Data Processing Agreement
Version 1.4 - Effective August 11, 2026
Effective Date: 2026-08-11 Last Updated: 2026-08-11
This Data Processing Agreement provides the structural framework for data processing obligations between Tapp Networks LLC and organizations using the Platform. Organizations requiring a signed DPA or custom terms should contact legal@tapphq.com.
1. Definitions
For the purposes of this Data Processing Agreement ("DPA"), the following terms have the meanings ascribed below, consistent with the definitions in Article 4 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"):
- "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject"), as defined in GDPR Article 4(1).
- "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction, as defined in GDPR Article 4(2).
- "Data Controller" or "Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data, as defined in GDPR Article 4(7).
- "Data Processor" or "Processor" means a natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Controller, as defined in GDPR Article 4(8).
- "Data Subject" means an identified or identifiable natural person whose Personal Data is processed, as defined in GDPR Article 4(1).
- "Subprocessor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Company" means Tapp Networks LLC, acting as Data Processor.
- "Organization" or "Customer" means the entity that has entered into a Terms of Service agreement with the Company, acting as Data Controller with respect to its organizational data.
2. Scope and Roles
2.1 Data Processor Role
The Company processes Organization Content Data (including documents, agent configurations, integration data, AI inputs and outputs, and other content uploaded by the Organization) as Data Processor on behalf of the Organization, which acts as Data Controller. The Company processes this data solely for the purpose of providing the Platform services as described in the Terms of Service.
2.2 Data Controller Role
The Company acts as Data Controller for operational and account data, including: account registration information (name, email address), billing data, aggregated usage analytics, and error monitoring data. The Company determines the purposes and means of processing this data independently.
3. Processing Instructions
The Company shall process Personal Data only on the documented instructions of the Controller, unless required to do so by applicable law. The Organization's documented instructions are: to process Personal Data as necessary to provide the Platform services described in the Terms of Service, including agent execution, integration management, monitoring, and all features available under the Organization's subscription plan. Any processing outside the scope of these instructions requires prior written agreement.
4. Subprocessing
4.1 Authorized Subprocessors
The Company engages subprocessors to provide the Platform. The current list of authorized subprocessors is available at tapphq.com/legal/subprocessors and includes each subprocessor's identity, purpose, location, and applicable data transfer mechanism.
4.2 New Subprocessors
The Company will provide the Controller with reasonable advance notice of the engagement of any new subprocessor. The Controller may object to a new subprocessor by notifying the Company in writing within thirty (30) days of receiving notice. If the Controller's objection is not resolved to the Controller's reasonable satisfaction, the Controller may terminate the affected services by providing written notice to the Company.
4.3 Subprocessor Obligations
The Company shall ensure that each subprocessor is bound by data protection obligations no less protective than those set out in this DPA. The Company shall remain fully liable to the Controller for the performance of each subprocessor's obligations.
5. Data Security
The Company shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include, but are not limited to:
- Encryption in transit: All data transmitted between users and the Platform is encrypted using TLS (Transport Layer Security).
- Authentication and access controls: User authentication is provided by Supabase Auth (SOC 2 Type II certified). The Company issues JSON Web Tokens with limited identity claims and resolves authorization decisions server-side against database-resident role and permission records. Multi-factor authentication is available on every subscription plan and may be enforced organization-wide on Pro and Enterprise plans.
- Tenant isolation: Database-enforced tenant isolation using PostgreSQL Row-Level Security (RLS) policies. Each organization's data is isolated at the database level, preventing cross-organization data access.
- Encrypted credential storage: Integration credentials and sensitive configuration data are encrypted at rest using AES-256-GCM encryption.
- Audit logging: All significant data operations are logged to an append-only, SHA-256 hash-chained audit log that provides tamper-evident records of data access and modification.
- Regular security reviews: The Company conducts periodic reviews of its security practices and infrastructure.
6. Data Subject Requests
The Company shall assist the Controller in responding to requests from Data Subjects exercising their rights under applicable data protection law (including rights of access, rectification, erasure, restriction, portability, and objection under GDPR Articles 15-22).
Users may submit Data Subject requests through: (a) the in-app privacy settings at Settings → Privacy; or (b) email to privacy@tapphq.com. The Company will forward any Data Subject request it receives directly to the relevant Controller and will not respond to the Data Subject directly except as instructed by the Controller or required by law.
