Legal
Taply’s Personal Data Processing Policy
This English version is provided for convenience. The Spanish version governs.
Version taply-politica-2026-10 · Effective September 24, 2026
This policy explains what personal data Taply processes, for what purposes, with whom it shares it, how long it keeps it and how you can exercise your rights. It implements the right of habeas data (Colombian Constitution, art. 15) and complies with Ley 1581 de 2012, Decreto 1377 de 2013 (compiled in Decreto 1074 de 2015) and the instructions of the Superintendencia de Industria y Comercio (SIC), Colombia's data protection authority.
1. Who Taply is
Taply is a platform operated by Jesus Auriol Villamarin Ortiz, an individual, with which businesses serve their customers through a virtual assistant on WhatsApp, Instagram, Facebook, Google Business and their website chat, and run their loyalty Club.
| Controller | Jesus Auriol Villamarin Ortiz, an individual who operates the Taply platform |
|---|---|
| Identification | Colombian citizen ID (C.C.) 1.034.318.093 |
| Address | Calle 152 # 9-80, Bogotá D.C., Colombia |
| Email for personal data | support@gettaply.com |
| Phone | +57 311 566 3842 |
| Website | gettaply.com |
Personal data inquiries and claims are handled by Taply's support team, at support@gettaply.com.
2. Taply's two roles
The law distinguishes between whoever decides what the data is used for (Controller, «Responsable») and whoever processes it on behalf of another (Processor, «Encargado»). Taply plays both roles, depending on the data:
| Data | Taply's role | Who decides |
|---|---|---|
| Data of the businesses that use Taply and of their teams, visitors to gettaply.com, the platform's security logs and the evidence Taply keeps to defend itself | Controller | Taply, under this policy |
| Data of each business's customers: conversations, contacts, Club data, form answers, data of children registered by their legal representative | Processor | Each business, which is their Controller and has its own policy |
When Taply acts as Processor, it follows the business's instructions set out in the data transmission agreement that the business accepts when using Taply, and never uses that data for its own purposes: it does not sell it, assign it, use it for its own advertising or cross-reference the data of one business's customers with another's.
3. Definitions
- Data Subject («Titular»): the person the data refers to.
- Personal data: any information that identifies a person or makes it possible to identify them.
- Sensitive data: data that affects privacy or whose misuse may lead to discrimination, such as racial or ethnic origin, political orientation, religious beliefs, health, sex life and biometric data.
- Processing: any operation on personal data: collection, storage, use, circulation or deletion.
- Authorization: the Data Subject's prior, express and informed consent to the Processing.
- Transmission: the communication of data to a Processor so that it processes it on the Controller's behalf, inside or outside Colombia.
- Transfer: sending data to another Controller.
4. Principles
Taply processes data under the principles of legality, purpose, freedom, accuracy, transparency, restricted access and circulation, security and confidentiality (Ley 1581, art. 4). It asks only for the data needed for each purpose, keeps it only as long as the purpose justifies and can demonstrate the measures it applies (demonstrated accountability).
5. Data Taply processes as Controller
| Data Subjects | Data | Purposes |
|---|---|---|
| People who create or use a business account on Taply | Name, email, phone, position or role, organization, sign-in data provided by the authentication provider, preferences | Creating and protecting the account; providing the service; support; billing; service notices; complying with the law. With a separate authorization, Taply's commercial news, which can be stopped at any time. |
| Customer businesses | Name or legal name, identification document, address, contact details, plan and payments (payments are processed by a payment provider; Taply does not store card numbers) | Contracting, billing and meeting legal and accounting obligations. |
| Visitors to gettaply.com and to the public Club pages | Technical data (IP address, browser, operating system, pages viewed) | Keeping the site running and secure. |
| Everyone who uses the platform | Security logs: access events, failed attempts and usage limits; when the IP address is stored to prevent abuse, it is transformed with a key and is not kept in clear | Preventing fraud, abuse and unauthorized access. |
| Data Subjects of the businesses' data, once their relationship with the business ends | Evidence of authorizations and of data requests (accepted version, date, channel and an encrypted identifier of the number) | Defending Taply and the business against claims and requests from authorities. |
Taply also produces aggregated and anonymous statistics on platform usage (for example, how many visits are recorded per day in total), which identify no one.
