DataTako privacy statement

Effective date: 01-02-2026
Last updated: 10-08-2026
Version: 2.1

Download as PDF

1. Introduction

This Privacy Statement (the "Statement") describes how DataTako B.V. ("DataTako", "we", "us", or "our") collects, uses, discloses, and otherwise processes personal data in connection with the DataTako software-as-a-service platform (the "Service"), the website at www.datatako.com, and all related applications, APIs, and customer-facing interfaces (together, the "Platform").

This Statement is designed to comply with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), the EU ePrivacy Directive (2002/58/EC) as transposed in the relevant Member States, and applicable national data protection legislation. Where DataTako processes personal data on behalf of a customer (as further described in Section 4), this Statement is supplemented by the Data Processing Agreement ("DPA") concluded between DataTako and that customer.

By using the Platform, data subjects acknowledge that their personal data may be processed as described in this Statement. This Statement does not, by itself, constitute a contract between DataTako and any data subject and does not waive rights granted under the GDPR.

2. Who we are

DataTako is operated by:

FieldDetail
Legal entityDataTako B.V.
Legal formBesloten Vennootschap / B.V.
Registered officeAntareslaan 65, 2132JE Hoofddorp
Chamber of Commerce / company number96958081
VAT numberNL869855384B01
General contactinfo@datatako.com
Privacy contactprivacy@datatako.com
Data Protection OfficerNot appointed; a designated privacy contact is reachable at privacy@datatako.com

DataTako is established in the European Union and the Platform is hosted within the European Union (see Section 9).

3. Roles: Controller and Processor

DataTako acts in two distinct capacities under the GDPR, and the legal basis, retention period, and rights-handling procedure depend on which capacity applies to a given processing activity.

3.1 DataTako as Processor

For personal data that is uploaded to, embedded in, or otherwise made available within reports, dashboards, datasets, content items, media items, or other customer-controlled resources on the Platform, the customer (typically the organization that has subscribed to the Service) is the controller. DataTako acts as processor and processes such data solely on documented instructions from the customer in accordance with the DPA.

This includes, in particular:

For these processing activities, the customer determines the purposes and means, the legal basis, the retention period, and is responsible for handling data subject requests in the first instance. DataTako will assist the customer in fulfilling its obligations as required by Article 28 GDPR.

3.2 DataTako as Controller

DataTako acts as controller for personal data processed for its own purposes, including:

For these activities, the legal bases set out in Section 6 apply.

4. Personal data we process

The categories of personal data DataTako processes depend on the role described in Section 3 and on the way the Platform is used.

4.1 Account and identity data

Collected directly when a user account is created or invited, or received from an identity provider through single sign-on.

4.2 Tenant (organization) data

For each customer organization ("tenant"), DataTako stores administrative information including organization name, postal address, city, country code, and primary domain name, together with administrative configuration such as inactivity timeout, IP whitelist settings, and 2FA policy.

4.3 Authentication and session data

4.4 Technical and usage data

4.5 Billing data

Billing identifiers and subscription state are processed by DataTako in connection with the contractual relationship with paying customers:

DataTako does not store full payment card numbers or bank account credentials. Payment credentials are entered by the customer directly into Stripe's hosted payment interface and are processed by Stripe, Inc. as an independent controller for payment-card processing (see Section 8).

4.6 Communications data

4.7 Power BI integration data

To enable embedded Power BI functionality, DataTako stores Microsoft service account credentials configured by the customer (Azure object identifier) and metadata about the workspaces and reports the customer has linked (workspace identifier, workspace name, report identifier, report name, embed configuration, and row-level security flag).

DataTako does not ingest, copy, or persist the underlying datasets that customers visualize through Power BI. Report content is rendered on demand by Microsoft's Power BI service; DataTako stores only the metadata necessary to manage and embed reports.

4.8 Customer-controlled data within reports and content

Personal data that customers choose to display in reports, dashboards, media items, or other content items may include any personal data category determined by the customer. This data is processed on the customer's instructions in DataTako's processor capacity (see Section 3.1).

4.9 Data we do not knowingly process

The Platform is intended for business use and is not directed at children. DataTako does not knowingly collect personal data from children under the age of 16. The Platform is not designed to process special categories of personal data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10 GDPR); customers should not upload such data without first concluding any additional contractual arrangements required by the GDPR and notifying DataTako.

