Terms of Service, DPA & TOMs
General Terms and Conditions of Taskbase
Version Date: 9.09.2026
1. Subject Matter
These General Terms and Conditions of Taskbase (“GTC”) are applicable to all services (“Services”) that Taskbase AG, Zahnradstrasse 22, 8005 Zürich, Switzerland (“Taskbase”) provides to its customers (“Customer”) (Taskbase and the Customer each individually a “Party” and jointly the “Parties”).
The Customer agrees to the application of these GTC by accepting Taskbase\’s offer or by signing a service agreement or any other agreement with Taskbase in which reference is made to these GTC (such offer, service agreement or other agreement together with all further contractual documents, including these GTC, the “Service Agreement”), whereby a contract is concluded between the Parties.
The application of any general terms and conditions of the Customer is herewith expressly excluded unless stated otherwise in the Service Agreement.
2. Taskbase’s Services
Taskbase shall provide the Services in accordance with the Service Agreement (including its annexes).
Taskbase shall be free to organize the manner in which it provides the Services, unless specified otherwise in the Service Agreement. It shall however be obliged to consult with the Customer and other parties involved, as required for the applicable project.
Taskbase is entitled to engage third parties and auxiliary persons (in particular subcontractors) for the purpose of providing the Services and meeting its contractual obligations.
3. Customer’s Duties of Cooperation
The Customer shall, by all reasonable means, to the extent necessary, and in a timely manner, actively support Taskbase, its employees and any third parties engaged by Taskbase for the purpose of providing the Services, cooperate in taking the necessary preparatory and provisioning actions (including the procurement of all requisite rights and authorizations), provide all relevant information and grant the necessary access to its systems and resources.
In addition, the specific duties of cooperation as set out in the Service Agreement apply.
The Customer shall bear all costs incurred by it in the course of fulfilling its duties of cooperation.
Taskbase shall attempt to perform the Services even if the Customer fails to comply with its duties of cooperation as agreed upon in the Service Agreement. Should this occur, Taskbase shall inform the Customer promptly and set a reasonable grace period in order to comply with the relevant duties that the Customer has not or not been properly complied with, and Taskbase shall state the consequences that may be expected for the Customer in the event of failure to comply with the relevant duties of cooperation within the grace period. If, upon expiry of the grace period, compliance has not been restored by the Customer, Taskbase has the right to suspend the Services with immediate effect and/or to terminate the Service Agreement for cause.
In the event of non-fulfilment or improper fulfilment of the Customer’s duties of cooperation, in addition to the remedies stated above, the Customer shall compensate Taskbase for the resulting additional efforts at the standard hourly rates of Taskbase as stated in the Service Agreement.
4. Duty to Provide Information
Each Party shall inform the other Party promptly of any circumstances, developments, incidents and findings that may be relevant for the other Party in connection with the performance of the Service Agreement or with the contractual relationship as such, unless prohibited by statutory or contractual confidentiality obligations.
5. Fees, Payment and Expenses
The fees for the provision of the Services are specified in the Service Agreement.
Invoices are payable net within 30 days net as of receipt. The Customer shall be in default upon expiry of the payment period without further ado. The statutory rate of default interest shall apply. If the Customer defaults on a payment, Taskbase has the right to suspend the provision of the Services until receipt of payment in full of all outstanding invoices. All fees are exclusive of value added tax (VAT) and any other taxes, duties and charges.
Unless otherwise agreed, any expenses (i.e. all necessary and reasonable out-of-pocket expenses, including, but not limited to travel, lodging, meals, and other business expenses incurred by Taskbase in the provision of the Services, all together the “Expenses”) shall be borne by the Customer.
If the Customer does not agree with the prices or expenses invoiced (the “Billing Dispute”), it must notify Taskbase in text form within 10 days of receipt of the respective invoice, stating the reasons and the type and amount of the disputed prices (the “Billing Dispute Notice”). The Customer shall cooperate with Taskbase to promptly address and attempt to resolve any Billing Dispute submitted in accordance herewith. The Customer acknowledges and agrees that in the event that the Customer does not submit a Billing Dispute Notice in accordance with the foregoing, the Customer waives all rights to dispute such invoice, and all fees and Expenses set forth in such invoice will be considered correct and binding on the Customer. In case of a Billing Dispute, the Customer shall remain obligated to pay all undisputed fees and Expenses.
6. Default by Taskbase
Contractually agreed deadlines shall be deemed met upon provisioning of the relevant Services by Taskbase.
If Taskbase fails to comply with a material contractual deadline set forth in the Service Agreement, Taskbase shall be in default upon expiry of a reasonable grace period set by the Customer in a written reminder (e-mail sufficient). If Taskbase fails to fulfil its performance obligation by the expiry date of this grace period, the Customer has the right to withdraw from the Service Agreement. Any Services (or parts thereof) that have already been provided substantially in accordance with the Service Agreement and that can be used by the Customer as such in an objectively reasonable manner must be paid for in full. Any withdrawal from the Service Agreement shall not affect these Services.
7. Acceptance Procedure for One-Time Services
7.1 General
In case the Parties agree in the Service Agreement on specific results of performance and the corresponding acceptance criteria (contract for work and services, “Werkvertrag”), then Taskbase’s duty to deliver shall be met upon the Customer’s acceptance of such work results in accordance with the acceptance criteria. The Customer shall declare acceptance in text form (e-mail sufficient). The work results shall, in the absence of any express written declaration to the contrary by the Customer, be deemed to have been accepted following operational use of the work results by the Customer during at least 30 days.
If the Parties agree to the acceptance of partial work results, the acceptance thereof shall be subject to final acceptance. Upon successful final acceptance, the warranty periods shall commence.
7.2 Failure of Acceptance
Acceptance shall be deferred, if acceptance testing by the Customer identifies major defects. The Customer is obliged to provide Taskbase with evidence of any such major defects claimed by it and to reproduce them if possible. Taskbase shall rectify the defects within a reasonable time period, taking into account the cause and nature of the defect, and once again provide the relevant deliverable for acceptance by the Customer.
