Privacy Policy
Updated:
1. Scope and Application
This Privacy Policy applies to personal information processed in connection with:
our public-facing websites and related properties, including our marketing website, support portal, documentation portal, developer portal, and service-status page (collectively, the "Websites");
the Takt Warehouse Intelligence Platform, including the web application, mobile applications, kiosk and Virtual Kiosk applications, TaktTV, APIs, and related integrations (collectively, the "Platform"); and
our business communications with customers, prospects, partners, and other business contacts.
The Platform is an enterprise business-to-business service. The Websites are directed to business users, and neither the Websites nor the Platform is directed to consumers or to children. This Policy does not apply to third-party websites, products, or services that we do not control.
2. Our Role: Controller and Processor
Takt processes personal information in two distinct capacities, and the obligations and rights described in this Policy differ accordingly.
Controller. In respect of personal information collected through our Websites and our own marketing, sales, support, documentation, developer, and service-status activities, Takt determines the purposes and means of processing and therefore acts as a data controller.
Processor. In respect of the workforce and operational data that our customers make available through the Platform, Takt processes personal information on behalf of, and under the documented instructions of, its customers. In that context, Takt acts as a data processor (or service provider under applicable U.S. state law), and the customer acts as the controller. Each customer is responsible for establishing a lawful basis for its processing, providing any required employee-facing or workplace-monitoring notices, determining what data is transferred to Takt, and validating and instructing Takt on data subject requests.
Processing of Platform data is governed by the applicable customer agreement, including the Software Licensing Agreement and the Data Processing Addendum where applicable. This Policy describes Takt's practices for transparency and does not modify those contractual terms.
3. Personal Information We Collect
3.1 Information collected as a controller (Websites and business contacts)
When you interact with our Websites or communicate with us, we may collect:
Business contact information you provide, such as name, business email address, company name, job title, and telephone number, together with the content of demo requests, inquiries, and correspondence.
Marketing and relationship information, such as communication preferences, campaign engagement, event participation, and relationship history.
Business-contact data obtained from third-party sources. For business development, we may obtain or supplement business-contact and firmographic information (such as name, business email, employer, and job title) from third-party business-data and enrichment providers and from advertising and analytics signals, rather than directly from you. Where we obtain personal information about you from such sources and you are located in the United Kingdom or European Economic Area, we provide the information required by Article 14 of the UK GDPR and EU GDPR and honor objection and erasure requests as described in Section 8.
Technical and usage information collected automatically, such as IP address, browser type and settings, device information, request metadata, pages viewed, referring URLs, search and navigation activity, and cookie or similar identifiers.
Support, documentation, and developer information, such as account and business-contact details, support-request content, attachments, and documentation or API-portal usage.
Service-status subscription information, such as the contact details and preferences of individuals who subscribe to incident and maintenance notifications.
We do not intentionally collect special-category data or other sensitive information through our Websites, and we ask that you not submit it.
3.2 Information processed as a processor (Platform)
On behalf of our customers, and depending on customer configuration and the data each customer supplies, the Platform may process the following categories of personal information relating to the customer's workforce and authorized users:
employee, worker, and user names and identifiers;
business email addresses and, where SMS one-time-passcode authentication is enabled, mobile telephone numbers;
job role, and facility, department, team, shift, and schedule attributes;
manager or reporting-hierarchy information;
attendance and time-clock records, work transactions, scan activity, and indirect-activity records;
productivity and performance metrics, goals, and labor standards;
manager observations, feedback, and coaching records;
authentication, access, device, IP, and application-log information; and
other data submitted or configured by the customer.
Wage or compensation data is configurable within the Platform but is not currently in use by any customer; where a customer chooses to enable it, that data is processed only as supplied by the customer and only after the applicable data-processing terms are confirmed. Takt does not intentionally require or request biometric, health, disability, union-membership, racial or ethnic origin, religious-belief, sexual-orientation, or criminal-conviction information for the core service, and customers are instructed not to submit such information unless expressly agreed in writing.
3.3 Mobile applications and Bluetooth proximity features
Our mobile and kiosk applications support certain proximity features using Bluetooth Low Energy (BLE) beacons within a customer's facility — for example, Virtual Kiosk check-ins and nearby workstation or task prompts. On Android, beacon scanning is classified by the operating system as a location permission, and the application may therefore request location access for this purpose. These features are used only to detect proximity to fixed beacons inside a facility. They are not used for GPS tracking, continuous geolocation, consumer location sharing, or advertising.
