1. Introduction
Welcome to Cliccc, a company in the process of being incorporated ("we," "our," or "us"). We take privacy seriously and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard information when you use Cliccc. It also outlines your rights under the General Data Protection Regulation (GDPR) and how you can exercise them.
By using Cliccc, you agree to the terms of this Privacy Policy. If you do not agree, please do not use our services.
TL;DR
How do we use your data?
- You connect to the platform and give us your travel preferences (request and proposal)
- We match your requests and proposals to other requests and proposals of the community then make recommendations of members you could swap with.
2. Who We Are
Cliccc is a community based home swapping platform. We help people who want to home swap by matching them together based on their preferences.
Our platform analyzes profiles and metadata using large language models, including those provided by OpenAI, to surface risks that traditional tools miss.
Users may provide confidential information and submit prompts that include personal or business-related information. We process this data solely to provide relevant, context-aware security insights.
If you have questions about this Privacy Policy, you can contact us at contact@cliccc.ai.
3. What Data We Collect
We collect different types of personal data depending on how you use Cliccc. This includes:
3.1. Data You Provide to Us
When you create an account, interact with our platform, or contact us, you may provide:
- Account Information: Name, email address and password.
- Company technical context: Any information you may provide to us during onboarding sessions such as your technical stack and third-party usage.
- Prompt Data: Any questions, instructions, or other input you submit to Cliccc (e.g., asking about a vulnerability or requesting analysis), including code snippets, logs, comments, or other text. This may include personal data if you or your users include it in code or prompts.
- Support Requests & Feedback: If you contact us, we collect the details of your request and any personal data you include.
3.2. Data Collected Automatically
When you use Cliccc, we may automatically collect:
- Usage Data: Information about your interactions with the app (e.g., session duration, feature usage).
- Device & Technical Data: IP address, browser type, device information, and operating system.
- Cookies & Tracking Data: We may use cookies or similar technologies to analyze how you use our services.
3.3. Data from Third-Party Services
- Basic profile information: If you sign in using any SSO platform we may receive basic profile information such as your name, email address, and profile picture, as permitted by those services.
We do not collect sensitive personal data (e.g., health, financial, or government ID information) unless you voluntarily submit it through your prompts.
4. Why We Collect and Process Your Data
We collect and process your personal data to provide, improve, and secure Cliccc, our home swapping platform. Under the General Data Protection Regulation (GDPR), we rely on the following legal bases to process your data:
4.1 To Provide and Improve Our Services (Contractual Necessity)
- To authenticate users and manage workspace accounts.
- To analyze source code and repositories using AI models to detect security risks.
- To store findings, insights, and historical context to enhance user workflows.
- To deliver product updates and respond to user inquiries or feedback.
4.2 To Maintain and Enhance Security (Legitimate Interest)
- To monitor platform activity to detect abuse, supply chain threats, or anomalous behavior.
- To perform security audits and continuously improve detection accuracy.
- To diagnose performance issues and ensure platform reliability.
4.3 To Comply with Legal Obligations
- To meet regulatory requirements, including data protection and cybersecurity regulations.
- To respond to lawful requests from authorities or to enforce our terms of use.
4.4 With Your Consent (When Required)
- For optional updates on new features, product improvements, or security webinars.
- For enabling third-party integrations like GitHub or GitLab, with user approval.
- For storing usage preferences or analytics cookies (if applicable).
You have the right to withdraw your consent at any time for any activity based on consent.
5. How Long We Keep Your Data
We only retain personal data for as long as necessary to fulfil the purposes outlined in this Privacy Policy, in compliance with GDPR and applicable laws.
5.1 Retention Periods
| Data Type | Retention Period |
|---|
| Account Information (name, email, password) | Stored as long as your account is active. Deleted within 30 days of account deletion. |
| Prompt Data (messages submitted to AI) | Retained as long as the account is active. Deleted within 30 days of account deletion. |
| Usage & Device Data (IP address, logs) | Retained as long as the account is active. Deleted within 30 days of account deletion. |
| Communication Data (support requests, emails) | Retained as long as the account is active. Deleted within 1 year of account deletion. |
| Marketing Data (emails, opt-in preferences) | Retained until you unsubscribe or after 3 years of inactivity. |
5.2 Data Deletion & User Rights
- Account Deletion: Users can request account deletion at any time. Once deleted, all associated personal data is removed within 30 days, except for data required for legal compliance.
