UXTap
  • UXTap

    • Protótipos Figma
    • Sites reais
    • Entrevistas com IA
    • Pesquisa contínua
    • Arquitetura da informação
    • Teste de preferência
    • Teste de conteúdo
    • Resultados e repositório
    Todos os recursos
  • Grupo TAP

    • Painel TAP
    • OpinaTAP
    • VisionCX
    • ZapTap
    • QualiTAP
    • AnáliseTAP
    • UXTap
  • Como funciona
  • Recrutamento
  • Preços
  • Blog
PT·ES·ENEntrarCriar conta grátis
Draft — pending legal review

Personal Data Processing Agreement

Attachment to the contract: UXTap as the operator of the data of your study participants.

Version 1.0 · in effect since September 4, 2026

Courtesy translation. In case of divergence, the Portuguese version prevails. View Portuguese version

In plain language

  • This document is valid when you use UXTap to collect participant data.
  • You are the controller: you decide what to ask, to whom, and why. We are the operator: we execute what you configured.
  • We only process this data to provide the service, never for our own purposes.
  • We list who else touches the data, what we do to protect it, and what happens when something goes wrong.
  • At the end of the contract, you choose between receiving the data back or having it deleted.

This summary helps to understand, but does not replace the text of the clauses below.

1. Parties and subject matter2. Description of processing3. Roles and responsibilities4. Documented instructions5. Confidentiality and authorized personnel6. Sub-processors7. Technical and organizational measures8. Support to the Controller9. Security incidents10. Retention, return, and deletion11. International transfer12. Audit13. Term and final provisions

1. Parties and subject matter

On one side, the Client, a natural or legal person holding the UXTap account, as Controller. On the other side, Painel TAP, CNPJ 59.701.681/0001-68, operator of the UXTap platform, as Operator.

  1. 1.1This attachment is an integral part of the Terms of Use and governs the processing of personal data of participants in studies created by the Client.
  2. 1.2In case of conflict between this attachment and the Terms of Use regarding data protection, this attachment shall prevail.
  3. 1.3Regarding the Client's registration and account usage data, Painel TAP acts as Controller, as per the Privacy Policy, and this attachment does not apply.

2. Description of processing

  1. 2.1Purpose: collection and processing of participant responses and behavior in usability and research studies configured by the Client.
  2. 2.2Nature and purpose: to host the study, collect responses, record interactions, record session when the Client enables and the participant consents, generate analyses, reports, and transcripts for the Client.
  3. 2.3Duration: for the duration of the contract, subject to the retention periods of clause 10.
  4. 2.4Categories of data subjects: participants invited by the Client, via open link or via recruitment panel.
  5. 2.5Categories of data: responses, including free text; click coordinates, screens visited, scrolling and timings; technical data of device, browser, and language; opaque identifier and panel variables; screen recording; voice audio; screenshots of real website, when applicable.
  6. 2.6We do not request from the participant any document, password, or financial data. If the Client configures questions that capture sensitive data, that decision and its legal basis are exclusively theirs.

3. Roles and responsibilities

  1. 3.1The Controller defines essential purposes and means, chooses the legal basis, informs the participant, obtains consent when necessary, and responds to data subjects' requests.
  2. 3.2The Processor processes data only according to the Controller's documented instructions, represented by the configurations made on the platform and by this addendum.
  3. 3.3The Processor will inform the Controller if, in its assessment, an instruction violates data protection legislation, and may suspend execution until clarification.
  4. 3.4The Processor does not use participant data for its own purposes, does not commercialize them, and does not use them to train its own models.

4. Documented instructions

  1. 4.1The Controller's instructions are: the study configuration, the choice of blocks and questions, the activation or deactivation of recording and audio, the language, the plan's retention period, the recruitment panel configuration, and the deletion actions performed on the panel.
  2. 4.2Additional instructions must be sent in writing to privacidade@uxtap.app and may imply a scope or price adjustment if they require development.

5. Confidentiality and authorized personnel

  1. 5.1Access to data is restricted to personnel who need it to operate and provide support, subject to a duty of confidentiality.
  2. 5.2Administrative access is limited to email addresses authorized by configuration, and every administrative action is recorded in an audit trail with author, action, target, and date.

6. Sub-processors

  1. 6.1The Controller generally authorizes the engagement of the sub-processors listed and kept updated at uxtap.app/subprocessadores, with purpose, data processed, and hosting country.
  2. 6.2The inclusion of a new sub-processor that processes participant data is announced 30 days in advance on this page.
  3. 6.3The Controller may object with justification. If there is no reasonable technical alternative, they may terminate the contract without penalty for the unused period.
  4. 6.4The Processor is liable to the Controller for the acts of its sub-processors with regard to this addendum.

7. Technical and organizational measures

The measures below are implemented as of the date of this version.