5. Purposes of processing

DataTako processes personal data for the following purposes:

  1. Provision of the Service — authenticating users; rendering reports; managing tenants, content, and permissions; enforcing access controls; delivering features the customer has subscribed to.
  2. Account administration — creating, modifying, and deactivating user accounts and tenant configurations; managing invitations; enforcing security policies (2FA, inactivity timeout, IP whitelisting).
  3. Billing and contract management — issuing invoices, processing subscriptions, calculating seat usage, managing renewals.
  4. Customer support — responding to support requests and diagnosing reported issues.
  5. Security, fraud prevention, and abuse detection — monitoring for unauthorized access, brute-force attempts, and abuse; bot detection via reCAPTCHA on public-facing forms; maintaining audit trails.
  6. Service reliability and quality — collecting application logs, error reports, and performance traces; investigating incidents; restoring service.
  7. Service improvement and product analytics — analyzing aggregated usage patterns to understand feature adoption and improve the Platform.
  8. Communications — sending transactional emails, security notices, and (where the recipient has opted in or where permitted under applicable law) service-related announcements.
  9. Legal compliance — meeting tax, accounting, anti-money-laundering, and other legal obligations; responding to lawful requests from competent authorities.
  10. Defence and enforcement of legal claims — establishing, exercising, or defending legal claims to which DataTako is a party.

6. Legal bases for processing

DataTako relies on the following legal bases under Article 6(1) GDPR.

Processing activityLegal basis
Provision of the Service to a customer; account administration; authenticationArticle 6(1)(b) — performance of a contract with the customer or pre-contractual steps at the customer's request
Billing, invoicing, subscription managementArticle 6(1)(b) — performance of contract; Article 6(1)(c) — compliance with legal obligation (tax, accounting)
Security, fraud prevention, audit logging, abuse detectionArticle 6(1)(f) — legitimate interests of DataTako and its customers in maintaining a secure service; Article 6(1)(c) where required by law
Service reliability monitoring, error diagnostics, application logsArticle 6(1)(f) — legitimate interest in operating a reliable service
Product analytics and service improvement (where active)Article 6(1)(a) — consent (where the analytics rely on non-essential cookies or similar technologies); otherwise Article 6(1)(f)
Direct service communicationsArticle 6(1)(b) — performance of contract; Article 6(1)(f) — legitimate interest in keeping users informed about the Service they use
Marketing communications to existing customersArticle 6(1)(f), subject to a clear right to object; Article 6(1)(a) where required
Compliance with legal obligations and responses to authoritiesArticle 6(1)(c)
Establishment, exercise, or defence of legal claimsArticle 6(1)(f)
Processing on behalf of a customer (DataTako as processor)Article 28 GDPR; the legal basis is determined and documented by the customer

A balancing test in respect of each legitimate-interest basis is documented internally and is available on reasoned request.

7. Data retention

DataTako retains personal data only for as long as necessary to fulfil the purposes set out in Section 5 or to comply with legal obligations.

Data categoryRetention
User account and tenant dataFor the duration of the contract with the customer. Following termination, accounts are flagged as deleted (soft-deleted). Hard deletion of soft-deleted records occurs in line with the schedule set out in the DPA, or upon documented written instruction from the controller, subject to overriding legal retention obligations.
Refresh tokensHard-deleted automatically seven (7) days after revocation or expiry.
Audit logsRetained for 6 months for security and compliance purposes, after which they are deleted or irreversibly anonymized, save where a longer retention period is required by law or to handle an active incident.
Application logsRetained on a rolling basis as configured in the platform, typically 90 days.
Billing records and invoicesRetained for the period required by applicable tax and accounting law (7 years).
Customer-controlled data (DataTako as processor)Retained for the period determined by the customer in accordance with the DPA. Customers may export and delete such data at any time during the term of the contract, and on termination in accordance with the DPA.
Support correspondenceRetained for 24 months following resolution of the matter.
Marketing contact dataRetained until the data subject objects or withdraws consent, after which the contact is suppressed.

Where personal data is no longer needed and no legal retention obligation applies, DataTako deletes or irreversibly anonymizes the data.

8. Data sharing and subprocessors

DataTako does not sell personal data and does not share personal data with third parties for their own marketing purposes.

