Open beta - try it freely.Sign in

Legal & Trust

Subprocessors

Last updated: 13 September 2026

Working draft. TaskForce is pre-launch. This document is provided for transparency and is pending final legal review - it is not yet a binding agreement. Questions? contact@taskforce-project.fr

To run TaskForce we rely on a small number of subprocessors, each bound by data-protection obligations and given only what they need. This is the current list; it will change as the product grows, and we'll give notice before adding one that handles personal data.

The big picture first

Much of TaskForce can run on your own infrastructure. On a self-hosted deployment using local models through Ollama, your content need not touch any third party - the subprocessors below apply mainly to our hosted service and to hosted-model calls you choose to make.

Current subprocessors

  • Stripe - payments. Processes billing and customer contact details for paid plans. We don't store full card numbers.
  • Groq, Inc. - United States - optional subprocessor, active only when the Groq provider is configured (GROQ_API_KEY). Receives the task context for inference (no direct PII). By default the AI runs locally (Ollama/Qwen), so there is no transfer. Safeguards when enabled: a DPA plus an out-of-EU transfer mechanism (Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework).
  • Hetzner Online GmbH - cloud infrastructure for our hosted service (application data at rest and in transit), located in the EU (Germany).
  • PostHog, Inc. (EU Cloud) - product and website analytics. Hosted in the EU (Frankfurt); no data leaves the EU. Loaded only after you consent to analytics cookies, and receives page-view and usage events (no advertising, no cross-site tracking). The US-based publisher's potential access is covered by a DPA with Standard Contractual Clauses (SCCs).
  • [Transactional email provider] - account and notification emails, if applicable.To be confirmed.

Components such as identity (Keycloak), object storage (MinIO) and the database (PostgreSQL) runwithin the deployment - on a self-hosted install, they're yours, not third-party subprocessors.

Changes

When we add or change a subprocessor that handles personal data, we'll update this page and notify customers with an active agreement so they can object. See the DPA andprivacy policy for how this fits together.


Questions about this document? Write to contact@taskforce-project.fr.