4. How We Use Personal Information
As a controller, we use personal information to:
operate, maintain, secure, and improve our Websites, and to prevent, detect, and investigate abuse or security events;
respond to demo requests, inquiries, and other business communications, and to take steps at your request before entering into a contract;
manage customer and prospect relationships and send requested or permitted business communications, and to measure their effectiveness;
provide documentation, developer resources, support, and service-status information; and
comply with legal obligations and establish, exercise, or defend legal claims.
As a processor, we process Platform data only to provide, secure, support, and improve the contracted services in accordance with customer instructions and the applicable agreement. Takt does not sell customer data, does not use customer data for advertising, and does not process customer data for purposes unrelated to providing the contracted services.
TaktAI
The Platform includes TaktAI features that provide summaries, analysis, conversational assistance, and suggested observations using customer-authorized data. TaktAI operates exclusively on Google Cloud Vertex AI (Gemini) under Takt's enterprise terms, under which customer prompts and responses are not used to train Google's foundation models. Takt does not use customer personal information to train generalized or foundation models. AI-generated outputs are informational and are reviewed and validated by human users before adoption; TaktAI does not independently make or execute employment decisions.
5. Legal Bases for Processing (UK/EEA)
Where the UK GDPR or EU GDPR applies to processing for which Takt is the controller, we rely on the following legal bases:
Legitimate interests (Article 6(1)(f)) — to operate and secure our Websites and prevent abuse; to conduct relevant business-to-business marketing and lead generation, including business-contact enrichment; and to provide documentation and developer resources. We maintain legitimate-interests assessments for these activities, and you may object as described in Section 8.
Consent (Article 6(1)(a)) — for non-essential cookies and similar technologies (including analytics and advertising) and for optional notifications. You may withdraw consent at any time.
Performance of a contract or steps at your request (Article 6(1)(b)) — to respond to inquiries and manage an existing business relationship.
Legal obligation (Article 6(1)(c)) — to comply with applicable law.
Where Takt acts as a processor for Platform data, the customer (as controller) is responsible for determining and documenting the lawful basis for its processing.
6. Cookies and Similar Technologies
Our Websites use cookies and similar technologies that are strictly necessary to deliver and secure the site, and — subject to your consent — analytics and advertising technologies that help us measure usage and the effectiveness of our marketing. Non-essential cookies and tags are blocked until you opt in through our consent-management banner, and consent signaling is applied to gate analytics and advertising tags accordingly. You can change or withdraw your cookie choices at any time through the banner or your browser settings. For more detail on the specific technologies used, please refer to our cookie notice and Trust Center.
7. How We Disclose Personal Information
We do not sell personal information. We may disclose personal information to the following categories of recipients:
Service providers and subprocessors that support our Websites and Platform, including cloud hosting and infrastructure, website and documentation hosting, authentication and identity, email and messaging delivery, analytics and advertising, customer-relationship and marketing tools, business-data and enrichment providers, customer-support and incident-response tooling, and internal administration tools. These providers are bound by contractual obligations to protect personal information and to process it only as instructed.
Customers and their authorized users, in respect of Platform data processed on the customer's behalf.
Professional advisers, such as legal, accounting, and audit advisers, under duties of confidentiality.
Public authorities, courts, or other third parties where required to comply with applicable law or legal process, to protect rights, property, or safety, or to enforce our agreements.
Parties to a corporate transaction, such as a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.
An authoritative, current list of the subprocessors that support the Platform is maintained through Takt's Trust Center at trust.takt.io.
8. Your Privacy Rights
8.1 Rights under the UK GDPR and EU GDPR
Subject to applicable law, individuals in the United Kingdom and European Economic Area have the right to request access to, and rectification or erasure of, their personal information; to restrict or object to processing; to data portability; and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority.
Where Takt is the controller (Website, marketing, support, documentation, developer, and service-status data), we will verify your identity by reasonable and proportionate means and respond without undue delay and in any event within one month of receipt. That period may be extended by up to two further months for complex or numerous requests, in which case we will inform you within one month. We provide our response free of charge, except where a request is manifestly unfounded or excessive.
