Privacy Policy
Last updated: 23 September 2026
This policy explains which personal data we process when you use our website, the web app or the iOS app, book an appointment through Calenytics or take part in a scheduling poll — and which rights you have.
Summary
- The iOS app analyses your calendar on your device only. Calendar content never leaves the device.
- In the web app we store only what you create yourself (account, availability, booking pages, scheduling polls, calendar subscriptions) and what guests and participants enter there.
- Website analytics only runs with your consent, using a self-hosted, cookieless tool (Umami).
- We do not sell data, do not use advertising trackers and do not build profiles.
- You can delete your account yourself at any time; all associated data is removed immediately.
Controller
Seisl Benjamin
Am Grünen Prater 11, 1020 Vienna, Austria
Email: contact@codequadrat.com
Phone: +43 677 64400670
We have not appointed a data protection officer because the requirements of Art. 37 GDPR are not met. You can reach us about any data protection matter at the address above.
Who is responsible for what?
There are two kinds of relationship in Calenytics, and they differ under data protection law:
- Users: Anyone who creates an account and runs booking pages, scheduling polls or calendar subscriptions is our contractual partner. We are the controller for account, usage and billing data.
- Guests, participants and subscribers: Anyone who books through a user's booking page, takes part in their scheduling poll or subscribes to their schedule is primarily in a relationship with that user. The user (host or organiser) is the controller for this data; we process it on their behalf under Art. 28 GDPR.
The details of this processing are set out in our Data Processing Agreement. As a guest or participant you can contact the respective host about your data — or us, in which case we forward your request and help the host respond. We remain independently responsible for operating and securing the platform itself (e.g. server logs, bot protection, abuse prevention).
Visiting the website and web app
Server logs
- Data
- IP address, date and time, requested address, status code, amount of data transferred, referrer, browser and operating system (user agent)
- Purpose
- Delivering pages, stability, error analysis, defence against attacks and abuse
- Legal basis
- Art. 6(1)(f) GDPR — our legitimate interest in secure, uninterrupted operation
- Retention
- short-term, usually a few days and no longer than 30 days; longer only where a specific security incident must be investigated
Cookies and local storage
We only use cookies and browser storage that are strictly necessary. Under § 165(3) of the Austrian Telecommunications Act 2021 these do not require consent. We do not set advertising or marketing cookies.
| Name | Where | Purpose | Duration |
|---|---|---|---|
| cookie-consent (local storage) | Website | remembers your choice in the cookie notice | until you change it or clear browser storage |
| NEXT_LOCALE (cookie) | Website | selected language | up to 1 year |
| sb-…-auth-token (cookies) | Web app | sign-in and session | until you sign out or the session expires |
| calenytics-locale (cookie and local storage) | Web app | selected language | 1 year |
| Sidebar state (local storage) | Web app | whether the navigation is expanded | until you clear browser storage |
You can change or withdraw your choice in the cookie notice at any time via the “Cookie settings” link in the website footer.
Analytics with Umami
If you consent to analytics in the cookie notice, we load Umami, an open-source web analytics tool that we run on our own servers (analytics.codequadrat.com). Umami sets no cookies and does not store IP addresses. It records pages visited, referrer and UTM campaign parameters, browser, operating system, device type, screen size, language, the country derived from the IP address, and individual interactions without personal reference — for example a click on a subscribe button, recorded with the schedule concerned and its position on the page. Page views within one visit are grouped by a check value that changes monthly, so you cannot be recognised over a longer period. The data does not leave our infrastructure.
- Legal basis
- Art. 6(1)(a) GDPR — your consent, which you can withdraw at any time with effect for the future
- Retention
- no longer than 24 months, after which raw data is deleted
Free tools
Tools such as the Timezone Meeting Planner run entirely in your browser. Your input is neither sent to us nor stored. If you share a link with parameters, you decide who receives it.
Web app account
- Data
- email address, password (hashed only), confirmation status, time of sign-up and sign-ins, name, language, time zone, location presets and other settings
- Purpose
- Providing your account, sign-in, account security, support
- Legal basis
- Art. 6(1)(b) GDPR — performance of the user agreement
- Retention
- until you delete your account
You can delete your account at any time in the settings. This removes your profile, availability, meeting types, bookings, organisations, scheduling polls including all answers, and calendar subscriptions including their statistics in one step; public links and feeds stop working. The only exception is data we must retain by law (see “Plans and payment”).
