Sidekik.io

Sidekik.io Privacy Policy

Last Updated: December 8, 2025

Introduction and Scope

Welcome to Sidekik.io! This Privacy Policy describes how Fixin Pty Ltd (owner of the platform Sidekik.io, referred to as “Sidekik.io,”, “Sidekik”, “we,” “us,” or “our”) collects, uses, stores, and shares your personal information when you use our website, platform, and services (collectively, the “Services”). Sidekik.io is a software-as-a-service (SaaS) platform and AI-powered customer communication representative that enables small and mid-sized businesses and service professionals to automate and manage customer interactions through text and voice chat, forms, meeting scheduling, and support request handling. We value your privacy and are committed to protecting your personal data in compliance with applicable laws worldwide.

This Privacy Policy applies to all users of Sidekik.io, including:

  • Business Users (Profile Owners): Small to mid-sized business owners, service professionals, and small teams who create and manage a Sidekik profile on our platform.
  • End Users (Customers/Visitors): Individuals who interact with a business or individual via their Sidekik profile – for example, by chatting (text or voice) with the Sidekik assistant, submitting inquiries or forms, scheduling meetings, or visiting the public profile page.

By using Sidekik.io Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please discontinue use of our Services. If you have any questions about this policy, feel free to contact us using the information in the Contact section below.

Our Role (Controller vs Processor): In certain cases, Sidekik.io acts as a “data controller” of your personal information (for example, when you sign up for an account or we collect your data for our own purposes like analytics or marketing). In other situations – particularly when End Users provide information through our platform to a Business User – Sidekik.io acts as a “data processor” (or “service provider”) processing that information on behalf of the Business User who is the data controller. This means we handle End User data only to provide the service as directed by the Business User and do not use it for our own independent purposes. Regardless of our role, we protect all personal data in accordance with this Privacy Policy and applicable law. (End Users should also review the privacy practices of the business they are interacting with, as that business may have its own privacy policy governing how they handle your data.)

Information We Collect

We collect various types of information from and about users of our Services. This includes information you provide directly, information collected automatically about your use of the Services, and information from third-party services (if you integrate them). The types of personal information we collect depend on how you interact with Sidekik.io and whether you are a Business User or an End User.

Information from Business Users (Profile Owners)

If you create a Sidekik.io profile for your business or organization, we may collect the following information about you and your company:

  • Account and Contact Information: Your name, business or company name, email address, phone number, postal address, and login credentials (such as username and password). This is collected when you sign up and create an account.
  • Business Profile Content: Information you choose to add to your Sidekik profile, such as a description of your business or services, your business logo or images, a summary of products and services, FAQs and knowledge base content about your company, links to your website or social media, calendar scheduling links, and any other details or content you input into the platform. We store this content to display on your public profile and to train your Sidekik assistant to answer inquiries.
  • Billing and Payment Information: If you purchase a subscription or paid features, we collect payment-related information. This may include your billing name, billing address, and payment method details. Important: We use trusted third-party payment processors (e.g., Stripe) to handle credit card and transaction information securely. Sidekik.io itself does not store your full credit card numbers; such sensitive financial data is handled by the payment processor. We may retain records of your transactions and subscription status.
  • Customer/Lead Information Provided by You: Through using our platform, you might input or upload personal information about your own customers, clients, or leads. For example, you may manually enter a lead’s contact details into your dashboard, or import a list of client contacts, or add notes about a client. This can include names, emails, phone numbers, company/organization names, or other information about individuals who are your customers or prospects. We will handle such personal data in accordance with this Policy and only as needed to provide the Services (see Our Role above, as we treat this as data you control and we process on your behalf).
  • Communications with Us: If you contact us (for example, via support email or chat), we will collect the information you provide in those communications (like your contact details and the content of your inquiry) in order to assist you.

Information from End Users (Customers and Visitors)

If you are an end user interacting with a Business User’s Sidekik (for instance, you’re a customer sending a message or filling out a form on someone’s Sidekik profile), Sidekik.io may collect the following information about you:

