This policy explains how we collect, use, share, store, and protect your personal information when you use our website, apps, interfaces, and social or interactive services (collectively, the "Service").
1) Scope & Who We Are
This policy applies to all current and future Tapylapy products and services that reference it. You can contact the Data Controller at [email protected] for privacy-related requests, or at [email protected] for formal legal correspondence.
By using the Service, you acknowledge that you have read this policy. This policy explains how we process your data; where we rely on consent as the basis for processing, we ask for it separately and clearly, and merely using the Service is not treated as consent to that processing. The legal bases for processing are those set out in Section 6.
2) What We Collect
- Account data: name, email, username, language, country, and date of birth (used to verify the 18+ minimum age requirement).
- Content and interactions: posts, images, videos, messages, comments, likes, saves, follows, reports, and interaction history.
- Technical data: IP address, device type, operating system, browser, logs, session identifiers, and crash/performance data.
- Location data: approximate location from IP, and precise location only if you expressly allow it.
- Payment and identity-verification data: when you use top-up, gift, or reward-withdrawal features, we may collect data needed to complete the transaction, verify your identity, or prevent fraud and money laundering, as described in our AML/KYC Policy, typically through approved payment providers (including our card payment provider(s), alongside PayPal, Apple, and Google). Card and payment-method details are handled by the payment provider itself.
- Payments made without signing in: if you complete a top-up without signing in to your account, we receive only limited data: the account identifier you supplied (so the balance is added to the right account) and the outcome of the payment, while payment details are handled by the payment provider.
- Device permissions (camera, microphone, photo library, screen and device-audio capture): we access these only after you expressly grant permission through the operating system, and only for specific purposes: live streaming, audio/video calls between users, uploading photos and videos, and capturing your verification photo during identity checks. Screen and game/device-audio capture applies to gaming live streams only, and runs only when you start it and only while you are streaming.
- Call data: when you make an audio or video call with another user through the app, we store call metadata only (the parties, call type, start time and duration, and status) to show the call log in your conversation — we do not record or store the actual audio or video content of the call.
- Partner or integration data: when you connect your account to other services within lawful limits.
- Security and session data: when you use two-factor authentication or device management, we collect the device name, device ID, IP address, and browser/OS information, along with hashed security secrets (such as backup two-factor codes), for the purpose of protecting your account and detecting unauthorized access.
Even in "browse as guest" mode without an account, we may collect limited technical data (such as IP address and device type) for security, abuse-prevention, and general performance-measurement purposes, without linking it to a known personal identity.
Data From People Reporting Content From Outside the Platform (/report-content)
Our public content report form lets anyone — including people who do not have a Tapylapy account at all — report content that harms them. When you use this form, we collect your name, your email address, a link to the reported content, and a description of the harm to you, along with your IP address for security and abuse-prevention purposes. The legal basis for this collection is legitimate interest in enabling people affected by harmful content — including non-registered users — to report it and request review. For more on how this data is shared and how long we keep it, see Section 8 below.
3) Public, Private Content & Message Confidentiality
Some information on Tapylapy may be public by nature, such as public posts, display name, profile photo, follower counts, and certain interactions depending on your settings.
You are responsible for choosing appropriate privacy settings and understanding that public content may be viewed, shared, or archived by others.
Confidentiality of Private Messages & Chats
We treat your private messages in chats and conversations as confidential: we do not sell or share them with any external party, we do not use their content for advertising or marketing, we do not scan your private conversations automatically (no keyword, image, or AI scanning), and we do not proactively monitor them.
How messages are protected technically: the text of your messages is stored encrypted on our servers, and everything travels between your app and our servers over encrypted connections (HTTPS/WSS). This is server-side encryption, not end-to-end encryption, which means our systems are able to decrypt the text. Photos, videos, and voice notes in chats are stored on our CDN under unlisted links that are hard to guess, and they are not encrypted at rest; anyone who has a link can open it, so do not share your media links with people you do not want to see them.
