Security & Data Residency
Last updated: 19 June 2026
1. Where your data lives
Taskr stores live application data on Convex (AWS eu-west-1, Ireland). Daily backups are written to Amazon S3 and Cloudflare R2 in ap-southeast (Australia / APAC). This gives genuine dual EU + Australian data residency: EU for the live operational store, Australia/APAC for all backup copies.
2. Sub-processors
We use the following sub-processors to deliver the Taskr service. Each is bound by a data processing agreement consistent with the GDPR and the Australian Privacy Act 1988.
| Sub-processor | Purpose | Region |
|---|---|---|
| Convex | Primary database & serverless functions | AWS eu-west-1 (Ireland) |
| Amazon S3 | Backup storage & file attachments | ap-southeast (Australia) |
| Cloudflare R2 | Backup storage & CDN | ap-southeast (Australia) |
| WorkOS | Identity, authentication & SSO | US (SOC 2 Type II) |
| Vercel | Web application hosting & edge network | Global edge / US |
3. Encryption
All data in transit is encrypted with TLS 1.2 or higher. All data at rest — including database records and backup files — is encrypted using AES-256 (or equivalent) by default on Convex and AWS/Cloudflare infrastructure. Encryption keys are managed by the respective cloud providers under their HSM-backed key management services.
4. Backups & retention
Taskr performs daily automated backups of all customer data. Backups are retained for a minimum of 30 days, stored in the ap-southeast region (Amazon S3 and Cloudflare R2). In the event of data loss, we target a recovery-point objective (RPO) of 24 hours and a recovery-time objective (RTO) of 8 business hours. Formal uptime SLAs are not yet published; contact us at [email protected] if your organisation requires a written SLA.
5. Compliance posture
Taskr is designed and operated to comply with the EU General Data Protection Regulation (GDPR) and the Australian Privacy Act 1988 (Cth). Key commitments include:
- Lawful basis for all data processing activities
- Data subject rights: access, correction, export, and deletion on request
- Breach notification within 72 hours to affected parties and relevant authorities where required
- Data minimisation — we collect only what the service needs
- Data Processing Agreements (DPAs) in place with all sub-processors listed above
To request a copy of our DPA or to exercise data subject rights, email [email protected].
6. Access controls
Access to production systems is restricted to authorised personnel on a need-to-know basis. We enforce multi-factor authentication for all production access, and all access is logged and audited. Employees undergo security awareness training annually.
7. Vulnerability disclosure
If you discover a security vulnerability in Taskr, please disclose it responsibly by emailing [email protected]. We will acknowledge your report within 2 business days and work to resolve confirmed vulnerabilities promptly.
8. Contact
Questions about our security or data practices? Contact us at [email protected] or write to Taskr Pty Ltd, Sydney NSW, Australia.