Back

Legal information

Provisional document — the company details will be completed before launch.

Privacy policy

This policy describes how taact collects, uses and protects its users’ personal data, in accordance with the General Data Protection Regulation (GDPR).

Data controller

The data controller is [company name — to be completed], [address — to be completed], reachable at [e-mail — to be completed].

Data collected

We collect the data you provide (name, e-mail address, profile and billing information, content you create) as well as technical data required to run the service (connection logs, session identifiers).

Purposes

Your data is processed to: create and manage your account, provide the application’s features (projects, deliverables, invoices), ensure the security of the service and comply with our legal obligations, in particular accounting and invoicing.

Legal basis

Processing relies on the performance of the contract between us, compliance with legal obligations, your consent where applicable, and our legitimate interest in securing and improving the service.

Recipients and processors

Your data is accessible only to authorised taact staff and to our technical processors (hosting, e-mail delivery, artificial-intelligence processing), all located in the European Union or providing adequate safeguards. It is never sold.

Google Calendar integration

If you choose to connect your Google calendar, taact accesses it through the Google Calendar API, solely within the “view, edit and create events” scope (`calendar.events` authorisation). This connection is optional, triggered by you, and only occurs after your explicit consent on the Google authorisation screen.

taact uses this access only to synchronise your deliverable dates and appointments between the application and your calendar: creating, updating and deleting the corresponding events, and importing into taact the appointments you add on the Google side. No other use is made of this data.

Google access tokens are stored encrypted and are used only for this synchronisation. You can revoke access at any time from your taact account or from your Google Account security settings; disconnecting the calendar and deleting your taact account revoke the token and erase the events created by taact.

In accordance with the Google API Services User Data Policy (“Limited Use”), data obtained through the Google APIs is never sold, never used for advertising, not transferred to third parties except as necessary for the functionality, for a legal obligation or for security measures, and is not read by any human except with your consent, for security reasons or to comply with a legal obligation.

Retention period

Your data is kept for the entire lifetime of your account.

Authentication technical logs have a short retention: the IP address, a personal data item, is anonymised after 90 days, and aggregated usage data is deleted after 90 days.

When you delete your account, it is immediately deactivated and your e-mail address anonymised; access to your connected services, including Google Calendar, is revoked and the corresponding tokens deleted. The only data we are legally required to keep — in particular accounting and invoicing records — is retained for ten years, then deleted. You may at any time request the erasure of your personal data by exercising the rights described below.

Your rights

You have the right to access, rectify, erase, restrict, object to and port your data.

To exercise these rights, write to [DPO e-mail — to be completed]. You may also lodge a complaint with the competent supervisory authority.

Security

We implement appropriate technical and organisational measures (encryption, access control, hosting in the European Union) to protect your data against unauthorised access.