- Backup & Logs: Certain logs and backups may be retained for 14 days for security and operational purposes before being permanently erased.
6. When and How We Share Your Data
We do not sell or rent your personal data. However, we may share it with trusted third-party service providers to operate and improve Cliccc.
6.1 Third-Party Service Providers (Subprocessors)
We use third parties to help us store data, process AI requests, and host our app. These subprocessors handle data under strict contractual agreements, including Data Processing Addendum. All subprocessors adhere to GDPR-compliant safeguards.
6.2 Legal Compliance & Law Enforcement
We may disclose your data:
- If required by law or in response to legal requests.
- To protect the security or rights of Cliccc, users, or third parties.
We ensure that all data transfers outside the EU comply with GDPR, using safeguards such as Standard Contractual Clauses (SCCs).
7. International Data Transfers
Since we work with service providers outside the European Economic Area (EEA), your personal data may be transferred to countries that do not have the same level of data protection laws as the EU.
7.1 How We Protect International Transfers
Whenever we transfer your data outside the EU, we ensure it is protected by one of the following safeguards:
- Adequacy Decision: If the country has been recognized by the European Commission as having adequate data protection laws.
- Standard Contractual Clauses (SCCs): We enter into SCCs approved by the European Commission with our subprocessors to ensure GDPR compliance.
- Other Appropriate Safeguards: Where necessary, we implement additional security measures such as encryption and access controls.
8. How We Protect Your Data
We take data security seriously and implement industry-standard security measures to protect your personal data from unauthorized access, loss, misuse, or disclosure.
8.1 Security Measures We Use
We apply the following technical and organizational safeguards:
- Data Encryption: All stored and transmitted data is encrypted using modern encryption protocols.
- Access Controls: Only authorized personnel have access to user data, and access is granted on a need-to-know basis.
- Secure Hosting: Our infrastructure is hosted on AWS (EU region), which follows strict security policies.
- Data Minimization: We limit the collection and retention of personal data to only what is necessary.
- Regular Security Audits: We monitor and review our security protocols to prevent vulnerabilities.
8.2 Data Breach Response
In the event of a security breach that affects your personal data:
- We will assess the impact and take immediate corrective actions.
- If the breach poses a risk to your rights and freedoms, we will notify affected users without undue delay.
- If required by law, we will report the breach to data protection authorities within 72 hours.
9. Your Rights Under GDPR
As an EU resident, you have certain rights regarding your personal data under the General Data Protection Regulation (GDPR). To exercise these rights, contact us at contact@cliccc.ai.
9.1 Your Rights
You have the following rights:
- Right to Access – You can request a copy of the personal data we hold about you.
- Right to Rectification – You can ask us to correct any inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten") – You can request that we delete your personal data, subject to legal or contractual obligations.
- Right to Restrict Processing – You can ask us to limit the way we process your data in certain situations.
- Right to Data Portability – You can request a copy of your data in a structured, commonly used, and machine-readable format.
- Right to Object – You can object to processing based on legitimate interests or for marketing purposes.
- Right to Withdraw Consent – If we process your data based on consent, you can withdraw it at any time.
9.2 How to Exercise Your Rights
To make a request, contact us at contact@cliccc.ai with the subject line: "GDPR Request" and specify which right you wish to exercise. We will respond within one month as required by GDPR.
9.3 Filing a Complaint
If you believe we have not handled your data properly, you have the right to file a complaint with your local Data Protection Authority (DPA).
9.4 California Residents (CCPA)
If you are a resident of California, you have specific rights under the California Consumer Privacy Act (CCPA). These rights include:
- The right to request access to the personal information we have collected about you.
- The right to request that we delete your personal information.
- The right to opt-out of the sale of your personal information (although we do not sell personal information).
To exercise any of these rights, please contact us at contact@cliccc.ai. Please note that we may require you to verify your identity before processing your request.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or to comply with legal requirements. When we update this policy, we will revise the "Last Updated" date at the top of this page. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
11. How to Contact Us
If you have any questions about this Privacy Policy or how we handle your personal data, you can contact us using the details below:
📩 contact@cliccc.ai
🌐 https://cliccc.ai