Privacy Policy
Last updated: August 2026
Company information
Maiky BV is a Belgian company (registration: BE0718712887) and is the data controller for the processing described here. The company values privacy and personal data security.
Maiky has appointed a Data Protection Officer. You can reach our DPO at privacy@maiky.io.
Policy scope
This privacy policy applies to personal data processing by Maiky as data controller for:
- Website usage
- The Maiky governance, risk and compliance (GRC) and information-security management platform
- Platform usage by registered users
Data collection and usage
Information collected
Users may voluntarily provide personal information including name, address, telephone number and email address through various interactions with Maiky.
Primary processing purposes
- Contact responses: Answering enquiries and sending marketing communications
- Event registration: Managing seminar, demo and workshop registrations
- Publication subscriptions: Delivering newsletters and alerts
- Trial accounts: Processing trial account requests and access
- Contract management: Handling agreements, invoicing and accounting
- Platform security: Detecting abuse and maintaining integrity
- Analytics: Understanding website and platform usage patterns
Third-party data integration
We use a customer-relationship management (CRM) system to manage communications, and Google Analytics 4 (Google Ireland Limited) together with Hotjar (Hotjar B.V., Netherlands) to understand how our website is used. Analytics are loaded only after you accept analytics cookies; see our Cookie Policy for the full list and retention periods. Where you interact with us through third-party platforms (for example social media or advertising networks), we may receive related data from those platforms.
Legal basis for processing
Processing relies on:
- Contract execution
- Legitimate business interests
- Compliance with legal obligations
- User consent (particularly for cookies and direct marketing)
Data protection measures
Maiky implements administrative, technical and organisational measures to ensure the security and confidentiality of your personal data, including access controls, encryption in transit and multi-factor authentication on systems that hold personal data.
Data retention
Personal data is retained only as long as necessary for the stated purposes or as legally required. Specific retention periods are available upon request.
Data sharing
Personal data may be shared with:
- Hosting and IT service providers
- CRM and marketing-tool providers
- Affiliated companies
- Contractual partners
- Law enforcement and regulatory agencies when legally required
- Professional advisors and auditors
- Prospective purchasers in a merger or acquisition context
International transfers
Where personal data is transferred outside the EEA, such transfers are governed by appropriate safeguards, such as the European Commission's Standard Contractual Clauses, together with any additional measures required to protect your data.
Your rights
Data subjects have the following rights:
Right to information and access
You may request information regarding data processing activities and your personal data file.
Right to rectification
You may request correction or supplementation of inaccurate or incomplete data.
Right to erasure ('right to be forgotten')
Data erasure is available when:
- Data is no longer necessary for the purposes for which it was collected
- Processing is consent-based
- Serious grounds exist to object
- Processing is unlawful
- A legal erasure obligation applies
Exceptions include freedom of expression, legal compliance, public health, archiving, research and legal claim purposes.
Right to restrict processing
You may restrict processing when:
- Data accuracy is contested
- Processing is unlawful
- Data is no longer needed but is required for legal claims
- Legitimate-interest objections are pending verification
Right to object
You may object to processing based on legitimate interests or prior consent at any time. For direct marketing, the right to object is absolute. You also have the right not to be subject to a decision based solely on automated processing, including profiling.
Right to data portability
Under certain conditions (consent or contract basis, automated processing), you may receive your data in a structured, machine-readable format and transmit it to other controllers.
Exercising your rights
To exercise your rights or update your information, contact privacy@maiky.io. You must provide proof of identity if necessary. Requests are generally free unless manifestly unfounded or excessive.
Unsubscribe options
To stop receiving marketing communications, you may:
- Email privacy@maiky.io
- Click the unsubscribe link in our emails
- Complete the contact form on the website
Complaints
You may lodge a complaint with the Belgian Data Protection Authority:
- Address: Rue de la Presse 35, 1000 Brussels
- Phone: +32 (0)2 274 48 00
- Website: https://www.dataprotectionauthority.be/
- Complaint form: https://www.dataprotectionauthority.be/citizen/actions/lodge-a-complaint
- Email: contact@apd-gba.be
Policy updates
Maiky may amend this policy. Material changes will be communicated actively to users with contact details on file. The latest version is always available on the website.
Contact
For privacy-related questions: privacy@maiky.io
Governing law: the EU General Data Protection Regulation (GDPR) and the Belgian Law of 30 July 2018 on the protection of personal data.