Kviklet
DeutschBack to website

Privacy Policy

Effective date: August 27, 2026

This Privacy Policy explains how Kviklet UG (haftungsbeschränkt) processes personal data when you visit https://kviklet.dev, contact us, request information, schedule a meeting, enter into or administer a business relationship with us, or make a payment through a payment service we offer.

It also explains the division of responsibilities for self-hosted Kviklet installations and the limited circumstances in which technical usage data may be transmitted to Kviklet.

1. Controller

Kviklet UG (haftungsbeschränkt), Alte Schönhauser Straße 23, 10119 Berlin, Germany

Represented by its managing directors, Jascha Beste and Daniel Quang Nguyen.

Email: info@kviklet.dev

2. Scope and Responsibilities

This Privacy Policy applies to Kviklet's public website, its contact and scheduling functions, payment processing, and Kviklet's own business communications and contract administration.

Kviklet is software that customers generally host and operate in their own environment. The organization operating a self-hosted installation is generally responsible for personal data processed inside that installation. Kviklet does not host the customer installation and does not routinely access databases, query results, logs, credentials, or personal data in the customer environment.

If Kviklet is asked to process personal data on a customer's behalf, for example through support, professional services, remote access, error reports, or agreed telemetry, appropriate data protection and security terms and, where required, a data processing agreement must be in place before that processing begins.

3. Personal Data We Collect

Depending on how you interact with us, we may process:

  • identity and business information, such as your name, company, job title, and role;
  • contact information, such as your email address and any other contact details you provide;
  • inquiry and communication data, such as your message, requested service, estimated user count, and correspondence history;
  • scheduling data, such as your selected date and time, time zone, booking-form responses, and meeting information;
  • website and device data, such as your IP address, timestamp, requested URL, referrer, browser, device, operating system, language settings, and HTTP status code;
  • analytics data, such as page views, interaction events, traffic source, approximate location, and online identifiers, but only where the required consent has been given;
  • contract, billing, and transaction data, such as billing contacts, billing address, tax identifiers, selected plan, invoice information, payment status, subscription status, refunds, and chargebacks;
  • payment-method and fraud-prevention data processed through Stripe, as described in Section 8;
  • limited technical usage data from a customer installation, but only where a relevant transmission is actually configured as described in Section 11.

Do not send production credentials, database contents, queries or query results, regulated data, special-category personal data, or other sensitive information through ordinary email, website forms, public issue trackers, or unencrypted channels. If such information is necessary for support or professional services, Kviklet must first agree a secure transfer process and the required data protection terms with the customer.

4. Purposes and Legal Bases

We process personal data for the following purposes and on the following legal bases:

Processing activityPurposeLegal basis
Website delivery and technical logsDelivering the website, maintaining stability, diagnosing errors, and preventing attacks and misuseArticle 6(1)(f) GDPR; our legitimate interests in secure, reliable, and economical website operation
Inquiries made by an individual on their own behalfResponding to the inquiry and taking requested steps before entering into a contractArticle 6(1)(b) GDPR
Inquiries from employees or representatives of an organizationBusiness communication, preparing proposals, and establishing or administering a relationship with the represented organizationArticle 6(1)(f) GDPR; our legitimate interests in business communication and contract administration
SchedulingOrganizing and holding a meeting requested by youArticle 6(1)(b) GDPR, or Article 6(1)(f) GDPR where you act for an organization
Contracts, billing, and paymentsEntering into and performing contracts, collecting fees, administering subscriptions, and keeping transaction recordsArticle 6(1)(b) GDPR; Article 6(1)(c) GDPR for legal, tax, and accounting duties; Article 6(1)(f) GDPR for organizational contacts
Payment security and dispute handlingPreventing fraud, securing payments, handling failed payments, refunds, disputes, and chargebacksArticle 6(1)(f) GDPR; our legitimate interests in secure payment processing and protecting legal and financial interests
Legal claimsEstablishing, exercising, or defending legal claimsArticle 6(1)(f) GDPR; our legitimate interests in protecting our rights
Google AnalyticsMeasuring website reach and improving the websiteYour consent under Article 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG
Technical usage dataLicense validation, checking agreed usage limits, and analyzing and improving software reliability and securityArticle 6(1)(b) or Article 6(1)(f) GDPR depending on the configuration and the parties' roles; see Section 11

Where we rely on consent, you may withdraw it at any time with effect for the future. Withdrawal does not affect processing that was lawful before withdrawal.

