TaskForMe Ltd – www.taskforme.co Effective Date: 03 August 2026
1. Parties
This Data Processing Agreement (“Agreement”, “DPA”) is entered into between:
TaskForMe Ltd, a company incorporated in the Republic of Cyprus, acting as Data Controller (“Controller”),
and
The third‑party service provider identified in the applicable service contract, acting as Data Processor (“Processor”).
This DPA forms an integral part of the service contract between the parties.
2. Purpose and Scope
The Processor shall process Personal Data solely for the purpose of providing services to the Controller as described in the main service contract.
This DPA governs:
- The nature and purpose of processing
- The categories of Personal Data processed
- The obligations of the Controller and Processor
- Security measures
- International transfers
- Sub‑processing
- Data subject rights
- Audit and compliance requirements
3. Definitions
- Personal Data — Any information relating to an identified or identifiable natural person.
- Processing — Any operation performed on Personal Data (collection, storage, use, deletion, etc.).
- Controller — TaskForMe Ltd, determining the purposes and means of processing.
- Processor — The third‑party service provider processing data on behalf of the Controller.
- Sub‑Processor — Any third party engaged by the Processor to process Personal Data.
- Supervisory Authority — Office of the Commissioner for Personal Data Protection (Cyprus).
- GDPR — Regulation (EU) 2016/679.
4. Categories of Personal Data
The Processor may process the following categories of Personal Data:
- Identification data (name, contact details)
- Account information
- Task‑related information
- Communication logs
- Payment‑related data (non‑financial identifiers)
- Device and usage data
Special categories of data (GDPR Art. 9) are not processed unless explicitly agreed in writing.
5. Obligations of the Processor
The Processor agrees to:
5.1 Process Only on Documented Instructions
Process Personal Data solely on the Controller’s documented instructions, including with respect to:
- Purpose
- Duration
- Type of data
- Categories of data subjects
5.2 Confidentiality
Ensure all persons authorised to process Personal Data:
- Are bound by confidentiality obligations
- Have received appropriate training
5.3 Security Measures
Implement appropriate technical and organisational measures, including:
- Encryption
- Access controls
- Secure servers
- Regular security audits
- Data minimisation
- Incident response procedures
5.4 Sub‑Processing
The Processor may not engage Sub‑Processors without:
- Prior written authorisation from the Controller
- GDPR‑compliant contracts with Sub‑Processors
- Ensuring equivalent data protection obligations
5.5 Assistance to the Controller
Assist the Controller in:
- Responding to data subject requests
- Ensuring compliance with GDPR Articles 32–36
- Conducting Data Protection Impact Assessments (DPIAs)
- Managing security incidents
5.6 Data Breach Notification
Notify the Controller without undue delay (and no later than 48 hours) after becoming aware of a Personal Data breach.
Notification must include:
- Nature of the breach
- Categories and number of data subjects affected
- Likely consequences
- Measures taken or proposed
5.7 Deletion or Return of Data
Upon termination of services, the Processor shall:
- Delete all Personal Data
- Or return all Personal Data to the Controller
- Unless EU or Cyprus law requires retention
6. Obligations of the Controller
The Controller agrees to:
- Provide lawful and documented processing instructions
- Ensure Personal Data is collected lawfully
- Maintain a lawful basis for processing
- Inform data subjects of processing activities
- Ensure compliance with GDPR and Cyprus law
7. International Transfers
The Processor shall not transfer Personal Data outside the EU/EEA without:
- Adequacy decision
- Standard Contractual Clauses (SCCs)
- Approved certification mechanisms
- Explicit written authorisation from the Controller
8. Data Subject Rights
The Processor shall assist the Controller in responding to requests under GDPR, including:
- Access
- Rectification
- Erasure
- Restriction
- Portability
- Objection
Requests must be forwarded to the Controller immediately.
9. Audit and Compliance
The Controller may:
- Conduct audits
- Request documentation
- Verify compliance with this DPA
The Processor shall:
- Cooperate fully
- Provide access to relevant records
- Allow inspections by the Controller or authorised auditors
10. Liability
Liability is governed by the main service contract. The Processor is liable for:
- Breaches of this DPA
- Breaches of GDPR caused by its actions
- Actions of authorised Sub‑Processors
11. Term and Termination
This DPA remains in effect for the duration of the service contract. Upon termination:
- All Personal Data must be deleted or returned
- All Sub‑Processors must cease processing
- All access credentials must be revoked
12. Governing Law
This DPA is governed by the laws of the Republic of Cyprus, including:
- GDPR
- Cyprus Data Protection Law 125(I)/2018
- Applicable EU directives and regulations
13. Contact Information
TaskForMe Ltd Email: info@taskforme.co Website: www.taskforme.co