Privacy Policy
This policy explains what Tassqi processes, why it is needed, which services may receive data, and how to exercise your rights.
Last updated: 31 August 2026
1. Who is responsible
Tassqi is operated by BITS Blackrock IT Solutions LLC, 8 Ali Basha Zulfakar St, Mostafa Kamel, Sidi Gaber, Alexandria, Egypt (Commercial Registration No. 191833; Unified Corporate Registry No. 01000191833), represented by Karim Bremer, Chief Executive Officer.
For account administration, service operation, billing, security, and direct support, BITS acts as the data controller. When an organization uses Tassqi to manage its own people, projects, and client work, that organization determines the purpose of its workspace content and BITS processes that content on its behalf.
2. Data Tassqi processes
- Account and organization data: name, email address, authentication and organization identifiers, membership, role, language, and account status.
- Workspace content: projects, tasks, milestones, commitments, decisions, reasons, comments, meeting notes, status information, and the people or clients associated with that work.
- Operational and security data: timestamps, audit events, request and delivery status, device or browser information, and network identifiers where they are recorded by the service or infrastructure for security and reliability.
- Billing data: plan, trial, customer, subscription, and transaction references when paid billing is enabled. Full payment-card details are handled by Stripe and are not stored by Tassqi.
- Integration data: configuration, identifiers, tokens, messages, and delivery records needed for an integration that an authorized administrator enables.
- AI input and output: only when an AI feature is enabled and a user invokes it, the selected instructions, workspace facts, or meeting text and the model response needed for that request.
3. Purposes and legal bases
We process data to:
- create and secure accounts and organizations;
- provide the project-management, notification, reporting, and collaboration service;
- execute requested integrations and AI features;
- provide support, prevent abuse, investigate incidents, and maintain auditability;
- administer subscriptions and comply with accounting or legal duties; and
- improve reliability using service-level operational information.
Depending on the context, the basis is performance of a contract or steps requested before a contract, compliance with a legal obligation, legitimate interests in operating and protecting the service, or consent where the applicable law requires it. Under Egypt's Personal Data Protection Law No. 151 of 2020, additional conditions may apply to collection and international transfers. EEA users may also rely on the rights and legal bases provided by the GDPR.
4. Service providers and destinations
| Service | Purpose | Data involved |
|---|---|---|
| Hetzner Online | Application, database, and supporting infrastructure in Germany | Account, workspace, and operational data |
| Clerk | Authentication and organization identity | Account, sign-in, membership, and security data |
| Stripe | Checkout, subscription management, and payment processing when enabled | Billing contact, customer, subscription, and payment data |
| Resend or Google Gmail | Transactional email, depending on the configured delivery provider | Recipient, subject, message, and delivery data |
| Anthropic | User-requested AI processing, only where the feature is enabled | The bounded input and context required for the request, plus model output |
| Connected services | Slack, Google Chat, GitHub, webhooks, or calendar feeds when enabled | Only configuration and work data required for the selected integration |
Some providers may process data outside Egypt or the EEA. We assess the applicable contractual and legal safeguards before enabling a provider for production data. An API credential by itself is not treated as proof that a provider is approved for customer data.
5. AI features
Tassqi does not silently create tasks from model output. AI-generated proposals remain drafts until a user reviews and confirms them, and external or irreversible actions require approval. When production AI processing is not approved or configured, the provider call is disabled. Do not submit secrets or data that your organization is not authorized to process.
6. Cookies and browser storage
Tassqi uses authentication and security storage supplied by Clerk, a theme-preference cookie, and local or session storage for interface preferences such as onboarding state, saved views, and the last project opened. These are used to provide the service, not for advertising. The Tassqi application does not currently deploy advertising trackers or a behavioral marketing analytics product.
7. Retention, export, and deletion
Workspace data is retained while the account or organization is active and as needed to provide the service. After a verified deletion request, data is removed from the active service unless a limited record must be retained for legal, accounting, fraud-prevention, dispute, or security purposes. Backup copies expire through the applicable backup cycle rather than being used as a live record. Project data can be exported as CSV before an organization is removed.
See the data-deletion procedure for the request and verification process.
8. Security and access
Tassqi applies role-based access, organization separation, audit records, encrypted transport, controlled production access, backup and restore procedures, and security review. No online service can promise absolute security. Please report a suspected incident through the contact route below without including credentials in the message.
9. Your rights
Subject to the law that applies to you, you may request information, access, correction, deletion, restriction, objection, or portability, and may withdraw consent without affecting prior lawful processing. We may need to verify your identity and authority over an organization before acting. You may also complain to the competent data-protection authority, including Egypt's Personal Data Protection Center where applicable.
10. Contact and changes
Submit privacy requests through the BITS contact form or call +20 155 45 14 10 8. We publish material changes on this page and update the date above.