1. Introduction
Topiko is a business platform that helps vendors create online stores, manage services, and reach customers through digital tools. We serve businesses and individuals worldwide.
2. What We Collect
- Account Info: Name, email, company name, billing details
- Project Content: Store information, product details, media, and files you submit to our platform
- Usage Data: Pages visited, features used, device & browser info
- Cookies: Session, analytics & preference data manageable at any time
3. How We Use Your Data
- Deliver and operate our business platform services
- Process payments and manage your account
- Send project updates, support responses & notifications
- Improve platform performance and features
- Detect and prevent fraud, abuse & security threats
- Comply with legal obligations
- Send marketing emails (opt out any time)
4. AI & Automated Processing
Human-in-the-Loop Guarantee
All production-grade outputs are reviewed by a human before delivery — always. You can request human review of any AI-generated decision at any time.
- AI processing: Your content is processed by AI models to generate outputs for you
- No training on your data: Your content is NOT used to train our AI models by default
- Automated decisions: Used for fraud detection, code analysis & billing — human review available on request
- AI log retention: Output logs kept 90 days, then deleted
- Enterprise isolation: Your data is never shared with or used to benefit other clients
5. Data Sharing
- We do NOT sell your data ever
- Service providers under data processing agreements
- When required by law or court order
- On acquisition — you will be notified
- Only with your explicit consent
6. Data Retention
- Account data: life of account + 3 years
- Project files: 5 years post-completion
- Financial records: 7 years (legal)
- Security logs: 12 months
- AI output logs: 90 days
7. Your Rights
- Access: See what data we hold
- Delete: Request erasure of your data
- Correct: Fix inaccurate data
- Portability: Get your data exported
- Opt Out: Marketing & profiling
- No ADMT: Opt out of automated decisions
Submit a request: privacy@topiko.com or www.topiko.store/privacy-request · Response within 30 days (GDPR) / 45 days (CCPA)
Security
TLS 1.2+ in transit, AES-256 at rest, MFA available, regular pen testing. Breach notification within 72 hrs.
International Transfers
US-based. EU/UK data transferred under Standard Contractual Clauses (SCCs) and UK IDTAs.
Cookies
Essential, analytics, preferences & marketing (consent required). Manage at: topiko.store/cookie-settings
Children
Services are not directed to anyone under 16. Contact privacy@topiko.com if you believe we hold a child's data.