Last updated 12 September 2026. Questions: [email protected]
This Agreement describes how Think Apps AI Ltd processes personal data on behalf of the organisations that use Think Projects. It was written by describing what the software actually does, clause by clause; every technical statement in the annexes was checked against the software on 12 September 2026.
This Agreement is between:
(1) Think Apps AI Ltd, a company registered in England and Wales with company number 16590741, whose registered office is at 12 Hibel Road, Macclesfield SK10 2AB ("we", "us", the "Processor"); and
(2) the customer identified in the Think Projects account to which this Agreement relates ("you", the "Customer", the "Controller").
It forms part of, and is governed by, the Think Projects Terms of Service (the "Terms"). Where they conflict on the processing of personal data, this Agreement prevails.
2.1 Think Projects holds two different kinds of personal data, and we hold them in two different capacities.
(a) Workspace content — the messages, replies, comments, tasks, files, time entries, project pages and notes, meeting notes, and the names and email addresses of the people you put into your workspace. You are the controller of this. We are your processor. This Agreement governs it.
(b) Account and billing data — the name, email address, password, sign-in records and subscription details of each person who has a Think Projects account. We are the controller of this, because we decide what is needed to run and secure the service and to take payment. It is governed by our Privacy Policy, not by this Agreement.
2.2 The practical difference is who a person asks. A request about what is inside a workspace comes to you; a request about someone's own account comes to us. Where a person asks the wrong one of us, we will each tell them who to ask rather than turn them away.
3.1 We will process workspace content only on your documented instructions, including as to transfers, unless we are required to do otherwise by law — in which case we will tell you first, unless the law forbids it.
3.2 Your instructions are: this Agreement, the Terms, and the choices you make in the product. Adding someone to a project, inviting a guest, importing a project from another tool, switching support access on, exporting or deleting a workspace, and turning a feature on or off are all instructions, and we will act on them without asking for anything further.
3.3 If we think an instruction infringes data protection law, we will tell you and may pause that processing until it is resolved.
3.4 We do not use workspace content for any purpose of our own. We do not sell it, we do not use it to train models, we do not profile the people in it, and we run no advertising or third-party analytics anywhere in the product.
4.1 Everyone we authorise to process workspace content is bound by a duty of confidence, whether by their employment contract or by a written undertaking, and that duty survives the end of their engagement.
4.2 How staff access actually works, described exactly rather than generously:
(a) Through the product, nobody at Think Apps AI Ltd can open your projects, messages, tasks or files unless an owner or administrator of your organisation switches on support access. That grant lasts 24 hours, 7 days or 30 days as you choose, and it is off by default. A support session is read-only — every write is refused. Every time a member of our staff opens your workspace, one record is written and an email goes to your organisation's owner, and you can see the full list of every look inside the product.
(b) Underneath the product, the small number of people who administer the servers can reach the database files and the object storage directly, as anyone maintaining a hosted service must. That access is for keeping the service running — restoring a backup, diagnosing a fault — and is not gated by the control in (a). We say so here because an agreement that implied otherwise would be untrue.
5.1 We will implement and maintain the technical and organisational measures set out in Annex 2, having regard to the state of the art, the cost of implementation, and the risk to the people whose data it is.
5.2 We may change those measures, but not in a way that materially reduces the overall level of security.
6.1 You give us general authorisation to engage the sub-processors listed in Annex 3.
6.2 Each is engaged under a written contract imposing data protection obligations no less protective than these, and we remain fully liable to you for their performance.
6.3 We will give you at least 30 days' notice before adding or replacing a sub-processor that handles workspace content, by email to your organisation's owner and administrators and in the product. You may object on reasonable data protection grounds within that period; if we cannot resolve your objection, you may terminate the affected part of the service and we will refund any prepaid fees for the unused period.
7.1 Your workspace — its database, its files and its backups — is stored in the European Union: on servers in Finland, and in Cloudflare R2's EU jurisdiction, which is an undertaking by Cloudflare that those objects stay in the EU rather than merely starting there.
7.2 Three things leave that boundary, and all are named rather than glossed:
(a) Notification email. An email telling someone what happened necessarily carries the title and roughly the first few hundred characters of the message or task it is about. Our email provider, Resend, sends from Amazon's Ireland region; Resend is a company incorporated in the United States whose terms state that its primary processing takes place there.
(b) Browser pop-ups. Where a person turns pop-ups on, the same title and extract are delivered through their browser's push service (Apple, Google or Mozilla).
(c) Network. Every connection to the service passes through Cloudflare's network, which operates worldwide.
Payments are handled by Stripe, in the United States among other places; no workspace content is ever sent to Stripe.
7.3 Where a transfer outside the UK or EEA takes place, it is made under a lawful transfer mechanism: for Cloudflare and Stripe, their certification under the EU–US Data Privacy Framework and its UK Extension, with the EU Standard Contractual Clauses and the UK International Data Transfer Addendum in their data-processing terms; for Resend, the EU Standard Contractual Clauses and the UK Addendum in its data-processing terms. Annex 3 states the position for each sub-processor.
8.1 Most of what you need, you can do yourself and immediately: an owner can export the whole workspace at any time (a ZIP containing the workspace database and every file attached to it), can delete any content, and can remove a person from the organisation.
