Privacy policy

What this website collects about you, why, and what you can do about it.

Effective 8 September 2026

Who we are and what this covers

This website, usetappr.com, is operated by Tappr Network B.V., Bosland 11A, 3063 EL Rotterdam, the Netherlands. For the personal data described on this page, Tappr Network B.V. is the controller under the General Data Protection Regulation (GDPR).

This policy covers the website only: the pages you read, the forms you send, and the cookies and services that run in your browser while you are here. It does not cover the Tappr platform. Data that a customer puts into a Digital Product Passport, and data that a consumer shares when scanning one, are processed under that customer's agreement with us and its data processing terms.

We are a business-to-business company. This site is aimed at people acting for a brand, manufacturer or retailer, and the data we collect is the professional contact data needed to talk to them. We do not sell personal data, and we do not use it for automated decisions with legal effect.

When you visit the site

Reading pages requires no account and no registration. To deliver a page, our hosting provider and network layer receive the technical data every web request carries: your IP address, browser type, the page requested, the referring page and the time. This is used for security, capacity and fault finding, on the basis of our legitimate interest in running a safe and reliable website (Art. 6(1)(f) GDPR). Server logs are rotated and kept for no longer than 30 days.

The site is hosted in the European Union, in Finland, and its images are stored in Finland. Fonts are served from our own servers, so no font provider sees your visit. Blog post images are delivered from Sanity's content network.

Nothing else is loaded, and no analytics or advertising cookie is set, until you make a choice in the cookie banner.

When you send us a form

Three forms on this site collect personal data. Each asks only for what it needs.

Book a demo

/book-demo

What we ask for. Full name, work email, company website, industry, how you heard about us, an optional message, and an optional tick to receive the newsletter.

Legal basis. Steps at your request before entering into a contract (Art. 6(1)(b) GDPR). The newsletter tick is consent (Art. 6(1)(a)).

Contact

/contact

What we ask for. Full name, work email and your message.

Legal basis. Our legitimate interest in answering enquiries about our services (Art. 6(1)(f) GDPR).

Newsletter

Footer, /newsletter, and the sidebars of regulation guides and blog posts

What we ask for. Work email. The newsletter page also asks for a first name.

Legal basis. Your consent (Art. 6(1)(a) GDPR). Withdraw it with the unsubscribe link in any issue.

What the site adds on its own

With every submission the site also records the page you sent it from, the page that referred you, any campaign tags in the address (utm_source, utm_medium and utm_campaign), and the time between opening the page and sending the form. The last item, together with a hidden field that only automated software fills in and a Cloudflare Turnstile check, is how we tell people from bots without asking anyone to solve a puzzle.

Your IP address is used for a few minutes in memory to limit how often one address can submit, and is then discarded. It is not written to our logs and it is not stored with your submission.

Where it goes

Submissions pass through a small service we run in Finland and are stored in our CRM, Attio, as a contact record for you and, where your email is on a company domain, a company record. A demo request also creates a sales opportunity linked to that record. If Attio is unreachable, the submission waits on our own server and is delivered once it is back.

We keep CRM records for as long as we are in contact with you or with your company, and for up to 24 months after the last contact. A demo request that does not lead to a conversation is removed after 12 months. You can ask for earlier deletion at any time.

The newsletter

One email a month on regulation changes that affect physical products sold in the EU. We record when and where you subscribed as evidence of consent. Every issue carries an unsubscribe link; using it stops the emails and withdraws your consent from that moment. Withdrawal does not affect the lawfulness of anything sent before it.

Cookies and similar technologies

On your first visit the site asks which cookies may run. Nothing beyond the strictly necessary category is set until you answer, and rejecting everything is one click, in the same place and with the same weight as accepting. Your answer is stored for six months. You can change it at any time.

Cookie settings

The categories

Strictly necessary
The cookie that remembers your banner choice, and the Cloudflare check that protects our forms. Cannot be switched off, and stores nothing that identifies you. Legal basis: our legitimate interest in a working, secure site, and the exemption for strictly necessary storage in Article 11.7a of the Dutch Telecommunications Act.
Performance
Google Analytics 4 and PostHog. They tell us which pages are read, where people arrive from and where they leave, and PostHog can replay how a page was used. We use both for aggregated statistics, not to identify individuals. Legal basis: your consent.
Targeting
Google Ads and the LinkedIn Insight Tag. They measure which campaigns bring visitors here and allow us to show relevant ads on those platforms. Legal basis: your consent.
Functionality
The Crisp chat widget, so you can message us and return to the same conversation later, and preferences such as a remembered tab. Leave this category off and the chat is not loaded; you can still open it from the button on the page, which loads Crisp at that moment because you asked for it. Legal basis: your consent, or your request when you press the button.

