// Legal
Data processing agreement
This Data Processing Agreement (DPA) forms part of the Terms of Service and applies when Tapat.link processes personal data on behalf of the customer as a data processor.
Last updated: September 1, 2026
1. Roles
The customer is the controller of personal data entered into Tapat.link. Tapat.link acts as processor and processes that data only on the customer's documented instructions.
2. Scope of processing
Processing covers hosting, storage, backup, support and the operation of features the customer uses. Categories of data include employee, customer and supplier contact and transaction data.
3. Confidentiality
Personnel with access to customer data are bound by confidentiality obligations and receive regular security training.
4. Security measures
Tapat.link maintains the technical and organisational measures described on our Security page, including encryption, access control and monitoring.
5. Sub-processors
We use a limited number of sub-processors, such as our hosting provider. We will notify customers before adding a new sub-processor, and customers may object on reasonable grounds.
6. Breach notification
We will notify the customer without undue delay after becoming aware of a personal data breach, and provide the information needed to meet regulatory obligations.
7. Return and deletion
At the end of the service, the customer may export their data. We delete remaining customer data within 30 days, except where retention is required by law.