The only exception to our staff not looking at conversations is when a report is submitted: our staff can open a chat only through a report. If a participant reports a single message, our safety team sees the reported message together with the surrounding messages (about 15 before and 15 after it); if the report concerns a whole conversation or group, they see the full conversation. This may also be made available to competent authorities where there is a valid legal obligation or a serious safety risk, to the extent needed to deal with the matter. This approach is similar to that used by major social platforms.
The purpose of viewing the surrounding messages (or the full conversation for a conversation-level report) is to verify the report and sufficiently understand its circumstances, which helps prevent misuse of the reporting tool and ensures the accuracy of the resulting decision. This access remains limited to the safety team and to what is necessary to investigate that report. Messages copied into a report may be kept for moderation purposes (see Section 11).
For more on how reports work and are handled, see our Safety Policy.
4) Why We Use It
- To operate the Service, create accounts, authenticate logins, and provide core features, including verifying the 18+ minimum age requirement.
- To personalize feeds, recommendations, search, and relevant content.
- We build a per-user preference profile (embeddings) from your content and interactions (such as text, audio transcripts, and preview images), through approved AI providers, to personalize your feed and recommendations; this profile is automatically deleted when you fully delete your account, and it is not used for any purpose outside improving your experience on the platform. This particular recommendation-profile task may instead be processed on self-hosted infrastructure operated directly by Tapylapy, without transferring your data to any external party; the option actually in use is configurable per tool from the admin panel, as described in Section 8.
- To run social features such as follows, messaging, notifications, engagement tools, and suggestions.
- To improve security and prevent fraud, impersonation, abuse, intrusions, and unlawful defamation.
- To verify identity and combat money laundering when gift or reward-withdrawal features are used, as described in our AML/KYC Policy.
- To analyze performance, improve quality, build features, and understand how the Service is used.
- To manage user-created self-promotional ads, measure their performance, and reduce misleading or unlawful ads.
- AI tools: content-safety scanning (e.g. detecting inappropriate content in live streams), audio transcription, machine translation, the in-app AI assistant, and photo-comparison support during identity verification — through approved external providers, detailed in Section 8 below. For the photo comparison during identity verification, we do not store a face template or any biometric template: the two images are sent to the comparison service and nothing is kept from it.
- Automated matching against blocked reference images: as part of our content-safety scanning systems, we use an automated system that compares certain uploaded content against blocked reference images (such as images of specific individuals whose content our administration has decided to block for violating our policies) to help detect repeat uploads of blocked content. This comparison runs automatically and is not used to create or retain a permanent biometric profile of an ordinary user's face or identity.
- We use AI tools to suggest titles, descriptions, hashtags, and video covers based on your content when you post, to help you save time; using any of these suggestions is entirely optional.
- We may occasionally send you marketing or informational emails or push notifications about new features or offers, in addition to necessary operational and security messages (such as verification codes and password-reset links, which cannot be opted out of because they are necessary for your account's security). You can unsubscribe from marketing messages via the link included in each such message.
- To comply with legal obligations and protect users, rights, the platform, and the public.
5) No Trading in Personal Data
We do not sell your personal data, and we do not share it with third parties for cross-context behavioural advertising. We share data only with the service providers and other recipients described in Section 8, and for the purposes described there.
SULTAN X LTD commits not to trade in users' personal information in a manner that violates the law or exceeds what is lawfully necessary to operate, protect, and improve the Service.
We commit not to sell, buy, rent, barter, take, or give personal information about any individual outside the law or outside what is legitimately necessary for platform operation, service delivery, safety, or legal compliance.
Nothing in this policy may be interpreted as permitting Tapylapy to turn your personal information into a standalone commercial commodity merely for profit.
6) Legal Bases (EEA/UK/CH)
Note: Under the Geographic Restrictions in our Terms of Service, Tapylapy is not currently available to anyone located in the EU/EEA, Switzerland, or Liechtenstein; this section applies to the United Kingdom as current users, and to users from those other regions only as former users for as long as we hold data about them — see Annex (B) below for detail.