6. Data Taply processes as the businesses' Processor
On behalf of each business, and only for the purposes the business defines and discloses to its customers, Taply processes:
- Conversations on WhatsApp, Instagram, Facebook, Google Business and the website chat: messages, files, voice notes and their transcription, and the profile data each platform provides.
- Contacts: name, phone, email and the fields the business defines and that its assistant or its team record.
- Club: confirmed WhatsApp number, name, birthday (day and month), visits, rewards and redemptions, notification preferences, technical data of the Apple Wallet and Google Wallet cards, answers to the Club form, data of children registered by their legal representative and the evidence of each authorization.
- Appointments and campaigns: appointments the assistant books in the business's calendar and the campaign messages the business sends to those who authorized them.
The specific purposes and retention period of this data are set by each business in its own policy. If the business adopted the model policy Taply offers it, that policy is published on its Club page.
7. The virtual assistant and artificial intelligence
Businesses serve their customers with an assistant that generates replies with artificial intelligence models. Taply designs and operates it under these rules:
- Transparency: in the first private conversation, the assistant introduces itself as the business's virtual assistant, says it runs on artificial intelligence, states where to read the data policy and that the person can ask to be served by someone from the team.
- Minimal data: the assistant receives the ongoing conversation and a limited summary of the customer data the business enabled, not the full database. Children's data is used only when talking with their representative on WhatsApp, never in public replies. The assistant does not ask for or store sensitive data or children's data from the chat.
- Human control: the business can review, pause and take over any conversation, and the customer can ask to be served by a person. The assistant makes no decisions that produce legal effects on anyone.
- No third-party training: Taply does not use the data of businesses or of their customers to train general-purpose models, and uses its model and audio providers under terms and settings that prevent them from using it for that purpose.
- Revocation: a Club customer can turn off the assistant's use of their data from their card without losing their membership.
- Assessment: Taply assesses the assistant's privacy risks before each relevant change in the data it uses, following the SIC's Circular Externa 002 de 2024 on personal data in artificial intelligence systems.
8. Data of children and adolescents
Taply processes data of people under 18 only as Processor, when a business collects it in its Club, and with these safeguards (Ley 1581, art. 7; Decreto 1377, art. 12; Sentencia C-748 de 2011):
- It is registered only by the child's mother, father or legal representative, with an express and separate authorization, after listening to the child according to their maturity and taking their opinion into account.
- Answering is always voluntary and the adult's membership never depends on that data.
- Only minimal data is requested: name or what they are called, age, birthday (day and month) and simple options. Taply prevents asking about children for health data, documents, photos, school, address or contact details.
- It is used only for their card and benefits in the Club, their birthday greeting and personalized service with their representative. It never appears on Wallet cards, in technical logs or in public replies.
- It is kept while the representative is a Club member or a customer of the business, until they ask for it to be deleted or until the child turns 18, whichever comes first. If we only know their age, we calculate that date from the age provided. Once a year the representative is asked to confirm it is still correct.
- The representative can at any time ask to see, correct or delete it.
Adolescents cannot join a Club on their own: the Club is for people over 18.
9. Sensitive data
Taply does not ask for sensitive data for its own purposes. In Club forms, questions that touch on sensitive topics are marked as voluntary and their use is explained before they are answered; about children they are prohibited. No one is required to provide sensitive data and no service depends on it (Ley 1581, arts. 5 and 6; Decreto 1377, art. 6). The virtual assistant does not ask for or store it from the chat.
10. Your rights
As a Data Subject you have the right to (Ley 1581, art. 8):
- Know, update and rectify your data.
- Request evidence of the authorization you gave.
- Be informed, on request, of how your data has been used.
- File complaints with the SIC, after having made your inquiry or claim to the Controller or the Processor.
- Revoke the authorization or request the deletion of your data, when there is no legal or contractual duty to keep it.
- Access your data free of charge.
These rights may be exercised by the Data Subject, their successors, their representative or attorney-in-fact, and anyone acting under a stipulation in favor of another. The rights of children and adolescents are exercised by their legal representative.
