TaskMatch.ai
Legal / Compliance

Compliance & Data Protection

How TaskMatch approaches data protection and regulatory compliance — the principles behind our processing, the rights available to data subjects, and how requests are handled.

Last updated: March 1, 2026

1. Compliance overview

TaskMatch.ai is operated by Tauraco and positions compliance as an operating discipline that spans platform design, data handling, access control, and review processes.

Processing of personal data is aligned with the EU General Data Protection Regulation (GDPR / RGPD) and comparable regimes. TaskMatch designs its controls around the SOC 2 Type II framework — certification is an objective on our roadmap, and no audit has been completed to date — and makes a Data Processing Agreement (DPA) available to enterprise customers.

Compliance posture is strongest when legal, technical, and operational controls are aligned instead of being treated as separate workstreams.

2. Processing principles

Core principles include lawful use, purpose limitation, minimization, accuracy, storage limitation, confidentiality, and accountability.

These principles should inform both product behavior and internal decision-making around data processing.

  • Only collect what the product and legal posture require
  • Preserve clear reasons for processing and retention
  • Apply review discipline to high-impact workflows

3. Data subject rights

Users may be entitled to access, correction, deletion, portability, restriction, objection, or related rights depending on applicable law.

Support for these rights should combine platform tooling with manual escalation paths where needed.

Where a request cannot be fully satisfied — for example, because of legal retention duties or the rights of others — we explain the reason for the limitation.

4. Operational posture

Compliance also depends on records of processing, internal controls, documented retention, and secure operational boundaries.

Because trust is core to the platform, we keep these controls documented and available for review by clients and partners.

Reviewability, traceability, and documented control ownership are all part of the broader compliance posture presented by the platform.

  • Role-scoped access and account boundaries
  • Operational logs and auditable state transitions
  • Controls designed against the SOC 2 Type II framework (certification is an objective; no audit completed to date)
  • Vetted sub-processors under data-processing agreements, with data hosted in the EU
  • Encryption of briefs and uploaded documents at rest and in transit
  • Retention and rights-handling process discipline

Sensitive material submitted in briefs is scoped to the assigned executor for the duration of a task, is never used to train models, and can be redacted or deleted on request.

5. Requests and escalation

Data-subject and privacy requests (access, correction, deletion, portability, restriction, and objection under GDPR / RGPD and comparable laws) can be sent to [email protected]. Enterprise customers can request the DPA, sub-processor list, and security questionnaire responses through the same channel.