Data processing

Data Processing Agreement

Last updated 12 September 2026. Questions: [email protected]

This Agreement describes how Think Apps AI Ltd processes personal data on behalf of the organisations that use Think Projects. It was written by describing what the software actually does, clause by clause; every technical statement in the annexes was checked against the software on 12 September 2026.

1. Parties

This Agreement is between:

(1) Think Apps AI Ltd, a company registered in England and Wales with company number 16590741, whose registered office is at 12 Hibel Road, Macclesfield SK10 2AB ("we", "us", the "Processor"); and

(2) the customer identified in the Think Projects account to which this Agreement relates ("you", the "Customer", the "Controller").

It forms part of, and is governed by, the Think Projects Terms of Service (the "Terms"). Where they conflict on the processing of personal data, this Agreement prevails.

2. What this covers, and what it does not

2.1 Think Projects holds two different kinds of personal data, and we hold them in two different capacities.

(a) Workspace content — the messages, replies, comments, tasks, files, time entries, project pages and notes, meeting notes, and the names and email addresses of the people you put into your workspace. You are the controller of this. We are your processor. This Agreement governs it.

(b) Account and billing data — the name, email address, password, sign-in records and subscription details of each person who has a Think Projects account. We are the controller of this, because we decide what is needed to run and secure the service and to take payment. It is governed by our Privacy Policy, not by this Agreement.

2.2 The practical difference is who a person asks. A request about what is inside a workspace comes to you; a request about someone's own account comes to us. Where a person asks the wrong one of us, we will each tell them who to ask rather than turn them away.

3. Our instructions

3.1 We will process workspace content only on your documented instructions, including as to transfers, unless we are required to do otherwise by law — in which case we will tell you first, unless the law forbids it.

3.2 Your instructions are: this Agreement, the Terms, and the choices you make in the product. Adding someone to a project, inviting a guest, importing a project from another tool, switching support access on, exporting or deleting a workspace, and turning a feature on or off are all instructions, and we will act on them without asking for anything further.

3.3 If we think an instruction infringes data protection law, we will tell you and may pause that processing until it is resolved.

3.4 We do not use workspace content for any purpose of our own. We do not sell it, we do not use it to train models, we do not profile the people in it, and we run no advertising or third-party analytics anywhere in the product.

4. Confidentiality

4.1 Everyone we authorise to process workspace content is bound by a duty of confidence, whether by their employment contract or by a written undertaking, and that duty survives the end of their engagement.

4.2 How staff access actually works, described exactly rather than generously:

(a) Through the product, nobody at Think Apps AI Ltd can open your projects, messages, tasks or files unless an owner or administrator of your organisation switches on support access. That grant lasts 24 hours, 7 days or 30 days as you choose, and it is off by default. A support session is read-only — every write is refused. Every time a member of our staff opens your workspace, one record is written and an email goes to your organisation's owner, and you can see the full list of every look inside the product.

(b) Underneath the product, the small number of people who administer the servers can reach the database files and the object storage directly, as anyone maintaining a hosted service must. That access is for keeping the service running — restoring a backup, diagnosing a fault — and is not gated by the control in (a). We say so here because an agreement that implied otherwise would be untrue.

5. Security

5.1 We will implement and maintain the technical and organisational measures set out in Annex 2, having regard to the state of the art, the cost of implementation, and the risk to the people whose data it is.

5.2 We may change those measures, but not in a way that materially reduces the overall level of security.

6. Sub-processors

6.1 You give us general authorisation to engage the sub-processors listed in Annex 3.

6.2 Each is engaged under a written contract imposing data protection obligations no less protective than these, and we remain fully liable to you for their performance.

6.3 We will give you at least 30 days' notice before adding or replacing a sub-processor that handles workspace content, by email to your organisation's owner and administrators and in the product. You may object on reasonable data protection grounds within that period; if we cannot resolve your objection, you may terminate the affected part of the service and we will refund any prepaid fees for the unused period.

7. International transfers

7.1 Your workspace — its database, its files and its backups — is stored in the European Union: on servers in Finland, and in Cloudflare R2's EU jurisdiction, which is an undertaking by Cloudflare that those objects stay in the EU rather than merely starting there.

7.2 Three things leave that boundary, and all are named rather than glossed:

(a) Notification email. An email telling someone what happened necessarily carries the title and roughly the first few hundred characters of the message or task it is about. Our email provider, Resend, sends from Amazon's Ireland region; Resend is a company incorporated in the United States whose terms state that its primary processing takes place there.

(b) Browser pop-ups. Where a person turns pop-ups on, the same title and extract are delivered through their browser's push service (Apple, Google or Mozilla).

(c) Network. Every connection to the service passes through Cloudflare's network, which operates worldwide.

