Privacy Notice
Effective Date: October 2023
Last Updated: August 13, 2026
Introduction and Scope
This Privacy Notice (“Notice”) describes how Taktile GmbH, Taktile LLC, Taktile Ltd, and Taktile SRL (collectively, “Taktile,” “we,” “us,” or “our”) collect, use, disclose, and protect Personal Data. In this Notice, “Personal Data” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an individual.
This Notice applies when you:
- Visit our website (taktile.com) or documentation sites
- Register for or attend events hosted or attended by Taktile
- Contact our sales, support, or other teams
- Do business with us as a customer, partner, or vendor
- Apply for employment or a contractor engagement with Taktile
- Otherwise interact or communicate with us
Please note that this Notice does not apply to Personal Data that our customers provide or otherwise make available to us for processing on their behalf, in our role as Service Provider and Data Processor, in connection with the delivery of our products and services to them (“Covered Personal Information”). Our processing of Covered Personal Information is governed by our customer Data Processing Agreement (“DPA”).
If you are a Taktile customer, you may access our Global Data Processing Addendum at [taktile.com/dpa].
If you are an end user of a Taktile customer and have questions about how your data is processed on our customer's behalf, please contact that organization directly and refer to their privacy notice.
Who We Are
Controllers
The Taktile entity responsible for your Personal Data depends on your location and the nature of your relationship with us:
| Your Location | Controller | Address |
|---|---|---|
| North America | Taktile LLC | 200 Vesey Street, Brookfield Place, New York, NY 10281, USA |
| Germany and all other locations not listed below | Taktile GmbH (HRB 216607 B, Charlottenburg) | Schönhauser Allee 9, 10119 Berlin, Germany |
| United Kingdom | Taktile Ltd (Companies House 16992965) | 30 Old Bailey, London, United Kingdom |
| Romania | Taktile SRL (J2025043162009) | Municipiul Iași, Str. PALAS, Nr. 7E, clădirea C2, United Business Center 3, birou nr. 1, Etaj 3, Județ Iași, Romania |
For all website-related processing (cookies, analytics, web forms), Taktile GmbH is the controller regardless of your location, in conjunction with Taktile LLC for visitors identified as North American residents.
Data Protection Officer
Carl Gottlieb, c/o Taktile LLC, 200 Vesey Street, Brookfield Place, New York, NY 10281, USA. Email: carl.gottlieb@taktile.com
Privacy Contact
For all privacy inquiries, rights requests, or complaints: privacy@taktile.com
California Notice at Collection
We collect the categories of personal information (as defined in the California Consumer Privacy Act, “CCPA”) listed in the table below. This notice is provided pursuant to California Civil Code § 1798.100.
| Category of Personal Information Collected | Sold or Shared |
|---|---|
| Identifiers, including names, email addresses, account names, IP addresses, and other similar identifiers. | Yes (advertising cookies) |
| Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)), including names, signatures, and telephone numbers. | No |
| Commercial information, including products or services purchased, obtained, or considered. | Yes (advertising cookies) |
| Internet or other electronic network activity information, including information regarding interactions with the Website. | Yes (advertising cookies) |
| Geolocation data, such as IP-derived location. | No |
| Audio, electronic, visual, or similar information, including call recordings. | No |
| Professional or employment-related information, including employer names and job roles/titles. | No |
| Sensitive personal information, including account log-in information in combination with passwords. | No |
We collect and use the above-listed categories of personal information to provide and manage the Services and achieve the business and commercial purposes described in this Notice. We retain each category of personal information for as long as necessary to fulfill those purposes, as detailed in Section 7.
We do not use or disclose sensitive personal information for any purpose outside of the limited permissible purposes set forth in the CCPA regulations.
As noted in the table above, we “share” (as defined in the CCPA) certain categories of personal information for cross-context behavioral advertising. You may exercise your right to opt out by clicking the “Do Not Sell or Share My Personal Information” link in our website footer, or by enabling Global Privacy Control (GPC) in your browser.
More information, including a description of your California legal rights, can be found in Section 11 (“California Privacy Rights”).
Personal Data We Collect
We may collect Personal Data about you from various sources, as described below.
Data Provided by You
- Contact data: Name, email address, postal address, phone number
- Business relationship data: Company name, industry, organization size, job title, department, function, and your organization's relationship history with Taktile
- Account data: Login credentials, account preferences
- Communications: Content of emails, form submissions, demo requests, support tickets, and chat messages
- Event data: Registration details, attendance records, dietary or accessibility preferences
- Payment data: Billing address, payment method details (processed by our payment service providers; we do not store full payment card numbers)
Where applicable, we may indicate whether and why you must provide us with your Personal Data as well as the consequences of failing to do so.
Data Collected by Automated Means
When you visit and interact with our website, we (and our service providers and partners) may use cookies and other similar technologies to collect certain data automatically:
- Computer or device information: IP address, browser type and version, operating system, device type, system language, screen resolution
- Usage information: Pages visited, date and time of access, referral URL, click patterns, session duration, data transferred
We also use third-party analytics and tracking tools to better understand who is using our website, how visitors interact with it, and how to improve its effectiveness. We may also use these tools to help us or our third-party partners serve interest-based advertisements. These tools may include cookies, pixel tags, or similar technologies. Our third-party partners and providers may combine data collected from your interactions with our website with data they collect from other sources.
