Data processing agreement
Last updated: 6 September 2026
This document covers your use of Tasked and everything stored in the service.
1. The roles
Your organisation is the data controller. Tasked is the processor and acts only on your documented instructions, which are your use of the service as described in the terms of service.
2. Scope of processing
The subject matter is running a video studio's work. The data is contact details, work content and the files you upload. The data subjects are your staff, your clients and their contacts. The duration is the term of the agreement.
3. Security
Encryption in transit and at rest, tokens encrypted in the database, per-organisation isolation enforced in the database access layer, role-based permissions, an audit log with no edit path, rate limits on every public route and malware scanning on every upload.
4. Sub-processors
We use infrastructure and cloud providers, an outbound email provider, a payment provider and AI model providers. A current list is available on request, and we give notice before adding one so you can object.
5. International transfers
Processing happens in the European Union. Where a provider processes outside it, the transfer relies on standard contractual clauses.
6. Assistance, incidents and deletion
We help you answer data subject requests and complete impact assessments. We notify you of a security incident without undue delay. When the agreement ends we export everything and delete it after thirty days.
Questions about this document: main@tasked.co.il. Tasked, a BScale venture, Israel.