Skip to content

GDPR Compliance

Tabseet is committed to protecting personal data. This page explains, in general terms, how data-protection responsibilities are allocated under the General Data Protection Regulation (GDPR). The Privacy Policy provides the broader notice for information Tabseet controls directly.

What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on 25 May 2018. It establishes rules for how organizations collect, store, process, and delete the personal data of EU individuals, and applies to any organization handling that data regardless of where the organization is located.

Our role as a data processor

For data your firm stores in its Tabseet workspace (client, matter, and case records), Tabseet acts as a data processor on your firm's behalf — your firm remains the data controller responsible for the lawful basis of that data. For account and contact information you provide to us directly, such as when requesting a workspace, Tabseet acts as the data controller.

Our commitment to data protection

We apply the following principles when handling personal data:

  • Transparency — clearly explaining what data we collect and how we use it;
  • Purpose limitation — only collecting data necessary for our services;
  • Data minimization — limiting data collection to what is essential;
  • Accuracy — keeping your data accurate and up to date;
  • Storage limitation — not keeping your data longer than necessary; and
  • Security — using industry-standard security measures to protect your data.

Your rights under GDPR

As a data subject under GDPR, you have the following rights:

  • Right to access — request a copy of your personal data;
  • Right to rectification — request correction of inaccurate data;
  • Right to erasure — request deletion of your personal data;
  • Right to data portability — receive your data in a portable format;
  • Right to object — object to certain processing of your data;
  • Right to restrict processing — request limitations on how your data is processed; and
  • Right to withdraw consent — withdraw previously given consent at any time.

Requests can be directed to us using the contact details on this page, and — where the data relates to a firm's workspace — will be routed to the relevant firm as the data controller.

Data processing activities

We process personal data for purposes including:

  • Account creation and management;
  • Workspace provisioning and operation;
  • Customer support and communication;
  • Billing and payment processing;
  • Legal compliance and security; and
  • Service improvements based on aggregated operational information, where applicable.

Data security measures

We use appropriate technical and organisational measures to protect personal data, including measures such as:

  • Encryption of data in transit and at rest;
  • Regular security audits and assessments;
  • Access controls and authentication;
  • Staff training on data protection;
  • Incident response procedures; and
  • Regular backups and disaster recovery planning.

Data retention

Our retention schedule is: registration requests and leads until deletion is requested; account and billing records until deletion is requested, subject to legal retention duties; support emails until deletion is requested; workspace and client data for one month after cancellation; security logs for one month; backups for three months; and no marketing consent records because client data is not used for marketing. Workspace data is handled under the applicable deletion or return terms after cancellation.

International data transfers

Our application and database infrastructure is hosted by Amazon Web Services (AWS) in the us-east-1, me-south-1, and eu-west-1 regions, as applicable to the deployment. Registration requests are sent to Tabseet internal APIs, and subscription payments are processed by Paddle.com. Where personal data is transferred outside the European Economic Area, the applicable transfer mechanism and safeguards will be documented in the service and processing terms before workspace data is activated.

Data protection contact

For GDPR-related questions or to exercise your data protection rights, please contact us:

  • Legal entity: Tabseet Technology
  • Commercial registration: 126423-1
  • Registered address: N/A — online commercial registration
  • Email: hello@tabseet.org
  • Response time: normally within one month, subject to any lawful extension.

Updates to our GDPR practices

We review our data-protection practices as the Site and service change. Any significant changes will be reflected in this page or communicated where required. For more detail on how we process personal data generally, see our Privacy Policy.

Questions about this page? Contact us.