Skip to main content
Trust Center
GDPR & UK GDPR

GDPR Compliance.
Six rights. One workflow.

TappHQ processes personal data of EU and UK data subjects under the General Data Protection Regulation and UK GDPR. Every right has a self-serve path.

Data Subject Rights

Six rights, exercisable in one click

Sign in and visit /settings/data-requests or email dpo@tapphq.com.

Every request is answered within 30 days - the ceiling set by Art. 12(3), counted from the day we receive it. Erasure carries a 14-day cancellation window: you can withdraw the request at any point inside it, and deletion begins the day after it closes, so the erasure itself also finishes inside the same 30 days. Access and portability exports carry no cancellation window: a daily job picks them up and dispatches them automatically, with no step in between that waits on us.

Erasure is not absolute, and we will not tell you otherwise. A small set of records is retained after your account is deleted where the law requires it or where the record is the evidence that we handled your data correctly - security and audit trails, and financial records under their statutory retention period. Those records are kept for that purpose alone, and your identity is removed from them when the erasure runs: the row survives as evidence, the link to you does not. A few record types are an exception we have not closed yet - an invitation, a data-subject request, or an erasure job cannot exist without the identifier that says whose it was. Those keep an internal id, they are not used to contact or profile you, and the set only ever shrinks. Everything outside all of this is deleted or anonymised.

ART. 15

Right of access

Download a copy of all personal data we hold about you.

ART. 16

Right to rectification

Correct inaccurate or incomplete personal data.

ART. 17

Right to erasure

Delete your account and the personal data we hold, except records we must retain.

ART. 18

Right to restriction

Limit how we process your personal data.

ART. 20

Right to portability

Export your data in a machine-readable format.

ART. 21

Right to object

Object to AI-assisted processing or other lawful processing.

Compliance Posture

Six pillars of our GDPR program

Lawful basis, transfers, recordkeeping, breach response, and AI-specific safeguards - documented and audited.

Legal basis for processing

Legitimate interest (Art. 6(1)(f)) for product analytics, security telemetry, and operational efficiency. Consent (Art. 6(1)(a)) for marketing and AI features you opt into. We do not rely on Art. 22 automated decision-making - all AI write actions require explicit user approval.

Data Protection Officer

DPO contact: dpo@tapphq.com. Written inquiries may also be directed to our registered address via the footer contact link.

Cross-border transfers

TappHQ is based in the United States. EU/UK transfers are governed by the EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum (IDTA). Our DPA incorporates both by reference.

Record of Processing Activities

TappHQ maintains a ROPA per Art. 30 GDPR. Enterprise customers may request a redacted copy under NDA via compliance@tapphq.com.

Object to AI-assisted decisions

TappHQ does not make solely-automated decisions with legal or similarly significant effects. All AI-generated content and proposed actions are human-reviewable. Disable AI features any time at /settings/ai-security.

72-hour breach notification

TappHQ commits to notifying the supervisory authority and affected data subjects within 72 hours of becoming aware of a qualifying personal data breach (Art. 33-34). Incident response runbook audited as part of SOC 2.

DPO Contact

Need a DPA, ROPA excerpt, or DPIA support?

Email our DPO directly. Enterprise customers can request a redacted ROPA copy and DPIA assistance for your own processing activities.