Where Takt is the processor (Platform workforce data), the customer is the controller. If you are a member of a customer's workforce, please direct your request to your employer or the relevant Takt customer. If you contact us directly about Platform data, we will not act on the underlying data except on the customer's verified instruction; we will acknowledge your request, forward or refer it to the relevant customer without undue delay, and provide reasonable assistance to that customer as required by the applicable agreement and Article 28 of the GDPR.
8.2 Rights under U.S. state privacy laws (including California)
Depending on your state of residence, U.S. state privacy laws — including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) — may provide rights to know or access the categories and specific pieces of personal information collected; to delete or correct personal information; to opt out of the sale or sharing of personal information and of targeted advertising; and to limit the use of sensitive personal information. Takt does not sell personal information and does not share personal information for cross-context behavioral advertising in the manner defined by these laws. We will not discriminate against you for exercising your rights. You may use an authorized agent to submit a request, and, where required, you may appeal a decision by contacting us. For workforce data processed through the Platform, requests should be directed to the relevant customer as the business.
8.3 How to exercise your rights
To exercise any right for which Takt is the controller, contact us at privacy@takt.io. We may need to request additional information to verify your identity before acting on a request.
9. International Data Transfers
Takt is established in the United States, and personal information we process may be transferred to, and processed in, the United States and other countries where we or our service providers operate. Where personal information is transferred from the United Kingdom or the European Economic Area to a country that has not received an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, and, where a provider is self-certified, the EU–U.S. Data Privacy Framework and its UK extension. We confirm the applicable transfer mechanism for each provider as part of vendor onboarding and support these transfers with a documented transfer impact assessment and appropriate technical and organizational measures. You may contact us at privacy@takt.io for further information about the safeguards we apply.
10. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.
Category | Retention |
|---|---|
Platform (customer workforce) data | For the customer contract term and up to 90 days after termination or expiration, unless the customer deletes the data earlier or a different period is required by law or contract. |
TaktAI prompts, responses, and conversation history | For the customer contract term and up to 90 days after termination or expiration, consistent with core Platform retention. |
Backups containing customer data | Rolling backup snapshots retained for 30 days and deleted or overwritten through the normal backup lifecycle. |
Security, audit, application, diagnostic, and incident logs | Up to 1 year. |
Marketing, prospect, and CRM data (controller) | While relevant to the business relationship or marketing purpose; suppression records may be retained to honor opt-out requests. |
Website security and operational records (controller) | Only as long as reasonably necessary for security, troubleshooting, and legal purposes, subject to provider configurations. |
Following the applicable retention period, personal information is securely deleted or anonymized, subject to any legal hold, security requirement, or contractual exception that applies.
11. Information Security
Takt maintains technical and organizational measures designed to protect personal information against unauthorized access, loss, alteration, disclosure, or destruction, including: encryption of data in transit using TLS 1.2 or higher and encryption of data at rest using AES-256; role-based access controls and least-privilege authorization; multi-factor authentication for privileged access; logical separation of customer environments; centralized secrets management; logging, monitoring, and alerting; vulnerability management and secure software-development practices; documented incident response; and backup, disaster-recovery, and business-continuity controls. Takt maintains a SOC 2 Type II compliance program and engages independent penetration testing. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Children's Privacy
Our Websites and services are not directed to individuals under the age of 16, and we do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without appropriate consent, we will take steps to delete it.
13. Data Protection Officer and EU/UK Representatives
Takt has assessed that it is not required to appoint a statutory Data Protection Officer under Article 37(1) of the GDPR, as its core activities do not consist of large-scale systematic monitoring or large-scale processing of special-category data. Privacy matters are handled through the contact below, and this assessment is reviewed at least annually. Takt is in the process of appointing representatives in the European Union and the United Kingdom under Article 27 of the EU GDPR and UK GDPR; once appointed, their contact details will be published in this Policy.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the effective date above and, where appropriate, provide additional notice. We encourage you to review this Policy periodically.
15. How to Contact Us
For questions about this Privacy Policy or our data-handling practices, or to exercise a privacy right for which Takt is the controller, contact us at:
Takt, Inc.
1902 Campus Commons Drive, Suite 200
Reston, VA 20191, United States
Privacy: privacy@takt.io
Security: security@takt.io
Support: help@takt.io
If you are in the United Kingdom or European Economic Area, you also have the right to lodge a complaint with your local data protection supervisory authority.