GDPR privacy noticeIndividual analysisEffective 24 August 2026

Privacy Notice

How The Task Graph uses personal data

This notice covers the public website, optional analytics, role requests and waitlists, the invitation-based personal role analysis, pilot feedback, and organization enquiries. It explains what is collected, why, where it goes, how long it is kept, and the choices you have.

Controller

PQ Investment Oy

Privacy contact

privacy@thetaskgraph.com

Individual pilot

No per-report payment; code and feedback required

1 · Who is responsible

Controller and scope

PQ Investment Oy is the controller for personal data processed through The Task Graph. Contact privacy@thetaskgraph.com for privacy matters or to request the controller's current postal contact details.

If an organization later provides The Task Graph to its workforce under a separate agreement, the roles of the organization and the operator will be defined for that engagement. This notice does not replace an organization-specific privacy notice.

2 · Boundaries

What we do not ask you to submit

Do not include health data, political or religious beliefs, biometric or genetic data, union membership, sexual-life data, national identifiers, confidential employer material, trade secrets, or personal data about colleagues. The analysis needs a work description, not a personal history.

We do not sell identifiable submissions, use them for third-party advertising, publish them as case studies without separate permission, or give an employer an individual pilot report. Public occupational sources do not receive your personal data.

3 · Processing register in plain language

What we process, why, and on what legal basis

ActivityData categoriesPurposeLegal basis
Public website and securityRequest data such as IP address, time, route, device or browser signals, and security events. Public pages do not require an account.Deliver the site, prevent abuse, investigate faults, and protect the service.Legitimate interests (GDPR Art. 6(1)(f)): operating a secure, reliable public service.
Optional usage analyticsPage path without query strings, timestamp, referrer, approximate country or region, browser/device class, a limited set of product-usage events, and limited campaign labels. No email or task free text.Understand which pages and product steps are useful and improve the service.Consent (Art. 6(1)(a)). Analytics stays off until you allow it and can be withdrawn in Cookie settings.
Waitlist, public-role request, or contactEmail, role title, selected public role, work context or task notes you choose to provide, message, source path, and request status.Respond, prioritize public coverage, select pilot groups, and manage the relationship you requested.Steps requested before providing a service (Art. 6(1)(b)) and legitimate interests in responding and planning the pilot (Art. 6(1)(f)).
Invitation-code accessEmail, email hash, code digest and campaign reference, pseudonymous participant reference, sign-in time, feedback commitment, and signed access state.Validate a code, maintain pilot access, connect a report to the right participant, prevent misuse, and administer the pilot.Performance of the requested pilot service (Art. 6(1)(b)) and legitimate interests in access security and cohort management (Art. 6(1)(f)).
Personal role analysis and private reportRole title, optional department and context, own task descriptions, selected reference role, accepted or rejected task mappings, optional work-time shares, task estimates and explanations, report id, access-token hash, and report status.Build, save, deliver, support, and secure the task-level analysis you requested.Performance of the requested pilot service (Art. 6(1)(b)).
Pilot feedbackEmail, report reference, usefulness rating, and the useful or unclear points you submit.Complete the pilot exchange, understand failure points, and improve matching, explanations, and usability.Performance and administration of the pilot (Art. 6(1)(b)); product improvement is also our legitimate interest (Art. 6(1)(f)).
Organization enquiryBusiness contact details, organization, role or function, and the information you choose to include in your enquiry.Respond to your enquiry and understand which role and workforce-planning questions a future organization product should support.Legitimate interests in responding to enquiries and conducting product research (GDPR Art. 6(1)(f)).

Where we rely on legitimate interests, we consider the limited data, the user-requested context, reasonable expectations, security needs, and your rights. You may object by contacting us; we will stop unless we demonstrate compelling lawful grounds or need the data for legal claims.

4 · Cookie notice

Cookies and similar browser storage

Essential storage is used to deliver features you request. Optional analytics and campaign attribution are off by default and start only after consent. The footer's Cookie settings link lets you refuse, allow, or withdraw optional analytics at any time. Refusing analytics does not limit the public site or analysis pilot.

ItemTypeDurationPurpose and contents
Privacy preferenceEssential local browser storageUntil you clear site data or this notice version changesRemembers whether optional analytics is allowed. It contains the choice version and time, not an identity.
Pilot accessEssential, signed HttpOnly cookieUp to 30 daysKeeps invitation access working. It contains expiry, campaign and pseudonymous references, and an email hash—not the email, code, or task text.
Analysis continuityEssential local browser storageUntil you clear site data or replace the saved draft/report referenceKeeps your draft, reviewed mappings, and private report reference available on this browser. The participant email is not stored for form prefill.
Campaign attributionOptional session storageCurrent browser tab/sessionStores bounded UTM labels or a referring host after analytics consent. It is deleted when analytics is turned off.
Vercel Web AnalyticsOptional, cookie-free analyticsThe visitor hash resets daily; aggregated reporting availability follows the Vercel plan windowCounts page views and a limited set of product-usage events without a third-party analytics cookie or cross-site identifier.

