Privacy Notice

Last updated 28 July 2026 · version 2026-07-28

Draft. This document is a working template. The bracketed details must be completed and the whole text reviewed by a qualified lawyer before RegTask accepts paying customers.

Who we are

RegTask is operated by [LEGAL ENTITY NAME], registered in Cyprus under company number [REG NUMBER], at [REGISTERED ADDRESS] (“we”, “us”). We are the data controller for the personal data described in this notice. You can reach us at [PRIVACY CONTACT EMAIL].

When you use RegTask to manage your own customers, you are the controller of their data and we act as your processor. That relationship is governed by the data processing terms in our Terms of Service.

What we collect and why

Only what the service needs to work:

  • Account data. Your name, email address, password hash (never the password itself) and, if you sign in with Google, the identifier Google gives us. Used to create and secure your account. Lawful basis: performance of our contract with you (art. 6(1)(b)).
  • Company data. Your company’s registered name, VAT and registration numbers, address, contact details, bank details and logo. Used to produce your invoices and receipts. Lawful basis: contract, and legal obligation for the records we must keep (art. 6(1)(b) and (c)).
  • Verification documents. A registration or VAT certificate you upload so we can confirm you represent the company you signed up as. Lawful basis: our legitimate interest in preventing fraud and impersonation on the platform (art. 6(1)(f)), balanced against the limited, business-only nature of what we ask for.
  • Your business content. The customers, jobs, invoices and payments you record. We hold this on your behalf as your processor; we do not use it for our own purposes.
  • Technical data. Server logs containing IP address, timestamp and the request made, kept to keep the service secure and available. Lawful basis: legitimate interest (art. 6(1)(f)).
  • Consent record. The date and version of the Terms and this notice that you accepted, so we can demonstrate consent as art. 7(1) requires.

We do not use cookies for advertising or analytics. The only cookies we set are strictly necessary: your session cookie, and a short-lived cookie during sign-in that protects against request forgery.

Verification documents in particular

We ask for business documents only, and we tell you so at the point of upload. Please do not send passports or identity cards, and redact anything a reviewer does not need. Files are stored outside any public web directory and can be read only by administrators of your own company and by the RegTask reviewer handling the check. They are never shared with third parties and are never used for anything other than verifying your company.

We delete the file 24 months after upload, or immediately when you delete it yourself in Settings → Company. After deletion we keep only a record that a document of a given name and type was checked, by whom and when — the audit trail, without the content.

Who we share data with

We use a small number of processors, each bound by a data processing agreement and none of whom may use your data for their own purposes:

  • [HOSTING PROVIDER]. Servers and database hosting, in the EU.
  • Google. Only if you choose Google sign-in, and only to verify your identity.
  • Revolut. Only if you enable card payment links, to create and check those payments.
  • Your own email provider. Invoice and receipt emails leave through the SMTP server you configure, so they are sent by your provider, not ours.

We do not sell personal data, and we do not transfer it outside the EEA except where a processor above does so under an adequacy decision or standard contractual clauses.

How long we keep it

  • Account and company data. For as long as your account is open, then deleted within 90 days of closure.
  • Invoices, receipts and their underlying records. Retained while your account is open. Note that tax law in your country may require you to keep these for several years — exporting them before closing your account is your responsibility.
  • Verification documents. 24 months from upload, or immediately on your request.
  • Server logs. 90 days.

Your rights

Under the GDPR you may request access to your personal data, correction of anything inaccurate, deletion, restriction of processing, portability of data you provided, and you may object to processing carried out on the basis of legitimate interest. Where processing rests on consent, you may withdraw it at any time without affecting what was done before.

Write to [PRIVACY CONTACT EMAIL] and we will respond within one month. If you are not satisfied you may complain to the Office of the Commissioner for Personal Data Protection in Cyprus, or to the supervisory authority where you live.

Security

Passwords are hashed with bcrypt. Sessions use signed, httpOnly cookies. Access to your data is scoped to your company throughout the application, uploads are served only to authenticated users, and administrative access to the platform is limited to named staff.

Changes

If we change this notice materially we will tell you in the app and ask you to accept the new version. Each version is dated, and we record which one you accepted.

Questions? Write to [CONTACT EMAIL].