Back to Home

Privacy Policy

Intaky is a client intake and document collection service, operated from Vietnam. This policy explains what we do with personal data — both the data we hold about the people who run workspaces on it, and the data those workspaces collect from their own applicants. Those are two different relationships, and section 1 sets out which one applies to you.

Intaky is in beta. If your organisation is subject to a particular data protection regime and needs terms that address it, write to privacy@intaky.com before you start and we will work it out with you.

1. Two different relationships

If you run a workspace — you signed up, you administer it, or you review submissions in it — this policy describes what we do with your personal data.

If you submitted an application to an organisation using Intaky, we only hold that information on their behalf. The organisation that asked you for it decides what to collect, why, and how long to keep it; we act on their instructions. Ask them first — they are the ones who can answer, correct or delete. If you cannot reach them, write to us and we will help you work out who to contact.

2. What we collect about workspace users

3. What we process for our customers

Workspaces collect forms and documents from their own applicants. Depending on what the organisation asks for, that can include identity documents and financial records. We do not choose what is asked for, and we do not use any of it for our own purposes: no profiling, no analytics across customers, and no training of machine-learning models.

4. Who else is involved

We do not sell personal data and we do not share it for advertising. We use a small number of service providers who process data on our behalf, under contract:

These providers operate outside Vietnam, so using Intaky means your data is stored and processed abroad. We will update this list before adding anyone to it.

5. How long we keep it

6. How we protect it

Traffic is encrypted in transit with TLS. Each workspace's data is separated by tenant-scoped queries and role-based authorisation, and uploaded documents sit in private object storage that is never publicly addressable — every download passes through an endpoint that checks who is asking. Passwords are stored only as salted hashes. Access to production systems is limited to the operator.

No system is perfectly secure, and we would rather say so than imply otherwise. If you believe you have found a vulnerability, please write to security@intaky.com.

7. Cookies

The application sets only what it needs in order to work: a sign-in cookie and an anti-forgery token. There is no analytics, advertising or cross-site tracking, on the application or on this marketing site, so there is nothing here to consent to or opt out of. If that ever changes, we will ask first.

8. Your choices

You can ask us for a copy of your personal data, to correct it, or to delete it. Write to privacy@intaky.com and we will respond within 30 days. Depending on where you live you may have further rights under local law, and we will honour them where they apply.

If you submitted an application to an organisation using Intaky, please see section 1 — those requests belong with that organisation, and we will pass them on.

9. Changes to this policy

We will post any new version on this page and change the date at the top. Where a change materially affects how we handle your data, we will tell workspace administrators by email rather than relying on you to check.

10. Contact

privacy@intaky.com