Dancetu legal
Privacy Policy
This notice explains when QikBuild acts as controller of personal data and when it processes studio-managed data only on a studio’s instructions.
- Effective:
- 15 September 2026
- Version:
- 2026-09-15-v1.0
1. Who we are
The controller for Dancetu account, billing, website, security, and direct-support data is QikBuild, s. r. o., Bottova 2A, 811 09 Bratislava – Staré Mesto, Slovak Republic, Company No. 55 100 015, Tax No. 2121862996, VAT No. SK2121862996.
Privacy requests may be sent to privacy@dancetu.com or through our contact form. QikBuild has not designated a data protection officer. Service and billing questions belong at support@dancetu.com.
2. Our two data-protection roles
QikBuild as controller. We decide why and how to process information needed to create and secure accounts, contract with studio customers, administer subscriptions, issue invoices, provide support, prevent abuse, operate the public website, and comply with law.
QikBuild as processor. A studio decides why and how it uses student, guest, instructor, booking, attendance, emergency-contact, pass, course, and similar operational data. The studio is the controller; QikBuild processes that data to provide Dancetu under the Data Processing Addendum. Questions about a studio’s use of that data should normally go to the studio first.
3. Data we process as controller
- Identity and account: name, email, user ID, authentication status, language, roles, and studio membership.
- Customer and contract: company/studio name, owner authority, plan, limits, trial, renewal, cancellation, and versions of legal terms accepted.
- Billing: Stripe customer and subscription identifiers, billing address, business tax ID, invoice/payment status, cadence, and limited payment metadata. Full card numbers and security codes go directly to Stripe and are not stored by Dancetu.
- Communications: contact requests, support correspondence, billing notices, delivery status, and preferences.
- Security and device: IP address or a salted hash where appropriate, user agent, session and security events, requested URLs, timestamps, webhook and operational error metadata.
- Website preferences: locale, active-studio selection, portal-studio selection, and sidebar state.
We receive data from you, your organization’s owner or administrator, normal use of Dancetu, Stripe and our other service providers, and—where you join a studio—from that studio.
4. Studio-controlled data processed for customers
Depending on studio configuration, Dancetu may hold student and guest names, emails, telephone numbers, dates of birth, gender fields, partner-role preferences, emergency-contact details, attendance, bookings, cancellations, passes, courses, instructor profiles and availability, internal notes, consent records, and communication history. A studio must collect only what it needs, choose a lawful basis, give its own privacy information, and respect data-subject rights.
Dancetu is not intended for medical records, government identifiers, full payment-card data, or other data not needed for the documented studio workflows. Studios should exercise particular care with minors and emergency contacts.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Create accounts, provide trials and subscriptions, deliver contracted features, manage plan changes and support | Contract and steps requested before contract |
| Invoices, VAT, accounting, regulatory responses, and legally required records | Legal obligation |
| Security, authentication, abuse prevention, service reliability, diagnostics, defense of claims, and limited operational communication | Legitimate interests in operating and protecting Dancetu and its users |
| Optional marketing or future non-essential analytics/cookies | Consent, where required; it can be withdrawn without affecting prior lawful processing |
| Studio operational data | The studio’s documented instructions under the DPA; the studio determines its own lawful basis |
Where we rely on legitimate interests, we balance those interests against the individual’s rights and use the data only where the impact is proportionate.
6. Required and optional information
An owner must provide an account email, authentication information, studio/company name, selected plan, and information Stripe requires for billing. Without it, we cannot create or administer the contract. Optional profile, marketing, telephone, biography, notes, and similar fields are identified in the interface and can be omitted unless the studio independently requires them for a lawful purpose.
7. Recipients and subprocessors
Authorized QikBuild personnel and authorized users of the relevant studio receive data only as needed for their roles. We use contracted infrastructure and service providers for hosting, database/authentication/storage, billing, email, DNS/security, and company communications. The current list, locations, purposes, and transfer safeguards is at Subprocessors.
We may disclose information to professional advisers, auditors, insurers, authorities, or courts where necessary to comply with law, establish or defend claims, or protect rights and safety. We do not sell personal data.
8. International transfers
Production application data is configured for an EU database region, but some providers and support operations may process data outside the EEA. Where an adequacy decision does not apply, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and supplementary measures. Studios can request relevant transfer information from privacy@dancetu.com.
9. Retention
- Active service data: for the contract. After termination, export remains available or requestable for 30 days and active customer content is deleted or anonymized within 90 days.
- Backups: removed through the documented rolling backup lifecycle; retained copies are isolated from ordinary use and deleted on expiry unless a legal hold applies.
- Billing, tax, and accounting records: generally ten years following the relevant accounting period where Slovak law requires it.
- Security and operational logs: normally 90 days, longer only for an active investigation, incident, or legal claim.
- Support and contact requests: for the request and normally up to 24 months afterward; longer where needed for an unresolved dispute or legal duty.
- Legacy launch waitlist: until the approved launch communication or no later than 90 days after production cutover, unless the person becomes a customer or another documented basis applies.
- Consent and contract acceptance: for the contract and applicable limitation period so acceptance can be demonstrated.
A studio may set shorter operational retention where Dancetu supports it. Legal holds override deletion only for the data and period genuinely required.
10. Security
Measures include access controls and role-based permissions, encrypted network transport, managed encryption at rest, environment-separated secrets, signature-verified Stripe webhooks, logging without card data or secrets, backups, dependency and access review, and incident handling. Studios remain responsible for user access, secure devices, strong passwords, accurate role assignment, and lawful exports.
No security measure eliminates all risk. Please report suspected incidents promptly to privacy@dancetu.com.
11. Cookies and similar storage
Dancetu currently uses only storage needed to provide the requested service or remember interface choices:
- Supabase authentication cookies for secure login and session refresh, for the session/token lifetime.
dancetu_localefor language preference, up to 180 days.dancetu_active_studioanddancetu_portal_studioto remember the selected studio, up to 180 days where configured.sidebar_stateto remember the navigation state, for seven days.
Stripe may set necessary cookies on its hosted Checkout and Customer Portal under Stripe’s privacy and cookie information. Dancetu does not currently load advertising or non-essential analytics cookies. If that changes, we will update this notice and obtain consent before loading them where required.
12. Your rights
Subject to GDPR conditions and exceptions, individuals may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and complain to the Úrad na ochranu osobných údajov Slovenskej republiky or another competent supervisory authority. Requests to QikBuild should use privacy@dancetu.com. We may verify identity and normally respond within one month.
For studio-controlled data, contact the studio first. We assist the studio under the DPA and will forward requests where appropriate.
13. Automated decisions and marketing
Dancetu does not make solely automated decisions about individuals that produce legal or similarly significant effects. Operational rules such as capacity, waitlist placement, plan limits, and payment-state access apply deterministic customer-configured or contractual rules and can be reviewed by the relevant studio or QikBuild.
Service and billing messages are not marketing. Optional marketing requires the applicable permission and includes a way to withdraw or unsubscribe.
14. Changes and complaints
We update this Policy when data practices, providers, or law change. Material changes are notified through Dancetu or email before they take effect where practicable. The effective date and version identify the current notice.
Please contact us first so we can investigate a concern. This does not limit the right to contact a supervisory authority or seek another remedy.