Privacy Policy

Last Updated: 14 May 2026

Overview and Our Role

Qik provides a software platform that organisations use to manage their members, attendees, events, check-ins, rosters, and other operational information. Our customers are organisations such as businesses, schools, community groups, clubs and programs ("Customer Organisations").

Qik operates primarily as a data processor. The personal information stored, organised, and managed within the Qik platform — about members, attendees, participants, children, contacts, and other individuals — is controlled by the Customer Organisation that uses Qik. We process that information only on the Customer Organisation's instructions and in accordance with our agreement with them.

This Privacy Policy explains:

  • How we handle personal information in our role as a data processor

  • The limited circumstances in which Qik also acts as a controller (specifically, for individuals who sign up for and log in to a Qik account on behalf of a Customer Organisation)

  • The security and data-handling measures we apply

  • Your options for contacting us, and when to contact a Customer Organisation directly instead

We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Where we process personal data relating to individuals in the European Economic Area, United Kingdom, or California, we comply with applicable provisions of the GDPR, UK GDPR, and CCPA in our capacity as a processor.

If You Are an Individual Whose Information Is in Qik

If you are a member, attendee, participant, child, parent, guardian, or contact of an organisation that uses Qik, and your information has been entered into Qik by that organisation, the organisation — not Qik — is the controller of your information.

The organisation is responsible for:

  • Deciding what information to collect about you and why

  • Obtaining any consents required (including from parents or guardians for children)

  • Providing you with privacy information about how they use your data

  • Responding to your requests to access, correct, or delete your information

Please direct privacy requests to the organisation that holds your information. If you are unable to identify or reach the organisation, you may contact us at support@qik.dev and we will, where reasonable, help connect you with them. We cannot action requests about Customer Data without the organisation's involvement.

Customer Data (Data We Process on Behalf of Customer Organisations)

What it is. Customer Data is the personal information that Customer Organisations enter into and store within Qik. The categories are determined by each organisation and may include:

  • Names, contact details, and demographic information

  • Family and relationship information

  • Attendance, check-in, and event participation records

  • Photographs and identifying images

  • Emergency contacts

  • Health, medical, allergy, or accessibility information (sensitive information under the Privacy Act 1988)

  • Child-safety records and notes

  • Communications and correspondence

Our role.

  • We do not decide what Customer Data is collected, from whom, or for what purpose

  • We process Customer Data only as needed to provide and maintain the Service, or as directed by the Customer Organisation

  • We do not access, use, or disclose Customer Data for any other purpose

  • We do not sell Customer Data

  • We do not use Customer Data to train AI or machine learning models

  • We do not perform behavioural analytics on Customer Data or on how individuals use the Service

Customer Organisation responsibilities. Each Customer Organisation is responsible for:

  • Determining the legal basis and purpose for collecting Customer Data

  • Obtaining any consents required from individuals or, where applicable, parents or guardians

  • Providing privacy notices to the individuals whose data they store

  • Responding to access, correction, deletion, and other privacy requests from those individuals

  • Configuring Qik appropriately, including access controls, retention settings, and optional features such as AI integrations

  • Notifying affected individuals and (where required) regulators of any data breach involving Customer Data

Where Customer Data Is Stored

Customer Data is stored within Australia.

  • Hosting: Amazon Web Services (AWS), ap-southeast-2 region (Sydney and Melbourne data centres)

  • Database: MongoDB Atlas, deployed on AWS infrastructure within the ap-southeast-2 region

By default, Customer Data does not leave Australia. The exceptions are:

  • Where a Customer Organisation enables an optional feature that involves overseas processing — for example, AI features (see below). In those cases, the Customer Organisation has chosen to enable the feature and is responsible for any consents required.

  • Operational metadata in server logs (such as user IDs, session IDs, request paths, and error information) may be forwarded to our monitoring provider (Grafana Cloud) for service health monitoring. These logs do not contain the substance of Customer Data records, but may contain identifiers and request information.

Sub-Processors

We engage the following sub-processors to help us provide the Service. Each is bound by contractual obligations to handle data securely and only for the purposes we direct.

