Data Processing Agreement

Last updated: August 30, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Taackk Pty Ltd (ABN 83 701 856 671) ("Taackk", "Processor") and the business entity that has accepted those terms ("Controller"). It governs Taackk's processing of personal data on behalf of the Controller in accordance with Article 28 of the EU General Data Protection Regulation ("GDPR").

1. Definitions

  • "Personal Data" has the meaning given in Article 4(1) GDPR.
  • "Processing" has the meaning given in Article 4(2) GDPR.
  • "Data Subject" means any identified or identifiable natural person whose Personal Data is processed under this DPA.
  • "Sub-processor" means any third party engaged by Taackk to process Personal Data on behalf of the Controller.
  • "Standard Contractual Clauses" or "SCCs" means the clauses adopted by the European Commission under Article 46(2)(c) GDPR for international data transfers.

2. Scope and nature of processing

Taackk processes Personal Data solely to provide the fractional executive marketplace services described in the Terms of Service. The categories of Personal Data and Data Subjects are as follows:

CategoryData SubjectsExamples
Account & identity dataBusiness users, leadersName, email, role, subscription tier
Professional profile dataLeadersWork history, skills, publications, availability
Communications dataBusiness users, leadersMessages, engagement notes, briefs
Usage & audit dataBusiness users, leadersIP addresses, session logs, action timestamps

3. Controller obligations

The Controller warrants and represents that:

  • It has a lawful basis for transferring Personal Data to Taackk for processing.
  • It has provided all required notices to, and obtained all required consents from, Data Subjects.
  • Its instructions to Taackk comply with applicable data protection laws.
  • It will promptly inform Taackk if it becomes aware of any inaccuracy in Personal Data held by Taackk.

4. Taackk's obligations as Processor

Taackk shall, in its capacity as Processor:

  • Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law.
  • Ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations.
  • Implement technical and organisational measures as described in Section 5 to ensure a level of security appropriate to the risk.
  • Assist the Controller in fulfilling its obligations to respond to Data Subject requests under Chapter III GDPR.
  • Assist the Controller in ensuring compliance with Articles 32–36 GDPR (security, breach notification, DPIAs).
  • At the Controller's choice, delete or return all Personal Data upon termination of the services, and delete existing copies unless retention is required by law.
  • Make available all information necessary to demonstrate compliance with Article 28 GDPR and allow for audits conducted by the Controller or a mandated auditor, on reasonable notice.

5. Security measures

Taackk maintains the following technical and organisational security measures:

  • Encryption at rest: AES-256-GCM field-level encryption for sensitive personal data (tokens, credentials).
  • Encryption in transit: TLS 1.2+ enforced for all data in transit.
  • Access control: Role-based access control (RBAC) with least-privilege principles; multi-factor authentication available for all accounts.
  • Audit logging: Append-only audit trail with PII redaction for all data access and modification events, retained for 12 months.
  • Vulnerability management: Regular dependency audits, automated security scanning, and penetration testing.
  • Incident response: Documented incident response plan; Data Subjects and supervisory authorities notified within 72 hours of a qualifying breach.
  • Data minimisation: Personal Data is collected only to the extent necessary for the stated purpose.

6. Sub-processors

The Controller grants Taackk general authorisation to engage the following sub-processors. Taackk will notify the Controller of any intended changes (additions or replacements) at least 14 days in advance, giving the Controller the opportunity to object.

Sub-processorPurposeLocation
Stripe, Inc.Payment processingUSA (SCCs apply)
Google LLCAnalytics (GA4), calendar integrationUSA (SCCs apply)
Microsoft CorporationCalendar integration (Outlook)USA (SCCs apply)
OpenAI, Inc.AI-assisted profile generationUSA (SCCs apply)

Taackk imposes data protection obligations on all sub-processors equivalent to those in this DPA and remains fully liable to the Controller for the performance of sub-processors' obligations.

7. International transfers

Where Personal Data is transferred outside the European Economic Area (EEA) or the UK, Taackk ensures an adequate level of protection through the use of Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or other approved transfer mechanisms. A copy of the applicable SCCs is available on request.

8. Data Subject requests

Taackk will promptly notify the Controller of any Data Subject request received directly and will not respond to such requests without the Controller's authorisation, except where required by law. Taackk will provide reasonable assistance to enable the Controller to respond within the statutory timeframe (typically 30 days under GDPR).

9. Personal data breaches

Taackk will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach. The notification will include, to the extent available: the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed to address the breach.

10. Term and termination

This DPA remains in force for the duration of the Terms of Service. Upon termination, Taackk will, at the Controller's written request, delete or return all Personal Data within 30 days, unless applicable law requires longer retention. Taackk will certify deletion in writing upon request.

11. Governing law

This DPA is governed by the laws of New South Wales, Australia, without prejudice to any mandatory provisions of GDPR or UK GDPR that apply to the Controller. For EU/UK Controllers, the Standard Contractual Clauses shall take precedence over this clause to the extent of any conflict.

12. Contact

For questions about this DPA, data protection enquiries, or to request a signed copy, contact our Privacy team at [email protected].