Trust Center

Trust is the product.

Your workflows run on your data. Here is exactly how we protect it — the controls, the legal terms, and the sub-processors behind the Services.

Overview

Your workflows run on your data. Here is exactly how we protect it.

Tapi connects to the tools where your business already lives — email, spreadsheets, messaging, documents — and does real work in them. We know what that access means. Trust is not a feature of this product; it is the product.

How Tapi is built to be trusted

You approve what goes out. Tapi supports approval checkpoints on outbound actions: a drafted reply or message waits for a human yes before it is sent. You decide which actions require sign-off.

Every run is on the record. Each task and workflow run produces a step-by-step activity log — what was read, which tools were called, what was produced — so you can always answer "what did it actually do?"

Least-privilege connections, revocable anytime. You connect your tools through OAuth with scoped permissions. You choose which accounts Tapi may touch, and you can disconnect or re-scope any of them at any time.

Team controls. Owner and Member roles with a defined permission matrix, passwordless sign-in via time-limited magic links, per-member usage reporting, and connector ownership boundaries so teammates can't act through each other's accounts.

Your data is not training material. We do not use your content to train AI models, and our model provider's commercial API terms prohibit it from doing so.

Encryption everywhere it should be. Data is encrypted in transit (TLS 1.2+) and at rest .

Data protection

You own your data. Content from your connected accounts is processed to run your tasks — nothing else. Export or delete it through the product; on termination we delete it on the timelines in our DPA.

Data Processing Agreement. Our DPA includes EU Standard Contractual Clauses and the UK Addendum for international transfers, CCPA service-provider terms, and 72-hour breach notification. Enterprise customers can request a countersigned copy at .

Sub-processors. We keep a public, current list of sub-processors with advance notice of changes and a right to object for DPA customers.

Hosting. The Services are hosted on Amazon Web Services in the United States.

Compliance

GDPR & UK GDPR: we act as a processor under our DPA, with SCCs and the UK Addendum for transfers.

CCPA/CPRA: we act as a service provider and do not sell or share customer personal information.

[SOC 2 — include only if an audit is genuinely underway or complete.]

Report a security issue

Found a vulnerability? Email security@tapi.ai and we will respond promptly. Please do not access data that isn't yours or disrupt the service while testing.

FAQ

Who can see my data? Access is limited to the systems and personnel needed to run and support the service, under confidentiality obligations and least-privilege controls. Your teammates' access is governed by your team's roles and connector ownership settings.

Does Tapi train on my data? No — see above.

What happens when I disconnect a tool or leave? Disconnecting a tool immediately revokes Tapi's access to it. On termination, your data is deleted on the timelines set out in the DPA, including backups.

Can my team control what the agent is allowed to send? Yes — approval checkpoints let you require a human confirmation before outbound actions like sending an email or message.

Where do I get the legal documents? The DPA and sub-processor list are public. For a countersigned DPA or security questionnaires, contact .

Terms of Service

Our full Terms of Service govern your access to and use of the TAPI Services. The complete document is being finalized for publication here. In the meantime, for a copy of the current Terms or a countersigned agreement, contact cam@tapi.ai.

Privacy Policy

Our Privacy Policy explains what data TAPI collects as a controller — such as account, billing, and product-telemetry data — and how it is used and protected. Processing of your connected-account content on your behalf is governed by our Data Processing Agreement. The full Privacy Policy is being finalized for publication here; for the current version contact cam@tapi.ai.

Data Processing Agreement

Tapi — Knova AI, Inc. · Version 1.0 · Last updated July 21, 2026

This Data Processing Agreement (“DPA”) is entered into by and between Knova AI, Inc., a Delaware corporation (“Tapi”), and the customer entity identified in the applicable ordering document, order form, or online registration for the Services (“Customer”). This DPA is incorporated into and forms part of the agreement between Tapi and Customer governing Customer's use of the Services (the “Agreement”, including the Tapi Terms of Service or any master services agreement executed between the parties). This DPA reflects the parties' agreement with respect to the Processing of Personal Data by Tapi on behalf of Customer. In the event of a conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA prevails to the extent of the conflict. Capitalized terms used but not defined in this DPA have the meanings given to them in the Agreement.

1. Definitions

“Authorized User” means an individual authorized by Customer to use the Services under the Agreement, including a team Owner or Member.

