1. Roles
When you use TAP TO CLOSE to collect leads, you are the data controller of those lead records and we are your processor. We process lead data only to provide the service to you, and on your documented instructions — your use of the product is that instruction. For your own account data (your billing details, your login), we are the controller.
2. Scope of processing
- Subject matter: providing tap-based lead capture, storage, scoring, pipeline and reporting.
- Duration: for as long as your account is active, plus the deletion windows in section 7.
- Categories of data subject: the prospects who submit your public lead forms.
- Categories of data: name, email, phone, the answers to your industry questions, consent records, tap metadata, and any notes you add.
- Special category data: our lead forms are configured to exclude health, financial-identifier and protected-characteristic fields. You must not add them.
3. Your obligations
- Have a lawful basis for collecting each lead and for any marketing you send.
- Do not paste sensitive personal data into free-text notes.
- Honour opt-outs — our suppression ledger blocks automated sends, but manual outreach is yours to control.
- Keep your own privacy notice accurate about how you use the leads you collect.
4. Our obligations
- Process lead data only to deliver the service, never to build our own marketing lists and never sold.
- Keep records isolated per account through database-level row security.
- Limit staff access to what is needed to operate and support the service.
- Serve all traffic over encrypted connections and keep credentials out of browser code.
- Assist you, so far as reasonably possible, with data subject requests, impact assessments and regulator queries.
5. Subprocessors
You give general authorisation for the providers listed on our subprocessors page. Each one is engaged under written terms no less protective than these. We remain responsible for their performance. When we add a provider that handles lead data, we update that page.
6. Security incidents
If we become aware of a breach affecting your lead data we will notify you without undue delay with what we know: what happened, what data was involved, what we have done, and what we recommend you do. We do not publish a fixed notification deadline here because the applicable deadline depends on your jurisdiction and role.
7. Return and deletion
You can export your leads at any time as CSV or vCard from inside the product. When you delete your account we remove your account and lead records from live systems and log each step of that deletion. Encrypted backups age out on their normal rotation, after which no copy remains.
8. International transfers
Our infrastructure providers are based in the United States. Where a transfer of personal data outside your region requires a transfer mechanism, we rely on the mechanism our provider has in place, as reflected in their agreements linked from the subprocessors page.
9. Audit
On reasonable written request, and no more than once a year unless required by a regulator, we will answer a security questionnaire and share the evidence we hold about our controls. We do not currently hold an independent penetration test report or a third-party audit certification, and we will not claim otherwise.
10. Priority
This addendum supplements our Terms of Service. Where it conflicts with the Terms on the processing of lead data, this addendum applies.
Contact
DPA requests and security questionnaires: support@taptoclose.com.