Tap4Go · Bimbiamore LLC
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Tap4Go Terms between Bimbiamore LLC (“Processor”) and an account customer that uses Tap4Go to process personal data on behalf of that customer (“Controller”). It is intended to satisfy GDPR Article 28 and comparable processor-contract requirements.
1. Scope and roles
The DPA applies to hosted user content, third-party information published by Controller, and contact requests collected for Controller. Bimbiamore remains an independent controller for account administration, billing, security, legal compliance and its consented service analytics. Each party will comply with applicable data-protection law. Controller determines the lawful purposes, content, retention and recipients and is responsible for notices, data-subject requests and lawful instructions.
2. Processing details
Subject and duration: hosting, displaying, transmitting, backing up, securing and deleting Controller Data for the subscription/account term plus deletion and backup wind-down. Data subjects: Controller’s personnel, customers, prospects, page visitors, business contacts and persons identified on a business card. Data: professional contact/profile identifiers, communications, page and lead data, photographs, online identifiers and device/log data. The Service is not designed for health, child, government-identity or other sensitive data. Frequency: continuous or as submitted. Purpose: provide and secure Tap4Go according to documented settings and instructions.
3. Instructions and confidentiality
Bimbiamore will process Controller Data only to provide the Service, follow documented settings/support instructions, comply with this DPA, or meet law. If an instruction appears unlawful, Bimbiamore will inform Controller unless prohibited and may suspend that processing. Personnel authorised to process Controller Data are bound by confidentiality and receive access on a need-to-know basis.
4. Security
Bimbiamore will maintain measures appropriate to risk, including TLS, credential and token hashing, access controls, session safeguards, CSRF protection, input and upload validation, prepared queries, rate limits, logging, backups, vulnerability maintenance and incident procedures, together with Hostinger infrastructure controls described in Security & Trust. Controller is responsible for strong credentials, authorised administrators, accurate content, minimisation and avoiding unnecessary sensitive identifiers.
5. Subprocessors
Controller gives general written authorisation for subprocessors listed at Subprocessors. Bimbiamore will impose materially equivalent data-protection obligations and remains responsible for their processor obligations as required by law. We will post material additions at least 30 days before use where practicable. Controller may object on reasonable data-protection grounds during that period; the parties will seek an alternative, and if none is commercially reasonable Controller may stop the affected feature.
6. Assistance
Taking account of the processing and information available, Bimbiamore will reasonably assist Controller with data-subject requests, security, breach assessment/notification, DPIAs and prior consultation. If a request concerns Controller Data, Bimbiamore may direct the requester to Controller and will not independently respond except on instruction or law. Additional work beyond standard Service functionality may be charged at a reasonable pre-agreed rate.
7. Security incidents
After becoming aware of a personal-data breach affecting Controller Data, Bimbiamore will notify Controller without undue delay and provide available information about nature, affected data/subjects, likely consequences, measures and contact. Notification is not an admission of fault. Controller decides whether and how to notify authorities or individuals unless law assigns that duty to Bimbiamore.
8. Return and deletion
During the term Controller may retrieve data through available features or request assistance. On verified termination/deletion instruction, Bimbiamore will delete or return Controller Data from live systems, normally within 30 days, and allow encrypted/restricted backup copies to expire within the normal cycle, unless law requires retention. Legal, security and billing records processed by Bimbiamore as controller are outside this deletion instruction.
9. Audits
On reasonable written request no more than annually, Bimbiamore will provide information reasonably necessary to demonstrate compliance, such as this DPA, security documentation and relevant provider reports. If that is insufficient, Controller may arrange a scoped independent audit during business hours with at least 30 days’ notice, confidentiality, no access to other customers’ data and reimbursement of reasonable costs. A regulator-mandated or breach-related audit is not subject to the annual limit.
10. International transfers
The parties will use a lawful Chapter V mechanism where required. Hostinger’s DPA incorporates EU Standard Contractual Clauses and the UK transfer addendum for covered transfers. Stripe and Google provide their own transfer terms for applicable processing. If Controller’s transfer to Bimbiamore requires a separate transfer instrument not already validly incorporated, the parties will execute the applicable SCC module/UK addendum and complete its annexes before that transfer; contact info@tap4go.com. Nothing in this DPA modifies mandatory SCC text.
11. Priority, liability and termination
SCCs or mandatory law prevail over conflicting terms, then this DPA, then the Terms. Liability follows the Terms to the extent lawful and without limiting data-subject rights under mandatory law. This DPA ends when Bimbiamore no longer processes Controller Data, subject to deletion and surviving confidentiality duties.