Skip to legal content
Legal & Trust Center
Trust Center Contact IK Studios ↗
Legal Center

Privacy & Data

Privacy Policy

What personal data IK Studios collects through its websites and company operations, why we collect it, and the choices and rights you have.

Owner
IK Studios
Updated
June 28, 2026
Effective
June 28, 2026
Scope
Netherlands · EU / EEA

On this page

Who is responsibleOur approachData we collectPaymentsWhy we are allowed to process itWho we share data withInternational transfersHow long we keep itYour rightsChildrenChanges to this policy

Back to Legal Center

Policy library

Overview

Trust CenterLegal FAQ

Privacy & Data

Privacy PolicyCookie PolicyGDPRCCPA (California)Data RetentionData DeletionPrivacy PreferencesCookie Settings

Terms & Use

Terms of ServiceLicense AgreementAcceptable UseSubscription TermsRefund Policy

Trust & Security

SecurityResponsible DisclosureSubprocessor ListThird-Party ServicesData Processing AgreementService Statussecurity.txt

Intellectual Property & Brand

Copyright PolicyCopyright NoticeTrademark PolicyBrand AssetsPress & MediaOpen Source Notices

Disclaimers & Liability

Website DisclaimerSoftware DisclaimerLimitation of Liability

Artificial Intelligence

AI Usage Policy

Accessibility

Accessibility Statement

Company

Contact & Legal InfoCommunity Guidelines

On this page

Who is responsibleOur approachData we collectPaymentsWhy we are allowed to process itWho we share data withInternational transfersHow long we keep itYour rightsChildrenChanges to this policy

Who is responsible

IK Studios (“we”, “us”, “our”) is an independent software studio based in the Netherlands. We are the data controller for personal data processed through our websites — including ikstudios.nl — and for company operations such as support, billing, and recruitment correspondence.

This policy explains those company-level and website practices. It does not replace the product-specific privacy details for Vault One, which are maintained in the Vault One Privacy Policy. Where the two overlap, the product policy governs your use of that product.

Our approach

We design for privacy first. That means we try to collect as little as possible, keep sensitive data close to you, and avoid building profiles of your behaviour.

No data sales

We never sell personal data and never use it for cross-site advertising.

No behavioural ads

Our websites carry no advertising or third-party tracking pixels.

Device-first products

Vault One is built to keep your connected finance data on your device, not in our cloud.

Minimal by default

We ask for the least we need to provide and secure a feature.

Data we collect

Depending on how you interact with us, we may process the following categories of personal data:

Categories of personal data
WhenDataWhy
You visit our websitesServer request logs (IP address, browser/user-agent, timestamps) and essential local storageServe pages, keep sites secure and reliable, remember basic preferences such as theme
You email or contact usYour email address, name if provided, and the contents of your messageRespond to your request and keep a record of the conversation
You become a customerAccount email and identifiers, plan and subscription status, and limited billing metadataOperate your account, take payment, and meet tax and accounting duties
You report a security issueYour contact details and the technical information you choose to shareInvestigate, fix, and follow up under our Responsible Disclosure Policy

We do not run a third-party product-analytics SDK (such as Google Analytics, Mixpanel, PostHog, or Segment) in the Vault One codebase, and our websites are served as largely static pages without behavioural tracking.

Payments

Paid products are billed through Stripe. When you subscribe, Stripe processes your payment details directly; we receive limited billing metadata such as your email, plan, subscription status, and invoice records. We do not store full card numbers.

Stripe acts as an independent controller and/or processor for payment data under its own terms. See our Subprocessor List and Subscription Terms.

Why we are allowed to process it

Under the GDPR we rely on a lawful basis for each activity:

  • Contract — to create and operate your account and provide a product you have purchased.
  • Legitimate interests — to keep our sites and services secure, prevent abuse, and respond to your messages, balanced against your rights.
  • Legal obligation — to keep invoices and tax records for the period the law requires.
  • Consent — for anything optional, such as non-essential communications, which you can withdraw at any time.

Our full lawful-basis mapping and your rights are set out in GDPR Compliance.

Who we share data with

We share personal data only with the service providers we need to operate, each bound to protect it and use it only on our instructions. The current list, with the role of each provider, is the Subprocessor List.

We may also disclose information where we are legally required to, or to protect the rights, safety, and security of people and our services — always limited to what is necessary.

International transfers

We favour hosting and providers within the EU/EEA. Where a provider processes data outside the EEA, we rely on appropriate safeguards such as European Commission adequacy decisions or Standard Contractual Clauses, together with data minimisation.

How long we keep it

We keep personal data only as long as we need it for the purpose we collected it, or as the law requires. The specifics are in our Data Retention Policy, and you can ask us to delete eligible data per the Data Deletion Policy.

Your rights

Subject to applicable law, you can request access, correction, deletion, restriction, portability, or object to certain processing, and withdraw consent at any time. Email support@ikstudios.nl from your account address; we may verify your identity first. You can also complain to a supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens.

Children

Our products and websites are intended for adults and are not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

We may update this policy as our products and practices evolve. We will change the “Updated” date above and, for material changes, take reasonable steps to let affected people know. Continued use after an update means you accept the revised policy.

Contact & notices

Questions about these documents, your privacy rights, a security report, or a business agreement — we read every message and route it to the right person.

General, privacy & security
support@ikstudios.nl
Business & billing
sales@ikstudios.nl
Product feedback
feedback@ikstudios.nl
Full contact page
Contact & Legal Information
Legal CenterPrivacyTermsCookiesSecurityTrust CenterContactIK StudiosVault One

IK Studios policies are written to be read — plain language first, with the detail behind it. We keep them aligned to what we actually build.

Last updated June 28, 2026. Questions: support@ikstudios.nl. These documents apply to IK Studios and its websites; product-specific terms for Vault One live in the Vault One Trust Center.

© 2026 IK Studios. An independent software studio.