  • Contact Details You Provide: You may be asked to provide certain information when you start a chat, submit an inquiry form, or schedule a meeting through Sidekik. Typically, this includes your name, email address, phone number, or other contact details. For example, if you initiate a conversation or request, you might enter your name and email so the business can respond to you.
  • Chat and Inquiry Content: We collect the content of the communications and requests you submit through the platform. This includes text chat messages you send to the Sidekik assistant, voice messages or questions (which may be recorded or transcribed to text), inquiry form inputs, service or support requests, and any files or attachments you choose to upload (if that functionality is available). In short, anything you explicitly communicate or submit via the Sidekik interface will be collected and provided to the relevant Business User, and stored by us to enable the Service. This may include details about the service you’re inquiring about, the issue you need help with, or any other information you volunteer.
  • Usage Data and Technical Information: Like many online services, we automatically collect certain technical information about your device and how you interact with Sidekik.io. This data helps us run the platform and provide analytics. It may include:
  • Device and Browser Information: e.g., your device type (desktop, phone, tablet), operating system, browser type and version.
  • IP Address and Geolocation: We collect your IP address when you interact with the Service. From the IP, we may derive an approximate geographic location such as country, state/region, and city. This helps in providing location-based features (for example, showing the Business User roughly where inquiries are coming from) and for security and analytics. We do not store your IP address.
  • Usage Details: timestamps of your visits or interactions (date and time of chat messages or form submissions), pages or screens you viewed on the Sidekik profile, the referring webpage or source that led you to a Sidekik profile (e.g., if you clicked a link from the business’s website or social media), and session information.
  • Cookies and Similar Technologies: We use cookies and similar tracking technologies (like web beacons or local storage) to collect some of the above information and to remember your interactions. For instance, cookies may keep you logged in (for Business Users on the dashboard) or help us understand how End Users navigate a profile page. For more details, see the Cookies and Tracking section below.
  • Audio Data (Voice Interactions): If you use voice chat features to talk to a Sidekik assistant, your voice input will be captured and processed. We may record the audio and/or convert voice queries into text transcripts to enable the AI responses and for quality assurance. These voice recordings or transcripts are treated as personal data since they may contain your voice or other personal information you share verbally.

We do not knowingly collect any sensitive personal data (such as government ID numbers, financial account passwords, health or biometric data, precise location data, etc.) from users, unless specifically requested for a feature and explicitly provided by the user. We ask that you do not provide any sensitive personal information unless it is necessary for your interaction with the Service. Sidekik.io also does not solicit or intentionally collect personal information from children (see Children’s Privacy below for more).

How We Use Your Information

We use personal information for various purposes consistent with providing, maintaining, and improving our Services, and as allowed by law. In particular, we may use the information we collect for the following business and operational purposes:

  • Providing and Operating the Service: We use the data to allow you to access and use the Sidekik.io platform and its features. For Business Users, this means enabling you to create and manage your profile, configure your Sidekik assistant, receive and respond to customer inquiries, and use the dashboard (e.g., to view leads, inquiries, and analytics). For End Users, this means processing your chat messages, inquiries, or bookings and delivering them to the appropriate Business User’s dashboard, as well as generating responses via the AI assistant. Essentially, your data is used to perform the contract with you or the Business User (for example, using your inquiries to connect you with the business you’re trying to reach).
  • Personalizing and Enhancing User Experience: We may use collected information to personalize the Services for you. For instance, Sidekik’s AI might utilize information provided by the Business User (such as FAQs and service details) to give you (the End User) more relevant and accurate answers. For Business Users, we may tailor aspects of the dashboard or communications based on your usage (e.g., show relevant tips or configure your profile page based on your industry).
  • Communication and Notifications: We use contact information (like email or phone number) to communicate with you.
  • For Business Users: We will send you service-related communications such as account verification emails, notifications of new customer inquiries or messages, updates on leads and support requests, and important alerts about your account or subscription. We may also respond to your support queries or send product announcements.
  • For End Users: If you provide your email or phone during an interaction (for example, to get a copy of a conversation transcript, to receive a booking confirmation, or to get a reply from the business), we will use that information to send you the requested information or facilitate further communication with the Business User. We do not use End User contact info to send marketing communications unless you separately consent to such marketing through the Business User or us.
  • Lead and Inquiry Management: Information submitted by End Users is used to create lead entries or support tickets for the Business User in their Sidekik dashboard. We process this data so the Business User can manage follow-ups, respond to requests, and keep a record of interactions with their customers. We also enable features like meeting scheduling by using provided info (e.g., sending your name and email to the Business User’s calendar system if you book an appointment).
  • Analytics and Platform Improvement: We use technical data and usage information (often in aggregated or de-identified form) to understand how our Services are used and to improve performance. For example, we analyze chat transcripts to improve our AI responses and to identify common questions or issues. We monitor usage patterns to detect bugs, improve user interface and experience, and develop new features. Analytics tools (like Google Analytics or our internal tools) help us measure traffic, understand which features are most used, and guide our business decisions. Wherever possible, we use aggregated data for these purposes that does not directly identify individuals.
  • Customer Support and Troubleshooting: We may use your information to provide support if you encounter issues. This includes using log data to diagnose technical problems, reviewing chat transcripts or error messages to fix bugs, and helping you resolve any account issues.
  • Payments and Subscription Management: For Business Users, we use your information to handle payments and billing. For example, we process your provided payment method through our payment processor (Stripe) when you subscribe to a paid plan. We also use purchase history to manage your subscription (e.g., to remind you of upcoming renewals, send invoices or receipts, or apply applicable taxes). If any issues arise with billing, we will use account data to contact you and resolve them.
  • Marketing and Updates (with Consent): We may use your contact information to send you newsletters, product updates, special offers, or promotional communications about Sidekik.io if you have opted-in or if it’s otherwise permitted by law. For instance, if you are a Business User, we might email you about new features that could benefit your business. You can always opt out of marketing emails by clicking the unsubscribe link in any such email or by contacting us. (We will not spam you, and we won’t send marketing to End Users who provided their email solely to communicate with a Business User unless they separately subscribe to our marketing communications.)
  • Security and Fraud Prevention: We use information (especially technical and usage data) to maintain the security of our platform, users, and their data. This includes monitoring for suspicious or fraudulent activity, detecting and protecting against malicious behavior, enforcing our Terms of Service, and verifying user identities where necessary. For example, we may use IP addresses and login history to identify potentially unauthorized access to accounts, or we may deploy automated tools to prevent spam or abusive use of the Sidekik chat widget.
  • Legal Compliance: We may process your personal information as required to comply with applicable laws, regulations, legal processes, or government requests. For instance, keeping payment transaction records for financial regulations, or using data to comply with consumer privacy laws’ requirements. We also may use and retain data to establish or defend legal claims.