“Connected Account” means a third-party service account (for example, email, messaging, spreadsheet, document, calendar, CRM, or e-commerce services) that Customer or an Authorized User connects to the Services and authorizes the Services to access and act upon.

“Customer Content” means data, content, instructions, files, and communications submitted to the Services by or on behalf of Customer, including natural-language tasks and workflow definitions, and data retrieved from Connected Accounts at Customer's direction, together with outputs generated by the Services for Customer.

“Customer Personal Data” means Personal Data contained in Customer Content that Tapi Processes on behalf of Customer in connection with the Services.

“Data Protection Laws” means all data protection and privacy laws applicable to the Processing of Personal Data under this DPA, including, as applicable, the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection (“FADP”), and US State Privacy Laws.

“GDPR” means Regulation (EU) 2016/679 (General Data Protection Regulation); “UK GDPR” means the GDPR as incorporated into the law of the United Kingdom.

“Personal Data” “Controller”, “Processor”, “Data Subject”, “Processing” (and “Process”), and “Personal Data Breach” have the meanings given in the GDPR, and include the equivalent terms under other Data Protection Laws (e.g., “personal information”, “business”, “service provider”, and “security breach”).

“SCCs” means the standard contractual clauses for the transfer of personal data to third countries approved by European Commission Implementing Decision (EU) 2021/914, as completed in Section 12; “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner (version B1.0).

“Sub-processor” means a third party engaged by Tapi that Processes Customer Personal Data on Tapi's behalf to provide the Services. Providers of Connected Accounts are not Sub-processors (see Section 2.4).

“US State Privacy Laws” means US state privacy laws applicable to the parties, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”).

“Services” means the Tapi products and services provided under the Agreement, including the natural-language task and workflow platform available at tapi.ai.

2. Roles, Scope, and Customer Responsibilities

2.1 Roles. As between the parties, Customer is the Controller of Customer Personal Data and Tapi is a Processor acting on Customer's behalf. Where Customer acts as a Processor for a third-party Controller, Customer warrants that its instructions and this DPA have been authorized by the relevant Controller, and Tapi is engaged as another processor (sub-processor) of that Controller.

2.2 Scope. This DPA applies to Tapi's Processing of Customer Personal Data in the course of providing the Services. It does not apply to Personal Data that Tapi processes as a Controller, such as account registration and billing contact details, marketing-site visitor data, and product telemetry, which are processed in accordance with Tapi's Privacy Policy.

2.3 Customer responsibilities. Customer is responsible for: (a) the accuracy, quality, and lawfulness of Customer Personal Data and the means by which it was acquired; (b) establishing a lawful basis and providing all notices and obtaining all consents and rights required under Data Protection Laws for Tapi to Process Customer Personal Data as contemplated by the Agreement, including in respect of individuals whose Personal Data is contained in Connected Accounts and in communications processed through the Services; (c) ensuring that its instructions, including workflow configurations and approvals, comply with applicable law; and (d) its Authorized Users' use of the Services, including configuring available access controls, approval checkpoints, and connector scopes appropriately for the sensitivity of the data concerned.

2.4 Connected Accounts. Third-party services that Customer connects to the Services (for example Google Workspace, Slack, WhatsApp, or Notion) act under Customer's separate agreements with those providers. Customer, not Tapi, determines which Connected Accounts to link and what the Services are instructed to do with them. Such providers are independent services chosen by Customer and are not Tapi Sub-processors.

2.5 Restricted data. The Services are not designed to Process, and Customer shall not intentionally submit or connect data sources for the purpose of Processing: (a) special categories of Personal Data within the meaning of Article 9 GDPR; (b) protected health information subject to HIPAA (Tapi does not enter into business associate agreements); (c) payment card data subject to PCI DSS (other than as collected directly by Tapi's payment processor); or (d) Personal Data of children under 16, in each case except as expressly agreed by the parties in writing. Customer acknowledges that such data may be incidentally present in Customer Content (for example, within emails in a Connected Account), and Sections 5 and 6 apply to all Customer Personal Data regardless of category.

3. Processing Instructions

3.1 Documented instructions. Tapi will Process Customer Personal Data only on Customer's documented instructions, including with regard to transfers to third countries, unless required to do otherwise by applicable law (in which case Tapi will inform Customer of that legal requirement before Processing, unless the law prohibits doing so on important grounds of public interest). Customer's documented instructions consist of: (a) the Agreement and this DPA; (b) Customer's and its Authorized Users' use and configuration of the Services, including natural-language tasks, workflow definitions, schedules and triggers, connector authorizations, and in-product approvals; and (c) other written instructions agreed by the parties.

