Privacy Notice
What TaskProof holds about people, why, where it sits, and how long it stays.
It was written from what the software actually stores — every table, column and outbound connection was read from the codebase rather than assumed — but it is not legal advice and has not yet been reviewed by a solicitor.
Anything shown as TO FILL or TO CONFIRM is a real gap, not formatting. This page comes into force when the gaps are closed, the review is done, and this banner is removed.
Who we are
TaskProof is software for recording the checks a kitchen, a housekeeping team or a maintenance team has to do, and proving afterwards that they were done.
It is provided by LEGAL ENTITY NAME, a company registered in England and Wales, company number NUMBER, registered office REGISTERED ADDRESS. We are the data controller for the personal data described in section 2 as ours.
For anything about this notice or about your data, write to support@taskproof.co.uk. We answer from a real mailbox and a person reads it.
We are registered with the Information Commissioner’s Office under registration number ICO NUMBER.
Two different jobs, and this notice only covers one of them
This distinction matters more than it sounds, so it comes first.
When your employer uses TaskProof
If you are a chef, a housekeeper, a maintenance engineer or a manager whose employer has bought TaskProof, then your employer decides what goes into it, who can see it and how long it is kept. In data protection terms they are the controller and we are their processor: we hold the records on their instructions and we do not decide what to do with them.
So if you want to know what is recorded about you, or you want something corrected, ask your employer first. They can see all of it in the app, and we will help them if they need us to. Our obligations to them are set out in a separate data processing agreement, not in this notice.
When you deal with us directly
We are the controller — and this notice applies — for the people we deal with ourselves: whoever signs an organisation up, the people we invoice, anyone who contacts support, and businesses we have recorded as a sales prospect.
Your employer’s copy of the records is theirs. Our record of you as a customer or a contact is ours. This notice is about the second one, and section 3 describes both so nothing is hidden.
What the system actually holds
The list below is exhaustive as at the date on this notice. It is written from the software’s own data model, not from a template.
| Who | What is held about them |
|---|---|
| People with a login | Name, email address, and optionally a phone number and a profile photo. A password, stored only as a one-way hash that cannot be turned back into the password. Job title, which sites and teams they work in, and when they were last seen in the app. Where shared kitchen tablets are used, a personal PIN, also stored only as a hash. |
| People on the staff list who have no login | Name, job title, site and team. Nothing else. No email address, no password, no PIN and no way into the app. This exists so an agency cook on a Tuesday can put their name to a check without anybody having to create them an account. |
| Anyone who signs a record | Their name and job title exactly as they appeared beside the signature at the moment of signing, the signature itself — stored as the shape that was drawn, so it can be redrawn on a printed record — the time it was signed, the time it reached us, and which device it came from. |
| Anyone doing a check | The answers given, any notes typed, and any photographs taken. Photographs have their embedded camera data — including GPS location — removed on the device before they are uploaded. |
| Anyone named on a filed document | Uploaded certificates and paperwork can be attached to a named person: training certificates, food hygiene qualifications and so on. The file may contain more about that person than we ever ask for, including a date of birth. We store the file as it was given to us. |
| Anyone who changes anything | An audit trail records every change: who made it, when, what was changed from and to, and the IP address it came from. This trail cannot be edited or deleted by anybody, including us — the database refuses it. That is what makes it worth something in an inspection. |
| Anyone signing in | Sign-in attempts and the IP address they came from, kept briefly to stop password guessing. Password reset links, which expire. Registrations for phone notifications, including a short description of the device so a person can tell their phone from their tablet. |
| Our own customers and contacts | Organisation and billing details, invoices, and — for businesses we have spoken to about buying TaskProof — a contact name, email address, phone number and notes from the conversation. |
| Anyone we help with support | If we need to look at an account to fix a problem, that access is time-limited, requires a written reason, and is recorded permanently against the account. The customer can see that record. |
We do not buy personal data from anyone, we do not sell it to anyone, and we do not build profiles or make automated decisions about people.
Residents, patients and the people being cared for
TaskProof is used in care homes, so this needs saying plainly.
TaskProof is not designed to hold records about residents or patients, and nothing in it asks for them. There is no resident record, no care plan, no medical field, and no place where a resident’s name is a structured part of the data.
Two things in the software hold that line rather than merely intending it. Where a handover note needs to point at a resident, it stores an internal reference and never a name. And any note connected to a resident is excluded from an exported audit pack — always, whatever anybody ticks — because an audit pack is the one document built to be handed to a third party.
The honest limit: some fields are free text, and files can be uploaded. If a member of staff types a resident’s name into a note, or uploads a document containing one, the software will store what it was given. Customers should not put resident or patient information into TaskProof, and it should be removed if it gets in. If you find some, tell us and we will help take it out.
Why we hold it
Under UK GDPR we need a lawful basis for each thing we do. Ours are:
- To perform our contract — running the service for the organisation that bought it, keeping their records, letting their staff sign in, and sending the emails the service depends on, such as invitations and password resets.
- Our legitimate interests — keeping accounts secure, stopping password guessing, answering support requests, keeping our own record of what we did for a customer, and contacting businesses that might want the product. We have weighed these against the individual’s interests and think they are reasonable and expected; if you disagree, section 12 tells you how to object.
- A legal obligation — keeping invoices and accounting records for as long as HMRC requires.
