Last Updated: 14 May 2026
Qik provides a software platform that organisations use to manage their members, attendees, events, check-ins, rosters, and other operational information. Our customers are organisations such as businesses, schools, community groups, clubs and programs ("Customer Organisations").
Qik operates primarily as a data processor. The personal information stored, organised, and managed within the Qik platform — about members, attendees, participants, children, contacts, and other individuals — is controlled by the Customer Organisation that uses Qik. We process that information only on the Customer Organisation's instructions and in accordance with our agreement with them.
This Privacy Policy explains:
How we handle personal information in our role as a data processor
The limited circumstances in which Qik also acts as a controller (specifically, for individuals who sign up for and log in to a Qik account on behalf of a Customer Organisation)
The security and data-handling measures we apply
Your options for contacting us, and when to contact a Customer Organisation directly instead
We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Where we process personal data relating to individuals in the European Economic Area, United Kingdom, or California, we comply with applicable provisions of the GDPR, UK GDPR, and CCPA in our capacity as a processor.
If you are a member, attendee, participant, child, parent, guardian, or contact of an organisation that uses Qik, and your information has been entered into Qik by that organisation, the organisation — not Qik — is the controller of your information.
The organisation is responsible for:
Deciding what information to collect about you and why
Obtaining any consents required (including from parents or guardians for children)
Providing you with privacy information about how they use your data
Responding to your requests to access, correct, or delete your information
Please direct privacy requests to the organisation that holds your information. If you are unable to identify or reach the organisation, you may contact us at support@qik.dev and we will, where reasonable, help connect you with them. We cannot action requests about Customer Data without the organisation's involvement.
What it is. Customer Data is the personal information that Customer Organisations enter into and store within Qik. The categories are determined by each organisation and may include:
Names, contact details, and demographic information
Family and relationship information
Attendance, check-in, and event participation records
Photographs and identifying images
Emergency contacts
Health, medical, allergy, or accessibility information (sensitive information under the Privacy Act 1988)
Child-safety records and notes
Communications and correspondence
Our role.
We do not decide what Customer Data is collected, from whom, or for what purpose
We process Customer Data only as needed to provide and maintain the Service, or as directed by the Customer Organisation
We do not access, use, or disclose Customer Data for any other purpose
We do not sell Customer Data
We do not use Customer Data to train AI or machine learning models
We do not perform behavioural analytics on Customer Data or on how individuals use the Service
Customer Organisation responsibilities. Each Customer Organisation is responsible for:
Determining the legal basis and purpose for collecting Customer Data
Obtaining any consents required from individuals or, where applicable, parents or guardians
Providing privacy notices to the individuals whose data they store
Responding to access, correction, deletion, and other privacy requests from those individuals
Configuring Qik appropriately, including access controls, retention settings, and optional features such as AI integrations
Notifying affected individuals and (where required) regulators of any data breach involving Customer Data
Customer Data is stored within Australia.
Hosting: Amazon Web Services (AWS), ap-southeast-2 region (Sydney and Melbourne data centres)
Database: MongoDB Atlas, deployed on AWS infrastructure within the ap-southeast-2 region
By default, Customer Data does not leave Australia. The exceptions are:
Where a Customer Organisation enables an optional feature that involves overseas processing — for example, AI features (see below). In those cases, the Customer Organisation has chosen to enable the feature and is responsible for any consents required.
Operational metadata in server logs (such as user IDs, session IDs, request paths, and error information) may be forwarded to our monitoring provider (Grafana Cloud) for service health monitoring. These logs do not contain the substance of Customer Data records, but may contain identifiers and request information.
We engage the following sub-processors to help us provide the Service. Each is bound by contractual obligations to handle data securely and only for the purposes we direct.
