Privacy Policy

Last updated: February 26, 2026

Tikk, sole proprietorship located at Korte Werf 17, 8970 Poperinge, Belgium — VAT number 1034.870.630 ("Tikk", "we", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, process and protect your personal data when you use our website and Platform.

This Policy is drafted in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection legislation.

1. Who is Responsible for Your Data?

Tikk acts as the data controller when processing your personal data as a website visitor or user of our Platform.

Contact Details:

Tikk

Korte Werf 17, 8970 Poperinge, Belgium

VAT: 1034.870.630

Email: [email protected]

For data protection inquiries: [email protected]

2. What Personal Data Do We Collect?

We may collect and process the following categories of personal data:

  • Identification data: First name, last name, email address, profile picture, username
  • Account data: Login credentials (encrypted), user preferences, availability settings, pricing information
  • Meeting data: Meeting requests, descriptions, duration, payment amounts, meeting status
  • Calendar data: Calendar integration tokens, availability schedules, timezone information
  • Payment data: Billing details and transaction history processed by Mollie (we do not store full payment card details)
  • Technical data: IP address, browser type, device data, operating system
  • Usage data: Pages visited, features used, login times, interaction metrics
  • Communication data: Support tickets, emails, feedback

We do not intentionally collect special categories of personal data (e.g., race, health, religion).

3. How Do We Collect Your Data?

Your data is collected through:

  • When you create an account on the Tikk Platform
  • When you create or respond to meeting requests
  • When you connect your calendar or other integrations
  • When you make or receive payments through the Platform
  • When you contact us via support or email
  • When you visit our website (through cookies and analytics)

4. Why Do We Process Your Data and on What Legal Basis?

Provide Platform Services

Purpose: Enable meeting requests, scheduling and payments

Legal basis: Contractual necessity

Calendar Integration

Purpose: Sync availability and prevent double bookings

Legal basis: Contractual necessity

Payment Processing

Purpose: Process payments between users

Legal basis: Contractual necessity

Customer Support

Purpose: Respond to inquiries and resolve issues

Legal basis: Legitimate interest

Product Improvement

Purpose: Improve user experience and Platform features

Legal basis: Legitimate interest

Security and Fraud Prevention

Purpose: Protect the Platform and users from abuse

Legal basis: Legal obligation / Legitimate interest

Legal Compliance

Purpose: Comply with tax, accounting and other legal obligations

Legal basis: Legal obligation

Marketing Communications

Purpose: Send newsletters and product updates

Legal basis: Consent (where required)

5. With Whom Do We Share Your Data?

We may share your data with:

  • Payment processors: Mollie (EU-based) processes payments on our behalf
  • Calendar services: Google Calendar, Microsoft Outlook, Apple iCloud or other calendar providers you connect (processed according to their privacy policies)
  • Hosting providers: EU-based providers in Frankfurt, Germany to store and process data securely
  • Email services: To send transactional emails (meeting confirmations, payment receipts)
  • Professional advisors: Legal, financial or auditing advisors when necessary
  • Authorities: When legally required (e.g., for tax compliance or fraud investigation)

We do not sell or rent your personal data to third parties.

For transfers outside the EEA (Resend, Google, Microsoft, Apple), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.

6. Data Storage & International Transfers

Your Data Stays in the EU

All your data is stored exclusively on servers located in EU Central (Frankfurt, Germany). Your personal data does not leave the European Economic Area.

While our primary infrastructure is EU-based, some service providers (such as email delivery or calendar integrations) may process data outside the EEA. When this occurs, we ensure appropriate safeguards are in place:

  • Adequacy decisions by the European Commission
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Other legally approved transfer mechanisms

7. How Long Do We Keep Your Data?

We retain personal data only as long as necessary for the purposes described in this Policy:

Account and Platform Data

Duration of account + up to 6 months

Payment and Transaction Data

7 years (legal requirement)

Support Communications

2 years after resolution

Analytics and Usage Data

Up to 26 months (unless aggregated and anonymized)

You may request earlier deletion, unless we are legally obliged to retain the data.

8. What Rights Do You Have?

Under GDPR, you have the following rights:

  • Right of access: Obtain confirmation and a copy of your data
  • Right to rectification: Correct inaccurate or incomplete data
  • Right to erasure: Request deletion of your data in certain circumstances
  • Right to restrict processing: Limit how we use your data
  • Right to data portability: Receive your data in a structured, commonly used format
  • Right to object: Object to processing based on legitimate interests
  • Right to withdraw consent: Withdraw consent at any time for processing based on consent

You can exercise these rights by contacting us at [email protected]. We will respond to your request within 30 days.

Data Protection Authority

You have the right to lodge a complaint with your local data protection authority. For Belgium:

Data Protection Authority

Rue de la Presse 35

1000 Brussels, Belgium

Email: [email protected]

Website: gegevensbeschermingsautoriteit.be

9. How Do We Protect Your Data?

We implement appropriate technical and organizational security measures, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure hosting in EU Central (Frankfurt) with reputable providers
  • Access controls and authentication mechanisms (including two-factor authentication)
  • Activity logging and monitoring for unauthorized access attempts
  • Regular security assessments and vulnerability testing
  • Encrypted password storage
  • Regular backups and disaster recovery procedures
  • Staff access on a need-to-know basis only

You are responsible for maintaining the security of your account credentials. We cannot be held liable for unauthorized access resulting from compromised credentials due to user negligence.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Belgian Data Protection Authority within 72 hours of becoming aware of the breach (GDPR Art. 33). Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay (GDPR Art. 34).

10. Cookies and Tracking

We use only essential cookies necessary for the Platform to function properly:

  • Strictly Necessary Cookies: Required for authentication, security basic platform functionality
  • Functional Cookies: Remember your preferences and settings

We do not use third-party analytics or advertising cookies. Disabling essential cookies may limit platform functionality.

11. Children's Privacy

The Platform is not intended for use by individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete such information.

12. Automated Decision-Making and Profiling

We do not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on you (GDPR Art. 22). Any decisions that affect your access to the Platform are made with human involvement.

13. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The latest version will always be available on our website. Material changes will be communicated via email or Platform notification where legally required.

Contact

For any questions regarding this Privacy Policy or to exercise your data protection rights, please contact us through our support channels or via email.

If you have concerns about how we handle your data, you may also contact your local data protection authority.