Payments are handled by Stripe, in the United States among other places; no workspace content is ever sent to Stripe.

7.3 Where a transfer outside the UK or EEA takes place, it is made under a lawful transfer mechanism: for Cloudflare and Stripe, their certification under the EU–US Data Privacy Framework and its UK Extension, with the EU Standard Contractual Clauses and the UK International Data Transfer Addendum in their data-processing terms; for Resend, the EU Standard Contractual Clauses and the UK Addendum in its data-processing terms. Annex 3 states the position for each sub-processor.

8. Helping you with the rights of the people in your workspace

8.1 Most of what you need, you can do yourself and immediately: an owner can export the whole workspace at any time (a ZIP containing the workspace database and every file attached to it), can delete any content, and can remove a person from the organisation.

8.2 What removing a person does, because it surprises people: their membership, notifications and follows are deleted and their name comes off what they wrote, but the messages, replies, comments and tasks themselves remain in the workspace, without an author. They are your organisation's record of its own work. If a person needs the content itself removed rather than their name, you can delete it, and we will act on your instruction to do so.

8.3 If a person contacts us directly about workspace content, we will not answer them on your behalf: we will tell them to ask you, and tell you that they asked, promptly.

8.4 We will assist you with data protection impact assessments and prior consultations, and provide the information reasonably needed for them, insofar as it relates to our processing.

9. Personal data breaches

9.1 We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting workspace content.

9.2 The notification will describe, so far as we know it at the time: what happened, the categories and approximate number of people and records concerned, the likely consequences, and what we are doing about it. Where we cannot provide it all at once, we will provide it in stages without undue further delay.

9.3 We will not notify a supervisory authority or any affected person on your behalf, or announce a breach affecting your workspace publicly, without telling you first.

10. Return and deletion

10.1 You may export your workspace at any time during the term, including while it is read-only after a plan lapses — being unable to add anything does not mean being unable to leave with what you already have.

10.2 On your instruction to delete, we delete the workspace database and every file belonging to it at once. After a plan lapses or a trial ends without one, the workspace is kept read-only for 90 days, with an email to the owner 14 days before it is deleted, and then deleted in the same way.

10.3 Backups. A deleted workspace can still exist inside encrypted backup snapshots for a period after deletion. Snapshots are taken hourly; every snapshot from the last two days is kept, then one per day for 30 days, after which it is deleted. So the outer limit is 30 days after deletion, and the data in those snapshots is not used for anything in the meantime.

10.4 The security record. We keep a central record of security-relevant events — when two-factor was changed, when a person was added or removed, when support access was opened and by whom. It sits outside the workspace database and is not deleted when the workspace is deleted, because it is the evidence of who did what, which is exactly what is wanted after an incident. Each record is deleted 24 months after the event; billing records are kept for six years as accounting law requires.

11. Audits

11.1 We will make available the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, and will respond to a reasonable security questionnaire once in any twelve-month period.

11.2 We hold no third-party security certification at present (no ISO 27001, no SOC 2).

11.3 An on-site audit or inspection may be carried out by you or a mandated auditor on 30 days' written notice, no more than once in any twelve-month period unless required by a supervisory authority, at your cost, during business hours, subject to confidentiality, and in a way that does not disturb the service or other customers' data.

12. General

12.1 This Agreement takes effect when you accept the Terms and continues while we process workspace content for you.

12.2 Our liability under this Agreement is subject to the limitations in the Terms.

12.3 This Agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Annex 1 — What is processed

Subject matter. Provision of Think Projects, a project collaboration service: projects, message threads, task lists, boards, timelines, pages, meetings, files, time tracking and the notifications that go with them.

Duration. For as long as the Customer's organisation exists, and then as set out in clause 10.

Nature and purpose. Storing, organising, displaying, searching, indexing, backing up, and transmitting workspace content to the people the Customer shares it with; sending the emails and notifications the service produces; and providing support when asked.

Categories of data subject

  • The Customer's own team members.
  • Guests and clients the Customer invites to particular projects.
  • People named in imported projects. When a project is imported from Teamwork, Trello, Asana, ClickUp, monday or a spreadsheet, the export can contain the names and email addresses of everyone who worked on it, and people are created from them.
  • Contacts recorded against a company in the Customer's address book, and people outside the workspace who take part in a conversation by email or attend a meeting.

Categories of personal data

  • Identifiers: name, email address, @handle, avatar image, job title, the company someone belongs to.
  • Workspace content: messages, replies, comments, task titles and descriptions, files and their contents, time entries, project pages and notes, meeting agendas and minutes — and therefore whatever personal data the Customer chooses to put into them.
  • Relationship data: which projects a person can see, what they are assigned, who mentions them, what they have read.
  • Technical data: IP address, sign-in times, browser language and time zone, and the fact that a device has notifications turned on.

