SOC 2 CertifiedGDPR CompliantISO 27001WCAG AAA
24/7 Enterprise SupportLog In
GDPR Compliant

Data Processing Agreement

Comprehensive Data Processing Agreement (DPA) governing the handling of personal data within the TapsIM encrypted messaging platform, ensuring full GDPR compliance and privacy protection.

Agreement Overview

Version & Status
v3.2 - Active
Effective Date
December 1, 2024
Last Updated
November 15, 2024
Primary Jurisdiction
European Union (GDPR)
Available Languages
EnglishGermanFrenchSpanish

Compliance Frameworks

GDPR Compliant
CCPA Compliant
UK GDPR Compliant
Swiss DPA Compliant
Privacy by Design

This DPA reflects our commitment to privacy by design principles, ensuring data protection is built into every aspect of our platform.

Data Processing Categories

Detailed breakdown of personal data categories processed, purposes, and retention periods

Account Information

Basic user account data required for service operation

GDPR Compliant

Data Types Processed

  • Username/Display name
  • Email address (encrypted)
  • Account creation timestamp
  • Last activity timestamp
  • Account preferences and settings
Processing Purpose

User authentication, account management, service provision

Legal Basis
Contract performance (GDPR Article 6.1(b))
Retention Period
Account lifetime + 30 days after deletion
Security Measures
End-to-end encryption, access controls, audit logging, automatic deletion

Authentication Data

Technical data necessary for secure user authentication

GDPR Compliant

Data Types Processed

  • Cryptographic public keys
  • Device fingerprints (hashed)
  • Authentication tokens (temporary)
  • Multi-factor authentication settings
  • Login attempt logs (IP addresses hashed)
Processing Purpose

Security, fraud prevention, access control

Legal Basis
Legitimate interest (GDPR Article 6.1(f)) - Security
Retention Period
90 days for logs, permanent for cryptographic keys
Security Measures
End-to-end encryption, access controls, audit logging, automatic deletion

Message Metadata

Technical metadata required for message routing (content is encrypted)

GDPR Compliant

Data Types Processed

  • Message routing information
  • Timestamp (encrypted)
  • Message size (encrypted)
  • Delivery status indicators
  • Federation server identifiers
Processing Purpose

Message delivery, system operation, federation routing

Legal Basis
Contract performance (GDPR Article 6.1(b))
Retention Period
30 days maximum (deleted upon delivery confirmation)
Security Measures
End-to-end encryption, access controls, audit logging, automatic deletion

Technical Operations Data

System performance and operational data for platform maintenance

GDPR Compliant

Data Types Processed

  • Server performance metrics
  • System health indicators
  • Error logs (anonymized)
  • P9 observability data
  • Resource utilization statistics
Processing Purpose

System maintenance, performance optimization, security monitoring

Legal Basis
Legitimate interest (GDPR Article 6.1(f)) - Service provision
Retention Period
12 months (anonymized after 90 days)
Security Measures
End-to-end encryption, access controls, audit logging, automatic deletion

Processing Activities

Detailed description of data processing activities and security measures implemented

1

Message Routing & Delivery

Routing encrypted messages between users and federation servers

Data Processed

Message metadata, routing information, delivery confirmations

Processing Type

Automated processing

Third Parties

Federation partner servers (under equivalent DPAs)

Security Measures

End-to-end encryption (Signal Protocol)
Zero-knowledge architecture
Metadata minimization
Automatic deletion upon delivery
2

User Authentication & Authorization

Verifying user identity and managing access permissions

Data Processed

Authentication credentials, device information, access logs

Processing Type

Automated with manual security review triggers

Third Parties

None (all processing internal)

Security Measures

Multi-factor authentication
Cryptographic key management
Rate limiting and fraud detection
Encrypted credential storage
3

System Monitoring & Operations

Maintaining system health and performance monitoring

Data Processed

System metrics, performance data, anonymized usage statistics

Processing Type

Automated processing and aggregation

Third Parties

Cloud infrastructure providers (under processor agreements)

Security Measures

Data anonymization techniques
Access controls and audit logs
Encrypted data transmission
Regular security assessments
4

Legal Compliance & Security

Meeting legal obligations and maintaining platform security

Data Processed

Audit logs, security incident data, compliance reports

Processing Type

Automated with manual review for incidents

Third Parties

Regulatory authorities (when legally required)

Security Measures

Audit trail maintenance
Incident response procedures
Data breach notification protocols
Regular compliance assessments

Data Subject Rights

Your comprehensive privacy rights under GDPR and how to exercise them

Right of Access (Article 15)

