Full text
Data Processing Agreement for TapInn
Version 2026-08-27 · Effective from 27 August 2026
1. Parties and roles
The Customer is the data controller for the personal data processed in the Customer’s TapInn environment. APREX AS, org. no. 937 881 444, is the data processor when APREX processes this data to deliver TapInn.
Each party is independently responsible for processing where that party determines its own purposes and means. Among other things, APREX is an independent data controller for necessary contract administration, invoicing, security documentation, and compliance with its own legal obligations.
2. Subject matter, purpose, nature and duration
The processing consists of receiving, structuring, storing, making available, securing, transferring, retrieving and deleting personal data to the extent necessary to deliver the Customer’s agreed TapInn features, support, troubleshooting, security, backup and export.
The purpose is to deliver a tenant-isolated service for working hours, point-in-time geo-verification, shift scheduling, tasks, communication, administration and related features chosen by the Customer. The processing lasts for as long as the service agreement exists, and thereafter until the data has been returned or deleted under clause 12.
3. Documented instructions
APREX shall only process personal data under documented instructions from the Customer, unless APREX is required to carry out processing under EEA or Norwegian law. The instructions follow from the service agreement, the Customer’s documented configuration, and later written instructions that are compatible with the service.
If the law requires processing without an instruction from the Customer, APREX shall inform the Customer before the processing unless the law prohibits such information. APREX shall notify the Customer without undue delay if APREX considers an instruction to conflict with data protection law, and may suspend the relevant processing while the matter is clarified.
4. The Customer’s rights and obligations
The Customer determines the purpose, legal basis, access, data minimisation, accuracy, retention period, and how data subjects’ rights are to be safeguarded. The Customer shall ensure that its instructions are lawful and that data subjects receive the necessary information.
The Customer has the right to information necessary to verify that APREX fulfils the agreement, to give lawful instructions, to request assistance, and to require that unlawful processing be stopped. The Customer may terminate the agreement if APREX no longer meets the requirements of GDPR Article 28 and the situation cannot be, or is not, remedied.
5. Confidentiality and access
APREX shall limit access to people who need it to deliver, secure or support TapInn. People with access shall be bound by statutory or contractual confidentiality and receive relevant training and instructions.
Access shall be governed by role and least privilege. APREX shall revoke access when the need for it ceases and shall regularly review privileged access.
6. Information security
APREX shall implement and maintain appropriate technical and organisational measures under GDPR Article 32, assessed against the nature of the processing, available technology, cost and risk to data subjects.
The measures shall support confidentiality, integrity, availability and resilience, the ability to restore data, and regular assessment of security. The specific main measures are set out in Appendix 2. Measures may be further developed as long as the level of security is not materially weakened.
7. Sub-processors
The Customer gives general written authorisation for the use of the sub-processors listed in Appendix 3. APREX shall enter into a written agreement imposing equivalent data protection obligations on the sub-processor for the relevant processing, and APREX is responsible to the Customer for the sub-processor’s performance.
APREX shall notify the Customer’s registered contact point at least 30 days before a new or replacement sub-processor begins processing Customer data, unless a shorter notice period is necessary to manage an acute security or operational risk. Within the deadline, the Customer may raise a concrete and reasoned privacy objection. The parties shall try to find a reasonable solution; if unsuccessful, the Customer may terminate the affected service before the change takes effect.
8. Transfers outside the EEA
APREX shall not transfer personal data to a country outside the EEA or an international organisation without a documented instruction and a valid basis under GDPR Chapter V.
Where a transfer is based on Standard Contractual Clauses, APREX shall ensure the relevant module is entered into, assess transfer risk, and implement supplementary measures where necessary. The current processing region and transfer basis for each sub-processor appear in the subprocessor list.
9. Assistance with data subjects’ rights
Taking into account the nature of the processing, APREX shall assist the Customer with appropriate technical and organisational measures so the Customer can respond to requests for access, rectification, erasure, restriction, data portability and objection.
If APREX receives an enquiry concerning the Customer’s data, APREX shall forward it to the Customer without undue delay and shall not respond to it on the Customer’s behalf unless instructed to do so or required by law.
10. Assistance with security, DPIAs and authorities
APREX shall give reasonable assistance with the Customer’s obligations under GDPR Articles 32–36, including risk assessment, data protection impact assessments and any prior consultation, to the extent the assistance concerns TapInn and information APREX has access to.
APREX shall cooperate with the competent supervisory authority within its own area of responsibility and, where permitted by law, inform the Customer of orders or requests concerning the Customer’s data.
11. Personal data breaches
APREX shall notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data. As information becomes available, the notification shall describe the incident, the categories and scope affected, the likely consequences, a contact point, and measures taken or planned.
APREX shall contain the incident, preserve necessary and data-minimised documentation, assist the Customer’s assessment of its notification obligations, and provide reasonable status updates. Notification is not an admission of liability. The Customer is responsible for notifications to the supervisory authority and to data subjects when the Customer is the data controller.
12. Return and deletion on termination
On termination, APREX shall, at the Customer’s choice, return or delete the personal data and delete existing copies, unless the law requires further retention. The Customer shall be given the choice and shall retrieve necessary data before ordinary access is closed.
Data in active systems is deleted or anonymised under documented deletion routines. Copies in secured backups are phased out according to the ordinary backup cycle and shall in the meantime be inaccessible for ordinary use and only processed for restoration, security or legal requirements. APREX may retain limited contract and security documentation for which APREX is itself the data controller.