Server log data is anonymized by IP address truncation after seven days and is not combined with other data sources.
To learn more about your interest-based advertising choices, please see Section 10 (“Your Choices”).
Data Collected from Other Sources
We may obtain Personal Data about you from third parties, including:
- Your employer, in connection with business dealings with Taktile
- Third parties you have directed to share data with us
- Business-oriented social networks and publicly available professional profiles (e.g., LinkedIn)
- Data enrichment, analytics, and visitor identification services
- Recruitment agencies, where applicable
Combination of Data
We may combine the Personal Data that we collect from and about you, including data you provide to us, data we automatically collect through the website, and data we receive from third-party sources, and use the combined data for the purposes described in this Notice.
Applicant and Employee Data
For detailed information about how we process personal data of job applicants, please see Appendix A: Applicant Privacy Policy below. A separate Employee Privacy Notice is provided to employees at the time of onboarding.
How We Use Personal Data
We use the Personal Data we collect for the following purposes:
- Providing the Services, including to operate, maintain, and support our website and business services, manage accounts, and process transactions
- Communicating with You, including to respond to inquiries, provide customer support, and send administrative communications (e.g., confirmations, invoices, technical notices, security alerts)
- Sending Marketing and Promotional Communications, including messages about promotions, events, products, or services that we think may interest you. You may opt out at any time (see Section 10)
- Engaging in Interest-Based Advertising, including to serve interest-based advertising on our website or on other online services
- Conducting Analytics and Improving Our Services, including to analyze usage trends and preferences, develop new features, and improve user experience
- Maintaining Security and Preventing Fraud, including to monitor and maintain the security of our systems, detect and prevent fraud, and investigate unauthorized or unlawful activity
- Satisfying Our Legal Obligations, including to comply with applicable law and respond to lawful requests from governmental authorities
- Supporting Our Business Operations, including to administer our business, manage personnel, and carry out business transactions (e.g., mergers, acquisitions)
- Recruitment, as described in Appendix A
We will also use your Personal Data as described to you at the point of data collection or with your consent.
Grounds for Processing Personal Data
Applicable law in certain jurisdictions requires us to set out the legal basis upon which we process your Personal Data. Where applicable, the legal bases are as follows:
- Consent. We may collect, use, and disclose your Personal Data on the basis of the consent that you provide. Where required by law, we will rely on your consent for direct marketing and to collect data from your device via cookies and similar technologies.
- Contractual Necessity. We may collect and use certain Personal Data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into a contract.
- Compliance with a Legal Obligation. We may use, disclose, and retain your Personal Data if necessary to comply with applicable law, including tax and accounting obligations, sanctions screening, and regulatory requirements.
- Legitimate Interests. We may collect and use your Personal Data to the extent necessary to carry out our legitimate interests (or those of a third party), provided that such interests do not outweigh your interests or fundamental rights and freedoms. Our legitimate interests include: managing our business relationships; providing customer support; developing and enhancing our services; detecting and preventing fraud; monitoring the security of our data, systems, and networks; and conducting analytics. Where we rely on legitimate interest, we have conducted a balancing test and determined that our interests do not override your rights and freedoms. You may request details of this assessment by contacting privacy@taktile.com.
How We Disclose Personal Data
Choice Regarding Disclosures
Before we disclose your Personal Data to a non-agent third party, or before we use it for a purpose that is materially different from the purpose(s) for which it was originally collected or subsequently authorized by you, we will offer you the opportunity to opt out of such disclosure or use.
For sensitive information (e.g., health data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, data concerning sex life), we will obtain your affirmative, express (opt-in) consent before disclosing it to a non-agent third party or using it for a purpose other than those for which it was originally collected or subsequently authorized.
Categories of Recipients
We may disclose Personal Data to the following categories of recipients:
Taktile Affiliates. We may disclose your Personal Data to Taktile LLC, Taktile GmbH, Taktile Ltd, and Taktile SRL for any of the purposes described in this Notice, subject to the transfer safeguards described in Section 9.
Service Providers. We engage third-party service providers, such as hosting, security, and analytics providers, to assist us in operating our business. Each provider processes data under our instructions and is bound by a data processing agreement.
Analytics and Advertising Partners. We disclose Personal Data to analytics and advertising partners, including social media networks, third-party advertising networks, and other parties that assist us in serving and optimizing our advertisements. These disclosures may constitute “sharing” under the CCPA (see Section 11).
Professional Advisors. Legal counsel, auditors, and insurance providers, as needed for the operation of our business.
Governmental and Public Authorities. Where required by law, regulation, court order, or legal process, or to protect the rights, safety, or property of Taktile, its employees, or third parties. Taktile may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Business Transaction Parties. In connection with a merger, acquisition, reorganization, or sale of assets, your Personal Data may be transferred to the acquiring entity, subject to continued protection under this Notice or a successor notice.
Other Parties. We will disclose your Personal Data to other parties as we believe necessary or appropriate to: (i) comply with applicable law; (ii) protect our operations and those of our affiliates; (iii) investigate and prevent fraud; (iv) protect our rights, privacy, safety, property, and those of others; or (v) pursue available remedies or limit damages.