We process data based on: Legitimate interests (to operate, secure, and improve), Contract performance (to provide features you use), Legal obligation (to comply with law, including anti-money-laundering obligations), and Consent (where the law requires it, such as for non-essential cookies, precise location, or some types of marketing).
Where we rely on consent, you may withdraw it at any time through available settings or by contacting us.
In particular, processing of identity documents, official documents, and biometric selfie images — a special (sensitive) category of data — that you provide when registering specifically for verification or to activate reward withdrawals is based on your explicit consent, given at the time of that specific action, rather than on the legitimate-interest basis applied to the other data categories described in this policy. You may withdraw this consent at any time by contacting us, noting that doing so may prevent you from completing verification or activating or continuing to use reward withdrawals. Withdrawing your consent to the processing of particular data does not, however, cancel Tapylapy's separate legal obligation to retain specified data (such as the approved identity-verification records referenced in Section 11) for the period stated there where applicable law requires it, regardless of that withdrawal.
7) Cookies
We use cookies and similar technologies to run the Service, maintain sessions, remember preferences, improve performance, and measure usage.
Essential, strictly-necessary cookies (such as session cookies and language preference) are required to run the Service and do not require consent to be activated. We may also use optional analytics/performance and self-promotion-ad cookies to understand and improve usage of the Service, which are activated only with your consent where required by law. You can manage or delete your cookie preferences at any time through your browser settings.
8) Who We Share Data With
- Service providers: hosting, security, support, email, analytics, and fraud prevention vendors under appropriate agreements.
- Resend: we use Resend as a technical provider for sending emails (such as verification codes, password-reset links, and email campaigns), through infrastructure configured to automatically fail over to an alternate mail server we operate if delivery through it is unsuccessful.
- Google Firebase: we use Firebase (Google) services to power crash reporting (Crashlytics) and push notifications (Firebase Cloud Messaging) — limited technical data (device identifier, crash logs, notification token) is shared with it, only as needed for these services.
- Sign in with Google (Google OAuth): if you choose to sign in using your Google account, Google shares basic profile data with us (such as your name and email) after your consent, to create or authenticate your account; this feature is separate from our use of Firebase services described above.
- Sign in with Apple: if you choose to sign in using your Apple ID on iOS devices, Apple shares basic identity data with us for authentication purposes (such as your unique Apple identifier, and your email only on the first sign-in) after your consent, to create or authenticate your account; this feature is separate from our use of the App Store Server API described below.
- LiveKit: we rely on LiveKit infrastructure to power live audio/video streaming, live battles, and audio/video calls between users. We run two LiveKit deployments in parallel: a self-hosted server fully operated by Tapylapy, and the LiveKit Cloud service as a technical alternative; only the Cloud variant (LiveKit Cloud) constitutes a third party, where the media data necessary to run the session is processed through its infrastructure.
- Payment and identity-verification providers: where top-up, gift, or reward-withdrawal features are enabled.
- PayPal: if you choose to pay via PayPal to purchase in-app coins, your payment data is processed directly by PayPal under its own privacy policy.
- Card payment providers: coins can be bought through Apple In-App Purchase (iOS), Google Play Billing (Android) and, where we offer them, PayPal or card payment through our payment providers. When you pay by card, your card and payment details are processed directly by the payment provider under its own privacy policy, and we receive from it the outcome of the transaction and the information needed to credit the right account, including when the payment is made without signing in.
- Apple In-App Purchases (App Store Server API): when you purchase through the Apple App Store on iOS devices, Apple processes your payment and billing data, and we use the App Store Server API to validate purchases and their status.
- Google Play Billing: when you purchase through Google Play on Android devices, Google processes your payment and billing data, and we use the Google Play Billing API to validate purchases and their status.
