LegalPrivacy Policy19.08.2026

Privacy Policy

How we handle personal data collected through this website, and the rights you have over it.

Template — not yet in force

This document is a generic draft placed here so the page exists. Every value highlighted in green is a placeholder that has to be completed, and the whole text has to be reviewed by qualified counsel, before this site is published. It is not legal advice.

01Who is responsible

The controller for the personal data described in this policy, within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR), is:

[Legal entity name]
[Street and number]
[Postcode and city]
[Country]
Email · hello@abikiosk.com

Our data protection officer, where one is appointed, can be reached at [DPO contact address].

02Scope of this policy

This policy covers the personal data we process when you visit this website or get in touch with us through it. It does not cover the processing that takes place inside the AbiKiosk platform on behalf of a customer. Where a customer operates the platform, that customer is the controller for the data held in it and we act as a processor under a separate data processing agreement.

03What we collect

Data you give us

If you contact us, request a demonstration or submit a form on this website, we collect what you enter. Typically that is your name, your business email address, your employer, your role, and whatever you choose to write in a free-text field.

Data collected automatically

When you load a page, our hosting provider records technical information needed to deliver it and to keep the service secure. This normally includes:

We do not use this information to identify individual visitors, and we do not combine it with other data to build a profile.

04Why we use it, and on what legal basis

To deliver and secure this website
Legal basis: our legitimate interest in operating a functioning, secure site, Article 6(1)(f) GDPR.
To answer your enquiry or arrange a demonstration
Legal basis: steps taken at your request before entering into a contract, Article 6(1)(b) GDPR, or our legitimate interest in responding to business enquiries, Article 6(1)(f) GDPR.
To set non-essential cookies or similar technologies
Legal basis: your consent, Article 6(1)(a) GDPR and § 25(1) TDDDG. You may withdraw consent at any time with effect for the future.
To meet legal obligations
Legal basis: compliance with a legal obligation, Article 6(1)(c) GDPR, including retention periods under commercial and tax law.

05Cookies and similar technologies

Cookies are small files stored by your browser. Similar technologies, such as local storage, work the same way for the purposes of this policy.

Strictly necessary storage. We store a single entry that records whether you have dismissed the cookie notice, so that it is not shown again on every page. It contains no identifier and is not shared with anyone.

Non-essential cookies. [List any analytics, embedded media or marketing cookies here, with provider, purpose and lifetime — or state that none are used.] These are set only with your consent.

You can delete cookies and site data at any time through your browser settings, and configure your browser to refuse them. Blocking strictly necessary storage may mean parts of the site stop working as intended.

06Who we share it with

We do not sell personal data. We disclose it only in these cases:

The providers we currently use are [list of processors].

07Transfers outside the EEA

Where a provider processes personal data outside the European Economic Area, we rely on an adequacy decision of the European Commission or, failing that, on the Commission's Standard Contractual Clauses together with any additional measures the transfer requires. You may request a copy of the safeguards in place using the contact details in clause 14.

08How long we keep it

We keep personal data only as long as the purpose it was collected for requires, and then delete it, unless a statutory retention period applies.

09How we protect it

We take appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access, as required by Article 32 GDPR. This site is served over an encrypted TLS connection. No transmission over the internet can be guaranteed to be completely secure, and any transmission is at your own risk.

10Your rights

Under the GDPR you have the right to:

To exercise any of these, write to us using the details in clause 14. You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work or of the alleged infringement. The authority responsible for us is [competent supervisory authority].

11Children

This website is directed at businesses and is not intended for children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

This website may link to sites we do not operate. We are not responsible for their content or their privacy practices. When you follow such a link, read the privacy policy of the site you arrive at.

13Changes to this policy

We may update this policy to reflect changes in our practices or in the law. The current version is always published on this page, and the date below shows when it last changed. Where a change is material, we will make it plain.

14How to contact us

For any question about this policy or about your personal data, write to hello@abikiosk.com or to the postal address in clause 1.

Last updated · 19 August 2026 · Version 0.1 (draft)