Data Processing Agreement
Last updated 23 July 2026
Parties
This Data Processing Agreement (DPA) is made between Tap App Ltd, registered in England and Wales under company number 11666887, whose registered office is at Great Woodland Farm, Woodland Road, Lyminge, Folkestone, Kent CT18 8DW (Processor, we, us), and the customer identified in the applicable order or agreement with us (Controller, you). This DPA forms part of, and is governed by, the agreement between the parties for the supply of the Tapapp platform (the Principal Agreement). Where this DPA conflicts with the Principal Agreement on data protection matters, this DPA prevails.
1. Definitions
Terms used in this DPA have the meanings given in UK data protection law. UK GDPR means the retained EU General Data Protection Regulation as it forms part of the law of England and Wales, Scotland, and Northern Ireland. Data Protection Law means the UK GDPR, the Data Protection Act 2018, and any other applicable law on the processing of personal data. Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, and Supervisory Authority have the meanings given in the UK GDPR. Sub-processor means any third party engaged by us to process Personal Data under this DPA.
2. Roles of the parties
For the Personal Data processed under this DPA, you are the Controller and we are the Processor, acting on your instructions. You are responsible for ensuring you have a lawful basis for the processing and for the lawfulness of your instructions.
3. Scope and purpose of processing
We will process Personal Data only to provide and support the Tapapp platform under the Principal Agreement, and as set out in Annex 1. The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex 1.
4. Our obligations
- Process on instructions. Process Personal Data only on your documented instructions, including the instructions set out in this DPA and the Principal Agreement, unless required to do otherwise by law. If we are required by law to process beyond your instructions, we will inform you first unless the law prohibits this.
- Ensure that persons authorised to process the Personal Data are bound by a duty of confidentiality.
- Implement appropriate technical and organisational measures to protect the Personal Data, as described in Annex 2. We operate an information security management system aligned to ISO 27001.
- Sub-processors. Engage Sub-processors only in line with section 6.
- Data subject rights. Taking into account the nature of the processing, assist you by appropriate technical and organisational measures, so far as possible, to respond to requests from Data Subjects exercising their rights under Data Protection Law.
- Assist you in ensuring compliance with your obligations on security, breach notification, data protection impact assessments, and prior consultation with the Supervisory Authority, taking into account the nature of the processing and the information available to us.
- Breach notification. Notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting the Personal Data, and provide the information set out in section 7.
- Deletion or return. At the end of the provision of services, delete or return the Personal Data as set out in section 8.
- Make available to you the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as set out in section 9.
5. Your obligations
You will ensure your instructions for the processing of Personal Data comply with Data Protection Law, have a lawful basis for the processing and provide all required notices to Data Subjects, including any notice required for staff monitoring through the platform, and be responsible for the accuracy, quality, and legality of the Personal Data and the means by which you acquired it.
6. Sub-processors
You give us general authorisation to engage Sub-processors to process Personal Data, subject to this section. Our current Sub-processors are listed in Annex 3 and maintained in our published Sub-processor List. We will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA. We remain responsible for the performance of each Sub-processor. We will give you at least 30 days notice before adding or replacing a Sub-processor, by updating our published Sub-processor List and by email where you have subscribed to changes. If you have a reasonable objection on data protection grounds, you may raise it within that period and the parties will work in good faith to resolve it. If it cannot be resolved, you may terminate the affected service.
7. Personal data breach
If we become aware of a Personal Data Breach, our notification to you will, so far as possible: describe the nature of the breach, including the categories and approximate number of Data Subjects and records affected, describe the likely consequences, describe the measures taken or proposed to address the breach, and provide a contact point for more information. We will provide information in phases if it is not all available at once. We will not make any public statement about a breach affecting your Personal Data that identifies you without your prior agreement, unless required by law.
8. Deletion and return of data
You are responsible for exporting your data using the in-product tools before the Principal Agreement ends. On termination or expiry, at your choice we will delete the Personal Data or, on your written request made within 30 days of closure, return a copy of it to you, for which we may charge a reasonable fee. 30 days after closure we delete the Personal Data from the live platform, except account and billing records retained for up to 12 months after closure as described in our Data Retention Policy, and except where retention is required by law. Residual copies held in routine backups will be deleted in line with our backup cycle, as described in our Data Retention Policy. While in backup, such data remains protected under this DPA and is not actively processed.
9. Audit
We will make available the information necessary to demonstrate compliance with this DPA, including our ISO 27001 aligned ISMS documentation and, once awarded, our ISO 27001 certificate, and relevant policies. You may audit our compliance no more than once per year, on at least 30 days written notice, during business hours, and without disrupting our operations. Where an independent certification or report covers the matters you wish to audit, you agree to accept that report in place of an on-site audit where reasonable.
10. International transfers
Where processing under this DPA involves a transfer of Personal Data outside the United Kingdom, we will ensure an appropriate transfer mechanism is in place, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the UK Extension to the EU-US Data Privacy Framework, or adequacy regulations. The location of Sub-processors and the safeguards relied on are set out in Annex 3.
11. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement.
12. Term
This DPA takes effect on the effective date and continues for as long as we process Personal Data on your behalf under the Principal Agreement.
Annex 1. Details of processing
Subject matter: provision of the Tapapp workforce management platform. Duration: the term of the Principal Agreement, plus any retention period set out in our Data Retention Policy. Nature and purpose: hosting, storage, and processing of Personal Data to deliver scheduling, staff check-in, digital checklists, evidence capture, reporting, and related features. Types of Personal Data: identity and contact data of your administrators and staff (such as name, email, role), authentication data (such as login identifiers), operational data (such as schedules, check-in and check-out records, timestamps), location data associated with check-in where you enable it, photographs and evidence uploaded by your users, and content entered into forms and checklists. Categories of Data Subjects: your administrators and authorised users, your staff and field workers, and any individuals appearing in evidence or content you upload.
Annex 2. Technical and organisational measures
We maintain an information security management system aligned to ISO 27001. Measures include: role-based access control with individual user accounts and least-privilege principles, encryption of data in transit and at rest, regular backups with a defined retention cycle, application and error monitoring to detect and respond to faults and security events, measures to maintain availability and restore access after an incident, patching and review of components, confidentiality obligations and security awareness for staff and development partners, and data protection terms imposed on Sub-processors. Infrastructure is hosted on Amazon Web Services in the United Kingdom, Europe (London) eu-west-2 region, under the AWS shared responsibility model. The detailed and current measures are maintained within our ISMS documentation.
Annex 3. Sub-processors
The current list of Sub-processors, the services they provide, the data they process, and their location is maintained in our published Sub-processor List, which forms part of this Annex. At the effective date this includes:
Sub-processor | Service | Location |
Amazon Web Services | Hosting and infrastructure | United Kingdom, Europe (London) eu-west-2 |
Anthropic | AI form generation (Tracey) | USA, with appropriate safeguards |
Twilio SendGrid | Transactional email | USA, with appropriate safeguards |
Stripe | Subscription billing | USA and EU, with appropriate safeguards |
Sentry | Error and performance monitoring | EU data storage |
All-in-One App to Simplify Your Business Operations
Whether you manage field staff, compliance, or customer jobs, Tapapp keeps everything in one place.