Skip to content
Maiky
  • Solutions
    • StartupStart your information security journey
    • SMEAffordable, scalable security without compromise
    • EnterpriseAutomate your information security programme
    • GovernmentCentral oversight with simplified compliance
    PartnersUnlock partner benefits and manage multiple clients with MaikyLearn more→
  • Features▾
    Govern & assess
    • Risk Management
    • Compliance Frameworks
    • Maturity Assessment
    • Audits
    Operate & respond
    • Policy Management
    • Automation
    • Incident Management
    • Tasks & Reminders
    Map your environment
    • Asset Management
    • Process Management
    • Supplier Risk
    • Trust Center
    Frameworks
    • ISO 27001
    • CyFun 2025
    • NIS 2
    • NSW AIAF
    Platform overviewThe whole platform at a glanceLearn more→
  • Services

    Expert-delivered services that get you compliant without burning internal resources.

    TPRMManage third-party risk without the spreadsheets.Learn more→ImplementationGo live in weeks, not months, with certified GRC experts.Learn more→
  • Pricing
    • About UsThe team and mission behind Maiky
    • ContactGet in touch with our team
  • FreeNIS2 Assessment
AcademyLog InBook a Demo

Privacy Policy

Last updated: August 2026

Company information

Maiky BV is a Belgian company (registration: BE0718712887) and is the data controller for the processing described here. The company values privacy and personal data security.

Maiky has appointed a Data Protection Officer. You can reach our DPO at privacy@maiky.io.

Policy scope

This privacy policy applies to personal data processing by Maiky as data controller for:

  • Website usage
  • The Maiky governance, risk and compliance (GRC) and information-security management platform
  • Platform usage by registered users

Data collection and usage

Information collected

Users may voluntarily provide personal information including name, address, telephone number and email address through various interactions with Maiky.

Primary processing purposes

  • Contact responses: Answering enquiries and sending marketing communications
  • Event registration: Managing seminar, demo and workshop registrations
  • Publication subscriptions: Delivering newsletters and alerts
  • Trial accounts: Processing trial account requests and access
  • Contract management: Handling agreements, invoicing and accounting
  • Platform security: Detecting abuse and maintaining integrity
  • Analytics: Understanding website and platform usage patterns

Third-party data integration

We use a customer-relationship management (CRM) system to manage communications, and Google Analytics 4 (Google Ireland Limited) together with Hotjar (Hotjar B.V., Netherlands) to understand how our website is used. Analytics are loaded only after you accept analytics cookies; see our Cookie Policy for the full list and retention periods. Where you interact with us through third-party platforms (for example social media or advertising networks), we may receive related data from those platforms.

Legal basis for processing

Processing relies on:

  • Contract execution
  • Legitimate business interests
  • Compliance with legal obligations
  • User consent (particularly for cookies and direct marketing)

Data protection measures

Maiky implements administrative, technical and organisational measures to ensure the security and confidentiality of your personal data, including access controls, encryption in transit and multi-factor authentication on systems that hold personal data.

Data retention

Personal data is retained only as long as necessary for the stated purposes or as legally required. Specific retention periods are available upon request.

Data sharing

Personal data may be shared with:

  • Hosting and IT service providers
  • CRM and marketing-tool providers
  • Affiliated companies
  • Contractual partners
  • Law enforcement and regulatory agencies when legally required
  • Professional advisors and auditors
  • Prospective purchasers in a merger or acquisition context

International transfers

Where personal data is transferred outside the EEA, such transfers are governed by appropriate safeguards, such as the European Commission's Standard Contractual Clauses, together with any additional measures required to protect your data.

Your rights

Data subjects have the following rights:

Right to information and access

You may request information regarding data processing activities and your personal data file.

Right to rectification

You may request correction or supplementation of inaccurate or incomplete data.

Right to erasure ('right to be forgotten')

Data erasure is available when:

  • Data is no longer necessary for the purposes for which it was collected
  • Processing is consent-based
  • Serious grounds exist to object
  • Processing is unlawful
  • A legal erasure obligation applies

Exceptions include freedom of expression, legal compliance, public health, archiving, research and legal claim purposes.

Right to restrict processing

You may restrict processing when:

  • Data accuracy is contested
  • Processing is unlawful
  • Data is no longer needed but is required for legal claims
  • Legitimate-interest objections are pending verification

Right to object

You may object to processing based on legitimate interests or prior consent at any time. For direct marketing, the right to object is absolute. You also have the right not to be subject to a decision based solely on automated processing, including profiling.

Right to data portability

Under certain conditions (consent or contract basis, automated processing), you may receive your data in a structured, machine-readable format and transmit it to other controllers.

Exercising your rights

To exercise your rights or update your information, contact privacy@maiky.io. You must provide proof of identity if necessary. Requests are generally free unless manifestly unfounded or excessive.

Unsubscribe options

To stop receiving marketing communications, you may:

  • Email privacy@maiky.io
  • Click the unsubscribe link in our emails
  • Complete the contact form on the website

Complaints

You may lodge a complaint with the Belgian Data Protection Authority:

  • Address: Rue de la Presse 35, 1000 Brussels
  • Phone: +32 (0)2 274 48 00
  • Website: https://www.dataprotectionauthority.be/
  • Complaint form: https://www.dataprotectionauthority.be/citizen/actions/lodge-a-complaint
  • Email: contact@apd-gba.be

Policy updates

Maiky may amend this policy. Material changes will be communicated actively to users with contact details on file. The latest version is always available on the website.

Contact

For privacy-related questions: privacy@maiky.io

Governing law: the EU General Data Protection Regulation (GDPR) and the Belgian Law of 30 July 2018 on the protection of personal data.

Maiky

The CISO's preferred platform for GRC and InfoSec management. Streamline compliance, automate evidence, and stay secure.

ISO 27001 certified · BE0718712887

LinkedInYouTube
ISO 27001 certifiedMade in Europe

Solutions

  • Startup
  • SME
  • Enterprise
  • Government
  • Partners
  • Pricing

Features

  • Platform overview
  • Risk Management
  • Compliance Frameworks
  • Maturity Assessment
  • Audits
  • Policy Management
  • Automation
  • Incident Management
  • Tasks & Reminders
  • Asset Management
  • Process Management
  • Supplier Risk
  • Trust Center

Frameworks

  • ISO 27001
  • CyFun 2025
  • NIS2Free scan
  • NSW AIAF
  • GDPR
  • DORA

Services

  • Third-Party Risk (TPRM)
  • Implementation

Company

  • About Us
  • Contact

© 2026 Maiky BV · All rights reserved

Privacy PolicyCookie PolicyTerms of Service