5. Website and Form-Backend Hosting

The website is delivered from Google Cloud Storage through Google Cloud infrastructure. Kviklet's own Enterprise and Consulting request forms use a backend service hosted on Google Cloud Run. Google and its subprocessors process technical request data and form data as necessary to provide this infrastructure, maintain availability and security, diagnose errors, and prevent misuse.

The relevant Google contracting entity and processing location depend on the Google Cloud account and service configuration. Google may process data outside the European Economic Area as described in Section 13.

Routine server logs are retained only for as long as they are needed for website operation and security. Data relating to a specific security incident may be retained until the investigation and any related legal claims are concluded.

6. Contact and Information-Request Forms and Email

Kviklet uses both Tally and its own website forms for contact and information requests.

Provider: Tally BV, Sint-Pietersnieuwstraat 11, 9000 Ghent, Belgium.

Tally processes form responses, contact details, timestamps, technical metadata, and other information you submit on our behalf. Tally states that form data is stored in the European Union and provides a data processing agreement. Depending on the enabled form functions, Tally may use subprocessors listed in its current documentation.

If you submit Kviklet's Enterprise or Consulting request form, we collect your email address, subject, message, request type, and, for Enterprise requests, the estimated number of seats. The form sends this information over HTTPS to Kviklet's backend on Google Cloud and then to the people responsible for responding through Kviklet's Google Workspace account. Kviklet does not use a separate database to retain these inquiries.

Kviklet uses Google Workspace for business email. If you contact us by email, Google processes sender and recipient details, message headers, message content, attachments, and technical metadata as our email service provider. Email and form inquiries are retained until the inquiry is concluded and afterwards only for as long as needed for a resulting business relationship, applicable legal obligations, or legal claims.

7. Scheduling Through Calendly

Kviklet uses Calendly to schedule requested meetings through the Kviklet booking account dan-kviklet.

Provider: Calendly LLC, 115 E Main Street, Suite A1B, Buford, Georgia 30518, United States.

Calendly processes information such as your name, email address, selected time, time zone, booking-form responses, technical request data, and calendar information needed to schedule and conduct the meeting. Calendly processes customer booking data on our behalf under its data processing addendum and also processes certain data for its own stated legal, security, and service-administration purposes.

Calendly states that it participates in the EU-US Data Privacy Framework. Where that framework does not apply, transfers may be protected through the European Commission's Standard Contractual Clauses and supplementary safeguards.

Scheduling and related communication data is retained for as long as needed to hold and follow up on the meeting, administer a resulting business relationship, comply with legal duties, or handle legal claims.

8. Payments Through Stripe

Where an Order Form, invoice, checkout page, or subscription provides for automatic payment, Kviklet uses Stripe to process the payment.

For a Stripe account located in the European Economic Area, the relevant Stripe entities may include Stripe Payments Europe, Limited, Stripe Technology Europe, Limited, and other Stripe entities involved in providing regulated payment, fraud-prevention, and platform services. The applicable entity depends on the service and processing activity.

When you enter payment details into a Stripe-hosted checkout page or payment form, the information is transmitted directly to Stripe over an encrypted connection. Stripe may process:

  • name, email address, phone number, billing or shipping address, and tax identifiers;
  • card, bank-account, wallet, or other payment-method information;
  • transaction amount, currency, merchant, date, payment status, subscription status, and purchased service;
  • invoice, refund, dispute, and chargeback information;
  • IP address, device identifiers, browser information, cookies, and activity signals used for authentication, security, and fraud prevention.

For Stripe-hosted payment collection, Kviklet does not receive or store the complete card number or card security code. Kviklet receives limited transaction information needed to administer the payment, such as the Stripe customer and transaction identifiers, payment status, amount, currency, payment-method type, and limited card information such as brand, expiry date, and last four digits where made available by Stripe.

Stripe processes payment data on our behalf when it follows our payment instructions. Stripe also acts as an independent or joint controller for certain activities required by financial-services law, payment-network rules, security, fraud prevention, and the administration and improvement of its services. Stripe may disclose data to banks, card networks, payment-method providers, identity and fraud-prevention services, affiliates, and subprocessors as necessary to process and secure the transaction.

For more information, see the Stripe Privacy Policy and Stripe Privacy Center.

9. Analytics, Cookies, and Similar Technologies

Kviklet uses Google Analytics 4 through the Google Tag with measurement ID G-4JEMLTWTRC to understand website use and improve the website.