13. Documentation and audit
APREX shall make available information necessary to demonstrate compliance with GDPR Article 28, normally through up-to-date documentation, security descriptions, audit reports or written responses.
The Customer may carry out, or have an independent auditor bound by confidentiality carry out, an audit normally once every twelve months, with at least 30 days’ notice and without undue disruption. This restriction does not apply in the event of a documented security breach, an order from a supervisory authority, or a specific and reasoned suspicion of a material deviation. The Customer bears its own and APREX’s reasonable additional costs unless the audit reveals a material deviation on APREX’s part.
Appendix 1. The processing
Categories of data subjects include the Customer’s employees, administrators, managers, contact persons and other users or contractors the Customer chooses to register in TapInn.
The data is processed to deliver the features the Customer activates. This may include the following categories:
- Identity, contact, business, role and account data.
- Shift schedule, availability, working hours, breaks, absence, approvals and payroll basis.
- Point-in-time location, geofence result, accuracy, check-in method and time for explicit check-ins.
- Tasks, checklists, comments, messages, announcements, files and photos submitted by users.
- Authentication, device, session, push, security, audit, support and operational data.
- Special categories of data may occur if the Customer or its users include such information in absence records, free text or attachments. The Customer shall limit this to what is necessary and lawful.
Appendix 2. Main technical and organisational measures
The measures are risk-based and apply to the extent relevant to the processing and service surface in question.
- Role-based access, least privilege, personal accounts and controlled privileged administration.
- Tenant isolation in the application’s authorisation logic, and tests intended to prevent cross-customer access.
- Encrypted transport and provider-managed encryption of production data and private files at rest, where supported by the agreed infrastructure.
- Secure handling of secrets outside source code and clients, with token scoping and rotation where relevant.
- Logging, audit trails, error monitoring, rate limiting and routines for incident handling and personal data breaches.
- Backup and recovery routines, integrity checks and controlled deletion under a documented retention policy.
- Change control, code review, dependency tracking and relevant automated tests before deployment to production.
- Data minimisation, point-in-time geo-verification, and a product-level bar on continuous background tracking.
Appendix 3. Approved sub-processors
The following sub-processors are approved at the time this agreement is entered into. The public subprocessor list provides up-to-date information on purpose, data categories, region and contractual basis.
Apple Push Notification service (APNs) is activated for iOS notifications after APREX confirmed the provider terms, region, transfer mechanism, safeguards, public subprocessor list and notice under clause 7 on 20 August 2026. Browser Web Push remains inactive. Card payments via Link/Stripe are not activated in production for this version of the agreement and are therefore not listed as a sub-processor. When they are switched on, Link is the seller and an independent controller for transaction data, not APREX’s sub-processor for card numbers. Before activation this list is updated and the Customer is notified under clause 7.
- Vercel: Hosting, application operations, serverless functions and any Vercel Blob storage. Data: Traffic data, application data, operational logs and files where Blob is enabled. Region: EU (Frankfurt, Germany) for production operations. Vercel edge/CDN may process network traffic at the nearest edge location under Vercel’s DPA.
- Neon: PostgreSQL database. Data: TapInn product data. Region: EU (Frankfurt, Germany).
- Vercel Analytics: Privacy-friendly usage statistics for public pages and product surfaces. Data: Page views, route, referrer and technical browser/device metadata in aggregated form. Region: The Vercel platform, tied to the production project in the EU (Frankfurt, Germany).
- CoreDesk: Customer support via the TapInn proxy. Data: Support enquiries and conversation references. Region: EU / Norway.
- Postmark: Sending transactional email, for example onboarding, password reset and customer follow-up. Data: Email address, name, message content and delivery metadata. Region: USA, with a DPA and Standard Contractual Clauses (SCCs) as the transfer basis.
- Sentry: Error monitoring, stack traces and performance tracing for operations and security. Data: Error events, technical route/runtime metadata, stack traces and release/build metadata. Default PII collection is off. Region: EU ingest (Germany) under Sentry’s DPA.
- Redis Ltd (Redis Cloud via Vercel Marketplace): Shared cache for rate limiting and security counters, for example repeated sign-in attempts and API calls. Data: Short-lived counters keyed by IP address, user ID or a hash of a token. No customer content, messages or records. Region: EU (Frankfurt, Germany – eu-central-1) under Redis’s data processing agreement.
- Google Firebase Cloud Messaging (Google Ireland Limited / Google LLC): Delivering push notifications to the Android app for events the Customer has enabled, for example a new shift, message or approval. Data: Push device token and the title and body of the notification. No location data. Region: Google infrastructure in the EU and the USA. Transfers outside the EEA are covered by Google’s data processing terms with the EU Standard Contractual Clauses (SCCs).
- Apple Push Notification service (APNs): Delivering push notifications to the iOS app for events the Customer has enabled, for example a new shift, message or approval. Data: Push device token, generic notification text and opaque recipient/delivery references. No message, absence, task, location or other business data is sent in the APNs payload. Region: Apple infrastructure globally, including the USA. Use is governed by the Apple Developer Program License Agreement and its APNs terms; Apple international transfers from the EEA are subject to Standard Contractual Clauses (SCCs).
14. Precedence, changes and duration
The Data Processing Agreement applies from the moment it is accepted electronically or in another documentable manner, and for as long as APREX processes personal data on behalf of the Customer. In the event of conflict with the General Terms of Agreement, this agreement takes precedence on data protection matters.
Changes that materially reduce the Customer’s rights or APREX’s obligations shall be notified and require a valid contractual basis. Updates necessary to comply with law, clarify the processing, or improve security may be notified as a new version without weakening rights already agreed.