Legal
Terms of Service and Personal Data Transmission Agreement
This English version is provided for convenience. The Spanish version governs.
Version negocio-transmision-2026-10 · Effective September 24, 2026
Taply Terms of Service
Acceptance
These Terms govern the use of Taply, the platform that lets you set up an agent to handle WhatsApp, Instagram, Facebook, Google Business and website chat conversations. By creating an account or using Taply you accept these Terms; if you do not agree with them, you must not use the service.
The service
Taply lets you set up an artificial intelligence assisted agent that replies on your behalf with the information you approve, shares files you upload, checks availability in Google Calendar when you connect it, and hands the conversation to a person on your team when that is appropriate.
The agent replies are generated by an artificial intelligence model from the configuration you defined. Although we aim for them to be useful and accurate, an AI model can make mistakes or misread a message; that is why Taply gives you control to review, pause and take over any conversation.
Your responsibility
You decide what information your agent loads, what files it shares, which rules and automations it applies and which integrations it connects. You are responsible for that configuration, the content you upload and the replies you authorize being accurate, lawful and compliant with the policies of the platforms you connect, including the Meta policies for WhatsApp Business and Instagram.
Taply is not responsible for commercial decisions you make on the basis of the agent replies, nor for the content a customer of yours sends through those channels.
Your account
You must provide accurate information to create your account and keep your access credentials secure. You are responsible for the activity that occurs in your account. Let us know as soon as possible if you suspect unauthorized use.
You may not use Taply to send spam, misleading or unlawful content, to breach the policies of the platforms you connect, or to attempt to compromise the security of the service.
Optional integrations and third parties
Taply connects, if you decide so, with third-party services such as WhatsApp, Instagram and Google Calendar. Each of those services has its own terms, and Taply does not control their availability, their changes or their approval decisions. Authorizing an integration means accepting that Taply queries it on the terms described in our Privacy Policy; you can disconnect any integration whenever you want from your account.
Intellectual property
The brand, the platform and the software associated with Taply belong to their respective owners or licensors. These Terms do not transfer any right over them to you beyond the use of the service.
Your business information, the files you upload and the content of your conversations remain yours. You give us permission to process them only to the extent necessary to provide the service to you.
Suspension and termination
We may suspend or close your account if you breach these Terms, if we detect a security or abuse risk, or if a third-party platform you connect requires it. Where reasonably possible, we will notify you beforehand or at the time.
You may stop using Taply and request the deletion of your account whenever you want.
Availability and changes
We work to keep Taply continuously available, but we do not guarantee that the service will run uninterrupted or free of errors. We may modify, add or withdraw features of the service, and we will update these Terms when such a change warrants it.
Limitation of liability
To the extent permitted by applicable law, Taply will not be liable for indirect, incidental or consequential damages arising from the use of the service. This limitation does not remove liabilities that the law does not allow to be limited by contract.
Your customers’ data and the Club
A.1. Your role regarding your customers' data. You decide which of your customers' data you collect and what for, so you are the Controller («Responsable del Tratamiento») of that data. Taply processes it on your behalf, as Processor («Encargado»), under the Personal Data Transmission Agreement (Part B), which forms part of these Terms.
A.2. Business legal details. You must record accurate and up-to-date details: name or legal name, document type and number, physical address, email for personal data requests and phone. Taply shows them to your customers in your Club and in your privacy notices, and provides them to anyone who needs them to file a complaint or claim against you and to the authorities that request them (Ley 1480 de 2011, art. 53; Ley 1581 de 2012, art. 12).
A.3. Your data policy. You must have a personal data processing policy. You can adopt the model policy that Taply offers you (Part C), which is published with your details in your Club, or link your own. If you use your own, it must be consistent with how you use Taply.
A.4. Your forms and their purpose. When you add questions to your Club form or fields to your contacts, you must write what you will use the answers for and ask only for data relevant to that purpose. You may not ask for sensitive data without the conditions Taply shows (always optional and with their notice) nor, about children, anything other than what Taply allows. Taply may block or flag questions to protect your customers, but responsibility for what you ask and why is yours.
A.5. Your customers' requests. You must handle your customers' inquiries and claims about their data within the legal deadlines: 10 business days for inquiries and 15 for claims, extendable by 5 and 8 business days by giving the reason (Ley 1581, arts. 14 and 15). Taply gives you the tools to view, correct and delete their data, and notifies you of the requests it receives.
