tptaplyy
HomeAbout
Featuresv
Pass creationCampaign managementAnalyticsCross-wallet supportTeam operations
Business Typev
All industriesRetail and store groupsRestaurants and hospitalityEvents and venuesGyms and membershipsClubs and associationsChains and franchises
Pricing
Englishv
EnglishFrancais
Get Started

Legal center

Data Processing Addendum

Contractual data-protection terms for personal data processed by taplyy for a customer.

Effective
July 18, 2026
Version
1.0
Language
English

Legal documents

Legal overviewTerms of ServiceAcceptable UsePrivacy NoticePassholder PrivacyData Processing AddendumCookie NoticeSubprocessors

Legal or privacy question?

support@taplyy.com
Pre-launch operator notice. taplyy is currently an unincorporated business operated from Lebanon. Its registered legal name, service address, and company number must be added before commercial launch.

Applies to: Business customers acting as controllers of Customer Personal Data · Effective July 18, 2026 · Version 1.0

1. Application and definitions

This Data Processing Addendum (DPA) forms part of the agreement between a Customer and taplyy when taplyy processes Customer Personal Data on the Customer's behalf. It takes effect when the Customer accepts the Business Terms of Service or another agreement that incorporates it.

Customer Personal Data means personal data submitted to or generated through the service that taplyy processes on the Customer's documented instructions. Applicable Data Protection Law means privacy and data-protection law applicable to that processing, including Lebanon Law No. 81/2018 and, where applicable, laws imposing controller and processor duties.

2. Roles and documented instructions

The Customer is the controller or equivalent responsible party and taplyy is the processor or service provider for Customer Personal Data. Each party will comply with its obligations under Applicable Data Protection Law.

taplyy will process Customer Personal Data only to provide, secure, support, and maintain the service; follow settings and requests submitted through the service; comply with the agreement; and follow other documented instructions agreed by the parties. taplyy may process data where law requires it and will notify the Customer before doing so unless prohibited.

The Customer is responsible for the lawfulness, fairness, accuracy, notices, consents, legal basis, data minimization, and instructions for its processing and for responding to passholders. The Customer will not instruct taplyy to violate law or platform requirements.

3. Processing details

  • Subject matter: digital-pass creation, issuance, delivery, updates, campaigns, scans, redemptions, analytics, support, and security.
  • Duration: the service term plus the limited return, deletion, backup, or legal-retention period described in the agreement.
  • Data subjects: passholders, loyalty or membership participants, ticket holders, visitors, customers, staff, workspace users, and other people whose data the Customer submits.
  • Data types: identifiers, contact details, program IDs, pass fields, status, tier, balances, points, entitlements, ticket or access details, lifecycle events, scans, redemptions, campaign interactions, device or technical signals, and support records.
  • Sensitive data: prohibited unless expressly approved in writing, legally permitted, and supported through the appropriate protected platform functionality.

4. Confidentiality and security

taplyy will ensure people authorized to process Customer Personal Data are bound by confidentiality and access it only as needed. taplyy will maintain security measures appropriate to the risk, taking into account the state of the art, implementation costs, processing context, and nature of the data.

  • Access control, least privilege, authentication, and periodic access review.
  • Encryption in transit and provider-supported encryption at rest.
  • Secure development, change control, dependency maintenance, and environment separation appropriate to the service stage.
  • Operational logging, monitoring, backups, recovery processes, and incident response.
  • Provider diligence, confidentiality, and contractual data-protection commitments.
  • Regular review and improvement of safeguards based on risk and service maturity.

5. Subprocessors

The Customer generally authorizes the subprocessors listed on the Subprocessor List. taplyy remains responsible for a subprocessor's processing to the extent required by Applicable Data Protection Law and will impose materially protective data obligations appropriate to the service supplied.

We will update the Subprocessor List before a new subprocessor begins processing Customer Personal Data and, where required, provide reasonable advance notice. A Customer may object on reasonable data-protection grounds within 15 days. The parties will work in good faith on a reasonable solution; if none is available, either party may terminate only the affected service.

6. Assistance and data-subject requests

Considering the nature of processing and information available, taplyy will reasonably assist the Customer with data-subject requests, security obligations, breach assessments, impact assessments, and consultations required by Applicable Data Protection Law. The Customer remains responsible for its response and may be charged reasonable costs for exceptional assistance outside standard functionality.

If taplyy receives a request concerning Customer Personal Data, it will direct the requester to the Customer or notify the Customer where appropriate and will not independently fulfill the request unless authorized or legally required.

7. Personal-data incidents

taplyy will notify the Customer without undue delay after confirming unauthorized access to, acquisition of, disclosure of, alteration of, or destruction of Customer Personal Data for which notice is required. Notice will include available information reasonably needed for the Customer's assessment and will be supplemented as facts become available.

Notification is not an admission of fault. The Customer is responsible for notifications to authorities and individuals unless law assigns that duty to taplyy. Both parties will cooperate on containment, investigation, remediation, and legally required communications.

8. International transfers

The Customer authorizes processing in Lebanon and in countries where listed subprocessors operate. The Customer is responsible for confirming that its instructions and selected configuration permit those transfers.

Where Applicable Data Protection Law requires a recognized transfer mechanism, the parties will cooperate in good faith to execute appropriate standard contractual clauses or another lawful mechanism. No transfer mechanism is incorporated for a jurisdiction that does not apply to the processing.

9. Return and deletion

During the service term, the Customer may use available functionality to access or export Customer Personal Data. After termination and on request, taplyy will return or delete Customer Personal Data within a reasonable period unless law requires retention, the data remains in protected backup cycles, or the agreement permits limited retention for disputes, security, or unpaid obligations.

Retained data remains protected and isolated from ordinary use and will be deleted when the applicable reason or backup cycle ends. Data held independently by Apple, Google, passholders, or Customer systems is outside taplyy's deletion control.

10. Information and audits

taplyy will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant provider documentation and written responses. No more than once annually, unless required after an incident or by an authority, the Customer may request an audit by an independent qualified auditor bound by confidentiality.

Audits must avoid disruption, protect other customers, not expose security-sensitive information, and use existing third-party reports first where sufficient. The Customer bears its audit costs and taplyy's reasonable costs for assistance beyond standard materials.

11. Liability, priority, and contact

The liability limitations in the main agreement apply to this DPA unless Applicable Data Protection Law prohibits them. If this DPA conflicts with the main agreement about processing Customer Personal Data, this DPA controls.

Questions and notices under this DPA may be sent to support@taplyy.com. The Customer should identify its workspace and a privacy contact in the request.

tptaplyy

Start with taplyy

Launch passes, manage programs, and see what performs.

Built for businesses that need a cleaner way to create wallet passes, manage campaigns, and measure engagement over time.

support@taplyy.com

taplyy

HomePricing

Features

Create passesRun campaignsTrack analyticsSupport both walletsOperate programs

Business Type

All industriesRetail and store groupsRestaurants and hospitalityEvents and venuesGyms and membershipsClubs and associationsChains and franchises

Company

AboutContact us

Legal

Terms of ServiceAcceptable UsePrivacy NoticePassholder PrivacyData Processing AddendumCookie NoticeSubprocessors

© 2026 taplyy. Apple Wallet and Google Wallet pass operations for modern teams.