TapUpCard
Products Review Connect AI Pricing Guides Contact
Log in Get started
TapUpCard Legal

Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the agreement between TapUpCard and a business customer where TapUpCard processes personal data on that customer’s behalf.

Last updated: 6 September 2026

1. Parties and scope

This DPA applies where a TapUpCard business customer determines the purposes and means of processing personal data and TapUpCard processes that personal data on the customer’s behalf in providing the services.

For that processing, the customer is the Controller and TapUpCard is the Processor, unless applicable data protection law requires a different classification.

This DPA supplements TapUpCard’s Terms & Conditions or another written service agreement between the parties (the “Service Agreement”).

2. TapUpCard’s separate controller activities

TapUpCard also processes some information for its own purposes as an independent controller. This includes information required to operate its own customer relationship, such as account administration, billing, fraud prevention, legal compliance, support records and business communications.

Those controller activities are governed by the TapUpCard Privacy Policy and are not processing carried out on the customer’s behalf under this DPA.

3. Definitions and applicable law

“Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing” and “Personal Data Breach” have the meanings given to them by applicable data protection law.

“Data Protection Law” means the UK GDPR, the Data Protection Act 2018 and other applicable UK data protection legislation. Where another data protection regime applies to the parties, they will comply with its mandatory requirements to the extent applicable.

4. Processing on documented instructions

TapUpCard will process Customer Personal Data only on the customer’s documented instructions, including instructions contained in the Service Agreement, this DPA, the customer’s account settings and other written directions accepted by TapUpCard.

TapUpCard will not process Customer Personal Data for its own unrelated purposes while acting as Processor.

If TapUpCard is required by applicable law to process Customer Personal Data outside the customer’s instructions, TapUpCard will inform the customer before doing so unless the law prohibits that notification.

If TapUpCard reasonably believes an instruction infringes applicable data protection law, it may suspend the affected processing while the parties discuss a lawful alternative.

5. Customer responsibilities

The customer is responsible for:

  • having a valid lawful basis for the processing it instructs TapUpCard to perform;
  • providing required privacy information to Data Subjects;
  • ensuring its instructions comply with Data Protection Law;
  • ensuring Customer Personal Data supplied to TapUpCard is relevant, accurate and not excessive for the intended purpose;
  • responding to Data Subject requests and regulatory obligations for which it is responsible as Controller; and
  • using TapUpCard’s security, approval and automation settings appropriately.

6. Confidentiality

TapUpCard will ensure that people authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality and access the data only where reasonably necessary for their role.

7. Security

TapUpCard will implement appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the nature of the processing, available technology, implementation cost and the risks to individuals.

Measures may include, as appropriate:

  • encrypted transport connections for web and API traffic;
  • access controls and authentication for administrative and customer systems;
  • password hashing and secure credential handling;
  • logical separation of customer records and permission checks;
  • regular backups and restoration procedures;
  • security logging, monitoring and incident-response procedures;
  • software updates, vulnerability remediation and secure configuration practices; and
  • limiting access to people and providers who reasonably need it.

Security measures may evolve as technology, risks and the TapUpCard service change, provided the overall level of protection is not materially reduced.

8. Sub-processors

The customer gives TapUpCard general written authorisation to engage Sub-processors where reasonably required to provide the services.

Sub-processors may include providers of hosting and infrastructure, transactional email, AI model/API services, backup and storage, logging and security, and customer-support technology.

TapUpCard will impose data protection obligations on each Sub-processor that provide an equivalent level of protection for Customer Personal Data as required by applicable law.

TapUpCard remains responsible for the performance of its Sub-processors to the extent required by Data Protection Law.

Where required, TapUpCard will provide reasonable notice of a new Sub-processor so that the customer can raise a legitimate data protection objection. The parties will work in good faith to resolve any reasonable objection. If no reasonable solution is available, either party may terminate the affected service in accordance with the Service Agreement.

9. International transfers

TapUpCard will not make a restricted transfer of Customer Personal Data outside the United Kingdom unless the transfer is permitted under applicable Data Protection Law.

Where required, TapUpCard will rely on an applicable UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful transfer mechanism.

TapUpCard will require relevant Sub-processors to maintain appropriate transfer safeguards where legally required.

10. Data Subject requests

Taking into account the nature of the processing, TapUpCard will provide reasonable assistance to help the customer respond to requests by Data Subjects exercising their legal rights.

If TapUpCard receives a request relating primarily to Customer Personal Data processed on the customer’s behalf, TapUpCard will normally direct the requester to the customer or notify the customer, unless law requires TapUpCard to respond directly.

11. Personal Data Breaches

TapUpCard will notify the customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

Where reasonably available, the notice will include information about the nature of the breach, affected data, likely consequences and measures taken or proposed to address it.

