GDPR

Last updated 07/13/2026

Privacy by design

Tapify is based in the Netherlands and is committed to meeting its obligations under the General Data Protection Regulation (GDPR). We build privacy and security into our products and aim to collect only the personal data needed to provide, protect, and improve Tapify.

This page summarizes how GDPR applies to Tapify. Our Privacy Policy explains in more detail what data we collect, why we use it, who we share it with, and how long we keep it.

How GDPR applies to Tapify

Our role depends on how Tapify is being used:

  • When we decide why and how personal data is used for our website, accounts, billing, shop, or support, Tapify acts as the data controller.
  • When a business customer uses Tapify to manage team members, profiles, or contacts, that customer generally acts as the data controller and Tapify acts as the data processor. In that role, we process personal data on the customer's documented instructions and under the applicable agreement.

If you use Tapify through your employer or another organization, that organization may be responsible for answering questions about how it uses your personal data. We support our customers in responding to data-protection requests where required.

How we protect personal data

We use practical and organizational measures to protect personal data and support GDPR requirements. These include:

  • limiting collection to data we need for a clear purpose;
  • explaining how personal data is used;
  • using access controls, encryption, monitoring, and other security measures;
  • limiting internal access to people who need it to provide or support the service;
  • working with service providers under appropriate data-protection terms; and
  • retaining personal data only for as long as it is needed or legally required.

No online service can guarantee absolute security. We review our safeguards and update them as our products, providers, and legal obligations change.

Your GDPR rights

Depending on the circumstances, GDPR gives you the right to:

  • be informed about how your personal data is used;
  • access the personal data held about you;
  • correct inaccurate or incomplete personal data;
  • request deletion of personal data in certain circumstances;
  • restrict how personal data is processed in certain circumstances;
  • receive certain personal data in a portable, machine-readable format;
  • object to certain uses of your personal data; and
  • not be subject to certain decisions based only on automated processing.

These rights are not absolute and may depend on the reason we process the data or on other legal requirements. We may ask you to verify your identity before completing a request. We respond without undue delay and generally within one month of receiving a valid request.

Account deletion and retention

When you delete your Tapify account, your personal data is removed from our active systems immediately. An encrypted copy may remain in Supabase backups for up to seven days, after which it is removed through the backup lifecycle. These backups are used for disaster recovery and are not part of normal product access.

Some records, such as invoices and transaction records, may need to be retained for longer when required by tax, accounting, or other legal obligations. Our Privacy Policy provides more detail.

International data transfers

We primarily store and process personal data in the European Union. Some service providers may process data outside the European Economic Area. When that happens, we use appropriate safeguards where required, such as the European Commission's Standard Contractual Clauses or another legally recognized transfer mechanism.

Contact us

For privacy questions or to exercise your rights, email support@tapify.app or write to:
Tapify
Binnenhof 7, 7642GW Wierden, The Netherlands