8.2 What removing a person does, because it surprises people: their membership, notifications and follows are deleted and their name comes off what they wrote, but the messages, replies, comments and tasks themselves remain in the workspace, without an author. They are your organisation's record of its own work. If a person needs the content itself removed rather than their name, you can delete it, and we will act on your instruction to do so.
8.3 If a person contacts us directly about workspace content, we will not answer them on your behalf: we will tell them to ask you, and tell you that they asked, promptly.
8.4 We will assist you with data protection impact assessments and prior consultations, and provide the information reasonably needed for them, insofar as it relates to our processing.
9.1 We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting workspace content.
9.2 The notification will describe, so far as we know it at the time: what happened, the categories and approximate number of people and records concerned, the likely consequences, and what we are doing about it. Where we cannot provide it all at once, we will provide it in stages without undue further delay.
9.3 We will not notify a supervisory authority or any affected person on your behalf, or announce a breach affecting your workspace publicly, without telling you first.
10.1 You may export your workspace at any time during the term, including while it is read-only after a plan lapses — being unable to add anything does not mean being unable to leave with what you already have.
10.2 On your instruction to delete, we delete the workspace database and every file belonging to it at once. After a plan lapses or a trial ends without one, the workspace is kept read-only for 90 days, with an email to the owner 14 days before it is deleted, and then deleted in the same way.
10.3 Backups. A deleted workspace can still exist inside encrypted backup snapshots for a period after deletion. Snapshots are taken hourly; every snapshot from the last two days is kept, then one per day for 30 days, after which it is deleted. So the outer limit is 30 days after deletion, and the data in those snapshots is not used for anything in the meantime.
10.4 The security record. We keep a central record of security-relevant events — when two-factor was changed, when a person was added or removed, when support access was opened and by whom. It sits outside the workspace database and is not deleted when the workspace is deleted, because it is the evidence of who did what, which is exactly what is wanted after an incident. Each record is deleted 24 months after the event; billing records are kept for six years as accounting law requires.
11.1 We will make available the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, and will respond to a reasonable security questionnaire once in any twelve-month period.
11.2 We hold no third-party security certification at present (no ISO 27001, no SOC 2).
11.3 An on-site audit or inspection may be carried out by you or a mandated auditor on 30 days' written notice, no more than once in any twelve-month period unless required by a supervisory authority, at your cost, during business hours, subject to confidentiality, and in a way that does not disturb the service or other customers' data.
12.1 This Agreement takes effect when you accept the Terms and continues while we process workspace content for you.
12.2 Our liability under this Agreement is subject to the limitations in the Terms.
12.3 This Agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Subject matter. Provision of Think Projects, a project collaboration service: projects, message threads, task lists, boards, timelines, pages, meetings, files, time tracking and the notifications that go with them.
Duration. For as long as the Customer's organisation exists, and then as set out in clause 10.
Nature and purpose. Storing, organising, displaying, searching, indexing, backing up, and transmitting workspace content to the people the Customer shares it with; sending the emails and notifications the service produces; and providing support when asked.
Categories of data subject
Categories of personal data
Special categories of personal data. The service is not designed for special category data and the Customer is asked not to place it there. If the Customer does, it is processed under the same measures as everything else, with no additional safeguards specific to it.
Access control
Separation
Staff access — as described in clause 4.2: support access is off by default, is granted by the Customer for a fixed period, is read-only, and every look is recorded and emailed to the organisation's owner.
Transmission
Storage and encryption
Backups and restoration
Availability and resilience
Logging and accountability
What we do not do — stated because a customer's security team will ask
| Supplier | What it does | Where, and transfer basis | Sees workspace content? |
|---|---|---|---|
| Hetzner Online GmbH | Hosting: the server the application and its databases run on | Finland (EU); no transfer | Yes — it is the machine the data sits on |
| Cloudflare, Inc. | Network, DNS, the tunnel that reaches the server, edge security; object storage (R2) for files and backups; routing of inbound email to the service | Storage in the EU jurisdiction; company incorporated in the US; EU–US Data Privacy Framework and UK Extension, with standard contractual clauses and the UK addendum in its data-processing addendum | Yes — files, backups, and traffic in transit |
| Resend (Plus Five Five, Inc.) | Sending outbound email: confirmations, invitations, notifications, billing messages | Sends via Amazon SES in Ireland; company incorporated in the US; standard contractual clauses and the UK addendum in its data-processing terms | Yes, in part — a notification email carries the title and about the first 400 characters of the message or task it concerns |
| Stripe (Stripe, Inc. and its affiliates) | Payments and subscriptions | US and Ireland; Stripe, LLC is certified under the EU–US Data Privacy Framework and UK Extension; standard contractual clauses in its data-processing terms | No |
| KLIPY (Kikliko, Inc.) | GIF search, where the organisation has it switched on and a person searches | US; no transfer safeguard stated in its published policy — the organisation can switch GIF search off | No — only the words typed into the GIF search box and a pseudonymous identifier; previews load from KLIPY into the person's browser |
| Google LLC | Sign-in with Google, and Google Drive export, only where an individual person chooses to connect them | US; EU–US Data Privacy Framework and UK Extension | Only what that person chooses to export |
© Think Apps AI Ltd — registered in England and Wales, company number 16590741, registered office 12 Hibel Road, Macclesfield SK10 2AB.