If the defect cannot be remedied within a time period appropriate to the cause and nature of the defect, the Customer shall set a reasonable grace period for the remedying of the defect. If the remedying definitely fails, the Customer is entitled to (a) demand an appropriate reduction of the respective fees, or (b) withdraw from the Service Agreement in the case of a substantial defect that prevents the Customer from using the deliverable in its entirety. Those Services or parts thereof which have already been provided substantially in accordance with the Service Agreement and which can be used by the Customer as such in an objectively reasonable manner must be paid in full. Any withdrawal from the Service Agreement shall not affect these Services and they shall remain subject to the relevant provisions of the Service Agreement.
Minor defects shall not entitle the Customer to refuse acceptance, but such defects must be rectified by Taskbase within a reasonable grace period set by the Customer.
8. Warranty
8.1 Recurring / Operational Services
Taskbase will provide the Services in a professional and diligent manner. If a Service Level Agreement (SLA) forms part of the Service Agreement, then the relevant provisions of the SLA apply. In the absence of any agreement to the contrary in the Service Agreement (including the SLA), there are no representations or warranties as to the availability, quality, security, operation or support of the Services. The Services are provided on a “best effort” basis. In the event of failures, malfunctions and delays, Taskbase shall use its available resources in a reasonable and customary manner to provide the Services or remedy the failures or malfunctions, without, however, giving any assurances in this respect.
8.2 One-Time Services
Taskbase warrants that the Services conform to the contractually agreed specifications. The warranty period is 12 months as of the date of acceptance (in accordance with section 7 of these GTC).
Defects must be stated in text form (e-mail sufficient) in a comprehensible form with evidence of the relevant defects and all information useful for identifying the defects. The Customer is obliged to reproduce the defects if possible.
In case of a defect covered by the warranty, the Customer may first demand that the defect shall be remedied free of charge. The Customer shall support Taskbase in the remedying of defects to the extent necessary. If the defect cannot be remedied within a time period appropriate to the cause and nature of the defect, the Customer shall set a reasonable grace period for the remedying of the defect. If the remedying definitely fails, the Customer is entitled to (a) demand an appropriate reduction of the respective fees, or (b) withdraw from the Agreement in the case of a substantial defect that prevents the Customer from using the deliverable in its entirety. Those Services or parts thereof which have already been provided substantially in accordance with the Service Agreement and which can be used by the Customer as such in an objectively reasonable manner must be paid in full. Any withdrawal from the Service Agreement shall not affect these Services and they shall remain subject to the relevant provisions of the Service Agreement.
In the event of defects that cannot be remedied in the short term, Taskbase has the right to provide the Customer with a temporary solution (workaround).
8.3 Warranty of Title
Taskbase warrants that the Services do not infringe any intellectual property rights of third parties which exclude or restrict the contractual use of the Services by the Customer.
If a third party attempts to prevent the Customer from using the Services in accordance with the Service Agreement on the basis of allegedly superior proprietary rights, the Customer shall notify Taskbase of this in text form without delay (e-mail sufficient). Provided that the Customer notifies Taskbase without delay and provides reasonable assistance, Taskbase shall, at its own discretion, either (i) modify the relevant Services in such a way that they do not infringe the proprietary rights of the respective third party while however, fulfilling all material requirements of the Customer, (ii) procure a license for the Customer from the third party at its own expense or (iii) dispute the third party claim. In the event that a legal action is brought against the Customer by the third party, the Customer shall transfer to Taskbase exclusive control regarding the conduct of the lawsuit and take all actions necessary for this purpose. Subject hereto, Taskbase shall bear the costs of litigation (including reasonable attorneys’ fees) and shall compensate the Customer for any direct damage resulting from a final judgment against the Customer. The Customer shall forfeit its claims under this provision if it withdraws or fails to give Taskbase control over the conduct of the lawsuit, in particular if it deals with third-party claims in whole or in part by means of settlement or recognition without the express consent of Taskbase.
8.4 Exclusion of Warranty
Taskbase’s warranty shall be excluded in case of incidents or circumstances, the causes of which are beyond Taskbases’ control and/or which are attributable in whole or in part to the Customer and/or to third parties not engaged by Taskbase (e.g. modifications of software or improper use of systems or other Services). Further, the warranty shall be excluded in case of incidents or circumstances related to force majeure events. No warranties apply to resources provided by the Customer (e.g. software licenses). In addition and in the absence of any agreement to the contrary in the Service Agreement, Taskbase makes no warranty that the Services can be used uninterruptedly and flawlessly in all combinations desired by the Customer, with any possible data or with any other IT systems or programs.
9. Liability
Taskbase shall be liable for proven direct damages in case of a breach of contract, unless Taskbase proves that it is not at fault. The liability shall be limited to the amount of the remuneration owed under the Service Agreement for the year in which the damage occurs. The liability shall be unlimited for any damages caused intentionally or through gross negligence, as well as for personal injury.
Taskbase’s liability for any indirect or consequential damages, including but not limited to lost profits, loss of data, loss of reputation and third-party claims, shall be excluded.
10. Force Majeure
Neither Party shall be liable for any damage, loss or delay resulting from any force majeure event, including but not limited to natural disaster, acts of war, terrorism, riots, labor strike, pandemics, DDOS attacks, hacking, malware, ransomware, unforeseeable official restrictions and criminal acts of third parties.
If performance of a contractual obligation is prevented by such a circumstance for a period of 90 days or more, each Party shall be entitled to terminate the Service Agreement subject to 90 days’ prior notice. In case of termination by the Customer, all fees under the Service Agreement are due and payable immediately pro rata up to the date of termination.
11. Intellectual Property Rights
11.1 In General
Unless otherwise agreed upon in the Service Agreement, no rights are transferred to the Customer in connection with the provision of the Services by Taskbase and the use of the Services by the Customer.
11.2 Recurring / Operational Services
Taskbase grants the Customer a non-exclusive, non-transferable, non-sublicensable right, limited to the term of the Service Agreement, to use the recurring Services in compliance and to the extent agreed upon in the Service Agreement.
