Scope and who we are
This Privacy Policy explains how Managed Tasks LLC, a Montana limited liability company (“Managed Tasks,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information when you visit mtasks.io, create or use an account, communicate with us, purchase services, use our hosted platform, or interact with our APIs, integrations, client experience, automation, and artificial-intelligence features (collectively, the “Service”).
This Policy applies to personal information Managed Tasks handles for its own business purposes. It also explains our role when a customer asks us to process personal information in a managed workspace. It does not govern the privacy practices of our customers, connected third-party services, or websites we do not control.
Managed Tasks LLC is located at 40 Spanish Peak Dr, Unit 101 #166, Bozeman, MT 59718. Privacy questions and requests may be sent to sales@mtasks.io.
Our roles: controller and processor
Managed Tasks as controller. We determine the purposes and means of processing personal information related to our website, sales inquiries, direct customer relationship, account administration, authentication, billing, support, security, service telemetry, communications, product improvement, and legal compliance. In this role, Managed Tasks is the controller under the GDPR and may be the business under California privacy law.
Managed Tasks as processor or service provider. Customers determine the purposes and means of processing personal information they submit to managed workspaces, including client, contact, task, project, service, document, communication, time, billing, integration, and automation data (“Customer Data”). For that information, Managed Tasks generally acts as processor under the GDPR or service provider or contractor under the CCPA. The customer’s privacy notice and instructions govern the processing, and you should direct a request about Customer Data to the customer that controls the relevant workspace.
Our Terms of Service, applicable order, and any data processing agreement provide additional terms for Customer Data.
Personal information we collect
Depending on how you interact with the Service, we may collect the following categories:
- Identity and contact information: name, business email, telephone number, organization, title, role, mailing address, and account identifiers.
- Account and authentication information: login identifiers, authentication events, session information, workspace memberships, roles, capabilities, security settings, and connected identity-provider information. Authentication secrets are protected using security controls appropriate to their type.
- Commercial and transaction information: subscription, order, billing contact, invoice, payment status, plan, usage entitlement, and transaction records. Payment-card processing is performed by our payment provider; we do not receive full payment-card numbers.
- Device, network, and usage information: IP address, approximate location derived from IP, browser and device type, operating system, referral information, pages or features used, timestamps, performance measurements, errors, diagnostic events, and security activity.
- Communications: sales inquiries, support requests, feedback, meeting information, correspondence, and records of communications with us.
- Integration and connected-service information: account identifiers, authorization grants, configuration, synchronization state, webhook events, and content a user instructs a connected service to exchange with Managed Tasks.
- Professional information: employer, team, job function, industry, service model, team size, and business needs.
- Inferences: preferences, likely areas of interest, account-health signals, or product recommendations derived from interactions with the Service.
- Customer Data: information submitted to a workspace by customers and authorized users. The categories depend on the customer’s services, configuration, and instructions and may include information about customer personnel, contractors, clients, and other individuals.
We do not intentionally request sensitive personal information through our public sales form. A managed workspace may contain sensitive information when a customer determines that it is appropriate and lawful to submit it.
Sources of personal information
We collect personal information from:
- you, when you create an account, submit a form, configure the Service, communicate with us, or otherwise provide information;
- your organization, workspace administrators, colleagues, clients, or collaborators who invite you or provide information about your role;
- your browser, device, and use of the website or Service;
- identity providers, payment providers, integrations, API clients, webhook senders, MCP clients, and other services you or your organization connect;
- service providers that help us operate, secure, support, measure, and communicate about the Service; and
- business partners, public professional sources, or referrals where lawful and relevant to a business relationship.
How and why we use personal information
We use personal information to:
- provide, configure, authenticate, operate, maintain, support, and troubleshoot the Service;
- create and administer accounts, workspaces, permissions, subscriptions, orders, invoices, and payments;
- fulfill customer instructions involving integrations, APIs, webhooks, MCP tools, automation, and AI features;
- communicate about sales inquiries, service events, security, support, billing, updates, and requested information;
- monitor performance, analyze use, improve features, develop new capabilities, and understand customer needs;
- protect users, customers, the Service, and others; detect fraud, misuse, unauthorized access, and security threats; and enforce agreements;
- comply with law, respond to lawful requests, preserve legal claims, complete corporate transactions, and meet accounting, tax, and recordkeeping obligations; and
- send business-to-business marketing where permitted, subject to applicable consent and opt-out requirements.