Plans and payment
Paid plans are not sold by Calenytics itself but by our reseller Creem (Armitage Labs OÜ, Tallinn, Estonia) acting as merchant of record. Creem handles payment, invoicing and VAT and is an independent controller for the payment data it processes; Creem's privacy policy applies. We do not receive card or bank details.
- Data we receive
- selected plan, term and status of the subscription, customer and subscription identifiers at Creem, time of payment events
- Purpose
- Activating the purchased plan, managing the subscription
- Legal basis
- Art. 6(1)(b) GDPR; for accounting records Art. 6(1)(c) GDPR
- Retention
- for the duration of the subscription; logs of payment events as accounting records for seven years (§ 132 Austrian Federal Fiscal Code) — after account deletion without any link to the account
Booking pages, availability and organisations
As a host
If you run booking pages, we store your availability windows and recurrences, meeting types (duration, lead time, buffers, locations), bookings and technical tokens for the public booking page and optional ICS feeds. If you create an organisation, we store its name, logo and accent colour; they appear on the pages for which you select that organisation. The legal basis is Art. 6(1)(b) GDPR; data is stored until you delete the entries or your account.
As a guest
If you book an appointment through a host's page, we process on the host's behalf your name, email address, an optional message, the selected time and time zone, meeting type and location, the booking status and a token that lets you reschedule or cancel the appointment yourself. This creates the booking, shows it to the host and sends you confirmations and management links by email. The host sees your details and decides how long to keep the booking; when the host deletes it or their account, your data is deleted too.
Scheduling polls
If you create a scheduling poll as an organiser, we store its basics (title, description, location, the organiser name shown to participants, time zone, optional reply deadline), the times you propose and a technical token that powers the public voting page.
Anyone voting through that link submits a name, one answer per proposed time (yes, maybe or no) and — optional or required depending on the organiser's settings — an email address, plus an optional note; we also store when the answer was given. If an address is given, we send a confirmation to it containing a personal link for changing the answer later; without an address we send nothing. Of that personal link we store only a non-reversible check value, not the link itself.
The organiser always sees every name, address and answer — including when they have chosen not to show participants each other's answers. Participants can change or fully withdraw their answer at any time through their personal link; the organiser can delete individual answers or the entire poll. There is currently no automatic deletion period. When the organiser sets a final time, no invitation is sent.
Calendar subscriptions and ICS feeds
Published schedules
If you create a calendar subscription, we store the calendar (name, description, time zone, display settings), areas such as stages or rooms, the entries you add (title, date or time range, location, description, link and, where applicable, people involved) and published versions. We serve this content through an ICS feed to anyone who knows the link. Do not enter personal data about third parties unless you have a basis to publish it. You can disable the feed, rotate the token or delete the calendar and its entries at any time.
Access statistics
For each calendar subscription we keep access statistics so that whoever publishes it can judge its reach. When a calendar app fetches the feed, we derive a non-reversible check value from the IP address, user agent and calendar identifier using a server-side secret. The IP address and user agent themselves are not stored, and because the calendar identifier goes into the check value, the same request cannot be linked across two calendars. We additionally record the broad category of calendar app (such as Apple, Google or Outlook), the time and number of requests, and daily totals. This yields estimated subscriber figures only; individuals are neither identified nor profiled.
- Legal basis
- Art. 6(1)(f) GDPR — legitimate interest in providing reach analytics to publishing users and in enforcing plan limits
- Retention
- check values 180 days after the last request, daily totals about 13 months; deleting a calendar deletes its statistics
Availability and booking feeds
Optional ICS feeds can bring your free or busy times and booked appointments (meeting type with the guest's name, time and location) into the calendar apps of your choice. Anyone who knows the feed URL can see the data the feed is designed to expose; treat it like a password.
Bot protection on public pages
We protect public booking and voting pages against automated submissions and spam with Cloudflare Turnstile. Cloudflare receives the data technically required for the check, in particular IP address, browser and device information and interaction signals. The provider is Cloudflare, Inc., USA; Cloudflare is certified under the EU-US Data Privacy Framework. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in preventing abuse.