11.3 One-Time Services
11.3.1 Newly Created Intellectual Property Rights
Insofar as agreed in the Service Agreement, all intellectual property rights newly and specifically created for the Customer in connection with the provision of one-time Services under the Service Agreement, in the case of software newly developed specifically for the Customer including the source code and the complete documentation, shall transfer to the Customer at the time of their creation. Taskbase undertakes to take all required actions for this purpose and issue the appropriate legal declarations in the requisite form to the extent required, and to ensure that any third parties involved do the same.
11.3.2 Pre-Existing Intellectual Property Rights
Unless otherwise specified in the Service Agreement, the Customer shall acquire a non-exclusive right, unlimited in time, to use any pre-existing intellectual property rights that are contained in the one-time Services provided by Taskbase. The Customer may create copies of such Services protected by pre-existing intellectual property rights for backup and archival purposes.
12. Confidentiality and Data Protection
12.1 Contractual Confidentiality Obligations
Both Parties undertake to treat as confidential any information that is not obvious or generally accessible concerning the other Party that may come to their attention in connection with their performance of the Service Agreement. Taskbase shall be entitled to pass on information to subcontractors and group companies to the extent necessary in connection with the Service Agreement.
The Parties undertake to make such information accessible to their staff, other auxiliary agents and third parties involved or other third parties only to the extent permitted to the Parties under the Service Agreement or where approved in advance by the other Party. Taskbase shall be entitled to pass on the information to third parties (e.g. subcontractors) engaged by it in Switzerland and abroad as well as to group companies (parent, sister or daughter companies of Taskbase) to the extent necessary in connection with the conclusion and performance of the Service Agreement.
The Parties’ confidentiality obligations shall not apply to information that:
was already in the public domain at the time of its disclosure;
was already known to the other Party before it was made accessible;
was lawfully provided to the other Party by a third party without any restrictions on disclosure;
was developed internally by the other Party without using the confidential information of the disclosing Party.
The confidentiality obligations shall also extend to information exchanged prior to the conclusion of the Service Agreement and shall continue to apply after its termination for at least 3 years.
12.2 Statutory or Regulatory Confidentiality Obligations
Taskbase shall be obliged to treat as confidential any information concerning the Customer that is protected by statutory or regulatory confidentiality obligations insofar as Taskbase has been informed about the Customer being subject to such obligations. This shall apply in particular with regard to information protected by banking secrecy, official secrecy, telecommunications secrecy, and non-disclosure duties under social insurance law.
12.3 Data Protection
The Parties shall comply at all times with applicable data protection laws, in particular the Swiss Data Protection Act (nDSG) and the EU-GDPR, when handling personal data. This also includes the implementation of appropriate technical and organizational security measures.
The Parties enter into a separate Data Processing Agreement (DPA) (Annex 6 to the Service Agreement).
Further data protection-related information can be found in Taskbase’s privacy policy, which the Customer acknowledges when concluding the Service Agreement. The Customer shall observe the current version, available at: taskbase.com/privacy-policy
12.4 Common Provisions
Notwithstanding the foregoing, each Party may disclose confidential information and personal data if and to the extent such disclosure is required pursuant to a court order or in accordance with a statutory or regulatory obligation. To the extent permitted by law, the other Party shall be informed of such disclosure in advance.
Any information and personal data that is no longer required for the performance of the Service Agreement shall be erased, subject to any mandatory statutory retention obligations. Each Party shall take reasonable technical and organizational security measures to protect confidential information and personal data.
13. Compliance with Laws and Regulations
The Parties shall comply with all laws and regulations applicable to them. Taskbase will thus comply with all laws and regulations applicable to Taskbase generally as a provider of the Services agreed upon in the Service Agreement. The Customer is responsible for determining and specifying the requirements of laws and regulations applicable to the Customer’s business, in particular those relating to the Services that the Customer procures under the Service Agreement.
14. Suspension of Services by Taskbase
Taskbase is entitled to suspend or restrict access of the Customer to the Services immediately and without further notice:
if the Customer is in default with the payment of fees due under the Service Agreement;
if the Customer breaches any clause of the Service Agreement, any terms of license and use (software) or any specifications or instructions by Taskbase (e.g. instructions for the use of systems);
if Taskbase terminates the Service Agreement for good cause;
if the undisturbed operation of Taskbase is endangered on the basis of circumstances within the Customer’s responsibility.
The suspension of the Services shall not affect the right to terminate for cause according to section 15.2 of these GTC.
15. Term, Termination and Effects of Termination
15.1 Term and Ordinary Termination
The Service Agreement enters into force as of the relevant effective date as specified therein and, subject to earlier termination as provided below, be concluded for the term as specified therein.
15.2 Termination for Cause
Either Party shall be entitled to terminate the Service Agreement with immediate effect for cause where:
the other Party materially breaches its obligations under the Service Agreement (including, with respect to the Customer, the failure to pay any agreed fees or the breach of essential terms of license and use) and has failed to remedy the breach within 30 days after written notice from the other Party;
the other Party dissolved or otherwise ceased operations;
the other Party is placed into bankruptcy, commences composition proceedings, or is insolvent.
15.3 Effects of Termination
Upon any termination of the Service Agreement, the Customer shall, as of the effective date of such termination, immediately cease accessing and otherwise utilizing the Services (except during an agreed transition period, if any) and any confidential information of Taskbase (as defined in section 12.1).
If Taskbase terminates the Service Agreement for the Customer’s uncured material breach, all fees under the Service Agreement shall become immediately due and payable within 10 days of the effective date of termination.
Termination of the Service Agreement will not affect any accrued rights (in particular Taskbase’s right to demand payment of all fees that the Customer is obliged to pay until the date of termination), claims and/or liabilities of either Party at the date of termination and shall be without prejudice to any other rights and/or remedies that either Party may have under the Service Agreement.