  1. 7.1Encryption in transit via HTTPS throughout the application, with HSTS and security headers (nosniff, referrer-policy).
  2. 7.2Password authentication with storage of only bcrypt cryptographic hash, and session signed with server secret.
  3. 7.3Role-based authorization, verified on the server with each request, with association read directly from the database.
  4. 7.4Recordings and audios in a private bucket, without a public URL, with access only via a short-lived, 1-hour signed link.
  5. 7.5Third-party integration tokens encrypted with AES-256-GCM at rest.
  6. 7.6Isolation by workspace in all read and write queries for study data.
  7. 7.7Limitation of requests per address and per session on public routes, and daily consumption caps per account, to contain abuse and cost.
  8. 7.8Collection event logging with deduplication, preventing duplicate responses due to resubmission.
  9. 7.9Error monitoring with prior sanitization, without request body or response content.
  10. 7.10Backups managed by the database provider, with encryption at rest.
  11. 7.11Automatic purge routine for expired recordings according to the plan's term.

The Processor maintains a program for the evolution of these measures. Items not yet implemented, such as second factor authentication and external certification, are not subject to contractual commitment in this version.

8. Support to the Controller

  1. 8.1The Processor provides resources in the product for the Controller to assist data subjects: response export, session deletion with its media, recording deletion, and study deletion.
  2. 8.2Upon receiving a data subject's request directly, the Processor does not respond to the merits and forwards it to the Controller within 3 business days, unless it can address it itself, in which case it informs the Controller.
  3. 8.3The Processor supports the Controller in preparing an impact assessment report and in responding to authorities, with regard to information under its domain.

9. Security incidents

  1. 9.1The Processor communicates to the Controller without undue delay, and within a maximum of 48 hours of becoming aware, of an incident that may entail significant risk or damage to the data under its responsibility.
  2. 9.2The communication indicates the nature of the incident, the affected data and data subjects, the measures adopted, the risks involved, and the contact for clarification.
  3. 9.3Communication to the ANPD and to data subjects, when applicable, is the Controller's obligation, observing the deadlines of Resolution CD/ANPD nº 15/2024, with the Processor's support.
  4. 9.4The Processor maintains a record of incidents and measures taken.

10. Retention, return, and deletion

  1. 10.1Recordings and audios are automatically deleted at the end of the contracted plan's retention period.
  2. 10.2Other participant data remains as long as the study exists in the account or until deletion commanded by the Controller.
  3. 10.3Upon termination of the contract, the Controller has 30 days to export the data. After this period, the Processor deletes participant data within 60 days, unless there is a legal obligation to retain it.
  4. 10.4Deletion covers database records and corresponding files in object storage. Backups are deleted in the normal rotation cycle.
  5. 10.5Upon request, the Processor issues a declaration of deletion.

11. International transfer

  1. 11.1Part of the processing occurs outside Brazil, as per the sub-processors page.
  2. 11.2Transfers rely on the standard contractual clauses approved by Resolution CD/ANPD nº 19/2024 or on another legitimate mechanism provided for in articles 33 to 36 of the General Data Protection Law.
  3. 11.3In case of conflict, the ANPD's standard clauses prevail over conflicting provisions of this addendum.

12. Audit

  1. 12.1The Processor provides, upon written request and once a year, reasonable information to demonstrate compliance with this addendum, including a description of technical measures and a response to a security questionnaire.
  2. 12.2On-site audit or by an independent third party may be agreed upon in a specific contract, with 30 days' notice, during business hours, without interruption of operation and subject to confidentiality, with costs borne by the Controller.

13. Term and final provisions

  1. 13.1This addendum remains in force for as long as the Processor processes participant data on behalf of the Controller.
  2. 13.2The obligations of confidentiality, deletion, and cooperation survive termination.
  3. 13.3Relevant changes will be published on this page 30 days in advance, applying the rule of justified objection from clause 6.

Pending definitions

Points in this document that still depend on commercial or legal decision before the final version.

  • Signature: define whether this attachment will be accepted electronically at the time of contracting or signed in a separate document for corporate clients.
  • ANPD Standard Clauses: confirm with the lawyer the form of formal adherence to Annex II of ANPD Board Resolution No. 19/2024 in contracts with foreign suppliers.
  • Audit term and eventual cost of on-site audit per client.

Legal basis cited

  • General Data Protection Law (Law 13.709/2018), articles 5, VII and VIII, 6, 37, 38, 39, 42 to 45, and 46 to 49.
  • ANPD Board Resolution No. 15/2024 (security incident communication).
  • ANPD Board Resolution No. 19/2024 (international transfer and standard contractual clauses).

Version history

  • 1.0 · September 4, 2026 · First version.
Privacy PolicyTerms of useSub-processorsData processing agreement
UXTap

Usability testing and user research for product and design teams.

UXTap is a Painel TAP.

CNPJ 59.701.681/0001-68

Product

  • All features
  • Figma prototype
  • Live site
  • In-product survey
  • Results and repository
  • Blog
  • How it works
  • Recruitment panels
  • Price
  • Frequently asked questions

Group products

  • Painel TAP
  • OpinaTAP
  • VisionCX
  • ZapTap
  • QualiTAP
  • AnáliseTAP
  • UXTap

Account

  • Help Center
  • Log in
  • Create free account
  • Privacy Policy
  • Terms of use
  • Sub-processors
  • Security
  • My data

Contact

  • contato@uxtap.app
  • paineltap.com.br

We reply by email on business days.

© 2026 Painel TAP. All rights reserved.