Sub-processor

Purpose

Location of Processing

Amazon Web Services (AWS)

Cloud hosting and infrastructure

Australia (ap-southeast-2)

MongoDB Atlas

Database (deployed on AWS)

Australia (ap-southeast-2)

Stripe

Subscription billing and payment processing

United States / Australia

Anthropic, PBC

AI processing — only when a Customer Organisation enables AI features

United States

SendGrid (Twilio Inc.)

Transactional email (account notices, password reset, service communications)

United States

Grafana Labs

Service health monitoring and operational logging

[INSERT — check your Grafana Cloud stack region: US, EU, or AU]

A current sub-processor list is maintained and is available to Customer Organisations on request. We will provide reasonable advance notice to Customer Organisations before adding or replacing a sub-processor.

AI Features and Third-Party AI Providers

Qik offers optional AI-powered features that allow authorised users of a Customer Organisation to connect Qik to third-party AI assistants (such as Anthropic's Claude) through our Model Context Protocol (MCP) server. These features are optional and only operate where the Customer Organisation has enabled them and an authorised user initiates a request.

What data is shared. When an AI assistant is instructed to act on the organisation's behalf, the Customer Data necessary to perform the requested action is transmitted to the AI provider. This may include names, contact details, content, records, and any other data the requested action requires.

Who receives it. The AI provider chosen by the Customer Organisation (for example, Anthropic, the operator of Claude). Once transmitted, the AI provider processes the data under its own privacy policy and terms.

International transfers. AI providers may process data outside Australia, including in the United States. Customer Organisations that enable AI features consent on behalf of their organisation to this transfer.

Customer Organisation responsibility. The decision to enable AI features, and to obtain any consents required from the individuals whose data may be processed (including parents or guardians where children's information is involved), rests with the Customer Organisation. AI features are off by default and Qik does not enable them on behalf of any Customer Organisation.

Scope of access. The MCP server exposes a defined set of actions and scopes data access to the authenticated user's permissions within the Customer Organisation's Qik instance. The AI provider cannot access data outside that scope.

Control. Customer Organisations and authorised users can disconnect the AI integration at any time from account settings. Disconnecting stops future transfers but does not retrieve data already shared with the AI provider.

Information Qik Collects as a Controller

In a limited set of circumstances Qik also acts as a controller — specifically, for information about individuals who sign themselves up for a Qik account on behalf of a Customer Organisation (administrators, staff, volunteers who log in to Qik directly).

What we collect:

  • Account information: name, email address, password (stored hashed), and role within the Customer Organisation, collected at signup

  • Billing information: subscription billing is handled by Stripe. We do not collect or store credit card or bank account numbers. We receive only subscription status, billing identifiers, and limited transaction metadata from Stripe to manage Customer Organisation accounts

  • Support communications: messages you send to our support team

  • Technical log data: IP address, user identifiers, session identifiers, timestamps, and request information retained in server logs for security, fraud prevention, and debugging purposes. These logs are also forwarded to our monitoring provider (Grafana Cloud) for service health monitoring. We do not perform behavioural or marketing analytics on account holders

How we use it:

  • To create and authenticate Qik accounts

  • To provide customer support

  • To manage subscriptions and billing for Customer Organisations (via Stripe)

  • To send service-related communications (account notices, security alerts, material policy changes)

  • To detect, prevent, and address fraud, abuse, and security issues

  • To comply with legal obligations

We do not use account holder data for marketing without consent.

Legal Basis (EU/UK Users)

To the extent the GDPR or UK GDPR applies:

  • As a processor, we process Customer Data on the documented instructions of the Customer Organisation (controller), under our agreement with them.

  • As a controller of account holder data, we rely on: performance of a contract (operating Qik accounts), legitimate interests (security, fraud prevention, service operation), consent (optional communications), and legal obligation.

Data Retention

We retain personal information for as long as the relevant Qik account is active. When an account is closed or a subscription is cancelled, we delete the associated personal information, subject to the exceptions below.

  • Customer Data: retained while the Customer Organisation maintains an active account with Qik. When a Customer Organisation cancels their subscription or closes their account, Customer Data is deleted within [INSERT — e.g., 90 days] of closure, except where we are legally required to retain specific records for longer.

