GDPR Compliance
Last updated: January 2025
GDPR Compliance Overview
CheckTube (operated by Aiklik.nl) is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and your rights as a data subject.
As a data controller, we process personal data lawfully, fairly, and transparently, ensuring your privacy rights are respected at all times.
Your GDPR Rights
Under GDPR, you have the following rights:
- ✓Right to Access
Request a copy of your personal data we process
- ✓Right to Rectification
Request correction of inaccurate personal data
- ✓Right to Erasure
Request deletion of your personal data
- ✓Right to Data Portability
Receive your data in a structured, machine-readable format
- ✓Right to Object
Object to processing of your personal data
- ✓Right to Restrict Processing
Request limitation of processing your data
Data We Process
Essential Service Data
- YouTube video URLs you submit
- Generated checklist content
- Session identifiers
- Basic usage analytics (anonymized)
Legal Basis for Processing
- Legitimate Interest: To provide and improve our service
- Consent: For optional features and analytics
- Legal Obligation: To comply with applicable laws
Data Security Measures
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption of data in transit (HTTPS/TLS)
- Encrypted database storage
- Access controls and authentication
- Regular security audits and updates
- Limited data retention periods
- Employee training on data protection
Data Retention Policy
We retain personal data only for as long as necessary:
- Saved checklists: Until you request deletion
- Session data: 30 days
- Analytics data: Anonymized after 90 days
- Server logs: 30 days
- Temporary processing data: Deleted immediately after use
International Data Transfers
Your data may be processed by third-party services:
- OpenAI (USA) - for checklist generation
- Supabase (USA) - for data storage
- Vercel (USA) - for hosting
All third-party processors are contractually bound to comply with GDPR requirements and use appropriate safeguards for international transfers.
Data Breach Procedures
In the unlikely event of a data breach:
- We will notify affected users within 72 hours
- Report to relevant supervisory authorities
- Document the breach and our response
- Take immediate steps to minimize impact
- Review and improve security measures
Contact Our Data Protection Officer
To exercise your GDPR rights or for privacy concerns, contact:
We aim to respond to all data subject requests within 30 days.
Supervisory Authority
You have the right to lodge a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens
Website: autoriteitpersoonsgegevens.nl
Updates to This Policy
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. We will notify you of significant changes through our website or via email if you have provided contact information.