3.2 Infringing instructions. Tapi will promptly inform Customer if, in Tapi's opinion, an instruction infringes Data Protection Laws; Tapi may suspend performance of that instruction until it is confirmed or modified. Tapi is not obliged to perform a legal review of Customer's instructions.

4. Confidentiality

Tapi will ensure that persons it authorizes to Process Customer Personal Data are subject to written or statutory obligations of confidentiality, and will limit access to Customer Personal Data to personnel who require such access to perform the Services, provide support, or comply with applicable law.

5. Security

5.1 Security measures. Taking into account the state of the art, the costs of implementation and the nature, scope, context, and purposes of Processing, as well as the risks to Data Subjects, Tapi will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against Personal Data Breaches, as described in Annex II. Tapi may update those measures from time to time, provided the updates do not materially reduce the overall protection of Customer Personal Data.

5.2 Customer controls. Customer is responsible for securing its own accounts and environment, including: protecting the email accounts used for magic-link sign-in; managing Authorized User access and roles; scoping and revoking Connected Account authorizations; and configuring approval checkpoints for outbound actions where appropriate.

6. Sub-processors

6.1 General authorization. Customer provides general written authorization for Tapi to engage Sub-processors to Process Customer Personal Data. The Sub-processors currently engaged are listed in Annex III and at the Sub-processor Page (the “Sub-processor Page”).

6.2 Notice of changes. Tapi will provide notice of any intended addition or replacement of a Sub-processor at least fifteen (15) days before the new Sub-processor Processes Customer Personal Data, by updating the Sub-processor Page and notifying subscribers via the notification mechanism offered on that page. In urgent cases necessary to maintain the security or continuity of the Services, Tapi may replace a Sub-processor without advance notice and will notify Customer without undue delay afterwards.

6.3 Objection. Customer may object to a new Sub-processor on reasonable data protection grounds by notifying Tapi in writing within fifteen (15) days of the notice. The parties will discuss the objection in good faith. If Tapi cannot provide a commercially reasonable alternative, Customer may terminate the affected Services on written notice and receive a pro-rata refund of any prepaid fees for the unused portion of the terminated Services.

6.4 Sub-processor obligations. Tapi will enter into a written agreement with each Sub-processor imposing data protection obligations that are, in substance, no less protective of Customer Personal Data than those in this DPA, to the extent applicable to the services the Sub-processor provides. Tapi remains liable for the performance of its Sub-processors' obligations under this DPA.

7. Data Subject Requests

Taking into account the nature of the Processing, Tapi will assist Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling Customer's obligation to respond to Data Subjects' requests to exercise their rights under Data Protection Laws (including access, rectification, erasure, restriction, portability, and objection). If Tapi receives such a request directly and can identify that it relates to Customer, Tapi will promptly forward it to Customer and will not respond to it except to direct the Data Subject to Customer, unless legally required to respond. Additional assistance beyond the Services' standard functionality will be provided at Customer's reasonable expense.

8. Personal Data Breach

Tapi will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects; Tapi may provide information in phases as it becomes available. Tapi will take reasonable steps to contain and remediate the breach and will reasonably cooperate with Customer's efforts to comply with its own notification obligations. Tapi's notification of a Personal Data Breach is not an acknowledgement of fault or liability.

9. Data Protection Impact Assessments and Prior Consultation

Taking into account the nature of the Processing and the information available to Tapi, Tapi will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities that Customer is required to carry out under Data Protection Laws in relation to the Services, including by making available the documentation described in Section 11.1.

10. Return and Deletion of Customer Personal Data

During the term of the Agreement, Customer may access, export, and delete Customer Content using the functionality of the Services. Upon termination or expiration of the Agreement, Tapi will, at Customer's written election made within thirty (30) days, delete or return Customer Personal Data, and will thereafter delete remaining copies within thirty (30) days of that election (or, absent an election, within a reasonable period after termination), except that: (a) Customer Personal Data in encrypted backups will be deleted in the ordinary course of Tapi's backup rotation and in any event within 90 days; and (b) Tapi may retain Customer Personal Data to the extent required by applicable law, in which case Tapi will protect it in accordance with this DPA and isolate it from further Processing. Upon request, Tapi will confirm deletion in writing.