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Depending on the processing, Google LLC in the United States and other Google entities or subprocessors may also receive data.

Google Analytics may process page views, interaction events, browser and device information, referrer information, approximate location, and online identifiers. It may use cookies including _ga and _ga_4JEMLTWTRC to distinguish users and sessions.

Google Analytics is activated only after you consent through the website's privacy settings. Consent is voluntary and may be withdrawn at any time through the same settings. If you do not consent, the Google Analytics tag does not send analytics data to Google or set analytics cookies.

Analytics cookies remain on your device until they reach the expiry configured for the Google tag or you delete them through your browser. Withdrawing consent stops future analytics collection but does not necessarily remove cookies already stored on your device. We retain user-level and event-level analytics data only for as long as needed for website measurement and improvement, subject to the retention controls available in our Google Analytics property. Google Analytics' standard aggregated reports are not governed by the same user- and event-level retention setting and may remain available for longer.

Essential storage may be used where strictly necessary to provide a service you expressly request or to remember your privacy choice. Contact-form and scheduling content from Tally or Calendly is loaded only when you request the relevant function. You can change your privacy choice at any time through the permanently available privacy settings.

10. External Links and Platforms

The website links to external platforms, including GitHub, LinkedIn, X/Twitter, Tally, and Calendly. If you follow an ordinary external link, the relevant platform processes data under its own privacy information from that point onward.

If you contact Kviklet through one of these platforms, we process the message and profile information you provide to respond to your inquiry under the legal bases described in Section 4. Kviklet does not collect information from your public profile merely because its website links to the platform.

11. Self-Hosted Installations, Support, and Technical Usage Data

Customers generally host and operate Kviklet themselves. Kviklet does not offer a cloud product or managed hosting of customer installations as its default model. The customer is responsible for operation, configuration, security, logging, retention, backups, credentials, and the lawfulness of processing inside its environment.

Under the baseline model without separately agreed processing, Kviklet does not receive databases, queries or query results, credentials, logs, backups, support exports, telemetry, or personal data from the customer environment. Customers must not provide such information through support, remote access, screenshots, screen sharing, public issue trackers, or unencrypted channels unless a secure process and the required data protection terms have first been agreed.

Depending on the edition, configuration, and contractual arrangement, the software may transmit limited technical usage data to Kviklet or an analytics provider. The categories must be documented in the product documentation and may include license status, software version, enabled user or seat count, use of individual features, and error reports. Under the Software License Agreement, technical usage data does not include database contents, queries or query results, credentials, or other customer-environment content.

Optional transmissions may be disabled using the configuration described in the product documentation. License validation required for Enterprise Features may remain enabled. Kviklet uses this data only to validate licenses, check agreed usage limits, and analyze and improve software reliability and security.

Before personal technical usage data is transmitted, the relevant product documentation and contractual terms must specify the fields, frequency, recipients, roles, legal basis, retention, disabling options, and international transfers. Where Kviklet processes the data on the customer's behalf, an appropriate data processing agreement must be in place first. Personal usage data is deleted or anonymized when no longer needed. Aggregated or anonymized information may be retained for longer.

12. Recipients and How We Disclose Data

We disclose personal data only where necessary for the purposes described in this Policy. Disclosure occurs through controlled account access, provider interfaces, encrypted network connections, hosted forms or checkout pages, or other agreed secure transfer channels. We do not sell personal data.

Depending on the processing activity, recipients may include:

  • Google as website infrastructure and business-email provider and, after consent, analytics provider;
  • Tally as form provider;
  • Calendly as scheduling provider;
  • Stripe, banks, card networks, payment-method providers, and related payment and fraud-prevention providers;
  • our email and business-communication providers;
  • a technical usage-data provider only if transmission under Section 11 is configured;
  • legal, tax, accounting, and audit advisers where necessary;
  • courts, regulators, law-enforcement agencies, or other authorities where legally required or necessary for legal claims.

Where a provider processes personal data solely on our behalf, we use a data processing agreement meeting Article 28 GDPR requirements. Some providers also process data as independent or joint controllers for their own legally defined purposes, as explained in their privacy information.

13. International Transfers

Google, Calendly, Stripe, and their subprocessors may process personal data outside the European Economic Area, including in the United States. We permit an international transfer only where the applicable legal requirements are met.