When loading available slots, your browser also sends your time zone so that times are displayed correctly; on voting pages the time zone is detected and used in the browser only.
Emails
We send sign-up and security emails, booking confirmations, links to reschedule or cancel and scheduling poll confirmations through ZeptoMail (Zoho Corporation B.V., Netherlands) from a data centre in the EU. Recipient address, subject, content and delivery logs are processed. The legal basis is Art. 6(1)(b) GDPR, for security messages additionally point (f). We do not send newsletters or promotional emails.
AI assistants and integrations (MCP)
You can connect AI assistants and other applications to your account through the Model Context Protocol (MCP). A connection is only established if you explicitly approve it on our consent page (OAuth). The connected application can then read and edit your calendar subscriptions on your behalf — it has no access to bookings, guest data, scheduling polls or payment data.
What the connected application does with the data it retrieves is determined by its provider (e.g. the provider of your AI assistant) under its own terms, and that provider is responsible for it. You can see and disconnect connected applications at any time in the web app settings. The legal basis is Art. 6(1)(b) GDPR.
Contact, support and job applications
If you email us, we process your address and the content of your message in order to reply (Art. 6(1)(b) GDPR where related to a contract, otherwise point (f)). We delete the correspondence once it is resolved and no retention obligation applies. We keep job applications for seven months after the process ends in order to defend against claims and delete them afterwards — unless you consent to longer retention.
iOS app
The app asks for permission to access your calendar. It calculates analytics, goals and habits on your device only; calendar content is transmitted neither to us nor to third parties. Notifications about goals and habits are scheduled locally if you enable them. You can revoke calendar access at any time in iOS Settings; uninstalling the app removes its local data.
Apple is responsible for downloads, updates and any purchases in the App Store; Apple's privacy policy applies. We only receive anonymous crash and usage statistics from Apple if you have allowed this in iOS Settings.
Recipients and processors
We share personal data only with service providers that help us operate our services, and only to the extent necessary. We have agreements under Art. 28 GDPR with all processors.
| Provider | Task | Location |
|---|---|---|
| Supabase Inc., USA | Database, sign-in, server functions of the web app | EU data centre; access from the USA possible |
| Hosting provider of our servers | Running the website, web app, content management system and Umami | EU |
| Zoho Corporation B.V. (ZeptoMail), Netherlands | Sending emails | EU |
| Cloudflare, Inc., USA | Bot protection (Turnstile) | worldwide, DPF-certified |
| Armitage Labs OÜ (Creem), Estonia | Selling and billing paid plans — independent controller | EU; payment processing via Stripe |
| Apple Inc. / Apple Distribution International Ltd. | Distribution of the iOS app — independent controller | Ireland / USA |
Beyond that we only disclose data where we are legally obliged to (for example to authorities or courts) or where it is necessary to enforce our rights.
Transfers to third countries
Where data is transferred to or accessible from countries outside the EEA — in particular the USA — this is based on the adequacy decision for the EU-US Data Privacy Framework where the recipient is certified, and otherwise on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR) together with supplementary safeguards. You can request a copy of these safeguards.
Your rights
You have the following rights with respect to us:
- Access to your data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) — for your account also at any time yourself in the settings
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on our legitimate interest (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR), for example via the cookie settings
To exercise them, write to contact@codequadrat.com. We respond within one month; we may ask questions to verify your identity.
You also have the right to lodge a complaint with a data protection supervisory authority. In Austria this is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, www.dsb.gv.at.
Security
All connections are encrypted with TLS. In the database, row level security restricts every record to its owner; public endpoints only read the fields released for them. Passwords are stored as hashes only. Secret links — booking pages, scheduling polls, personal answer links and ICS feeds — are based on random tokens that you can rotate at any time. Treat these links like passwords.
No automated decision-making
We do not make automated decisions within the meaning of Art. 22 GDPR and do not carry out profiling. Available slots are calculated purely by rules from the host's settings.
Children
Calenytics is not directed at children. Only persons aged 14 or over may create an account, minors with the consent of their parents or guardians. If we learn that data of a child under 14 is being processed without such consent, we delete it.
Changes
We update this privacy policy when our services, providers or the law change. The version published here applies. We additionally inform registered users of material changes by email or in the web app.