11. Audit and Information Rights

11.1 Information. Tapi will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including summaries of Tapi's security program, this DPA's Annex II, and, when available, third-party audit reports or certifications and penetration testing summaries, subject to confidentiality obligations.

11.2 Audits. Where the information provided under Section 11.1 is not sufficient for Customer to demonstrate compliance with its obligations under Data Protection Laws, Customer (or its independent third-party auditor, which may not be a competitor of Tapi) may conduct an audit of Tapi's Processing of Customer Personal Data, subject to: (a) no more than one audit in any twelve (12) month period, except following a Personal Data Breach affecting Customer Personal Data or where required by a supervisory authority; (b) at least thirty (30) days' prior written notice; (c) a mutually agreed scope, duration, and timing during normal business hours; (d) remote review of documentation as the preferred method; (e) no access to data of other customers or to information that would compromise the security of Tapi's systems; and (f) Customer bearing its own costs and reimbursing Tapi's reasonable costs for extraordinary assistance. Audit results are Tapi's Confidential Information under the Agreement.

11.3 SCC audits. The parties agree that this Section 11 sets out the manner in which the audit rights under Clause 8.9 of the SCCs will be exercised, to the fullest extent permitted by the SCCs.

12. International Data Transfers

12.1 Processing locations. Tapi and its Sub-processors Process Customer Personal Data primarily in the United States, and in the other locations identified on the Sub-processor Page (currently including the European Union, for payment processing by Adyen N.V.).

12.2 EEA transfers. To the extent the Processing involves a transfer of Personal Data from the European Economic Area to a country without an adequacy decision, the parties hereby enter into the SCCs, which are incorporated into this DPA by reference and completed as follows: (a) Module Two (controller to processor) applies where Customer is a Controller, and Module Three (processor to processor) applies where Customer is a Processor; (b) in Clause 7, the optional docking clause applies; (c) in Clause 9, Option 2 (general written authorisation) applies with the notice period in Section 6.2; (d) in Clause 11, the optional language does not apply; (e) in Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland; (f) in Clause 18(b), disputes will be resolved before the courts of Ireland; and (g) Annexes I, II, and III of the SCCs are completed with the information set out in Annexes I, II, and III of this DPA respectively.

12.3 UK transfers. For transfers of Personal Data subject to the UK GDPR, the UK Addendum is incorporated into this DPA and completes the SCCs as follows: Table 1 is completed with the parties' details in Annex I; Table 2 refers to the SCCs as completed in Section 12.2; Table 3 refers to Annexes I–III of this DPA; and for Table 4, either party may end the UK Addendum as set out in Section 19 thereof.

12.4 Swiss transfers. For transfers subject to the FADP, the SCCs apply with the following adjustments: references to the GDPR are understood as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; the governing law and forum in Clauses 17 and 18 are Switzerland to the extent required; and Data Subjects in Switzerland may enforce their rights in Switzerland.

12.5 Alternative mechanisms. If Tapi adopts an alternative lawful transfer mechanism recognized under Data Protection Laws (for example, certification under the EU–US Data Privacy Framework ), that mechanism will apply in place of the SCCs to the extent it lawfully covers the relevant transfer.

13. US State Privacy Laws

To the extent US State Privacy Laws apply to Customer Personal Data, the following terms apply and the terms “business”, “service provider”, “sell”, “share”, “business purpose”, and “commercial purpose” have the meanings given in the CCPA (or the equivalent terms under other US State Privacy Laws). Tapi acts as a “service provider” or “processor”. Tapi is prohibited from, and certifies that it understands and will comply with the prohibitions on: (a) selling or sharing Customer Personal Data; (b) retaining, using, or disclosing Customer Personal Data for any purpose other than the business purposes specified in this DPA and the Agreement, or as otherwise permitted by the CCPA; (c) retaining, using, or disclosing Customer Personal Data outside of the direct business relationship between the parties; and (d) combining Customer Personal Data with personal information received from other sources, except as permitted by the CCPA for the business purposes. Tapi will notify Customer if it determines it can no longer meet its obligations under US State Privacy Laws, in which case Customer may take reasonable and appropriate steps in accordance with the CCPA to stop and remediate unauthorized use of Customer Personal Data. Tapi will impose equivalent obligations on Sub-processors, and will not attempt to re-identify de-identified data received from Customer.

