Data Processing Agreement

Last updated: 29 June 2026

Download PDF

This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Agreement between Cogniqor BV (“Cogniqor”, the “Processor”) and the customer (the “Customer”, the “Controller”) for use of the TapPass platform (the “Service”). It governs the processing of Personal Data by Cogniqor on behalf of the Customer under Article 28 of the GDPR (Regulation (EU) 2016/679). A signed counterpart is available on request via dpo@tappass.ai; in case of conflict, this DPA prevails over the Agreement for data-protection matters.

Processor: Cogniqor BV, Venneborglaan 85, 2100 Antwerp, Belgium. KBO/VAT BE 1033.796.306. Data protection contact: dpo@tappass.ai.

1. Definitions and roles

1.1. Terms such as “Personal Data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the GDPR. “Customer Personal Data” means Personal Data within Customer Data that Cogniqor processes on the Customer’s behalf.

1.2. For Customer Personal Data processed through the Service, the Customer acts as controller (or processor on behalf of its own controllers) and Cogniqor acts as processor. The subject matter, duration, nature, purpose, types of Personal Data and categories of data subjects are described in Annex 1.

2. Processing instructions

2.1. Cogniqor will process Customer Personal Data only on the Customer’s documented instructions, including as set out in the Agreement and this DPA and as necessary to provide the Service, unless required to act otherwise by EU or Member-State law (in which case it will inform the Customer, unless that law prohibits it).

2.2. Cogniqor will inform the Customer if, in its opinion, an instruction infringes the GDPR or other data-protection law. Cogniqor does not use Customer Personal Data to train or improve any machine-learning model, and does not sell it.

3. Confidentiality

3.1. Cogniqor ensures that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality and process the data only as instructed.

4. Security

4.1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects, Cogniqor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2.

5. Sub-processors

5.1. The Customer grants a general authorisation for Cogniqor to engage sub-processors. Current sub-processors are listed in Annex 3 and kept up to date at trust.tappass.ai.

5.2. Cogniqor imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for their performance. Cogniqor gives the Customer at least thirty (30) days’ prior notice of any intended addition or replacement of a sub-processor, during which the Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected part of the Service.

6. Assistance to the Customer

6.1. Taking into account the nature of the processing, Cogniqor assists the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Chapter III of the GDPR.

6.2. Cogniqor assists the Customer in ensuring compliance with its obligations under Articles 32–36 of the GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the information available to Cogniqor.

7. Personal data breach

7.1. Cogniqor notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provides information reasonably available to it to help the Customer meet its own notification obligations.

8. International transfers

8.1. Customer Personal Data is hosted in the European Union. Cogniqor will not transfer Customer Personal Data outside the EEA except as necessary to provide the Service and subject to an appropriate transfer mechanism under Chapter V of the GDPR (such as the European Commission’s Standard Contractual Clauses), which the parties agree to enter into where required.

9. Deletion and return

9.1. On termination or expiry of the Agreement, Cogniqor will, at the Customer’s choice, delete or return Customer Personal Data and delete existing copies, within ninety (90) days, except to the extent EU or Member-State law requires storage, or where retention is necessary for the integrity of the tamper-evident audit trail (in which case the data remains protected and is processed only for that purpose).

10. Audits

10.1. Cogniqor makes available to the Customer information necessary to demonstrate compliance with Article 28 of the GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates. Audits take place on reasonable prior notice, no more than once per twelve (12) months (unless required by a supervisory authority or following a breach), during business hours, and subject to confidentiality. Cogniqor may satisfy audit requests by providing relevant documentation and responses to reasonable security questionnaires.

11. Liability and term

11.1. Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA takes effect on the effective date of the Agreement and continues for as long as Cogniqor processes Customer Personal Data. It is governed by Belgian law, with exclusive jurisdiction of the courts of Antwerp.

Annex 1 — Details of processing

Subject matterProvision of the TapPass AI-governance platform to the Customer.
DurationFor the term of the Agreement, plus the deletion period in clause 9.
Nature and purposeHosting, processing, governing, monitoring and auditing the actions of the Customer’s AI agents, and providing the related control plane, audit trail and administration.
Types of Personal DataAccount and user identifiers (names, business email addresses, roles); authentication data; and any Personal Data contained in the content the Customer’s agents process or that appears in audit records. The Customer controls what content it sends through the Service.
Categories of data subjectsThe Customer’s Authorized Users and administrators, and any individuals whose Personal Data appears in the content processed by the Customer’s agents.
Special categoriesNot intended. The Customer should not submit special-category data unless agreed and appropriately safeguarded.

Annex 2 — Technical and organisational measures

Cogniqor maintains, at minimum, the following measures (which may be updated to keep pace with the state of the art, provided protection is not reduced):

Cogniqor does not currently hold SOC 2 or ISO 27001 certification and makes no such representation.

Annex 3 — Sub-processors

Sub-processorPurpose & region
Google Cloud (Google Ireland Ltd.)Application hosting and database — EU (Belgium)
CloudflareEdge security, CDN and TLS — EU and global edge
ResendTransactional email — United States
PostHogProduct analytics — EU
SentryError monitoring — EU
OpenAIIn-product assistant (Jorge) — United States

AI model providers are engaged only when the Customer activates a given model with its own key (BYOK); the current list and regions are published at trust.tappass.ai. The Customer’s prompts are never used to train any model.

Contact

Data protection: dpo@tappass.ai. Legal: legal@tappass.ai.