1. Introduction

TicQ ("we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, process, and protect your personal information in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.

2. Data Controller

The data controller responsible for your personal data is:

TicQ AB
Sweden
Email: privacy@ticq.se

3. Personal Data We Collect

3.1 Account Information

  • Name and email address
  • Password (stored in hashed form)
  • Workspace and team information
  • Account preferences and settings

3.2 Usage Data

  • Time entries and project data
  • Client and article information
  • Integration data (Fortnox, ABAX)
  • Login activity and timestamps

3.3 Technical Data

  • IP addresses and device information
  • Browser type and version
  • Session data

4. Legal Basis for Processing

We process your personal data based on:

  • Contract Performance: To provide the Service you subscribed to
  • Consent: When you explicitly agree to specific processing activities
  • Legitimate Interests: For service improvement, security, and fraud prevention
  • Legal Obligations: To comply with applicable laws and regulations

5. How We Use Your Data

We use your personal data to:

  • Provide, maintain, and improve the Service
  • Process your transactions and manage subscriptions
  • Communicate with you about the Service
  • Provide customer support
  • Ensure security and prevent fraud
  • Comply with legal obligations
  • Integrate with third-party services you authorize (Fortnox, ABAX)

6. Data Sharing and Disclosure

We do not sell your personal data. We may share your data with:

6.1 Service Providers

We use trusted third-party service providers who process data on our behalf:

  • Cloud hosting and infrastructure providers
  • Payment processors
  • Email service providers

6.2 Third-Party Integrations

When you enable integrations (Fortnox, ABAX), we share relevant data with these services as necessary to provide the integrated functionality. You control these integrations through your account settings.

6.3 Legal Requirements

We may disclose your data if required by law, court order, or governmental authority.

7. International Data Transfers

Your data is primarily stored and processed within the European Economic Area (EEA). If we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.

8. Data Retention

We retain your personal data for as long as:

  • Your account is active
  • Necessary to provide the Service
  • Required by law or for legitimate business purposes

After account termination, we retain data for 30 days to allow data recovery, then delete it in accordance with our data retention schedule. Some data may be retained longer where required by law (e.g., financial records).

9. Your Rights Under GDPR

You have the following rights regarding your personal data:

9.1 Right of Access

Request a copy of the personal data we hold about you.

9.2 Right to Rectification

Request correction of inaccurate or incomplete data.

9.3 Right to Erasure ("Right to be Forgotten")

Request deletion of your personal data under certain conditions.

9.4 Right to Restriction of Processing

Request that we limit how we use your data.

9.5 Right to Data Portability

Receive your data in a structured, machine-readable format and transfer it to another service.

9.6 Right to Object

Object to processing based on legitimate interests or for direct marketing.

9.7 Right to Withdraw Consent

Withdraw consent for processing where we rely on consent as the legal basis.

9.8 Right to Lodge a Complaint

Lodge a complaint with your national data protection authority.

To exercise these rights, contact us at: privacy@ticq.se

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit and at rest
  • Access controls and authentication
  • Regular security assessments
  • Employee training on data protection
  • Incident response procedures

11. Cookies and Tracking

We use essential cookies to maintain your session and ensure the Service functions properly. These cookies are necessary for the Service and do not require consent.

We do not use third-party analytics or advertising cookies.

12. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. The "Last updated" date at the top of this page indicates when the policy was last revised.

14. Contact Us

For questions about this Privacy Policy or to exercise your data rights, contact us at:

Email: privacy@ticq.se
Data Protection Officer: dpo@ticq.se