Topkee is a leader in the digital marketing space, focused on leveraging forward-looking technologies such as data analytics and artificial intelligence to help businesses navigate ever-changing market dynamics, uncover growth opportunities, and reach broader audiences and markets.
This Privacy Policy explains how Topkee and its group companies (collectively, "Topkee," "we," "us," or "our") collect, use, and protect personal information processed by us. This is our global code of conduct, governing how Topkee handles personal data in the locations where we operate.
Building Trust through Transparency
speed and scale, transparency is fundamental to our positioning and how we operate. It is the foundation of the trust we build with the individuals and organizations that rely on Topkee. To uphold this trust, we explain our privacy practices in a clear, accessible, and easy-to-understand manner, and we let you know how to exercise your rights regarding your data.
Putting Privacy into Practice
To deliver our products and services (collectively, "our Services") and carry out our day-to-day business operations, we collect, store, use, and share personal data. Personal data is any information that can directly (e.g., your name) or indirectly (e.g., phone number or device identifier) identify you. Depending on the Services used, the individuals whose personal data we process include:
Customers: Individuals or entities that have contracted with us to use the Services.
End Users: Individuals who interact with our customers through our Services (e.g., receiving SMS messages or verifying their identity).
Prospects and Visitors: Individuals who visit our websites, attend our events, or engage with our sales teams.
Our responsibilities regarding personal data depend on how you use our Services or interact with us:
Topkee as Data Controller: We determine the “how” and the “why” personal data is used in relation to our Services, accounts, websites, and operations. In these cases, we are directly responsible for protecting the data.
Topkee as Data Processor: We process personal data according to our customers' instructions – whether through specific instructions, or their chosen service configurations. In these cases, we must use and protect personal data in accordance with those instructions.
This Privacy Policy (this "Policy") applies when Topkee acts as a Data Controller.
What This Policy Does Not Cover
Supplemental Policies: Specific Services or business operations may have additional privacy terms provided at the time of collection.
Job Applicants: This Policy does not apply to job candidates.
What Personal Data We Process
To provide the Services, manage business operations, drive research and development, secure our platform and network, and prevent fraud, we process personal data from three sources: 1) data you directly share; 2) data we automatically generate or collect; and 3) data from third parties. In the past 12 months, the categories of personal data we have collected, processed, and disclosed for business purposes depend on the nature of your relationship with us, or the Services you or our customers use, and may include the following:
Data You Directly Share
Personal data you provide for account setup, purchases, or seeking support
Contact Data
Name, company name, company address, phone number, email address, job title, industry, social media profile URL
Customer Account Data
Purchase and Payment Data: Purchase history, credit/debit card details, billing address, PayPal account information
Service Configuration Data: Application details regarding the intended use of specific Services
Security and Verification Data: Username, password, account name, unique account ID, API tokens, government-issued identification documents
Subscriber Records: Proof of identity and physical service address and other information required by local law to provide specific Services (e.g., phone numbers)
Customer Content
Communication content (e.g., email subject lines, email bodies, SMS message bodies, media files), transcripts, voice recordings, communication logs, and other data uploaded to the Services
Marketing and Communications Data
Privacy settings, communication preferences, event attendance information, dietary requirements or accessibility needs for physical events
Customer Support and Feedback Data
Call recordings with support personnel, transcripts of conversations with AI chatbots, feedback, and survey responses
Data We Automatically Generate or Collect
Personal data we automatically collect or generate for routing communications, optimizing performance, and preventing fraud, including through tracking technologies such as cookies and web beacons
Communications Usage Data
Electronic Communications Metadata: Sender/recipient information, routing details, timestamps, communication type, duration, message status and activities (e.g., delivered, opened, bounced, spam, clicks, or unsubscribes), error data, and traffic logs
Device Data: IP address, operating system type/version, browser type, screen resolution, CPU cores, manufacturer/model, device ID, time zone, device IP address location generated in the context of message delivery, and general location (city/town) when using our account portal, making API requests, and activity logs. Precise geolocation data is not collected
Online Activity Data
Browsing behavior, page and feature interactions, products viewed or searched for, response times, download errors
Data from Other Sources
Personal data we receive from third parties, trusted partners, telecommunications carriers, aggregators, or telecom operators to configure accounts, verify identities, and enhance the Services
Partner Source Data
Contact data provided by event partners and co-sponsors, as well as marketing and lead generation partners. Data may also include information you choose to share through third-party forms or advertisements, which may be auto-populated from your profiles on those platforms and may include location-related data.