11. How to exercise your rights
If your data belongs to a business (you are its customer or a member of its Club), the Controller is that business. Write to it through the channels in its policy: in the Club, from «Tus datos» on your card or to the email under «Datos del negocio». You can also write to us at support@gettaply.com: we forward your request to the business within 2 business days at most, let you know and support the business so it answers you on time.
If your data belongs to Taply (you are a business account user or a visitor), write to us at support@gettaply.com, call or message us on WhatsApp at +57 311 566 3842, or send a letter to Calle 152 # 9-80, Bogotá D.C., Colombia.
Your request must include your name, the contact detail at which you want the answer, a description of what you are asking for and, if you act for another person, the document that proves it. To protect your data we may ask you to confirm your identity, for example by writing from the same registered WhatsApp number.
Inquiries (knowing your data or its use): answered within 10 business days at most from receipt. If that is not possible, we tell you why and answer within 5 more business days at most (Ley 1581, art. 14).
Claims (correcting, updating, deleting, revoking the authorization or reporting a breach):
- If the claim is incomplete, we ask you to complete it within 5 days of receiving it. If 2 months pass from that request without you completing it, you are deemed to have withdrawn it.
- Within 2 business days at most from when the claim is complete, we mark your data with the legend «reclamo en trámite» (claim in progress) and the reason.
- We answer within 15 business days at most from the day after receiving it. If that is not possible, we tell you why and answer within 8 more business days at most (Ley 1581, art. 15).
- If whoever receives the claim is not competent to resolve it, they forward it to whoever is within 2 business days at most and let you know.
Deletion or revocation does not apply when you have a legal or contractual duty to remain in the database. Even after a deletion, the evidence of your authorization and of your request is kept, as the law requires. You can only go to the SIC after completing this procedure (Ley 1581, art. 16).
12. Who we share data with
Taply does not sell personal data. It shares it, by transmission and under contracts that require them to process it only to provide their service to Taply, securely and confidentially, with these providers:
| Provider | What for | Where it processes the data |
|---|---|---|
| Cloudflare, Inc. | Hosting, databases, storage, transactional email, a gateway to the audio service and fallback models for captions and voice in the Content Studio | United States, Europe and the other countries of its global network |
| Meta Platforms (WhatsApp, Instagram, Facebook) | The business's messaging channels | United States, Ireland and other European Union countries |
| Kapso, Inc. | Connecting the business to WhatsApp | United States, Chile and other countries where the provider operates |
| Zernio Software S.L. | Connection with Instagram, Facebook and Google Business, and publishing | Spain and other countries where the provider operates |
| OpenRouter, Inc. | Routing to the artificial intelligence models | United States |
| OpenAI and Google (Gemini) | Artificial intelligence models that generate the assistant's replies; OpenRouter may serve them from OpenAI's or Google's infrastructure, or from Microsoft Azure or Amazon Web Services (Amazon Bedrock) | United States and other countries where the provider operates |
| TypeSafe AI, Inc. | A model that evaluates and organizes the information the business gives the assistant | United States |
| Groq LLC | Transcription of voice notes from customers and businesses | United States and other countries where the provider operates |
| ElevenLabs (Eleven Labs Inc.) | Audio processing: voices, music and effects | United States and other countries where the provider operates |
| Image, video and music providers of the Content Studio: currently Google, OpenAI, ByteDance (BytePlus), MiniMax, xAI, Alibaba Cloud and Atlas Cloud, which Taply reaches through OpenRouter | Creating the content the business requests, with the texts and images the business provides | United States, Singapore, China and other countries where the providers operate |
| Google (Google Wallet, Google Calendar, Google Business) | Club cards, calendar and business profile, when used | United States and other countries where Google operates |
| Apple (Apple Wallet and its notification service) | Club cards on iPhone, when the customer saves one | United States |
| Stytch, Inc. | Sign-in for business accounts | United States |
| Polar Software, Inc. | Billing of Taply's plans | United States, Canada and other countries where the provider operates |
When a Club customer saves their card to Apple Wallet or Google Wallet, Apple or Google also process the card's information under their own terms.
Taply may also hand over data when a competent authority orders it in accordance with the law.
