Tackt. ← Back to site
Legal

Privacy policy.

How we collect, use and protect personal data, written so a human can actually read it.

Version 1.0Effective 1 January 2026Last updated [DATE]

Plain-English summary. Tackt is a Maltese-registered company that helps UK professional services firms find new clients. We process personal data about two groups: (i) our clients and their staff, and (ii) people at firms we contact on our clients’ behalf. We comply with both UK GDPR and EU GDPR. We never sell data. You can ask us what we hold about you, correct it, or ask us to delete it, at any time.

Contents

  1. Who we are
  2. What this covers
  3. Data we process
  4. Lawful bases
  5. Where we get data
  6. What we use it for
  7. Who we share with
  8. International transfers
  9. How long we keep it
  10. Your rights
  11. Security
  12. Direct marketing & PECR
  13. Cookies
  14. Changes to this policy
  15. How to contact us

1. Who we are

“Tackt,” “we,” “us” and “our” refer to [TACKT LEGAL ENTITY NAME], a company registered in Malta (company number [MT COMPANY NUMBER]), with its registered office at [MALTA REGISTERED ADDRESS].

We are the data controller for the personal data described in this policy, unless we tell you we are acting as a processor on a client’s behalf (in which case the client is the controller and our processing is governed by the data processing addendum between us).

Our regulators

Malta (lead authority)
Information and Data Protection Commissioner (IDPC) — idpc.org.mt
United Kingdom
Information Commissioner’s Office (ICO) — ico.org.uk

UK representative (Article 27, UK GDPR)

Because we target UK data subjects from outside the UK, we have appointed a UK representative as our point of contact for UK data subjects and the ICO:

[UK REP NAME]
[UK REP ADDRESS]
Email: [UK REP EMAIL]

2. What this covers

This policy covers personal data we process in connection with the Tackt website (tackthq.com) and our service. It does not cover third-party websites we link to, or the internal privacy practices of our clients.

3. Data we process

About people at firms we contact on a client’s behalf (“prospects”)

This is most of what we do. For individuals at firms our clients have told us they want to approach, we process:

We do not process personal email addresses, home addresses, special category data (e.g. health, religion, politics), or data about children.

About our clients’ staff

About visitors to our website

4. Lawful bases

We rely on different lawful bases depending on what we are doing:

Contacting prospects
Legitimate interests (UK/EU GDPR Art. 6(1)(f)): the mutual business interest in a senior professional at a regulated UK firm being made aware of a relevant service, where we have taken reasonable steps to ensure the message is genuinely relevant and the data subject can object at any time. We have carried out a legitimate interests assessment (LIA).
Providing the service to clients
Contract (Art. 6(1)(b)): processing necessary to perform our agreement with the client.
Billing, tax and records
Legal obligation (Art. 6(1)(c)): we must keep accounting records under Maltese and international tax law.
Website analytics & security
Legitimate interests (Art. 6(1)(f)): running and securing our own website.
Direct marketing to our own prospects
Legitimate interests in the UK/EU B2B context, combined with PECR compliance (see section 12).

5. Where we get data

6. What we use it for

We do not use personal data for automated decisions that produce legal or similarly significant effects about individuals, in the sense of Article 22 UK/EU GDPR.

7. Who we share with

We share personal data only with:

We do not sell personal data. We do not share personal data with advertising networks.

8. International transfers

Tackt is established in Malta. Some of our processors are in the United Kingdom, the European Economic Area, or the United States.

9. How long we keep it

Prospect data (not contacted)
Up to 12 months from last refresh, then deleted unless still relevant.
Prospect data (contacted, no reply)
Up to 24 months from last contact, then deleted or suppressed.
Prospect data (replied / meeting taken)
Retained for the life of the client relationship plus 12 months.
Unsubscribe / opt-out records
Retained indefinitely so we can honour the opt-out.
Client contract & billing data
Six years from end of relationship, for tax and accounting.
Website analytics
Up to 13 months, then aggregated.
Server security logs
30 days.

10. Your rights

Whether you are in the UK, the EEA, or Malta, you have the right to:

To exercise any of these, email privacy@tackthq.com. We respond within one month. We will not charge a fee unless a request is manifestly unfounded or excessive.

Opting out of our outreach is instant. Reply “unsubscribe” to any message, click the unsubscribe link, or email suppress@tackthq.com. We suppress across every client we work for, not just the one that contacted you.

11. Security

We take appropriate technical and organisational measures, including: encryption in transit (TLS 1.2+) and at rest; access controls with least-privilege and audit logging; multi-factor authentication on all admin systems; regular backups; documented incident response; and vendor due diligence before any processor is engaged.

We are required to notify the IDPC (and, where relevant, the ICO) of a personal data breach within 72 hours where it is likely to result in a risk to individuals, and to notify affected individuals where the risk is high.

12. Direct marketing & PECR

Our outreach to UK recipients is governed by the UK’s Privacy and Electronic Communications Regulations 2003 (PECR) as well as the UK GDPR. For outreach to EEA recipients, the ePrivacy Directive as implemented locally, and the EU GDPR, apply.

13. Cookies

The Tackt marketing site uses no advertising or tracking cookies. We use a privacy-preserving analytics tool ([ANALYTICS TOOL]) that does not set cookies and does not collect personal data. If we add any non-essential cookies in future, we will ask for your consent first.

14. Changes to this policy

We update this policy when our practices change or the law does. The “last updated” date at the top tells you when. If a change is material, we will also notify clients directly.

15. How to contact us

General privacy enquiries: privacy@tackthq.com

Opt-out / suppression: suppress@tackthq.com

Post (Malta): [TACKT LEGAL ENTITY NAME], [MALTA REGISTERED ADDRESS]

UK representative: [UK REP NAME], [UK REP ADDRESS], [UK REP EMAIL]

For your solicitor. The bracketed fields — legal entity name, Malta company number, registered office, UK representative, named processors, and analytics tool — should be completed before this page goes live. A Maltese-qualified data protection adviser should review the legitimate interests assessment referenced in section 4 and sign off on the final version of this policy.