- Consent — notifications on your phone, which only happen after your device asks you and you say yes, and which you can withdraw in the app or in your browser at any time.
Where we are acting for a customer rather than for ourselves, the lawful basis is theirs to determine, not ours.
Where it is kept
The application runs on Vercel and the database and file storage are provided by Supabase. Data is held in TO CONFIRM: REGION.
Where any of our suppliers process data outside the UK, that transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or by an adequacy decision where one applies.
Who else touches it
We use a small number of suppliers to run the service. Each one is contracted to act only on our instructions. They are:
- Vercel — runs the application itself, and holds short-lived server logs.
- Supabase — the database and the file storage where photographs and documents are kept.
- Resend — sends the service emails: invitations, password resets, reminders and digests.
- Google Workspace — our own mailbox, so anything you email us is held there.
- Anthropic — the AI features described in section 8, and only when someone presses the button.
- Your browser’s push service — Google, Apple or Mozilla depending on the device, if you have turned on notifications. They carry the message; they are not told what it says beyond what is in it.
We do not use any analytics, advertising or tracking service. There are no third-party scripts on the pages at all — this website included.
We will disclose data if the law requires it, and we would tell the customer unless we were forbidden to.
The AI features
Three parts of TaskProof can use an AI model, all provided by Anthropic. Each one only ever runs because a person pressed a button, and each one only ever suggests:
- Reading an allergen label — a photograph of packaging is sent, and the suggested allergens come back for a person to accept or reject.
- Reading an expiry date — an uploaded certificate is sent, and the date it found is offered as a suggestion, along with the wording it read it from.
- Drafting a check — a written description is sent, and a draft check comes back for a manager to edit and publish.
Nothing an AI produces is saved, published or acted on without a person approving it. Nothing is deleted, changed or signed by a model. If the feature is switched off for an organisation, the button does not appear and nothing is sent.
Under Anthropic’s commercial terms, what we send is not used to train their models. Their handling of it is described at anthropic.com/legal/privacy.
Because a document sent to the expiry reader may contain more about a person than the date we asked for, this is worth stating plainly: if you would not send that certificate to a supplier, do not press the button.
How long we keep it
Records of checks, signatures, photographs and the audit trail are kept for seven years by default, which matches the retention that statutory food safety records are generally expected to meet. A customer can set a longer period; the software will not let anybody set a shorter one.
When a customer leaves, their records stay untouched for 90 days. After that they become eligible for deletion — a person at our end still has to decide to delete them, by name and with a written reason, and that decision is itself recorded.
Some things outlive the account on purpose:
- Invoices, because HMRC’s retention duty on them is ours, not the customer’s.
- Our record of what we did to an account, including the deletion itself. The trail of an action has to outlive the thing it was done to.
Sign-in attempt records are pruned automatically. Password reset links expire.
Almost nothing in TaskProof is truly deleted while an account is live — a leaver is marked as gone but their name still resolves on the records they signed years ago, because a statutory record with a blank where a person used to be is not a record.
How it is protected
These are the measures actually in place, not the ones we intend:
- Passwords and tablet PINs are stored only as one-way hashes. Nobody at TaskProof can read them.
- Every query is restricted to a single organisation in the application, with database-level row security underneath as a backstop, so one customer’s data cannot be reached from another’s account even if the application has a bug.
- Permissions deny by default: an account without an explicit capability is refused, rather than merely having the button hidden.
- The audit trail cannot be updated or deleted — that permission is revoked at the database, not enforced by convention.
- Records of completed checks cannot be edited or removed. A correction is a new record that supersedes the old one; the original stays.
- Support access to a customer account is time-limited, requires a written reason, and is recorded where the customer can see it.
- Photographs have their embedded camera data, including GPS coordinates, stripped on the device before upload.
- Suspending an account or changing a password kills every existing session immediately.
- All traffic is encrypted in transit; the database and file storage are encrypted at rest by our hosting providers.
If a breach happens that puts people at risk, we will report it to the ICO within 72 hours and tell affected customers without delay.
Cookies
The TaskProof app sets two cookies, both strictly necessary:
- A sign-in cookie, so you stay signed in between pages.
- A support-access cookie, set only when a member of our staff is helping with an account and only for the length of that session.
There are no analytics cookies, no advertising cookies and no third-party cookies — and this website sets none at all — so there is nothing to consent to and no cookie banner. The app also stores today’s checks in your browser so it keeps working when the signal drops; that stays on your device and is cleared when you sign out.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, hand it over in a portable form, or object to us using it. You can withdraw consent for notifications at any time. We do not charge for this and we will answer within one month.
One practical point, repeating section 2: if your employer is the TaskProof customer, ask them first. They hold the records and they decide. If you ask us, we will point you to them and help them answer — we are not allowed to hand over their records on our own initiative, and you would not want a supplier who was.
There are limits, and they are worth knowing in advance. We cannot delete an entry from the audit trail or a completed compliance record, because those are the customer’s statutory records and the software is deliberately built so that nobody can rewrite them. Where a right conflicts with a legal duty to keep something, the duty wins and we will tell you that is what happened.
Complaints, and changes to this notice
If you are unhappy with how we have handled your data, tell us first at support@taskproof.co.uk and we will try to put it right. You can also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, by phone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
If we change this notice we will change the version and date at the top, and we will tell customers directly about anything that materially affects them rather than relying on them re-reading the page.