Further, the termination of the Service Agreement shall have no effect on the clauses which, by their nature, shall survive termination of the Service Agreement, particularly but not exclusively the clauses relating to intellectual property rights, liability, confidentiality and applicable law and place of jurisdiction.
16. Changes
16.1 Changes to Services and Fees
Should the Customer wish to make any changes to any contractually pre-defined Services, it shall inform Taskbase thereof in text form (change request). Taskbase shall promptly state whether the change is possible along with any implications that it will have, in particular on the Services to be provided as well as on the fees and contractual deadlines (if any). The changes to the Taskbase Services as requested by the Customer, along with any adjustment of the fees, contractual deadlines (if any) and other terms of the Service Agreement, shall be agreed on in text form prior to execution and, if requested by a Party, signed by both Parties (e.g. by means of an addendum to the Service Agreement).
With respect to recurring Services (e.g. operating and maintenance services), Taskbase may adapt the Services at any time (e.g. due to further developments), provided that this does not impair the Customer’s use of the Services. Further, Taskbase reserves the right to make changes to the Services that affect the Customer’s use, as well as adjustments to the fees. Taskbase will inform the Customer of such changes in an appropriate manner (e.g. via e-mail). If Taskbase increases fees in such a way that they lead to a higher total charge for the Customer, or if Taskbase significantly changes the Services to the detriment of the Customer, then Taskbase will inform the Customer sufficiently in advance and the Customer may terminate the Service Agreement as of the effective date of the changes. If the Customer fails to do so, the changes are deemed approved.
Adjustments to the fees as a result of a change in legal requirements (e.g. increase of the value-added tax rate), as a result of an adjustment to inflation (in accordance with the Consumer Price Index (CPI) of the Swiss Federal Statistical Office) and increases of the fees by service partners or other third party providers of Taskbase are not considered increases of the fees and do not entitle the Customer to terminate the Service Agreement.
16.2 Contractual Amendments
Any amendments or supplements to the Service Agreement (including amendments to this provision) shall only be legally valid if concluded in writing (with handwritten signatures) or in electronic form (e.g. an electronic file which contains a scan of the signature(s) or a signature with DocuSign, Skribble or any other reputable provider of electronic signatures).
However, Taskbase reserves the right to amend these GTC at any time. Taskbase will notify the Customer of such amendments in an appropriate manner (e.g. via e-mail). If Taskbase amends the GTC significantly to the detriment of the Customer, Taskbase will inform the Customer sufficiently in advance and the Customer may terminate the Service Agreement, which is affected by the amendments, as of the effective date of the amendments. If the Customer fails to do so, the amendments are deemed approved.
17. Miscellaneous
The Service Agreement sets forth the entire agreement between the Parties in relation to the subject matter thereof and shall replace all previous written or oral agreements or declarations of intention in this regard between the Parties.
The waiver of any contractual breach or the failure to enforce any of the rights thereunder shall not be construed as a waiver to enforce other rights or the same right in the future.
In the event that any term or part of any term of the Service Agreement is or becomes invalid or unenforceable, this shall not affect the remaining terms of the Service Agreement. An invalid or partially invalid or unenforceable or partially unenforceable clause shall be replaced by a valid clause (as the case may be by a court order), which comes as close as possible to the meaning and purpose of such clause, and the Parties undertake to sign all agreements and documents that may be necessary in that respect. The same procedure shall be followed should any gap become apparent in the Service Agreement.
The Parties undertake to refrain from transferring/assigning the Service Agreement or any rights or obligations thereunder to any third party without the prior written approval of the other Party.
No agency, partnership, joint venture, or employment is created as a result of the Service Agreement and neither Party has any authority of any kind to bind the other Party in any respect whatsoever.
All notices between the Parties under the Service Agreement must be made by e-mail or letter to the addresses stated in Annex 1 to the Service Agreement. This does not apply to notices and communications on operational matters.
18. Dispute Resolution, Applicable Law and Jurisdiction
Any disagreement arising out of or in connection with the Service Agreement shall be resolved by mutual agreement if possible. If this is not possible, a mediation proceeding shall be conducted by an independent lawyer. If the disagreement cannot be resolved within 60 days of the commencement of the mediation procedure, the Parties shall be free to bring the matter to the ordinary courts.
The Service Agreement shall be governed in all respects by the substantive laws of Switzerland, excluding the United Nations Convention on Contracts of International Sale of Goods of 11 April 1980 (CISG) and the provisions of international private law (which shall not apply).
All disputes arising out of or in relation to the Service Agreement, including those concerning its valid conclusion, legal validity, amendment or dissolution shall fall under the exclusive jurisdiction of the courts of Zurich 1, Switzerland.
Version: 10.9.2026
Annex 6 – Data Processing Agreement (DPA)
This Annex 6 describes the data processing carried out by Taskbase under the data processing agreement (DPA) within the scope of the contract for the Sales Coach.
Information on Taskbase
1. Taskbase contact details (responsible recipient of instructions):
Taskbase AG, Samuel Portmann, CEO, Zahnradstrasse 22, 8005 Zurich, Switzerland. Email: samuel@taskbase.com
2. Contact details of the data protection contact point at Taskbase:
Taskbase AG, Samuel Portmann, CEO, Zahnradstrasse 22, 8005 Zurich, Switzerland. Email: privacy@taskbase.com
3. Contact details of Taskbase’s data protection representative in the European Union:
Jetro Capiaghi, Hammerweg 8, 83022 Rosenheim, Germany. Email: jetro@taskbase.com
Data Processing
Within the scope of the contract, the customer entrusts Taskbase with confidential data for processing, at its own discretion and on its behalf. The customer acts as Controller and Taskbase as Processor.
1.1 Purpose of Processing
Taskbase processes the personal data entrusted to it by the customer only for the purposes set out below. By entering into this DPA, the customer instructs Taskbase to carry out the processing described in each of them:
(a) Provision of the Services. Delivering, operating, maintaining and supporting the Sales Coach product, including the capture and transcription of business conversations where configured by the customer, and the generation of coaching content, learning progress, development feedback as well as user-configured sales productivity outputs that support the customer’s users in their day-to-day work, such as call prioritisation lists, daily activity summaries and pre-meeting briefings.
