Privacy policy
Last updated: 25 September 2026
Plek is an online booking platform. Studios, clubs, schools and other organisations use it to publish their activities, sessions and series and to take bookings and payments. This policy explains what personal data Plek processes, why, who else receives it and what your rights are.
Who we are and who is responsible
Plek is operated by Small Victories, Mellestraat 303, 9090 Merelbeke-Melle, enterprise number BE0793.301.929 ("Plek", "we", "us"). You can reach us at hello@small-victories.co.
Who is responsible for your data depends on how you use Plek:
- You book with an organisation (as a customer, or for a participant such as your child): the organisation you book with is the controller of that data. It decides what it asks and what it does with it. Plek is its processor: we store and process the data on its behalf and on its instructions, under a data processing agreement. For questions about your bookings, or to exercise your rights, contact that organisation first; if you contact us, we pass your request on and help it respond.
- You use Plek as a staff member of an organisation (owner, administrator, coach, ...), you visit this website or you contact us: Plek is the controller of that data.
What data we process
Customers and participants (on behalf of the organisation)
- Account: name, email address, phone number (optional), preferred language, whether your email address is verified, a password (stored only as a hash) if you set one, and one-time sign-in codes and links. A customer account belongs to one organisation: the same person at two organisations has two separate accounts.
- Sign in with Google or Microsoft (optional): the unique account identifier, email address, whether it is verified, and your name. We don't receive your password or any other data from those accounts.
- Participants (the people who attend, which may be you or, for example, your children): first and last name, date of birth, and, only if the organisation asks for them, national register number, T-shirt size and remarks.
- Extra questions and consents the organisation adds to its booking form, and your answers. These may include health information (such as allergies or medical notes) when the organisation asks for it, and consents such as permission to take photos.
- Bookings: what you booked and when, cancellations and their reason, absences, attendance and check-ins, waiting list entries, gift cards, discount codes, passes, subscriptions and their use, and your acceptance of the organisation's terms (which version, when, and the IP address and browser used).
- Payments and invoices: amounts, payment method, status and the reference of the payment provider, and on invoices the billing name, email address and address. Card and bank details are entered with the payment provider and never reach Plek.
- Emails: the booking emails sent to you (confirmations, reminders, sign-in codes, messages from the organisation) and their delivery status, such as a bounce. Emails never contain details about children or health.
- Notes by the organisation: staff can keep internal notes about a participant.
Inside the organisation, staff only see what their role allows. A coach, for example, sees the name, date of birth, internal notes and medical answers of the participants in their own sessions, but no payment data.
Staff accounts (Plek is controller)
- Name, email address, password (stored only as a hash), preferred language and locale, and the organisations you belong to with your role.
- If you turn on two-step verification: the encrypted secret of your authenticator app and your recovery codes (stored as hashes).
- If you sign in with Google: the unique account identifier, email address and name.
- Invitations you send or receive, and an audit log of important actions (for example who anonymised a customer or changed a role).
Technical data
Our servers and Cloudflare log requests, including IP address, browser, time and the page or API address requested, to keep the service secure and to find and fix errors. We don't use this data to track you or build profiles.
Why we process it and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Taking and managing bookings, payments, attendance and the customer portal | Performance of the contract between you and the organisation (art. 6(1)(b)); Plek acts on the organisation's instructions |
| Health information and other sensitive answers you give in the booking form | Your explicit consent (art. 9(2)(a)) or another ground determined by the organisation; you can leave optional questions empty |
| Invoices and accounting records | Legal obligation (art. 6(1)(c)) |
| Staff accounts and the Plek service for organisations | Performance of our contract with the organisation and its staff (art. 6(1)(b)) |
| Security, preventing abuse, audit logs and backups | Legitimate interest in a safe and reliable service (art. 6(1)(f)) |
| Service emails (booking confirmations, reminders, sign-in codes, account notices) | Performance of the contract (art. 6(1)(b)) |
Plek does not sell personal data, does not show advertising, does not send marketing emails to customers of organisations and does not use your data for profiling or to train AI models.
Google and Microsoft sign-in and Google integrations
Sign in with Google or Microsoft. We only ask for the standard OpenID Connect scopes openid, email and profile, and use the unique account identifier, the email address, whether it is verified and your name to create your account or link it to an existing one. You can unlink a sign-in method in your account.
