This Data Processing Agreement (“DPA”) is entered into between Jootsing Research Inc., a Delaware corporation with its principal place of business in San Francisco, California (“TapKit”), and the customer that has entered into the TapKit Terms of Service or another written agreement with TapKit governing the customer’s use of the Service (the “Agreement”) (“Customer”). This DPA is incorporated into the Agreement pursuant to its Section 11.4 and applies to the extent TapKit Processes Customer Personal Data on Customer’s behalf in providing the Service. In the event of a conflict between this DPA and the Agreement with respect to that Processing, this DPA controls. Capitalized terms used but not defined in this DPA have the meanings given in the Agreement.
1. Definitions
“Customer Personal Data” means Personal Data contained in Customer Content that TapKit Processes on Customer’s behalf in providing the Service, including Personal Data contained in inputs, screenshots, session data, live streams, and automation trajectories processed during Customer’s authorized workflows (“In-Session Data”). Customer Personal Data does not include Account, billing, usage, telemetry, or Website data that TapKit processes for its own purposes as a controller or business, as described in the TapKit Privacy Policy.
“Data Protection Laws” means all data protection and privacy laws applicable to the Processing of Customer Personal Data under the Agreement, including, as applicable: Regulation (EU) 2016/679 (“GDPR”); the GDPR as incorporated into United Kingdom law (“UK GDPR”); the Swiss Federal Act on Data Protection; the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its regulations (“CCPA”); and other U.S. state comprehensive privacy laws.
“Personal Data” “Controller,” “Processor,” “Data Subject,” “Processing” (and “Process”), and “Supervisory Authority” have the meanings given in applicable Data Protection Laws; “Controller” includes a “business” and “Processor” includes a “service provider” as those terms are defined in the CCPA.
“Security Incident” means a breach of TapKit’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. A Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, such as unsuccessful log-in attempts, pings, port scans, or denial-of-service attacks.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries annexed to European Commission Implementing Decision (EU) 2021/914.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under s.119A(1) of the Data Protection Act 2018.
“Subprocessor” means a third party engaged by TapKit to Process Customer Personal Data on TapKit’s behalf in connection with the Service.
2. Scope and Roles
2.1 As between the parties, Customer is the Controller of Customer Personal Data and TapKit is Customer’s Processor. Customer’s use of the Service may involve the Processing of Personal Data of third parties (for example, individuals whose information is displayed in applications on Customer’s Controlled Devices); Customer, not TapKit, determines the purposes and means of that Processing by selecting the workflows the Service executes.
2.2 This DPA does not apply to data TapKit processes as a Controller or business — including Account information, billing information, Service usage and diagnostic data, device metadata, and Website data — which TapKit processes as described in the TapKit Privacy Policy. Personal Data contained in workflow inputs, screenshots, or other Customer Content remains Customer Personal Data even if it appears in a diagnostic log or is associated with a device identifier.
2.3 Each party will comply with its respective obligations under Data Protection Laws. Customer is responsible for the accuracy and lawfulness of Customer Personal Data, for its instructions to TapKit, and for providing all notices to, and obtaining all consents and authorizations from, Data Subjects that are required by Data Protection Laws in connection with Customer’s use of the Service, as further provided in Section 5.1 of the Agreement.
3. Details of Processing
The subject matter, duration, nature and purpose of the Processing, the categories of Personal Data, and the categories of Data Subjects are set out in Annex I.
4. TapKit’s Processing Obligations
4.1 Documented Instructions
TapKit will Process Customer Personal Data only on Customer’s documented instructions, including with regard to transfers to a third country, unless required to do otherwise by applicable law (in which case TapKit will inform Customer of that legal requirement before Processing, unless the law prohibits such disclosure on important grounds of public interest). Customer’s instructions consist of: (a) the Agreement, this DPA, and any applicable Order Form; (b) Customer’s configuration of and automation commands submitted through the Service, including through the API and any Third-Party Client acting on Customer’s behalf; and (c) any other documented written instructions agreed by the parties. TapKit will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
4.2 No Sale or Sharing; CCPA Service Provider Terms
TapKit is prohibited from, and certifies that it understands and will comply with the prohibitions on: (a) selling or sharing Customer Personal Data; (b) retaining, using, or disclosing Customer Personal Data for any purpose other than the specific business purposes of providing the Service under the Agreement, including retaining, using, or disclosing it for a commercial purpose other than providing the Service, except as permitted by the CCPA; and (c) combining Customer Personal Data with Personal Data that TapKit receives from or on behalf of another person, or collects from its own interactions with a consumer, except as permitted by the CCPA. TapKit will notify Customer if it determines it can no longer meet its obligations under the CCPA. Customer may take reasonable and appropriate steps to ensure TapKit uses Customer Personal Data consistently with Customer’s CCPA obligations and, upon reasonable notice, to stop and remediate unauthorized use.