- AI service providers: we use approved external AI providers — primarily OpenAI, and occasionally Cloudflare (Workers AI) as a technical alternative — to power features such as live-stream content-safety scanning, audio transcription, machine translation, the AI assistant, discovery/recommendation improvements, and photo-comparison support during identity verification (see our AML/KYC Policy). Only the minimum data (text, image, or audio) needed for the specific task is sent to these providers. These providers are based in the United States and are subject to the same international-transfer safeguards described in Section 10. Some of these tools — specifically the verification-photo comparison used during identity checks, and the recommendation-profile (embeddings) building described in Section 4 above — may instead be processed on self-hosted infrastructure operated directly by Tapylapy, without transferring your data or photos to any external party; the option actually in use — an external provider or self-hosted infrastructure — is configurable per tool from the admin panel.
- Cloudflare R2: we store media files (images and videos) using the Cloudflare R2 cloud storage service; this use is separate from Cloudflare's AI role (Workers AI) described above.
- Cloudflare Turnstile: we use the Cloudflare Turnstile service to verify that whoever submits our public content report form (see Section 2 above) is a real person, not a bot; this use is separate from our other uses of Cloudflare services (R2 storage, and Workers AI as a technical alternative for some AI tools) described elsewhere in this section.
- Klipy: we use the Klipy service to power GIF and sticker search inside chat, comments, the post composer, and Notes. When you use this feature, the search terms you type are sent to Klipy, through our server, to return the requested results.
- Jamendo: we use the Jamendo licensed music catalogue as a source for some of the audio tracks available in the in-app sound library (for use in posts and reels).
- Photon (by Komoot): we use Komoot's Photon geocoding service to power location-name search when you add a location sticker to your Story; the search text you type is sent to this service, through our server, to return matching place results.
- Apple APNs (call notifications on iOS): to alert iOS users of an incoming call even when the app is fully closed, we send a VoIP-type push notification directly to Apple's servers (APNs) — separately from Firebase, which does not support this notification type — containing the minimum call data needed to display it via iOS's native call interface (CallKit).
- Affiliates or lawful successors: in connection with mergers, acquisitions, or restructuring.
- Competent authorities: when legally required or necessary to protect rights, safety, public order, or for anti-money-laundering purposes.
YouTube API Services: the app uses YouTube API Services to let a live-stream host search for YouTube videos and share them, synchronized, with viewers in a live audio chat room. When this feature is used, search terms are sent to YouTube/Google through our server, and the chosen video is displayed via YouTube's own official embedded player. We do not require the user to sign in with a Google or YouTube account to use this feature, and we do not download or store any YouTube video content on our servers. The embedded YouTube player may set its own cookies or identifiers under YouTube/Google's policies; we do not add cookies or device identifiers of our own specifically for this feature. Search results are cached on our server for a maximum of 10 minutes (keyed by the search query itself, not by user or device) to reduce API quota usage and are deleted automatically afterward, and a room's video-playback state is cached for a maximum of 6 hours or until the host ends the live stream or stops the video, whichever comes first. By using this feature, you agree to be bound by the YouTube Terms of Service. You can review the Google Privacy Policy to learn how Google/YouTube collects and processes data, and you can review or revoke any access permissions on your Google account at any time via the Google Account permissions page. Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
If you enter into a business relationship with Tapylapy that requires signing a Data Processing Agreement (DPA), we are willing to consider signing an appropriate agreement upon request, subject to agreed commercial terms.
Retention period for external content-report form data: we retain the data collected through our public content report form (described in Section 2 above) for 12 months from the date the report is closed, as a reasonable default retention period, unless a longer period is needed to preserve evidence related to serious violations (such as CSAE content), in which case that specific evidence is subject to its own retention rules described in Section 11.
9) Legal Requests & Authorities
Our default position is to protect user privacy and not disclose personal information without a valid legal basis.
However, if we receive a valid and binding legal request from a competent court or authority, and the request is specific, legitimate, and related to alleged unlawful conduct, we may review and respond to that request as required by law.
For users who are not subject to valid legal demands, we do not have the right to disclose their personal information arbitrarily or outside the law.