The cookies themselves

NameSet byCategoryPurposeLifetime
cc_cookie Tappr Strictly necessary Remembers the choices you made in the cookie banner. 6 months
_ga, _ga_VFZH2WDYEJ Google Analytics Performance Distinguishes visitors and sessions for aggregated site statistics. 2 years
ph_<project key>_posthog PostHog (EU) Performance Distinguishes visitors and sessions for product analytics and session replay. 1 year
_gcl_au Google Ads Targeting Links a visit to the ad click that brought it here, for conversion measurement. 90 days
bcookie, lidc, li_gc, UserMatchHistory, AnalyticsSyncHistory LinkedIn Targeting Measures which LinkedIn campaigns lead to visits and enables relevant ads on LinkedIn. 1 day to 1 year
crisp-client/* Crisp Functionality Identifies your chat session so a conversation you start can be continued later. Set only after you accept this category or open the chat yourself. 6 months

Withdrawing consent for a category removes the cookies listed under it from your browser. Data already sent to a provider before withdrawal is handled under that provider's retention settings, described below.

Embedded content

A few pages embed content from other companies: interactive product demos from Supademo on the Brand Cloud, Passport Builder and Trace pages, and recorded webinars from YouTube on two event pages. When such an embed loads, your browser connects to that company directly, which gives it your IP address and lets it set its own cookies under its own privacy policy. Where the page allows it, the embed is only loaded when you open the tab that contains it.

Who receives your data

We share personal data only with the service providers below, each bound by a data processing agreement and acting on our instructions, and with authorities where the law obliges us to. Nobody else.

ProviderWhat they do for usWhere the data is processed
Hetzner Online GmbH Hosting of this website and of the form service, and storage of site images. Helsinki, Finland and Nuremberg, Germany (EU).
Cloudflare, Inc. Network security and delivery in front of the site and the form service, and the Turnstile bot check on forms. Global network, EU entry points. Transfers covered by Cloudflare's standard contractual clauses and EU-US Data Privacy Framework certification.
Attio Ltd Our CRM. Every form submission is stored here as a contact record. United Kingdom (adequacy decision). Where Attio's infrastructure sits outside the EEA, transfers are covered by the standard contractual clauses in Attio's data processing agreement.
PostHog, Inc. Product analytics and session replay, only after you accept Performance cookies. EU cloud, data stored in the EU.
Google Ireland Ltd Google Analytics 4 (Performance) and Google Ads conversion measurement (Targeting), only after consent. EU and United States. Transfers covered by Google's standard contractual clauses and EU-US Data Privacy Framework certification.
LinkedIn Ireland Unlimited Company LinkedIn Insight Tag for campaign measurement (Targeting), only after consent. EU and United States. Transfers covered by LinkedIn's standard contractual clauses and EU-US Data Privacy Framework certification.
Crisp IM SAS The chat widget on this site, and the messages you send through it, once you accept Functionality cookies or open the chat yourself. France (EU).
Sanity AS Delivers the images used in blog posts. Global content delivery network.
Supademo, Inc. and Google (YouTube) Interactive product demos and event recordings embedded on a few pages. United States. See "Embedded content" below.

Transfers outside the EEA

Our own systems run in the European Union. Where a provider processes data in the United Kingdom, that is covered by the European Commission's adequacy decision. Where a provider processes data in the United States, the transfer is covered by the EU-US Data Privacy Framework where the provider is certified, and otherwise by the European Commission's standard contractual clauses, with supplementary measures where needed. Copies of the relevant clauses are available on request.

Retention by analytics and advertising providers

Google Analytics keeps event data for 14 months. PostHog keeps event and replay data for the period set in our project, which we review annually. Google Ads and LinkedIn hold campaign data under their own retention rules as independent controllers for the advertising part of that processing. We do not keep raw analytics data ourselves.

Your rights

Under the GDPR you have the following rights over the personal data we hold about you. For visitors in the United Kingdom the same rights apply under the UK GDPR.

Access

A copy of the personal data we hold about you.

Rectification

Correction of anything inaccurate or incomplete.

Erasure

Deletion of your data where we no longer need it, or where you withdraw consent.

Restriction

A pause on processing while a question about the data is resolved.

Portability

The data you gave us, in a common machine-readable format.

Objection

To processing based on our legitimate interests, including any direct marketing.

Where processing is based on consent, you can withdraw it at any time: use the unsubscribe link for the newsletter, and the cookie settings above for cookies. Withdrawal does not affect processing that took place before it.

To exercise any right, email legal@usetappr.com. We reply within one month, and we may ask you to confirm your identity first so that we do not release data to the wrong person. Exercising these rights is free of charge.

If you believe we have handled your data unlawfully, you can lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or with the authority in the EU country where you live or work. We would appreciate the chance to resolve the matter with you first.

Security

Every connection to this site and to our form service is encrypted with TLS. Our hosting is in the EU, access to the CRM is limited to the people who need it and protected by two-factor authentication, and Tappr Network B.V. is certified to ISO 27001. This site has no user accounts and takes no payments, so it holds no passwords and no card data.

Children

This site is aimed at professionals and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has given us personal data, tell us and we will delete it.

Changes to this policy

When the site changes in a way that affects your data, for example a new form or a new analytics provider, this page changes with it and the effective date at the top is updated. For material changes we will also say so on the site for a period after the change. Continuing to use the site after a change does not by itself count as consent to anything that requires it; where consent is needed, we ask for it.

Contact

Tappr Network B.V.
Bosland 11A
3063 EL Rotterdam, the Netherlands
legal@usetappr.com

See it on your own products

A 30-minute walkthrough, and a passport built from one of your products, live.

Or call us: +31 10 360 2885 · we reply within one business day.