1. Introduction
FIKA ("we", "our", or "us") is committed to protecting the privacy of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use the FIKA platform ("Service").
By accessing or using the Service, you consent to the data practices described in this policy. If you do not agree with this policy, please do not access or use the Service.
2. Information We Collect
Account Information: When your organization provisions your account, we collect information such as your name, email address, job title, and role within your organization. This information is provided by your organization administrator.
Usage Data: We automatically collect information about how you interact with the Service, including pages visited, features used, actions performed, timestamps, and session duration. This helps us improve platform performance and usability.
Device and Log Data: We collect information about the device and network you use to access the Service, including IP address, browser type, operating system, and referring URLs.
Operational Data: Data you create or submit through the Service — including inspection reports, audit records, issue logs, asset data, photos, GPS coordinates, and SLA metrics — is collected and stored as part of delivering the Service to your organization.
3. How We Use Your Information
We use the information we collect to provide, maintain, and improve the Service; to process and fulfill your organization's operational workflows; to send transactional communications such as notifications, alerts, and reports; and to respond to inquiries and provide support.
We may use aggregated and anonymized data for analytics, research, and product development purposes. This data cannot be used to identify any individual user or organization.
We do not sell your personal information to third parties, and we do not use your data to serve advertising.
4. Data Sharing and Disclosure
Within Your Organization: Data you submit is accessible to other authorized users within your organization according to the role-based access controls configured by your administrator.
Service Providers: We engage trusted third-party vendors to assist in operating the Service (e.g., cloud infrastructure, email delivery). These providers are contractually obligated to handle data only as instructed by us and in accordance with this policy.
Legal Requirements: We may disclose your information if required to do so by law or in response to a valid legal process, such as a court order or government request.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify your organization's administrator before your data is subject to a different privacy policy.
5. Data Retention
We retain your data for as long as your organization's account is active or as needed to provide the Service. Your organization administrator may configure retention periods for specific data types within the platform settings.
When your organization's account is terminated, we will delete or anonymize your data within 90 days, unless we are required to retain it for legal or compliance reasons.
6. Data Security
We implement industry-standard technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit (TLS) and at rest, access controls, audit logging, and regular security reviews.
While we take reasonable steps to secure your data, no system is completely immune to security risks. We encourage you to use strong passwords, enable multi-factor authentication where available, and promptly report any suspected security incidents to your administrator.
7. Your Rights and Choices
Depending on your jurisdiction, you may have rights regarding your personal data, including the right to access, correct, or delete your information, and the right to restrict or object to certain processing activities.
Requests related to personal data are primarily managed through your organization administrator. For requests that cannot be fulfilled at the organizational level, please contact FIKA support. We will respond to verifiable requests within the timeframe required by applicable law.
Please note that certain data may need to be retained for compliance, legal, or audit purposes even if you request deletion.
8. Cookies and Tracking
The Service uses session cookies and similar technologies to maintain your authenticated session, remember your preferences, and understand how the Service is being used. These are necessary for the platform to function correctly.
We do not use third-party advertising cookies or behavioral tracking technologies. You can configure your browser to refuse cookies, but doing so may prevent you from using certain features of the Service.
9. International Data Transfers
Your information may be stored and processed in any country where we or our service providers maintain facilities. By using the Service, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection rules.
Where required by applicable law, we rely on appropriate safeguards such as standard contractual clauses to govern international transfers of personal data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and notify organization administrators by email.
Your continued use of the Service after any changes indicates your acceptance of the updated policy. We encourage you to review this policy periodically.
11. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact your organization administrator or reach out to FIKA support through the help center within the platform.
