Legal
Privacy policy
This explains what the Klikka app does with your information, why, how long we keep it, and how to make us stop. It covers the live app at klikka.travel and this website.
Printed from klikka.travel/privacy.html
1. Who we are
Klikka is a trading name of CB DISTRIBUTION LIMITED, a company registered in Malta, registration number C101740, VAT MT29034909, registered address Patri Frangisk Grech Street, Santa Venera SVR 1361, Malta. Where this policy says we, us or our, it means that company.
For anything about your personal data, including a rights request, write to cb@cbdistributionltd.com. That mailbox is monitored by us and is the correct route for data protection matters. We have not appointed a Data Protection Officer, because we are not required to; requests go to the address above and are handled by the company's director.
We are a software company. We do not sell, resell, book or take payment for flights, accommodation, car hire, transfers, activities or event tickets, and we do not hold client money for travel services. That matters here because it limits what we ever need to know about you.
2. What this policy covers
It covers two things:
- The Klikka app at klikka.travel — the group trip app used by trip organisers, operators and their guests.
- This marketing website — the pages you are reading now. It sets one cookie, only after you choose, and it loads nothing from a third party. See the cookie policy.
It does not cover what a travel operator, planner or supplier does with your data in their own systems, or what a booking site does when you book travel. Those are their responsibility.
3. Whether we are the controller or a processor
This depends on who set up your trip, and it changes who you should ask first.
- Private trips. If a friend or family member created the trip, CB DISTRIBUTION LIMITED is the controller for the personal data in it, and this policy applies in full.
- Operator trips. If a travel operator, tour company or wedding planner created the trip on a paid plan, that business is the controller and we act as its processor under Article 28 of the GDPR. We process trip data on its written instructions, under a data processing agreement, and we do not use it for our own purposes. Ask them first; if you ask us, we will tell you who they are and pass the request on.
- Always us. We are the controller for account data, billing data, support correspondence, security logs and anything you send us directly, whoever created the trip.
4. What we collect
Only what the app needs to run a trip. There is no advertising profile, no data broker, no enrichment, no sale of data. We do not buy contact lists.
- Account and identity. Name or display name, email address, profile photo if you add one, sign-in identifiers, the trips you belong to and your role in them.
- Trip content. Itinerary text, activity names and locations, dates and times, notes, checklists, packing lists, messages and announcements posted in the trip.
- Photos. Images you or other members upload to a trip gallery. Files are stored as uploaded, which means any location or camera metadata embedded in the file is stored with it. If you would rather not share that, remove it before uploading.
- Travel documents. Files uploaded to satisfy a document request — for example a passport data page, a visa, an insurance certificate, a parental consent form, a licence copy. See section 7, which is stricter than the rest of this policy.
- Money between friends. Contribution and shared-expense records: amount, currency, date, who paid, what it was for, and the settlement status. Card and bank details are entered on the payment provider's own pages and never reach us; we receive a reference, the amount, the outcome and the last four digits.
- Technical data. IP address, browser and device type, timestamps, error traces and security events in server logs. Used to keep the service up and to investigate abuse.
- Correspondence. Emails you send us, and what we reply.
We do not collect precise geolocation. Location in Klikka is the text address of an activity, typed by a person, not a reading from your device. Device-level location processing is switched off and will not be enabled without a written impact assessment and a clear, separate notice.
5. Why we use it, and the lawful basis for each purpose
| What we do | Data used | Lawful basis |
|---|---|---|
| Run your trip: show the itinerary, keep the group in sync, deliver notifications | Account, trip content, photos | Performance of a contract, Article 6(1)(b). For operator trips, the operator's instruction under Article 28 |
| Collect the documents an organiser has asked for and show who is still missing one | Travel documents, names, deadlines | Contract, Article 6(1)(b), and the organiser's legitimate interest in a trip that can legally depart, Article 6(1)(f) |
| Track contributions and shared spend, and process a contribution you choose to make | Contribution records, payment references | Contract, Article 6(1)(b) |
| Keep financial and tax records of what we were paid | Billing records, invoices | Legal obligation, Article 6(1)(c), under Maltese tax and accounting law |
| Answer your emails and provide support | Correspondence, account | Contract, Article 6(1)(b), or legitimate interests, Article 6(1)(f) |
| Keep the service secure, prevent abuse, debug faults, keep backups | Technical data, logs | Legitimate interests, Article 6(1)(f), in a service that works and is not abused |
| Send you product or marketing email you asked for | Name, email | Consent, Article 6(1)(a). Withdrawable in one click, in every message |
| Store non-essential cookies on this website | Cookie identifiers | Consent, Article 6(1)(a) and Malta's Processing of Personal Data (Electronic Communications Sector) Regulations. None is set today |
| Defend a legal claim, or comply with a lawful order | Whatever is strictly relevant | Legitimate interests, Article 6(1)(f), or legal obligation, Article 6(1)(c) |
Where we rely on legitimate interests, we have weighed them against your rights and recorded the result. You can object at any time using the contact address above, and we will stop unless we can show an overriding reason.
