Contaps
Privacy Policy Terms of Service Cookie Policy Security & GDPR

Security & GDPR

Last updated: 23 June 2026

Summary: We encrypt data in transit, host in secure environments, comply with UK GDPR, and never sell your contact data. You control what appears on your digital card.

Our commitment

Contaps is built for professionals who share contact details and capture leads every day. Security and privacy are core to that promise-not an afterthought.

Data protection (UK GDPR)

We process personal data in line with UK GDPR and the Data Protection Act 2018:

  • We collect only what we need to run the service.
  • We use clear legal bases for processing (see our Privacy Policy).
  • We respond to data subject requests within statutory timeframes.
  • We use data processing agreements with subprocessors where required.
  • We do not sell personal data to third parties.

Security measures

  • Encryption in transit - traffic to Contaps is served over HTTPS (TLS).
  • Password protection - passwords are stored using industry-standard hashing; we never store plain-text passwords.
  • Access controls - role-based permissions for company admins, team members, and platform administrators.
  • Payment security - card payments are handled by Stripe; we do not store full payment card numbers on our servers.
  • Monitoring - activity logging and administrative controls to detect misuse.
  • Backups and recovery - regular backups to support business continuity.

Your data on digital cards

Information on your public card profile is visible to people you share it with (via NFC tap, QR code, or link). You choose what fields to publish. Lead-capture forms collect data you configure; you are responsible for using that data in compliance with applicable marketing and privacy laws.

Company and team accounts

Company administrators may manage cards and view contacts for their organisation according to their role. We recommend assigning admin access only to trusted individuals and reviewing team permissions regularly.

Data location and subprocessors

Our infrastructure and key providers may process data in the UK and, where necessary, in other countries with appropriate safeguards. We vet providers for security and contractual data protection commitments.

Incident response

If we become aware of a personal data breach likely to affect your rights, we will investigate promptly and notify you and/or the ICO where required by law.

Your responsibilities

  • Use a strong, unique password and keep it confidential.
  • Log out on shared devices.
  • Only collect contact information you are entitled to process.
  • Report suspected unauthorised access to us immediately.

Reporting a concern

Security or privacy questions: noreply@contaps.co. You may also contact the ICO at ico.org.uk.

Related policies

  • Privacy Policy
  • Cookie Policy
  • Terms of Service
Privacy Policy Terms of Service Cookie Policy Security & GDPR

© 2026 Contaps. All rights reserved.