4.3 Model Training
For the avoidance of doubt, TapKit will not use Customer Personal Data to train or improve machine-learning or artificial-intelligence models except with Customer’s express opt-in consent as described in Section 7 of the TapKit Privacy Policy. Where Customer has opted in, TapKit will de-identify or aggregate the data wherever feasible before such use, and de-identified data that no longer constitutes Personal Data is outside the scope of this DPA; TapKit will maintain and use de-identified data only in de-identified form and will not attempt to re-identify it.
4.4 Confidentiality of Personnel
TapKit will ensure that persons authorized to Process Customer Personal Data are bound by written or statutory obligations of confidentiality and Process Customer Personal Data only as necessary to provide the Service.
4.5 Security
TapKit will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against Security Incidents, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as described in Annex II. TapKit may update those measures from time to time, provided the updates do not materially reduce the overall protection of Customer Personal Data.
4.6 Security Incident Notification
TapKit will notify Customer without undue delay after becoming aware of a Security Incident and, in any event, within the time period required by applicable Data Protection Laws. The notification will describe, to the extent then known, the nature of the Security Incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. TapKit will provide timely updates as material information becomes available and will provide reasonable assistance with Customer’s notification obligations. TapKit’s notification of or response to a Security Incident is not an acknowledgment of fault or liability.
4.7 Assistance
Taking into account the nature of the Processing, TapKit will provide reasonable assistance to Customer: (a) by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer’s obligation to respond to Data Subject requests to exercise rights under Data Protection Laws; and (b) in ensuring compliance with Customer’s obligations regarding security, Security Incident notification, data protection impact assessments, and prior consultation with Supervisory Authorities, taking into account the information available to TapKit. If TapKit receives a request from a Data Subject relating to Customer Personal Data, TapKit will promptly forward the request to Customer and will not respond except to acknowledge receipt or direct the Data Subject to Customer, unless required by law.
4.8 Deletion and Return
Upon termination or expiration of the Agreement, TapKit will, at Customer’s election, delete or return Customer Personal Data, unless applicable law requires its retention. Customer may request return or deletion by emailing privacy@tapkit.ai. During the thirty (30) days following termination, TapKit will make Customer Content still held by TapKit available for export on request, as provided in Section 9.6 of the Agreement; this does not require retention of content already deleted pursuant to Customer’s instructions or applicable retention criteria. Deletion is handled manually and without undue delay in accordance with applicable Data Protection Laws. Information that must be retained by law, or that cannot immediately be deleted from backups, remains protected and is not used for ordinary operations pending deletion. The retention criteria in Section 9 of the Privacy Policy apply; screenshots and trajectories are not subject to an automatic 90-day deletion schedule.
4.9 Audits and Information
TapKit will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including, when available, summaries of third-party audit reports and security certifications, and will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer. Audits: (a) require thirty (30) days’ prior written notice; (b) may occur no more than once per twelve (12) months, except following a Security Incident or where required by a Supervisory Authority; (c) must be conducted during normal business hours, subject to TapKit’s reasonable confidentiality and security requirements; and (d) are at Customer’s expense. TapKit may first satisfy an audit request by providing its most recent audit reports or certifications where they reasonably address the scope of the request.
5. Subprocessing
5.1 Customer provides general written authorization for TapKit to engage Subprocessors, subject to this Section. TapKit’s current Subprocessors are listed in Annex III and at https://tapkit.ai/subprocessors. Customer approves the Subprocessors listed as of the Effective Date.
5.2 TapKit will provide notice of any intended addition or replacement of a Subprocessor at least ten (10) days before the change takes effect, by email to Customer’s Account email address and by updating the subprocessor page. Customer may object on reasonable, data-protection-related grounds within ten (10) days of the notice. The parties will discuss the objection in good faith; if TapKit cannot reasonably accommodate it, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused portion of the Subscription Term as its sole remedy.
5.3 TapKit will impose on each Subprocessor, by written contract, data protection obligations that are substantially no less protective than those in this DPA, and TapKit remains fully liable to Customer for the performance of each Subprocessor’s obligations.
6. International Transfers
6.1 TapKit Processes Customer Personal Data in the United States. To the extent the Processing involves a transfer of Personal Data subject to the GDPR, UK GDPR, or Swiss law to a country not recognized as providing an adequate level of protection, the parties enter into the SCCs, which are incorporated into this DPA by reference, as follows: Module Two (controller to processor) applies, with Customer as data exporter and TapKit as data importer; Clause 7 (docking) is included; Clause 9(a), Option 2 (general written authorization) applies with the notice period in Section 5.2; the optional language in Clause 11 is not included; Clause 17, Option 1 applies and the SCCs are governed by the laws of Ireland; and Clause 18(b) designates the courts of Ireland. Annexes I and II to this DPA serve as Annexes I and II to the SCCs.