14. Machine Learning; Model Providers

14.1 No training on Customer Content. Tapi will not use Customer Content, including Customer Personal Data, to train or improve generalized artificial intelligence or machine-learning models, whether Tapi's own or a third party's, without Customer's prior written consent. For clarity, Tapi may use Customer Content as necessary to provide, secure, and support the Services for Customer, and may use aggregated or de-identified usage data that does not identify Customer or any Data Subject to operate and improve the Services.

14.2 Model providers. Where the Services use third-party large language model providers to process Customer Content, such providers are engaged as Sub-processors under Section 6 and are listed on the Sub-processor Page. Tapi will engage model providers on API terms that (a) prohibit the provider from using Customer Content to train its models, and (b) limit the provider's retention of Customer Content to that necessary to provide the inference service and enforce acceptable-use policies.

15. General

15.1 Term. This DPA becomes effective upon the effective date of the Agreement (or, if later, the date this DPA is executed or otherwise agreed) and remains in force for as long as Tapi Processes Customer Personal Data.

15.2 Precedence. In case of conflict, the order of precedence with respect to the Processing of Personal Data is: (a) the SCCs and UK Addendum; (b) this DPA; and (c) the Agreement.

15.3 Liability. Each party's and its affiliates' aggregate liability arising out of or related to this DPA (including the SCCs) is subject to the exclusions and limitations of liability set out in the Agreement, except to the extent such limitation is prohibited by applicable Data Protection Laws or the SCCs.

15.4 Updates. Tapi may update this DPA from time to time as required to reflect changes in Data Protection Laws or in the Services, by posting the updated version and providing notice to Customer, provided the update does not materially reduce the protection of Customer Personal Data.

15.5 Severability; governing law. If any provision of this DPA is held invalid, the remainder remains in effect and the invalid provision will be replaced with a valid one that most closely reflects its intent. This DPA is governed by the law governing the Agreement, except where the SCCs or mandatory Data Protection Laws require otherwise. This DPA may be executed electronically and in counterparts.

IN WITNESS WHEREOF, the parties have executed this DPA by their duly authorized representatives.

Name: ______________________________

Title: _______________________________

Date: _______________________________

<w:tcPr><w:tcW w:w="4140" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:b w:val="true"/><w:sz w:val="22"/></w:rPr><w:t>CUSTOMER

Name: ______________________________

Title: _______________________________

Date: _______________________________

Annex I — Description of the Processing

A. List of parties

Data exporter: Customer, as identified in the Agreement or applicable order form. Contact details and activities: as set out in the Agreement. Role: Controller (or Processor, where Section 2.1 applies). Signature and date: by entering into the Agreement and this DPA.

Data importer: Knova AI, Inc. (Tapi), a Delaware corporation, , contact: . Activities: provision of the Services described in the Agreement. Role: Processor. Signature and date: by entering into the Agreement and this DPA.

B. Description of the transfer / processing

Categories of Data Subjects: Authorized Users (Customer personnel and contractors); and individuals whose Personal Data is contained in Customer Content or Connected Accounts, such as Customer's customers, prospects, suppliers, business partners, and other correspondents.

Categories of Personal Data: identification and contact data (e.g., names, email addresses, phone numbers, messaging handles); professional information (e.g., employer, role, business contact details); the content and metadata of communications and documents processed through the Services (e.g., emails, chat messages, inquiries, spreadsheets, files, calendar entries); commercial and transactional data contained in Customer Content (e.g., bookings, orders, quotes, invoices); connector authorization data (e.g., OAuth tokens and account identifiers); and usage and log data relating to workflow runs.

Sensitive data: the Services are not intended for the Processing of special categories of Personal Data, and Customer is instructed not to intentionally submit such data (Section 2.5). Sensitive data may be incidentally present within Customer Content (for example, within the body of an email in a Connected Account). Applied restrictions and safeguards: the measures in Annex II, including encryption, access controls, purpose limitation, and Customer-managed connector scoping and approval checkpoints.

Frequency of the transfer / processing: continuous, as initiated by Authorized Users' tasks and by Customer-configured workflow schedules and triggers, for the duration of the Agreement.

Nature of the processing: collection, retrieval, consultation, organization, structuring, analysis, use, storage, disclosure by transmission (to Connected Accounts and Sub-processors as instructed), erasure, and destruction, in each case as necessary to perform the Services, including interpreting natural-language instructions, orchestrating workflow steps across Connected Accounts, generating drafts and other outputs (including via model-provider Sub-processors), presenting actions for human approval where configured, and maintaining run logs.

