Parties and roles
The customer organisation acts as the controller for the purposes and means of processing it determines. Tap Tap Go Ltd, at 71–75 Shelton Street, Covent Garden, London, United Kingdom, acts as processor where it processes that data solely to deliver the agreed service on the customer’s instructions.
Tap Tap Go may act as an independent controller for its own account administration, website enquiries and legal obligations. Those activities are described in the Privacy Policy. Contact hello@taptapgo.io to arrange a DPA and complete the processing schedule for your organisation.
Processing scope and schedule
The service agreement and processing schedule must identify the subject matter, duration, nature and purpose of processing, categories of individuals and personal data, approved locations and the controller’s instructions.
- Typical purposes: providing managed professional profiles, team administration, authorised sharing, lead capture, reporting and support.
- Potential individuals: authorised employees, representatives, business contacts and people who submit enquiries to the customer.
- Potential data: names, professional roles, contact details, profile content, shared business documents, interaction records and authorised lead information.
- Excluded unless specifically agreed: unnecessary sensitive data, identity-document files, passwords and full payment-card credentials.
Instructions and controller responsibilities
The processor will process covered personal data only on documented instructions, including instructions about international transfers, unless a legal requirement applies. Where legally permitted, the controller will be informed of such a requirement. The processor will notify the controller if it believes an instruction infringes applicable data protection law.
The controller is responsible for lawful collection, appropriate notices and permissions, accuracy, the scope of information supplied and the lawful basis for its processing instructions. It must use the service consistently with the agreement and avoid uploading unnecessary personal data.
Confidentiality and security
Authorised personnel with access to covered personal data must be subject to confidentiality obligations. Appropriate technical and organisational measures must address the risk associated with the agreed processing.
The security schedule should document access controls, protection of data in transit, operational safeguards, recovery arrangements, incident handling and relevant monitoring. The agreed safeguards and processing locations must be confirmed for the actual corporate service; this website does not represent that every service or enquiry is hosted in one country.
Sub-processors and international transfers
Any sub-processors, their functions and processing locations must be recorded for the contracted service and authorised in accordance with the written agreement. The processor must impose relevant data protection obligations on approved sub-processors and follow the agreed notice and objection process when proposing changes.
Transfers that require a lawful safeguard under applicable data protection law must use that safeguard. Hosting and email delivery for this website are separate from a customer’s contracted corporate processing environment. Website enquiry forms use FormSubmit; the corporate processing schedule must not assume that website forms share the app’s infrastructure.
Rights requests, incidents and assistance
Taking account of the nature of processing and information available, the processor will assist the controller with data-subject requests, security obligations, impact assessments and regulator consultation as required by applicable law and the agreement.
For covered corporate processing, the processor will notify the controller of a personal data breach without undue delay and no later than 24 hours after becoming aware, in line with the agreed notification commitment. Available information should describe the incident, affected data, likely consequences and mitigation; further information may follow as the investigation progresses. The controller remains responsible for notifications it is legally required to make.
Retention, return and deletion
Covered personal data will be kept only for the agreed service duration and any legally required retention. At the end of the service, the processor will return or delete the data in accordance with the controller’s documented choice and the agreement, unless retention is required by law.
The parties should record practical export, backup and deletion arrangements, including any legally required records that remain after termination.
Records, assurance and agreement details
The processor will maintain relevant processing records and make information available to demonstrate compliance. Audits and inspections are subject to reasonable notice, the agreed process, confidentiality and protections for other customers’ information.
The DPA and its schedules should identify the parties, effective date, contacts, service description, security measures, authorised sub-processors, locations and transfer safeguards. Amendments must be recorded in writing. The service agreement governs applicable law and the relationship with other contractual terms, subject to mandatory data protection law.
For a completed agreement or a corporate privacy enquiry, contact hello@taptapgo.io. Do not send confidential customer datasets through the general enquiry form.