DataTako shares personal data with the following categories of recipients:

The current list of subprocessors is published and is updated in accordance with the notice period set out in the DPA. As of the effective date of this Statement, DataTako engages the following principal subprocessors and third-party service providers:

ProviderRoleLocation of processing
Hetzner Online GmbHInfrastructure hosting (servers, primary database, application runtime)Germany (EU)
Stripe Payments Europe, Limited / Stripe, Inc.Payment processing (acts as independent controller for payment-card data)Ireland (EU) / United States
Twilio Inc. (SendGrid)Transactional email deliveryUnited States
Microsoft Ireland Operations Limited / Microsoft CorporationPower BI embedding, Microsoft Graph, Entra ID, Microsoft 365 SMTP relay (where used)European Union and globally per Microsoft's data residency commitments
Functional Software, Inc. (Sentry)Error and performance monitoringUnited States
Google Ireland LimitedGoogle Analytics 4, Google Tag Manager, reCAPTCHA (only where the customer or user has activated the corresponding integration)European Union and United States
Product Fruits s.r.o.In-app product guidance and usage analyticsEuropean Union
UserJotCustomer feedback collectionUnited States

Customers operating their own custom domain may additionally configure their own analytics tags (Google Analytics 4 and Google Tag Manager). In such cases, the customer is the controller for the personal data collected through those tags and is responsible for the lawful basis, transparency, and consent management with respect to the visitors to its custom-domain interface.

9. International data transfers

The Platform's primary application infrastructure and database are hosted with Hetzner Online GmbH in Germany, within the European Economic Area ("EEA"). Personal data processed for the core functioning of the Service is therefore stored within the EEA.

Certain subprocessors listed in Section 8 are established in, or may transfer personal data to, countries outside the EEA, in particular the United States. Where such transfers occur, DataTako relies on the following transfer mechanisms under Chapter V of the GDPR:

A copy of the Standard Contractual Clauses concluded with a given subprocessor, and the related transfer impact assessment, is available to data subjects on reasoned request, with redactions where necessary to protect commercial confidentiality.

10. Security measures

DataTako implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in line with Article 32 GDPR. These include:

In the event of a personal data breach affecting customer data, DataTako will notify the affected customer without undue delay in accordance with the DPA.

11. Rights of data subjects

Subject to the conditions set out in the GDPR, data subjects have the following rights in respect of their personal data:

Where the data subject is an end user provisioned within a customer's tenant, requests should in the first instance be directed to that customer as controller. DataTako will assist the customer in responding to such requests as set out in the DPA. Requests addressed to DataTako directly will be acknowledged and, where appropriate, forwarded to the relevant customer.

To exercise rights in respect of processing for which DataTako is the controller, data subjects may contact privacy@datatako.com. DataTako will respond within one month of receipt of the request, with the possibility of extending that period by two further months in accordance with Article 12(3) GDPR. DataTako may request additional information to verify the identity of the requester, in order to prevent unauthorized disclosure.

12. Cookies and similar technologies

The Platform uses cookies and equivalent client-side storage mechanisms for the following purposes.

12.1 Strictly necessary

These are required for the Platform to function and cannot be disabled without breaking core functionality. They are set on the basis of Article 6(1)(b) GDPR and the strictly-necessary exemption under the ePrivacy Directive.

12.2 Functional

12.3 Analytics, product, and feedback

These technologies are activated where applicable and are subject to consent in accordance with Article 6(1)(a) GDPR and applicable national ePrivacy rules. They include:

Users may manage their preferences at any time through the cookie consent interface presented on first use of the website.

Where a customer operates the Platform under its own custom domain and configures its own Google Analytics 4 or Google Tag Manager containers, the customer is the controller for the resulting cookies and is responsible for providing notice and obtaining consent from its visitors.

13. Contact

TopicContact
General inquiriesinfo@datatako.com
Privacy inquiries and rights requestsprivacy@datatako.com
Security disclosuressecurity@datatako.com
Postal addressAntareslaan 65, 2132JE Hoofddorp
Data Protection Officersecurity@datatako.com

Customers with an existing DPA may use the contact channels designated therein.

14. Updates to this Statement

DataTako may update this Statement from time to time to reflect changes in the Platform, in applicable law, or in the way personal data is processed. The "Effective date" and "Last updated" fields at the top of this Statement indicate when it was last revised. Material changes will be communicated to customers in advance through the Platform, by email to the registered administrative contact, or by another reasonable means, and where required will not take effect before the notice period set out in the DPA has elapsed. Continued use of the Platform after a revised Statement takes effect constitutes acknowledgement of the revised Statement; it does not, however, constitute consent where consent is required as a legal basis under the GDPR.