Privacy Policy
This policy explains how Tascer processes personal data under the EU General Data Protection Regulation (GDPR).
1. Controller
The controller responsible for data processing within Tascer is:
Loucom HLD GmbH
Trauerberg 14, 14776 Brandenburg an der Havel, Germany
Email: info@loucom.de · Phone: +49 176 34570959
For all data-protection matters you can reach us at the address above. Full company details are in our Imprint.
2. What we process and why
Account data
When you register we store your username, email address, a securely hashed password, your role and preferences such as your chosen accent colour. This is required to create and operate your account (Art. 6(1)(b) GDPR).
Content you create
Tascer stores the content you enter to provide the service: projects, boards, tasks, task comments, project notes, stored access-data entries (credentials you choose to save), uploaded files and their metadata. This data is processed to perform our contract with you (Art. 6(1)(b) GDPR). You decide what content you enter — please do not store third-party personal data you are not entitled to process.
Technical & security data
- Session cookie (essential) to keep you logged in.
- An optional “remember me” cookie if you choose to stay signed in.
- Browser local storage for a CSRF security token and UI state (e.g. highlighted tasks).
- Activity & security logs containing your IP address, browser (user agent) and timestamps of key actions, to secure the service and provide the task history and audit trail (Art. 6(1)(f) GDPR — legitimate interest in security and integrity).
- Failed-login counters to protect accounts against brute-force attempts.
API keys
If you create an API key, only a hashed representation of the key is stored (the plain key is shown once and never persisted). Keys are scoped to your account and can be revoked at any time.
Notifications & email
We use your email address to send transactional messages such as account verification, password resets and invitations. If you enable push notifications, we store the push subscription (endpoint and keys) and basic device information needed to deliver them.
3. AI processing (Tara & the API)
Tascer offers optional AI features: the built-in Tara assistant and the REST API. When you use an AI feature, the relevant board and task content needed for your request is transmitted to the AI provider configured for that project (OpenAI or Anthropic), using the API key you or your project administrator provided, so the provider can process your request.
- Only the context necessary for the request is sent (data minimisation).
- Processing takes place under the respective provider’s API terms. Under those terms, data submitted via the API is generally not used to train the providers’ models.
- These providers may process data on servers outside the EU/EEA (e.g. the USA); transfers are covered by the providers’ safeguards such as EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
- AI features are used at your initiative; the legal basis is the performance of the contract and/or your consent (Art. 6(1)(b)/(a) GDPR).
If you do not wish to use AI processing, simply do not use Tara or the API and do not configure an AI provider key.
4. Cookies
Tascer uses only strictly necessary cookies and local storage — for your login session, the optional “remember me” function and CSRF protection. We do not use advertising, tracking or third-party analytics cookies. Because these cookies are essential to provide the service you requested, they do not require consent; the cookie notice is informational.
5. Recipients & processors
We share data only with service providers who process it on our behalf under data-processing agreements, and only as needed to run Tascer:
- our hosting/infrastructure provider;
- our email/SMTP provider for transactional messages;
- the web-push delivery service (if you enable push notifications);
- the AI providers named in section 3, only when you use AI features.
6. Storage duration
- Account data and the content you create: until you delete the item or your account.
- Activity/security logs: automatically deleted after 30 days.
- Read notifications: removed after 30 days.
- Hashed API keys: until you revoke or delete them.
Deleting your account removes your API keys, push subscriptions, notifications, logs, memberships, view records and assistant chat history associated with it.
7. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing (Art. 21). Where processing is based on consent, you may withdraw it at any time with future effect. To exercise these rights, contact us at info@loucom.de.
You also have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU member state of your residence or workplace.
8. Data security
We apply appropriate technical and organisational measures: passwords are stored as salted hashes, API keys as SHA-256 hashes, access to your projects and boards is enforced by per-object permission checks, and we recommend operating Tascer over an encrypted (HTTPS) connection.
9. Changes to this policy
We may update this policy to reflect changes to the service or legal requirements. The current version always applies and is available on this page.
10. Contact
Questions about this policy or your data? Email info@loucom.de.