers |
| Push notifications | Enabled by the user and handled through dedicated technical identifiers |
| Internal operational access | Limited to authorised personnel as needed |
| Deletion | Deletion after 6 months, or earlier on request |
DutyTask may progressively add further measures, including stronger authentication functions, monitoring and additional security controls.
Annex C — Authorised sub-processors
| Provider | Service / purpose | Location / transfers |
|---|---|---|
| Supabase | Authentication (including invite and password-reset email), database, file storage | Primary DutyTask project: West EU (Ireland), eu-west-1; any further processing according to Supabase’s DPA and sub-processor list |
| Vercel | Hosting, deployment and delivery of the application | May involve international processing according to Vercel’s DPA and transfer mechanisms |
| Stripe | Payments and subscriptions | May act as processor or independent controller under Stripe’s DPA; transfers under DPF and SCCs |
| OpenAI | Voice transcription, task interpretation, Daily AI Brief | For EEA customers, DPA relationship with OpenAI Ireland Ltd.; possible processing by OpenAI sub-processors according to the relevant DPA and transfer mechanisms |
Supabase also publishes in its DPA the list of its own sub-processors, including AWS for hosting. Vercel publishes and updates its sub-processor list and provides substantially similar contractual obligations for them. Stripe publishes a DPA and the applicable transfer safeguards. OpenAI likewise publishes the current list of sub-processors used for API and business services. Push notifications use the Web Push protocol (VAPID) to the user’s browser and are not an email service.
Le texte juridiquement contraignant du DPA, de la confidentialité et des conditions est l’italien. Cette page en anglais est une traduction de convenance.

