Scope
      This Policy applies to personal information processed by Tasqly through our marketing website (including forms), our web and mobile applications (including the installable PWA and kiosks), integrations (e.g., Slack/Teams apps, APIs, and webhooks), and related services (collectively, the “Services”).
      We provide enterprise request and task management features such as intake portals, smart dispatch, workboards/KDS, SLAs, notifications, analytics, and admin tooling. Customers (employers/venues) control the data they submit to the Services (“Customer Data”). For Customer Data, Tasqly acts as a processor/service provider; the customer is the controller/business responsible for its own privacy notices and lawful use.
    
    
      Data We Collect
      Information you provide
      
        - Account & profile (name, work email, role, location, team, preferences).
- Requests & tasks submitted by guests or staff (categories, notes, attached photos, station/suite numbers, timestamps, status, assignees, SLA info).
- Communications (messages, comments, in-thread actions via Slack/Teams, email/SMS replies).
- Support & sales (form submissions, demo requests, surveys).
Information collected automatically
      
        - Usage & device (pages/screens viewed, features used, clicks, performance data, app version, device/browser type, language, approximate location derived from IP).
- Log data (IP address, timestamps, identifiers, error logs). For the PWA, certain actions may be queued locally on the device for offline use and synced on reconnect.
- Cookies and similar tech (see Cookies).
Information from third parties
      
        - Integrations (e.g., Slack/Teams messages and user IDs; optional POS/order metadata; printing events).
- Vendors (analytics, communications, payment, or hosting providers acting as processors).
Sensitive personal information: Tasqly is not intended to collect sensitive categories (e.g., health records, precise geolocation, government IDs). Do not upload such data unless your agreement expressly allows it and applicable law requirements are met.
    
    
      How We Use Data
      
        - Provide and secure the Services (authentication, RBAC, routing, SLAs, notifications, KDS, printing, offline sync, audit logs).
- Operate, maintain, and improve (performance, quality, UI/UX, analytics, troubleshooting).
- Communicate (service notices, security alerts, transactional messages; marketing with your consent where required).
- Compliance (enforce Terms, prevent abuse, meet legal obligations).
- Research & development (aggregated and de-identified insights that do not identify individuals).
Legal Bases (EEA/UK)
      Where GDPR/UK GDPR applies, we rely on the following bases: (i) contract to provide the Services; (ii) legitimate interests (e.g., security, product improvement) not overridden by your interests or rights; (iii) consent for certain marketing or optional cookies; and (iv) legal obligations.
    
    
      Sharing & Transfers
      
        - Service providers (processors): hosting, storage, analytics, communications, and support vendors under contract.
- Integrations: at your direction we share relevant data with configured integrations (e.g., Slack/Teams, optional POS/printing). You can enable/disable these in admin settings.
- Legal and safety: to comply with law, enforce agreements, or protect rights and safety.
- Business transfers: as part of a merger, acquisition, or asset sale with appropriate safeguards.
International transfers: When transferring personal data internationally, we use appropriate safeguards such as Standard Contractual Clauses where required.
      Subprocessors: We maintain contracts with our subprocessors and will provide an up-to-date list upon request.
      Sale/Share: We do not sell personal information. We do not “share” personal information for cross-context behavioral advertising as defined by U.S. state laws.
    
    
      Data Retention
      We retain personal information for as long as necessary to provide the Services and fulfill the purposes outlined here, including legal, accounting, or reporting requirements. Customer Data retention is managed by the customer’s administrators (e.g., request/task history). Operational logs are typically retained for a limited period reasonable for security and diagnostics. Locally cached offline data persists on the device until sync or user clears site/app storage.
    
    
      Your Privacy Rights
      Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection to certain processing, and to withdraw consent where processing is based on consent.
      
        - EEA/UK: GDPR rights to access/rectify/erase/portability/restrict/object; right to lodge a complaint with a supervisory authority.
- U.S. state laws (e.g., CA, CO, CT, VA, UT): right to know/access, delete, correct, portability, opt-out of targeted advertising or certain profiling where applicable, and non-discrimination.
Exercising rights: Contact us at [email protected]. If your data is part of a customer account, we may redirect your request to the appropriate customer administrator.
      Do Not Track: We do not respond to DNT signals due to lack of industry standard. You can control cookies as described below.
      Children: The Services are not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided information, contact us to delete it.
    
    
      Security
      We employ administrative, technical, and organizational measures appropriate to the risk, including TLS in transit, encryption at rest for primary data stores, role-based access controls, session hardening, and signed webhooks. No method of transmission or storage is 100% secure; we cannot guarantee absolute security. If we learn of a security incident affecting personal information, we will notify customers and/or individuals as required by law.
    
    
      Cookies & Similar Technologies
      We use: (i) necessary cookies for authentication and core features; (ii) functional cookies to remember preferences; and (iii) analytics cookies to understand usage and improve the product. You can manage cookies via your browser settings. Blocking cookies may impact functionality, particularly for authenticated features.
      Push notifications can be controlled at the device/browser level and within user preferences in the app.
    
    
      International Users
      Your information may be processed in countries other than your own. Where required, we use appropriate safeguards (e.g., SCCs). For questions about international transfers, contact [email protected].
    
    
      Changes to this Policy
      We may update this Policy from time to time. We will post the updated version here and update the “Effective” date. Material changes may be communicated via the Services or email.
      Effective: August 28, 2025
    
    
      Contact
      Questions about privacy or data requests: [email protected] or [email protected].