TapUpCard will provide reasonable cooperation to help the customer meet its breach notification obligations. A breach notification is not an admission of fault or liability.

12. Assistance with compliance

Taking into account the nature of processing and the information reasonably available to TapUpCard, TapUpCard will provide reasonable assistance with:

  • security obligations;
  • Personal Data Breach assessment and notification;
  • data protection impact assessments where the service processing is relevant; and
  • consultation with a supervisory authority where legally required.

The customer remains responsible for determining whether a DPIA, consultation or other compliance measure is legally required for its use of the service.

13. Return and deletion

At the end of the services involving Customer Personal Data, and at the customer’s choice where technically and legally practicable, TapUpCard will delete or return Customer Personal Data and delete remaining copies, unless applicable law requires retention.

Deletion from backup systems may occur through normal backup rotation rather than immediately, provided retained backup data remains protected and is not restored for ordinary business use.

TapUpCard may retain information it processes independently as Controller in accordance with its Privacy Policy and legal obligations.

14. Information and audits

TapUpCard will make available information reasonably necessary to demonstrate compliance with the processor obligations addressed by this DPA.

Where that information is insufficient, the customer may request a reasonable audit concerning processing under this DPA. Audits must:

  • be conducted on reasonable prior written notice;
  • normally occur no more than once in any 12-month period unless a breach, regulator request or material compliance concern reasonably requires otherwise;
  • take place during normal business hours;
  • avoid unreasonable disruption to TapUpCard or other customers;
  • protect confidential information and the security of other customers; and
  • be limited to systems and records relevant to the customer’s processing.

The requesting customer will normally bear its audit costs unless the audit identifies a material breach of this DPA by TapUpCard.

15. Government and legal requests

If TapUpCard receives a legally binding request from a public authority for Customer Personal Data, TapUpCard will disclose only the information it is legally required to provide.

Where legally permitted, TapUpCard will notify the customer before disclosure.

16. Liability and precedence

The liability provisions and limitations in the Service Agreement apply to this DPA to the extent legally permitted.

If there is a conflict between this DPA and the Service Agreement specifically concerning the processing of Customer Personal Data, this DPA takes precedence for that conflict. Mandatory Data Protection Law takes precedence over both.

17. Duration

This DPA starts when the customer first uses a TapUpCard service in circumstances where TapUpCard acts as Processor and remains in effect while TapUpCard processes Customer Personal Data on the customer’s behalf.

Schedule 1 — Details of processing

Subject matter

Provision, operation, support and security of TapUpCard services where the customer supplies or connects personal data for processing on its behalf.

Duration

For the duration of the applicable service and for limited retention periods afterwards as required for deletion, backups, legal obligations, security or dispute resolution.

Nature and purpose

Receiving, hosting, storing, organising, retrieving, displaying, transmitting, analysing, generating requested outputs from, updating and deleting personal data as necessary to provide TapUpCard functionality.

Examples of services

  • TapUp Connect: hosting and displaying customer-configured digital profile information;
  • TapUp AI: receiving connected review information and customer settings, generating proposed responses, managing approval workflows and, where configured, carrying out supported automation; and
  • related support, security, troubleshooting and service administration performed on the customer’s behalf.

Categories of Data Subjects

  • the customer’s customers and reviewers;
  • the customer’s employees, contractors, representatives and profile contacts; and
  • other individuals whose information the customer lawfully submits to the service.

Types of Personal Data

  • names and public profile identifiers;
  • contact and business-profile information;
  • review text, ratings, review metadata and reply content;
  • digital-profile content selected by the customer;
  • technical identifiers, timestamps and service activity associated with the relevant processing; and
  • other personal data the customer chooses to submit through supported fields or connected services.

Special category and highly sensitive data

TapUpCard services are not designed for the intentional submission of special category data, criminal-offence data or highly sensitive personal information unless expressly agreed in writing. Customers should avoid submitting such information unless they have established an appropriate lawful basis and safeguards.

Controller rights and obligations

The customer retains control over the purposes of processing, its lawful basis, the data it submits, service configuration, retention decisions available through the service and instructions given to TapUpCard, subject to the Service Agreement and applicable law.

18. Contact

Questions about this DPA or processor arrangements can be sent to:

TapUpCard
2–14 Bury New Road
M8 8EL
United Kingdom

info@tapupcard.com

TapUpCard

NFC + QR products and AI tools that help businesses collect reviews, connect with customers and manage replies more easily.

Products
  • TapUp Review
  • TapUp Connect
  • TapUp AI
  • Pricing
Support
  • Guides
  • Contact Us
  • Affiliate Programme
Legal
  • Affiliate Terms
  • Privacy Policy
  • Cookie Policy
  • Refund & Cancellation Policy
  • Shipping & Delivery Policy
  • Data Processing Addendum (DPA)
Log in Create Account Dashboard
© 2026 TapUpCard. All rights reserved.