EveryTask legal
Data Processing Addendum
This standard addendum supplements the EveryTask Terms of Service for a customer that needs processor terms for Customer Personal Data.
Last updated: 12 August 2026
1. Definitions and scope
This Data Processing Addendum (“DPA”) is between BIY, LLC, the provider of EveryTask, at 5900 Balcones Drive #28242, Austin, TX 78731, USA, and the customer accepting it. It forms part of the Terms of Service or another agreement governing the customer’s use of EveryTask (the “Agreement”). It applies when EveryTask processes Customer Personal Data for the customer in providing the workspace and related document workflow services.
“Customer Personal Data” means personal data contained in Customer Content. “Customer” means the organization using the Service; “EveryTask” means the provider of the Service; and “Data Protection Laws” means applicable privacy and data-protection laws, including the GDPR or UK GDPR where applicable.
2. Roles of the parties
The customer is the controller of Customer Personal Data and EveryTask is its processor, except where EveryTask independently determines the purposes and means of processing account, billing, website and product-usage information. The company privacy policy governs that independent processing.
The customer instructs EveryTask to process Customer Personal Data only as necessary to provide, secure, maintain and support the Service; to comply with the Agreement and this DPA; and as required by applicable law. The customer is responsible for ensuring that its instructions and use of the Service comply with Data Protection Laws.
3. Customer responsibilities
The customer is responsible for providing any notices and obtaining any consents or other lawful basis required for EveryTask to process Customer Personal Data under the Agreement and this DPA. If the customer acts as a processor for another controller, it confirms it is authorized to appoint EveryTask as a subprocessor and give the instructions in this DPA.
4. Processing and protection
EveryTask will ensure that people authorized to process Customer Personal Data are bound by confidentiality obligations. EveryTask will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, taking account of the nature of the processing and the risks involved.
Security measures evolve with the Service and technology. We may update them where the overall level of protection is not materially reduced. Customers remain responsible for their own access controls, sharing decisions, member permissions and the lawful use of review and signature invitations.
5. European, UK and Swiss personal data
Where European, UK or Swiss Data Protection Laws apply, EveryTask will provide reasonable assistance, taking account of the nature of processing and information available to it, with the customer’s obligations concerning security, breach notification, data-protection impact assessments and consultations with supervisory authorities.
6. Subprocessors
The customer gives general authorisation for EveryTask to use subprocessors that are reasonably necessary to provide the Service. EveryTask will enter into written agreements with subprocessors that require protection of Customer Personal Data consistent with this DPA, and remains responsible for its subprocessor obligations to the extent required by Data Protection Laws.
Information about service providers that process personal data will be made available through the company privacy documentation or on written request. Where Data Protection Laws require notice of a new or replacement subprocessor, EveryTask will provide it through that documentation or to the customer’s designated contact before the change takes effect.
A customer may object to a proposed new subprocessor on reasonable data-protection grounds by contacting EveryTask before the change takes effect. The parties will discuss the concern in good faith. If it cannot be resolved, the customer may terminate the affected Service before the new subprocessor processes its Customer Personal Data; this does not create a right to a refund for service already provided.
7. Assistance, incidents and data-subject requests
Taking account of the nature of processing, EveryTask will provide reasonable assistance to the customer in responding to valid data-subject requests, security assessments and regulatory duties relating to Customer Personal Data. If EveryTask receives a request directly relating to Customer Personal Data, it will direct the requester to the customer where appropriate and legally permitted.
EveryTask will notify the customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to help the customer meet its legal notification obligations. A “Personal Data Breach” has the meaning given by applicable Data Protection Laws.
8. Return and deletion
During the Agreement, the customer can access and download Customer Content using the Service, subject to the plan and feature limits. On termination, EveryTask will delete or return Customer Personal Data in accordance with the Service’s deletion and retention processes, unless continued storage is required by law. Limited backup copies may persist for a restricted period and will remain protected and isolated from routine use until deleted.
9. International transfers
Customer Personal Data may be processed in the countries in which EveryTask and its authorized subprocessors operate. Where a restricted international transfer is involved, the parties will cooperate in good faith to put in place a valid transfer mechanism required by applicable Data Protection Laws, such as the applicable standard contractual clauses.
10. Compliance information and audits
On reasonable written request, and no more than once in a twelve month period unless required by law or following a Personal Data Breach, EveryTask will make available information reasonably needed to demonstrate compliance with this DPA. Any audit must be proportionate, conducted during normal business hours on reasonable notice, and must not compromise the security, confidentiality or availability of the Service or another customer’s data.
Schedule A: Processing details
- Subject matter
- Document storage, editing, review, approval, signature and related workspace functions.
- Duration
- For the duration of the Agreement and any limited retention period described in Section 6.
- Nature and purpose
- Processing needed to provide, secure, maintain and support the Service on the customer’s instructions.
- Data subjects
- Customer personnel, invited collaborators, reviewers, signers, clients and individuals whose personal data the customer includes in Customer Content.
- Types of personal data
- Contact and account details, document content, comments, signature and review activity, and technical records generated by use of the Service. The customer controls the content it uploads.
Schedule B: Security measures
EveryTask maintains measures appropriate to the Service and the risks of the processing, including access controls intended to limit access to authorized personnel and users; authentication and authorization controls; encryption in transit and at rest where supported by the relevant Service component; logging and monitoring appropriate to operations; secure development and change-management practices; and incident-response processes. These measures may evolve as the Service and security practices develop, provided the overall protection is not materially reduced.
11. Miscellaneous
This DPA prevails over the Agreement only to the extent of a conflict about processing Customer Personal Data. It does not amend any limitation of liability in the Agreement unless the parties agree otherwise in writing. Questions or execution requests can be sent to hello@everytask.io.