Privacy Policy

Last updated August 1, 2026 · ManageYourProject, operating manageyourproject.net

This policy explains what personal data ManageYourProject collects, why, how long we keep it and what rights you have. We are the controller for account and website data, and the processor for data you put into your workspace on behalf of your organisation.

1. What we collect

CategoryExamplesWhy
AccountName, email, hashed password, avatar, timezone, localeProvide the Service, authenticate you
WorkspaceOrganisation name, members, roles, settingsMulti-tenancy and access control
Customer DataProjects, tasks, comments, documents, time entries, filesThe Service itself; processed on your instruction
BillingPlan, seat count, invoices, last four digits and country from PaddleCharging you and tax compliance
TechnicalIP address, user agent, request timestamps, error tracesSecurity, abuse prevention, debugging
Product analyticsPage and feature events, aggregated and IP-anonymisedImproving the product

We do not collect special category data and ask that you do not store it in the Service. We do not buy personal data from brokers.

2. Legal bases (GDPR Article 6)

  • Contract — providing the Service, billing and support.
  • Legitimate interests — security, fraud prevention, aggregate product analytics, and transactional email about your account. We have balanced these against your rights and you may object.
  • Consent — marketing email and non-essential cookies. Withdrawable at any time.
  • Legal obligation — tax records and lawful requests.

3. Sub-processors

We use a small set of vendors listed and versioned on the sub-processor page. Each is bound by a data processing agreement with confidentiality and security obligations. We give 30 days' notice before adding a sub-processor that processes Customer Data, and you may object.

4. International transfers

Data is hosted in the region you select. Business and Enterprise plans can pin residency to the EU or the US. Where a transfer outside the EEA or UK is necessary, we rely on Standard Contractual Clauses plus the UK Addendum, with a transfer impact assessment on file.

5. Retention

  • Active accounts: for as long as the account exists.
  • After deletion: 30 days in live systems, up to 90 days in encrypted backups, then permanent deletion.
  • Audit and security logs: 12 months (24 on Enterprise).
  • Invoices and tax records: 7 years, as required by law.
  • Support email: 24 months.

6. Your rights

You may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Account holders can self-serve most of this: Settings → Account exports everything as JSON and CSV, and Settings → Account → Delete erases your personal data and anonymises your contributions. We respond to written requests within 30 days and never charge for a first request. You may also complain to your local supervisory authority.

7. Security

TLS 1.3 in transit, AES-256 at rest, bcrypt password hashing, optional two-factor authentication, role-based access control, IP allowlisting, per-endpoint rate limiting and audit logging. Details are on the security page. We notify affected customers and, where required, regulators within 72 hours of confirming a personal data breach.

8. AI features

When you invoke an AI feature we send the minimum necessary content to our AI sub-processor to produce that response. Those requests are not used to train third-party models, and we retain only a token count and cost for billing. AI features can be disabled for an entire organisation in Settings.

9. Children

The Service is not directed at children under 16. If we learn we hold such data we delete it.

10. Changes and contact

We announce material changes by email and in-app 30 days ahead. Privacy questions and rights requests: [email protected].


Questions about this document: [email protected]. Prior versions are available on request.