Skip to content

Privacy Policy

How we handle personal information across the Manage Tasks website and services, and how to exercise your rights.

Last revised: 2026-09-17

Infinity Web Ltd.

Company number (UIC):
203092753
VAT number:
BG203092753
Registered office:
Lyulin district, Block 983, Apartment 57, 1324 Sofia, Bulgaria
Support and privacy:
Support and privacy email address
Contact us
On this page
  1. 1. Who is responsible for your data
  2. 2. Information we receive
  3. 3. Where information comes from
  4. 4. Why we process data and the legal bases
  5. 5. Required information and automated checks
  6. 6. Who can receive information
  7. 7. International transfers
  8. 8. How long information is kept
  9. 9. Cookies and optional analytics
  10. 10. Your rights and how to exercise them
  11. 11. Security and your choices
  12. 12. Complaints and changes to this notice

1. Who is responsible for your data

Infinity Web Ltd. (Инфинити Уеб ЕООД), UIC 203092753, VAT BG203092753, is responsible as controller for personal data used to operate this website, handle enquiries, manage its customer accounts and billing, and protect its services. Our registered office is Lyulin district, Block 983, Apartment 57, 1324 Sofia, Bulgaria. Email Support and privacy email address to send a privacy request, stating “Privacy request” and the relevant account or enquiry.

For business records that an organization enters into its workspace, that organization generally determines the purposes and means of processing and acts as controller. We process those records on its instructions where we act as processor. If you are an employee, contact, guest or customer of such an organization, its own privacy notice applies to its use of your data. You can contact that organization first; we assist it with requests as required by our agreement and law.

2. Information we receive

Account and commercial data may include your name, email, phone number, organization, role, login identifiers, authentication and security information, billing details, purchased plan and add-ons, payment status and payment-provider references. If you choose a supported social sign-in provider, we receive the profile and account information authorized through that provider.

Enquiries can include your name, email, phone number, subject, message and requested service or configuration. Contact and security records may also contain IP address, approximate location inferred from the connection, browser and device information, screen size, language, time zone, requested page, referrer and campaign parameters. Optional abuse checks may produce VPN, proxy, Tor or risk indicators.

Depending on the modules your organization enables, workspace data can include company and contact records, employee and contract information, orders, invoices, payment records, inventory, reservations, addresses, deliveries, tasks, messages, attachments, calendars and audit trails. Vehicle features can include location, routes, timestamps, speed and associated driver or device identifiers; connected camera features may include images or recordings where enabled. Your organization controls which features are used and who can access them. Do not submit unnecessary sensitive data in a general enquiry.

3. Where information comes from

We receive information from you, your organization and its authorized users, service activity and devices, and integrations your organization connects. Optional sign-in and payment providers supply the information needed for the selected transaction or login. Company lookup features may use public company registers or authorized data providers. The relevant organization is responsible for telling affected people about data it supplies to the service.

4. Why we process data and the legal bases

We use account, subscription, order and support information to take steps you request before a contract and perform our contract with you. Where the customer is an organization, handling its representatives’ contact details and administering their access also serves our legitimate interests in delivering and managing that business relationship.

We process invoices and other legally required records to comply with accounting, tax and other legal obligations. We process security logs, access events and abuse indicators in our legitimate interests in preventing fraud, protecting users and systems, troubleshooting faults and establishing or defending legal claims. We balance these interests against individuals’ rights and limit access accordingly.

Optional analytics uses your consent. Where we ask for consent for another optional purpose, the request identifies that purpose; you can withdraw it without affecting earlier lawful processing. Business records processed on an organization’s instructions follow its documented instructions and legal bases, subject to the applicable processing agreement. We do not treat acceptance of the Terms as consent to every use of personal data.

5. Required information and automated checks

Information marked as required in a form is needed to create the account, answer the enquiry, complete the order or meet a legal obligation. If you do not provide it, we may be unable to provide that particular service. Optional information is not required to browse the public site.

Security and anti-spam rules, including configured IP reputation checks, can automatically reject or limit requests. If a legitimate request is blocked, email Support and privacy email address and ask for review. This notice does not authorize decisions producing legal or similarly significant effects based solely on automated processing. If such a feature is introduced, the responsible controller must provide the required specific information and safeguards.