(b) Configuration and tailoring for the customer. Configuring, adapting and improving the Services for the customer, including the adaptation of coaching skills, playbooks, prompts and evaluation logic to the customer’s own context, and the review of processing results by authorised Taskbase personnel for that purpose.
(c) Integrity, security and support: Securing the Services, diagnosing and remedying faults and errors, investigating security incidents, and maintaining availability.
(d) Administration of the contractual relationship: Customer relationship management, invoicing and archiving.
1.2 Instructions
(a) Taskbase processes personal data only on documented instructions from the Controller, unless there is an obligation to process under Swiss law or Union law. In such a case, Taskbase shall inform the customer of these legal requirements prior to processing, unless the relevant law prohibits this due to an important public interest. The customer may issue further instructions throughout the duration of the processing of personal data. These instructions must always be documented.
(b) Taskbase shall inform the customer without delay if it is of the opinion that instructions issued by the customer violate applicable data protection provisions.
1.3 Duration of Processing
Processing runs for the duration of the contract. Personal data will be handled by Taskbase as follows after the end of the contract:
Live customer data is deleted within 30 days of termination.
Backup data containing customer information is expired after at most 65 days after termination.
Log information is kept for up to 12 months for forensic purposes.
Transfer of data to the customer before deletion of live data upon request of the customer.
Deletion will take place unless there are longer statutory retention obligations or legitimate interests in relation to certain personal data.
1.4 Categories of Data Subjects
Taskbase processes personal data of the following categories:
Internal or external employees/auxiliary personnel of the customer
End customers of the customer
Internal or external employees/auxiliary personnel of the customer’s business clients
1.5 Categories of Personal Data
Taskbase processes the following categories of personal data:
Private and professional contact and identification data as well as organization data (name, first name, email address)
Data on personal/professional circumstances and characteristics (job title, professional career, company affiliation, tasks, activities, coaching content)
Image and/or sound recordings (e.g. audio, video, photos) of business meetings
Contract data (e.g. purchased products, financial services, purchase price, guarantees)
IT usage data (User ID)
Taskbase does not intentionally process special categories of personal data; the customer must not instruct it to do so. Unstructured content may incidentally contain such data, and no special-category attributes are derived from it.
1.6 Special Statutory Confidentiality Obligations
Taskbase, as an auxiliary person of the customer, does not process any personal data which is subject to a special statutory confidentiality obligation.
1.7 Confidentiality of Authorised Personnel
Taskbase grants access to the personal data processed on behalf of the customer only to those employees and other persons acting under its authority who require such access in order to carry out the purposes set out in section 1.1. Taskbase ensures that these persons are bound by a contractual or statutory obligation of confidentiality, are instructed in the lawful handling of personal data, and that they process the personal data only on the instructions of Taskbase and within the scope of this DPA.
2. Location of Data Processing
2.1 Location of personal data processing
The personal data is processed in the EU/EEA and Switzerland. All processing countries are listed in Annex 8 (Sub-Processors).
2.2 Guarantees for Subprocessors outside the EU/EEA
Taskbase ensures an adequate level of protection for personal data when processing is performed in the EU/CH by an entity located outside EU/CH by concluding data processing agreements with the relevant sub-processors, in which these sub-processors are obliged to take sufficient technical and organizational measures to protect the processed personal data and/or to ensure data security appropriate to the risk, and which contain the EU Standard Contractual Clauses (SCC) or are adequate according to the EU commission.
2.3 Disclosure of Personal Data to Sub-processors
The third parties listed in Annex 8 (Sub-processors) have access to and process personal data as sub-processors, or personal data is disclosed to these third parties.
Taskbase shall explicitly inform the customer at least 14 days in advance of intended changes to this list by adding or replacing sub-processors, thereby giving the customer sufficient time to raise objections to these changes before commissioning the relevant sub-processor(s).
Taskbase ensures that the sub-processor fulfills the obligations to which Taskbase is subject in accordance with these clauses, the Swiss Data Protection Act (nDSG), and Regulation (EU) 2016/679 (EU GDPR).
Assistance to the Controller
(a) Taskbase shall provide the customer with all information necessary to demonstrate compliance with the obligations set out in these clauses and arising directly from the Swiss Data Protection Act (nDSG) and/or Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725. At the customer’s request, Taskbase shall also permit and contribute to audits of the processing activities falling under these clauses at reasonable intervals or where there are indications of non-compliance. When deciding on a review or audit, the customer may take into account relevant certifications of Taskbase.
(b) The customer can carry out the audit themselves or commission an independent auditor. Audits may also include inspections of Taskbase’s premises or physical facilities and will be carried out with reasonable prior notice if applicable.
(c) Taking into account the nature of the processing, Taskbase shall assist the customer in fulfilling its obligation to respond to requests from data subjects to exercise their rights. Where a data subject addresses such a request directly to Taskbase, Taskbase shall not respond on its own account but shall forward the request to the customer without undue delay.
(d) Apart from the obligation to assist the customer pursuant to clause (c), Taskbase shall also assist the customer in complying with the following obligations, taking into account the nature of the data processing and the information available to it: (1) Obligation to carry out an assessment of the consequences of the planned processing operations for the protection of personal data (“Data Protection Impact Assessment”) if a form of processing is likely to result in a high risk to the rights and freedoms of natural persons; (2) Obligation to consult the competent supervisory authority(ies) prior to processing if a data protection impact assessment shows that the processing would result in a high risk, unless the customer takes measures to mitigate the risk.
Notification of Data Breaches
Taskbase shall notify the customer without undue delay, and at the latest within 36 hours of becoming aware of a personal data breach. This timeline is designed to ensure that the customer retains sufficient time to fulfil its own notification obligations to the competent supervisory authority within the 72-hour period prescribed by Art. 33 GDPR.
