Security & Data Residency

Last updated: 19 June 2026

1. Where your data lives

Taskr stores live application data on Convex (AWS eu-west-1, Ireland). Daily backups are written to Amazon S3 and Cloudflare R2 in ap-southeast (Australia / APAC). This gives genuine dual EU + Australian data residency: EU for the live operational store, Australia/APAC for all backup copies.

2. Sub-processors

We use the following sub-processors to deliver the Taskr service. Each is bound by a data processing agreement consistent with the GDPR and the Australian Privacy Act 1988.

Sub-processorPurposeRegion
ConvexPrimary database & serverless functionsAWS eu-west-1 (Ireland)
Amazon S3Backup storage & file attachmentsap-southeast (Australia)
Cloudflare R2Backup storage & CDNap-southeast (Australia)
WorkOSIdentity, authentication & SSOUS (SOC 2 Type II)
VercelWeb application hosting & edge networkGlobal edge / US

3. Encryption

All data in transit is encrypted with TLS 1.2 or higher. All data at rest — including database records and backup files — is encrypted using AES-256 (or equivalent) by default on Convex and AWS/Cloudflare infrastructure. Encryption keys are managed by the respective cloud providers under their HSM-backed key management services.

4. Backups & retention

Taskr performs daily automated backups of all customer data. Backups are retained for a minimum of 30 days, stored in the ap-southeast region (Amazon S3 and Cloudflare R2). In the event of data loss, we target a recovery-point objective (RPO) of 24 hours and a recovery-time objective (RTO) of 8 business hours. Formal uptime SLAs are not yet published; contact us at [email protected] if your organisation requires a written SLA.

5. Compliance posture

Taskr is designed and operated to comply with the EU General Data Protection Regulation (GDPR) and the Australian Privacy Act 1988 (Cth). Key commitments include:

  • Lawful basis for all data processing activities
  • Data subject rights: access, correction, export, and deletion on request
  • Breach notification within 72 hours to affected parties and relevant authorities where required
  • Data minimisation — we collect only what the service needs
  • Data Processing Agreements (DPAs) in place with all sub-processors listed above

To request a copy of our DPA or to exercise data subject rights, email [email protected].

6. Access controls

Access to production systems is restricted to authorised personnel on a need-to-know basis. We enforce multi-factor authentication for all production access, and all access is logged and audited. Employees undergo security awareness training annually.

7. Vulnerability disclosure

If you discover a security vulnerability in Taskr, please disclose it responsibly by emailing [email protected]. We will acknowledge your report within 2 business days and work to resolve confirmed vulnerabilities promptly.

8. Contact

Questions about our security or data practices? Contact us at [email protected] or write to Taskr Pty Ltd, Sydney NSW, Australia.