Taskiim — Privacy Policy
Effective date: 13 August 2026 Last updated: 15 August 2026
This Policy explains how Arif Setyo Wibowo, an individual business operator based in Indonesia (“Taskiim”, “we”, “us”), handles personal data in connection with the Taskiim service at https://taskiim.com.
It is written to meet Indonesia’s Law No. 27 of 2022 on Personal Data Protection (UU PDP) and, for users in the European Economic Area and the United Kingdom, the GDPR.
1. Two different roles
Taskiim handles personal data in two capacities, and your rights differ accordingly.
We are the controller of the data we need in order to run the Service itself: account identity, authentication, security records, and support correspondence. This Policy governs that data.
We are the processor of the data your organisation puts into its workspace — tasks, comments, files, time entries and everything else your colleagues write. Your employer or the organisation that invited you is the controller of that data. It decides what goes in, who may see it, and how long it is kept. Requests about that data should go to that organisation first; our obligations to it are set out in the Data Processing Agreement.
2. What we collect
2.1 Account and profile
| Data | Source | Why |
|---|---|---|
| Email address | Your Google account, or the invitation sent to you | Identifies your account; delivers notifications |
| Name | Google account, or entered by you | Shows who did what to colleagues |
| Profile picture URL | Google account | Displays your avatar |
| Google account identifier | Google Sign-In | Links your sign-ins to your account |
| Language preference | Set by you | Displays the interface in your language |
| Last sign-in time | Generated | Account security and support |
We never receive or store a password. Taskiim has no password field. You sign in with Google Sign-In or with a passkey. For passkeys we store only the public key and the credential identifier your device generated — never a fingerprint, a face scan, or any other biometric, all of which stay on your device and are never transmitted to us.
2.2 Security and session data
To keep sessions safe we store, for each active session: a hashed refresh token, the session family it belongs to, the time you originally authenticated, the expiry, and — for real (non-demo) accounts — the IP address and browser user-agent of the device. This lets you and your administrators recognise an unfamiliar device, and lets us shut down a stolen session.
2.3 Audit log
Actions taken in a workspace — creating, updating, deleting and restoring records, signing in and out, permission changes, and exports — are written to an audit log visible to administrators of that workspace. Entries record who acted, what changed, when, and the IP address and user-agent used.
This is workspace data under your organisation’s control, not ours. If you use Taskiim through an employer, your employer can see it.
2.4 Content you and your colleagues create
Projects, tasks, descriptions, comments, labels, milestones, client records, uploaded files, and time entries — including timers, notes, approvals and rejection reasons. This content frequently contains personal data about identifiable people, and time tracking in particular concerns individual working patterns.
2.5 Billing, for workspaces on a paid plan
Paid subscriptions are sold and processed by Lemon Squeezy, LLC as our Merchant of Record. What that means for your data:
| Data | Who holds it | Why |
|---|---|---|
| Billing contact name and email | Lemon Squeezy, from us | Issues your receipt and reaches you about payment |
| Card or bank details | Lemon Squeezy only | Takes the payment |
| Billing address and tax identifiers | Lemon Squeezy only | Works out and remits the tax due on your purchase |
| Subscription status, plan and renewal date | Us, from Lemon Squeezy | Applies the right plan to your workspace |
Your card details never reach us. You give them to Lemon Squeezy, on its pages, and we are not sent them, do not store them, and could not retrieve them if asked. What we receive back is which workspace bought which plan and whether it is still active — which is all that running your subscription requires.
Lemon Squeezy decides for itself what it must keep to meet its own tax and fraud-prevention duties, so for the payment transaction it is not acting only on our instructions. Its own privacy notice governs that part.
2.6 What we do not do
- We do not use tracking cookies, advertising cookies, or third-party analytics or advertising pixels. The only browser storage we use is what the application needs to function — see section 7.
- We do not sell personal data, and we do not share it for advertising.
- We do not use your content to train machine learning models.
- We do not see, hold, or have any way of recovering your card details.
- We do not record anything about visitors to the public demo — see section 8.
3. Why we process it, and on what basis
| Purpose | Data | Legal basis (GDPR) | Basis (UU PDP) |
|---|---|---|---|
| Providing the Service to you | Account, profile, content | Contract (Art. 6(1)(b)) | Contract performance |
| Keeping accounts and data secure | Session, IP, user-agent, audit | Legitimate interests (Art. 6(1)(f)) | Legitimate interest |
| Malware scanning of uploads | File contents | Legitimate interests | Legitimate interest |
| Service and security notifications | Email, name | Contract | Contract performance |
| Complying with legal obligations | As required | Legal obligation (Art. 6(1)(c)) | Legal obligation |
| Responding to your support requests | Correspondence | Legitimate interests / Contract | Legitimate interest |
Where we rely on legitimate interests, we have weighed them against your rights and concluded the processing is limited to what is necessary. You may object — see section 9.
4. Who we share it with
We share personal data only with:
- Service providers (sub-processors) who host and operate the Service on our behalf, under contract and only on our instructions. The current list is in the Data Processing Agreement.
- Google, when you choose Google Sign-In. Google confirms your identity to us; your use of Google is governed by Google’s own privacy policy.
