Website legal information

Privacy Policy

This policy explains how we handle personal data when you visit the Task Shmask marketing website or contact us about it. We operate from Denmark and apply the EU General Data Protection Regulation (GDPR) and applicable Danish data protection and cookie rules.

Website only. This website displays product information and screenshots and may link to the App Store, application websites, or download pages. It does not run the Task Shmask application or access your tasks. This policy does not cover data processing inside the application, cloud synchronization, app accounts, or purchases. Consult the separate application privacy notice and the relevant store's notice for those activities.

1. Who is responsible for your data?

The business identified below is the controller for the website-related processing described here. “We,” “us,” and “our” refer to that business, not to Apple or the application download platform.

Use the email above for privacy questions and to exercise your GDPR rights.

2. What data is processed, why, and on what basis?

Website delivery and security

Our website is hosted on Cloudflare Pages™. Delivering a page necessarily involves processing technical request information, such as your IP address, requested URL, request time, HTTP headers (which may include browser information and a referring page), response status, and security or error information. Cloudflare, Inc. processes this information through its hosting and security infrastructure; the information retained in logs depends on the enabled service features.

We use this processing to deliver the website, diagnose faults, and protect it and its visitors against abuse. The GDPR basis is our legitimate interests in operating a reliable, secure informational website (Article 6(1)(f)). We do not use this data for advertising profiles.

Messages you choose to send

If you email us, we receive your email address, any name you provide, the message, attachments, and related correspondence metadata. We use them to answer your enquiry and manage necessary follow-up. Please send only information relevant to your request; do not send passwords, sign-in codes, or unnecessary sensitive information.

The basis is our legitimate interest in responding to correspondence (Article 6(1)(f)); where your enquiry concerns steps you request before entering a contract with us, Article 6(1)(b) may apply. Records needed to comply with a specific legal obligation are processed under Article 6(1)(c). Providing a message is voluntary, but without a contact address or enough information we may be unable to respond.

What the website does not collect

The website has no account registration, payment checkout, newsletter signup, or contact form. Its code contains no analytics, advertising trackers, crash-reporting SDKs, embedded third-party media, or external fonts. We do not receive your application workspace, Apple password, or payment-card details merely because you visit this website or follow a download link.

3. Cookies and similar technologies

The website's own code does not set or read cookies, localStorage, IndexedDB, or other persistent tracking identifiers. Screenshot selection, slideshow controls, image previews, and the mobile menu keep their state only in memory while the page is open. Your browser may cache ordinary static files; we do not use that cache to identify you.

Cloudflare may use technically necessary security cookies if the relevant protection features are enabled, for example __cf_bm for bot protection (expires after 30 minutes of inactivity) or cf_clearance to remember a passed security challenge (its lifetime depends on the configured challenge settings). These are conditional infrastructure cookies, not an assertion that both are set on every visit. Cloudflare describes their purposes and current lifetimes in its cookie documentation.

Under Danish cookie rules, an exemption from prior consent applies only to storage or access that is technically necessary to transmit a communication or provide a service you expressly request. This is separate from the GDPR legal basis for any personal-data processing. We do not rely on the exemption for advertising or optional analytics.

We have not added a consent banner because this website has no optional tracking or non-essential storage in its code. If we introduce technologies requiring consent, we will explain the providers, purposes, and lifetimes, obtain consent before activating them, and provide an accessible way to refuse or withdraw it. Simply browsing the website is not consent.

You can block or remove cookies using your browser's settings. Blocking a necessary security cookie may cause repeated challenges or prevent access. Cookies on an App Store or download page are controlled by that service, not by this website.

4. Who receives personal data?

We do not sell or rent website visitors' personal data or disclose it to advertising networks.

5. International transfers

Operating from Denmark does not mean all infrastructure processing stays in Denmark or the European Economic Area (EEA). Cloudflare operates a global network and may process information outside the EEA, including in the United States.

For Cloudflare's processing on our behalf, we use its Data Processing Addendum, which provides for transfers under the EU–US Data Privacy Framework where applicable and incorporates the European Commission's Standard Contractual Clauses for restricted transfers. The applicable mechanism depends on the recipient and transfer; we do not assume every US recipient is covered by an adequacy decision. Other processors used for website-related data must likewise have an applicable lawful transfer basis and any necessary additional safeguards.

You may contact us for information about the safeguards applicable to your data and a copy where available, with confidential or unrelated information redacted as necessary.

6. How long is data kept?

We apply the following retention criteria rather than keeping personal data indefinitely:

A legal retention requirement applies only to the records it covers, not automatically to everything you send us.

7. Your GDPR rights and complaints

Depending on the processing and applicable conditions, you have rights to access your personal data, correct inaccurate data, request erasure, restrict processing, and receive data in a portable format where processing is automated and based on consent or contract.

You may object to processing based on legitimate interests for reasons relating to your particular situation. We must stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or need it for legal claims. If processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Send requests to the email in section 1. We may ask only for information reasonably needed to confirm your identity and locate relevant records. Requests are generally free. We respond without undue delay and normally within one month of receipt. Where GDPR permits an extension for complexity or the number of requests, we may extend by up to two further months and will explain the extension within the first month.

You can complain to the Danish supervisory authority, Datatilsynet, or another competent EU/EEA supervisory authority, including where you live or work. Datatilsynet recommends contacting the organization first to try to resolve the issue; this does not remove your GDPR right to lodge a complaint.

8. Security and automated processing

We use appropriate technical and organizational safeguards for the website and correspondence, including encrypted website delivery in production and limiting access to business systems. No transmission or storage method can be guaranteed completely secure.

We do not use website data for decisions based solely on automated processing that produce legal or similarly significant effects within Article 22 GDPR. Hosting infrastructure may automatically filter abusive traffic or present a security challenge; this is not advertising profiling.

The website does not ask visitors for their age or create child accounts. If you believe a child has sent unnecessary personal information to us, contact us so we can address it appropriately.

9. App Store and download links

Store and download links are ordinary navigation links, not embedded store widgets or tracking SDKs. Our code does not contact those services just to display a link. Configured application/download links use rel="noreferrer" so the browser is instructed not to send this page as a referrer.

When you follow a link, the destination receives your request and handles your data under its own applicable notice. Apple and other independent destination operators determine their own processing for browsing, downloads, accounts, and purchases. See, for example, Apple's privacy information. This policy does not replace those notices or the application's separate privacy policy.

10. Changes to this policy

We may update this policy to reflect actual changes to the website, our practices, or legal requirements. The date above identifies the latest revision. Where required, we will provide additional notice or obtain consent before starting new processing; a policy update alone is not your consent.