TAKT Privacy Notice
Version 6a3a63a50278
Effective: 5 October 2026.
Controller: ABX DEVELOPMENT LLP, a limited liability partnership registered in Scotland (United Kingdom) under number SO301872; address: 39/5 Granton Crescent, Edinburgh, EH5 1BN, United Kingdom. Contact for privacy matters: [email protected].
This notice explains how we handle personal data on the website taktcycles.com and in the dashboard app.taktcycles.com. Personal data inside the code and data that clients upload is processed for the client under the Data Processing Agreement.
1. What we collect.
1.1. Request form on the website: name, email address, company, platform, size of the hot code, priority and the text of the request. The fields marked as required are needed to answer the request.
1.2. Dashboard: email address, language, company details for invoices, sign-in data (a password hash, the public keys of passkeys and the authenticator-app secret, stored encrypted), sessions (IP address and browser), balance, invoices and payments, and the log of actions. If you register through a distributor's referral link or apply a distributor's promo code, we record the distributor associated with your account and the related commission entries.
1.3. Technical records: we keep no separate web-server access log. Application, sign-in, system and security records may contain IP addresses, browser information, times and operational details. Cloudflare processes network and security information as described in the Recipients Schedule.
1.4. Cookies and similar technologies: the dashboard session cookie keeps you signed in and protects your account (it lasts at most 12 hours); takt_lang remembers a language you choose (one year); Cloudflare Turnstile processes technical signals to tell people from bots on the sign-in and request forms. We use no advertising, analytics or referral cookies and no local-storage identifier for referrals: a distributor's referral code is passed through the registration link and forms and, on registration, may be recorded against the account as described in 1.2.
1.5. Support chat and tickets: what you write to the TAKT assistant on the website or in the dashboard and its answers; when a conversation becomes a ticket or you open one, the ticket's messages, your email address and the ticket's status. For a website chat we also keep the IP address to protect the service from abuse, and Cloudflare Turnstile checks the first message (see the Recipients Schedule). The website and dashboard chat assistant runs on our own server and uses our public website and documents together with the messages in your conversation to answer you; it does not retrieve other clients' conversations. The assistant's model inference is performed locally, without sending its inference requests to an external AI provider. If you turn a conversation into a ticket, we copy it into the ticket for our support team to handle. When you open a ticket you can tick a box to let our AI support agent handle it; the agent works through an external AI provider identified in the Recipients Schedule. We do not supply your account or contact email address as a separate field. The ticket subject and messages, including any copied chat transcript, are sent as written and may contain email addresses or other personal information you include. Unless you give permission for AI handling of that ticket, only our staff handle it and its content is not sent to an external AI provider. If you write to [email protected], your message becomes a ticket handled by our staff. Our confirmation contains a link to a page showing the consent statement, where you can select “Allow AI handling” for that ticket. Opening the link alone does not give permission. Replies you send to our ticket emails are added to the same ticket. Email never authorises sensitive actions: account, payment and access changes are made only in the dashboard, and we do not disclose account information by email. Requests about your personal data can be made by email. If we have reasonable doubts about your identity or authority, we request only what is necessary to verify it, through the dashboard where practicable or by other reasonable means, including if you have no account or cannot access it. Please keep ticket email links and reply addresses private. You can withdraw your consent at any time using the “Stop AI handling” control on the ticket page or the link in the ticket confirmation email, or by writing to [email protected]. We then stop further consent-based AI handling and our staff continue the ticket. Withdrawal does not affect the lawfulness of processing carried out before it. We use browser session storage to keep a chat-session identifier for your browser tab so that we can continue the conversation you requested; it is not used for advertising or referral tracking.
2. Why, and on what legal basis (UK GDPR).
2.1. Where you contract with us personally, processing needed to answer your request and to provide the services is based on steps you ask for before a contract and on the contract. Where you represent an organisation, we rely on our legitimate interests in communicating with its representatives and in delivering and administering its services.
2.2. Security, the prevention of fraud and abuse, and the handling of legal claims: our legitimate interests.
2.3. Invoices and accounting records: our legal obligations.
2.4. Distributor attribution: we use it to administer our distributor programme and to calculate commissions, which we pay from our own funds, relying on our legitimate interests in remunerating introductions and keeping accurate commission records. It does not change your prices. The distributor receives no personal data about you from us, only the commission amounts. You may object at [email protected].
2.5. Support chat and tickets: answering your questions and requests, as steps you ask for before entering into a contract or under your contract, and otherwise our legitimate interest in answering enquiries about our services; the IP address of a website chat, our legitimate interest in preventing abuse. Sending a ticket's content to the AI support agent's provider: your consent, given by ticking the box when you open the ticket or selecting “Allow AI handling” on the page linked from the confirmation email (UK GDPR Article 6(1)(a)), which you can withdraw at any time for the future.
We do not sell personal data and do not send marketing emails. The platform calculates offer prices automatically and runs the agreed payment and trial deadlines; the Trial Agreement explains when a hold becomes a charge and how to challenge it. You may ask for a human review of any automated account or payment action at [email protected].
3. Who receives the data. The Recipients Schedule (taktcycles.com/legal/recipients.html) lists the recipients, namely Cloudflare (network delivery, security and Turnstile), the payment services (Stripe, Wise) and OpenAI (the AI service of our support agent, for tickets whose sender allowed it), with their roles, the data, the purposes, the locations and the safeguards for transfers outside the United Kingdom. Stripe and Wise also act as independent controllers for their own purposes under their privacy notices, which the schedule links. OpenAI processes support-ticket content on our behalf under the OpenAI Services Agreement and Data Processing Addendum; the Recipients Schedule describes this processing and the applicable transfer safeguards. You may ask [email protected] for a copy of the safeguards that apply to a transfer.
4. How long.
4.1. Requests from the website form: two years after receipt.
4.2. Accounts: while the account exists. Sign-in sessions, login codes and password attempts: 30 days after they end.
4.3. Project materials: normally 30 days from project creation, subject to the limited continued processing and deletion arrangements in clause 4 of the Data Processing Agreement.
4.4. Invoices, payments, contract acceptances and the log of actions: as long as tax, accounting and limitation rules require, generally six years.
4.5. System and security logs: no longer than 90 days, and sooner by size-based rotation. Records needed for a specific security incident or legal claim may be kept, with restricted access, while needed for that purpose.
4.6. The link between an account and a distributor: while the distributor's programme lasts; it is removed when the programme ends or on a justified objection, unless it is needed for a specific legal claim or obligation. The related payment and commission records follow 4.4.
4.7. Backups: the service's database and files are included in snapshots and backups of the application server, which are replaced in a rotation of no more than 7 days. Data deleted under this clause may remain in them until then; it is kept beyond use, and, if a backup is restored to recover from a failure, deletions made since it was taken are applied again before the restored data return to normal service use. Project keys are never included in backups (clause 4 of the Data Processing Agreement).
4.8. Support: tickets, including any chat transcript copied into them, are kept for three years after closure. A chat session is deleted once 90 days have passed since its last message and no retained ticket is linked to it. Records needed for a specific legal claim may be kept with restricted access while needed for that claim. Backups follow clause 4.7.
5. Your rights. You may ask for access to your data, its correction or erasure, the restriction of or objection to its processing (including processing based on legitimate interests) and a copy in a portable form, by writing to [email protected]. Some rights depend on the legal basis of the processing. You may complain to the UK Information Commissioner's Office or its successor, the Information Commission (ico.org.uk).