Privacy at Qlik

Qlik has an ongoing commitment to protecting the data of our customers, business partners and employees. We believe in communicating in an open, transparent manner about the ways in which your data is collected and used, and respecting customers’ choice and control over their data. Accordingly, we have developed a robust, enterprise-wide privacy program to ensure compliance with the evolving landscape of privacy and data protection laws and maintain the trust our customers have in our products and services.

Trust in Qlik as a Privacy Compliant Vendor

Qlik’s Privacy Team, led by our Data Protection Officer, in conjunction with our IT Security Team, administers and monitors the effectiveness of our privacy program. Our privacy program is supported by a cross-functional team of Data Privacy Champions, including representatives from Legal, IT, R&D, Product, Consulting, Sales, Marketing and Support. The privacy program is underpinned by comprehensive processes and controls, such as:

  • Measures to ensure the lawful transfer of personal data between Qlik group companies in different countries.
  • Our record of data processing activities, as required under Article 30 GDPR.
  • Privacy-By-Design and Privacy-By-Default methodologies, e.g., in our vendor vetting and our R&D/product development processes.
  • Data retention and access rules.
  • Regular data privacy and security training.
  • A Data Processing Addendum for our Qlik Cloud customers containing strong privacy commitments.
  • Comprehensive data privacy policies, including our Product Privacy Policy and our Cookie & Privacy Policy.

Privacy in Qlik’s Products and Services

Privacy-By-Design
Organizations and individuals can use Qlik products with confidence, knowing that we built our products, from inception, with security and privacy in mind. We utilize both security- and privacy-by-design practices in our development processes which adhere to applicable privacy laws.

Your Data, Your Choice
You decide what content data (i.e. the data/applications) you upload into or create in our products. You can also correct and delete your content data whenever you need, to suit your business.

Data Access
For client-managed products that are on-premise or customer or third party hosted Qlik SaaS solutions, Qlik does not host these and has no access to your content data.

Privacy in Qlik Cloud

Qlik as a Data Processor
Qlik is a processor of our customers’ personal data within Qlik Cloud. Therefore, customers can confidently use personal data in their tenants with the knowledge that the Qlik Data Processing Addendum provides the protections required by applicable law.

Your Tenant, Your Choice
You decide what content data (i.e. the data/applications) you upload into or create in your Qlik Cloud tenant. You can also access, correct and delete your Qlik Cloud tenant content data to suit your business and privacy-related compliance needs.

Security of Your Data
Your content data is encrypted in Qlik Cloud and we have multiple layers of security in place to protect it. Qlik personnel do not have direct access to your data unless you otherwise invite us into your Qlik Cloud tenant (e.g., to perform Consulting Services). Visit our Trust and Security page to learn more about the industry-standard security controls we apply to protect your data and our security certifications and accreditations.

Choose your Region
You can select your server location by region when creating your Qlik Cloud tenant.

Read our Product Privacy Policy for more information on how Qlik handles privacy within our products, the server regions available to our Qlik Cloud customers, and other relevant information.

Frequently Asked Questions

  • At Qlik, we implement various measures ensuring personal data is protected and that our products comply with data protection/privacy laws, including the EU General Data Protection Regulation (GDPR).

    These include, for example:

    • Appointing a global Data Protection Officer.
    • Measures to safeguard the lawful transfer of personal data between group companies in different countries.
    • Maintaining a Record of Processing Activities, as required under Article 30 GDPR.
    • Privacy-By-Design and Privacy-By-Default processes, e.g., in our vendor vetting and in our R&D/product development processes.
    • Data Retention and Access governance.
    • Implementing Privacy Policies on various topics, from website data collection to our products.
    • Maintaining a data incident detection and response program.
    • Regular privacy and security training.
  • Yes, when creating a new Qlik Cloud tenant, you have the option to select your region of preference for storing your content data. You maintain control over access to your content (e.g., apps) through permissions and access granting.

    Please note that personal data in your Qlik Cloud tenant may leave your region:

    1. If you share the data outside the EU, e.g., by sharing content data with a colleague in the US; and/or
    2. If you attach personal data to a Qlik support case (Qlik does not require personal data from you to provide support services and we advise that you anonymize the data before disclosing it to Qlik) or, in the unlikely event that a Qlik employee needs to access your tenant to fix an issue. Qlik uses its Affiliates and third parties for support and consulting services, some of which may be located globally. Qlik has implemented, internally and with relevant external sub-processors, data protection agreements ensuring lawful data transfers. You can find Qlik’s list of sub-processors on Qlik Community.
  • On-premise products are client managed and you maintain control over where your data is stored. Qlik cannot access your content data.

  • For Qlik's on-premise products, which are client-managed, Qlik does not receive the content that the customer puts in the software. For Qlik SaaS offerings hosted on Qlik Cloud (e.g., Qlik Sense Enterprise SaaS), Qlik does not have direct access to your content data unless you invite us into your Qlik Cloud tenant. Qlik may have access to metadata about the content, which is accessible only to support personnel responsible for providing support.

    For support and consulting services, support case attachments and/or consulting-related data are only accessible to those that need access as part of their job responsibilities. All Qlik personnel are bound by confidentiality obligations and receive training on data protection and security.

    For further information see our Product Privacy Policy.

  • Qlik’s lead Data Protection Authority (DPA) for pan-European data protection matters would be the Swedish DPA. Qlik has a significant presence in Sweden, where we were founded and is still home to our European R&D and Support Infrastructure teams.

  • Yes, Qlik has a global Data Protection Officer. Any inquiries can be sent to privacy@qlik.com.

  • No.

  • For technical support queries, Qlik will only process personal data that is provided per instruction from the relevant customer to resolve the relevant technical issue. Qlik does not require personal data from you to provide support services and we advise that you anonymize the data before disclosing it to Qlik. Any data sent as part of a support case attachment is subject to Qlik’s data retention and deletion rules (for support cases, deletion is typically within 90 days of case closure). Like any business we may use third party cloud hosting tools to provide these services. A list of these sub-processor systems is available on Qlik Community.

  • Qlik may hold B2B contact details in our sales and marketing databases for the purpose of customer services, sending marketing information and conducting sales related operations. Checks are made on a regular basis for any contact details that have remained inactive in our sales and marketing databases for a total of 2 years, and if so, they are deleted out of the database. Any deletion and marketing opt-out requests are actioned promptly. For further information, please see our Website Cookie & Privacy Policy.