Data Processing Addendum
Last updated: July 12, 2026Effective date: July 12, 2026
Bosster is developed and operated by Cinute InfoMedia (www.cinuteinfomedia.com). This Data Processing Addendum (“DPA”) supplements the Terms of Service and applies whenever a customer’s use of the Service involves the processing of personal data subject to the GDPR, UK GDPR, or comparable data-protection laws.
Roles: the customer organization that owns a workspace is the controller of personal data in that workspace (“Customer Data”), and Cinute InfoMedia is the processor, acting only on the controller’s documented instructions.
1. Definitions
“Personal data”, “processing”, “controller”, “processor”, “data subject”, and “personal data breach” have the meanings given in the GDPR. “Customer Data” means personal data contained in a customer’s workspace that Cinute InfoMedia processes on the customer’s behalf. Capitalized terms not defined here have the meanings given in the Terms of Service.
2. Scope, Nature, and Duration of Processing
- Subject matter: provision of the Bosster task-management service.
- Nature and purpose: hosting, storage, transmission, display, backup, and deletion of Customer Data as needed to operate the Service’s features (tasks, timesheets, templates, chat, audit trails).
- Categories of data: identification and contact data of workspace members (name, email), work content (tasks, comments, attachments, time entries), and usage records. Customers should not store special categories of data without a separate written agreement.
- Data subjects: the customer’s workspace members and any individuals referenced in workspace content.
- Duration: the term of the customer’s subscription plus the retrieval and deletion periods in Section 9.
3. Documented Instructions
Cinute InfoMedia processes Customer Data only on the customer’s documented instructions — which consist of the Terms of Service, this DPA, the customer’s configuration of the Service, and any further written instructions agreed between the parties — unless processing is required by law, in which case we will inform the customer before processing unless the law prohibits it. We will inform the customer if, in our opinion, an instruction infringes applicable data-protection law.
4. Confidentiality
We ensure that all personnel authorized to process Customer Data are bound by contractual or statutory obligations of confidentiality, receive appropriate data-protection training, and access Customer Data only to the extent necessary to perform their role (least privilege).
5. Security Measures
Taking into account the state of the art and the risks of the processing, we implement and maintain appropriate technical and organizational measures, including:
- encryption of Customer Data in transit (TLS 1.2+) and at rest;
- logical tenant isolation preventing cross-workspace data access;
- role-based access controls, strong authentication for administrative access, and password hashing;
- audit logging of data access and administrative actions;
- encrypted backups with tested restoration procedures, and vulnerability management including timely patching.
We review these measures regularly and will not materially degrade the overall security of the Service during a subscription term.
6. Subprocessors
The customer grants Cinute InfoMedia general written authorization to engage subprocessors for hosting, payment processing, and email delivery, as listed in our Privacy Policy. For each subprocessor we:
- impose data-protection obligations no less protective than this DPA by written contract;
- remain fully liable to the customer for the subprocessor’s performance;
- give at least 30 days’ advance notice of any intended addition or replacement of a subprocessor. If the customer has a reasonable, data-protection-related objection that we cannot resolve, the customer may terminate the affected subscription and receive a pro-rated refund of prepaid fees.
7. Assistance with Data Subject Requests
Taking into account the nature of the processing, we assist the customer with appropriate technical and organizational measures to respond to data subjects’ requests (access, rectification, erasure, portability, restriction, objection) — primarily through the Service’s built-in admin, export, and deletion tools. If a data subject contacts us directly about Customer Data, we will refer the request to the customer without undue delay and will not respond substantively except on the customer’s instruction or where legally required. We also provide reasonable assistance with data-protection impact assessments and consultations with supervisory authorities, considering the information available to us.
8. Personal Data Breach Notification
We will notify the customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will cooperate with the customer and provide timely updates so the customer can meet its own notification obligations. Notification is not an admission of fault.
9. Deletion and Return of Customer Data
During the subscription, customers can export Customer Data at any time using the Service’s export tools. On termination or expiry, we make Customer Data available for export for at least 30 days, after which we delete it from active systems and allow it to age out of encrypted backups within 90 days, unless retention is required by applicable law (in which case the data is isolated and protected until deletion is possible). On written request, we will confirm deletion.
10. Audit Rights
On written request, we will make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of security assessments and subprocessor lists. Where that information is insufficient, the customer (or an independent auditor bound by confidentiality) may conduct an audit no more than once per year, on at least 30 days’ written notice, during business hours, and at the customer’s cost, conducted so as not to compromise the security of other tenants’ data or unreasonably disrupt our operations. Audits triggered by a personal data breach affecting the customer do not count against the annual limit.
11. International Transfers
Where the provision of the Service involves transferring Customer Data protected by the GDPR or UK GDPR to a country without an adequacy decision, the parties incorporate the European Commission’s Standard Contractual Clauses (Module Two: controller-to-processor), and the UK International Data Transfer Addendum where applicable, into this DPA by reference, with Cinute InfoMedia as data importer and the customer as data exporter. We apply supplementary measures — encryption in transit and at rest and strict access controls — to all transferred data.
12. Liability and Precedence
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, except where applicable data-protection law does not permit such limitation. In the event of a conflict between this DPA and the Terms of Service regarding the processing of Customer Data, this DPA prevails; in the event of a conflict between this DPA and the Standard Contractual Clauses, the Clauses prevail.
13. Contact
Data-protection inquiries relating to this DPA: privacy@opentask.app; legal notices: legal@opentask.app. Bosster is developed and operated by Cinute InfoMedia — www.cinuteinfomedia.com.