  • Account holder data: retained while you maintain an active Qik account. When you close your account, your personal information is deleted within [INSERT — e.g., 90 days].

  • Billing records: retained for 7 years as required by Australian tax and accounting laws, regardless of account status. Card data is held by Stripe, not by Qik.

  • Backups: Customer Data may persist in encrypted backups for a limited period after deletion before being overwritten in the normal course of backup rotation. Our current backup retention is approximately [INSERT — e.g., 35 days], determined by our AWS and MongoDB Atlas configuration.

  • Server logs: technical logs (IP addresses, user IDs, session IDs, request metadata, error logs) are retained for up to [INSERT — e.g., 90 days] for security, fraud prevention, and debugging, then automatically rotated. A copy of operational log data is also retained within Grafana Cloud for service health monitoring, in accordance with our Grafana Cloud plan's retention settings.

If you exercise your right to deletion under applicable privacy law, we will action your request within the timeframes required by law, subject to legal retention obligations (such as billing records) and the backup-rotation period described above.

Security

We apply reasonable technical and organisational measures to protect personal information against unauthorised access, alteration, disclosure, or destruction. These include:

  • Encryption in transit: TLS for all connections to the Service

  • Encryption at rest: Customer Data encrypted at rest within MongoDB Atlas and AWS infrastructure

  • Access controls: least-privilege access for Qik staff; multi-factor authentication for administrative access; role-based access controls within the Service

  • Network security: private networking, firewalls, and security group restrictions

  • Logging and monitoring: access logs and security monitoring on production systems

  • Sub-processor due diligence: we select reputable sub-processors and contractually require equivalent security standards

  • Backups: regular encrypted backups stored within the same Australian region

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Data Breach Notification

If we become aware of a data breach affecting Customer Data, we will:

  • Notify the affected Customer Organisation without undue delay, and in any event within 72 hours]of becoming aware

  • Provide the information the Customer Organisation reasonably needs to assess the breach and meet their own notification obligations

  • Cooperate with the Customer Organisation's investigation and response

The Customer Organisation, as controller, is responsible for notifying affected individuals and regulators (such as the OAIC under the Notifiable Data Breaches scheme, or supervisory authorities under the GDPR/UK GDPR).

For breaches affecting account holder data for which Qik is the controller, we will notify affected individuals and the OAIC as required by the Notifiable Data Breaches scheme.

Your Rights

If you are an account holder (you log into Qik on behalf of a Customer Organisation), you have the right to:

  • Access the personal information we hold about you

  • Request correction of inaccurate or incomplete information

  • Request deletion of your personal information, subject to legal exceptions

  • Object to or restrict processing in certain circumstances

  • Withdraw consent where processing is based on consent

  • Lodge a complaint with a privacy regulator (see "Complaints" below)

Contact us at support@qik.dev to exercise these rights. We will respond within the timeframes required by applicable law (typically 30 days). We may need to verify your identity before actioning a request.

If you are an individual whose information is held within a Customer Organisation's Qik instance, please direct your privacy requests to that organisation. Qik can act on Customer Data only on the organisation's instructions.

Cookies and Similar Technologies

We use only essential cookies and similar technologies needed to operate the Service, including to:

  • Keep you signed in

  • Remember your preferences

  • Maintain session security

We do not use cookies for behavioural analytics, advertising, or marketing. You can control cookies through your browser settings, but disabling essential cookies will prevent the Service from functioning correctly.

Complaints

If you have a concern about how we have handled personal information, please contact us first at support@qik.dev. We will work to resolve it.

If you are not satisfied with our response, you may lodge a complaint with the relevant regulator:

  • Australia: Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au

  • European Economic Area: the data protection authority in your country of residence

  • United Kingdom: Information Commissioner's Office (ICO) — www.ico.org.uk

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The "Last Updated" date reflects the most recent revision.

If we make material changes, we will provide reasonable notice — by email to Customer Organisation account holders or by a prominent notice within the Service — before the changes take effect.

Contact Us

  • Email: support@qik.dev

  • Postal address: Melbourne, 3156 Victoria, Australia

  • ABN: 99 681 746 010