Data Processing Agreement

Last updated: May 8, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Tikk, sole proprietorship located at Korte Werf 17, 8970 Poperinge, Belgium β€” VAT number 1034.870.630 ("Tikk", "Processor") and the user of the Tikk Platform ("Controller").

By creating a Tikk account and accepting our Terms of Service, you also agree to this DPA. It is not necessary to sign this document separately.

This DPA is drafted in accordance with Regulation (EU) 2016/679 of the European Parliament (GDPR), in particular Article 28 thereof.

1. Definitions

For the purposes of this DPA:

  • "Personal Data" means any information relating to an identified or identifiable natural person processed in the context of the Services.
  • "Controller" means the Tikk user who determines the purposes and means of processing personal data collected through the Platform (e.g., booking request data from their clients).
  • "Processor" means Tikk, which processes personal data on behalf of the Controller.
  • "Sub-processor" means any third party engaged by Tikk to process personal data on behalf of the Controller.
  • "Services" means the Tikk Platform as described in the Terms of Service.
  • "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.

2. Roles and Responsibilities

The parties acknowledge that:

  • The Controller determines the purposes for which personal data of their clients/guests is collected through the Platform (e.g., name, email address, booking details).
  • Tikk acts as Processor of such data solely on the Controller's behalf and only for the purpose of providing the Services.
  • Tikk acts as an independent Controller for data it processes for its own purposes (e.g., account registration data, billing), as described in the Privacy Policy.

3. Subject Matter and Nature of Processing

Subject matter

Processing personal data of the Controller's clients/guests in connection with booking requests submitted via the Tikk Platform.

Nature of processing

Collection, storage, transmission and deletion of personal data as necessary to provide the Services.

Categories of data subjects

Clients, guests or other individuals who submit booking requests to the Controller via the Platform.

Categories of personal data

Name, email address, booking topic, message content, payment status (if applicable).

Duration

For the duration of the Controller's active Tikk account, unless earlier deletion is requested.

4. Obligations of the Processor (Tikk)

Tikk shall:

  • Process personal data only on documented instructions from the Controller (i.e., through the Controller's use of the Platform), unless required to do so by EU or Member State law.
  • Ensure that persons authorized to process the personal data are committed to confidentiality.
  • Implement appropriate technical and organizational security measures in accordance with GDPR Article 32, including encryption in transit and at rest, access controls and regular backups.
  • Not engage sub-processors without informing the Controller in advance (see Section 6).
  • Assist the Controller in responding to requests from data subjects exercising their GDPR rights, to the extent technically feasible.
  • Assist the Controller in ensuring compliance with GDPR Articles 32–36 (security, breach notification, DPIAs).
  • At the Controller's choice, delete or return all personal data after the end of the provision of Services.
  • Provide the Controller with all information necessary to demonstrate compliance with GDPR Article 28 obligations.
  • Notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller data.

5. Obligations of the Controller

The Controller shall:

  • Ensure they have a valid legal basis for collecting and processing personal data of their clients/guests through the Platform.
  • Provide any required privacy notices to their clients/guests prior to collecting their data via the Platform.
  • Comply with applicable data protection legislation when using the Platform.
  • Not instruct Tikk to process personal data in a manner that would violate applicable law.

6. Sub-processors

The Controller hereby grants Tikk general written authorization to engage sub-processors. Tikk will inform the Controller of any intended changes to sub-processors (additions or replacements) by updating this DPA and notifying users via email or Platform notification at least 14 days in advance. The Controller may object to such changes within that period.

Current sub-processors that may process Controller data:

ProviderPurposeCountry Transfer mechanism
Hetzner Cloud GmbH Hosting & storageπŸ‡©πŸ‡ͺ Germany (EU)N/A (EU)
Mollie B.V. Payment processing (opt-in: paid bookings) πŸ‡³πŸ‡± Netherlands (EU)N/A (EU)
Resend Transactional email delivery πŸ‡ΊπŸ‡Έ United StatesSCCs
Google LLC Calendar integration (opt-in: Google Calendar) πŸ‡ΊπŸ‡Έ United StatesSCCs
Microsoft Corporation Calendar integration (opt-in: Outlook Calendar) πŸ‡ΊπŸ‡Έ United StatesSCCs

SCCs = Standard Contractual Clauses approved by the European Commission (Decision 2021/914).

7. International Data Transfers

Personal data is primarily stored on EU-based servers (Frankfurt, Germany). Transfers to sub-processors outside the EEA (as listed above) are governed by Standard Contractual Clauses (SCCs) pursuant to European Commission Decision 2021/914, ensuring an equivalent level of data protection.

8. Security Measures

Tikk implements the following technical and organizational measures (TOMs):

  • Encryption of data in transit (TLS 1.2+) and at rest
  • Access control and role-based permissions
  • Encrypted password storage (bcrypt)
  • Regular automated backups
  • Activity logging and anomaly monitoring
  • Two-factor authentication available for user accounts
  • Vulnerability assessments and patching procedures
  • Staff access on a need-to-know basis

9. Data Breach Notification

In the event of a personal data breach affecting data processed on behalf of the Controller, Tikk will notify the Controller without undue delay and provide, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences and measures taken or proposed. This notification is to enable the Controller to meet its own obligations under GDPR Articles 33 and 34.

10. Data Subject Rights

Where a data subject exercises a GDPR right (access, rectification, erasure, portability, restriction, objection) with respect to data processed by Tikk on behalf of the Controller, Tikk will forward the request to the Controller and provide reasonable technical assistance to enable the Controller to fulfil the request within the statutory timescales.

11. Audit Rights

The Controller may request information to demonstrate compliance with this DPA. Tikk will provide available documentation and, where technically feasible, allow for audits conducted by the Controller or an auditor mandated by the Controller, subject to reasonable advance notice (minimum 30 days) and agreement on scope and confidentiality.

12. Governing Law

This DPA is governed by the laws of Belgium. Any disputes shall be submitted to the competent courts of Belgium.

Questions

For any questions regarding this Data Processing Agreement, please contact us at:

Email: [email protected]

Tikk β€” Korte Werf 17, 8970 Poperinge, Belgium β€” VAT 1034.870.630