Legal
Operator Agreements
Every third party that processes personal information on our behalf, what they touch, where they sit, and the contract that binds them. Published in full rather than summarised.
- Last updated 7 September 2026
- Embrisk is operated by Tapnet Solutions (Pty) Ltd.
1. Purpose
Under Section 21 of POPIA, when Tapnet Solutions (Pty) Ltd (the responsible party) engages a third party (an "operator") to process personal information on our behalf, we must ensure that operator provides adequate data protection through a written agreement.
This page lists every operator that processes personal information for Embrisk and other Tapnet Solutions (Pty) Ltd services, what they process, where they are located, and what contractual protections are in place.
2. Operators
Vercel Inc.: Website and application hosting
| What they process | HTTP requests, server rendered pages, serverless function execution, cached content, and edge server logs |
| Location | Global edge network, primary compute in the US and EU |
| Agreement | Vercel Data Processing Addendum. Vercel is SOC 2 Type II certified. |
| Security | Automatic TLS, DDoS protection, edge network, encrypted at rest |
| Sub processors | AWS (multiple regions) |
Neon Inc.: PostgreSQL database
| What they process | Platform application data: workspace and user accounts, client projects, tracked prompts, sampled results and generated reports |
| Location | Frankfurt, Germany (EU). The region is selected to provide adequate protection under POPIA Section 72(1)(a) via the EU GDPR framework. |
| Agreement | Neon Data Processing Addendum. SOC 2 Type II certified, ISO 27001 aligned. |
| Security | TLS with channel binding on all connections, encryption at rest, automated point-in-time recovery, private network isolation between projects |
| Sub processors | AWS (eu-central-1) |
| Data minimisation | Raw IP addresses are never stored, only salted SHA-256 hashes |
Upstash Inc.: Rate limit store (Redis)
| What they process | Short lived rate limit counters keyed by hashed IP or email. No personal data is persisted long term. |
| Location | Ireland (EU). Covered by EU GDPR. |
| Agreement | Upstash Data Processing Agreement. SOC 2 Type II certified. |
| Security | TLS 1.3 for all API traffic, per-database access tokens, encryption at rest |
| Retention | Rate limit keys auto-expire within 24 hours. No writes are permanent. |
Google LLC: Workspace and email
| What they process | Inbound and outbound email at wynand@tapnet.co.za, including demo requests, plus documents, calendars and meeting notes created during a customer relationship |
| Location | United States and EU (Google global infrastructure) |
| Agreement | Google Workspace Data Processing Amendment. ISO 27001, SOC 2 and SOC 3 certified. |
| Security | OAuth 2.0, two factor authentication, encryption at rest and in transit |
GitHub Inc.: Source code hosting
| What they process | Platform source code, commit history and engineering collaboration records |
| Location | United States |
| Agreement | GitHub Data Protection Agreement. SOC 2 Type II certified. |
| Security | Encryption at rest and in transit, 2FA enforced on all team accounts, SSH key authentication for deployments |
| Note | Source code does not contain customer personal information |
3. Requirements for all operators
In line with POPIA Section 21, every operator agreement requires the operator to:
- Process personal information only on our documented instructions
- Maintain confidentiality of all personal information processed
- Implement appropriate technical and organisational security measures
- Notify us of any data breach as soon as reasonably possible
- Not engage sub operators without our knowledge
- Delete or return all personal information on termination of the agreement
- Allow for audits and inspections to verify compliance
4. Contractors and freelancers
Any contractor, freelance developer, writer or designer who accesses personal information on behalf of Tapnet Solutions (Pty) Ltd is required to sign a confidentiality and data processing agreement before being granted access. That agreement includes:
- An obligation to process data only as instructed
- Confidentiality obligations surviving termination
- A prohibition on copying or exporting personal information
- Immediate notification of any suspected breach
- Return or destruction of data on completion of the engagement
Access to production systems is granted on a need-to-know basis only, using separate credentials that are revoked within one working day of the engagement ending.
5. Liability
Under POPIA, Tapnet Solutions (Pty) Ltd remains the responsible party even when personal information is processed by an operator. If an operator causes a data breach or misuses personal information, Tapnet Solutions (Pty) Ltd is liable to affected data subjects. We may then seek recourse from the operator under our contractual agreements.
This is why we select operators with strong security practices and adequate data protection certifications, and why the list above is short.
6. Review
Operator agreements and this list are reviewed annually, and whenever a new operator is engaged or an existing one is replaced. The Information Officer is responsible for maintaining the list and ensuring the agreements are in place.
7. Contact
- Responsible party: Tapnet Solutions (Pty) Ltd
- Information Officer: Wynand de Beer
- Phone: 079 174 8357
- Email: wynand@tapnet.co.za
For the wider picture of what we collect and why, see the Privacy Policy.
Other legal documents