We will not use your personal data for purposes that are incompatible with the above, unless we obtain your consent or are required/permitted by law. If we intend to use your data for a new purpose, we will update this Privacy Policy and notify you as appropriate.

Legal Bases for Processing (EEA/UK Users)

For individuals in the European Economic Area (EEA), United Kingdom, or other regions with similar laws, Sidekik.io must inform you of the legal grounds we rely on to process your personal data under the General Data Protection Regulation (GDPR) or applicable law. We process personal data only when we have a lawful basis to do so, which may be one of the following:

  • Performance of a Contract: Much of our processing is to fulfill our contractual obligations to you (the data subject). When you sign up for Sidekik.io and agree to our Terms of Service, we must process your data to provide the Services as described (e.g. maintaining your account, enabling the chat functionality, delivering inquiries). Likewise, if you are an End User contacting a business via Sidekik, we process your data to connect you with that business – effectively providing the service you are requesting.
  • Legitimate Interests: We process certain data as necessary for our (or others’) legitimate interests, provided those interests are not overridden by your data protection rights. Our legitimate interests include: improving and ensuring the security of our Services, understanding how the platform is used, serving the communications between users and customers effectively, and running and growing our business. For example, using analytics to improve our UI is based on our legitimate interest in enhancing our service. When we rely on this basis, we consider and balance any potential impact on your rights.
  • Consent: In some cases, we rely on your consent to process personal data. For instance, we will obtain your consent before using certain cookies that are not strictly necessary, or before sending you marketing emails. If we process any sensitive information (though we typically do not), it would also be on the basis of explicit consent. You have the right to withdraw consent at any time, as described in Your Rights and Choices below.
  • Legal Obligation: We will process personal data if necessary to comply with a legal obligation that we are subject to. For example, accounting and tax laws may require us to retain certain transaction data, or consumer protection laws might require we honor opt-out requests and document those.

If you have any questions about the legal basis of how we process your data, feel free to contact us for more information.

How We Share Your Information

We understand the importance of keeping your personal information private. Sidekik.io does not sell or rent your personal data to third parties for their own marketing or commercial purposes. We only share your information in a limited number of situations, typically with trusted third parties who help us provide and improve our Services, or if necessary for legal reasons or business transfers as described below. When we share data, we do so in accordance with applicable data protection laws and with appropriate safeguards in place.

The scenarios in which we may share personal information are:

