Data Processing Agreement
Last updated: August 30, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Taackk Pty Ltd (ABN 83 701 856 671) ("Taackk", "Processor") and the business entity that has accepted those terms ("Controller"). It governs Taackk's processing of personal data on behalf of the Controller in accordance with Article 28 of the EU General Data Protection Regulation ("GDPR").
1. Definitions
- "Personal Data" has the meaning given in Article 4(1) GDPR.
- "Processing" has the meaning given in Article 4(2) GDPR.
- "Data Subject" means any identified or identifiable natural person whose Personal Data is processed under this DPA.
- "Sub-processor" means any third party engaged by Taackk to process Personal Data on behalf of the Controller.
- "Standard Contractual Clauses" or "SCCs" means the clauses adopted by the European Commission under Article 46(2)(c) GDPR for international data transfers.
2. Scope and nature of processing
Taackk processes Personal Data solely to provide the fractional executive marketplace services described in the Terms of Service. The categories of Personal Data and Data Subjects are as follows:
| Category | Data Subjects | Examples |
|---|---|---|
| Account & identity data | Business users, leaders | Name, email, role, subscription tier |
| Professional profile data | Leaders | Work history, skills, publications, availability |
| Communications data | Business users, leaders | Messages, engagement notes, briefs |
| Usage & audit data | Business users, leaders | IP addresses, session logs, action timestamps |
3. Controller obligations
The Controller warrants and represents that:
- It has a lawful basis for transferring Personal Data to Taackk for processing.
- It has provided all required notices to, and obtained all required consents from, Data Subjects.
- Its instructions to Taackk comply with applicable data protection laws.
- It will promptly inform Taackk if it becomes aware of any inaccuracy in Personal Data held by Taackk.
4. Taackk's obligations as Processor
Taackk shall, in its capacity as Processor:
- Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law.
- Ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations.
- Implement technical and organisational measures as described in Section 5 to ensure a level of security appropriate to the risk.
- Assist the Controller in fulfilling its obligations to respond to Data Subject requests under Chapter III GDPR.
- Assist the Controller in ensuring compliance with Articles 32–36 GDPR (security, breach notification, DPIAs).
- At the Controller's choice, delete or return all Personal Data upon termination of the services, and delete existing copies unless retention is required by law.
- Make available all information necessary to demonstrate compliance with Article 28 GDPR and allow for audits conducted by the Controller or a mandated auditor, on reasonable notice.
5. Security measures
Taackk maintains the following technical and organisational security measures:
- Encryption at rest: AES-256-GCM field-level encryption for sensitive personal data (tokens, credentials).
- Encryption in transit: TLS 1.2+ enforced for all data in transit.
- Access control: Role-based access control (RBAC) with least-privilege principles; multi-factor authentication available for all accounts.
- Audit logging: Append-only audit trail with PII redaction for all data access and modification events, retained for 12 months.
- Vulnerability management: Regular dependency audits, automated security scanning, and penetration testing.
- Incident response: Documented incident response plan; Data Subjects and supervisory authorities notified within 72 hours of a qualifying breach.
- Data minimisation: Personal Data is collected only to the extent necessary for the stated purpose.
6. Sub-processors
The Controller grants Taackk general authorisation to engage the following sub-processors. Taackk will notify the Controller of any intended changes (additions or replacements) at least 14 days in advance, giving the Controller the opportunity to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing | USA (SCCs apply) |
| Google LLC | Analytics (GA4), calendar integration | USA (SCCs apply) |
| Microsoft Corporation | Calendar integration (Outlook) | USA (SCCs apply) |
| OpenAI, Inc. | AI-assisted profile generation | USA (SCCs apply) |
Taackk imposes data protection obligations on all sub-processors equivalent to those in this DPA and remains fully liable to the Controller for the performance of sub-processors' obligations.
7. International transfers
Where Personal Data is transferred outside the European Economic Area (EEA) or the UK, Taackk ensures an adequate level of protection through the use of Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or other approved transfer mechanisms. A copy of the applicable SCCs is available on request.
8. Data Subject requests
Taackk will promptly notify the Controller of any Data Subject request received directly and will not respond to such requests without the Controller's authorisation, except where required by law. Taackk will provide reasonable assistance to enable the Controller to respond within the statutory timeframe (typically 30 days under GDPR).
9. Personal data breaches
Taackk will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach. The notification will include, to the extent available: the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed to address the breach.
10. Term and termination
This DPA remains in force for the duration of the Terms of Service. Upon termination, Taackk will, at the Controller's written request, delete or return all Personal Data within 30 days, unless applicable law requires longer retention. Taackk will certify deletion in writing upon request.
11. Governing law
This DPA is governed by the laws of New South Wales, Australia, without prejudice to any mandatory provisions of GDPR or UK GDPR that apply to the Controller. For EU/UK Controllers, the Standard Contractual Clauses shall take precedence over this clause to the extent of any conflict.
12. Contact
For questions about this DPA, data protection enquiries, or to request a signed copy, contact our Privacy team at [email protected].