Privacy policy
What we collect, why, for how long, and what you can require of us. Written to be read, not to be survived.
Who is responsible
The data controller for the personal data described in this policy is PUBLISHER LEGAL NAME, REGISTERED ADDRESS.
For any question or request relating to your personal data: [email protected].
Where you use Calenday to receive bookings from your own clients, you are the controller for your invitees' data and Calenday acts as your processor. The terms of that relationship are set out in our data processing agreement.
What we collect
When you create an account: email address, first and last name, password (stored hashed, never in clear text), display language, time zone.
When you use the service: the organisations and brands you create, your availability rules, your event types, your bookings and their history, your contacts, and the technical connection logs.
When you connect an integration: the access and refresh tokens issued by Google, Microsoft, Zoom, Stripe or PayPal, encrypted at rest with AES-GCM, together with the identifier of the connected account. Calenday never sees or stores your password for those services.
When you buy the Lifetime licence: Stripe processes the payment and Calenday retains only the transaction identifier and the licence status. Calenday never receives or stores your card number.
When you browse this website: the pages viewed and the technical data in the HTTP request, in an aggregated and non-identifying form.
Why, and on what legal basis
- To provide the service — creating your account, computing availability, confirming bookings, sending confirmations. Legal basis: performance of the contract.
- To send transactional emails — confirmations, reminders, cancellations. Legal basis: performance of the contract.
- To secure the service — rate limiting, fraud detection, connection logs. Legal basis: legitimate interest in protecting the service and its users.
- To meet accounting and tax obligations — retaining proof of purchase. Legal basis: legal obligation.
- To answer your messages — support and pre-sales exchanges. Legal basis: legitimate interest in responding to a request you made.
Calenday does not sell personal data, does not rent it, does not transfer it to advertising brokers, and does not use it to train machine-learning models.
How long we keep it
- Account data: for as long as your account exists, then deleted within thirty days of deletion.
- Bookings and contacts: for as long as your account exists, or until you delete them.
- Integration tokens: until you disconnect the integration, then deleted immediately.
- Accounting records: for the statutory period, currently ACCOUNTING RETENTION.
- Connection and security logs: twelve months.
Who we share it with
Calenday relies on the following processors, each bound by a contract that restricts them to processing data on our instructions:
- {{DATABASE_PROVIDER}} — database, authentication and storage, in the DATA REGION region.
- {{HOSTING_PROVIDER}} — application hosting.
- Stripe — payment processing for the Lifetime licence, and, where you enable it, payment for your own bookings.
- PayPal — where you enable it, payment for your own bookings.
- AcumbaMail — sending transactional email.
- Google, Microsoft, Zoom — only where you have connected the corresponding integration, and only for what that integration requires.
Where a transfer outside the European Economic Area takes place, it is governed by the European Commission's standard contractual clauses or by an adequacy decision.
Your rights
Under the GDPR you may request access to your data, its rectification, its erasure, the restriction of its processing, its portability in a machine-readable format, and you may object to processing based on legitimate interest.
Contacts and booking history can be exported to CSV from your dashboard at any time, without contacting us. For anything else, write to [email protected]. Your request will be acknowledged within seventy-two hours and answered within one month.
If you believe your rights are not respected, you may lodge a complaint with your national supervisory authority — in France, the CNIL (cnil.fr).
Security
Third-party tokens are encrypted at rest with AES-GCM. Every database table enforces row-level security, so data is scoped to an organisation at the database layer and not only in application code. Accounts can require a TOTP second factor. Payment webhook signatures are verified and de-duplicated before anything is written.
Calenday holds no SOC 2, ISO 27001 or HIPAA certification. We describe the measures actually in place rather than display a badge we do not have.
Self-hosting
If you deploy Calenday on your own infrastructure, you are the sole controller of the data stored there. The publisher has no access to it, and this policy then applies only to your use of this website and to any purchase of a licence.
Changes
This policy may be updated. Any material change is announced by email to account holders at least fifteen days before it takes effect.