De-Identified Data
We may de-identify, anonymize, or aggregate Personal Data and disclose such information to third parties for various purposes as permitted by law. Where we de-identify data, we will maintain and use the data in de-identified form and will not attempt to re-identify the data except as required or permitted by law.
Automated Decision-Making and AI
Taktile uses the following automated tools:
- Website analytics and visitor identification: We use analytics and visitor identification services to understand website traffic patterns and identify organizations visiting our website for sales purposes. These tools may use cookies, IP address matching, and device fingerprinting. You may opt out through our cookie consent tool or by enabling Global Privacy Control (GPC) in your browser.
- AI-assisted internal tools: Taktile employees may use AI-powered tools (such as AI coding assistants, AI writing tools, and AI research tools) in the course of their work. Where these tools process Personal Data, we maintain appropriate data processing agreements and usage policies.
- Recruitment screening: See Appendix A, Section A.7.
We do not make decisions with legal or similarly significant effects based solely on automated processing without human review. If this changes, we will update this Notice and provide appropriate notice, opt-out mechanisms, and the right to human intervention as required by applicable law.
International Data Transfers
Taktile operates in the United States, Germany, the United Kingdom, Romania, and Brazil. Depending on your country of residence, your Personal Data may be transferred to countries or regions with data protection and privacy laws that differ from those in your country of residence.
Transfers from the EEA
For transfers from the European Economic Area to countries without an EU adequacy decision, we rely on:
- EU-U.S. Data Privacy Framework (DPF). Taktile LLC participates in the EU-U.S. DPF. See Section 13 for details.
- Standard Contractual Clauses (SCCs). We use the European Commission's approved SCCs (June 2021 modules), supplemented by transfer impact assessments where required.
- Adequacy decisions. Romania is an EU/EEA member state; transfers between Taktile GmbH and Taktile SRL do not require additional safeguards. The European Commission has granted an adequacy decision for the United Kingdom; transfers between Taktile GmbH and Taktile Ltd are covered by this decision for so long as it remains in effect.
Transfers from the United Kingdom
For transfers from the United Kingdom:
- UK Extension to the EU-U.S. DPF. Taktile LLC participates in the UK Extension to the EU-U.S. DPF. See Section 13 for details.
- UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs. Where the DPF does not apply, we use the UK-approved IDTA or the UK Addendum to the EU SCCs.
- UK adequacy regulations. The UK has recognized EEA countries as adequate; transfers between Taktile Ltd and Taktile GmbH or Taktile SRL are covered by this recognition.
Transfers from Romania
Romania is an EU/EEA member state. Transfers from Taktile SRL to other Taktile entities within the EEA do not require additional safeguards. Transfers from Taktile SRL to Taktile LLC and Taktile Ltd are subject to the safeguards in Sections 9.1 and 9.2.
Transfers from Brazil
For Personal Data of Brazilian contractors and candidates, Taktile relies on:
- Standard Contractual Clauses approved by the ANPD (Resolution CD/ANPD No. 19/2024).
- ANPD-EU mutual adequacy recognition (Resolution No. 32/2026) for transfers between Brazil and the EEA.
- Consent, where other mechanisms are not available, with clear information about the risks of the transfer.
Transfers from Switzerland
For transfers from Switzerland, Taktile LLC participates in the Swiss-U.S. Data Privacy Framework. See Section 13 for details. Where the Swiss-U.S. DPF does not apply, we use SCCs recognized by the Swiss Federal Data Protection and Information Commissioner (FDPIC).
Service Provider Transfers
We ensure that our service providers who process Personal Data outside the EEA, UK, Switzerland, or Brazil maintain appropriate transfer mechanisms (DPF certification, SCCs, or adequacy decisions) and data processing agreements. You may request details of the specific safeguards by contacting privacy@taktile.com.
Your Choices
We provide you with the ability to exercise control over our use of your Personal Data.
Marketing and Promotional Communications. You can opt out of receiving marketing and promotional communications from us at any time by following the unsubscribe instructions included in any marketing communication or by contacting privacy@taktile.com. Opting out does not affect transactional or service-related communications.
Interest-Based Advertising. You may opt out of receiving interest-based advertising using the browser opt-out tools and consumer choice mechanisms provided by:
- Digital Advertising Alliance (DAA): http://www.aboutads.info/choices
- European Interactive Digital Advertising Alliance (EDAA): https://youronlinechoices.eu/
- Network Advertising Initiative (NAI): http://www.networkadvertising.org/choices/
You will need to opt out separately on all of your browsers and devices. If you delete or reset cookies, change browsers, or use a different device, any opt-out cookie may no longer work, and you will need to opt out again.
Cookie Preferences. You may adjust your cookie preferences at any time by clicking “Cookie Settings” in the website footer. You may also adjust your browser settings to limit tracking or decline cookies. Please refer to your browser's help section for instructions. To learn more about cookies, including how to manage them, please visit https://allaboutcookies.org/.
Global Privacy Control (GPC). We honor GPC and other legally recognized universal opt-out preference signals. When we detect a GPC signal, we treat it as a valid request to opt out of the sale or sharing of Personal Data and of targeted advertising.