7. Data Breach Notification
In the event of a Personal Data breach affecting the Controller's data, the Company shall:
- Notify the Controller without undue delay, and in any event within seventy-two (72) hours of becoming aware of the breach, where required by GDPR Article 33.
- Provide the Controller with sufficient information to enable the Controller to fulfill its own breach notification obligations, including: (a) the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences of the breach; and (c) the measures taken or proposed to address the breach and mitigate its effects.
- Cooperate with the Controller in investigating and remediating the breach.
8. International Data Transfers
All Personal Data processed by the Company is processed in the United States. The Platform's primary infrastructure providers are US-based: Vercel (hosting), Railway (execution), Supabase (authentication, database, file storage), Anthropic (AI processing), Stripe (payments), and Resend (email delivery). The Supabase Data Processing Addendum is available at https://supabase.com/legal/dpa and applies as a sub-processor agreement; it is incorporated by reference into this DPA.
For transfers of Personal Data from the European Union, European Economic Area, or United Kingdom to the United States, the following transfer mechanisms apply:
- EU-U.S. Data Privacy Framework: Where the receiving subprocessor is certified under the EU-U.S. Data Privacy Framework (and the UK Extension and/or Swiss-U.S. Data Privacy Framework where applicable), the DPF serves as the primary transfer mechanism.
- Standard Contractual Clauses: Where DPF certification is not available, transfers are governed by the EU Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), Module 2 (Controller to Processor) and Module 3 (Processor to Sub-processor), as applicable.
- UK International Data Transfer Addendum: For transfers from the United Kingdom, the UK International Data Transfer Addendum to the EU SCCs (issued by the UK Information Commissioner's Office) is incorporated where required.
The specific transfer mechanism applicable to each subprocessor is documented in the Subprocessor List at tapphq.com/legal/subprocessors.
9. Data Return and Deletion
Upon termination of the Terms of Service for any reason, the Company shall delete all Organization Content Data immediately, unless: (a) retention is required by applicable law or regulation; or (b) the data is contained in encrypted backup systems that are subject to automatic rotation and deletion on a defined schedule. The Controller may request export of its data prior to termination through the Platform's data export features or by contacting the Company.
10. Audit Rights
The Controller may request evidence of the Company's compliance with this DPA. The Company shall make available to the Controller, upon reasonable request, relevant information demonstrating compliance, including: security certifications, third-party audit reports, and documentation of technical and organizational measures.
On-site audits may be conducted upon thirty (30) calendar days' prior written notice to the Company, during normal business hours, and subject to reasonable confidentiality obligations. The Controller shall bear the costs of any on-site audit. Audits shall not unreasonably interfere with the Company's business operations.
11. Liability
The liability of each party under this DPA is subject to the limitations of liability set forth in the Terms of Service. Nothing in this DPA shall limit either party's liability for breaches of its data protection obligations to the extent such limitation is prohibited by applicable law.
12. Standard Contractual Clauses
The EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated into this DPA by reference. Module 2 (Controller to Processor) applies to transfers of Personal Data from the Controller to the Company. Module 3 (Processor to Sub-processor) applies to transfers from the Company to its subprocessors.
For the purposes of the Standard Contractual Clauses:
- The "data exporter" is the Organization (Controller).
- The "data importer" is Tapp Networks LLC (Processor).
- Clause 7 (Docking clause): Approved - additional data exporters may accede to the SCCs.
- Clause 9(a) (Subprocessor authorization): Option 2 - General written authorization, with the list maintained at tapphq.com/legal/subprocessors.
- Clause 13 (Supervision): The supervisory authority of the EU Member State in which the data exporter is established, or where the data exporter is not established in the EU, the supervisory authority designated by the data exporter.
- Clause 17 (Governing law): The law of Ireland.
- Clause 18 (Choice of forum): The courts of Ireland.
The UK International Data Transfer Addendum to the EU Standard Contractual Clauses (issued by the UK Information Commissioner under s.119A(1) Data Protection Act 2018) is incorporated for transfers of Personal Data from the United Kingdom.
13. Contact
For questions regarding this DPA or to request a signed copy, please contact:
- Privacy inquiries: privacy@tapphq.com
- Legal inquiries: legal@tapphq.com
Tapp Networks LLC