Data Processing Information
How taaap processes customer Form information and uses service providers.
- Effective
- September 9, 2026
- Version
- 1.0
1. Roles and instructions
For customer-created Forms, the customer determines what information to request, why it is needed, and the lawful instructions for handling it. Siliconstation Software processes that information through taaap to provide and secure the service and comply with applicable law.
Customers must provide appropriate notices and permissions and must not request prohibited sensitive information. Each party remains responsible for its own mandatory duties.
2. Processing scope
| Item | Current scope |
|---|---|
| Activities | Hosting, storing, displaying, exporting, and deleting Form responses; related security and support |
| People | Form respondents and customer personnel using taaap |
| Data | Customer-defined contact, text, consent, and selection fields; Form version and approved source context |
| Restricted data | Passwords, full card details, identity-document copies, medical information, and information deliberately collected from children |
| Duration | Current operational retention described in the Privacy Notice and authorized deletion requirements |
3. Service providers
Depending on the feature used, service providers can include IONOS for public infrastructure, Cloudflare for DNS and edge services on some hostnames, Resend for transactional email, Google and Apple for optional sign-in, and Stripe for billing. An operator-controlled production origin stores the primary application database and cache.
Provider processing can occur outside Canada. We apply reasonable access restrictions and do not promise Canada-only processing, end-to-end encryption, SOC 2 certification, ISO certification, or an independently audited recovery objective.
Contact [email protected] for current provider information relevant to your use of taaap or to discuss a separate data processing agreement for a business deployment.
4. Security and requests
Technical controls include tenant isolation, authenticated access, encrypted network transport, bounded exports, and API log redaction for request URLs, credentials, cookies, and request bodies. No security control removes all risk.
We assist with access, correction, deletion, and incident assessment within our role. We notify customers and regulators when required by applicable law and process verified deletion requests according to the current Privacy Notice.
5. Document status
This page provides transparency about current processing. It is not a signed data processing agreement and does not replace a separately executed agreement where one is required.