Privacy Policy

1. Data controller

Your organization (or its designated system administrator) is the data controller for work data processed in the System. For privacy requests, contact your IT department or system administrator.

2. Information we collect

2.1 Account information

  • Email address, display name, and profile photo (if uploaded)
  • Password (stored using secure hashing, not as plain text)
  • Role, calendar access, and team membership

2.2 Work data

  • Events, meetings, dates, locations, and attachments
  • Event types and calendar settings (e.g. monthly backgrounds, theme, reminders)
  • Technical logs needed for security and operations

2.3 Notifications

  • Device identifiers (FCM tokens) when you register for push notifications
  • In-app notification history (e.g. event reminders)

3. How we use information

  • Provide and operate calendar and event services
  • Send notifications and reminders according to your settings
  • Maintain security, access control, and system updates
  • Meet legal and organizational compliance obligations

4. Legal basis

Processing is based on performing the service contract and the Provider's legitimate interests in operating a secure internal system.

5. Sharing

We do not sell your personal data. Data may be accessed by:

  • Authorized personnel within your organization (according to role)
  • Infrastructure providers (e.g. hosting) under confidentiality obligations
  • Authorities when required by law

6. Retention

Data is kept as long as needed for the purposes above or per your organization's retention policy. Deleted accounts or data may remain in backups for a limited period per technical policy.

7. Security

We apply reasonable measures including account authentication (OAuth2 / JWT), role-based access, encrypted connections, and network controls. No system is 100% secure—report suspected unauthorized access promptly.

8. Your rights

Where applicable law allows, you may have the right to:

  • Access or request a copy of your personal data
  • Request correction of inaccurate data
  • Request deletion of your account or data (subject to organizational policy)
  • Disable notifications in settings or on your device

Contact your system administrator to exercise these rights.

9. Cookies and sessions

The web application uses session cookies for sign-in. Mobile clients may store tokens on your device. We do not use third-party advertising cookies.

10. Changes

We may update this Policy. The "Last updated" date above indicates the latest version. Continued use after an update means you accept the revised Policy.