Google Calendar (optional, for staff). A staff member can connect their Google Calendar so the organisation's sessions appear there. We use this access to create, update and delete the events for the organisation's sessions in your primary calendar. We don't read, store or change your other events.
Gmail (optional, for organisations). An organisation can send its booking emails from its own Gmail address. We use this access to send those emails and to read the email address of the connected account. We don't read, store or analyse your messages.
Plek's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data from Google is only used to provide the features described above, is never sold, never used for advertising, never used to develop, improve or train generalised AI or machine-learning models, and is not read by people unless you ask us to (for support), it is needed for security, or the law requires it. Access tokens are only used for these features and are deleted when you disconnect the integration in Plek; you can also revoke access at any time in your Google account.
Who receives your data
We only use service providers that need the data to run Plek, under contracts that oblige them to protect it:
- Oracle Cloud Infrastructure: servers, database and file storage (such as uploaded images and exports), in a data centre in the European Union.
- Cloudflare: hosting of the web apps, DNS, content delivery and protection against attacks.
- Brevo (Sendinblue SAS, France): sending emails and reporting their delivery. If an organisation connects its own Gmail or mail server, its emails are sent through that instead.
- Payment providers chosen by the organisation: Mollie, Worldline or Payconiq. They process your payment as independent controllers under their own privacy policies.
- Google and Microsoft, only if you use their sign-in or an organisation connects Google Calendar or Gmail.
The organisation you book with sees the data of its own customers and participants. Organisations never see each other's data. We only share data with authorities when the law requires it.
Transfers outside the European Union
Plek's database and files are stored in the European Union. Some providers (Cloudflare, Google, Microsoft) may process data outside the European Economic Area. In that case the transfer is covered by an adequacy decision (such as the EU-U.S. Data Privacy Framework) or by the European Commission's standard contractual clauses.
How long we keep data
- Customer and participant data is kept for as long as the organisation uses Plek, or until the organisation, or you, have it deleted. Each organisation can switch on automatic clean-up: anonymising customers who have been inactive for a number of years, accounts whose email address was never confirmed after a number of months, and clearing booking answers (such as medical notes) a number of months after the session or series ended. These periods are set by the organisation.
- Anonymising removes names, email address, phone number, date of birth, national register number, booking answers, sign-in methods, and the IP address and browser stored with accepted terms. What remains (for example that a booking was paid) can no longer be linked to you.
- Invoices and payment records are kept for as long as accounting and tax law requires (in Belgium currently up to 10 years), even after anonymisation.
- Staff accounts are kept until they are deleted; audit log entries are kept for as long as the organisation's account exists.
- Server logs are kept for a short period, at most 30 days, unless needed to investigate an incident.
- When an organisation stops using Plek, we delete its data within 90 days, except what we must keep by law.
Your rights
You have the right to access your data, to have it corrected or deleted, to restrict or object to its processing, to data portability, and to withdraw consent at any time (without affecting processing before that). In the customer portal of the organisation you book with, you can:
- view and update your details and those of your participants;
- download all the data stored about you and your participants as a file;
- request the deletion of your account. You confirm with a code we email you. If you still have upcoming bookings, your data is anonymised once they are over.
For anything else, contact the organisation you book with, or us at hello@small-victories.co. We answer within one month. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35, 1000 Brussels, www.dataprotectionauthority.be, or with the authority in the country where you live.
Cookies and local storage
Plek does not use advertising, analytics or tracking cookies, so we don't ask for cookie consent. The apps store a few things in your browser's local storage that they need to work: your sign-in session, your chosen language, the organisation you are managing (for staff) and a booking you are completing. Cloudflare may set a strictly necessary cookie to protect the service against bots. Payment providers' pages set their own cookies.
Security
All connections are encrypted (HTTPS). Passwords are stored as hashes, staff can use two-step verification, access within an organisation follows roles and permissions, important actions are logged, and backups are made regularly. If a data breach puts your rights at risk, the organisation and, where required, you and the authority are informed without undue delay.
Children
Participants can be children. Their data is provided by a parent or guardian, who manages the booking from their own customer account. Customer accounts are meant for adults.
Changes to this policy
We may update this policy when Plek or the law changes. The date at the top shows the latest version. We inform organisations and staff of important changes in advance.
Contact
Small Victories, Mellestraat 303, 9090 Merelbeke-Melle, enterprise number BE0793.301.929. Email: hello@small-victories.co.