Special categories of personal data. The service is not designed for special category data and the Customer is asked not to place it there. If the Customer does, it is processed under the same measures as everything else, with no additional safeguards specific to it.

Annex 2 — Technical and organisational measures

Access control

  • Passwords are stored as bcrypt hashes and never in plain text. A password is refused if it is weak or guessable.
  • Optional two-factor authentication (TOTP, RFC 6238, with ten single-use recovery codes stored only as hashes). An organisation can require two-factor of all its members, and then nothing but the sign-in routes will answer until it is set up. The TOTP shared secret is encrypted at rest in the database under a key held only on the server.
  • Sessions are signed tokens with a matching server-side record, so a session can be revoked. The cookie is HTTP-only, SameSite=Lax and Secure in production, and lasts one day, or thirty with "keep me signed in".
  • Sign-in is rate-limited (20 attempts per 15 minutes per IP and email address), as are two-factor attempts (15 per 15 minutes) and password reset requests (5 per hour). Cloudflare applies a further limit at the edge.

Separation

  • Each organisation's content lives in its own database file, and its own prefix in object storage. Every request is scoped to one organisation for its lifetime, and an attempt to reach another organisation's data is refused outright.

Staff access — as described in clause 4.2: support access is off by default, is granted by the Customer for a fixed period, is read-only, and every look is recorded and emailed to the organisation's owner.

Transmission

  • HTTPS throughout, with HSTS (one year, including subdomains).
  • The application server has no inbound ports open to the internet: traffic reaches it only through an outbound Cloudflare Tunnel. A host firewall and a cloud firewall sit in front of that.
  • A strict content security policy; framing refused; no third-party scripts beyond the payment provider's.

Storage and encryption

  • Databases: on the application server, in Finland (EU).
  • Files and backups: Cloudflare R2, EU jurisdiction, encrypted at rest by the provider.
  • The application server's own disk is not encrypted at rest — the host does not offer it, and a self-unlocking encrypted volume on the same machine would protect against nothing realistic.

Backups and restoration

  • Hourly snapshots of every database, compressed and written to EU object storage. Every snapshot from the last two days is kept, then one per day for thirty days.
  • Restoration is tested: a snapshot was fetched, unpacked and verified end to end on 8 September 2026, and the record counts matched the live system exactly.

Availability and resilience

  • Uptime monitoring with alerting.
  • The service restarts itself on failure; the host takes daily machine-level backups in addition to the application's own.

Logging and accountability

  • A central record of security-relevant events: password and two-factor changes, sessions revoked, people added and removed, support access granted and used, billing changes, and administrative actions, kept for 24 months (clause 10.4).
  • Customers can see every occasion on which our staff opened their workspace.

What we do not do — stated because a customer's security team will ask

  • Uploaded files are not scanned for malware. They are stored as received and served back only to people who can already see that project.
  • We hold no third-party security certification (no ISO 27001, no SOC 2), and no external penetration test has been carried out.

Annex 3 — Sub-processors

Supplier What it does Where, and transfer basis Sees workspace content?
Hetzner Online GmbH Hosting: the server the application and its databases run on Finland (EU); no transfer Yes — it is the machine the data sits on
Cloudflare, Inc. Network, DNS, the tunnel that reaches the server, edge security; object storage (R2) for files and backups; routing of inbound email to the service Storage in the EU jurisdiction; company incorporated in the US; EU–US Data Privacy Framework and UK Extension, with standard contractual clauses and the UK addendum in its data-processing addendum Yes — files, backups, and traffic in transit
Resend (Plus Five Five, Inc.) Sending outbound email: confirmations, invitations, notifications, billing messages Sends via Amazon SES in Ireland; company incorporated in the US; standard contractual clauses and the UK addendum in its data-processing terms Yes, in part — a notification email carries the title and about the first 400 characters of the message or task it concerns
Stripe (Stripe, Inc. and its affiliates) Payments and subscriptions US and Ireland; Stripe, LLC is certified under the EU–US Data Privacy Framework and UK Extension; standard contractual clauses in its data-processing terms No
KLIPY (Kikliko, Inc.) GIF search, where the organisation has it switched on and a person searches US; no transfer safeguard stated in its published policy — the organisation can switch GIF search off No — only the words typed into the GIF search box and a pseudonymous identifier; previews load from KLIPY into the person's browser
Google LLC Sign-in with Google, and Google Drive export, only where an individual person chooses to connect them US; EU–US Data Privacy Framework and UK Extension Only what that person chooses to export

© Think Apps AI Ltd — registered in England and Wales, company number 16590741, registered office 12 Hibel Road, Macclesfield SK10 2AB.