“Do Not Sell or Share My Personal Information.” Available in the website footer for all visitors.
Your Legal Rights
Rights Under GDPR and UK GDPR (EEA, UK, and Romanian Residents)
You have the right to:
- Access your Personal Data and obtain a copy (Art. 15)
- Correct inaccurate or incomplete Personal Data (Art. 16)
- Delete your Personal Data (Art. 17), subject to legal exceptions
- Restrict processing of your Personal Data (Art. 18)
- Data portability: Receive your data in a structured, machine-readable format (Art. 20)
- Object to processing based on legitimate interest or for direct marketing purposes (Art. 21)
- Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing (Art. 7(3))
- Not be subject to solely automated decisions with legal or similarly significant effects (Art. 22)
- Lodge a complaint with a supervisory authority:
- Germany: Your relevant state data protection authority (Landesdatenschutzbeauftragte)
- United Kingdom: Information Commissioner's Office (ico.org.uk)
- Romania: National Supervisory Authority for Personal Data Processing (dataprotection.ro)
Rights Under US State Privacy Laws (Excluding California)
This section applies to residents of US states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. For California-specific rights, see Section 11.3.
Your rights under applicable state laws may include:
- Right to know / access: Request information about the categories and specific pieces of Personal Data we collect, the sources, purposes, and third parties with whom we share it
- Right to delete: Request deletion of your Personal Data, subject to legal exceptions
- Right to correct: Request correction of inaccurate Personal Data
- Right to portability: Receive your data in a portable format
- Right to opt out of: Sale of Personal Data; targeted advertising; profiling in furtherance of decisions that produce legal or similarly significant effects
- Right to obtain a list of specific third parties to whom Personal Data has been disclosed (Connecticut, Oregon, Minnesota)
- Right to appeal: If we deny your request, you may appeal by contacting privacy@taktile.com
- Right to non-discrimination / non-retaliation: We will not discriminate against you for exercising your rights
California Privacy Rights
The California Consumer Privacy Act (CCPA) provides California residents with certain rights in relation to their “personal information” (as defined in the CCPA).
Personal Information Collection, Disclosure, Sale, and Sharing
The following table details the categories of personal information we have collected from and about California residents in the past twelve (12) months, the source(s) of each category, the categories of third parties to whom we have disclosed each category for a business purpose, and the categories of third parties to whom we have “sold” or with whom we have “shared” each category (as such terms are defined in the CCPA).
| Category of Personal Information | Categories of Sources | Disclosed for a Business Purpose To | Sold or Shared To |
|---|---|---|---|
| Identifiers (names, email addresses, account names, IP addresses) | Directly from individuals; through automated means; third-party sources | Affiliates; service providers | Advertising and analytics partners (via cookies) |
| California Customer Records statute categories (names, signatures, telephone numbers) | Directly from individuals | Affiliates; service providers | Not sold or shared |
| Commercial information (products/services purchased or considered) | Directly from individuals; through automated means | Affiliates; service providers | Advertising and analytics partners (via cookies) |
| Internet or electronic network activity (browsing history, interactions with website) | Through automated means | Affiliates; service providers | Advertising and analytics partners (via cookies) |
| Geolocation data (IP-derived location) | Through automated means | Affiliates; service providers | Not sold or shared |
| Audio, electronic, visual information (call recordings) | Directly from individuals | Affiliates; service providers | Not sold or shared |
| Professional or employment-related information (employer, job title) | Directly from individuals; third-party sources | Affiliates; service providers | Not sold or shared |
| Sensitive personal information (account credentials) | Directly from individuals | Service providers | Not sold or shared |
Purposes for Collection. We collect personal information to provide and manage our services and achieve the business and commercial purposes described in this Notice.
Sale and Sharing. We “share” (as defined in the CCPA) certain categories of personal information with advertising and analytics partners through cookies and similar tracking technologies for cross-context behavioral advertising. We do not “sell” personal information for monetary consideration. We do not sell or share the personal information of minors we know to be under the age of 16.
Use and Disclosure of Sensitive Personal Information. We do not use or disclose sensitive personal information for any purpose outside of the limited permissible purposes set forth in the CCPA regulations. These purposes include providing our services, preventing security incidents, and verifying account access.
Your California Rights. You have the right to request that we:
- Disclose to you the following information covering the twelve (12) months preceding your request:
- The categories of personal information we have collected about you and the categories of sources from which we collected such information
- The specific pieces of personal information we have collected about you
- The business or commercial purposes for collecting, selling, or sharing your personal information
- The categories of third parties to whom we disclosed such personal information
- If we sold, shared, or disclosed your personal information for a business purpose, two separate lists disclosing: (a) sales and shares, identifying the personal information categories that each category of recipient received; and (b) disclosures for a business purpose, identifying the personal information categories that each category of recipient obtained
- Delete the personal information that we have collected from you, subject to certain exceptions
- Correct inaccurate personal information that we maintain about you
We will not discriminate against you if you decide to exercise your rights under the CCPA.