13. International transmissions and transfers
Several of these providers process data outside Colombia, mainly in the United States and in European Union countries, which the SIC recognizes as having an adequate level of protection. The Content Studio providers may also process in Singapore and China the texts and images the business uses to create its content. Taply only transmits data to countries with an adequate level or under transmission contracts that require the provider to protect the data as Colombian law demands, in accordance with article 26 of Ley 1581 and articles 24 and 25 of Decreto 1377. When Taply acts as Processor, these transmissions are made on the business's instructions, and Taply informs the business of this in the contract.
14. Security
Taply applies reasonable technical, human and administrative measures: encryption in transit, access control by organization on every query, least privilege for its team, encrypted secrets and credentials, technical logs limited to what is needed to operate, without Club form answers, identifiers transformed with keys instead of numbers in clear, and backups. No system is completely infallible. If a security incident affects personal data, Taply reports it to the SIC within 15 business days of detecting it, whether it is Controller or Processor of that data (Ley 1581, arts. 17 and 18) and, when it is Processor, it also notifies the business without undue delay and within 48 hours at most of becoming aware of it, so the business can meet its duties.
15. How long we keep data
| Data | Period |
|---|---|
| Business account and its users' data | While the account exists; afterwards, the period required by accounting and tax rules for billing data. |
| Data of a business's customers (Processor) | What the business sets in its policy. If the business stops using Taply, it is returned to the business and deleted within 30 calendar days at most, except the evidence in the next row. |
| Evidence of authorizations and data requests | Up to 5 years after the Data Subject's relationship with the business ends, with the number stored only as an encrypted identifier. |
| Security logs | Up to 12 months. |
| Website technical data | Up to 12 months. |
Taply's databases will remain in force while Taply provides its services; when they end, their data will be handled as this table indicates.
16. Cookies
Taply uses cookies and browser storage strictly necessary to sign in, keep your Club card open on your phone and remember basic preferences. It does not use advertising or cross-site tracking cookies.
17. National Database Registry
Taply is not currently required to register its databases in the SIC's National Database Registry (Registro Nacional de Bases de Datos), because that duty applies to companies and non-profit entities with assets over 100,000 UVT and to public entities, not to individuals (Decreto 1074 de 2015, art. 2.2.2.26.1.2, as amended by Decreto 090 de 2018). It will register them if the law comes to require it. Each business that uses Taply registers its own, naming Taply as Processor, if applicable.
18. Changes to this policy
We publish any change on this page with its new version and date. If the change is substantial, we announce it before applying it; if it adds a new purpose, we ask for a new authorization before using your data for it. Previous versions remain available for consultation.
Annex: Google Calendar
If you connect Google Calendar, Taply requests access to the list of your calendars so that you can choose which ones your agent uses. For each calendar you can select, we store its identifier, its name, whether it is your primary calendar and its time zone.
For the calendars you choose, Taply reads only the intervals marked as busy or free; we do not read titles, descriptions, guests, locations or any other content of your events. In the calendar you designate for booking, your agent can also create, modify or cancel the appointments it books for your customer, always after the customer confirms: it does not touch events it did not create, and it does not write to any other calendar.
We use that availability so your agent knows whether a slot is free or busy and, in the calendar you chose, manages the appointments it books. OAuth access tokens are stored encrypted and always travel over HTTPS. We keep a short availability cache so as not to query Google on every message; after five minutes that cache is no longer considered current, although that does not mean it is deleted automatically at that instant.
We share this information only with the providers we need to deliver that feature (section 12), such as the model that drafts your agent's reply, and when the law requires it. No one on our team reads it unless you ask us to for support, to investigate abuse or a security problem, or because the law requires it.
When you disconnect Google Calendar from Taply, we delete the stored tokens, the calendar selection and the availability cache associated with your account. You can also revoke Taply's access directly from your Google Account, on the official third-party connections page: https://myaccount.google.com/connections.
We do not sell the information we obtain from Google Calendar, nor do we use it for advertising, scoring, surveillance or to train general-purpose artificial intelligence models. Our use of this data complies with the Google API Services User Data Policy, including its Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy#limited-use.