Sub-processor | Purpose | Location of Processing |
|---|---|---|
Amazon Web Services (AWS) | Cloud hosting and infrastructure | Australia ( |
MongoDB Atlas | Database (deployed on AWS) | Australia ( |
Stripe | Subscription billing and payment processing | United States / Australia |
Anthropic, PBC | AI processing — only when a Customer Organisation enables AI features | United States |
SendGrid (Twilio Inc.) | Transactional email (account notices, password reset, service communications) | United States |
Grafana Labs | Service health monitoring and operational logging | [INSERT — check your Grafana Cloud stack region: US, EU, or AU] |
A current sub-processor list is maintained and is available to Customer Organisations on request. We will provide reasonable advance notice to Customer Organisations before adding or replacing a sub-processor.
Qik offers optional AI-powered features that allow authorised users of a Customer Organisation to connect Qik to third-party AI assistants (such as Anthropic's Claude) through our Model Context Protocol (MCP) server. These features are optional and only operate where the Customer Organisation has enabled them and an authorised user initiates a request.
What data is shared. When an AI assistant is instructed to act on the organisation's behalf, the Customer Data necessary to perform the requested action is transmitted to the AI provider. This may include names, contact details, content, records, and any other data the requested action requires.
Who receives it. The AI provider chosen by the Customer Organisation (for example, Anthropic, the operator of Claude). Once transmitted, the AI provider processes the data under its own privacy policy and terms.
International transfers. AI providers may process data outside Australia, including in the United States. Customer Organisations that enable AI features consent on behalf of their organisation to this transfer.
Customer Organisation responsibility. The decision to enable AI features, and to obtain any consents required from the individuals whose data may be processed (including parents or guardians where children's information is involved), rests with the Customer Organisation. AI features are off by default and Qik does not enable them on behalf of any Customer Organisation.
Scope of access. The MCP server exposes a defined set of actions and scopes data access to the authenticated user's permissions within the Customer Organisation's Qik instance. The AI provider cannot access data outside that scope.
Control. Customer Organisations and authorised users can disconnect the AI integration at any time from account settings. Disconnecting stops future transfers but does not retrieve data already shared with the AI provider.
In a limited set of circumstances Qik also acts as a controller — specifically, for information about individuals who sign themselves up for a Qik account on behalf of a Customer Organisation (administrators, staff, volunteers who log in to Qik directly).
What we collect:
Account information: name, email address, password (stored hashed), and role within the Customer Organisation, collected at signup
Billing information: subscription billing is handled by Stripe. We do not collect or store credit card or bank account numbers. We receive only subscription status, billing identifiers, and limited transaction metadata from Stripe to manage Customer Organisation accounts
Support communications: messages you send to our support team
Technical log data: IP address, user identifiers, session identifiers, timestamps, and request information retained in server logs for security, fraud prevention, and debugging purposes. These logs are also forwarded to our monitoring provider (Grafana Cloud) for service health monitoring. We do not perform behavioural or marketing analytics on account holders
How we use it:
To create and authenticate Qik accounts
To provide customer support
To manage subscriptions and billing for Customer Organisations (via Stripe)
To send service-related communications (account notices, security alerts, material policy changes)
To detect, prevent, and address fraud, abuse, and security issues
To comply with legal obligations
We do not use account holder data for marketing without consent.
To the extent the GDPR or UK GDPR applies:
As a processor, we process Customer Data on the documented instructions of the Customer Organisation (controller), under our agreement with them.
As a controller of account holder data, we rely on: performance of a contract (operating Qik accounts), legitimate interests (security, fraud prevention, service operation), consent (optional communications), and legal obligation.
We retain personal information for as long as the relevant Qik account is active. When an account is closed or a subscription is cancelled, we delete the associated personal information, subject to the exceptions below.
Customer Data: retained while the Customer Organisation maintains an active account with Qik. When a Customer Organisation cancels their subscription or closes their account, Customer Data is deleted within [INSERT — e.g., 90 days] of closure, except where we are legally required to retain specific records for longer.