  • With Service Providers and Sub-Processors: We use reputable third-party companies to support our operations and provide specific services on our behalf. These service providers (or “sub-processors”) are bound by confidentiality obligations and only given access to data as needed to perform their functions. They are not allowed to use your data for any purpose other than providing services to Sidekik.io. Key categories of service providers we use include:
  • Hosting and Infrastructure: We host our application and databases on cloud platforms (for example, providers like Supabase, Hostinger, Amazon Web Services (AWS), or similar). These services store and manage the data (including personal information) that our platform needs to function. They act under our instructions to ensure data is secure and available.
  • Payment Processing: We partner with external payment gateways such as Stripe to handle credit card processing and subscription billing securely. When you make a purchase, your payment information is transmitted directly to the payment processor; we receive a confirmation and basic details (like the last four digits of your card, payment dates, amounts) but not your full credit card number. Stripe (or any payment provider we use) is authorized to use your payment data only as necessary to process payments and comply with applicable law.
  • Analytics and Usage Monitoring: We may use third-party analytics tools like Google Analytics or similar services to help us understand usage of our site and application. These analytics services may set cookies or use tracking technologies to collect technical data (as described in Information We Collect). This helps us analyze user interactions and improve the platform. Analytics providers process data on our behalf and are not allowed to use it for their own marketing. We might also employ internal analytics solutions that process data stored on our servers.
  • Communications and Messaging: We rely on email and messaging service providers to send out communications. For example, we might use an email delivery service such as Brevo (formerly Sendinblue), Mailgun, Amazon SES, or similar, to send verification emails, notification messages, or newsletters. These providers handle the sending of messages to your email or phone, and in doing so will process your contact info and the content of the message. They are contractually prohibited from using that info for anything aside from delivering the communication. If our Service offers SMS or voice call notifications, we may use telecommunication APIs (e.g., Twilio or others) – similarly, they would process phone numbers and message content just to deliver the SMS/voice.
  • Other Sub-processors: From time to time, we may use other specialized vendors to provide certain functionality (for example, an AI speech-to-text service to transcribe voice messages, or a cloud function service to process data). We will ensure any such sub-processor is subject to strict privacy and security standards.
  • With Business User’s Organization (for End Users): If you are using Sidekik.io as an End User interacting with a Business User (e.g., you message a company through their Sidekik chat), the information you provide will be shared with that Business User who operates that Sidekik profile. For instance, your inquiry and contact details will become visible to the profile owner and their authorized team members via the Sidekik dashboard so they can respond to you. The Business User will handle that information according to their own policies and obligations. (Sidekik.io simply facilitates the transfer of data to them as part of the service.)
  • Legal Compliance and Protection: We may disclose personal information to third parties if we have a good-faith belief that such disclosure is necessary to:
  • Comply with any applicable law, regulation, legal process, or enforceable governmental request (for example, responding to a court order, subpoena, or regulatory inquiry).
  • Enforce or apply our Terms of Service and other agreements, including investigation of potential violations thereof.
  • Detect, prevent, or otherwise address fraud, security or technical issues (for example, exchanging information with other companies or organizations for fraud protection and risk reduction).
  • Protect the rights, property, or safety of Sidekik.io, our users, customers, or the public, as required or permitted by law. This may include sharing information with law enforcement or regulatory authorities in the event of threats or harm to any person, or investigating malicious activities.
  • Business Transfers: If Sidekik.io (or Fixin Pty Ltd) is involved in a merger, acquisition, bankruptcy, asset sale, reorganization, or other transaction where customer data would be transferred to or reviewed by a third party as part of the transaction, we reserve the right to transfer personal information as part of that deal. We will ensure that any acquiring entity is bound to respect the personal data as described in this Privacy Policy. If such a transfer is subject to additional mandatory legal requirements, we will comply with those. We will also notify you (for example, via email or a prominent notice on our site) of any change in ownership or use of your personal information, as well as any choices you may have regarding that information.
  • With Your Consent: Apart from the cases listed above, we will share your personal information with third parties only if you have given us your explicit consent to do so. For example, if we ever want to post a user testimonial that contains personal info, we would seek your permission. Or if you opt-in to integrate a third-party service with your Sidekik account (where data needs to flow to that service), we will do so under your direction. You have the right to revoke such consent at any time.

No Selling of Personal Data: We do not sell your personal information to data brokers or third parties for monetary or other valuable consideration. In the context of the California Consumer Privacy Act (CCPA), we do not “sell” personal info and have no intention to do so. If this ever changes, we will update this policy and implement any required opt-out mechanisms.

Third-Party Websites: Note that the Sidekik platform may contain links to external websites or services not operated by us (for example, a Business User’s social media links on their profile, or a scheduling link that directs you to a third-party calendar service). This Privacy Policy does not apply to those third-party sites or services, and we are not responsible for the privacy practices of any site that we do not control. We encourage you to review the privacy policies of any third-party websites or services that you visit or use.

Cookies and Tracking Technologies

Like most online services, Sidekik.io uses cookies and similar tracking technologies to make our website and Services function properly, to analyze usage, and to personalize your experience. This section explains what these technologies are and how we use them.

What Are Cookies? Cookies are small text files that are placed on your device (computer, smartphone, etc.) when you visit a website. They are widely used to make websites work, or work more efficiently, as well as to provide information to the site owners. Cookies can be “session cookies” (which expire once you close your web browser) or “persistent cookies” (which remain on your device for a set period or until you delete them). Similar technologies include web beacons (tiny graphic images embedded on pages or emails), local storage (used by web browsers), and scripts or tags that run on a site. For simplicity, we refer to all of these as “cookies.”