Responding to any request from a governmental or law-enforcement authority requires that the request be issued in the legally correct form (such as a court order or an official request signed by a competent authority) and be clearly defined in scope; in emergency situations involving imminent danger to life, we may act on an urgent request before all formalities are completed. Where the law permits and unless we are expressly prohibited from doing so (such as by a court-ordered non-disclosure order), we seek to notify the affected user that a request exists.
10) International Transfers
SULTAN X LTD is a company registered in the United Kingdom, and some data may be stored or processed in the United Kingdom or outside your country of residence, subject to appropriate safeguards where required by law. For transfers of data from the United Kingdom to a recipient outside it, we rely, as applicable, on UK adequacy regulations, the UK-US data bridge where the recipient is certified under it, or the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
Under the Geographic Restrictions in our Terms of Service, the Service is not offered or directed to anyone in the European Union, the European Economic Area, Switzerland, or Liechtenstein, and we do not target these markets in any way (no dedicated language, currency, or marketing directed at them). For this reason, Article 27 of the GDPR does not require us to appoint an EU representative. That said, as a matter of good faith toward any former user whose data was collected before this restriction took effect, we will continue to respond to rights requests and privacy-related correspondence in accordance with applicable law via [email protected].
11) Security & Deletion
We apply reasonable technical and organizational measures to protect data against unauthorized access, alteration, disclosure, destruction, or misuse.
Data breach response: in the event of a material data breach likely to pose a risk to your rights or freedoms, Tapylapy is committed to notifying affected users and the relevant regulatory authorities as required by applicable law. Under the UK GDPR, we notify the UK Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to individuals' rights and freedoms; we also notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
How long we keep data depends on its type, as set out below. Account deletion is immediate and permanent: when you delete your account under our Account Deletion Policy, we immediately delete your profile, posts, stories, comments, likes, follows, the messages you sent, notifications, push tokens, devices, sessions, wallet, transactions, earnings, VIP subscriptions, and coin orders.
What remains after your account is deleted
- An anonymised deletion record showing that the deletion took place.
- Anonymised financial ledger entries: your personal financial records are deleted at once; only an anonymised accounting ledger remains, with no personal identifiers.
- Approved identity-verification records, including the photos, are kept for up to 5 years after the account is closed, in line with anti-money-laundering obligations (see our AML/KYC Policy). Rejected or pending verification records are deleted at once.
- Reports about the account and the identity snapshot attached to them, and abuse-prevention records (such as IP or device blocks): kept for as long as necessary for security, fraud-prevention, and moderation purposes.
- Email delivery logs (recipient, subject, status): kept for as long as necessary for security, fraud-prevention, and moderation purposes.
- Evidence of serious violations (such as child sexual abuse/exploitation material, CSAE): kept for as long as necessary to cooperate with the relevant law enforcement authorities, in line with our legal obligations described in our Safety Policy.
- Ban-appeal record (the appeal's written message, the decision and the administrator's note): kept for one year from the decision date and then deleted automatically, per our Safety Policy. Identity photos requested in specific cases as part of an appeal are permanently and immediately deleted when the decision is issued and are not covered by this exception.
- Limited technical backups may persist for a short period not exceeding 30 days before permanent deletion.
How long we keep each type of data
- Chat messages: kept until you or the other participants delete them; deleting a message that has media removes that media from our storage at once. In one-to-one chats where the disappearing-messages timer is on (24 hours, 7 days or 90 days; either person can change or stop it), new messages are permanently deleted from our servers — text and media together — when the chosen time is up and we cannot recover them afterwards (apart from what may remain in encrypted technical backups for no more than 30 days); messages sent before it was turned on are not affected. This does not stop the other person from taking a screenshot or copying a message before it disappears. Messages copied into a report may be kept for moderation purposes, and if disappearing messages are reported, a copy of them (and of their files) is kept inside the report only, for the review team only, without delaying their deletion from the chat, and is permanently deleted when the report is closed or rejected, and the text of group-moderated messages is cleared after 30 days. The call log (who called, when, and for how long) is kept with the conversation; we do not record calls or live streams.