Purpose(s): providing, securing, supporting, and billing for the Services in accordance with the Agreement and Customer's instructions.

Duration / retention: for the term of the Agreement plus the deletion periods in Section 10. Workflow run logs are retained for or such other period as the parties agree or the functionality of the Services provides.

Transfers to (sub-)processors: as set out in Annex III and on the Sub-processor Page, for the purposes stated there and for the duration above.

C. Competent supervisory authority

The supervisory authority determined in accordance with Clause 13 of the SCCs: where the data exporter is established in an EU Member State, the supervisory authority of that Member State; where the data exporter is not established in the EU but falls within the extraterritorial scope of the GDPR, the supervisory authority of the Member State in which its EU representative is appointed or, absent such appointment, of a Member State in which the relevant Data Subjects are located. For UK transfers, the UK Information Commissioner; for Swiss transfers, the Swiss Federal Data Protection and Information Commissioner.

Annex II — Technical and Organisational Measures

Description of the technical and organisational measures implemented by Tapi (as Processor / data importer) to ensure an appropriate level of security, taking into account the nature, scope, context, and purpose of the Processing.

1. Access control and identity. Role-based access control within the Services (team Owner and Member roles with a defined permission matrix); unique accounts per Authorized User; passwordless magic-link authentication with time-limited, single-use links and bounded session duration; least-privilege access for Tapi personnel to production systems, granted on a need-to-know basis and reviewed periodically; .

2. Encryption. Encryption of Customer Personal Data in transit using TLS 1.2 or higher; encryption at rest using industry-standard algorithms ; encrypted storage of Connected Account OAuth tokens .

3. Connector and action safeguards. Connected Accounts are authorized by Customer via OAuth with provider-scoped permissions; Customer may disconnect or re-scope a Connected Account at any time; the Services support human approval checkpoints before designated outbound actions (for example, sending communications on Customer's behalf); connector ownership boundaries between team members restrict who may use whose Connected Accounts.

4. Transparency and logging. Per-run activity logs showing the steps taken by a workflow (including tool and connector calls) are available to Customer; usage reporting provides per-member run breakdowns for team accounts; administrative and infrastructure access to production systems is logged .

5. Infrastructure and network security. Hosting on Amazon Web Services with logical separation between production and non-production environments (separate production and testing domains and environments); network-level controls including firewalls and restricted administrative access; .

6. Secure development and change management. Code review prior to release; a defined release process including pre-release test suites, staged deployment, and rapid rollback capability; end-to-end regression testing of critical user flows; separation of duties between development and production deployment .

7. Vulnerability and incident management. ; a documented incident response process covering detection, containment, remediation, and the customer notification commitments in Section 8 of this DPA.

8. Personnel. Written confidentiality obligations for all personnel with access to Customer Personal Data; security and privacy onboarding and periodic training ; .

9. Vendor management. Written data protection agreements with all Sub-processors (Section 6.4); review of Sub-processors' security and privacy practices before engagement and periodically thereafter.

10. Data minimisation, retention, and deletion. The Services access Connected Account data as directed by Customer's tasks and workflow configurations; retention and deletion in accordance with Section 10 and Annex I.B; secure deletion procedures for decommissioned media via the cloud provider's certified processes.

11. Assistance to the Controller. The measures above, together with Sections 7–9 of this DPA, constitute the technical and organisational measures by which Tapi assists Customer in fulfilling its obligations regarding Data Subject requests, breach notification, security, and impact assessments.

Annex III — Sub-processors

The Controller has authorized the use of the Sub-processors listed on the Sub-processor Page at the Sub-processor Page, which as of the date of this DPA includes the following. In case of any difference, the Sub-processor Page controls as updated in accordance with Section 6.

<w:tcPr><w:tcW w:w="3885" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:b w:val="true"/><w:sz w:val="22"/></w:rPr><w:t>Purpose of Processing

<w:tcPr><w:tcW w:w="2175" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:b w:val="true"/><w:sz w:val="22"/></w:rPr><w:t>Location

<w:tc><w:tcPr><w:tcW w:w="2205" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:sz w:val="22"/></w:rPr><w:t>Amazon Web Services, Inc.