Obtain confirmation of data processing and access to personal data

Within 30 days of request

Implementation

Self-service data export tool in user settings

Limitations

Identity verification required; technical limitations for encrypted data

Right to Rectification (Article 16)

Correct inaccurate or incomplete personal data

Immediate for user-editable data, up to 30 days for other data

Implementation

User profile editing tools, support ticket system

Limitations

Technical constraints on encrypted data modification

Right to Erasure (Article 17)

Request deletion of personal data under specific circumstances

Immediate account deactivation, complete deletion within 30 days

Implementation

Account deletion feature with complete data removal

Limitations

Legal retention requirements, backup deletion timelines

Right to Restrict Processing (Article 18)

Limit processing under specific circumstances

Within 72 hours of request

Implementation

Account suspension feature, data processing flags

Limitations

Essential processing for security may continue

Right to Data Portability (Article 20)

Receive personal data in structured, machine-readable format

Within 30 days of request

Implementation

Data export tools providing JSON/XML format

Limitations

Only applies to user-provided data, not derived data

Right to Object (Article 21)

Object to processing based on legitimate interests or direct marketing

Immediate for marketing, up to 30 days for other processing

Implementation

Opt-out mechanisms, communication preferences

Limitations

Overriding legitimate interests for security and fraud prevention

International Data Transfers

Safeguards and legal mechanisms for cross-border data transfers

European Economic Area (EEA)

Primary data processing and storage
Intra-EEA

Transfer Mechanism

Intra-EEA transfer (no additional safeguards required)

Data Types

All personal data categories

Safeguards

GDPR compliance, equivalent protection

United Kingdom

Local data processing for UK federation servers
UK

Transfer Mechanism

UK GDPR Adequacy Decision

Data Types

Account and metadata for UK users

Safeguards

UK GDPR compliance, equivalent protection standards

Switzerland

Local data processing for Swiss federation servers
Swiss

Transfer Mechanism

Swiss DPA compliance and adequacy framework

Data Types

Account and metadata for Swiss users

Safeguards

Swiss Federal DPA compliance, FDPIC oversight

United States

Cloud infrastructure services (anonymized data only)
Standard

Transfer Mechanism

Standard Contractual Clauses (SCCs) + additional safeguards

Data Types

Limited technical operations data only

Safeguards

EU SCCs, encryption in transit and at rest, access controls

Subprocessors & Partners

Third-party service providers with access to personal data under strict contractual obligations

AWS Europe (Amazon Web Services)

European Union (Dublin, Frankfurt)
Active DPA
Services
Cloud infrastructure, data storage
Data Access
Infrastructure level only (encrypted data)
Agreement
AWS Data Processing Agreement (DPA)
Certifications
ISO 27001SOC 2 Type IICSA STAR

Cloudflare (European data centers)

European Union (multiple locations)
Active DPA
Services
Content delivery, DDoS protection
Data Access
Network level only (encrypted traffic)
Agreement
Cloudflare Data Processing Agreement
Certifications
ISO 27001SOC 2 Type IIPCI DSS

Hetzner Online GmbH

Germany (Nuremberg, Falkenstein)
Active DPA
Services
Dedicated servers, cloud infrastructure
Data Access
Infrastructure level only (encrypted data)
Agreement
Hetzner Data Processing Agreement (DPA)
Certifications
ISO 27001ISO 14001PCI DSS

Our Privacy Commitments

Core GDPR principles and our implementation approach for comprehensive data protection

Data Minimization

Process only data necessary for specified purposes

Regular data audits and cleanup procedures
Automated data retention policy enforcement
Purpose limitation controls in system design
Minimal data collection by default

Purpose Limitation

Use personal data only for specified, explicit, and legitimate purposes

Clear purpose documentation for all processing activities
Technical controls preventing unauthorized data use
Staff training on purpose limitation principles
Regular compliance monitoring and auditing

Storage Limitation

Retain personal data only as long as necessary

Automated data retention policies
Regular deletion of expired data
User-controlled data retention preferences
Clear retention schedules for all data categories

Security of Processing

Implement appropriate technical and organizational security measures

End-to-end encryption for all user communications
Zero-knowledge architecture design
Regular security audits and penetration testing
ISO 27001 certified information security management

Exercise Your Privacy Rights

Contact our Data Protection Officer or use our self-service tools to exercise your GDPR rights and manage your privacy preferences.

📧 Data Protection Officer
Response within 30 days
🔧 Self-Service Portal
Account Settings
Immediate access
📋 Download DPA
Full Agreement (PDF)
Multiple languages
All Compliance Docs
GDPR Article 30 compliant
Regular updates
Supervisory authority approved