Privacy for a housing communication platform

Sicket is designed with GDPR principles in mind and includes controls that can support customer privacy obligations. This notice explains how personal data is handled on the marketing site and in the Sicket product.

Last updated:

Roles and scope

For the public marketing website at sicket.app, Sicket acts as controller for personal data submitted through contact forms, newsletter subscriptions, career applications, cookie choices, and consented analytics.

For customer data processed inside Sicket, Sicket generally acts as processor on behalf of the housing organization using the platform. The customer determines why resident and operational data is processed, which users receive access, and the applicable legal basis. Sicket may act as controller for limited account, security, billing, support, and service-operation data.

Account creation and your choices

Self-serve organization onboarding, invitation acceptance, and building self-join require users to acknowledge the current Privacy Notice and accept the current Terms of Service. Sicket records the applicable version and timestamp for each acknowledgment or acceptance so the account can show which legal information applied.

The public Sicket newsletter requires a separate opt-in and confirmation through a link sent to the submitted email address. It is separate from customer operational emails and in-product communication preferences. Website and onboarding analytics require a separate cookie choice, and embedded Google Maps content is controlled through a separate preference. Rejecting these optional choices does not prevent a user from accepting the Privacy Notice or Terms of Service.

What data we process

  • Contact form details such as name, work email, organization name, number of buildings, and the message you send us.
  • Public newsletter details such as email address, selected language, consent version and timestamps, confirmation status, and unsubscribe status.
  • Career application information submitted through Tally, including contact details, form answers, and any CV or portfolio files you choose to upload.
  • Cookie preferences and selected website, onboarding, and checkout events where analytics consent has been given.
  • Account and profile details, authentication and session records, legal-acceptance records, notification preferences, organization memberships, building assignments, and residential-unit assignments.
  • Ticket titles and descriptions, type, status, location, comments, internal notes, attachments, activity history, read state, incident links, and AI-assisted fields or outputs.
  • Incidents, announcements, News & Updates, Knowledge Base entries, Contractor Cases, invitations, audit history, and other organization records created through enabled features, including retained historical records.
  • Subscription, invoice, tax-status, and Stripe reference data needed to administer billing. Sicket does not receive or store full payment-card details entered on Stripe-hosted pages.

Ticket visibility and anonymous submission

  • Personal tickets are not shown to other tenants. They are available to the creator and authorized organization staff within the applicable scope.
  • Community tickets are visible to tenants in the same building and may appear as similar-ticket suggestions during ticket creation.
  • Anonymous submission is available only for community tickets. It hides the creator's name and residential unit from tenant-facing views and masks comments made by the original creator for other tenants.
  • Authorized organization administrators and assigned landlords can still see the reporter identity needed to handle an anonymous community ticket. Observers do not receive that hidden identity.
  • Anonymous ticket data remains available to the internal systems and authorized platform administrators needed to operate, protect, and support the service.

Do not place identifying or unnecessary sensitive information in a community ticket's title or description. Anonymous submission masks account and unit fields; it cannot remove personal details a user writes into the ticket content. Read the ticket visibility guide for practical examples.

Job applications

Sicket uses Tally to collect job applications and uploaded CVs. We use this information to review potential fit for current or future roles. Submitting an application does not create an automated hiring decision.

Only include information relevant to your application and avoid unnecessary sensitive or special-category personal data. We retain applications only as long as reasonably needed for review, relevant future opportunities, legal obligations, or dispute handling. Contact hello@sicket.app to request deletion.

Optional website and onboarding analytics

With consent, Sicket uses PostHog on the public website and self-serve onboarding and checkout flow. We measure events such as page or onboarding-step views, selected plan and currency, checkout redirects and outcomes, completed setup, referring domains, and high-level campaign details. Our custom events do not store the referring page or a full browsing URL.

Custom analytics events exclude names, email addresses, phone numbers, postal addresses, passwords, tax identifiers, payment-card data, organization or building names, free-text form entries, verification tokens, and onboarding or Stripe session identifiers.

Sicket does not use PostHog session replay, automatic click or form capture, exception autocapture, or identified person profiles in these flows. You can reject analytics or change your choice later through Cookie preferences.

Form security and optional Google services

Where enabled, Cloudflare Turnstile protects public forms and signup using browser and connection signals. This security check is separate from optional analytics. Google sign-in runs when you choose it, and embedded Google Maps loads only after you allow map content in the dashboard. The providers and their privacy notices are listed on the Subprocessors page.

AI-assisted features

Current optional dashboard features include ticket category and priority assessment, similar-community-ticket retrieval, self-service answer support, Knowledge Base retrieval, and recurring pattern detection. Backend support for draft-reply processing may remain for compatibility, but draft replies are not offered as a current dashboard feature. Authorized staff can adjust an assessed priority, while category remains automatically managed and may be reassessed when core ticket details change.

Where OpenAI processing is enabled, Sicket sends a minimized and sanitized subset of relevant content and metadata through the OpenAI API. The integration requests that response content is not stored as application state. Content with detected sensitive data may be skipped, and deleted, withdrawn, archived, or redacted records are excluded where the feature requires it.

OpenAI states that API data is not used to train its models by default unless the customer explicitly opts in. Under OpenAI's default API controls, abuse-monitoring logs may be retained for up to 30 days unless approved retention controls or a legal requirement changes that period.

Service providers and international transfers

Sicket uses service providers for infrastructure, email delivery, billing, analytics, career applications, monitoring, and optional AI features. The current list and processing notes are available on the Subprocessors page. Depending on the provider and feature path, processing may involve countries outside the European Economic Area and the applicable contractual or organizational safeguards.

Security and access controls

  • Role- and building-scoped authorization limits access to the relevant organization, buildings, and records.
  • Production access is restricted to authorized personnel and operational needs.
  • Personal ticket conversations, internal notes, attachment contents, and anonymous identities receive additional viewer restrictions.
  • Session, audit, redaction, and lifecycle controls support investigation and privacy workflows.

Read the Security overview for the current public description of these controls.

Retention, account deletion, and privacy rights

Sicket uses automated retention windows for expired sessions, invitations, join tokens, and incomplete onboarding records. Customer content retention can depend on organization settings, the customer contract, legal obligations, security needs, and dispute handling.

A newsletter subscription remains active until it is unsubscribed. After unsubscribing, Sicket may retain a limited consent and suppression record where needed to honor the opt-out, demonstrate consent history, prevent unwanted delivery, or meet legal obligations. Every marketing newsletter can link to the public unsubscribe page.

The product supports personal-data export and erasure workflows. Eligible users can schedule account deletion and cancel it during the displayed waiting period; account types with operational ownership responsibilities may require support or an administrator transfer first. Erasure deactivates access and replaces or removes direct account identifiers. Necessary operational or audit records may remain in anonymized or restricted form where retention is justified.

Contact support@sicket.app regarding access, correction, export, restriction, deletion, or objection requests. Sicket and the relevant housing organization will handle the request according to their respective roles.

Email communications

The Email communications page explains operational email categories, in-product preference controls, newsletters and resident updates, and the separate opt-ins for in-product updates and the public Sicket newsletter.