TapTalk AAC Ireland • Child Speech Privacy Charter
Statutory Entity: TapTalk Ireland Ltd (Dublin, Ireland) • Reference: GDPR-DPA2018-AAC-CHARTER-v2026.1 • Effective: August 2026
Official Statutory Privacy Policy & Consent Charter
OFFICIAL PDF v2026.1 CORU CLINICAL VERIFIED
Document ID: TAPTALK-CLINICAL-DPA2018-GDPR-ART9.PDF • SHA-256: 9b4c2e71...8ace02468 • Authority: Data Protection Commission (DPC) Ireland
1. The Sacred Data: Our 100% Zero-Sale & Zero-Ad Guarantee
A child's voice, symbol selections, and communicative expressions are the most sacred data of all. Under the laws of Ireland and the European Union, communication generated through an Augmentative and Alternative Communication (AAC) device constitutes Special Category Health & Biometric Data (EU GDPR Article 9(1)).
2. Statutory Legal Framework (Irish Law & EU GDPR)
Our processing of personal and health telemetry data strictly adheres to statutory Irish legislation and European Union privacy regulations:
| Statute / Article | Legal Requirement | TapTalk AAC Implementation |
|---|---|---|
| Irish Data Protection Act 2018 (Section 31) | Digital Age of Consent for children in Ireland is established at 16 years of age. | Explicit consent is obtained from the verified parent or legal guardian prior to telemetry recording. |
| Irish Data Protection Act 2018 (Section 36 & 55) | Lawful processing of special categories of data for health and social care purposes. | Clinical telemetry is gathered solely to support speech therapy, NCSE Assistive Technology grants, and SLT IEP guidance. |
| EU GDPR Article 6(1)(a) & (b) | Lawful basis: Explicit Consent & Performance of a Service Contract. | Parents subscribe to the service and authorize clinical monitoring for their child. |
| EU GDPR Article 9(2)(a) & (h) | Processing of Special Category Health Data for clinical diagnosis and healthcare provision. | Managed under the direct clinical oversight of CORU-registered Speech and Language Therapists. |
| Irish ePrivacy Regulations (S.I. No. 336/2011) | Prior opt-in consent required for non-essential cookies and browser storage. | Granular Cookie & Telemetry Consent Engine with 1-click opt-out and persistent preferences badge. |
3. Clinical Telemetry: Why We Collect Tile Presses & How It Protects the Child
To legally protect the clinical integrity of our service and provide world-class therapy outcomes, we record tile interaction events. Here is the explicit breakdown of why this data is collected:
1. Core vs. Fringe Vocabulary Frequencies
Quantifies whether the child is utilizing generative core words (e.g. "Want", "More", "Help", "Stop") or relying on nouns. This informs the SLT when to expand from 12-tile to 20-tile communication grids.
2. Motor Targeting & Keyguard Calibration
Measures touch latency (ms) and adjacent-cell hit accuracy. This data verifies whether the child's physical 3.0mm laser-cut PMMA acrylic keyguard is properly aligned or requires CNC adjustments.
3. Statutory NCSE Grant & Clinical Progress Reports
Generates evidence-based telemetry required for the Department of Education Circular 0010/2013 Assistive Technology Grant reviews and school IEP meetings.
4. 5-Minute Daily Home Practice Feedback Loop
Syncs everyday home communication wins between the parent and their assigned clinician (Dr. Sarah O'Connor / Dr. Niamh Brennan).
4. Strict Caseload Isolation & Post-Quantum Cryptography
We implement Zero-Trust Caseload Isolation. Child records are strictly siloed so that unauthorized URL tampering or lateral browsing is physically impossible:
- Superadmin Access: Full system administration and database maintenance.
- Assigned SLT Access: Strictly limited to children assigned to that clinician's caseload. Attempting to view unassigned children returns HTTP 403 Forbidden.
- Parent Access: Strictly restricted to their own child. Parents cannot view or query other children.
- Post-Quantum Encryption: Telemetry and VoIP signaling are enveloped using NIST FIPS 203 (ML-KEM-768) and AES-256-GCM.
4B. Ephemeral Voice Notes & Single-Play Zero-Retention Memory Scrubbing
In strict compliance with Irish Data Protection Act 2018 Section 36 & Section 55 (Special Category Health & Pediatric Communication) and EU GDPR Article 9 & Article 17 (Right to Immediate Erasure), all Intranet and Clinical Voice Notes operate on a strict 1-Play Self-Destruct Architecture:
5. Cookies & Local Browser Storage Policy
In compliance with the Irish ePrivacy Regulations (S.I. No. 336/2011) and DPC guidance, we categorize our storage as follows:
| Storage Key / Cookie | Category | Purpose & Expiry | Consent Requirement |
|---|---|---|---|
PHPSESSID • taptalk_auth |
Strictly Necessary | User authentication, CSRF protection, and session security. Expires on session close. | Exempt under S.I. 336/2011 Reg 5(5). |
taptalk_pqc_kem_state |
Strictly Necessary | NIST FIPS 203 ML-KEM cryptographic key exchange state for VoIP. | Exempt (Essential Security). |
taptalk_board_custom_v4 |
Functional | Saves customized speech board tile layout and speech synthesis settings. | Exempt (User Requested Functionality). |
taptalk_speech_telemetry |
Clinical Analytics | Calculates daily word count and motor accuracy for SLT reports. | Requires Explicit Opt-In Consent. |
6. Parental Statutory Rights (GDPR Articles 15–22)
As a verified parent or legal guardian, you have full statutory sovereignty over your child's data:
Data Protection Commission (DPC) Ireland Oversight
You have the statutory right to raise any concern or lodge a formal complaint with the supervisory authority: Data Protection Commission (DPC) Ireland, 21 Fitzwilliam Square South, Dublin 2, D02 RD28 | Website: dataprotection.ie.
7. Data Protection Officer & Clinical Governance Contacts
Dublin, Ireland
Email: info@___DOMAIN_TapTalk_IE___ / [email protected]
Dr. Sarah O'Connor, BSc SLT (CORU #049281)
Email: dpo@___DOMAIN_TapTalk_IE___