6. How long we keep it
| Category | Kept for |
|---|---|
| Account data | While the account is active. Deleted 12 months after the last sign-in, or within 30 days of a deletion request |
| Trip content: itinerary, checklists, messages | 12 months after the trip end date, or immediately when the trip is deleted by its organiser |
| Photos uploaded to a trip | Same as trip content. You can delete your own uploads at any time |
| Travel documents, including passport scans | 30 days after the trip end date, then deleted automatically. You can delete yours at any time before that |
| Contribution and shared-expense records | Kept as a financial record for at least six years after the end of the relevant financial year, because Maltese tax and accounting law requires it |
| Billing records and invoices | Six years after the end of the relevant financial year |
| Support correspondence | 24 months from the last message |
| Server and security logs | 12 months, or longer for a specific record under active investigation |
| Backups | Rolling backups purged within 35 days, so deleted data can persist in a backup for up to 35 days after deletion |
| Consent cookie on this website | Six months, then we ask you again |
For operator trips, the operator can instruct a shorter period, and we will follow it.
7. Travel documents, and exactly how sharing works
A passport scan is the most sensitive thing in the app, so it is handled differently from everything else.
- Documents are stored in private storage that is not publicly listable and not indexable.
- They are never served from a permanent public URL. Every view or download goes through a short-lived link that expires, and that we can revoke.
- A link is issued only to a named recipient with a role that needs it — normally the trip organiser or a named member of the operator's staff — and only for the document requested.
- Other guests cannot see your documents. Group members see a completion status, not a file. Operators are shown who has and has not submitted, so the routine question is answered without opening anything.
- Documents are excluded from exports, printed packs, message threads, activity feeds, notifications and any AI or model context.
- Access is logged: what was issued, to whom, and when.
- They are deleted 30 days after the trip ends, and you can delete yours sooner from the app.
We do not verify your documents. We do not check whether a passport is valid, whether you need a visa, or whether your insurance covers your trip. That is stated plainly in the disclaimers, and it is your responsibility.
8. We do not collect special-category data
Klikka has no field for health information, medical conditions, allergies, dietary requirements, religion, ethnicity, political opinions, trade union membership, sexual orientation or biometrics, and we do not ask for any. Free-text fields exist for itinerary and note content and are not intended for such information — please do not enter it. Where an operator must collect health or dietary details for a trip, it does so in its own systems, outside Klikka.
A passport scan contains an identity document number and a facial photograph. We treat it as high risk and handle it as set out in section 7, but we do not run biometric matching or facial recognition on it, which would make it special-category data under Article 9.
9. Who processes data for us
We are a small company and we use established providers rather than running our own servers. Each is bound by a written data processing agreement and may use the data only to provide its service to us. The list below is the one an operator's own compliance review would ask for.
| Provider | What it does for us | Where |
|---|---|---|
| Base44, a Wix.com Ltd service | Application platform: hosts the app, its database and uploaded files | United States by default, with company entities in Israel |
| Render | Server and web infrastructure the app is served from, engaged through the application platform | United States |
| MongoDB Atlas | Database hosting, engaged through the application platform | United States |
| Supabase | Storage for uploaded media and documents, engaged through the application platform | United States |
| Twilio SendGrid | Sends transactional email: invitations, notifications, password and document-request messages | United States |
| Google LLC | Sign-in with Google, where you choose it, and cloud infrastructure used by the application platform | United States and EU regions |
| Datadog, Logfire | Error and server-log monitoring, engaged through the application platform | United States, United Kingdom |
| Stripe Payments Europe | Processes contributions and subscription payments. Stripe is an independent controller for payment data and applies its own privacy notice | Ireland, with group transfers to the United States |
| GoDaddy | Domain registration and DNS for klikka.travel | United States and EU |
Two honest notes. First, the application platform's default storage region is the United States, and that is where the live app's data sits today; European storage is a paid platform tier we have not moved to, and if we do we will say so here. Second, the platform's own sub-processor list includes large-language-model providers for its AI features. Klikka does not send trip content, photos or travel documents into any model, and travel documents are excluded from model context by design. If that ever changes, this policy changes first and we will ask before it applies to you.
