← Back to TaskFlow

Privacy Policy

Effective date: 18 April 2026  ·  Last updated: 25 September 2026

1. Who we are

TaskFlow is a task and appointment management SaaS product operated by Ease AI (“TaskFlow”, “we”, “us”). Contact: privacy@ease-ai.my.

This policy explains what personal information TaskFlow collects, how we use it, how we share it, and the rights you have over it.

2. Scope

This policy covers:

3. Information we collect

3.1 Account & workspace data

3.2 Google Calendar data (opt-in)

If an admin connects a Google account via the in-app Connect Google Calendar button, TaskFlow stores:

TaskFlow requests only the three OAuth scopes it needs: calendar.events (read/write events), calendar.readonly (list calendars) and drive.file (only the Google Drive files a user explicitly picks in the Drive file picker to attach to a task). For an attached Drive file, TaskFlow stores its name, link and file ID on the task; it cannot see any other file in your Drive. TaskFlow does not read or store contacts, Gmail content, or any data outside the calendars the admin explicitly selects and the files a user explicitly attaches.

Disconnection: an admin can revoke TaskFlow's access at any time from the in-app Settings page, or directly via myaccount.google.com/permissions. On disconnect, stored tokens are cleared; existing calendar events in your workspace remain visible so historical context is not lost, but no further sync is performed until you reconnect.

3.3 WhatsApp integration data

If your workspace connects a WhatsApp account via QR code scan:

3.4 Operational / log data

4. How we use information

We use the information above strictly to:

TaskFlow does not sell personal information and does not use Google user data for advertising.

5. Google API Services user data policy compliance

TaskFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice:

6. Sharing

We share personal data only with the following categories:

7. Retention

8. Your rights

Subject to local law (we operate under Malaysia's PDPA 2010 by default), you can:

To exercise these rights, email privacy@ease-ai.my. We aim to respond within 30 days.

9. Security

TaskFlow uses bcrypt for password hashing, AES-256-GCM for at-rest encryption of OAuth tokens, TLS 1.2+ for all in-transit traffic, and cookie-based JWT session tokens with a 7-day rolling lifetime that always end after 90 days at most. We keep the software patched and monitor for anomalies, but no system is absolutely secure — if you discover a vulnerability, please email security@ease-ai.my.

10. Cookies

TaskFlow sets a small number of functional cookies:

We do not set advertising or tracking cookies.

11. Children

TaskFlow is a business product and is not directed at children under 13. We do not knowingly collect personal data from children.

12. Changes

We may update this policy as the product evolves. Material changes will be announced inside your workspace and by email to the workspace admin. The “Last updated” date at the top always reflects the current version.

13. Contact