Privacy Policy
Last updated: August 27, 2026
1. Who we are
Taackk Pty Ltd (ABN 83 701 856 671) ("Taackk", "we", "us", or "our") operates the fractional executive marketplace at taackk.com. We are the data controller for personal data processed through our platform. For privacy enquiries, contact us at [email protected].
2. Data we collect
We collect the following categories of personal data:
- Account data: name, email address, password (stored as a bcrypt hash — never in plain text), role, and subscription tier.
- Profile data: professional history, skills, industries, publications, and other information you provide when building your leader or business profile.
- Usage data: pages visited, features used, timestamps of actions, and IP addresses (retained for fraud prevention and audit purposes).
- Communications: messages exchanged through our platform between leaders and businesses.
- Payment data: billing information is processed by Stripe and is not stored on our servers. We retain only a Stripe customer ID and subscription status.
- Technical data: browser type, device type, and session tokens (stored in HTTP-only cookies).
3. How we use your data
We process your personal data on the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR): to provide the marketplace, match leaders with businesses, and manage your account.
- Legitimate interests (Art. 6(1)(f) GDPR): to detect and prevent fraud, improve our services, and maintain platform security.
- Legal obligation (Art. 6(1)(c) GDPR): to comply with applicable laws, including tax and financial regulations.
- Consent (Art. 6(1)(a) GDPR): for optional analytics cookies (you may withdraw consent at any time via our cookie banner).
4. Data retention
We retain personal data only as long as necessary for the purposes described above:
- Account data: for the duration of your account plus 30 days after deletion (to allow recovery).
- Audit logs: 12 months (required for security and compliance purposes).
- Login attempt records: 90 days (fraud prevention).
- Session tokens: automatically purged on expiry.
- One-time tokens (OTP, password reset, email verification): 30 days after use.
5. Your rights
Under GDPR and applicable privacy laws, you have the following rights:
- Right of access (Art. 15): request a copy of all personal data we hold about you. You can download this directly from your account settings.
- Right to rectification (Art. 16): correct inaccurate data via your profile settings, or contact us.
- Right to erasure (Art. 17): request deletion of your account and personal data. Contact [email protected].
- Right to data portability (Art. 20): download your data in machine-readable JSON format from your account settings.
- Right to object (Art. 21): object to processing based on legitimate interests.
- Right to restrict processing (Art. 18): request that we limit how we use your data.
- Right to withdraw consent: for analytics cookies, use the cookie banner at any time.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
6. Data sharing
We do not sell your personal data. We share data only with:
- Stripe: payment processing (PCI DSS Level 1 certified).
- OpenAI: AI-powered features such as profile generation and matching. Data is processed under OpenAI's data processing agreement and is not used to train their models.
- Infrastructure providers: cloud hosting and database services, bound by data processing agreements.
- Law enforcement: where required by law or to protect the rights and safety of our users.
7. Cookies
We use strictly necessary cookies (session management, CSRF protection) and, with your consent, analytics cookies (Google Analytics 4). You can manage your cookie preferences at any time using the cookie banner displayed on your first visit.
8. Security
We implement technical and organisational measures to protect your personal data, including: AES-256-GCM encryption for sensitive credentials, bcrypt password hashing (12 rounds), HTTP-only SameSite=Strict session cookies, TLS in transit, and role-based access controls. To report a security vulnerability, see our security disclosure policy.
9. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email or via a notice on the platform. Continued use of Taackk after changes take effect constitutes acceptance of the updated policy.
10. Contact
For any privacy-related enquiries, contact our Privacy Team at [email protected].