The initial notification shall be made in text form (email sufficient) to the customer’s designated contact and shall include, to the extent available at the time of notification: (a) a description of the nature of the breach, including the categories and approximate number of data subjects and personal data records affected; (b) the name and contact details of Taskbase’s data protection contact point; (c) a description of the likely consequences of the breach; (d) a description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
Where all required information cannot be provided at the time of the initial notification, Taskbase shall provide it in phases without further undue delay. Taskbase shall additionally notify the customer by telephone if the breach is of a severity that warrants immediate escalation, as assessed by Taskbase in good faith.
Taskbase shall document all personal data breaches, including those not requiring notification to a supervisory authority, and make this documentation available to the customer upon request.
Where the customer is subject to the Swiss Federal Act on Data Protection (nDSG), Taskbase shall notify the customer without undue delay upon becoming aware of a data breach involving a likely high risk to the personality or fundamental rights of affected data subjects, in accordance with Art. 24 nDSG. The above notification timelines and content requirements apply correspondingly. Where both the GDPR and the nDSG apply, Taskbase shall fulfil whichever obligation is more stringent in the circumstances.
3. Security of Processing
Taskbase implements and maintains the technical and organisational measures set out in Annex 7 (Technical and Organisational Measures) in order to ensure a level of security appropriate to the risk, in accordance with Art. 32 GDPR and with Art. 8 nDSG together with Art. 3 of the Swiss Data Protection Ordinance (DSV).
The measures reflect the state of the art at the time of conclusion of this DPA and are subject to technical development. Taskbase may replace individual measures with alternative or additional measures, provided that the level of protection agreed in Annex 7 is not reduced. Taskbase reviews the protection requirement of the personal data, the risk, and the effectiveness of the measures over the entire duration of the processing, in particular upon material change to the processing or to the measures and following a security incident, and adapts the measures where necessary.
Version: 17.9.2026
Annex 7 – Technical and Organizational Measures (TOM)
This Annex 7 describes the technical and organizational measures taken by Taskbase for the Sales Coach under the DPA. Taskbase operates no own server or data-centre infrastructure. All production systems run on AWS (EU) and cloudscale.ch (CH); physical, environmental and hypervisor-level security is provided by those sub-processors under their certifications.
Status
Meaning
Implemented
Formally in place and consistently applied
Partial
In place, with the stated limitation
Planned
Committed and scheduled, not yet in place
1. Governance
Who is accountable for security, and how Taskbase knows the measures are working.
Ref
Measure
Status
G1
A named internal information security owner is accountable for the security programme and reports to the CEO. A designated data protection contact point is in place.
Implemented
G2
A documented risk methodology is applied, and information security risks are recorded in a risk register with owner, likelihood, impact and treatment decision.
Implemented
G3
All measures in this annex correspond to entries in an internal control register with an owner, a status and a review date. This annex is derived from that register.
Implemented
G4
Security posture and roadmap are reviewed with company leadership on a recurring basis.
Implemented
G5
The full control set is reviewed at least annually.
Implemented
2. People
The staff who can reach customer data, and the obligations they are under.
Ref
Measure
Status
P1
All employment and contractor agreements contain confidentiality obligations covering personal data, which continue to apply after the engagement ends.
Implemented
P2
Access to customer personal data is limited to personnel who require it for the purposes set out in Annex 6.
Implemented
P3
Security awareness training for all staff, with role-specific secure-development content for engineers.
Planned
P4
Documented joiner, mover and leaver process with access revocation on departure.
Partial — lived but not documented
P5
A named internal escalation path for reporting suspected security incidents.
Implemented
3. Physical and Environmental
Where the hardware sits, and who can physically reach it.
Ref
Measure
Status
PH1
Physical and environmental security of all processing facilities is provided by AWS (EU) and cloudscale.ch (CH) under their ISO 27001 and SOC 2 certifications.
Implemented by sub-processor
PH2
No production customer data is stored on office infrastructure or on employee endpoints in the ordinary course.
Implemented
PH3
Entry to the office building requires a PIN code. The office is automatically locked outside business hours. Because building entry is credential-gated, visitors cannot enter unaccompanied.
Implemented
PH4
Endpoints are personally owned and not centrally managed. At-rest encryption is mandated. Compensating control: production data access is cloud-side via VPN, centrally logged and centrally revocable rather than local, so loss of an endpoint does not expose customer data.
Partial — endpoints not centrally managed
4. Identity and Access
Who is allowed in, to which systems, and with what privilege.
Ref
Measure
Status
IA1
Multi-factor authentication is enforced on all business systems and administrative interfaces.
Implemented
IA2
Product user authentication runs through a central identity provider (ZITADEL) supporting enforced multi-factor authentication.
Implemented
IA3
Access to production customer data follows least privilege; access rights are granted per role and per need.
Partial — engineers have broad access for quick repairs
IA4
Copies of production data for development or diagnostic purposes are created only through a sanctioned script that records requester, purpose and time; runs server-side; and tears copies down automatically each night.
Implemented
IA5
Such copies default to masked or synthetic data; a copy containing real customer data is a justified, logged, time-limited exception confined to the requester.
Planned
IA6
Cloud infrastructure access is separated into normal and administrative access. Administrative access requires additional authentication.
Implemented
IA7
No long-lived static access keys for human or automated access; pipelines authenticate using short-lived federated credentials.
Planned
IA8
Service and infrastructure secrets are held in a managed secret store, never in source repositories or plaintext files, with secret detection in the pipeline.
Partial — secrets in CI/CD, not yet in dedicated secret store
IA9
Granted access rights are reviewed and recertified periodically.
Planned
5. Network and Communications
What data moves between systems, and whether it can be intercepted.
Ref
Measure
Status
N1
TLS 1.2 or higher for all external traffic carrying customer data; no plaintext protocols.
Implemented
N2
Administrative access to production requires connection through the company VPN; production systems are not directly reachable from the internet outside defined ingress points.
Implemented
N3
SPF, DKIM and DMARC are configured on all company sending domains, with DMARC reports reviewed at least semi-annually.
