Tap is a trading name of BrightThemes Ltd.
It is important that you read this privacy notice together with any other privacy notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy notice supplements any other notices previously provided and is not intended to override them.
Registered office address: 20a Carlton Place, Southampton, SO15 2DY, United Kingdom.
If you have any questions about this privacy notice, including any requests to exercise your legal rights, please email us at hello@thisistap.com.
Data Privacy Manager: Joe Perkins
Email Address: hello@thisistap.com
Postal Address: 20a Carlton Place, Southampton, SO15 2DY, United Kingdom.
The type of data we collect about you includes:
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users who upgrade a Tap site within a given timeframe.
Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.
We use different methods to collect data from and about you including through:
Direct Interactions: You may give us your data by filling in forms, using our website, using Wi-Fi, by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
Automated technologies or interactions. As you interact with our website, we may automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using server logs and other similar technologies.
Third parties or publicly available sources. We may receive personal data about you from various third parties and public sources, such as:
We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the reasons we rely on to do so. We have also identified what our legitimate interests are where appropriate.
Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest | Our reasons |
---|---|---|---|
To sell and provide you with our services | Identity Data Contact Data Financial Data Transaction Data Profile Data Usage Data Marketing and Communications Data |
(a) Your consent (b) Fulfilling contracts (c) Our legitimate interests (d) Our legal duty |
(a) Keeping our records up-to-date, working out which of our products and services will interest you and telling you about them. (b) Developing products and services and what we charge for them. (c) Defining types of customers for new products and services. (d) Seeking your consent when we need it to contact you. (e) Being efficient about how we fulfil our legal duties. |
To process and deliver your orders including: (a) managing payments, fees and charges (b) collecting and recovering money owed to us (c) Ensuring you receive the products and services you pay for. |
Identity Data Contact Data Financial Data Transaction Data Usage Data |
(a) Fulfilling contracts. (b) Our legitimate interests. |
(a) To recover debts due to us. (b) To be efficient about how we process and deliver your orders. |
To allow you to register as a new user by creating an account | Identity Data Contact Data Technical Data Profile Data Usage Data Marketing and Communications Data |
(a) Your consent (b) Fulfilling contracts (c) Our legitimate interests (d) Our legal duty |
(a) Being efficient about how we run our service and offer our services to users. (b) Developing products and services, and what we charge for them. |
To manage our relationship with you which will include: (a) user support requests and general enquiries; (b) administrating user accounts, orders and subscriptions; (c) obtaining and monitoring reviews, surveys or feedback relating to Tap; (d) notifying you about changes to our terms; (e) responding to complaints and seeking to resolve them. | Identity Data Contact Data Financial Data Transaction Data Technical Data Profile Data Usage Data Marketing and Communications Data |
(a) Your consent. (b) Fulfilling contracts (c) Our legitimate interests |
(a) Being efficient about how we fulfil our contractual obligations to you. (b) To study how our customers use our products/services, to develop them and grow our business. (c) To keep our records updated and to define types of customers for our products and services. (d) Keeping our records up to date, working out which of our products and services may interest you and telling you about them. (e) To develop our business and to inform our marketing strategy). (f) Seeking your consent when we need it to contact you. |
To develop and manage our brands, products and services. To test new products. To manage how we work with other companies that provide services to us and our customers. |
Identity Data Contact Data Financial Data Transaction Data Usage Data Marketing and Communications Data |
(a) Your consent (b) Fulfilling contracts (c) Necessary for our legitimate interests (d) Our legal duty |
(a) For developing products and services and what we charge for them. (b) Defining types of customers for new products or services (c) To be efficient about how we run our contracts with other companies that provide services |
To enable you to partake in a prize draw, competition or complete a survey. | Identity Data Contact Data Marketing and Communications Data |
(a) Your consent | |
To administer and protect our business. Prevention of fraud and related offences. To detect, investigate, report and seek to prevent crime (including sharing passport information). To manage risk for us and our customers. To obey laws and regulations that apply to us. | Identity Data Financial Data Transaction Data Technical Data Profile Data Usage Data |
(a) Necessary for our legitimate interests (b) Our legal duty |
(a) For running our business, provision of administration and IT services, network security, to prevent fraud. (b) For reporting possible criminal acts or threats to public security. (c) Developing and improving how we deal with financial and other types of crime, as well as fulfilling our legal duties in this respect. (d) Complying with regulations that apply to us. (e) Being efficient about how we fulfil our legal and contractual duties and obligations. |
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you; to create an individual profile for you so that we can understand and respect your preferences. To personalise and improve your experience on our digital platforms |
Identity Data Contact Data Transaction Data Technical Data Profile Data Usage Data Marketing and Communications Data |
(a) Your consent (b) Necessary for our legitimate interests |
(a) To study how our customers use our products/services, to develop them, to grow our business and to inform our marketing strategy. |
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences; to track your activity on our digital platforms | Identity Data Contact Data Transaction Data Technical Data Profile Data Usage Data |
(a) Your consent (b) Necessary for our legitimate interests |
(a) To define types of customers for our products and services. (b) To keep our website updated and relevant. (c) To develop our business and to inform our marketing strategy. |
To migrate your website to Tap | Identity Data Contact Data Profile Data |
(a) Your consent |
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent where this is required or permitted by law.
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly.
We may also participate in Facebook's ‘Custom Audience’ service from time to time. This service enables Tap to display to you personalized advertisements when you visit Facebook’s social media platforms. It works by converting your email address to a unique number that Facebook uses to match to unique numbers that Facebook generates from email addresses of its users. Where we use Facebook Custom Audiences, we will only include you if you have consented to receive marketing from us.
Information about our users is an important part of our business and we do not sell it to others. We only share it in the circumstances set out below:
Third Party Service Providers: We employ other companies and individuals to perform functions on our behalf, fulfil our obligations and as activation partners. Examples of such activity include analysing data, providing marketing assistance, processing credit card payments, providing customer services, social networks, fraud prevention agencies, hosting providers, data storage providers and other technical partners.
Promotional Offers: Sometimes we send offers to selected groups of customers on behalf of other businesses. When we do this, it will only be in circumstances where you have indicated the necessary marketing preferences.
Protection of Tap and third parties: We release account and other personal information when we believe release is appropriate to comply with the law; enforce or apply our Conditions of Use and other agreements; or protect the rights, property or safety of Tap our users or others.
With Your Consent: Other than as set out above, you will receive notice when information about you might go to third parties and you will have an opportunity to choose not to share the information.
List of third party service providers: Google Cloud Platform, SendGrid, Stripe, Intercom.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
You have the right to ask Tap to provide you with all the information it stores on you. To see all of the personal data held on you, you can make a Data Subject Access Request by contacting hello@thisistap.com.
You have the right to ask Tap to rectify, block, complete and delete your personal data, to restrict its use, and to port your data to another organisation. You have the right to object to the processing of your data by Tap, provided such processing is not necessary to continue to provide goods or services to you, we will stop processing your data in accordance with your request. Where we have asked for consent to process your data, you can withdraw this consent at any time by emailing hello@thisistap.com.
Tap may be able to retain data even if you withdraw your consent, where we can demonstrate that we have a legal requirement to process your data.
If at any time you are unhappy with the way your data has been processed or you feel we have not provided you with correct information you can make a complaint to the Information Commissioner’s Office (the ICO). The ICO website is also a useful resource should you require any further guidance on the contents of this privacy notice.
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
In some circumstances, we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
Aggregated Data means statistical or demographic data derived from your personal data but is not considered personal data in law.
Comply with a legal or regulatory obligation means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we are subject to.
Legitimate Interest means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
Performance of Contract means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.