Where the GDPR applies, we rely on one or more of these legal bases: performance of a contract or steps requested before entering a contract; compliance with legal obligations; our legitimate interests in operating, securing, supporting, improving, and communicating about the Service; consent where required; and establishment, exercise, or defense of legal claims. You may withdraw consent at any time, but withdrawal does not affect processing already performed lawfully.
How we disclose personal information
We may disclose personal information to the following categories of recipients for the purposes described in this Policy:
- Service providers and processors that provide hosting, storage, database, identity, email, monitoring, security, support, analytics, payment, professional, and related operational services.
- Connected services and customer-authorized recipients when a user or customer enables an integration, API, webhook, MCP client, payment workflow, accounting connection, automation, or other data exchange.
- Workspace customers and authorized users according to workspace configuration, membership, roles, permissions, client visibility, and user instructions.
- Professional advisers such as attorneys, auditors, insurers, and accountants where reasonably necessary and subject to appropriate duties.
- Authorities or other parties for legal and safety reasons when we reasonably believe disclosure is required by law or needed to protect rights, security, safety, property, users, or the Service.
- Transaction participants in connection with due diligence, financing, reorganization, merger, acquisition, or sale, subject to confidentiality and applicable law.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising as those terms are defined by the CCPA. We do not use personal information from a customer workspace for our own independent advertising purposes.
Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, maintain security and continuity, honor customer instructions, comply with law and contracts, resolve disputes, and establish or defend legal claims.
Retention depends on the type and context of the information. Account and subscription records are generally retained while an account is active and for an appropriate period afterward. Customer Data is retained according to the customer relationship, applicable order, workspace controls, backup cycle, and legal obligations. Security, audit, diagnostic, and transaction records are retained according to operational, integrity, fraud-prevention, accounting, and legal needs. Sales and support communications are retained while the relationship or request remains relevant and for a reasonable period afterward.
When information is no longer required, we delete it, anonymize it, or isolate it until deletion is completed. Data may remain temporarily in backups or records that cannot reasonably be altered, subject to access restrictions and scheduled expiration.
Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information. These include controls for authentication, tenant context, authorization, database access, encryption, secrets, logging, monitoring, deployment, backup, incident response, and service-provider management.
No method of transmission, storage, or processing is completely secure. You are responsible for using appropriate authentication, protecting credentials and devices, assigning minimum necessary permissions, reviewing connected services and automation, and notifying us promptly of suspected compromise.
International data transfers
Managed Tasks is based in the United States, and personal information may be processed in the United States and other countries where we, our customers, or our service providers operate. Those countries may have data-protection rules that differ from the rules in your jurisdiction.
When the GDPR or another law requires safeguards for a transfer, we use an approved legal mechanism as applicable, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, a corresponding United Kingdom transfer mechanism, or another lawful transfer basis. You may contact us for information about safeguards relevant to your personal information.
EEA, United Kingdom, and Swiss privacy rights
If applicable law provides these rights, you may request access to personal information, correction, erasure, restriction of processing, data portability, or objection to processing based on legitimate interests or direct marketing. Where processing relies on consent, you may withdraw consent at any time.
You also have the right to lodge a complaint with the data-protection authority where you live, work, or believe a violation occurred. We encourage you to contact us first so we can address the concern.
Managed Tasks does not use personal information it controls to make a decision based solely on automated processing that produces legal or similarly significant effects. Customers may configure workflow or automation features for Customer Data; the customer determines that processing and is responsible for its notices, lawful basis, rights handling, and required human review.