- Lemon Squeezy, when your workspace buys a paid plan. It is the seller of record and handles the payment and its tax; your purchase is governed by its own terms and privacy notice as well as ours — see section 2.5.
- Other members of your workspace, according to the roles and permissions your administrators configure.
- Authorities, where we are legally compelled. We will notify you unless legally prohibited, and we will challenge requests that appear overbroad or unlawful.
- An acquirer, in a merger or sale of assets, subject to this Policy continuing to apply.
5. Where data is stored and transferred
The Service is hosted in Germany (Hetzner Online GmbH, Falkenstein). If you are in Indonesia, this means your personal data is transferred outside Indonesia; UU PDP permits this where the receiving country provides adequate protection or where appropriate safeguards are in place. For transfers of EEA/UK personal data outside those areas we rely on the European Commission’s Standard Contractual Clauses.
Billing data is the exception. For workspaces on a paid plan, the billing contact and the payment itself are handled by Lemon Squeezy in the United States, under its own terms — see section 2.5. Workspace content is never sent there; only what a receipt and a subscription record require.
We will tell you before changing the hosting region in a way that materially affects this.
6. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | While your account exists |
| Refresh tokens / sessions | Until expiry (30 days) or revocation |
| Workspace content | Until deleted by your organisation, then as set out in the DPA |
| Audit log entries | Retained for the workspace’s lifetime unless your organisation instructs otherwise; the log is append-only by design |
| Public demo data | Erased on a recurring schedule, currently every 30 minutes |
| Support correspondence | Up to 24 months |
| Subscription record (plan, status, renewal date) | While the subscription exists, then up to 24 months |
| Receipts, invoices and payment records | Held by Lemon Squeezy, for as long as its own tax and accounting duties require |
Deleting a record in the application is usually a soft delete — the row is marked deleted and hidden, so your organisation can recover from mistakes. It is removed permanently on account deletion or on request. Backups of the database are taken every six hours and kept for 30 days, transmitted over TLS and encrypted at rest by our storage provider, so a deleted record may persist in a backup for up to 30 days after deletion. Backups are used for no purpose other than restoring the Service.
7. Cookies and browser storage
We use no advertising or analytics cookies. We use:
- A session cookie holding your refresh token. It is
httpOnly,Secure, scoped to the authentication endpoints, and strictly necessary — the Service cannot keep you signed in without it. - Local storage on your device for interface preferences (such as theme and dialog size) and for unsent drafts of work you are typing, so that an interrupted session does not destroy it. Drafts are stored only on your own device, are scoped to your user account, and are cleared once the item is saved or after seven days.
Because none of this is used for tracking or advertising, no consent banner is required; strictly necessary storage is exempt.
8. The public demo
Visitors to the public demo are not identified and not recorded. We store no IP address and no user-agent for demo sessions — not in the audit log, and not on the session record. Every visitor shares a persona, so recording an address from one anonymous stranger would only display it to the next.
The demo is writable and is wiped on a schedule. Anything you type there may be seen by other visitors and will be deleted. Do not put real personal data in it.
9. Your rights
Under UU PDP and the GDPR you have the right to: access your personal data and obtain a copy; have inaccurate data corrected; have data erased; restrict or object to processing; receive your data in a portable format; withdraw consent where processing is based on consent; and not be subject to solely automated decisions with legal or similarly significant effects — Taskiim makes no such decisions.
To exercise these rights, contact [email protected]. We will respond within thirty (30) days, extendable where a request is complex, and we may need to verify your identity first.
If your data is in an employer’s workspace, ask that organisation. We will forward your request to them and assist them in answering it, but we cannot delete or amend an employer’s records on our own initiative.
Complaints. You may complain to the Indonesian personal data protection authority, or — in the EEA/UK — to your local supervisory authority. We would prefer the chance to resolve it first.
10. How we protect it
- Encryption in transit (TLS) for all traffic; the site is served over HTTPS only.
- Passwordless authentication — there is no password database to steal.
- Refresh tokens and invitation tokens are stored hashed, so a database leak yields no working credential.
- Automatic revocation of an entire session family when a used token is presented again, which is how a stolen session is caught.
- Workspace isolation enforced at the data-access layer, with automated tests running against a real database asserting that one workspace cannot read another’s records.
- Permissions read from the database on every request, so revoking someone’s access takes effect within minutes rather than at token expiry.
- Uploads identified by their actual content, macro-carrying documents refused, and every file scanned for malware before it is stored. If the scanner is unavailable the upload is refused rather than admitted.
- Private object storage; files are reachable only through short-lived presigned links issued per request.
No system is perfectly secure. If a breach occurs that poses a risk to you, we will notify you and the relevant authority within 72 hours of becoming aware, as UU PDP and the GDPR require.
11. Children
Taskiim is a workplace tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has an account, contact us and we will delete it.
12. Changes
We will post any change here and update the date above. For material changes we will notify workspace owners by email at least thirty (30) days in advance.
13. Contact
Arif Setyo Wibowo — Indonesia Privacy and data protection: [email protected] Security reports: [email protected] No Data Protection Officer is appointed; privacy enquiries go to the address above.