Privacy Policy
Last updated: July 12, 2026Effective date: July 12, 2026
Bosster is developed and operated by Cinute InfoMedia (www.cinuteinfomedia.com). This Privacy Policy explains what personal data we collect when you visit our websites or use the Bosster service (the “Service”), why we collect it, who we share it with, how long we keep it, and the rights you have over it.
We have tried to write this policy in plain language. If anything is unclear, email us at privacy@opentask.app and we will explain.
1. Who We Are (Data Controller)
For personal data described in this policy — such as your account data, billing data, and usage data — the data controller is Cinute InfoMedia, reachable at privacy@opentask.app. For personal data contained inside a customer’s workspace, roles are different: see Section 5 (“Multi-Tenant Workspaces”) below.
2. Scope of This Policy
This policy covers the Bosster websites (including the blog) and the Bosster application. It does not cover third-party websites we link to, or the practices of customer organizations that operate workspaces on the Service — their own privacy policies govern how they handle their members’ data.
3. Information We Collect
- Account data — name, email address, password (stored only as a salted hash), profile picture if you add one, and workspace membership and role information.
- Workspace content — tasks, comments, attachments, timesheet entries, templates, and chat messages you or your teammates create. This content may contain personal data, depending on what your team puts in it.
- Usage and log data — IP address, browser and device type, pages viewed, actions taken in the Service (which also feed the audit trail feature), timestamps, and error diagnostics.
- Cookies — a small number of first-party cookies for sign-in and preferences, described in our Cookie Policy. We do not use advertising cookies.
- Payment data — payments are handled by Stripe. We never receive or store full card numbers. We receive from Stripe only what we need to administer your subscription: billing name, the last four digits and brand of your card, invoice history, and subscription status.
- Communications — messages you send to our support, privacy, or legal addresses, so we can respond and keep a record of the conversation.
We do not collect special categories of personal data (such as health or biometric data) and ask that you not store such data in the Service unless your organization has an appropriate agreement with us.
4. How We Use Information and Legal Bases
We use personal data for the following purposes, relying on the legal bases indicated (as required under the GDPR and similar laws):
- Providing the Service — creating your account, operating workspaces, syncing content, processing payments, and providing support. Legal basis: performance of a contract.
- Security and integrity — detecting and preventing fraud, abuse, and unauthorized access; maintaining audit logs. Legal basis: legitimate interest in keeping the Service and its tenants safe.
- Improving the Service — analyzing aggregated usage to understand which features work and fixing bugs. Legal basis: legitimate interest. We use aggregated or de-identified data wherever possible.
- Communications — transactional emails (receipts, security alerts, service notices) are sent as part of the contract; product news and marketing emails are sent only with your consent, which you can withdraw at any time via the unsubscribe link.
- Legal compliance — retaining billing records, responding to lawful requests. Legal basis: legal obligation.
We do not use your workspace content to train machine-learning models, and we do not build advertising profiles from your data.
5. Multi-Tenant Workspaces: Roles and Responsibilities
Bosster is a multi-tenant platform: organizations create workspaces and invite members. For personal data contained within a workspace (including member profiles, tasks, and timesheets), the organization that administers the workspace is the data controller, and Cinute InfoMedia acts as its data processor, processing that data only on the organization’s documented instructions.
In practice this means workspace admins decide who can join, what data is stored, and when it is deleted, and they can access and export member data within their workspace. If you are a workspace member with questions about how your employer or team handles your data, contact your workspace admin first; we will assist controllers in responding, as described in our Data Processing Addendum.
7. International Data Transfers
Cinute InfoMedia is based in India, and our subprocessors may store or process data in other countries. Where personal data protected by the GDPR or similar laws is transferred to a country without an adequacy decision, we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant) with supplementary technical measures such as encryption in transit and at rest. You may request a summary of the safeguards applicable to your data at privacy@opentask.app.
8. Data Retention
We keep personal data only as long as needed for the purposes described above, then delete or anonymize it:
- Account data — for the life of your account, plus 30 days after deletion to allow for accidental-deletion recovery.
- Workspace content — until deleted by you or your workspace admin, or until the end of the post-termination retrieval window described in the Terms of Service, plus the backup cycle below.
- Backups — encrypted backups are retained for up to 90 days, after which deleted data ages out of backup storage automatically.
- Billing records — retained for 7 years, as required by tax and accounting law.
- Server logs — typically retained for 12 months for security investigation, then deleted or anonymized.
9. Your Rights and How to Exercise Them
Depending on your jurisdiction, you have some or all of the following rights over your personal data:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data (much of this you can do directly in your account settings).
- Erasure — request deletion of your data (“right to be forgotten”), subject to legal retention obligations.
- Portability — receive your data in a structured, machine-readable format; the Service’s export tools cover most content.
- Objection and restriction — object to processing based on legitimate interest, or ask us to restrict processing while a dispute is resolved.
- Withdraw consent — at any time, for processing based on consent (such as marketing emails), without affecting prior processing.
- Complain — to your local data-protection supervisory authority. We would appreciate the chance to address your concern first, but you are not required to contact us before complaining.
To exercise any right, email privacy@opentask.app. We will verify your identity, respond within 30 days, and never charge a fee for a first, reasonable request. If your request concerns data inside a workspace controlled by another organization, we will refer it to that organization and assist them in responding.
10. Regional Disclosures (GDPR, CCPA/CPRA, India DPDP)
- EEA/UK (GDPR). The legal bases in Section 4 apply. Where we rely on legitimate interest, we have balanced our interest against your rights and will provide our assessment on request.
- California (CCPA/CPRA). We do not “sell” or “share” personal information as those terms are defined in the CCPA/CPRA, and we have not done so in the preceding 12 months. California residents may exercise access, deletion, correction, and non-discrimination rights via privacy@opentask.app, including through an authorized agent.
- India (DPDP Act, 2023). We process digital personal data in accordance with the Digital Personal Data Protection Act, 2023. You may exercise your rights to access, correction, erasure, and grievance redressal via privacy@opentask.app; unresolved grievances may be escalated to the Data Protection Board of India.
12. Children's Privacy
The Service is not directed at children and may not be used by anyone under 16 years of age (or the higher minimum age of your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has created an account, contact us at privacy@opentask.app and we will delete the account and its data promptly.
13. Security Measures
We protect personal data with technical and organizational measures appropriate to the risk, including:
- encryption of data in transit (TLS) and at rest;
- logical tenant isolation so one workspace cannot access another’s data;
- password hashing, role-based access controls, and least-privilege access for our staff;
- audit logging of administrative and data access;
- encrypted backups and tested recovery procedures.
No system is perfectly secure, so we also maintain an incident-response process (Section 14) and encourage responsible disclosure of vulnerabilities under our Acceptable Use Policy.
14. Data Breach Notification
If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data, we will notify affected users and customers without undue delay — and within 72 hours of becoming aware where required by law (including for notifications to controllers under the GDPR). Notifications will describe the nature of the breach, the data affected, the measures taken, and recommended steps you can take.
15. Changes to This Policy
We may update this policy as the Service or the law evolves. For material changes, we will notify you by email or in-product notice at least 14 days before the change takes effect. The “Last updated” date at the top of this page always reflects the current version, and we keep prior versions available on request.
16. Contact
Privacy questions and requests: privacy@opentask.app. General support: support@opentask.app. Bosster is developed and operated by Cinute InfoMedia — www.cinuteinfomedia.com.