This statement describes in outline how Taply B.V. puts its obligations under the General Data Protection Regulation (GDPR) into practice. For a full description of which data we process and why, see the Privacy policy.
Controller for the processing
The controller for the processing of personal data is:
- Taply B.V.
- Roermond, the Netherlands
- Chamber of Commerce (KVK) number: [KVK NUMBER TO BE ADDED]
- Email: info@taplyreceipts.com
Data Protection Officer
At its current scale, Taply is not legally required to appoint a Data Protection Officer (DPO). For all data protection questions you can reach our central point of contact: info@taplyreceipts.com.
Should our scale or the nature of our processing change, we will reassess the DPO question and update this page.
Processing register
In accordance with Article 30 GDPR we maintain an internal processing register recording, per processing activity:
- Name and purpose of the processing
- Categories of data subjects and data
- Recipients of the data
- Retention periods
- Technical and organisational security measures
An anonymised summary of this register is available on request via info@taplyreceipts.com.
Privacy by design and by default
We apply the following principles:
- Data minimisation: we only ask for what we need.
- Purpose limitation: we only process data for the purpose it was provided for.
- Opt-in by default: marketing and non-functional cookies require active consent.
- EU residency: primary storage within the EU/EEA.
- Encryption at rest and in transit: standard, not merely optional.
- Least privilege: employees only get access to data needed for their role.
- Audit logging: critical actions on customer data are logged.
Data Protection Impact Assessments (DPIA)
A DPIA is mandatory when a processing activity poses a high risk to data subjects. At the current scale and given the nature of the processing — transaction and contact data of business users and their end customers with explicit opt-in — no legally required DPIA applies. With every substantial extension of the Service we reassess whether a DPIA is necessary.
Data breach protocol
In case of a (suspected) data breach we follow a fixed protocol:
- Immediately raise the alarm internally and contain the breach.
- Assess which data and how many data subjects are affected.
- If the breach is likely to pose a risk to data subjects, we report it within 72 hours to the Autoriteit Persoonsgegevens (Dutch DPA).
- In case of high risk we also inform the data subjects directly.
- We document every incident in our internal register, including measures taken.
Requests to exercise your rights
Requests for access, rectification, erasure, restriction, objection or data portability can be sent to info@taplyreceipts.com. We verify your identity (to avoid disclosing data to the wrong person) and respond within one month. For complex requests this period may be extended by two months; in that case we inform you within the first month.
Complaints
We would like to get it right ourselves first. Should you nevertheless be dissatisfied with how we handle your data, you have the right to lodge a complaint with the supervisory authority:
- Autoriteit Persoonsgegevens (Netherlands)
- Gegevensbeschermingsautoriteit / Data Protection Authority (Belgium)
Questions about this document? Email info@taplyreceipts.com.