← taktcycles.com

TAKT Recipients and Transfers Schedule

Version 25f60f913fd9

Effective: 5 October 2026. Last reviewed: 5 October 2026.

This schedule supplements the Privacy Notice and the Data Processing Agreement of TAKT (ABX DEVELOPMENT LLP). Transfers from the United Kingdom to countries of the European Economic Area are approved by regulations, formerly called adequacy regulations (Data Protection Act 2018, Schedule 21, paragraphs 4 and 5; UK GDPR, Article 45A). Changes to the sub-processors are notified to clients by email at least 30 days in advance (DPA, clause 5).

1. ABX DEVELOPMENT LLP, Lithuania (EU). Role: the Provider itself. ABX DEVELOPMENT LLP operates the application server (which also holds the service's main database), a separate data server for the project keys, its email relay (mail.taktcycles.com) and their host infrastructure in Lithuania; no separate hosting provider processes the account or project contents or the emails there. Data: accounts, project materials and their execution, the database, the emails we send and receive, and logs. Connectivity providers, including the network through which the email relay reaches the internet, carry the service's traffic and do not administer those systems or hold decryption keys; web traffic and the connections between the Provider's servers are encrypted, and email is exchanged with other mail servers over TLS where they support it.

2. Cloudflare, Inc. (USA). Role: processor. Data: visitors' IP addresses, request data (addresses, headers), the content of pages and forms passing through its network, security and access logs. In dashboard upload requests and downloads of delivered builds, file contents and file names are carried as application-encrypted data (clause 5 of the Data Processing Agreement). File names, sizes and checksums displayed on dashboard pages remain readable to Cloudflare. Purpose: DNS, delivery and TLS termination, web application firewall, rate limiting and bot protection (Turnstile) for taktcycles.com and app.taktcycles.com. Location: Cloudflare's global network (TLS may terminate in any Cloudflare data centre); storage mainly in the USA and the EEA. Safeguard: the UK Extension to the EU-US Data Privacy Framework; otherwise the EU standard contractual clauses with the UK International Data Transfer Addendum, under Cloudflare's data processing addendum (https://www.cloudflare.com/cloudflare-customer-dpa/; sub-processors: https://www.cloudflare.com/gdpr/subprocessors/cloudflare-services/).

3. Cloudflare, Inc. (USA). Role: independent controller for Turnstile signals and for security information derived from network traffic. Purpose: improving bot detection and protecting Cloudflare's network and services. Safeguard: the UK Extension to the EU-US Data Privacy Framework, or standard contractual clauses (https://www.cloudflare.com/privacypolicy/; https://www.cloudflare.com/turnstile-privacy-policy/).

4. Stripe: Stripe Payments Europe, Limited (Ireland), Stripe Payments UK, Ltd. (United Kingdom), Stripe Technology Company Limited (Ireland) and Stripe, LLC (USA). Role: processor for providing the payment service; independent controller for fraud prevention, anti-money-laundering, legal and regulatory compliance and improving its services. Data: name, email address, billing address, card details, transaction details, IP address and device data. Location: the United Kingdom, Ireland, the USA and other countries where Stripe's affiliates operate. Safeguard: EEA countries are approved by regulations; transfers to the USA rely on the UK Extension to the EU-US Data Privacy Framework (Stripe, LLC), otherwise on the UK International Data Transfer Addendum to the EU standard contractual clauses (https://stripe.com/gb/legal/dpa; https://stripe.com/gb/legal/dta; https://stripe.com/gb/privacy).

5. Wise Payments Limited (United Kingdom). Role: independent controller. Data: the payer's name, bank details, payment reference, amount and date. Purpose: receiving bank transfers into the Provider's Wise Business account; Wise's own fraud prevention and regulatory compliance. Location: the United Kingdom; Wise's onward transfers rely on its own safeguards (https://wise.com/gb/legal/privacy-notice-business-en).

6. OpenAI OpCo, LLC (United States), through the OpenAI API organisation of ABX DEVELOPMENT LLP. Role: processor for support-ticket content under our OpenAI Services Agreement and Data Processing Addendum. We do not opt in to sharing this content for model training. We disable optional storage of generated chat completions. This is not a zero-retention arrangement: OpenAI may retain request and response content in abuse-monitoring logs for up to 30 days, or longer where required by law or reasonably necessary to protect its services or others from harm. Temporary processing caches may also apply, as described in OpenAI's API data controls (https://developers.openai.com/api/docs/guides/your-data). Data: the content of support tickets for which the client allowed our AI support agent, either by ticking the box when opening the ticket or by selecting “Allow AI handling” on the page linked from the confirmation of an emailed ticket: the subject and the messages (including any chat transcript copied into the ticket). We do not supply the client's account or contact email address as a separate field; the ticket subject and messages are sent as written and may contain email addresses or other personal information the client includes. Tickets without AI permission are handled by our staff. When you withdraw permission, we stop further AI requests for that ticket and our staff continue handling it. Withdrawal cannot recall a request that has already been sent. Conversations with the website and dashboard chat assistant are not supplied through this support integration unless they are copied into a ticket. Project upload files are not automatically attached to tickets or supplied through this integration. Information you include in ticket messages forms part of the ticket content processed by the support tools; please do not include source code, benchmark inputs or secrets. Purpose: our AI support agent answering tickets or passing them to our staff. Each model request is isolated from other tickets and contains our support instructions, relevant passages of our public website and documents, and the content of that ticket. A ticket may require several requests, including retries and handling follow-up messages, while AI permission remains in force. Location: processing may take place in the United States and other countries where OpenAI's affiliates and sub-processors operate. Safeguard for UK personal data: the Standard Contractual Clauses with the UK International Data Transfer Addendum incorporated into clause 4.2 of the OpenAI Data Processing Addendum (https://openai.com/policies/data-processing-addendum/).

Text: recipients.md