Features Industries Customer Service AI Pricing Blog Log in Start for free
Project Management

LGPD (Brazil's Data Protection Law) and Project Management Tools: What to Ask the Vendor Before You Buy

Tasks, tickets and conversations carry personal data of customers and employees. The questions your company should ask any project management software vendor — from permissions to export — before signing.

A project management tool seems harmless: tasks, deadlines, comments. But open any account with a year of use and you will find client names, emails, phone numbers, customer service conversations, attached contracts, and sometimes employee data. All of that is personal data, and whoever buys the software remains responsible for it toward the data subjects.

This article is not legal advice, and it doesn't replace the opinion of your lawyer or your company's data protection officer. It is a list of practical questions to ask any vendor before signing. At the end, we show how Tasskee answers each one, using only what is published on the security and LGPD page (LGPD is Brazil's data protection law).

Why the question falls to whoever buys

Under the LGPD, the company that decides what the data is used for is the controller; the software vendor generally processes the data on its behalf. In practice, this means that if data leaks or is misused inside the tool, the conversation with the customer and with the authority starts with your company. Choosing the vendor well is part of your duty of care, and the questions below help document that choice.

The questions that matter

1. Who sees what? (permissions)

Ask whether permission profiles exist, whether they are configurable, and whether they apply per project. The person in finance doesn't need to see the recruiting project, and the guest client should see nothing beyond what you released. Also ask whether sensitive information, such as rates and costs, has its own permission.

2. Is one company's data isolated from another's?

In multi-tenant software, several customers share the same infrastructure. Ask the vendor to explain how one organization is separated from another: its own team, permissions, and settings, or everything mixed together?

3. Is there a record of who changed what?

In case of an incident or a doubt, the change log answers "who did it, when, and from what to what." Ask how long the history is kept and whether it also covers automatic actions and artificial intelligence actions.

4. Can I export my data?

Portability is a right of the data subject and a protection for the customer against being locked in. Ask which formats exist, whether scheduled export is available, and whether there is a documented API for pulling data out automatically.

5. Is there a data protection officer and a channel for the data subject?

Someone needs to respond when a data subject asks for access, correction, or deletion of their data. Ask who the vendor's data protection officer is, what the email is, and whether the privacy policy explains how to make the request.

6. Who are the subprocessors?

Your vendor probably uses other services to operate: hosting, email, payment. Ask which ones they are, what they are for, and whether there is public information about them. A vendor that can't list what it uses is a red flag.

7. How does artificial intelligence handle my data?

Specific questions: does the product's AI see more than the user would? Does my data train third-party models? Who is the AI provider and whose key is it? Is there confirmation before irreversible actions and a record of what the AI did?

8. What about integrations and the API?

Access tokens with scope and expiration, revocable, and signed webhooks are signs the integration was designed with security in mind. Ask whether a compromised key can be canceled on the spot.

9. What happens if I cancel?

Ask how long the data is kept after cancellation, how it is deleted, and whether you can export everything first. The answer should be in the terms of use or the privacy policy.

A table for comparing vendors

QuestionWhat to expect from a good answerRed flag
PermissionsConfigurable profiles, per project, with sensitive values separatedEveryone sees everything
IsolationA clear explanation of how organizations are separated"Everything is secure" with no detail
Action logLog with author, date, and stated retentionNo history
ExportOpen formats, scheduled export, APIOnly exports on request to support
Data protection officerPublic name or email and an accessible privacy policyNo contact for data subjects
SubprocessorsList or information available on requestThey can't answer
AIAccess limits, confirmation, and audit explainedAI reads everything, with no log

How Tasskee answers

To be transparent about what we say and what we don't: below is what the security and LGPD page publishes. What isn't there, we don't claim here.

  • Permissions: custom profiles per organization and a different role in each project. In Hours, seeing the billed amount, seeing cost, and doing closings are separate permissions.
  • Isolation: each organization has its own team, permissions, statuses, tags, and fields. Guests access, through the client portal, only what was released from the project.
  • Log: change log on each task, with retention of 7 days on Start, 90 days on Pro, and unlimited on Max. Automations appear signed, with a history of each run.
  • Export: list export, scheduled account export, and a REST API with public documentation.
  • Data protection officer: the channel for data subject rights is the email [email protected], and processing follows Tasskee's Privacy Policy and Terms of Use.
  • AI: uses the key of the provider your company subscribes to (OpenAI, Gemini, or Claude); Tasskee does not resell AI. The AI sees what the person sees, asks for confirmation before irreversible actions in execution mode, and records each action in an audit log.
  • Integrations: API and MCP server tokens with scope and expiration, revocable, and signed outbound webhooks.

What Tasskee does not claim in this article

This page does not state where the servers are located nor declare certifications. If those points are a requirement of your contract or your IT department, ask directly through contact and request the answer in writing. The same rule applies to any vendor: what matters is what they agree to put on paper.

How to use this list in practice

  1. Copy the questions into an email and send it to every vendor you are evaluating.
  2. Ask for the answers in writing and keep them with the contract.
  3. Take questions of interpretation to your lawyer or data protection officer, because the legal framing depends on your case.
  4. Revisit the choice when usage changes: when you turn on AI, when you open the portal to clients, when you integrate another system.

Beyond the vendor: what is your responsibility

Even with the best vendor, part of the care for personal data depends on how your own team uses the tool. A few habits make a difference and cost nothing.

  • Give each person only the access they need. Permission profiles exist for this. Reviewing access when someone changes roles or leaves the company is routine, not the exception.
  • Avoid pasting sensitive data into descriptions and comments. ID documents, health data, passwords: the right place for that kind of thing is not a task's text field.
  • Deactivate people who left. An active account for a former employee is one of the most common and most easily avoided risks.
  • Know what the AI accesses. Before turning on artificial intelligence features, understand which provider and which key they run on, and record the decision.
  • Define what the client sees. If you use a portal for guests, review on each project what has been released.

What if the vendor doesn't answer well?

An evasive answer is not, in itself, proof of bad faith: many small vendors simply don't have the documentation ready. But it is information. Weigh three things: whether the answer exists and is specific, whether it is in writing, and whether the vendor agrees to answer new questions after you sign. When your case involves sensitive data, or a contractual requirement from a large client, take the matter to legal before rolling out, not after.

See what Tasskee publishes about security and LGPD

Permissions, change log, AI with brakes, and the channel for data subject rights, on the official page.

See security and LGPD at Tasskee
Contact us