Exercising Your Rights. You can submit a request by emailing privacy@taktile.com or writing to us at Taktile, 200 Vesey Street, Brookfield Place, New York, NY 10281, USA. To protect your privacy, we will verify your identity by matching up to three pieces of personal information you provide with information we maintain. Where applicable, we will use the requested information for verification purposes only. We may decline a request where we are unable to verify your identity and confirm the personal information we maintain relates to you.
Authorized Agent. You may authorize someone to submit a privacy rights request on your behalf. An authorized agent will need to demonstrate that you have authorized them to act on your behalf, unless the agent has been granted power of attorney under applicable probate law. We may also contact you to verify your identity or confirm the agent's authority.
Exercising Your Sale and Sharing Opt-Out Right. To opt out of the “sharing” of your personal information, click the “Do Not Sell or Share My Personal Information” link in the website footer. You may also opt out via cookies by clicking “Cookie Settings” in the website footer. If you enable a browser-based opt-out preference signal that complies with the CCPA, such as Global Privacy Control (GPC), we will treat the signal as a valid request to opt out of the sale or sharing of personal information linked to that browser and any consumer profile we have associated with that browser.
Rights Under Brazil's LGPD
If you are located in Brazil (including contractors engaged by Taktile), you have the right under the Lei Geral de Proteção de Dados (LGPD) to:
- Confirm the existence of processing of your data
- Access your data
- Correct incomplete, inaccurate, or outdated data
- Anonymize, block, or delete unnecessary or excessive data
- Request portability of your data to another service provider
- Request deletion of data processed with your consent
- Obtain information about public and private entities with which your data has been shared
- Obtain information about the possibility of denying consent and the consequences of doing so
- Revoke consent
- Request review of automated decisions
You may file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.
Exercising Your Rights
To exercise any of the rights described above, contact us at:
- Email: privacy@taktile.com
- Mail: Taktile, 200 Vesey Street, Brookfield Place, New York, NY 10281, USA
We will respond within 30 days (GDPR/UK GDPR), 45 days (US state laws), or 15 days (LGPD), with extensions as permitted by applicable law.
Identity Verification. To protect your privacy, we will require verification of your identity before processing a rights request. We may request specific information from you to help confirm your identity. Where applicable, we will use the requested information for verification purposes only. We may decline a request where we are unable to verify that you are the individual whose data is the subject of the request.
Authorized Agents. You may designate an authorized agent to submit a privacy rights request on your behalf. An authorized agent will need to demonstrate that you have authorized them to act on your behalf, unless the agent has been granted power of attorney under applicable law. We may also contact you to verify your identity or confirm the agent's authority.
Data Retention
We take measures to delete, de-identify, or anonymize your Personal Data when it is no longer necessary for the purposes for which we process it, unless we are required by law to keep it for a longer period. When determining the retention period, we take into account the type of services provided to you, the nature and length of our relationship, mandatory retention periods, and applicable statutes of limitations.
| Data Category | Retention Period |
|---|---|
| Website server logs | 7 days before IP anonymization; anonymized data retained for statistical purposes |
| Cookie consent records | Duration of cookie lifespan or until consent is withdrawn |
| Demo request / contact form data | Deleted after purpose is fulfilled, unless a contract is entered |
| Marketing contacts | Until opt-out, plus 30 days for processing |
| Customer / contractual data | Duration of the contract plus applicable statutory retention periods (typically 6 to 10 years under commercial and tax law) |
| Applicant data | See Appendix A, Section A.6 |
| Employee data | Duration of employment plus applicable statutory retention periods (varies by jurisdiction and data type) |
| Financial / billing records | As required by applicable tax and commercial law (typically 6 to 10 years) |
After the applicable retention period, data is securely deleted or anonymized. If we de-identify data, we will maintain and use the data in de-identified form and not attempt to re-identify the data except as required or permitted by law.
Data Privacy Framework
Taktile LLC complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.
Taktile LLC has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Taktile LLC has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF.
If there is any conflict between the terms in this Notice and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern.
To learn more about the Data Privacy Framework program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
Independent Recourse Mechanism. In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Taktile LLC commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU, UK, and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, or the Swiss-U.S. DPF should first contact Taktile at: privacy@taktile.com.
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Taktile LLC commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF to JAMS, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your complaint to your satisfaction, please visit https://www.jamsadr.com/DPF-Dispute-Resolution for more information or to file a complaint. The services of JAMS are provided at no cost to you.
Binding Arbitration. Individuals have the possibility, under certain conditions, to invoke binding arbitration for complaints regarding DPF compliance not resolved by any of the other DPF mechanisms. For additional information, see Annex I of the DPF Principles.
Onward Transfer Liability. Taktile LLC has responsibility for the processing of personal information it receives under the DPF Principles and subsequently transfers to a third party acting as an agent on its behalf. Taktile LLC shall remain liable under the DPF Principles if its agent processes such personal information in a manner inconsistent with the DPF Principles, unless Taktile LLC proves that it is not responsible for the event giving rise to the damage.
Enforcement. The Federal Trade Commission has jurisdiction over Taktile LLC's compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).