Implemented
N4
A maintained overview records which systems exchange data, the data class carried by each flow, and every external recipient with its region.
Planned
6. Systems and Applications
How changes reach production, and how defects are found before they do.
Ref
Measure
Status
S1
Production, staging and development environments are separated.
Implemented
S2
All production changes pass through a merge request; every change is attributable to an author and revertible.
Implemented
S3
An automated test suite gates deployment.
Implemented
S4
Human review is required for changes affecting authentication, authorisation, data access or infrastructure.
Partial — applied but not formalized
S5
Static analysis, dependency scanning, secret detection and infrastructure-as-code scanning run in the pipeline, with high-severity findings tracked to closure under a remediation deadline.
Planned
S6
Automated dependency updating with review, and remediation deadlines by severity.
Planned
S7
Recurring automated vulnerability scanning of internet-facing services and infrastructure.
Partial — not all systems yet
S8
Independent external penetration test with tracked remediation.
Planned
7. AI and Agent Processing
How the models and agents handle customer content, and what they are prevented from doing.
Ref
Measure
Status
AI1
Customer content is not used to train, fine-tune or otherwise adapt Taskbase models.
Implemented
AI2
Sub-processed model providers are contractually excluded from training on customer data. Inference runs in EU regions, and the primary inference path is configured for zero data retention at the provider.
Implemented
AI3
The Service produces coaching guidance for human use. It performs no automated decision-making producing legal effects or similarly significant effects on a data subject.
Implemented
AI4
Agent observability data (prompts, outputs and tool calls) is retained on Taskbase-operated infrastructure and is not transmitted to a third-party observability provider.
Implemented
AI5
Agent tool calls and data access are traced in sufficient depth to reconstruct what an agent did with customer data.
Implemented
AI6
Tenant and persona isolation is enforced in the retrieval, cache and execution layers.
Partial — enforced in code, automated verification planned
AI7
Agent permissions follow least privilege per tenant, with no access to data the requesting user could not see directly.
Partial — additional measures planned
AI8
Ingested content (transcripts, CRM text, uploads) is not treated as instruction, and tool calls are validated before execution.
Planned
AI9
Sensitive or irreversible agent actions require human confirmation.
Planned
8. Data and Information
Protection of the data itself, including how long it is kept and when it is deleted.
Ref
Measure
Status
D1
Encryption at rest for all persistent storage holding customer data, including databases and object storage.
Implemented
D2
Backups are encrypted and integrity-protected by cryptographic signing.
Implemented
D3
Customer data is processed and stored in the EU/EEA and Switzerland; per-sub-processor locations are listed in Annex 8.
Implemented
D4
Customer tenants are logically separated, with the tenant identifier enforced at the data access layer.
Implemented
D5
Retention is bounded and documented: live customer data until end of contract plus 30 days, backups 65 days, operational and security logs up to 12 months.
Implemented
D6
Deletion on termination is executed rather than left to expiry; data export is available to the customer before deletion on request.
Implemented
D7
Alerting on bulk reads of customer data.
Planned
D8
A data classification scheme drives handling requirements per class.
Planned
9. Suppliers and Third Parties
The sub-processor chain, and the assurance obtained before a vendor is engaged.
Ref
Measure
Status
SU1
A documented vendor risk assessment is completed before onboarding any vendor with access to customer data, covering certifications, data processing terms, breach notification, sub-processors and data residency.
Implemented
SU2
A data processing agreement is in place with each sub-processor, with Standard Contractual Clauses and Swiss addendum where required, and a transfer impact assessment where applicable.
Implemented
SU3
The sub-processor list is maintained and published as Annex 8, with advance notice of additions and replacements.
Implemented
SU4
Sub-processors are reassessed on material change and on a defined periodic cadence.
Implemented
10. Operations and Resilience
Detecting incidents, responding to them, and recovering from data loss.
Ref
Measure
Status
O1
Central audit logging of authentication, privileged actions and infrastructure changes.
Implemented
O2
Security alerts are routed to a channel that is actively monitored.
Partial — coverage narrower than O1
O3
All systems holding customer data are backed up.
Implemented
O4
At least one backup copy is immutable or isolated from production credentials.
Planned
O5
Recovery point and recovery time objectives are documented per system.
Implemented
O6
Restores are tested on a recurring schedule and the restore time is controlled.
Implemented
O7
A written disaster recovery plan covers roles, decision points, communication and per-system recovery order.
Partial — steps exist, comprehensive plan in construction
O8
A documented incident response process defines severity levels, roles, escalation, and the customer and regulator notification route.
Partial — process exists, severity levels need formal definition
O9
Post-incident review with tracked follow-up actions.
Partial — performed, not yet formalised
11. Compliance and Audit
Demonstrating that the measures operate, and meeting legal obligations.
Ref
Measure
Status
C1
A register of applicable legal and regulatory obligations records, per entry, why it applies, the role held, status and owner.
Partial — drafted, verification in progress
C2
This annex is derived from the internal control register and reviewed on material change to the control set and at least annually.
Implemented
C3
Records of processing activities as processor under Art. 30(2) GDPR are maintained and made available on request.
Planned
C4
Taskbase assists controllers with data protection impact assessments and prior consultation.
Implemented
C5
A documented process handles data subject requests forwarded by the customer, within a defined response time.
Partial — responsibility assigned, not fully formalized
C6
A published security contact and vulnerability disclosure route. Main contact: security@taskbase.com
Partial — contact exists, security.txt not yet deployed
C7
ISO 27001 certification.
Planned — first steps initiated
Mapping to Statutory and Legacy Control Categories
This table maps the measures above to the control categories named in Swiss and EU data protection law, and to the legacy control categories used in the previous version of this annex. It adds no measures of its own; the sections above govern.
