subtask.app Legal Portal

Privacy policy

1. What This Policy Covers

This policy explains which personal data is processed when you use Subtask (subtask.app), for what purpose, who it is shared with, and what rights you have. The identity and contact details of the data controller are at the end of this page.

2. An Important Distinction: Your Own Data and Data Entered by Your Employer

Subtask processes personal data in two different situations, and responsibility differs between them:

  • Data you give us directly: The email address and name you enter when creating an account, and messages you send through the contact form. We are the data controller for this data.
  • Data entered by your employer: Personnel records, salary, leave and asset records held by your company in the HR module. Your company decides why this data is collected and how long it is kept; for this data your company is the data controller and Subtask acts only as a data processor providing the infrastructure. Requests about this data should go to your employer first.

3. Personal Data We Process

Account data: Email address, your password (stored encrypted), profile photo, interface language, last sign-in time and your marketing email preference. If you sign in with Google or Apple, the authentication information those providers return.

HR and personnel data (entered by your employer): First name, surname, date of birth, national identification number, sex, marital status, military service status, nationality, home address, phone; salary, currency, registration number, working type, start date and contract end date; uploaded personnel files; education and work history; leave records and leave notes.

Data about employees' relatives: Your employer may record the name, surname, phone, date of birth and national identification number of your relatives. These people are not Subtask users; your employer is responsible for collecting this data and for informing the individuals concerned.

Content created while using the service: Chat messages and attachments, issue records, comments, meeting and topic notes, action items, knowledge base documents, quick notes, help desk requests, announcements and asset records.

Audit records: We keep a record of who changed which item and when inside the application.

Technical data: IP address, browser and device information, session identifier; and, if you consent, Google Analytics measurement data.

4. Purposes of Processing

  • Creating your account, authenticating you and maintaining your session
  • Providing the service and connecting your team's data together
  • Sending service-related notifications and transactional email
  • Calculating and invoicing your use of paid modules
  • Detecting errors, maintaining security and preventing abuse
  • Sending product announcements if you have opted in
  • Meeting our legal obligations

You can stop marketing email at any time with a single click, using the link at the bottom of every message or from your account settings.

5. Third Parties We Share Data With

We use the following service providers in order to deliver the service. We do not share, sell or rent your data to anyone else:

  • Sentry (error tracking, European Union region): When an error occurs in the application, technical information including your IP address is sent along with the error report.
  • SendGrid / Twilio (email delivery): Your email address, your name and the content of the message sent.
  • ImageKit and Cloudinary (image storage and delivery): Images you upload to issues and to the knowledge base.
  • Google Analytics (web analytics): Only if you have accepted analytics cookies.
  • Google reCAPTCHA: Device and browser information, for bot protection on the sign-up form.
  • Google and Apple: Only if you use social sign-in, for authentication.
  • Iyzico (payments): If you pay by card, your card details go directly to Iyzico and are never stored on Subtask servers. We receive only the fact that a payment was made.
  • Google Play: If you pay from the Android application, the transaction is handled through Google Play.

If you pay by bank transfer or cryptocurrency, the transfer details, sender name or wallet information you enter reach us so that we can match the payment, and are stored with your payment record.

We may also be obliged to share information in response to lawful requests from competent public authorities.

6. Where Data Is Stored and International Transfers

Subtask's servers and database are located within the European Union / European Economic Area. Some of the service providers listed above are located outside Europe. Your personal data is therefore transferred abroad. By creating an account and using the service you proceed in the knowledge that this transfer takes place.

7. Retention Periods

To be clear: at present there is no automatic deletion period defined for most data. The rules we do apply are:

  • Accounts whose email address has not been verified are deleted automatically after 48 hours.
  • Company records left with no users are deleted automatically.
  • Other data is kept until you or your company deletes it, or the account is closed.

If you want your data deleted, you can contact us at the address below. For personnel data entered by your employer, you need to address your request to your company first.

8. Security

Passwords are stored encrypted, connections are made over an encrypted channel, and access to data is limited by role-based permissions. Even so, we cannot guarantee that any transmission or storage of data over the internet is 100% secure.

9. Your Rights

Under Article 11 of Turkish Personal Data Protection Law no. 6698 you have the right to: learn whether your personal data is being processed; request information if it has been processed; learn the purpose of processing and whether the data is used in accordance with that purpose; know the third parties to whom the data is transferred in Turkey or abroad; request correction if it has been processed incompletely or inaccurately; request its erasure or destruction; request that these actions be notified to the third parties to whom the data has been transferred; object to a result reached against you through analysis carried out exclusively by automated systems; and claim compensation if you suffer damage due to unlawful processing.

If you are located in the European Union, under the GDPR you have the rights of access, rectification, erasure, restriction of processing, data portability and objection.

You can send your requests to the contact address below.

10. Changes

When we update this policy we publish it on this page and change the update date shown below. For significant changes we notify registered users by email.

We use cookies to improve user experience and analyze website traffic. By clicking “Accept“, you agree to our website's cookie use as described in our Cookie Policy.
CONTACT US
CLOSE
error_outline Name, surname, email and message field must be valid!
error_outline Email field must be valid!
error_outline Unauthorized transaction!