A.6. Your Club. Your Club's conditions, goal and reward are a promotion of yours that binds you towards your customers (Ley 1480, art. 33). You undertake to deliver the rewards earned, not to apply changes to cards in progress, to void visits only for the objective reasons in the Club Conditions and to announce the end of the Club at least 30 calendar days in advance, honoring the redemption of rewards earned for at least 90 days from the announcement.
A.7. Commercial messages. You may only send promotions to people who gave you that authorization separately, through the channel they authorized and within the hours of Ley 2300 de 2023 (Monday to Friday from 7:00 a.m. to 7:00 p.m. and Saturdays from 8:00 a.m. to 3:00 p.m.; never Sundays or public holidays), besides complying with Meta's policies. Joining the Club is not an authorization for promotions.
A.8. Your virtual assistant. You configure what your assistant does and what data it can use. You must not instruct it to ask for data that the law or these Terms do not allow, nor to answer personal data requests on your behalf: it must hand them over to you.
A.9. National Database Registry. If the law requires you to register your databases with the SIC, you must do so and name Taply as Processor.
A.10. Indemnity. You are answerable to your customers and to the authorities for your instructions, your purposes, your questions and your policy, and you will hold Taply harmless from claims, fines and costs arising from them, except to the extent the damage was caused by a breach by Taply.
A.11. Taply's powers. If a question, a field, a campaign or a setting of your Club or your assistant violates the law or these Terms, Taply may unpublish, pause or block it, telling you the reason, and restore it once it is corrected.
Governing law
These Terms are governed by Colombian law. Nothing set out here limits the rights granted to you by mandatory law. We will seek to resolve any disagreement directly with you, through contact@gettaply.com, for 30 calendar days; if we cannot, either of us may go to the competent courts of Colombia.
Contact
For questions about these Terms, write to us at contact@gettaply.com.
Personal Data Transmission Agreement
Personal data transmission agreement under article 25 of Decreto 1377 de 2013 (article 2.2.2.25.5.2 of Decreto 1074 de 2015).
1. Parties
The Controller is the business identified in its Taply account and in «Datos legales del negocio» (business legal details). The Processor is Jesus Auriol Villamarin Ortiz, an individual identified with C.C. 1.034.318.093, domiciled at Calle 152 # 9-80, Bogotá D.C., Colombia, email support@gettaply.com and phone +57 311 566 3842, who operates the Taply platform.
2. Purpose of the agreement
The Controller transmits to the Processor the personal data of its customers and contacts so that the Processor processes it on the Controller's behalf when providing the Taply service, and the Processor undertakes to process it in accordance with this agreement, the Controller's instructions and Colombian law.
3. Data Subjects and data
The Controller's customers and contacts, members of its Club and, when the Controller enables it, children registered by their legal representative. Data: identification and contact (name, WhatsApp number, social media username, email), conversations and their files, fields and answers the Controller defines, birthdays, visits, rewards and redemptions, notification preferences, technical data of Wallet cards, appointments, campaign sends and the evidence of authorizations and requests.
4. Activities the Processor performs
Collecting the data through the forms, chats and integrations the Controller configures; storing and protecting it; showing it in the Controller's dashboard; operating the virtual assistant with the data the Controller enables; confirming WhatsApp numbers; issuing and updating Apple Wallet and Google Wallet cards; sending the notices and messages the Controller orders to those who authorized them; computing statistics for the Controller; keeping the evidence of authorizations and requests; making backups; and correcting, anonymizing or deleting data when appropriate.
5. Purposes
The Processor processes the data only for the purposes the Controller sets in its policy and in its forms, and for those inherent to providing the service: platform security and fraud prevention, evidence of authorizations and requests, and aggregated and anonymous statistics. It does not use it for its own purposes, does not sell or assign it, does not use it to train general-purpose artificial intelligence models and does not cross-reference it with that of other businesses.
6. Instructions
The Controller's instructions are this agreement, the configuration it makes in the dashboard and those it gives in writing. If the Processor considers that an instruction violates the law, it informs the Controller and may refrain from following it.
7. Standing instructions
The Controller hereby instructs the Processor to:
- Apply the rules on data of children and adolescents in Taply's policy (the representative's authorization, minimal data, use only with their representative, never in public replies or on Wallet cards).
- Mark questions on sensitive topics as voluntary, collect them only in forms with their notice (the assistant does not ask for or store them from the chat) and block them about children.