Statutory or Legacy Category
Covered by
DSV Art. 3(1) Zugriffskontrolle
IA1, IA3, IA4, IA5, IA9, P2, D4, AI6, AI7
DSV Art. 3(1) Zugangskontrolle
PH1, PH2, PH3
DSV Art. 3(1) Benutzerkontrolle
IA1, IA2, IA6, IA7, IA8, N1, N2
DSV Art. 3(2) Datenträgerkontrolle
D1, D2, PH1, PH4
DSV Art. 3(2) Speicherkontrolle
D1, D4, IA3, O1
DSV Art. 3(2) Transportkontrolle
N1, D1, D3
DSV Art. 3(2) Availability, integrity and recovery
D2, O3, O4, O5, O6, O7
DSV Art. 3(3) Eingabekontrolle (input logging)
O1, S2, AI5
DSV Art. 3(3) Bekanntgabekontrolle (disclosure traceability)
D3, N4, SU2, SU3, Annex 8
DSV Art. 3(3) Detection and remediation of breaches
O1, O2, O8, O9, S5, S7
DSV Art. 4 Protokollierung
O1, S2, AI5, D5
DSV Art. 7 Processor obligations
SU1, SU2, SU3, SU4, P1, P2
GDPR Art. 32(1)(a) Pseudonymisation and encryption
D1, D2, N1, IA5
GDPR Art. 32(1)(b) Confidentiality, integrity, availability, resilience
D1, D2, D4, O1, O2, O3, O4, AI6
GDPR Art. 32(1)(c) Restoration after an incident
O3, O4, O5, O6, O7
GDPR Art. 32(1)(d) Testing and evaluating effectiveness
G3, G5, C2, S5, S7, S8, O6
GDPR Art. 32(4) Personnel acting under authority
P1, P2
GDPR Art. 25 Data protection by design and by default
IA5, D4, D5, D8, AI1, AI2, AI7, AI8
Legacy: Access Control (Physical) / Zutrittskontrolle
PH1, PH2, PH3
Legacy: Access Control (System) / Zugangskontrolle
IA1, IA2, IA6, IA7, IA8, N1, N2, PH4
Legacy: Access Control (Data) / Zugriffskontrolle
IA3, IA4, IA5, IA9, P2, D4, D6, AI6, AI7
Legacy: Transfer and Transmission Control / Weitergabekontrolle
N1, N4, D3, SU2, SU3, Annex 8
Legacy: Input Control / Eingabekontrolle
O1, S2, AI5, D5, D6
Legacy: Order Control / Auftragskontrolle
SU1, SU2, SU3, SU4
Legacy: Availability Control / Verfügbarkeitskontrolle
D2, O3, O4, O5, O6, O7, PH1
Legacy: Separability / Trennungskontrolle
S1, D4, AI6
Legacy: Review, Assessment and Evaluation
G1, G2, G3, G4, G5, C1, C2, C4, S8, O6
Legacy: Incident Response Management
O1, O2, O8, O9, P5, C6
Legacy: Privacy by Design / Privacy by Default
IA5, D4, D5, D8, AI1, AI2, AI3, AI7, AI8
Version: 3.9.2026
Annex 8 – Sub-processors
This Annex 8 lists the sub-processors engaged by Taskbase. Processing location is where personal data is stored and processed. Additions and replacements are governed by the sub-processor clause of Annex 6.
Sub-processor
Service
Location
Transfer Safeguard
Amazon Web Services
Cloud infrastructure and application hosting; LLM inference via Amazon Bedrock. Data: name, email, CRM contact and activity data, conversation and transcript content, application data.
Germany (EU)
AWS GDPR DPA; EU SCCs and Swiss Addendum apply to any onward transfer
Supabase
Application platform: PostgreSQL database, object storage, authentication, realtime, edge functions. Data: name, email, CRM contact and activity data, conversation and transcript content, application data.
Switzerland (CH)
Signed DPA; EU SCC Modules 2 & 3 with Swiss Addendum; Transfer Impact Assessment completed
cloudscale.ch AG
IaaS hosting for parts of the application. Data: name, email, conversation data.
Switzerland (CH)
DPA compliant with GDPR and nDSG; Swiss adequacy decision (EU)
Anthropic
Claude large language models via Amazon Bedrock. Data: prompts and model outputs which may contain any customer content submitted to the Service.
Germany (EU) — Bedrock EU region, zero-day retention
Via AWS DPA and SCCs above. No training on customer data
Microsoft Azure
EU-region LLM inference (Azure OpenAI / Azure AI). Data: prompts and model outputs which may contain any customer content submitted to the Service.
Germany (EU)
Microsoft Products DPA including EU SCCs; EU–US DPF; no training on customer data
Google Cloud
Gemini Enterprise Agent Platform (formerly Vertex AI) — agent hosting and inference. Data: prompts and model outputs which may contain any customer content.
Belgium (EU)
Google Cloud DPA including EU SCCs; EU–US DPF; no training on customer data
Recall.ai *
* Only relevant if Taskbase Recording Tool is used. Meeting capture, transcription and meeting metadata. Data: transcripts, participant names and email addresses, join/leave times, meeting titles, audio/video as controlled by customer.
Germany (EU)
DPA with EU SCC Modules 2 & 3 (Swiss modifications); Transfer Impact Assessment completed
bliro GmbH *
* Only relevant if Bliro is used as part of a partnership agreement. AI meeting transcription and summarisation; no audio/video stored. Data: name, email, meeting transcripts, audio transiently processed on device.
Germany (EU)
DPA under German law signed per customer order
ZITADEL
Identity and access management for Service users. Data: first name, last name, email, language, gender, authentication data.
Switzerland (CH)
ZITADEL DPA; SCC; US–EU and Swiss–US Data Privacy Framework
iWay AG
Outbound transactional email (SMTP relay). Data: email address, name, message content. Relay only — no mailbox or message storage.
Switzerland (CH)
DPA under Swiss law; Swiss adequacy decision (EU)
PostHog
Product analytics. Data: device and browser data, product usage events, pseudonymous user identifier. No customer content beyond incidental info in URLs/browser data.
Germany (EU)
PostHog DPA including EU SCCs and nDSG adaptations; EU–US DPF + Swiss–US DPF