<w:tcPr><w:tcW w:w="3885" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:sz w:val="22"/></w:rPr><w:t>Cloud infrastructure: hosting, compute, storage, databases and backups; delivery of sign-in (magic link) emails and service notifications (Amazon SES); service usage analytics and application error monitoring (Amazon OpenSearch Service)

<w:tcPr><w:tcW w:w="2175" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:sz w:val="22"/></w:rPr><w:t>United States

<w:tc><w:tcPr><w:tcW w:w="2205" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:sz w:val="22"/></w:rPr><w:t>Composio, Inc.

<w:tcPr><w:tcW w:w="3885" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:sz w:val="22"/></w:rPr><w:t>Integration infrastructure: manages OAuth connections and API calls between the Services and Customer's Connected Accounts

<w:tcPr><w:tcW w:w="2175" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:sz w:val="22"/></w:rPr><w:t>United States

<w:tc><w:tcPr><w:tcW w:w="2205" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:sz w:val="22"/></w:rPr><w:t>Anthropic, PBC

<w:tcPr><w:tcW w:w="3885" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:sz w:val="22"/></w:rPr><w:t>Large language model inference used to interpret instructions and generate outputs

<w:tcPr><w:tcW w:w="2175" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:sz w:val="22"/></w:rPr><w:t>United States

<w:tc><w:tcPr><w:tcW w:w="2205" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:sz w:val="22"/></w:rPr><w:t>Adyen N.V.

<w:tcPr><w:tcW w:w="3885" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:sz w:val="22"/></w:rPr><w:t>Payment processing for subscription and usage-based billing; payment card data is collected and processed directly by Adyen and is not stored by Tapi

<w:tcPr><w:tcW w:w="2175" w:type="dxa"/><w:tcMar><w:top w:type="dxa" w:w="60"/><w:left w:type="dxa" w:w="120"/><w:bottom w:type="dxa" w:w="30"/><w:right w:type="dxa" w:w="120"/></w:tcMar></w:tcPr><w:p><w:pPr><w:spacing w:before="120" w:after="120" w:line="288" w:lineRule="auto"/><w:ind w:left="0"/><w:jc w:val="left"/></w:pPr><w:r><w:rPr><w:rFonts w:eastAsia="等线" w:ascii="Arial" w:cs="Arial" w:hAnsi="Arial"/><w:sz w:val="22"/></w:rPr><w:t>European Union (Netherlands)

Note: providers of Connected Accounts that Customer chooses to link (e.g., Google Workspace, Slack, WhatsApp, Notion) are engaged by Customer, act under Customer's agreements with them, and are not Tapi Sub-processors.

Sub-processors

Last updated July 2026

Last updated:

Tapi (Knova AI, Inc.) uses a small number of third-party service providers — "sub-processors" — to help provide the Services. A sub-processor is a vendor we engage that may process Customer Content, including personal data, on our behalf.

Before engaging any sub-processor, we evaluate its security and privacy practices and put a written data protection agreement in place that holds it to obligations consistent with our Data Processing Agreement.

Current sub-processors

The tools you connect are not sub-processors

When you connect your own accounts to Tapi — Gmail, Google Sheets, Slack, WhatsApp, Notion, and other supported tools — those services act under your agreements with those providers. You choose which accounts to connect, what Tapi is instructed to do with them, and you can disconnect them at any time. They are your service providers, not our sub-processors.

How we handle our model provider

Task content is sent to our model provider, Anthropic, only to run your tasks. Anthropic's commercial API terms prohibit using customer content to train its models, and retention is limited to what is needed to provide the service and enforce acceptable-use policies.

Updates and notifications

We will update this page at least 15 days before a new sub-processor begins processing Customer Content, except for urgent replacements needed to keep the Services secure or available, which we will disclose here promptly afterwards.

Questions

Contact us at cam@tapi.ai

Sub-processorPurpose of processingLocation
Amazon Web Services, Inc.Cloud infrastructure: hosting, compute, storage, databases and backups; magic-link sign-in emails and service notifications (Amazon SES); usage analytics and application error monitoring (Amazon OpenSearch Service).United States
Composio, Inc.Integration infrastructure: manages OAuth connections and API calls between the Services and your Connected Accounts.United States
Anthropic, PBCLarge language model inference used to interpret instructions and generate outputs.United States
Adyen N.V.Payment processing for subscription and usage-based billing; payment card data is collected and processed directly by Adyen and is not stored by Tapi.European Union (Netherlands)
© 2026 TAPI, Inc. (Knova AI, Inc.)Questions? cam@tapi.ai