Solution Provider Source Data
Contact data and customer account data shared by our solution providers – independent software vendors ("ISVs") and managed service providers ("MSPs") – to assist us in processing orders and setting up sub-accounts.
Data Enrichment Services
Contact data obtained from third-party data providers and value-added services, as well as publicly available data. We may combine this contact data with other data we have already collected about you.
Third-Party Verification Data
Contact data and customer account data shared by linked third-party services (such as Google and Meta) when you connect those accounts to your Topkee account (subject to your privacy settings on those platforms).
Telecom Data
Communications-related data from telecommunications carriers, aggregators, and telecom operators – including phone type, SIM and carrier history, registration location, account type, and IP address – used to verify that personal data provided to Topkee matches records held by telecommunications carriers, aggregators, or telecom operators.
How and Why We Use Your Data
The specific reasons we process personal data depend on your relationship with us. We only process personal data as necessary to achieve the purposes described below, in compliance with applicable data protection laws. In the past 12 months, we have processed personal data for the following business purposes:
Categories of Data Use and Legal Bases for Processing
Categories of Data Use and Legal Bases for Processing
Account Management
Purpose: To establish and manage your Topkee account throughout your customer lifecycle.
Personal Data Processed:
Contact Data
Customer Account Data
Solution Provider Source Data
Third-Party Verification Data
Examples: Determining service eligibility; verifying identity (KYC); billing and relationship management; and sending important administrative or service updates.
Legal Bases for Processing:
Consent
Legitimate Interests
Legal Obligation
Business Operations
Purpose: To manage essential business functions.
Personal Data Processed:
Contact Data
Customer Account Data
Communications Usage Data
Customer Support and Feedback Data
Online Activity Data
Solution Provider Source Data
Data Enrichment Services
Third-Party Verification Data
Examples: Financial management (accounting, auditing, and revenue planning); strategic growth (lead scoring and operational insights); relationship management; corporate governance; risk management; maintaining customer records; identifying potential job applicants; and ensuring the security of employees, visitors, and property.
Legal Bases for Processing:
Consent
Legitimate Interests
Legal Obligation
Platform Security and Fraud Prevention
Purpose: To protect our platform and data, while proactively safeguarding our network and users from abuse.
Personal Data Processed:
Contact Data
Customer Account Data
Customer Content
Communications Usage Data
Customer Support and Feedback Data
Solution Provider Source Data
Third-Party Verification Data
Telecom Data
Examples: Protecting systems from unauthorized access and security threats; identifying signs of account takeover and spam or bot attacks; training AI/ML models to recognize evolving security vulnerabilities and fraud patterns; and using signals to make real-time automated security decisions, such as approving account applications or suspending fraudulent accounts (you will be notified and have an opportunity to object).
Legal Bases for Processing:
Consent
Legitimate Interests
Legal Obligation
Service Support and Improvement
Purpose: To operate, maintain, and grow our communications and engagement platform.
Personal Data Processed:
Contact Data
Customer Account Data
Customer Content
Communications Usage Data
Customer Support and Feedback Data
Solution Provider Source Data
Third-Party Verification Data
Telecom Data
Examples: Providing global connectivity and routing communications; troubleshooting technical issues; training AI/ML models with performance metrics to optimize network reliability; providing dedicated customer support; and refining our service offerings through usage insights.
Legal Bases for Processing:
Consent
Legitimate Interests
Legal Obligation
Research and Innovation
Purpose: To expand platform capabilities and develop next-generation communications, engagement, and identity solutions.
Personal Data Processed:
Contact Data
Customer Account Data
Customer Content
Communications Usage Data
Customer Support and Feedback Data
Solution Provider Source Data
Third-Party Verification Data
Telecom Data
Examples: Developing new features or products to continuously improve our Services.
