Summary: We encrypt data in transit, host in secure environments, comply with UK GDPR, and never sell your contact data. You control what appears on your digital card.
Our commitment
Contaps is built for professionals who share contact details and capture leads every day. Security and privacy are core to that promise-not an afterthought.
Data protection (UK GDPR)
We process personal data in line with UK GDPR and the Data Protection Act 2018:
- We collect only what we need to run the service.
- We use clear legal bases for processing (see our Privacy Policy).
- We respond to data subject requests within statutory timeframes.
- We use data processing agreements with subprocessors where required.
- We do not sell personal data to third parties.
Security measures
- Encryption in transit - traffic to Contaps is served over HTTPS (TLS).
- Password protection - passwords are stored using industry-standard hashing; we never store plain-text passwords.
- Access controls - role-based permissions for company admins, team members, and platform administrators.
- Payment security - card payments are handled by Stripe; we do not store full payment card numbers on our servers.
- Monitoring - activity logging and administrative controls to detect misuse.
- Backups and recovery - regular backups to support business continuity.
Your data on digital cards
Information on your public card profile is visible to people you share it with (via NFC tap, QR code, or link). You choose what fields to publish. Lead-capture forms collect data you configure; you are responsible for using that data in compliance with applicable marketing and privacy laws.
Company and team accounts
Company administrators may manage cards and view contacts for their organisation according to their role. We recommend assigning admin access only to trusted individuals and reviewing team permissions regularly.
Data location and subprocessors
Our infrastructure and key providers may process data in the UK and, where necessary, in other countries with appropriate safeguards. We vet providers for security and contractual data protection commitments.
Incident response
If we become aware of a personal data breach likely to affect your rights, we will investigate promptly and notify you and/or the ICO where required by law.
Your responsibilities
- Use a strong, unique password and keep it confidential.
- Log out on shared devices.
- Only collect contact information you are entitled to process.
- Report suspected unauthorised access to us immediately.
Reporting a concern
Security or privacy questions: noreply@contaps.co. You may also contact the ICO at ico.org.uk.