Last updated: 17 July 2026
This Privacy Policy explains how Taskpath, operated by Metanol B.V. ("Taskpath", "we", "us"), handles personal data. Taskpath is designed to be EU-sovereign: it runs on EU infrastructure, uses EU-hosted AI, and keeps your work on systems you control.
Application data is hosted in the EU (Hetzner, Germany). AI processing uses an EU-hosted provider (Mistral) by default; you may connect your own AI provider. We do not sell personal data, and we do not use Customer Data to train third-party models.
We process account and usage data to perform our contract with you, for our legitimate interests in operating and securing the Service, and to comply with legal obligations. Customer Data is processed on your documented instructions as your processor.
We use a small set of processors to run the Service, including: Hetzner (EU hosting), Mistral (EU-hosted AI, unless you bring your own), Brevo (transactional email), and AppSignal (error and performance monitoring). We require appropriate safeguards from each and will keep an up-to-date list available on request.
Account data is kept for the life of your account. Customer Data working copies are retained while needed to operate the Service and can be purged by workspace admins; retention is manual, and audit records of consequential actions are kept for accountability. We delete or return Customer Data after termination as described in the Terms.
Subject to applicable law (including the GDPR), you may request access to, correction, deletion, restriction or portability of your personal data, and object to certain processing. For Customer Data, please direct requests to the workspace controller (your organisation); we will assist them as processor. To exercise rights or complain, contact us below; you also have the right to lodge a complaint with your data protection authority.
We use encryption in transit and at rest for sensitive data, permission-aware access, audit logging, and off-site encrypted backups. No system is perfectly secure, but security and governance are core to how the Service is built.
We aim to keep processing within the EU/EEA. Where a transfer outside the EEA is necessary, we rely on appropriate safeguards such as Standard Contractual Clauses.
We may update this Policy; material changes will be notified through the Service or by email.
Privacy questions or requests: privacy@taskpath.eu.