California privacy notice
This section supplements the rest of this Policy for California residents. Terms defined by the California Consumer Privacy Act, as amended (“CCPA”), have the same meaning here. The disclosures below describe our practices during the preceding twelve months and our current practices.
| Category | Examples | Business purposes | Disclosed to |
|---|---|---|---|
| Identifiers | Name, email, IP address, account and organization identifiers | Provide accounts and Service; communicate; secure and support operations | Service providers; customer-authorized users and connected services; legal recipients |
| Customer-record information | Contact, billing, account, and business relationship details | Sales, contracting, billing, support, administration, and compliance | Service providers; professional advisers; transaction or legal recipients |
| Commercial information | Orders, subscriptions, invoices, plan, payment status, and transaction history | Provide and administer paid services; accounting, fraud prevention, and compliance | Payment and operational providers; professional advisers; legal recipients |
| Internet or electronic-network activity | Device, browser, pages and features used, logs, sessions, errors, and security events | Operate, secure, measure, support, and improve the Service | Hosting, analytics, monitoring, identity, security, and support providers |
| Geolocation | Approximate location derived from IP address | Security, fraud prevention, localization, and Service operation | Hosting, security, and monitoring providers |
| Professional or employment information | Organization, role, title, team size, industry, and service model | Account administration, sales, support, product fit, and communications | Operational providers; customer-authorized users; professional advisers |
| Communications and user content | Sales and support messages, feedback, Customer Data, files, comments, and instructions | Respond to requests; provide, support, and secure the Service; fulfill customer instructions | Service providers; workspace recipients; connected services; legal recipients |
| Inferences | Preferences, areas of interest, product recommendations, and account-health indicators | Personalize, support, improve, and communicate about the Service | Operational, analytics, support, and communications providers |
| Sensitive personal information | Account login and security information; sensitive content a customer chooses to submit | Authenticate and secure accounts; provide the customer-directed Service | Identity and security providers; customer-authorized workspace and connected-service recipients |
We use and disclose sensitive personal information only for permitted operational purposes or as directed by the customer that controls the relevant workspace. We do not use or disclose sensitive personal information for purposes that require a “Limit the Use of My Sensitive Personal Information” link under the CCPA.
No sale or sharing. We have not sold personal information or shared it for cross-context behavioral advertising. We do not knowingly sell or share personal information of consumers under sixteen years of age.
Subject to scope and exceptions in the CCPA, California residents may request to know the categories and specific pieces of personal information we collected; know the sources, purposes, and recipient categories; delete personal information; correct inaccurate personal information; opt out of sale or sharing; limit certain uses of sensitive personal information; and receive equal service and pricing without unlawful discrimination for exercising a right.
You or an authorized agent may submit a request by emailing sales@mtasks.io. We will verify a request using information appropriate to its sensitivity and the risk of unauthorized disclosure or deletion. An authorized agent may be required to provide signed permission, and we may ask you to verify identity or confirm authority directly. We will respond within the period required by applicable law and explain any basis for denying or limiting a request.
Other United States privacy rights
Residents of other U.S. states may have rights to access, correct, delete, or obtain a portable copy of personal data; opt out of targeted advertising, sale, or certain profiling; or appeal a decision on a request. The availability and scope of a right depend on the applicable law and exemptions.
Managed Tasks does not sell personal information or process personal information it controls for targeted advertising. To submit a request or appeal, email sales@mtasks.io and identify your state of residence and the right you wish to exercise.
How to exercise privacy rights
Send a privacy request to sales@mtasks.io. Describe your relationship with Managed Tasks, the account or workspace involved, your jurisdiction, and the right you want to exercise. Do not send passwords or highly sensitive documents by ordinary email.
We may need to verify identity and authority before completing a request. We use information provided for verification only for that purpose and related security, fraud-prevention, and legal obligations. We may deny or limit a request where permitted by law, including when we cannot verify identity, another person’s rights would be affected, the information is controlled by a customer, or a legal exception applies.
If your request concerns data in a customer workspace, contact the customer that controls the workspace. We support our customers in responding to valid requests according to our contract and applicable data-protection law.
Children
The Service is designed for business organizations and is not directed to children under sixteen. We do not knowingly collect personal information directly from children under sixteen for our own purposes. If you believe a child has provided personal information to Managed Tasks, contact us so we can investigate and take appropriate action.
Changes and contact information
We may update this Policy to reflect changes in law, technology, the Service, or our privacy practices. We will post the revised Policy, update the effective date, and provide additional notice when required. Material changes apply prospectively unless law permits otherwise.
Questions, requests, and complaints may be sent to:
Managed Tasks LLC40 Spanish Peak Dr, Unit 101 #166
Bozeman, MT 59718
sales@mtasks.io