Privacy Policy
Last updated August 1, 2026 · ManageYourProject, operating manageyourproject.net
This policy explains what personal data ManageYourProject collects, why, how long we keep it and what rights you have. We are the controller for account and website data, and the processor for data you put into your workspace on behalf of your organisation.
1. What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Name, email, hashed password, avatar, timezone, locale | Provide the Service, authenticate you |
| Workspace | Organisation name, members, roles, settings | Multi-tenancy and access control |
| Customer Data | Projects, tasks, comments, documents, time entries, files | The Service itself; processed on your instruction |
| Billing | Plan, seat count, invoices, last four digits and country from Paddle | Charging you and tax compliance |
| Technical | IP address, user agent, request timestamps, error traces | Security, abuse prevention, debugging |
| Product analytics | Page and feature events, aggregated and IP-anonymised | Improving the product |
We do not collect special category data and ask that you do not store it in the Service. We do not buy personal data from brokers.
2. Legal bases (GDPR Article 6)
- Contract — providing the Service, billing and support.
- Legitimate interests — security, fraud prevention, aggregate product analytics, and transactional email about your account. We have balanced these against your rights and you may object.
- Consent — marketing email and non-essential cookies. Withdrawable at any time.
- Legal obligation — tax records and lawful requests.
3. Sub-processors
We use a small set of vendors listed and versioned on the sub-processor page. Each is bound by a data processing agreement with confidentiality and security obligations. We give 30 days' notice before adding a sub-processor that processes Customer Data, and you may object.
4. International transfers
Data is hosted in the region you select. Business and Enterprise plans can pin residency to the EU or the US. Where a transfer outside the EEA or UK is necessary, we rely on Standard Contractual Clauses plus the UK Addendum, with a transfer impact assessment on file.
5. Retention
- Active accounts: for as long as the account exists.
- After deletion: 30 days in live systems, up to 90 days in encrypted backups, then permanent deletion.
- Audit and security logs: 12 months (24 on Enterprise).
- Invoices and tax records: 7 years, as required by law.
- Support email: 24 months.
6. Your rights
You may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Account holders can self-serve most of this: Settings → Account exports everything as JSON and CSV, and Settings → Account → Delete erases your personal data and anonymises your contributions. We respond to written requests within 30 days and never charge for a first request. You may also complain to your local supervisory authority.
7. Security
TLS 1.3 in transit, AES-256 at rest, bcrypt password hashing, optional two-factor authentication, role-based access control, IP allowlisting, per-endpoint rate limiting and audit logging. Details are on the security page. We notify affected customers and, where required, regulators within 72 hours of confirming a personal data breach.
8. AI features
When you invoke an AI feature we send the minimum necessary content to our AI sub-processor to produce that response. Those requests are not used to train third-party models, and we retain only a token count and cost for billing. AI features can be disabled for an entire organisation in Settings.
9. Children
The Service is not directed at children under 16. If we learn we hold such data we delete it.
10. Changes and contact
We announce material changes by email and in-app 30 days ahead. Privacy questions and rights requests: [email protected].
Questions about this document: [email protected]. Prior versions are available on request.