How We Use Cookies: Sidekik.io uses cookies and related technologies for the following purposes:

  • Essential Cookies: These are necessary for the operation of our Services. For example, we use cookies to remember your login session so you don’t have to re-enter your credentials on every page; to enable core features like authentication, security (e.g., detecting if someone is trying to log into your account from a new device); and to load balance and maintain the stability of our platform. Without these cookies, the Services may not function properly.
  • Functional/Preference Cookies: These cookies allow us to remember choices you make and provide more personalized features. For instance, if our dashboard has user-preference settings or if we support multiple languages, a cookie might remember your selected language or other preferences so that you have a tailored experience. They may also help in pre-filling forms or remembering other small customizations.
  • Analytics Cookies: We use analytics and performance cookies to collect information about how users interact with our website and Services, which pages are visited, or what features are used. This data helps us understand user behavior and improve our product. For example, we might use Google Analytics which sets cookies to track page visit counts, dwell time, referral sources, and aggregate usage patterns. The information collected is generally aggregated and does not directly identify individual visitors. It helps us diagnose problems and optimize the Service’s design and functionality.
  • Advertising/Marketing Cookies: (Currently, Sidekik.io does not run third-party ads on our site and we do not use advertising cookies for third-party marketing.) If in future we engage in any advertising or retargeting campaigns, we will update this section and obtain any necessary consents. At present, the only marketing-related cookies might be ones that track the effectiveness of our own site’s announcements or sign-up funnel (and these would fall under analytics). We do not share cookie data with third-party advertisers.

Cookie Consent and Choice: When you first visit our site (in jurisdictions where cookie consent is required), you will see a cookie banner or notice that informs you about our use of cookies. Where applicable law requires, we will ask for your consent before placing non-essential cookies (such as analytics cookies) on your device. You have the right to accept or reject cookies. You can manage your preferences through the cookie consent banner (select which categories of cookies you allow) and you can change your settings at any time via a “Cookie Settings” link (if provided) or by clearing cookies in your browser.

Additionally, most web browsers let you control cookies through their settings preferences. You can set your browser to refuse certain cookies or to prompt you before accepting cookies. You can also delete cookies that have already been set. Please be aware that if you disable cookies entirely, our website may not function correctly for you – for example, you might not be able to log in or use certain features.

“Do Not Track” Signals: Some browsers offer a “Do Not Track” (DNT) feature that, when enabled, sends a signal to websites that you do not wish to be tracked. There is currently no industry consensus on how to respond to DNT signals, and at this time, Sidekik.io does not respond differently to a browser DNT signal. We treat all visitors per this Privacy Policy and the consents you have provided. You may opt out of certain tracking as explained above (cookie settings or browser controls).

For more detailed information on our use of cookies and to see a list of cookies deployed on our site (if applicable), you can refer to our separate Cookies Policy or Cookies section on our site (if one is available). If you have any questions about our cookie practices, you can contact us.

Data Retention and Deletion

We retain personal information for as long as necessary to fulfill the purposes for which it was collected, as outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. In practice, this means:

  • Active Account Data: If you have a Sidekik.io account (Business User profile), we will keep your account information, profile content, and associated data for as long as your account is active. This allows you to continue using the Service over time. The data includes the content you have provided (FAQs, links, etc.), your leads/inquiry history, and any settings or preferences.
  • End User Inquiry Data: If you are an End User who has communicated through Sidekik, the messages or inquiries you submit and your contact details are retained so that the Business User can respond and maintain a record. The Business User may choose to delete or archive those inquiry records from their dashboard. Sidekik.io will not delete those records from an active Business User’s account unless instructed by the Business User or required by law, since those records belong to them as part of the service we provide. End Users who wish to have their data removed should reach out to the relevant Business User or to us (see Your Rights below).
  • Account Deletion: If you choose to delete your Sidekik.io account (or if a Business User’s account is terminated in accordance with our Terms), we will initiate deletion of personal data associated with that account. We first may deactivate the account and then, during a retention period, we will delete data from live systems. Retention Period: We typically retain backup copies and server logs for a short period after account deletion to ensure we can recover data in case of accidental deletion or to comply with legal obligations. This period is usually around 30 to 90 days following account deletion, after which personal data is purged from our production systems. During this interim, your data will be inaccessible to you and to the Service operations, except for system administrators managing the deletion process.
  • Marketing Data: If you have subscribed to receive marketing emails, we will retain your contact information for that purpose until you opt out or unsubscribe from marketing. Once you unsubscribe, we may keep your contact info on a suppression list (to ensure we respect your opt-out) but will no longer send you marketing messages.
  • Legal and Business Necessities: In certain cases, we may keep some information after deletion of an account or a specific piece of data, if necessary for legitimate business interests or legal obligations. Examples:
  • We may retain transaction records and invoices for accounting/tax purposes for the duration required by tax law (e.g., 7 years in some jurisdictions).
  • If there is an unresolved issue, dispute, or legal claim, we might retain relevant information until it is resolved.
  • We may keep server logs and security records to the extent needed for security monitoring and fraud prevention.
  • Data that has been aggregated or anonymized such that it is no longer personal information may be retained indefinitely for analytics, research, and service improvement purposes (as this data no longer identifies an individual).
  • Backup and Archive: Please note that residual copies of data might continue to exist in routine backups (archives) even after active databases are cleaned. However, we have processes to eventually overwrite or delete backup data as well, on a schedule. In the interim, we maintain the security of such backups and will not restore deleted personal data except if required for certain rare circumstances (e.g., to prove compliance, or as part of an investigation into fraud, etc.).