- Identity verification: the ID photos and selfie of an approved verification stay while the account is active (and afterwards as described above); rejected or revoked ones are wiped at once; the monthly re-verification selfie is deleted when that cycle is decided; identity photos submitted with a ban appeal (in specific cases only) are permanently and immediately deleted when the decision is issued, and the written appeal record is kept for one year from the decision. We do not store a face template or any biometric template: the comparison is done by sending the two images to the comparison service, and nothing is kept from it.
- Stories disappear after 24 hours. Live chat is held only temporarily (about 6 hours). Deleted posts are removed at once. Deleted comments are erased permanently after 90 days.
- Activity and analytics events are pruned periodically, between 90 and 730 days (feed impressions 90 days, interaction events 180 days, post views 730 days). Notifications: 180 days. Search-suggestion data: 30 days.
- Sign-in tokens are valid for a rolling 90 days. Sign-in, device, and IP records are kept while the account exists. Some security block lists are kept until an administrator removes them.
Where we have no fixed period (such as email delivery logs, abuse-prevention blocks, and reports), we keep the data for as long as necessary for security, fraud-prevention, and moderation purposes.
12) Social Platform Features
As a social platform, Tapylapy may offer features such as user profiles, follows, notifications, suggested content, messaging, public posting, engagement features, reporting tools, blocking, muting, verification, and tags or labels.
Having your account's social verification badge (blue or gold) is a completely separate process from the financial identity verification (KYC) required to activate reward-withdrawal eligibility, and does not automatically grant that eligibility. The verification badge is a public mark showing that the account belongs to a known user with real, verified information; on its own it does not make anyone a creator and does not allow withdrawals. Activating withdrawals requires independently completing the financial verification procedures described in our AML/KYC Policy. For details on the difference between Blue and Gold Verification and the requirements for each, see our AML/KYC Policy.
Tapylapy may grant the social verification badge to individuals or entities who are publicly known (such as public figures, officials, or business people) through an internal verification process based on trusted public sources, as an alternative to the standard document-submission pathway, at its sole discretion; Tapylapy reserves the right to withdraw this verification at any time if it turns out to have been granted in error or the account does not genuinely represent the person it claims to be.
For VIP subscribers, we offer a feature that lets them see who has recently visited their profile; this means your activity browsing other users' profiles may be revealed to the profile owner if they are a VIP subscriber. The platform also lets you add private "relationship badges" on one-to-one conversations, visible only to the person who added them and not shared with the other party or any third party.
The platform may also show, on another user's profile, suggestions such as "also followed by people you know"; this feature reveals overlaps between your follow network and the follow networks of other users viewing that same profile, in order to suggest accounts relevant to your connections.
Live streams also publicly display supporter and top-supporter leaderboards, which reveal a user's in-app coin spending level to everyone else present in that stream, unless the user is eligible for and has enabled "Invisible Man" mode, which lets them opt out of this visibility.
We may use technical and behavioral indicators to detect fake, abusive, or deceptive accounts and to protect the digital safety of the platform and its users.
13) Your Rights
Depending on applicable law, your rights may include: access, correction, deletion, restriction, objection to certain processing, withdrawal of consent, opt-out from non-essential tracking as the law allows, and data portability. (We do not currently offer a separate setting to turn off ad personalisation; you can, however, mark a sponsored post "Not interested", hide its creator, or report it, as described in Section 15.) We honor Global Privacy Control (GPC) where required by law.
Automated decisions: you can ask for a human review of any automated decision that has a legal or similarly significant effect on you (for example automated content or verification checks), and you can express your point of view and contest the decision, through our support channels or by contacting [email protected]. We will respond to your request within one month.
Applicable law for UK users and supervisory authority: for users in the United Kingdom, we process your data in accordance with the UK GDPR and the Data Protection Act 2018. You have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
Time to respond to rights requests: we respond to requests to exercise your rights within one month of receiving them. Where the law permits, this period may be extended by up to two further months for complex or numerous requests, and we will tell you so, with the reason, within the first month.
