These Data Processing Terms ("DPA") form part of the agreement between Taprs, an Ontario-based business operated by its sole proprietor ("Taprs") and the business subscribing to Taprs ("Customer") where Taprs processes personal information on behalf of Customer.
Nothing in this DPA permits either party to contract out of mandatory privacy responsibilities.
1. Definitions
"Applicable Privacy Law" means privacy and data-protection legislation applicable to the processing covered by this DPA, including PIPEDA where applicable.
"Customer Personal Information" means personal information Taprs processes on Customer's behalf in providing the Services.
"Processing" includes collecting, using, accessing, storing, transmitting, organizing, modifying, deleting, disclosing, or otherwise handling information.
"Security Incident" means unauthorized access, disclosure, use, loss, or material compromise of Customer Personal Information under Taprs' custody or control.
"Subprocessor" means a third-party provider used by Taprs to process Customer Personal Information in support of the Services.
2. Roles
Customer generally determines why Customer Personal Information is provided to or processed through Taprs.
Taprs processes Customer Personal Information to provide the Services and according to:
- Customer's lawful instructions;
- the parties' agreement;
- this DPA; and
- applicable law.
Nothing prevents Taprs from processing information for an independent lawful purpose where permitted by applicable law.
3. Customer Instructions
Customer instructs Taprs to process Customer Personal Information as reasonably necessary to:
- operate Taprs Services;
- operate dashboards;
- operate NFC functionality;
- produce NFC interaction analytics;
- administer subscriptions;
- provide support;
- maintain security;
- troubleshoot;
- prevent abuse; and
- provide functionality authorized by Customer.
Future integrations or AI functionality may involve additional processing after applicable disclosures and safeguards are implemented.
Taprs is not required to follow an instruction Taprs reasonably believes is unlawful.
4. Customer Responsibility for Lawful Collection
Customer represents that:
- Customer has lawful authority to provide Customer Personal Information to Taprs;
- Customer has provided legally required notices;
- required consent has been obtained;
- Customer's instructions are lawful; and
- the information was lawfully collected.
Customer remains responsible for its independent customer relationships and collection practices.
5. Purpose Limitation
Taprs will use Customer Personal Information only as reasonably necessary to:
- provide;
- maintain;
- administer;
- troubleshoot;
- secure; and
- support
the Services, comply with lawful instructions, or comply with applicable law.
6. Data Minimization
Customer should not provide personal information that is unnecessary for the Services.
Customer must not intentionally provide highly sensitive personal information unless Taprs has expressly agreed to the processing and appropriate legal and security requirements have been addressed.
7. Confidentiality and Access
Administrative access to Taprs is currently limited to the Taprs owner/operator.
If Taprs later gives employees, contractors, or other personnel access to Customer Personal Information, Taprs will seek to restrict access to persons with a legitimate need and appropriate confidentiality obligations.
8. Safeguards
Taprs will use safeguards reasonably appropriate to:
- the sensitivity of information;
- Taprs' size and operations;
- reasonably foreseeable risks; and
- applicable legal obligations.
Taprs currently uses administrative authentication and session controls.
Customer dashboard access currently relies on private tokenized URLs.
Taprs does not represent that it currently possesses:
- SOC 2 certification;
- ISO 27001 certification;
- a separate proprietary backup system;
- a formally certified security-management system; or
- another unverified security certification.
No security system can guarantee absolute protection.
9. Customer Access Security
Customer is responsible for:
- safeguarding private dashboard links;
- controlling who receives dashboard links;
- maintaining security of Customer devices;
- notifying Taprs of suspected unauthorized access; and
- avoiding public disclosure of private dashboard links.
10. Subprocessors
Customer authorizes Taprs to use reasonably necessary Subprocessors.
Current primary Subprocessors include:
Cloudflare
Used for website, Worker, application infrastructure, KV-related storage, and related technical services.
Stripe
Used for payment processing and payment-related services.
Taprs may add subprocessors for:
- email;
- communications;
- hosting;
- authentication;
- analytics;
- security;
- artificial intelligence;
- monitoring;
- customer support;
- databases; and
- other operational requirements.
Taprs will update relevant disclosures when a material new provider begins processing Customer Personal Information.
11. Cross-Border Processing
Cloudflare, Stripe, and future providers may process information outside Canada.
Accordingly, Customer Personal Information may be processed in:
- Canada;
- the United States; or
- other jurisdictions in which applicable service providers operate.
Information may therefore become subject to applicable foreign laws and lawful governmental access.
Taprs does not guarantee Canadian-only processing.
12. Security Incidents
Taprs will take reasonable steps appropriate to its operations to:
- investigate;
- contain;
- document; and
- respond
to confirmed Security Incidents involving Customer Personal Information.
Where Customer has applicable notification obligations and Taprs becomes aware of a qualifying Security Incident affecting Customer Personal Information, Taprs will provide notice without unreasonable delay where required by applicable law or contract.
