Legal
GDPR Statement & Data Processing Summary
Our commitment to EU/EEA data protection rights.
Last updated August 10, 2026
At clikd: (https://clikd.app), operated by Cheriie AB (org. nr: 559527-2393, VAT: SE559527239301, Sturegatan 18 A, 211 50 Malmö, Sweden), we are committed to protecting personal privacy, maintaining robust data security, and adhering strictly to the European Union General Data Protection Regulation (EU GDPR 2016/679) and UK GDPR.
This GDPR Statement outlines our data protection framework, our roles under European privacy law, and how we empower Creators ("Sellers", "Admins") to run compliant digital storefronts, communities, and multi-channel social workflows.
1. Dual Data Roles: Controller vs. Processor
+---------------------------------------------------------------------------------+
| Cheriie AB / clikd: PLATFORM |
+---------------------------------------------------------------------------------+
| |
| (clikd: as DATA CONTROLLER) | (clikd: as DATA PROCESSOR)
v v
+-----------------------------+ +-----------------------------+
| CREATOR ACCOUNT DATA | | END-CUSTOMER / MEMBER DATA|
| (Name, Billing, API Tokens) | | (Course progress, Purchases)|
+-----------------------------+ +-----------------------------+A. clikd: as Data Controller
Cheriie AB acts as the Data Controller for the personal data of our registered Creators and direct platform users (account credentials, billing details, custom domain routing, connected social API tokens, and AI prompt logs).
B. clikd: as Data Processor (for Creators)
When Creators host digital storefronts, sell courses, or build communities on clikd:, the Creator acts as the Data Controller for their End-Customers' data. Cheriie AB acts as the Data Processor, processing End-Customer data solely on the Creator's behalf pursuant to Article 28 GDPR.
2. Technical & Organizational Security Measures (Art. 32 GDPR)
- Encryption in Transit: All web and API traffic is encrypted using TLS 1.3 / HTTPS with HSTS enforcement.
- Custom Domain SSL: Automated SSL certificates are provisioned for all PRO custom domains via Vercel Edge API.
- Encryption at Rest: Primary PostgreSQL databases (Supabase EU) and automated backups are encrypted using AES-256.
- API Vault Isolation: Third-party OAuth tokens (Meta, Pinterest, TikTok, YouTube, OpenAI) are encrypted and stored in environment-isolated vaults.
- AI Data Privacy: Text prompts sent to the OpenAI API are processed in ephemeral sessions and never used to train public LLM models.
3. Sub-processors List
| Sub-processor | Purpose | Processing Location | Safeguard Mechanism |
|---|---|---|---|
| Supabase Inc. | Relational Database, Auth & Realtime | EU (Frankfurt / Dublin) | GDPR DPA / EU Hosting |
| Vercel Inc. | Web Application Hosting & Custom Domain Routing | EU / Global Edge | EU-U.S. Data Privacy Framework |
| OpenAI LLC | AI Copilot Text Generation | USA | Data Privacy Framework / DPA |
| Stripe Inc. | Card & Subscription Payment Processing | EU / USA | PCI-DSS Level 1 / DPA |
| Swish (Hippo/Banker) | Mobile BankID & 1-Tap Swish Payments | Sweden | Swedish Banking Standards |
| Meta Platforms Inc. | Instagram, Facebook & Messenger API | EU / USA | Meta Platform Terms / SCCs |
| TikTok Inc. | TikTok Content Posting & Analytics API | EU / USA | TikTok Developer DPA |
| Pinterest Inc. | Pinterest Pin Publishing & Board API | USA | Pinterest Developer Terms |
| Fortnox AB | Automated VAT Calculation & Invoice Sync | Sweden | Swedish Statutory Accounting Laws |
4. Fulfilling Data Subject Rights
Creators can export subscriber lists, member directories, and transaction histories in CSV/JSON format at any time. When an End-Customer or Creator requests account erasure ("Right to be Forgotten"), associated profiles and API tokens are deleted or permanently anonymized within 30 days.
For any GDPR inquiries, contact Cheriie AB's Data Protection Team at hello@clikd.app.
See also our Privacy Policy and Terms of Service.