Privacy Policy

    Last updated: 23 September 2026

    This policy explains which personal data we process when you use our website, the web app or the iOS app, book an appointment through Calenytics or take part in a scheduling poll — and which rights you have.

    Summary

    • The iOS app analyses your calendar on your device only. Calendar content never leaves the device.
    • In the web app we store only what you create yourself (account, availability, booking pages, scheduling polls, calendar subscriptions) and what guests and participants enter there.
    • Website analytics only runs with your consent, using a self-hosted, cookieless tool (Umami).
    • We do not sell data, do not use advertising trackers and do not build profiles.
    • You can delete your account yourself at any time; all associated data is removed immediately.

    Controller

    Seisl Benjamin

    Am Grünen Prater 11, 1020 Vienna, Austria

    Email: contact@codequadrat.com

    Phone: +43 677 64400670

    We have not appointed a data protection officer because the requirements of Art. 37 GDPR are not met. You can reach us about any data protection matter at the address above.

    Who is responsible for what?

    There are two kinds of relationship in Calenytics, and they differ under data protection law:

    • Users: Anyone who creates an account and runs booking pages, scheduling polls or calendar subscriptions is our contractual partner. We are the controller for account, usage and billing data.
    • Guests, participants and subscribers: Anyone who books through a user's booking page, takes part in their scheduling poll or subscribes to their schedule is primarily in a relationship with that user. The user (host or organiser) is the controller for this data; we process it on their behalf under Art. 28 GDPR.

    The details of this processing are set out in our Data Processing Agreement. As a guest or participant you can contact the respective host about your data — or us, in which case we forward your request and help the host respond. We remain independently responsible for operating and securing the platform itself (e.g. server logs, bot protection, abuse prevention).

    Visiting the website and web app

    Server logs

    Data
    IP address, date and time, requested address, status code, amount of data transferred, referrer, browser and operating system (user agent)
    Purpose
    Delivering pages, stability, error analysis, defence against attacks and abuse
    Legal basis
    Art. 6(1)(f) GDPR — our legitimate interest in secure, uninterrupted operation
    Retention
    short-term, usually a few days and no longer than 30 days; longer only where a specific security incident must be investigated

    Cookies and local storage

    We only use cookies and browser storage that are strictly necessary. Under § 165(3) of the Austrian Telecommunications Act 2021 these do not require consent. We do not set advertising or marketing cookies.

    NameWherePurposeDuration
    cookie-consent (local storage)Websiteremembers your choice in the cookie noticeuntil you change it or clear browser storage
    NEXT_LOCALE (cookie)Websiteselected languageup to 1 year
    sb-…-auth-token (cookies)Web appsign-in and sessionuntil you sign out or the session expires
    calenytics-locale (cookie and local storage)Web appselected language1 year
    Sidebar state (local storage)Web appwhether the navigation is expandeduntil you clear browser storage

    You can change or withdraw your choice in the cookie notice at any time via the “Cookie settings” link in the website footer.

    Analytics with Umami

    If you consent to analytics in the cookie notice, we load Umami, an open-source web analytics tool that we run on our own servers (analytics.codequadrat.com). Umami sets no cookies and does not store IP addresses. It records pages visited, referrer and UTM campaign parameters, browser, operating system, device type, screen size, language, the country derived from the IP address, and individual interactions without personal reference — for example a click on a subscribe button, recorded with the schedule concerned and its position on the page. Page views within one visit are grouped by a check value that changes monthly, so you cannot be recognised over a longer period. The data does not leave our infrastructure.

    Legal basis
    Art. 6(1)(a) GDPR — your consent, which you can withdraw at any time with effect for the future
    Retention
    no longer than 24 months, after which raw data is deleted

    Free tools

    Tools such as the Timezone Meeting Planner run entirely in your browser. Your input is neither sent to us nor stored. If you share a link with parameters, you decide who receives it.

    Web app account

    Data
    email address, password (hashed only), confirmation status, time of sign-up and sign-ins, name, language, time zone, location presets and other settings
    Purpose
    Providing your account, sign-in, account security, support
    Legal basis
    Art. 6(1)(b) GDPR — performance of the user agreement
    Retention
    until you delete your account

    You can delete your account at any time in the settings. This removes your profile, availability, meeting types, bookings, organisations, scheduling polls including all answers, and calendar subscriptions including their statistics in one step; public links and feeds stop working. The only exception is data we must retain by law (see “Plans and payment”).

    Plans and payment

    Paid plans are not sold by Calenytics itself but by our reseller Creem (Armitage Labs OÜ, Tallinn, Estonia) acting as merchant of record. Creem handles payment, invoicing and VAT and is an independent controller for the payment data it processes; Creem's privacy policy applies. We do not receive card or bank details.

    Data we receive
    selected plan, term and status of the subscription, customer and subscription identifiers at Creem, time of payment events
    Purpose
    Activating the purchased plan, managing the subscription
    Legal basis
    Art. 6(1)(b) GDPR; for accounting records Art. 6(1)(c) GDPR
    Retention
    for the duration of the subscription; logs of payment events as accounting records for seven years (§ 132 Austrian Federal Fiscal Code) — after account deletion without any link to the account

    Booking pages, availability and organisations

    As a host

    If you run booking pages, we store your availability windows and recurrences, meeting types (duration, lead time, buffers, locations), bookings and technical tokens for the public booking page and optional ICS feeds. If you create an organisation, we store its name, logo and accent colour; they appear on the pages for which you select that organisation. The legal basis is Art. 6(1)(b) GDPR; data is stored until you delete the entries or your account.