You can exercise these rights through settings or by contacting: [email protected].
14) Data of Persons Under 18
Tapylapy does not permit use of the Service by anyone under 18 years old. If we learn that an account belongs to a person under this age, we immediately suspend or delete the account, including deleting that person's data under our Account Deletion Policy.
If you are a parent or guardian and believe a person under 18 has created a Tapylapy account, please contact us immediately at [email protected] and we will review and delete the account without delay.
15) Ads & Reputation-Sensitive Content
Any user may create self-made promotional or advertising content directly from their regular personal account (no separate business account is required), and we attempt to label it appropriately. Paid promotion slots are placed only in the feeds of signed-in users whose date of birth confirms they are 18 or older; a promoted post can also appear as an ordinary post, always labelled "Promoted", to visitors without an account or to accounts without a confirmed age. Every registered account must confirm it is 18+ at sign-up. You can see that a post is sponsored, mark it "Not interested", hide its creator, or report it like any other post. We do not currently offer a separate setting to turn off ad personalisation, and "Why this post" currently says only that the post is sponsored. We also provide ways to report impersonation, trademark misuse, unlawful defamation, misleading advertising, and other content that may unlawfully harm reputation or rights.
16) Abuse, Reporting & Enforcement
We may monitor certain technical and behavioral signals for security, anti-fraud, anti-spam, and anti-abuse purposes. We provide reporting tools for unlawful or policy-violating content and reserve the right to take action such as restricting content, removing material, or suspending accounts where legally appropriate.
17) Indemnification
Any indemnification obligation relating to this policy is governed by the comprehensive clause in our Terms of Service.
18) Changes to This Policy
We may update this policy from time to time. The latest version will be posted on the website or app. For material changes we will give reasonable advance notice (at least 14 days, except where a change is required by law or needed urgently to protect safety) through the app or by email. If you continue to use the Service after the effective date, the updated version applies to you where the law allows; if you do not agree, you may stop using the Service and close your account.
19) Contact
For privacy questions, data requests, or rights-related inquiries: [email protected].
For formal legal correspondence addressed to the Data Controller: [email protected].
For users in the United Kingdom, the processing of your data is governed by the UK GDPR and the Data Protection Act 2018, and you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
Owner & Operator: SULTAN X LTD — a company registered in England, United Kingdom, company number 17198402. Registered address: Flat 15, Aneurin Bevan Court, 55 Coles Green Road, London NW2 6EE, United Kingdom.
The Arabic and English versions of this policy are meant to say the same thing and both apply. If they differ, the version in the language you use the service in (the language selected in the app or on the page) applies to you.
Regional Annexes (Short)
(A) U.S. State Privacy Notice
If you are a resident of a U.S. state with applicable privacy laws, you may have additional rights such as access, correction, deletion, portability, and opt-out rights relating to certain forms of sale, sharing, or targeted advertising as defined by local law. As stated in Section 5, we do not sell your personal data and we do not share it for cross-context behavioural advertising. We honor GPC where required by law.
(B) GDPR Notice — EEA/UK/Switzerland/Liechtenstein
Note: Under the Geographic Restrictions in our Terms of Service, Tapylapy is not currently available to anyone located in the EU, EEA, Switzerland, Norway, Iceland, or Liechtenstein. This annex remains in force for any user from these regions for as long as we hold data about them, and for the United Kingdom, which is not among the restricted territories.
For users in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply, and you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk; we respond to rights requests within one month (extendable by up to two further months where the law permits).
If you are subject to the EU GDPR or similar rules, you may have enhanced rights such as restriction, objection, withdrawal of consent, portability, and the right to complain to the competent supervisory authority in your country of residence or work. As noted in Section 10, because the Service is not offered or directed to the EU/EEA/Switzerland/Liechtenstein, Article 27 GDPR does not require SULTAN X LTD to appoint a representative there — but we respond to legitimate requests as required by law.