Legal Bases for Processing:
Consent
Legitimate Interests
Legal Obligation
Customer Engagement
Purpose: To personalize your experience and manage our ongoing relationship with you.
Personal Data Processed:
Contact Data
Customer Account Data
Marketing and Communications Data
Communications Usage Data (Device Data)
Online Activity Data
Partner Source Data
Solution Provider Source Data
Data Enrichment Services
Third-Party Verification Data
Examples: Sending important service notifications and account support; sending relevant service updates and news based on your preferences; facilitating event participation and access to resources such as white papers; and conducting surveys to gather insights for service improvement.
Legal Bases for Processing:
Legitimate Interests
Consent
Personalization and Optimization
Purpose: To analyze website and platform interactions to improve your digital experience, refine our interfaces, and optimize our marketing ecosystem through a unified understanding of the customer journey.
Personal Data Processed:
Contact Data
Customer Account Data
Marketing and Communications Data
Communications Usage Data (Device Data)
Online Activity Data
Partner Source Data
Solution Provider Source Data
Third-Party Verification Data
Examples: Analyzing website and platform navigation to improve functionality and experience; using identity resolution to build unified profiles to ensure a consistent experience across devices and touchpoints; measuring and optimizing the effectiveness of our advertising campaigns; and deploying online tracking technologies in accordance with your preferences.
Legal Bases for Processing:
Legitimate Interests
Consent
Legal Compliance
Purpose: To fulfill our global legal obligations and protect the public interest.
Personal Data Processed:
Customer Account Data
Customer Content
Communications Usage Data
Solution Provider Source Data
Third-Party Verification Data
Examples: Responding to lawful legal requests (such as court orders or subpoenas); and safeguarding individuals' fundamental rights and freedoms.
Legal Bases for Processing:
Legitimate Interests
Legal Obligation
How We Disclose Personal Data
We only share your data when necessary to provide the Services, operate our business, or comply with the law, and we do not sell your data to third parties. While we may share certain categories of personal data for these business purposes, no action information will be shared or sold with any third party for marketing or promotional purposes. In the past 12 months, we may have shared personal data with the following categories of recipients:
Categories of Data Recipients
Categories of Data Recipients
Telecommunications Service Providers
Recipient Details: A global network of carriers, aggregators, and telecom operators that act as the transmission medium for Customer Content. These providers act as independent data controllers when processing metadata for billing, fraud prevention, or legal compliance.
Reason for Sharing: Routing and connecting communications over the Public Switched Telephone Network ("PSTN").
Important Note: When required by local law, we share user records with local telecom operators or authorities only to provide connectivity, and we maintain the highest level of confidentiality over these records.
Other Communications Service Providers
Recipient Details: Over-The-Top ("OTT") providers (e.g., WhatsApp) acting as independent data controllers.
Reason for Sharing: Routing and connecting communications over the PSTN.
Third-Party Service Providers
Recipient Details: Third-party vendors and service providers engaged by Topkee to process personal data on our behalf.
Reason for Sharing: Performing specific operational functions, with access strictly limited to providing Topkee Services under robust security and confidentiality safeguards.
Topkee Group Companies
Recipient Details: Topkee group companies (subsidiaries and affiliates) as listed in our Binding Corporate Rules.
Reason for Sharing: Facilitating global operations and service delivery, with all members contractually bound to use your information strictly in accordance with this Policy.
Legal, Regulatory, and Judicial Authorities
Recipient Details: Law enforcement agencies, government authorities, emergency services, private parties involved in legal proceedings (e.g., opposing counsel or court-appointed personnel), or third parties.
Reason for Sharing: Complying with legal obligations, responding to court orders or subpoenas in civil or criminal cases, enforcing our agreements and policies, preventing fraud, and protecting the security and integrity of the platform or the public.
Important Note: We notify users about legal requests where permitted and where Topkee believes disclosure would not interfere with an ongoing investigation. We object to any requests that are not issued through proper process.
Parties Involved in Corporate Transactions
Recipient Details: Potential or actual buyers, merger partners, and their professional advisors (e.g., legal and financial advisors).
