Legal

Privacy & Data Protection

This policy explains what personal data DataTap collects on this website and during the free trial period. It does not govern data processed through the DataTap Collection Engine (DCE) after an Integrator or Service Provider (“ISV”) embeds it into their own product — that is entirely the Integrator’s responsibility. Effective date: July 21, 2025.

1. Who We Are

[LEGAL ENTITY TBD], operating as DataTap, provides the DataTap Collection Engine (DCE) — a cloud-native Microsoft 365 data collection and restore platform licensed to Independent Software Vendors and Cloud/Data Service Providers (“ISV”). For privacy enquiries, contact info@datatap.stream.

2. Scope of This Policy

This policy applies to two things only:

  • This website (datatap.stream) — visitors who browse our pages or use the live chat.
  • The free trial — companies that sign up for a 30-day trial and the Microsoft 365 data collected through the DataTap-hosted trial instance.

This policy does not apply to data processed after integration. Once an ISV embeds DCE in their own product and deploys it to their customers, DataTap has no access to, visibility into, or control over that data. Data handling from that point on is governed entirely by the ISV’s own privacy policy and data protection obligations. End users with questions about their data should contact the ISV whose product they use, not DataTap.

3. Data We Collect as Controller

When you submit a trial request at datatap.stream/trial, we collect:

  • Your name and email address — used solely to provision the trial tenant and send API credentials. We do not use this for marketing and we do not sell it.

The legal basis is performance of a contract — specifically, setting up and managing your free trial. This data is retained for up to 12 months from submission and then deleted, unless a paid license is established.

4. Microsoft 365 Data During the Trial

During the 30-day trial, DataTap operates a hosted DCE instance on your behalf. Any Microsoft 365 content you collect through that instance — emails, files, Teams messages, calendar items — is stored temporarily in DataTap’s Azure infrastructure for the sole purpose of letting you evaluate the Service.

This data is never read, analysed, or used for any purpose other than running your trial. You are responsible for ensuring you have lawful authority to connect and collect any Microsoft 365 tenant during the trial.

All trial Microsoft 365 data is permanently deleted within seven (7) days of trial expiry. If you convert to a paid license before expiry, the data transitions to your own Azure deployment — at which point DataTap ceases to host or have access to it.

5. Sub-processors (Trial Infrastructure)

DataTap uses the following third parties to operate the trial and this website:

Microsoft Azure

All compute, storage (Cosmos DB, Azure Blob), and Key Vault used to run the trial instance. Trial Microsoft 365 data is stored exclusively on Azure.

Cloudflare

CAPTCHA verification (Turnstile) on the trial sign-up form, and CDN delivery of this website. Cloudflare processes your IP address and browser metadata when you submit the form or visit the site.

DigiChat

Live support chat on datatap.stream/chat. Any information you share in a support conversation is processed by DigiChat. Do not share sensitive content in the chat interface.

6. Data Residency (Trial)

Trial Microsoft 365 data is stored in Azure West Central US. If your organisation has data residency requirements that prohibit storage in the United States, please contact us before starting a trial.

7. Security

During the trial period DataTap applies the following measures:

  • TLS 1.2+ encryption for all data in transit.
  • Azure-managed encryption at rest for all stored content and metadata.
  • App-only, certificate-based OAuth for Microsoft 365 access — no user passwords are stored or transmitted.
  • All secrets stored in Azure Key Vault; never embedded in code or config.
  • Tenant isolation: each trial instance is provisioned in a dedicated Azure resource group, with no cross-tenant data access at the infrastructure level.

8. Post-Integration: ISV Responsibility

After an ISV integrates the DCE into their Licensed Application, DataTap functions as a software vendor only — equivalent to any other software library or SDK the ISV uses. DataTap:

  • has no access to data processed by the ISV’s deployment;
  • is not a data processor, sub-processor, or joint controller for End Customer data;
  • bears no responsibility for the ISV’s compliance with GDPR, PIPEDA, or any other data protection law with respect to their End Customers.

ISVs are solely responsible for implementing their own data protection practices, publishing their own privacy policies, obtaining End Customer consent, and responding to data subject requests. If you are an End Customer of an ISV product that uses the DCE, please direct all data-related requests to that ISV.

9. Your Rights

If you submitted a trial request and want to access, correct, or delete your name and email address, contact us at info@datatap.stream. We respond within 30 days.

10. Changes to This Policy

Material changes will be communicated to known ISV contacts by email at least 30 days before taking effect. The effective date above reflects the version currently in force.

11. Contact

Privacy enquiries: info@datatap.stream.