- Keep adults' data while their relationship with the Controller lasts and until they request its deletion, and children's data while their representative's relationship with the Controller lasts, until the representative asks for it to be deleted or until they turn 18, whichever comes first, asking the representative for a yearly confirmation.
- When carrying out a deletion, also delete the content of that person's conversations, keeping only what is needed to respect their decision not to receive messages.
- Carry out the deletions and revocations the Controller decides or that the Data Subject makes from their card.
- Notify the Controller of each data request recorded in Taply and remind it of its deadline when 5 business days and 1 business day remain before the end of the legal period.
- Show the Controller's privacy notice in the first private conversation with each person and record its evidence.
- Keep the evidence of authorizations and requests for up to 5 years after the Data Subject's relationship with the Controller ends, with the number stored only as an encrypted identifier.
8. Obligations of the Processor
(Ley 1581, art. 18, and Decreto 1377, art. 25):
- Process the data according to the principles of the law, the Controller's policy and this agreement.
- Guarantee Data Subjects the exercise of their rights, and forward to the Controller within 2 business days at most the inquiries and claims it receives, informing the Data Subject.
- Keep the data under security conditions that prevent its tampering, loss, consultation, use or unauthorized or fraudulent access.
- Keep the data confidential, also after the agreement ends, and require the same of its team.
- Update, rectify or delete the data when appropriate and record the legend «reclamo en trámite» (claim in progress) when applicable.
- Refrain from circulating information disputed by the Data Subject when the SIC so orders.
- Allow access to the data only to those who must have it.
- Inform the Controller of security incidents under clause 12 and report them to the SIC (Ley 1581, art. 18 lit. k).
- Comply with the SIC's instructions and requirements.
9. Obligations of the Controller
(Ley 1581, art. 17): obtain and keep the Data Subjects' authorization through the means Taply offers or its own; inform them of the purpose and their rights; have and publish its policy; handle their inquiries and claims within the legal deadlines; give the Processor only data whose processing is authorized; inform it of the corrections and claims it learns of through other means; register its databases in the RNBD (National Database Registry) if applicable; and report security incidents to the SIC within 15 business days of learning of them.
10. Sub-processors
The Controller authorizes the Processor to rely on the providers listed in the section «Con quién compartimos datos» (who we share data with) of Taply's policy. The Processor requires of them data protection obligations equivalent to those of this agreement and is answerable for them to the Controller. It will announce any new provider in the dashboard at least 15 calendar days in advance; if the Controller objects for a reasonable data protection reason, it may terminate the agreement without penalty.
11. International transmission
The Controller authorizes the data to be processed outside Colombia, mainly in the United States, a country with an adequate level of protection according to the SIC's Circular Externa 005 de 2017, and in the other countries of the listed providers, under contracts that require them to protect the data (Ley 1581, art. 26; Decreto 1377, arts. 24 and 25).
12. Security and incidents
The Processor maintains encryption in transit, access control by organization on every query, least privilege, encrypted credentials, limited technical logs and backups. In the event of an incident affecting the Controller's data, it notifies the Controller without undue delay and within 48 hours at most of becoming aware of it, with the information available (what happened, which data and Data Subjects, what measures were taken), and cooperates so that the Controller reports it to the SIC and to the Data Subjects when appropriate. The Processor also makes its own report to the SIC within 15 business days of becoming aware of it.
13. Demonstration and audit
The Processor provides the Controller, on request and at most once a year, with reasonable information to demonstrate compliance with this agreement, following the SIC's Guide on demonstrated accountability. On-site audits are agreed in writing, at the Controller's expense and without access to other businesses' data.
14. Term, return and deletion
The agreement lasts as long as the Controller uses Taply. When it ends, the Controller may export its data for 30 calendar days; once that period expires, the Processor deletes it, except the evidence in clause 7.8 and the data a law requires it to keep.
15. Liability
Each party is liable for its own obligations. The Processor is liable for processing it carries out outside the Controller's instructions or against the law. Otherwise, the Processor's liability to the Controller is limited to the amount paid by the Controller to Taply in the 12 months before the event, except in cases of willful misconduct or gross negligence. This limitation does not affect the rights of Data Subjects.
16. Changes
The Processor may update this agreement by giving notice in the dashboard at least 30 calendar days in advance. If the Controller does not agree, it may terminate the agreement before the change takes effect.
17. Law and disputes
This agreement is governed by Colombian law. The parties will seek to resolve any disagreement directly for 30 calendar days; if they do not succeed, they will go to the competent courts of Colombia.