Privacy statement
Last changed on 16 September 2026
Taskstand is a service of amphora.interactive, established at Acaciastraat 11, 3551 BD Utrecht, Netherlands, Dutch Chamber of Commerce number 30157344. This statement explains which personal data we process, why, for how long, and what you can do about it.
Two roles
For your account data we are the controller: we decide why we process it. For what you put into the service, your projects, tasks, comments and files, we are the processor and you are responsible. What we agree about that is in the processing annex to our terms and conditions.
What we process
- Account data
- Your name, email address, password (only as a hash), language, time zone, your work week, and whether you have set up two-factor authentication or a passkey.
- Content you add yourself
- Projects, sections, tasks, descriptions, comments, labels, attachments, tracked hours, rates and budgets. That may contain other people's personal data; what goes in is up to you.
- Usage data
- An activity log per task, and technical server log lines with a timestamp, an IP address and the page requested.
- Payment data
- Once paying is possible: the chosen plan, the payment status and the invoicing details. Your card or account details go through our payment provider and never reach us.
Why we process it, and on what basis
| Purpose | Data | Basis |
|---|---|---|
| Running the service and your account | Account, content | Performance of the agreement |
| Emailing you about your tasks, invitations and mentions | Account | Performance of the agreement; you can switch off each type per channel |
| Handling payments and invoicing | Payment data | Performance of the agreement and a legal obligation |
| Security, preventing abuse and fixing faults | Usage data | Legitimate interest in a working, secure service |
| Answering your questions | What you email us | Legitimate interest in helping customers |
How long we keep it
- Account data and content: as long as your account exists. Delete your account and we delete them.
- Technical log lines: briefly, and no longer than needed to look into a fault or abuse.
- Invoices and what belongs with them: seven years, because Dutch tax law requires it.
Who else sees your data
We do not sell your data and we do not use it to train models. We use the following parties, and no more than that:
| Party | For what | Where |
|---|---|---|
| Hetzner Online GmbH | The servers running the service and the database | Germany |
| Amazon Web Services EMEA SARL | Storing attachments, daily database backups and sending email | Frankfurt, Germany |
| Mollie B.V. | Handling payments | The Netherlands |
All of this processing takes place inside the European Economic Area. We pass nothing to countries outside it. If that changes, we update this statement and tell you beforehand.
Visitor statistics
We count which pages are visited with Matomo, which we run ourselves on a server of our own at Hetzner in Germany. Those numbers do not go to Google or to any other company, and no cookie is set for them. For pages behind the login we do not pass on the real address but the pattern of it, /projects/{projectId} instead of the name of your project: that shows us which screen is used, without the names of projects or tasks ending up in the statistics.
Cookies
We use one cookie: the session cookie that lets the service know it is you after you log in. Our visitor statistics work without a cookie and there are no third-party trackers on our site, so there is no cookie banner either. If you choose to be remembered when you log in, we set a second cookie that keeps you signed in.
For your preferences on this device, such as light or dark and how dense the lists are, we use your browser's local storage. That stays on your own device.
Security
Traffic is encrypted over https. Passwords are stored only as a hash. You can set up two-factor authentication or a passkey. Inside the service there is access control per project and per section, so someone you invite with limited access sees only what you shared and not the rest of the project. An invitation link works once.
The database is backed up daily, stored encrypted with Amazon Web Services in Frankfurt. Those backups exist to bring the service back after a failure; they are not a replacement for copies of your own.
Your rights
You may ask us for access to your data, for correction, for deletion, for restriction of processing, and for a copy in a machine-readable format. You may also object to processing based on our legitimate interest.
You can delete your account yourself, in the settings. For the other requests, email support@taskstand.app; we answer within a month.
If you think we handle your data badly, you can complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.
Changes
If what we process or who we use changes, we update this statement. If the change is substantial, we tell you at the email address on your account.
Contact
Questions about your data? Email support@taskstand.app. There is no data protection officer; that question reaches amphora.interactive directly.