Government Access. Taktile LLC may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Data Security
We use physical, managerial, and technical safeguards designed to improve the integrity and security of Personal Data that we collect, maintain, and process, including:
- Encryption in transit (TLS/SSL) and at rest
- SOC 2 Type II and ISO 27001 certified infrastructure
- Role-based access controls and single sign-on (SSO) enforcement
- Regular security assessments and penetration testing
- Employee security awareness training
- Incident response procedures
No method of electronic transmission or storage is completely secure. If you have reason to believe your interaction with us is no longer secure, please contact privacy@taktile.com immediately.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- EU/UK/Romania: Notify the competent supervisory authority within 72 hours of becoming aware of the breach (GDPR Art. 33). Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay (GDPR Art. 34), unless an exception applies.
- United States: Notify affected individuals and relevant state authorities in accordance with applicable state data breach notification laws.
- Brazil: Notify the ANPD and affected data subjects within a reasonable timeframe as required by LGPD Art. 48.
- Switzerland: Notify the FDPIC as soon as possible in accordance with the revised Federal Act on Data Protection (revFADP).
Breach notifications will include the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken or proposed to address the breach.
Cookies and Tracking Technologies
We use cookies and similar technologies on our website. For detailed information about the cookies we use, their purposes, categories, lifespans, and your choices, please see our Cookie Policy.
Key points:
- EU/UK/Swiss visitors: Non-essential cookies are blocked until you provide affirmative consent through our cookie consent banner.
- US visitors: Our cookie consent tool allows you to opt out of analytics and marketing cookies. We honor GPC signals as a valid opt-out of the sale or sharing of your Personal Data.
- “Do Not Sell or Share My Personal Information”: Available in the website footer for all visitors.
- Cookie lifespan: No non-essential cookie on taktile.com exceeds 12 months. We review cookie lifespans quarterly.
Third-Party Services
Our website and communications may contain features or links to websites and services operated by third parties, including social media widgets and plugins. Any Personal Data you provide to the owner or operator of a third-party service is subject to that third party's privacy notice, even if accessed through our website. We are not responsible for the privacy practices of third parties. We encourage you to review the privacy notices of any third-party service before providing your Personal Data.
Children's Privacy
Our services are not intended for or directed to children under the age of 16, and we do not knowingly collect Personal Data from children under the age of 16. Taktile does not have actual knowledge that it sells or shares Personal Data of consumers under 16 years of age. If we become aware that we have collected Personal Data from a child under 16, we will take steps to delete it.
Changes to This Notice
We may update this Notice from time to time to reflect changes in our privacy practices. The “Last Updated” date at the top indicates when this Notice was last revised. If we make material changes to how we process Personal Data, we will notify you through our website, by email, or other appropriate means before the changes take effect. We will follow applicable laws and regulations regarding notification of changes to this Notice.
Contact Us
Taktile LLC is the entity responsible for the processing of your Personal Data in North America. Taktile GmbH is the entity responsible for the processing of your Personal Data in Germany and all other locations except the UK and Romania, where Taktile Ltd and Taktile SRL are responsible, respectively.
If you have any questions or comments about this Notice or our privacy practices, please contact us:
Email: privacy@taktile.com Phone: +49 89 250039222 Mail: Taktile, 200 Vesey Street, Brookfield Place, New York, NY 10281, USA
Data Protection Officer: Carl Gottlieb, c/o Taktile LLC, 200 Vesey Street, Brookfield Place, New York, NY 10281, USA. Email: carl.gottlieb@taktile.com.
APPENDIX A: APPLICANT PRIVACY POLICY
Last Updated: August 13, 2026
This Appendix explains how Taktile collects, uses, stores, and shares your Personal Data when you apply for a role with us. It applies to all candidates who apply through our careers page, job boards, recruitment platforms, or any other channel.
Who We Are
Taktile's recruitment process is managed by Taktile LLC (US) and Taktile GmbH (Germany), which are the joint controllers of your Personal Data during the application process. Depending on the role, your local employing entity may be one of the following:
| Role Location | Employing Entity |
|---|---|
| United States | Taktile LLC, 200 Vesey Street, Brookfield Place, New York, NY 10281, USA |
| Germany | Taktile GmbH, HRB 216607 B, Charlottenburg, Berlin, Germany |
| United Kingdom | Taktile Ltd, 30 Old Bailey, London, United Kingdom |
| Romania | Taktile SRL, Municipiul Iași, Str. PALAS, Nr. 7E, clădirea C2, United Business Center 3, birou nr. 1, Etaj 3, Județ Iași, Romania |
Taktile LLC and Taktile GmbH jointly determine the purposes and means of processing your applicant data. Your employing entity (if different) receives your data as needed to manage the local hiring and onboarding process.
What Personal Data We Collect
We collect the following categories of Personal Data during the recruitment process:
- Identity and contact information: Name, email address, phone number, postal address
- Professional information: Resume/CV, cover letter, work history, job titles, employer names, professional licenses and certifications
- Education information: Degrees, institutions, dates of attendance, academic achievements
- Application materials: Responses to screening questions, writing samples, portfolio materials, assessment or test results
- Interview information: Notes and evaluations from interviews, interview recordings (only with your separate consent, see Section A.4), reference check results
- Publicly available information: Professional profiles (e.g., LinkedIn, GitHub), published work
- Right-to-work information: Citizenship or immigration status, work authorization documents (collected at the offer stage or as required by law)
- Background check information: Criminal records, identity verification, employment history verification (US candidates only, through Checkr, subject to FCRA authorization, see Section A.3)
- Diversity information (voluntary): Gender, ethnicity, veteran status, or disability status where you voluntarily provide it for equal opportunity monitoring (see Section A.4)
- Technical information: IP address, browser type, and device information collected automatically when you visit our careers page
We collect Personal Data directly from you, from publicly available sources, from recruitment agencies (if applicable), and from individuals you identify as references.