6.2 For transfers subject to the UK GDPR, the UK Addendum is incorporated and amends the SCCs as set out therein; Table 1 is completed with the parties’ details in Annex I, Tables 2 and 3 refer to the SCCs and Annexes as configured in this DPA, and for Table 4, either party may end the UK Addendum as set out in Section 19 thereof. For transfers subject to Swiss law, the SCCs apply with the adaptations customary for Switzerland (references to the GDPR are to the Swiss Federal Act on Data Protection insofar as transfers are subject to it; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; “Member State” is interpreted to allow Data Subjects in Switzerland to enforce their rights in Switzerland).
6.3 If TapKit adopts an alternative lawful transfer mechanism (such as certification under a successor adequacy framework), that mechanism will apply in place of the SCCs to the extent it is valid, and the SCCs will remain as a fallback.
7. Liability; Term; Miscellaneous
7.1 Each party’s liability arising out of or relating to this DPA (including the SCCs) is subject to the exclusions and limitations of liability in the Agreement, except to the extent a Data Subject’s rights under the SCCs cannot be so limited. This Section does not limit either party’s liability to Data Subjects under the SCCs or to Supervisory Authorities.
7.2 This DPA takes effect on the later of the effective date of the Agreement and the date Customer accepts or the parties execute this DPA, and continues until TapKit ceases to Process Customer Personal Data.
7.3 This DPA is governed by the law governing the Agreement, except where Data Protection Laws or the SCCs require otherwise. If any provision of this DPA is held invalid or unenforceable, the remainder remains in effect, and the provision will be enforced to the maximum extent permissible.
Annex I — Description of Processing
A. List of Parties
Data exporter: Customer (contact details as provided in the Account). Role: Controller. Data importer: Jootsing Research Inc., San Francisco, California; privacy@tapkit.ai. Role: Processor.
B. Description of Transfer / Processing
| Item | Description |
|---|---|
| Subject matter | Provision of the TapKit device automation platform under the Agreement |
| Duration | The term of the Agreement, plus the deletion periods in Section 4.8 of this DPA |
| Nature and purpose | Capture, transmission, storage, and display of screenshots, session data, and automation trajectories from Customer’s Controlled Devices; execution of Customer’s automation commands, including transmission of screenshots and interaction data to AI/LLM Subprocessors solely to execute those commands; delivery of session traces and logs to Customer; debugging and securing the Service |
| Categories of Data Subjects | Customer’s Authorized Users; individuals whose information is displayed on Controlled Devices during automation sessions directed by Customer (e.g., contacts, message counterparties, and users of Third-Party Applications) |
| Categories of Personal Data | Any Personal Data displayed on a Controlled Device’s screen during an automation session directed by Customer, which may include names, usernames, contact details, message content, images, and other information visible in Third-Party Applications; device identifiers associated with Controlled Devices |
| Sensitive data | Credentials, verification codes, and payment details may be processed as necessary for authorized workflows permitted by Agreement Section 5.3. Other sensitive data may be incidentally captured from a device screen. Restricted Data remains subject to Section 5.3; Customer is responsible for applicable safeguards, notices, and consents. |
| Frequency | Continuous, as directed by Customer during the Subscription Term |
| Retention | As set out in Section 9 of the Privacy Policy and Section 4.8 of this DPA. Deletion requests are handled manually; screenshots and trajectories do not automatically expire after 90 days. |
C. Competent Supervisory Authority
For transfers subject to the GDPR: the Supervisory Authority of the Member State in which the data exporter is established or, where the exporter is not established in the EEA, of the Member State in which its representative is located or in which the Data Subjects are located, determined in accordance with Clause 13 of the SCCs. For UK transfers: the Information Commissioner. For Swiss transfers: the Federal Data Protection and Information Commissioner.
Annex II — Technical and Organizational Measures
- Encryption of Customer Personal Data in transit using TLS/SSL, and encryption of sensitive data at rest;
- Secure hashing of passwords; API key authentication and rate limiting;
- Role-based access controls limiting personnel access to Customer Personal Data to a need-to-know basis; prompt revocation on role change or departure;
- Logical separation of customer environments and data;
- Manual handling of deletion requests and retention decisions in accordance with Section 9 of the TapKit Privacy Policy and Section 4.8 of this DPA;
- Regular security assessments of systems and practices; vulnerability management and patching processes;
- Personnel confidentiality obligations and security awareness practices;
- Incident response procedures supporting the notification obligations in Section 4.6;
- Vendor management: written data protection terms with all Subprocessors (Section 5.3);
- Business continuity measures appropriate to the Service, including managed cloud infrastructure with redundancy and backups.
Annex III — Approved Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting and authentication | United States |
| Railway | Application hosting and infrastructure | United States |
| Agora | WebRTC streaming for real-time device interaction | United States |
| Anthropic | AI/LLM processing to execute automation commands | United States |
| OpenAI | AI/LLM processing to execute automation commands | United States |
Stripe (payment processing), PostHog (product analytics), Vercel (Website hosting), and the advertising and visitor-identification providers described in the TapKit Privacy Policy process data for which TapKit is the Controller or business; they are not Subprocessors of Customer Personal Data and are therefore not listed above.
