Version 1.0 · effective from: July 19, 2026 · Annex to the Terms of Service
This data processing agreement (“DPA”) is an annex, within the meaning of GDPR Article 28, to the agreement between 1/2 Mind OÜ (the “processor”, “we”) and the customer of the Service (the “controller”, the “customer”), and applies to all personal data that we process on the customer’s behalf when providing the Service (juhiabi.ee / taskment.io / backline.ee / stagement.live).
Subject matter: providing the SaaS service — hosting, backing up and processing the customer’s workspace data under the customer’s instructions. Duration: the term of the agreement and the transition period described in clause 14 of the Terms.
Storing, retaining, displaying, backing up, exporting and deleting data, and performing the integrations chosen by the customer (e.g. email, calendar, e-invoices, marketing, AI features, cloud storage).
The customer’s employees and users; the customer’s clients, contact persons and suppliers; other persons whose data the customer enters into the workspace. Data types: names and contact details, role and communication data, content of projects/tasks/documents, billing data and other content entered by the customer. The Service is not intended for processing special categories of personal data.
We process personal data only on the customer’s documented instructions (the agreement, Service settings, written instructions), unless processing is required by law — in that case we inform the customer before processing, unless prohibited.
Persons with access to personal data are bound by confidentiality. We apply appropriate technical and organisational measures: encrypted connections (TLS), isolation of workspace data, a role-based permission system, access restrictions, logging, daily backups (kept up to 30 days) and regular security updates.
The customer grants a general authorisation to use sub-processors. The current list is published in the privacy policy (server hosting in the EU; Google, Dropbox, Microsoft, Brevo, Smaily, Finbite and Anthropic — only if the customer enables the respective integration or feature). We give advance notice of material changes in the Service or by email; the customer may object on reasonable grounds. We impose equivalent data protection obligations on sub-processors.
We assist the customer to a reasonable extent in responding to data subject requests (access, rectification, erasure, portability, etc.) and in fulfilling the obligations of GDPR Articles 32–36 (security, breach notifications, impact assessments).
We notify the customer of a personal data breach without undue delay after becoming aware of it, including the known information about the nature, impact and measures taken.
We process data in the European Union. If an integration chosen by the customer (e.g. Google, Microsoft, Dropbox, Anthropic) transfers data outside the EU, it takes place under that provider’s GDPR Chapter V mechanism (e.g. the EU-US Data Privacy Framework or standard contractual clauses).
Upon termination we return the customer’s data in a machine-readable format and/or delete it within the periods described in clause 14 of the Terms and the privacy policy, except for data we must retain by law.
Upon reasonable request we provide the information necessary to demonstrate compliance with Article 28 and allow audits to a reasonable extent that does not endanger other customers’ data.
1/2 Mind OÜ · registry code 11550459 · Keki tn 3, 76606 Keila, Estonia · VAT EE101298384 · registered in the Estonian Commercial Register
Email: info@juhiabi.ee