Vercel states that its Web Analytics does not use third-party cookies, uses a daily-reset visitor hash, and reports aggregated data. Our implementation additionally removes query strings and waits for your consent. Read Vercel's Web Analytics privacy documentation.

5 · AI processing

What is sent to the report-writing model

To suggest task matches and write a short report summary and general skills guidance, the server sends OpenRouter only the role and task information needed for those steps: task descriptions, approved public-task matches, matched research estimates, submitted workload shares, and existing explanations. Email, access codes, participant and report identifiers, organization details, and source URLs are excluded.

Requests use providers configured not to retain prompt or response content. OpenRouter may retain non-content metadata such as token counts and response time. If the AI request fails, the report uses prewritten explanations based on the same analyzed data.

The AI-written text does not create or change task values, task matches, workload weighting, or the overall estimate. It summarizes the mappings and research already shown in the report. Review the output; it can still be incomplete or wrong.

OpenRouter zero-data-retention documentation

6 · Required and optional information

What you need to provide

Email, a valid invitation code, feedback commitment, role title, and enough task information to map the role are needed for the individual pilot. Without them we cannot validate access or create the requested analysis. Department, broader work context, and task time shares are optional.

Public-role requests and waitlist entries require an email and role title so we can understand and respond to the request. Organization enquiries need a business contact channel and enough scope to discuss the requested work.

Data comes primarily from you. We also derive code/campaign references, email hashes, report identifiers, mapping candidates, and security events. Public reference-role and task data, along with supporting evidence, come from the sources listed on the Sources page.

7 · Retention

How long data is kept

We keep identifiable data only for the stated period or while the stated need remains. A valid deletion request can shorten these periods; legal obligations, fraud/security investigations, or legal claims can require a limited longer hold.

Pilot access cookie

30 days from code redemption.

Browser draft, mappings, and report reference

Stored on your device until you clear site data or the saved value is replaced. We cannot read browser-local content until it is submitted.

Invitation sign-in, personal report, and pilot feedback

For the pilot and up to 12 months after your latest pilot interaction, then deleted or irreversibly anonymized unless a shorter deletion request applies or law requires longer retention.

Waitlist, public-role request, and general enquiry

Up to 24 months after the latest interaction, unless an active relationship or legal requirement justifies longer retention.

Organization enquiries and any future customer records

Enquiries are kept for up to 24 months after the latest interaction. If a future paid engagement is agreed, its records would be kept according to that agreement and applicable accounting and legal obligations.

Security and technical logs

For the provider's configured operational window and longer only when needed to investigate an incident, establish legal claims, or meet a legal obligation.

8 · Recipients and transfers

Who processes data for us

Authorized operator personnel access personal data only when needed for support, pilot administration, security, product improvement, or organization delivery. Service providers receive only what is needed for their role.

  • Vercel — hosting, server functions, private Blob storage, bot/abuse protection, and consented Web Analytics.
  • OpenRouter and the selected zero-retention model provider — task matching and report narrative processing after you agree to AI processing.
  • Email or request-delivery providers — only when a form uses the configured notification route or you use the email fallback.
  • Professional advisers or authorities where necessary to comply with law, protect rights, or establish legal claims.

Vercel, OpenRouter, or model providers may process data outside Finland or the EEA. Where GDPR transfer rules apply, we rely on an adequacy decision or contractual safeguards such as the European Commission's Standard Contractual Clauses, as applicable to the provider and route. You may request more information about the applicable safeguard.

9 · Automated decisions

The report is informational, not a decision about you

Task matching and narrative generation use automated processing, but you review the proposed task mappings before the report is created. The service does not make a decision producing legal or similarly significant effects about you within GDPR Article 22.

The report must not be used to hire, fire, promote, rank, compensate, or otherwise make a high-impact decision about a person. It estimates how tasks may change; it does not evaluate an individual's performance, capability, or employability.

10 · Your rights

Access, correct, delete, object, or complain

Ask whether we process your personal data and obtain a copy
Correct inaccurate or incomplete personal data
Request deletion where the legal conditions are met
Restrict processing where the legal conditions are met
Receive data you provided in a portable format where applicable
Object to processing based on legitimate interests
Withdraw analytics consent at any time without affecting earlier lawful processing
Lodge a complaint with the Finnish Office of the Data Protection Ombudsman or another competent EEA supervisory authority

Email us from the address used in the service and include the report/request reference and role title where available. We may verify identity before disclosing or deleting data. We respond without undue delay and normally within one month, subject to the GDPR's permitted extensions.

Finland's supervisory authority is the Office of the Data Protection Ombudsman.

Make a privacy request

11 · Changes and related pages

Notice updates

We update this notice when the product, vendors, legal bases, or retention practices materially change. The effective date above shows the current version. Material changes will be presented through the site or analysis flow where appropriate.