6. Who can receive information

Access is limited to authorized personnel and service providers who need it for their role. Depending on the service, recipients may include infrastructure and hosting providers, email and notification providers, technical support providers, payment processors and providers of the integrations you choose. Stripe processes online subscription payments offered through Stripe checkout. Where enabled, Google provides analytics or sign-in, LinkedIn provides sign-in, and IPinfo or IPQualityScore may provide IP reputation checks. External media loaded by a page can disclose connection information to the media provider.

Your workspace administrators and authorized users can see information according to their permissions. Connected banks, carriers, fiscal systems or other providers receive information needed for the actions your organization requests and may act as independent controllers for their own services. We may also disclose information where required by law, to competent authorities, or where necessary to protect rights and address security incidents. Contact us for details of the providers relevant to your service and applicable processing arrangements.

7. International transfers

Some selected providers or integrations may process information outside Bulgaria or the European Economic Area. Where a transfer is subject to GDPR restrictions, an appropriate legal transfer mechanism is required, such as an applicable European Commission adequacy decision or standard contractual clauses with any necessary supplementary safeguards.

You may request information about the destinations and safeguards relevant to your service and how to obtain a copy of applicable safeguards, with confidential information protected where necessary. A connected third party’s own notice also explains its processing. This policy does not promise that all processing takes place only in Bulgaria or the EU.

8. How long information is kept

Retention depends on the purpose and type of record. Account and service administration data is kept while needed for the relationship and its closure; enquiry records while needed to answer and follow up the request; accounting and transaction records for applicable statutory periods; and security records for the period needed to investigate incidents and protect the service. Disputed matters may require relevant records to be kept until claims are resolved or applicable limitation periods expire.

Workspace record retention and return or deletion after termination follow the customer’s instructions, service agreement, applicable processing terms and law. Backup copies are removed according to the applicable backup cycle and may remain until that cycle completes. We then delete or anonymize information that is no longer needed. Contact us for the retention period or criteria applicable to a particular record or service.

9. Cookies and optional analytics

We use necessary storage and cookies for functions such as login sessions, security and remembering relevant preferences. Blocking necessary cookies may prevent forms or account features from working. You can manage stored cookies through your browser.

Where Google Analytics is configured, it is off until you choose “Accept analytics”. Choosing “Reject analytics” leaves it off and does not prevent use of the website. The analytics preference is stored in this browser for 180 days; you can reopen “Analytics settings” at any time to change it. If browser storage is unavailable, a choice may last only for the current page.

With consent, Google Analytics receives page and usage events and technical information such as browser, device and connection information and may set identifiers such as _ga cookies. We configure analytics cookies to expire after 180 days. Changing the setting to reject stops further collection on this site and removes accessible first-party _ga cookies; it does not automatically erase information already sent to the provider. You can also clear browser storage or make a data rights request. Preferences apply to this browser and website, so another device or domain may ask again.

10. Your rights and how to exercise them

Subject to the conditions in applicable law, you may request access and a copy, correction, deletion, restriction and portability of your personal data. You may object to processing based on legitimate interests for reasons relating to your situation and may object to direct marketing at any time. You may withdraw consent at any time without affecting the lawfulness of earlier processing. Rights may be limited where a legal obligation or another lawful exception applies.

Email Support and privacy email address or use the contact link below. Tell us what you need and enough information to locate the relevant records; we may request proportionate identity or authority verification. Please do not send identity documents unless specifically requested through an appropriate channel. Requests are normally free of charge and answered within one month. Where the law permits an extension of up to two further months for complexity or number of requests, we will tell you within the first month and explain why.

For records controlled by your employer or another customer organization, direct the request to that controller. If you contact us about such records, we will assist or refer it appropriately without disclosing another organization’s data.

11. Security and your choices

We apply technical and organizational measures appropriate to the processing risks, including access controls and service security measures. No online system can guarantee absolute security. Protect your credentials, use available account protection, review workspace permissions and report suspected misuse promptly.

Vehicle tracking, workforce and camera features require particular care by the organization using them. It must establish a lawful purpose, inform the people affected, apply proportionate monitoring and access restrictions, and avoid collecting more information than needed. Our public services are intended for business and professional use, not directed to children. Contact us if you believe a child has provided data to us inappropriately.

12. Complaints and changes to this notice

You may lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP) or another competent supervisory authority, including in the EU country where you live or work or where an alleged infringement occurred. You do not have to contact us before exercising this right. The official CPDP complaints page is linked below.

We may update this notice when services or processing arrangements change. The revision date identifies the current text. Where required, we will provide further notice of significant changes or seek fresh consent before a new consent-based use. Contact us if you need clarification about a specific service or data flow.