Reason for Sharing: Conducting due diligence or completing the transfer of assets during a merger, sale, reorganization, or dissolution to ensure business continuity.
Important Note: Where required by law, we will provide you with advance notice and information about your choices regarding the transfer of your data to the new entity.
Aggregated, Anonymized, and De-identified Data
We may derive aggregated, anonymized, or de-identified data from your personal data. Because such data cannot identify you, it is not considered personal data under law. We may use such data for any purpose. We commit to never attempting to re-identify such information and will only share it with third parties that are legally or technically obligated to maintain its de-identified status.
U.S. Supplemental Disclosure
If you are a U.S. resident and are interested in the categories of personal data we have disclosed for business purposes recently, the following is a list:
Identifiers
Commercial Information
Financial Information
Internet or Other Electronic Network Activity Information
Geolocation Data
Professional or Employment-Related Information
By "our business purposes," we mean we disclose personal data solely as described in this section.
International Transfers
As a global platform, we move data across borders to ensure seamless connectivity, service delivery, and business operations. Whether transferring data within the Topkee group or externally to trusted third parties, we rely on the following legal protection mechanisms:
Data Privacy Framework ("DPF"): Our subsidiary, Topkee Inc., complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. In the event of any conflict between the terms of this Privacy Policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. Topkee Inc. is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC).
EU and UK Standard Contractual Clauses ("SCCs"): Transfer mechanism used for EU and UK transfers where the DPF does not apply.
Data Security & Retention
Topkee protects personal data through a risk-based security framework and data lifecycle management processes.
Security Measures
To prevent loss, unauthorized use, access, or disclosure, Topkee employs reasonable and appropriate security measures designed to protect personal data both online and offline.
Risk-Based Protection: These measures vary according to the sensitivity of the personal data we collect, process, and store, as well as the current state of technology.
Global Standards: All systems are governed by policies based on Security Risk Assessment and Audit.
Retention Policy
We are committed to not retaining personal data in a form that identifies individuals for longer than is necessary to achieve the purposes for which the data was processed. We retain personal data in accordance with Topkee's Records Retention Policy and Guidelines.
Customer account data is stored as long as necessary to provide the Services and operate our business. Please note that requests to delete customer account data are subject to the limitations set forth in the "Privacy Rights & Choices" section of this Policy.
Managing Your Data
We provide you with the tools you need to store, access, delete, and exercise control over your data. The specific choices available to you depend entirely on the Services you use and how you configure those Services.
California-Specific Terms
1. Topkee, when processing customer personal data subject to the CCPA as a controller, is an independent "business."
2. The following terms apply when Topkee processes customer personal data subject to the CCPA as a processor and acts as a "service provider":
(a) The term "personal information" as used in this specific section has the meaning provided in the CCPA;
(b) Topkee will process any personal information within customer personal data solely for the business purposes set forth in this Policy (the "Purposes"). As a service provider, Topkee will not sell or share personal information within customer personal data, nor will it (i) retain, use, or disclose the data for any purpose other than the Purposes (including retaining, using, or disclosing the data for a commercial purpose other than the Purposes or as otherwise permitted by the CCPA) or (ii) retain, use, or disclose the data outside of the direct business relationship between Customer and Topkee;
(c) Topkee will (i) comply with its obligations applicable to it as a service provider under the CCPA, and (ii) provide personal information with the same level of privacy protection as required by the CCPA. Customer is responsible for ensuring that it has complied and will continue to comply with the requirements of the CCPA in its use of the Services and its own processing of personal information;
(d) Customer has the right to take reasonable and appropriate steps to help ensure that Topkee's use of personal information is consistent with Customer's obligations under the CCPA;
(e) If Topkee determines that it can no longer fulfill its obligations as a service provider under the CCPA, it will notify Customer;
(f) Upon receipt of such notice, Customer has the right to take reasonable and appropriate steps in accordance with this Policy to stop and remediate unauthorized use of personal information;
(g) Topkee will provide reasonable additional and timely assistance to help Customer fulfill its obligations regarding consumer requests (as set forth in this Policy);
(h) For any sub-processor used by Topkee to process personal information subject to the CCPA ("Sub-processor" means (a) Topkee and its affiliates, where Topkee or its affiliate is processing customer personal data and Customer is the processor of that data; or (b) any third-party processor engaged by Topkee to process customer personal data as a sub-processor of Topkee in order to provide the Services to Customer. Telecommunications providers used by Topkee to provide the Services are not considered Sub-processors.), Topkee will ensure that the agreement between Topkee and that Sub-processor complies with the CCPA, including but not limited to the contractual requirements for service providers and contractors;
(i) Topkee will not combine customer personal data received from or on behalf of Customer with personal information received from or on behalf of another person or persons, or collected from its own interactions with consumers, unless such combination is necessary to fulfill any business purpose permitted by the CCPA (including its regulations) or regulations adopted by the California Privacy Protection Agency;
(j) Topkee certifies that it understands and will comply with its obligations under the CCPA.