Once we no longer have a legitimate purpose for retaining your personal information, we will securely dispose of it or anonymize it. If deletion is not immediately possible (for instance, because the data is stored in a backup archive), we will ensure the data remains securely stored and isolated from further processing until deletion is possible.

Data Security

Sidekik.io is committed to protecting the security of your personal information. We implement a variety of technical and organizational security measures to safeguard data against unauthorized access, disclosure, alteration, or destruction. These measures include, but are not limited to:

  • Encryption: All data transmitted between your device and our servers is protected using encryption protocols such as HTTPS and TLS. This means any personal information (like login credentials or messages) is encrypted in transit. We also encrypt sensitive data at rest in our databases where feasible, or use hashed representations for things like passwords (which are stored using one-way cryptographic hash functions, never in plain text).
  • Access Controls: We limit access to personal data to authorized personnel who need it to operate or support our Service. Our team members and service providers are bound by confidentiality and are subject to background checks and strict contractual data protection obligations. Internally, we employ role-based access controls so that employees only access the level of information necessary for their role. Administrative access to systems storing personal data is logged and monitored.
  • Authentication and Account Security: Business User accounts are protected by email/password login, and we encourage the use of strong, unique passwords. (In the future we may offer multi-factor authentication for added security.) We also employ measures to detect and block suspicious login attempts or account misuse. If we detect unusual activity on an account, we may alert the user or temporarily lock access as a precaution.
  • Network and Application Security: Our infrastructure providers (like cloud hosts) maintain high security standards including firewalls, intrusion detection systems, and regular security patching. We use secure coding practices in developing Sidekik.io software and routinely update dependencies to mitigate vulnerabilities. Regular penetration testing and vulnerability scans are conducted to identify and address potential security risks.
  • Monitoring and Auditing: We continuously monitor our systems for possible attacks or intrusions. Logs of important actions (such as access to sensitive data or system configuration changes) are maintained and reviewed. We also have systems in place to alert us of anomalies that could indicate a security issue.
  • Third-Party Security: When we engage third-party service providers (such as those listed in How We Share Your Information), we vet their security practices and ensure they commit to protecting personal data with appropriate safeguards (through Data Processing Agreements and security audits as needed). For example, our payment provider is PCI-DSS compliant for handling payment card data.
  • Training and Policies: Our staff are trained on data privacy and security best practices. We maintain internal policies to handle data securely and respond swiftly to any potential incidents.

No Absolute Guarantee: While we strive to protect your information with diligent measures, no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, we cannot guarantee absolute security of your personal information. In the event of a data breach that affects your personal data, we will notify you and the relevant authorities as required by law, and we will take all reasonable steps to mitigate the impact and prevent future occurrences.

You also play a role in security: Please maintain the confidentiality of your account credentials and notify us immediately at [email protected] if you suspect any unauthorized access to your account or any security vulnerabilities. We will take prompt action on any reported issues.

International Data Transfers

Sidekik.io is a global service. By using our Services, you acknowledge and understand that your personal information may be transferred to and processed in countries other than your own. This can occur because our company is based in Australia, our customers can be worldwide, and our service providers may operate or store data in multiple jurisdictions (such as the United States, European Union, Malaysia, and others).

Specifically, the primary data storage locations for Sidekik.io are secure cloud servers located in Australia and Malaysia. However, depending on your location and the location of our third-party providers, your data might be transferred to or accessed from other countries. For example, if you are in the EEA, your data may be transferred to Australia; if you are in Australia, some data might be processed in the U.S. (for instance, by our use of a U.S.-based email service or payment processor), etc.

Different countries have different data protection laws, some of which may not be as strict as those in your home country. Regardless of where your data is processed, we will handle it in accordance with this Privacy Policy and take appropriate safeguards to ensure it remains protected.

Safeguards for International Transfers: When we transfer personal data across national borders, we take steps to protect it. These include: – For transfers from the European Economic Area (EEA), United Kingdom, or Switzerland to countries not deemed by the European Commission (or UK authorities) to provide an adequate level of data protection (such as Australia or the US), we rely on approved legal mechanisms. Typically, this involves implementing Standard Contractual Clauses (SCCs) – contractual commitments between the transferring and receiving parties that ensure your data is afforded essentially equivalent protection to EU standards. Our agreements with service providers include these SCCs where applicable, along with supplementary technical and organizational measures as necessary. – We may also rely on other mechanisms recognized under applicable law, such as an individual’s consent for specific transfers (where you have been informed of possible risks), or transfers that are necessary for the performance of a contract (e.g., when an End User outside Australia is communicating with an Australian Business User, the transfer of that communication may be necessary to fulfill their inquiry). – For transfers involving other regions (e.g., from Australia to the US, or US to other countries), we ensure compliance with local requirements. For example, Australian Privacy Principle 8.1 requires that we take reasonable steps to ensure the overseas recipient does not breach the APPs in relation to the information, or that an exception applies. We take those steps as needed.