Depending on the recipient and processing activity, transfers may rely on an adequacy decision of the European Commission, including a recipient's valid certification under the EU-US Data Privacy Framework, the European Commission's Standard Contractual Clauses with supplementary safeguards where required, or a specific statutory exception.

You may request information about or a copy of the relevant transfer safeguards using the contact details in Section 1.

14. Retention

We retain personal data only for as long as needed for the relevant purpose. We then delete or anonymize it unless a legal retention duty, an overriding legitimate interest, or the establishment, exercise, or defense of legal claims requires longer retention.

The following criteria apply:

  • routine website logs are retained until the operational or security purpose ends; incident data may be retained until the investigation and related claims are concluded;
  • analytics data is retained as described in Section 9;
  • inquiry and scheduling data is retained until the matter is concluded and afterwards only for a resulting business relationship, legal obligations, or legal claims;
  • contracts, invoices, payments, tax records, and accounting documents are retained for the applicable statutory retention periods;
  • Stripe retains payment data according to its legal, regulatory, contractual, and fraud-prevention obligations, as described in its privacy information;
  • personal technical usage data is retained for the period documented before the transmission is enabled;
  • data relating to disputes or legal claims is retained until the matter and applicable limitation periods are concluded.

15. Security Practices

We use technical and organizational measures appropriate to the nature of the data and the processing risk. These practices include, as applicable:

  • using HTTPS and transport encryption for the website and provider connections;
  • directing payment-method information to Stripe-hosted payment interfaces so Kviklet does not store complete card numbers or card security codes;
  • restricting access to personal data to authorized people and providers who need it for their role;
  • using authentication, account permissions, and provider access controls;
  • minimizing the personal data collected and separating customer-environment data from ordinary business systems;
  • requiring appropriate confidentiality and data protection terms from service providers;
  • using agreed secure transfer channels before receiving sensitive support materials;
  • applying retention, deletion, and anonymization controls;
  • reviewing suspected security incidents and notifying affected parties or authorities where legally required.

Stripe states that it is certified as a PCI DSS Level 1 service provider and uses encryption and other controls to protect payment data. Further information is available in Stripe's security documentation.

No transmission or storage system can be guaranteed to be completely secure. If you believe data has been compromised, contact us promptly at info@kviklet.dev.

16. Required and Optional Data

Fields marked as required in contact, scheduling, billing, or payment forms are needed to process the relevant request, arrange a meeting, enter into or administer a contract, issue a compliant invoice, or complete a payment. If you do not provide required information, we may be unable to provide the requested function or service. Other information is voluntary.

There is generally no statutory requirement to provide personal data merely to browse the website or submit an ordinary inquiry. Certain identity, billing, tax, transaction, and recordkeeping data may be required by contract or law when you purchase a service.

17. Your Rights

Subject to the conditions of the GDPR, you may have the right to:

  • obtain access to your personal data;
  • correct inaccurate or complete incomplete data;
  • request deletion of your data;
  • restrict processing;
  • receive data in a portable format where applicable;
  • withdraw consent at any time with effect for the future;
  • object to processing based on legitimate interests;
  • lodge a complaint with a data protection authority.

Right to Object

You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. We will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed for legal claims.

If personal data is processed for direct marketing, you may object at any time without giving a reason. We will then stop using the data for direct marketing.

To exercise your rights, contact info@kviklet.dev. If we have reasonable doubts about your identity, we may request the additional information necessary to verify it.

Stripe may act as an independent controller for some payment-processing activities. Requests relating to data controlled by Stripe may also be submitted to Stripe as described in its Privacy Policy.

18. Right to Lodge a Complaint

You may lodge a complaint with a data protection supervisory authority. The authority responsible for Kviklet is:

Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin, Germany

Website: https://www.datenschutz-berlin.de

You may also contact the authority for your habitual residence, place of work, or the place of the alleged infringement.

19. Automated Decision-Making

Kviklet does not use the personal data described in this Policy to make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.

Stripe and other payment providers may use automated fraud and risk models as part of their own payment-security activities. Information about Stripe's processing is available in the Stripe Privacy Center.

20. Changes to This Policy

We update this Privacy Policy when our processing activities, service providers, or legal requirements change. The version published on the website applies from the effective date shown at the beginning.

21. Language Versions

English is the default language of this Privacy Policy. A German version is available at https://kviklet.dev/privacy-policy/de. Both versions are intended to provide the same substantive information.

© 2026 Kviklet
ImpressumPrivacy PolicySoftware License Agreement