3. Topkee acknowledges and confirms that it does not receive personal information within customer personal data as consideration for any Services provided to Customer.
Privacy Rights & Choices
Under applicable data protection laws, you may have the following rights regarding personal data we process as a Data Controller:
Privacy Rights and Choices
Privacy Rights and Choices
Transparency and Control
Right to Know: Request clear details about data categories, sources, purposes, and third-party sharing.
Right to Access: View or request a copy of your data. Right to Correct: Update inaccurate or outdated information.
Right to Delete: Request destruction of data when there is no legal or legitimate business reason to retain it.
Right to Portability: Receive your data in a structured, machine-readable format for transfer.
Right to Object or Restrict: Object to or restrict data processing, including automated decision-making and related profiling.
Right to Withdraw Consent: Withdraw consent to processing at any time.
Right to Opt Out: Opt out of disclosing your data to third parties (other than our service providers) or using your data for purposes materially different from those for which it was collected or authorized.
Important Note: Account closure or deletion is permanent and results in immediate loss of access to some or all data. Requests are subject to the limitations set forth below.
How to Exercise Rights: Contact: privacy@topkee.com
Marketing Communications and Targeted Advertising Rights
Opt out of marketing communications; update your communication preferences; update your Cookie preferences; opt out of targeted advertising.
How to Exercise Rights:
Click the "unsubscribe" link at the bottom of any Topkee marketing email.
Update your communication preferences. For targeted advertising, please refer to the Cookies & Tracking Technologies section of this Policy.
Contact: privacy@topkee.com
Important Note: Marketing opt-outs may take up to three days to process. Important service communications – such as billing or password reset – will continue unless your account is deactivated.
Automated Decision-Making Rights
Object to and request human review of decisions made about you based solely on automated processing (currently including account approvals and account suspensions related to abuse or fraudulent activity, or other decisions that have a significant impact on you).
How to Exercise Rights: Contact: privacy@topkee.com
Complaint Rights
Submit a complaint to Topkee; file a formal complaint with a government data protection supervisory authority; take legal action through the relevant court system.
How to Exercise Rights: Please refer to the "Resolving Complaints" section of this Policy.
Data Privacy Framework Choices and Means
Under the Data Privacy Framework Principles, opt out of (i) disclosing your personal data to third parties (other than service providers acting on our behalf); or (ii) using your personal data for purposes materially different from those for which it was originally collected or authorized by you.
How to Exercise Rights: Contact: privacy@topkee.com
Additional Rights
Depending on your jurisdiction, you may be able to exercise certain specific controls over your data:
Sensitive Data: Limit the use of sensitive personal data to what is strictly necessary for service delivery. Topkee currently limits processing to the specific purposes described in this Policy or as permitted by law.
EU Rights: If you believe that data transferred from Europe to our U.S. headquarters or other non-U.S. companies violates our privacy policy, you may file a complaint with the Topkee company that transferred the data or its local supervisory authority, or bring legal action against that company.
Security and Verification
To protect your account, we must verify your identity before processing certain requests (e.g., deletion).
Verification Process: We will typically ask for proof of your recent interaction with us or login verification.
Authorized Agents: If you use an authorized agent to make a request, we may ask for a power of attorney or written authorization proving they have the authority to act on your behalf.