If you would like more information about cross-border data transfers or the safeguards in place, please contact us. By continuing to use Sidekik.io, or by providing us with your personal information, you consent to the transfer of your data as described here, subject to the specified safeguards.

Your Privacy Rights and Choices

We respect your rights to access and control your personal information. Depending on your jurisdiction and whether you are a Business User or End User, you may have certain rights under privacy laws to request information or take action regarding data we have about you. Below, we outline general rights that we honor, followed by additional information for specific regions like the European Union/United Kingdom, California (USA), and Australia.

General Rights Available to Users:

  • Access Your Information: You have the right to request access to the personal data we hold about you. We can provide you with a copy of your information in a common electronic format. For Business Users, much of your basic info and content is accessible directly by logging into your account and viewing your profile/settings.
  • Correct or Update: If any of your personal data is inaccurate or outdated, you have the right to ask us to correct or update it. Business Users can directly edit some information in their account (like profile details, contact info). For any other corrections, contact us and we will rectify errors.
  • Delete Your Information: You can request that we delete your personal data. For example, Business Users can delete their account which triggers deletion of their data as described in Data Retention. End Users who interacted via Sidekik and wish their info removed should ideally contact the Business User (who controls their inquiry data) or contact us to assist. We will honor deletion requests to the extent required by law, but please note we may need to retain certain information for reasons permitted by law (such as completing a transaction you’re involved in, or for legal compliance).
  • Object to Processing: You have the right to object to our processing of your personal information in certain cases. For example, if we are processing your data based on legitimate interests, and you have a particular situation that makes you object to that processing, you can request that we stop. We will consider your request and will stop or limit processing unless we have compelling legitimate grounds to continue or the processing is needed for legal claims.
  • Restrict Processing: You can ask us to restrict (pause) the processing of your personal data in certain circumstances – for instance, while we verify your data correction request or objection request, or if you contest the lawfulness of processing.
  • Data Portability: Where applicable, you have the right to obtain a copy of certain information in a structured, commonly used, machine-readable format that you can transmit to another service provider (this generally applies to data you provided to us, and that we process by automated means based on consent or contract). For instance, Business Users can export their lead data from the dashboard. We can assist with other exports upon request.
  • Withdraw Consent: If we rely on consent for processing any of your personal data (for example, consent for receiving marketing emails or certain cookie usage), you can withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing that was based on consent before it was withdrawn. You can withdraw consent for marketing by unsubscribing from emails or contacting us, and for cookies by adjusting settings as described in Cookies.
  • Opt-Out of Marketing Communications: As noted, you can opt out of marketing emails by using the “unsubscribe” link in any such email or by contacting us. For SMS marketing (if ever used), you may reply “STOP” or follow provided opt-out instructions. Transactional and service-related communications (like billing notices or security alerts) are not typically subject to opt-out as they are necessary for our Services.

To exercise any of the above rights, please contact us at [email protected] with your request. We may need to verify your identity before fulfilling certain requests (for example, to ensure that the person requesting data deletion is the account owner or the person whom the data is about). Verification might involve asking you to provide information that matches our records. We will respond to your request within a reasonable timeframe as required by law (typically within 30 days for most rights, or faster if possible). If we cannot comply with your request in full (due to legal requirements or other issues), we will provide an explanation.

Additional Privacy Rights for Specific Regions:

  • European Union / EEA / UK (GDPR): If you are in the EEA or the United Kingdom, in addition to the rights listed above, you have the right to lodge a complaint with your local Data Protection Authority (DPA) or the UK Information Commissioner’s Office (ICO) if you believe we have infringed your data protection rights. We encourage you to contact us first so we can address your concerns. We hereby inform EEA/UK users that any personal data we collect may be processed outside the EEA/UK (as described in International Transfers), and we take appropriate measures (like SCCs) to protect it. Our EU/UK users also have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal or similarly significant effects – Sidekik.io does not engage in such solely automated decisions without human involvement that would have significant effects on individuals.
  • California, USA (CCPA/CPRA): If you are a resident of California, you are protected by the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). Under CCPA/CPRA, California residents have the right to:
  • Know/About Personal Information: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources for that information, the business or commercial purpose for collecting (or selling/sharing, if applicable) the information, and the categories of third parties with whom we share personal information. (Much of this information is provided in this Privacy Policy.)
  • Delete: You can request that we delete personal information we collected from you, subject to certain exceptions (for example, if the information is necessary to complete a transaction you initiated or to comply with a legal obligation, we may deny the deletion request for those specific data).
  • Correct: You can request correction of inaccurate personal information that we maintain about you.
  • Opt-Out of Sale or Sharing: As noted, we do not sell personal information as defined by CCPA. We also do not “share” personal information for cross-context behavioral advertising. If that ever changes, we will provide a means for you to opt out (such as a “Do Not Sell or Share My Personal Information” link). We do recognize Global Privacy Control (GPC) signals as a valid opt-out of sale/sharing, but since we don’t sell/share data, this is moot at present.
  • Non-Discrimination: You have the right not to receive discriminatory treatment from us for exercising any CCPA rights. We will not deny you service, charge you a different price, or provide a lesser quality of service because you exercised your privacy rights.