How and Why We Process Your Data
Processing That Does Not Require Your Consent
These activities are necessary to evaluate your application or are justified by our legitimate interests or legal obligations. You do not need to consent, and your application will not be affected.
| Purpose | Legal Basis (EU/UK) | Legal Basis (US) |
|---|---|---|
| Evaluating your candidacy for the role you applied to | Pre-contractual steps at your request (Art. 6(1)(b)) | Business purpose |
| Communicating with you about the recruitment process | Pre-contractual steps at your request (Art. 6(1)(b)) | Business purpose |
| Conducting reference checks | Legitimate interest (Art. 6(1)(f)) | Business purpose |
| Verifying your right to work | Legal obligation (Art. 6(1)(c)) | Legal obligation |
| Sanctions screening | Legal obligation (Art. 6(1)(c)) | Legal obligation (OFAC) |
| Improving our recruitment process (aggregated/anonymized data) | Legitimate interest (Art. 6(1)(f)) | Business purpose |
| Establishing, exercising, or defending legal claims | Legitimate interest (Art. 6(1)(f)) | Business purpose |
| Retaining data for the default post-rejection period (see Section A.6) | Legitimate interest (Art. 6(1)(f)) | Business purpose |
| Technical assessments (e.g., HackerRank) | Pre-contractual steps (Art. 6(1)(b)) | Business purpose |
Where we rely on legitimate interest, we have assessed that our interests do not override your rights and freedoms. You may request details of this assessment by contacting us.
Processing That Requires Your Separate Consent
For the following activities, we request your consent separately from your application. You are under no obligation to consent, and declining will not affect your candidacy or any future application.
| Purpose | Legal Basis (EU/UK) | How We Obtain Consent |
|---|---|---|
| Recording a video interview | Consent (Art. 6(1)(a)) | Verbal or written request before the interview begins. You may decline; the interview proceeds without recording. US two-party consent states (California, Illinois, Connecticut, Florida, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania, Washington) also require consent under state recording laws. |
| AI-powered analysis of interview recordings (if applicable) | Consent (Art. 6(1)(a)), plus Art. 22 compliance | Written notice and consent before any AI analysis. No AI-analyzed interview is the sole basis for a hiring decision. [Include only if Taktile uses AI interview analysis tools.] |
| Voluntary EEO / diversity data | Explicit consent (Art. 9(2)(a)) for EU/UK; voluntary under US EEO law | Separate, clearly optional section of the application form. Stored separately; not accessible to hiring managers. |
| Talent pool: retention for future opportunities after rejection | Consent (Art. 6(1)(a)) | Separate request sent after the recruitment decision. Accept or decline via a link. |
| Sharing your profile with other Taktile entities for roles in other locations | Consent (Art. 6(1)(a)) | Combined with the talent pool request at rejection, or requested separately. |
| Receiving Taktile marketing communications | Consent (Art. 6(1)(a)) | Separate opt-in, never bundled with the application. |
California applicants: Under the CCPA/CPRA, the purposes above constitute “business purposes.” We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
Background Checks (US Candidates)
Taktile uses Checkr to conduct background checks for US-based candidates. Before obtaining any consumer report, we will provide a standalone written disclosure (as required by the Fair Credit Reporting Act) and obtain your written authorization on a standalone form. If we consider taking adverse action based on the results, we will provide pre-adverse action notice, a copy of the report, and a Summary of Your Rights before making a final decision.
For EU/UK-based candidates, background checks are conducted only where relevant to the role and based on legitimate interest (Art. 6(1)(f)), limited to information proportionate to the position.
When and How We Request Consent
To ensure that consent is freely given, specific, informed, and unambiguous as required by GDPR Article 7, we separate consent from the application process:
| Timing | What We Ask | How |
|---|---|---|
| At application | Acknowledgment that you have read this Applicant Privacy Policy | Informational notice on the application page. Not consent; transparency only. |
| At application (US roles, optional) | Voluntary EEO/diversity data | Clearly labeled optional section. May be skipped. |
| Before a video interview | Consent to record | Verbal or written request before the interview. |
| Before AI analysis (if applicable) | Consent to AI-powered analysis | Written notice before the interview with explanation of what the tool does. |
| Before a background check (US roles) | FCRA written authorization | Standalone form at the offer stage. |
| After rejection | Talent pool opt-in; cross-entity sharing opt-in | Separate email with accept/decline options. |
Withdrawing consent. You may withdraw any consent at any time by emailing privacy@taktile.com. Withdrawal does not affect the lawfulness of processing performed before withdrawal. If you withdraw talent pool consent, your data will be deleted within 30 days (or at the end of the default retention period for your jurisdiction, whichever is sooner).
