Data Processing Agreement (DPA)

This DPA is entered into Effective Date, between Tap Tap Go Ltd, with its registered office at 71-75 Shelton Street, Covent Garden, London, UK, and ICO Registration Number: ZB667237, herein referred to as the “Data Processor,” and other signing contracting party, herein referred to as the “Client” acting as the DATA CONTROLLER. Collectively, they are known as the “Parties.”

  1. Definitions: The agreement defines terms in alignment with GDPR, including DATA CONTROLLER, DATA PROCESSOR, PERSONAL DATA, PROCESSING, PERSONAL DATA BREACH, and SUB-PROCESSOR, clarifying the roles and compliance responsibilities.
  2. Nature and Purpose of Processing: The DATA PROCESSOR agrees to handle PERSONAL DATA solely for delivering services related to digital business cards via taptapgo.io, and Tap Tap Go mobile applications, respecting confidentiality and the agreement’s terms.
  3. Rights and Obligations of the DATA CONTROLLER: The DATA CONTROLLER governs the processing purposes and means, ensuring legality, accuracy, and adherence to applicable laws. It’s responsible for informing and managing DATA SUBJECTS’ rights and inquiries in compliance with the law.
  4. Obligations of the DATA PROCESSOR: The DATA PROCESSOR will process PERSONAL DATA per the DATA CONTROLLER’s instructions and legal requirements, safeguarding the data’s security and confidentiality. This includes technical and organizational measures for data protection and facilitating inspections.
  5. Assistance to the DATA CONTROLLER: The DATA PROCESSOR supports the DATA CONTROLLER in managing DATA SUBJECT requests, addressing PERSONAL DATA BREACHES, and complying with GDPR obligations like data protection impact assessments.
  6. PERSONAL DATA Breaches and Reporting: The DATA PROCESSOR must notify the DATA CONTROLLER of any PERSONAL DATA BREACH immediately, no later than 24 hours after awareness, aiding in breach management and communication.
  7. Retention and Liquidation of PERSONAL DATA: PERSONAL DATA is kept only as needed for service delivery or legal obligations, with procedures for returning, deleting, or destroying the data upon the DATA CONTROLLER’s request or agreement termination.
  8. Record Keeping: Maintaining records of processing activities, the DATA PROCESSOR assists the DATA CONTROLLER in data subject inquiries and complies with supervisory authority requests.
  9. Confidentiality: PERSONAL DATA access is limited to authorized individuals committed to confidentiality, ensuring data protection.
  10. Sub-processors: The DATA PROCESSOR may engage Tap Tap Go Ltd. entities as SUB-PROCESSORS, ensuring they adhere to this DPA and GDPR, with the DATA CONTROLLER informed of any changes.
  11. Monitoring and Audit: The DATA CONTROLLER may audit the DATA PROCESSOR’s compliance with the DPA and applicable laws, given reasonable notice.
  12. Data Transfer: PERSONAL DATA transfers are restricted as per the agreement, with specified processing and storage locations unless otherwise directed by the DATA CONTROLLER.
  13. Notices:  Notices and communication should be directed to the identified contacts within the agreement for data privacy and security matters.
  14. Changes to Applicable Law: The Parties will amend the DPA as necessary to maintain compliance with data protection laws, implementing required changes to processing activities.
  15. Final Provisions: This DPA represents the complete agreement regarding data processing, modifiable in writing and governed by the law of United Kingdom.
  16. Annexes: The following Annexes form an integral part of this Agreement:
    • Annex 1 – Tap Tap Go Ltd.
    • Annex 2 – Service Description
    • Annex 3 – Technical and Organizational Measures

Annex 1 – Tap Tap Go Ltd.

Tap Tap Go Ltd. operates as a cohesive entity, with all members driven by a unified goal, mission, and vision. They serve as strategic and technological partners, adhering to uniform rules, regulations, and measures for information security, data protection, and privacy. Their collective expertise is pivotal in the service provisioning lifecycle to clients. Members of the Tap Tap Go Ltd, with a centralized operation to ensure seamless service delivery and data security, are listed as follows:

  • Tap Tap Go Ltd, 71-75 Shelton Street, Covent Garden, London, UK

All products and services are exclusively provided by Tap Tap Go Ltd. members, with data hosted and securely stored in London, on Amazon Web Service Inc., emphasizing stringent privacy and security measures across all operations.

Privacy and security within Tap Tap Go Ltd.:

  • Access to data is strictly controlled, adhering to the principle of least privilege, with all personnel committed to confidentiality through signed NDAs and stringent data protection protocols.
  • AWS hosts all data, prohibiting transfers outside the cloud environment to ensure data integrity and security, aligning with client requests and data protection regulations.
  • Encryption protocols are in place for all data access, with TLS connections for platform interaction and VPN for internal network access, adhering to strict access controls and monitoring.

Annex 2 – Service Description

Tap Tap Go Ltd offers innovative digital networking tools, allowing clients to share their professional details through a modern and efficient platform. Services include the creation and personalization of digital profiles through web-based platforms and mobile applications, culminating in a digital business card that encapsulates professional and personal contact information, social profiles, and custom links. These digital cards can be shared through NFC smart cards, accessories, or QR codes, enhancing connectivity in the professional sphere.

Annex 3 – Technical and Organizational Measures

Tap Tap Go Ltd commits to the highest standards of information security and personal data protection by implementing comprehensive technical and organizational measures. These measures encompass information security policies, asset management, access control, physical security, and continuous monitoring, all designed to safeguard data integrity, confidentiality, and availability.