We also disclose data where we must: to a court, regulator or law-enforcement authority acting lawfully, to our accountant or lawyer under confidentiality, and to a buyer if the business is ever sold, in which case you will be told before your data moves.
10. Transfers outside the EEA
Because our providers are largely United States companies, personal data is transferred outside the European Economic Area. Those transfers rely on the European Commission's Standard Contractual Clauses, on the EU–US Data Privacy Framework where the provider is certified, and on the providers' own supplementary technical measures such as encryption in transit and at rest. You can ask us for a copy of the relevant transfer mechanism for a specific provider at cb@cbdistributionltd.com.
11. Security
Encryption in transit for everything, encryption at rest for stored files, role-based access inside a trip, private storage buckets, short-lived and revocable document links, access logging, and administrative access limited to the company's director. We patch promptly and we do not keep production copies on laptops. No system is perfect: if a breach happens that is likely to risk your rights, we will notify the Information and Data Protection Commissioner within 72 hours and tell affected people without undue delay. To report a vulnerability, see our security contact.
12. Your rights, and how to use them
Under the GDPR you can ask us to:
- Give you a copy of your personal data, and tell you what we do with it (Articles 15).
- Correct anything wrong or incomplete (Article 16).
- Delete it, where we have no overriding reason to keep it (Article 17).
- Restrict what we do with it while a dispute is resolved (Article 18).
- Port it, in a structured machine-readable file, to you or to another provider (Article 20).
- Object to processing based on legitimate interests, and to marketing at any time (Article 21).
- Withdraw consent you gave, without affecting what was lawful before (Article 7(3)).
To exercise any of them, email cb@cbdistributionltd.com and say what you want. You do not need a form or a particular wording. We will reply within one month, and tell you if we need up to two further months for a complex request. It is free unless a request is manifestly excessive. We may ask you to confirm your identity, but only enough to be sure we are not disclosing your data to someone else. We do not make automated decisions about you that have legal or similarly significant effects, and we do not profile you.
If your trip belongs to an operator, we may need to route the request to that operator as controller. We will tell you when we do, and who they are.
13. Complaints, and the supervisory authority
Tell us first if you can — cb@cbdistributionltd.com — because we can usually fix it faster than a regulator can. You do not have to, and you can complain directly to our supervisory authority in Malta:
Office of the Information and Data Protection Commissioner (IDPC)
Floor 2, Airways House, High Street, Sliema SLM 1549, Malta
Telephone +356 2328 7100
Email idpc.info@idpc.org.mt
Complaints must be submitted through the IDPC's own online complaint form at idpc.org.mt/file-a-complaint
If you live in another EU or EEA country, you may also complain to your local data protection authority, which will liaise with the IDPC.
14. Children
Klikka is not designed for children to sign up on their own and we do not knowingly create accounts for under-16s. School and youth sports trips are run by adults: a teacher or tour manager holds the account, and a parent or guardian provides any document about a child, such as a consent form or a passport copy, with the school's own consent paperwork behind it. Where a child's data appears in a trip, the operator or school is the controller of it and we process it on their instruction. If you believe a child has created an account, tell us and we will remove it.
15. Changes to this policy
If we change something material, we will update the version and date at the top of this page and, where the change affects how we use your data, tell you by email or in the app before it takes effect. If a change adds a cookie category or a new purpose that needs consent, the cookie banner will ask you again rather than assuming your old answer.
Version 1.0, 4 August 2026. Controller: CB DISTRIBUTION LIMITED, registration number C101740, VAT MT29034909, Patri Frangisk Grech Street, Santa Venera SVR 1361, Malta. Contact for all privacy matters: cb@cbdistributionltd.com.