Who We Share Your Data With
- Within Taktile: Hiring managers, interviewers, and People team members involved in the hiring decision. EEO/diversity data is not shared with hiring managers or interviewers.
- Other Taktile entities: Where the role involves cross-entity collaboration, or where you have consented to be considered for roles at other offices.
- Service providers: Ashby (ATS), Checkr (background checks, US), HackerRank (technical assessments), Google Workspace (email and collaboration), LinkedIn (recruiting and sourcing). Each bound by data processing agreements.
- Professional advisors: Legal counsel or auditors, as needed.
- Legal requirements: Where required by law, regulation, or legal process.
Notice to referees: When you provide the names of references, we will inform each referee of our identity, the purpose of processing, and how they can exercise their rights under applicable law (GDPR Art. 14).
We do not sell your Personal Data to third parties.
How Long We Keep Your Data
Default Retention Periods (No Consent Required)
| Jurisdiction | Default Retention Period | Legal Basis |
|---|---|---|
| Germany | 6 months after the recruitment process concludes | AGG § 15(4) + ArbGG § 61b(1) limitation periods |
| United Kingdom | 12 months after the recruitment process concludes | Equality Act 2010 limitation periods; ICO guidance |
| Romania | 12 months after the recruitment process concludes | Documented legitimate interest; ANSPDCP guidance |
| United States (California) | 4 years after the recruitment process concludes | [CRD statute of limitations; pending HR confirmation] |
| United States (general) | 12 months after the recruitment process concludes | EEOC record retention guidance |
| Brazil | 12 months after the recruitment process concludes | LGPD purpose limitation; labor claims statute of limitations |
| Netherlands (if recruiting in NL) | 4 weeks after the recruitment process concludes | Autoriteit Persoonsgegevens guidance |
Consent-Based Extended Retention (Talent Pool)
| Jurisdiction | Maximum Talent Pool Retention | Renewal |
|---|---|---|
| Germany | 24 months from the date of consent | Consent renewal request at 12 months |
| United Kingdom | 24 months from the date of consent | No mandatory renewal |
| Romania | 24 months from the date of consent | No mandatory renewal |
| United States | 24 months from the date of consent | No mandatory renewal |
| Brazil | 24 months from the date of consent | No mandatory renewal |
| Netherlands (if recruiting in NL) | 12 months from the date of consent | Maximum under AP guidance |
Other Retention Scenarios
| Scenario | Retention Period |
|---|---|
| Successful application | Data becomes part of employment records per Employee Privacy Notice |
| Legal claims | Retained as necessary to establish, exercise, or defend legal claims |
| Video interview recordings | Deleted within 30 days of the recruitment decision, unless you consent to talent pool retention |
| Background check results | Retained for the default retention period, then deleted |
After the applicable retention period, data is securely deleted or anonymized.
Automated Decision-Making
We use automated tools to assist in screening and organizing applications. These tools may sort, rank, or filter applications based on criteria defined by our hiring team.
No hiring decision is made solely by automated means. A human reviewer is involved in every decision that affects your candidacy.
If we use any AI-powered tool that evaluates, scores, or ranks candidates, we will:
- Inform you before the tool is used
- Obtain your consent where required by applicable law
- Ensure the output is reviewed by a human before any decision is made
- Provide you with the right to contest the decision, express your point of view, and obtain human intervention (Art. 22(3) GDPR)
Jurisdiction-specific protections:
- EU/UK: GDPR Art. 22 prohibits solely automated decisions with legal or significant effects. Taktile does not make such decisions.
- California: CCPA/CPRA ADMT regulations require notice and opt-out rights for automated decision-making in employment.
- New York City: Local Law 144 requires a bias audit and notice at least 10 business days before using an automated employment decision tool.
- Colorado: The Colorado AI Act (effective February 1, 2026) requires disclosure and impact assessments for high-risk AI employment decisions.
- Illinois: The AI Video Interview Act requires consent and disclosure before using AI to analyze video interviews.
Your Rights
EU, UK, and Romanian applicants: You have all rights described in Section 11.1 of the main Privacy Notice. You may lodge a complaint with:
- Germany: Your relevant state data protection authority
- United Kingdom: Information Commissioner's Office (ico.org.uk)
- Romania: National Supervisory Authority for Personal Data Processing (dataprotection.ro)
US applicants: You have all rights described in Sections 11.2 and 11.3 of the main Privacy Notice.
Brazilian applicants and contractor candidates: You have all rights described in Section 11.4 of the main Privacy Notice.
We will respond to verifiable requests within 30 days (GDPR/UK GDPR), 45 days (CCPA), or 15 days (LGPD).
International Data Transfers
Your Personal Data may be transferred to and processed in the United States, Germany, the United Kingdom, or Romania. We rely on the transfer mechanisms described in Sections 9 and 13 of the main Privacy Notice.
Salary History
Taktile does not request or consider salary history during the recruitment process, in compliance with applicable state and local salary history bans.
Contact Us
To exercise any of your rights, withdraw consent, or ask questions:
- Email: privacy@taktile.com
- Mail: Taktile, 200 Vesey Street, Brookfield Place, New York, NY 10281, USA
Discover Taktile