Limitations
In certain circumstances, these rights may be limited or subject to exemptions, such as where Topkee can demonstrate a legal requirement or legitimate interest in processing your data. We will not discriminate against you or change the price of our Services for exercising your rights, but if you request deletion of your data, it may affect your ability to use our Services.
Important Note
If Topkee processes your data as a Data Processor on behalf of our Customer, we will direct you to contact our Customer to exercise your rights.
Children's Privacy
Our Services are not directed at, or intended for use by, children (under 13 in the United States and the UK, or under 16 in the European Economic Area). If we discover that a child has created an account, we will deactivate the account and delete the data as soon as possible. If you believe we have inadvertently collected a child's data, please contact us at privacy@topkee.com with "Children" in the subject line.
Cookies & Tracking Technologies
We use cookies, pixels, web beacons, and similar tools to protect our websites, analyze performance, and deliver relevant advertisements. These tools help us identify your device, making your experience safer, more efficient, and more aligned with your interests. Under certain U.S. state laws, this is considered "sharing" or "targeted advertising."
cookies
Cookies are small files stored on your device that help us identify you, making your experience more efficient and personalized. We use session cookies (which expire when you close your browser) and persistent cookies (which remain on your device for a period of time). Our cookies fall into three categories:
Essential Cookies: Essential for website operation (e.g., secure login or remembering your position in an ordering process). You cannot opt out of Essential Cookies.
Functional Cookies: Used to remember your choices (e.g., language or region) and analyze website usage to improve customer experience and website performance. You can opt out of Functional Cookies, but some website features may not function properly.
Advertising Cookies: Used to show you content and advertisements relevant to your interests. You can opt out of Advertising Cookies at any time.
Web Beacons (Pixels)
Web beacons (or pixels) are 1x1 transparent images that can be embedded in our marketing emails, allowing us to see whether you have opened the email or clicked on a link, which helps us measure the effectiveness of our communications.
Your Controls: How to Manage Tracking Technologies
We provide several ways for you to manage tracking technologies:
Browser Settings: You can use your browser settings to opt out of Functional Cookies and Advertising Cookies. For more information on how to do this, please click here. To manage cookie privacy and storage settings, please click here.
Universal Opt-Outs: [Global Privacy Control]{.underline} ("GPC") and [Do Not Track]{.underline} ("DNT") are tools you can use to inform websites about your privacy preferences regarding advertising trackers. To set GPC, you can visit the Global Privacy Control page. To set DNT, you can visit the All About DNT page. Please note that this may affect the functionality of our website or your account.
We are committed to resolving any questions or concerns in accordance with our complaint handling procedures. If you have questions or wish to file a complaint (whether regarding our privacy practices or other matters), please contact the Topkee Privacy Team at privacy@topkee.com or by mail to the physical address listed under "How to Contact Us."
We encourage you to use these direct channels to ensure a timely response, but we will also handle complaints received through any other means.
Data Protection Authorities
You may have the right to lodge a complaint with your local data protection authority or bring court proceedings under local law.
European Economic Area Residents
You have the right to lodge a complaint with the Data Protection Commission in Ireland.
UK Residents
If you have concerns about our privacy practices, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO). Under the UK Data (Use and Access) Act, you must first submit your complaint directly to Topkee to give us the opportunity to resolve the issue. We will acknowledge receipt of your complaint within 30 days and strive to provide a substantive response without undue delay. If you remain dissatisfied after receiving our final response, you may then escalate your complaint to the ICO (www.ico.org.uk).
If your complaint relates to a company that uses our Services (e.g., you wish to stop receiving emails from a specific brand), please contact that company directly. As a Data Processor, we cannot resolve complaints about our customers' data practices.
In addition to the above regulatory authorities, Topkee's group company, Topkee Inc., is also subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC).
Changes to This Privacy Policy
We review and update this Policy periodically for clarity or to reflect legal, technical, or business changes. The latest version will always be posted at topkee.com/privacy-policy, with the "Last Updated" date at the top. If we make material changes that affect your rights, we will provide advance notice via email and obtain your consent where required by law.