To exercise your California rights, you (or your authorized agent) can contact us at [email protected] with your request. We will need to verify your identity (and authorization, if through an agent) before responding. We aim to respond within 45 days as required by CCPA. Some information may be exempt from such requests under CCPA (for example, information subject to federal laws like HIPAA, or data we process as a service provider on behalf of a business client – in which case we may direct you to contact that business).

Notice for Minors: While our Services are not intended for minors, if a California minor under 18 has used our site and posted content that they later cannot remove, they can contact us to request removal. We will then make reasonably good-faith efforts to remove (or anonymize) such content, except to the extent retained as required by law. – Australia: Sidekik.io adheres to the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Australian users have rights to access the personal information we hold about them and to request corrections if needed. We will handle those requests within a reasonable time and may take steps to verify identity. If you are in Australia and have a complaint about our privacy practices, please contact us so we can resolve it. We will acknowledge your complaint promptly and aim to resolve it within a reasonable timeframe. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC). Also, as required by Australian law, we note that your personal information may be transferred overseas as described, and by using our Services you consent to that transfer. We take reasonable steps to ensure overseas recipients do not breach the APPs in relation to your information. – Other Regions: We strive to respect privacy rights provided by laws of other countries as well. For example, if you are in Canada (subject to PIPEDA), you have similar access and correction rights; if you are in Brazil (LGPD), you have rights like confirmation of processing and anonymization, and can contact us or our Brazilian representative if applicable; etc. Please reach out to us with any region-specific questions or requests and we will do our best to accommodate them in line with applicable law.

Children’s Privacy

No Use by Minors: Sidekik.io is not directed to children, and we do not knowingly collect personal information from individuals under the age of 18. Our Services are designed for businesses and their customers, and use of the platform is intended for adults (and, in some jurisdictions, persons at least the age of majority, which may be older than 18). You must be at least 18 years old to create a Sidekik.io profile or otherwise use our platform.

No Collection from Children Under 13 (or 16): We do not knowingly collect or solicit personal data from anyone under the age of 13 (and for certain jurisdictions under 16, in compliance with the EU GDPR). In fact, our Terms of Service prohibit children under 13 from using the Service. If you are under 13, please do not attempt to use the Service or send any personal information about yourself to us. If we learn that we have inadvertently collected personal information from a child under the applicable minimum age without verifiable parental consent, we will promptly delete that information from our records.

If you are a parent or guardian and you believe that a child under 13 (or under 16 in the EU/EEA) has provided us with personal information, please contact us immediately at [email protected]. We will work to delete the data as soon as possible and take any other appropriate actions required by applicable law (such as notifying relevant authorities if required).

Changes to this Privacy Policy

We may update or modify this Privacy Policy from time to time to reflect changes in our business, legal or regulatory obligations, or best practices in privacy and security. If we make material changes to how we collect, use, or share your personal information, we will provide clear notice of those changes. This may include posting a prominent notice on our website or within the app, and/or contacting you via the email address associated with your account.

The date at the top of this Privacy Policy indicates when it was last updated. We encourage you to review this Policy periodically to stay informed about our data practices and your privacy rights. If you continue to use Sidekik.io after an update, it signifies your acceptance of the revised Privacy Policy. If you do not agree with any changes, you should stop using the Services and may request deletion of your data as outlined above.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how Sidekik.io handles your personal information, please do not hesitate to contact us. We are here to help and will respond as promptly as we can.

  • Email: [email protected]
  • Postal Mail: Fixin Pty Ltd (Attn: Privacy Officer)
    81-83 Campbell St
    Surry Hills, NSW 2010
    Australia

We will address your inquiries and resolve any concerns to the best of our ability. If you contact us with a privacy-related complaint, we will investigate the issue and respond to you within a reasonable time frame, following any applicable laws.

Thank you for trusting Sidekik.io with your business and communications. We are committed to protecting your privacy and ensuring the security of your data as you use our Services.

 

Claim your handle before it's gone!

Your AI Receptionist has a unique name - as unique as you and your business.
Type your business name and see if your handle is available.

Your always-on AI Receptionist and AI Chatbot that handles your customers and audience on autopilot via phone, text and voice chat.

Made with ♡ in Sydney | Website by Grendesign

Sidekik.io © 2026, All rights reserved.