Privacy Policy

Last updated 14 August 2026

Template for launch — items in [BRACKETS] must be completed and the text reviewed by qualified legal counsel before you rely on it.

This Privacy Policy explains how Klik processes personal data when you use our website and the Klik service for collecting event photos, videos and messages. We have written it to be read, not just filed. Where the law gives you rights, we tell you how to use them.

1. Who we are

Klik ("Klik", "we", "us", "our") is operated by [KLIK LEGAL ENTITY NAME], a company registered in [COUNTRY] under company number [KvK / COMPANY NUMBER], with its registered office at [REGISTERED ADDRESS].

For any question about this policy or your personal data, contact us at hello@klik.app. If we have appointed a Data Protection Officer, their contact details are [DPO CONTACT — or state "we have not appointed a DPO as we are not required to"].

For the personal data we process to run our own business — host accounts, billing, security and communications with hosts — Klik is the "data controller" under the EU General Data Protection Regulation (GDPR).

2. Controller and processor — an important distinction

Klik has two different roles depending on the data:

  • ·Host account & service data (e.g. a host's email, sign-in method, event settings, security logs): Klik is the controller and this Policy governs it.
  • ·Event content uploaded by guests (photos, videos, messages and any optional name a guest types): here the host who created the event is the controller — it is their event and their guests — and Klik acts as a processor that stores and displays that content on the host's behalf, under our Terms of Service which include data-processing terms.

This means the host is responsible for having a lawful basis to collect their guests' photos and for informing their guests appropriately. Klik processes that content only to provide the service, following the host's instructions, and never sells it or uses it to train models or for advertising.

3. The personal data we process

Host account data

  • ·Email address (required to create an account).
  • ·Authentication data: a securely hashed password if you sign up with email/password, or your Google account identifier and basic profile (name, email) if you sign in with Google.
  • ·Session data: cookies that keep you signed in (see "Cookies" below).

Event data

  • ·Event name, optional event date, welcome message, chosen theme, gallery settings and the unique event link/QR code.

Guest-contributed content

  • ·Photos, videos and text messages that guests choose to upload.
  • ·An optional first name a guest may type. Guests do not create accounts and we do not ask them for an email, phone number or any account credential.
  • ·Note: photos and videos can contain personal data about identifiable people (guests and third parties). We do not run facial recognition and do not intentionally derive biometric or other special-category data from them.

Technical and security data

  • ·IP address and basic request metadata, used transiently for rate-limiting and to protect the service against abuse. We do not store IP addresses in our application database alongside uploads.
  • ·Standard server logs kept for a short period for security and debugging.

Email delivery data

  • ·When we send you a transactional email (for example a password reset, a first-upload notification or an event-ended notice), your email address and the message are processed by our email provider.

We do not use advertising cookies, third-party trackers, ad pixels or cross-site analytics.

4. Why we process it, and our legal bases

Under Article 6 GDPR we rely on the following legal bases:

  • ·Performance of a contract (Art. 6(1)(b)): to create and secure your account, create and run your events, store and display uploads, and send you transactional emails that are part of the service.
  • ·Legitimate interests (Art. 6(1)(f)): to keep the service secure, prevent abuse and rate-limit uploads, debug problems, and understand aggregate, privacy-preserving usage. You may object to processing based on legitimate interests (see "Your rights").
  • ·Consent (Art. 6(1)(a)): where consent is the appropriate basis — for example, a guest choosing to upload their photos to an event is a clear affirmative act. You can withdraw consent at any time, without affecting processing that already took place.
  • ·Legal obligation (Art. 6(1)(c)): where we must process data to comply with the law.

For guest-uploaded content, the host (as controller) is responsible for establishing the appropriate legal basis for collecting their guests' content and for informing their guests. Klik processes it under the host's instructions as their processor.

5. Who we share data with (sub-processors)

We do not sell personal data and we do not share it for advertising. We use a small number of carefully chosen service providers who process data on our behalf under contract:

  • ·Supabase — database, file storage and authentication. Event media and account data are stored in the European Union (currently AWS region eu-west-1, Ireland).
  • ·Resend — delivery of transactional emails to hosts.
  • ·Google — only if a host chooses "Continue with Google" to sign in (OAuth).
  • ·Our application hosting / CDN provider (e.g. Vercel) — to serve the website and app.

We may also disclose data where required by law, to enforce our Terms, or to protect the rights, safety and property of Klik, our users or the public.

6. International transfers

We aim to keep personal data within the European Economic Area (EEA). Some of our sub-processors are established in the United States or operate globally. Where personal data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V GDPR — such as the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework — to ensure your data receives an equivalent level of protection.

You can ask us for more detail about a specific transfer or safeguard by emailing hello@klik.app.

7. How long we keep it

  • ·Event media and messages are retained for the event's storage window (30 days after the event on the free tier; longer on paid plans). After the window closes, and following a short grace period during which the host can still download, the media is deleted.
  • ·Media that a host deletes is removed from the live gallery immediately and deleted from our storage within 24 hours.
  • ·Host account data is kept while your account is active and deleted when you delete your account (subject to short-lived backups and any records we must keep by law).
  • ·Security logs are kept only for a short period.

Deleting an event removes its media, messages and settings; this cannot be undone.

8. How we protect it

  • ·Encryption in transit (TLS) for all traffic to and from the service.
  • ·Row-Level Security in the database so that events and uploads are only accessible to the right parties; event links use unguessable identifiers and are never listed or indexed.
  • ·Uploads are validated and size-limited; privileged keys are used only on the server and never exposed to browsers.
  • ·Access to production data is limited to what is necessary to operate the service.

No online service can be guaranteed to be 100% secure, but we work to protect your data using appropriate technical and organisational measures.

9. Your rights

Subject to the conditions in the GDPR, you have the right to:

  • ·Access the personal data we hold about you and receive a copy;
  • ·Rectify inaccurate or incomplete data;
  • ·Erasure ("be forgotten") in certain circumstances;
  • ·Restrict or object to certain processing, including processing based on our legitimate interests;
  • ·Data portability — receive certain data in a structured, machine-readable format;
  • ·Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, email hello@klik.app. We will respond within the time limits set by law (normally one month). We may need to verify your identity first. Exercising your rights is free unless a request is manifestly unfounded or excessive.

If you are a guest and want a photo of you removed, you can contact the host of the event directly, or contact us and we will help facilitate the request with the host who controls that event.

You also have the right to lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl); you may also complain to the authority in your country of residence.

10. Children

Klik is not directed at children and hosts must be adults. Event photos may nonetheless include children who are guests. The host, as controller, is responsible for any consents required in relation to minors appearing in uploaded content. If you believe a child's personal data has been uploaded without an appropriate basis, contact us and we will act on it promptly.

11. Cookies

We use only strictly-necessary cookies to keep hosts signed in. Guest upload and gallery pages set no non-essential cookies. See our Cookie Policy for details. Because these cookies are essential to provide a service you asked for, they do not require consent under the ePrivacy rules.

12. Automated decision-making

We do not carry out automated decision-making that produces legal or similarly significant effects about you. Cap and expiry checks on uploads are simple technical rules, not profiling.

13. Changes to this policy

We may update this Policy from time to time. When we make material changes we will update the "Last updated" date and, where appropriate, notify hosts by email or in-app. Continued use of the service after an update means you accept the revised Policy.

14. Contact

Questions, requests or complaints: hello@klik.app. Postal: [KLIK LEGAL ENTITY NAME], [REGISTERED ADDRESS].