Privacy for a housing communication platform

Sicket is designed with GDPR principles in mind and includes controls that can support customer privacy obligations. This page summarizes how we handle personal data on the marketing site and in the Sicket product.

Last updated:

Roles and scope

For the public marketing website at sicket.app, Sicket acts as controller for the small amount of personal data submitted through contact forms, cookies, and privacy-friendly analytics where consent applies.

For customer data processed inside the Sicket product, Sicket generally acts as processor on behalf of the housing organization using the platform, while each customer remains responsible for its own resident communication and legal basis.

What data we process

  • Contact form details such as name, work email, organization name, number of buildings, and the message you send us.
  • Career application information submitted through Tally, including contact details, form answers, and any CV or portfolio files you choose to upload.
  • Basic website analytics and cookie preferences where you have consented to them.
  • Inside the product, account details, organization and building memberships, tickets, comments, announcements, news posts, invitations, and account or session activity.
  • Anonymous tickets are masked from other tenants in the product, but they are not anonymous to Sicket staff, platform administrators, or internal systems required to operate the service.

Job applications

Sicket uses Tally to collect open applications and uploaded CVs. We use this information to review potential fit for current or future roles. Submitting an application does not create an automated hiring decision.

Only include information relevant to your application and avoid unnecessary sensitive or special-category personal data. We retain applications only as long as reasonably needed for review, relevant future opportunities, legal obligations, or dispute handling. Contact hello@sicket.app to request deletion.

Optional website and onboarding analytics

With consent, Sicket uses PostHog on the public website and the self-serve onboarding and checkout flow. We measure events such as page or onboarding-step views, selected plan and currency, checkout redirects, checkout outcomes, whether setup was completed, referring domains, and high-level campaign details such as source, medium, campaign, and placement codes. We do not store the referring page or a full browsing URL in our custom events.

Our custom analytics events do not include names, email addresses, phone numbers, postal addresses, passwords, tax identifiers, payment-card data, organization or building names, free-text form entries, verification tokens, or onboarding and Stripe session identifiers. Stripe processes payment details on its own checkout pages.

Sicket does not use PostHog session replay, automatic click or form capture, exception autocapture, or identified person profiles in these flows. You can reject analytics or change your choice later through Cookie preferences.

AI-assisted features

Some Sicket features use AI assistance, including ticket priority and category assessment, similar-ticket retrieval, draft reply support, self-service answer support, and recurring pattern detection.

For those features, Sicket may send a minimized subset of ticket content and metadata to the OpenAI API as a processor for Sicket. The consumer ChatGPT product is not used for production ticket processing.

OpenAI states that API data is not used to train OpenAI models by default unless data sharing is explicitly enabled. Depending on the API controls available for the project, limited abuse-monitoring logs may still be retained for a short period.

How we reduce risk

  • We restrict production data access to authorized personnel only.
  • We minimize the fields sent to AI services wherever the feature allows it.
  • We preserve operational records only as long as needed for the service, legal obligations, audit, and dispute handling.
  • We support masking, redaction, lifecycle controls, and GDPR erasure workflows inside the product.

Retention, responsibilities, and privacy rights

Do not include unnecessary sensitive information in tickets or announcements. Where possible, describe the situation without health data or other special-category personal data.

Sicket includes privacy rights workflows, configurable retention settings, and auditability features inside the product. Customers can contact us regarding access, correction, restriction, deletion, export, or objection requests at support@sicket.app.

We aim to keep data only as long as it is needed for contractual, legal, support, or security purposes.

Email communications and consent

Sicket explains its product-email categories, consent approach, and in-app preference controls on the Email communications page. That includes operational announcement categories, news and newsletter preferences, and the separate opt-in for Sicket product updates.