Available information may include:
- nature of the incident;
- affected information;
- investigation status;
- mitigation efforts; and
- reasonably recommended actions.
Information may be provided in stages as an investigation continues.
Notification is not an admission of fault or liability.
13. Breach Records
Taprs will maintain records of privacy breaches where required by applicable law.
Customer remains responsible for its own independent statutory obligations.
14. Privacy Requests
Where Customer receives a lawful request regarding Customer Personal Information processed through Taprs, Taprs will provide commercially reasonable assistance where:
- Customer reasonably requires Taprs' assistance;
- the information exists within Taprs systems;
- the request is legally valid; and
- assistance is required by applicable law or contract.
Customer remains primarily responsible for responding where Customer controls the relevant relationship.
15. Regulatory Cooperation
Taprs and Customer will reasonably cooperate concerning lawful privacy-regulatory inquiries relating to Customer Personal Information.
Neither party is required to waive legal privilege or disclose information it is prohibited from disclosing.
16. Retention
Customer Personal Information relating to an active customer may be retained while the customer relationship remains active.
After cancellation or termination, Taprs generally intends to retain Customer Personal Information for up to 24 months, unless longer retention is reasonably necessary for:
- legal compliance;
- accounting;
- fraud prevention;
- security;
- dispute resolution;
- enforcement of agreements; or
- another legitimate purpose permitted by law.
Cancellation alone does not automatically cause immediate deletion.
17. Return and Deletion
Following expiration of the applicable retention period, Taprs will delete, destroy, or appropriately de-identify Customer Personal Information where:
- it is no longer reasonably necessary;
- retention is not legally required; and
- continued retention is not otherwise legally permitted.
Taprs does not promise instantaneous deletion from every technical system.
18. Backups
Taprs does not currently knowingly operate a separate proprietary backup system.
Third-party infrastructure providers may maintain technical redundancy, backups, or recovery systems according to their own services and policies.
Taprs will not represent that particular backup or recovery guarantees exist unless confirmed.
19. Artificial Intelligence
Taprs uses third-party AI service providers, including OpenAI where configured, to support features such as review-response assistance and Pro SEO recommendations.
Depending on the feature invoked, information sent for processing may include review text and rating, business name, target SEO keyword, bounded evidence from public website pages, and related technical findings.
Taprs seeks to limit AI-provider processing to the information reasonably necessary to provide the requested feature and to maintain appropriate provider, retention, contractual, security, and privacy reviews.
Taprs will not intentionally transmit sensitive personal information to an AI provider unless such processing is authorized, lawful, and appropriately protected.
20. Google Business Profile
Taprs supports Google Business Profile connection functionality through Google APIs and/or third-party integration providers where configured and authorized by the Customer.
Google and any integration provider remain independent third parties and control their own permissions, availability, retention, and platform behavior.
21. Documentation
Taprs will maintain privacy and security documentation reasonably appropriate to the nature and scale of its operations.
Taprs will not represent that it possesses enterprise security certifications or audit reports that it does not actually possess.
22. Audits and Information Requests
Where reasonably required for Customer to assess compliance with this DPA or applicable privacy law, Taprs will provide relevant documentation reasonably available to it.
Any additional review or audit must:
- be reasonably scoped;
- protect Taprs confidential information;
- protect information relating to other customers;
- avoid unreasonable business disruption;
- respect security restrictions; and
- ordinarily be conducted at Customer's cost unless otherwise required by law or resulting from material Taprs non-compliance.
23. Government Requests
Taprs may disclose Customer Personal Information where legally required by:
- court order;
- legal process;
- regulatory requirement;
- governmental request; or
- law-enforcement demand.
Where legally permitted and reasonably appropriate, Taprs may notify Customer.
24. Responsibility Allocation
Customer remains responsible for:
- lawfulness of Customer's data collection;
- Customer notices;
- Customer consent;
- Customer instructions;
- Customer review solicitation;
- Customer use of personal information; and
- Customer compliance with applicable privacy law.
Taprs remains responsible for obligations applicable directly to Taprs.
Nothing in this DPA transfers or waives statutory responsibilities that cannot legally be transferred or waived.
25. Liability
Liability under this DPA is subject to the limitation-of-liability provisions in the Taprs Terms of Service to the maximum extent permitted by applicable law.
Nothing limits liability that cannot legally be limited.
26. Term
This DPA applies for as long as Taprs processes Customer Personal Information in connection with the parties' relationship.
Confidentiality, incident, deletion, legal, and other provisions that by their nature must continue will survive termination as necessary.
27. Governing Law
This DPA is governed by the laws of Ontario and the applicable federal laws of Canada, subject to mandatory privacy law.
28. Contact
Privacy and data-processing requests may be directed to:
Privacy Officer, Taprs
Ontario, Canada
admin@taprs.ca