Account holder data: retained while you maintain an active Qik account. When you close your account, your personal information is deleted within [INSERT — e.g., 90 days].
Billing records: retained for 7 years as required by Australian tax and accounting laws, regardless of account status. Card data is held by Stripe, not by Qik.
Backups: Customer Data may persist in encrypted backups for a limited period after deletion before being overwritten in the normal course of backup rotation. Our current backup retention is approximately [INSERT — e.g., 35 days], determined by our AWS and MongoDB Atlas configuration.
Server logs: technical logs (IP addresses, user IDs, session IDs, request metadata, error logs) are retained for up to [INSERT — e.g., 90 days] for security, fraud prevention, and debugging, then automatically rotated. A copy of operational log data is also retained within Grafana Cloud for service health monitoring, in accordance with our Grafana Cloud plan's retention settings.
If you exercise your right to deletion under applicable privacy law, we will action your request within the timeframes required by law, subject to legal retention obligations (such as billing records) and the backup-rotation period described above.
We apply reasonable technical and organisational measures to protect personal information against unauthorised access, alteration, disclosure, or destruction. These include:
Encryption in transit: TLS for all connections to the Service
Encryption at rest: Customer Data encrypted at rest within MongoDB Atlas and AWS infrastructure
Access controls: least-privilege access for Qik staff; multi-factor authentication for administrative access; role-based access controls within the Service
Network security: private networking, firewalls, and security group restrictions
Logging and monitoring: access logs and security monitoring on production systems
Sub-processor due diligence: we select reputable sub-processors and contractually require equivalent security standards
Backups: regular encrypted backups stored within the same Australian region
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If we become aware of a data breach affecting Customer Data, we will:
Notify the affected Customer Organisation without undue delay, and in any event within 72 hours]of becoming aware
Provide the information the Customer Organisation reasonably needs to assess the breach and meet their own notification obligations
Cooperate with the Customer Organisation's investigation and response
The Customer Organisation, as controller, is responsible for notifying affected individuals and regulators (such as the OAIC under the Notifiable Data Breaches scheme, or supervisory authorities under the GDPR/UK GDPR).
For breaches affecting account holder data for which Qik is the controller, we will notify affected individuals and the OAIC as required by the Notifiable Data Breaches scheme.
If you are an account holder (you log into Qik on behalf of a Customer Organisation), you have the right to:
Access the personal information we hold about you
Request correction of inaccurate or incomplete information
Request deletion of your personal information, subject to legal exceptions
Object to or restrict processing in certain circumstances
Withdraw consent where processing is based on consent
Lodge a complaint with a privacy regulator (see "Complaints" below)
Contact us at support@qik.dev to exercise these rights. We will respond within the timeframes required by applicable law (typically 30 days). We may need to verify your identity before actioning a request.
If you are an individual whose information is held within a Customer Organisation's Qik instance, please direct your privacy requests to that organisation. Qik can act on Customer Data only on the organisation's instructions.
We use only essential cookies and similar technologies needed to operate the Service, including to:
Keep you signed in
Remember your preferences
Maintain session security
We do not use cookies for behavioural analytics, advertising, or marketing. You can control cookies through your browser settings, but disabling essential cookies will prevent the Service from functioning correctly.
If you have a concern about how we have handled personal information, please contact us first at support@qik.dev. We will work to resolve it.
If you are not satisfied with our response, you may lodge a complaint with the relevant regulator:
Australia: Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au
European Economic Area: the data protection authority in your country of residence
United Kingdom: Information Commissioner's Office (ICO) — www.ico.org.uk
We may update this Privacy Policy from time to time. The "Last Updated" date reflects the most recent revision.
If we make material changes, we will provide reasonable notice — by email to Customer Organisation account holders or by a prominent notice within the Service — before the changes take effect.
Email: support@qik.dev
Postal address: Melbourne, 3156 Victoria, Australia
ABN: 99 681 746 010