    As a guest

    If you book an appointment through a host's page, we process on the host's behalf your name, email address, an optional message, the selected time and time zone, meeting type and location, the booking status and a token that lets you reschedule or cancel the appointment yourself. This creates the booking, shows it to the host and sends you confirmations and management links by email. The host sees your details and decides how long to keep the booking; when the host deletes it or their account, your data is deleted too.

    Scheduling polls

    If you create a scheduling poll as an organiser, we store its basics (title, description, location, the organiser name shown to participants, time zone, optional reply deadline), the times you propose and a technical token that powers the public voting page.

    Anyone voting through that link submits a name, one answer per proposed time (yes, maybe or no) and — optional or required depending on the organiser's settings — an email address, plus an optional note; we also store when the answer was given. If an address is given, we send a confirmation to it containing a personal link for changing the answer later; without an address we send nothing. Of that personal link we store only a non-reversible check value, not the link itself.

    The organiser always sees every name, address and answer — including when they have chosen not to show participants each other's answers. Participants can change or fully withdraw their answer at any time through their personal link; the organiser can delete individual answers or the entire poll. There is currently no automatic deletion period. When the organiser sets a final time, no invitation is sent.

    Calendar subscriptions and ICS feeds

    Published schedules

    If you create a calendar subscription, we store the calendar (name, description, time zone, display settings), areas such as stages or rooms, the entries you add (title, date or time range, location, description, link and, where applicable, people involved) and published versions. We serve this content through an ICS feed to anyone who knows the link. Do not enter personal data about third parties unless you have a basis to publish it. You can disable the feed, rotate the token or delete the calendar and its entries at any time.

    Access statistics

    For each calendar subscription we keep access statistics so that whoever publishes it can judge its reach. When a calendar app fetches the feed, we derive a non-reversible check value from the IP address, user agent and calendar identifier using a server-side secret. The IP address and user agent themselves are not stored, and because the calendar identifier goes into the check value, the same request cannot be linked across two calendars. We additionally record the broad category of calendar app (such as Apple, Google or Outlook), the time and number of requests, and daily totals. This yields estimated subscriber figures only; individuals are neither identified nor profiled.

    Legal basis
    Art. 6(1)(f) GDPR — legitimate interest in providing reach analytics to publishing users and in enforcing plan limits
    Retention
    check values 180 days after the last request, daily totals about 13 months; deleting a calendar deletes its statistics

    Availability and booking feeds

    Optional ICS feeds can bring your free or busy times and booked appointments (meeting type with the guest's name, time and location) into the calendar apps of your choice. Anyone who knows the feed URL can see the data the feed is designed to expose; treat it like a password.

    Bot protection on public pages

    We protect public booking and voting pages against automated submissions and spam with Cloudflare Turnstile. Cloudflare receives the data technically required for the check, in particular IP address, browser and device information and interaction signals. The provider is Cloudflare, Inc., USA; Cloudflare is certified under the EU-US Data Privacy Framework. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in preventing abuse.

    When loading available slots, your browser also sends your time zone so that times are displayed correctly; on voting pages the time zone is detected and used in the browser only.

    Emails

    We send sign-up and security emails, booking confirmations, links to reschedule or cancel and scheduling poll confirmations through ZeptoMail (Zoho Corporation B.V., Netherlands) from a data centre in the EU. Recipient address, subject, content and delivery logs are processed. The legal basis is Art. 6(1)(b) GDPR, for security messages additionally point (f). We do not send newsletters or promotional emails.

    AI assistants and integrations (MCP)

    You can connect AI assistants and other applications to your account through the Model Context Protocol (MCP). A connection is only established if you explicitly approve it on our consent page (OAuth). The connected application can then read and edit your calendar subscriptions on your behalf — it has no access to bookings, guest data, scheduling polls or payment data.

    What the connected application does with the data it retrieves is determined by its provider (e.g. the provider of your AI assistant) under its own terms, and that provider is responsible for it. You can see and disconnect connected applications at any time in the web app settings. The legal basis is Art. 6(1)(b) GDPR.

    Contact, support and job applications

    If you email us, we process your address and the content of your message in order to reply (Art. 6(1)(b) GDPR where related to a contract, otherwise point (f)). We delete the correspondence once it is resolved and no retention obligation applies. We keep job applications for seven months after the process ends in order to defend against claims and delete them afterwards — unless you consent to longer retention.

    iOS app

    The app asks for permission to access your calendar. It calculates analytics, goals and habits on your device only; calendar content is transmitted neither to us nor to third parties. Notifications about goals and habits are scheduled locally if you enable them. You can revoke calendar access at any time in iOS Settings; uninstalling the app removes its local data.

    Apple is responsible for downloads, updates and any purchases in the App Store; Apple's privacy policy applies. We only receive anonymous crash and usage statistics from Apple if you have allowed this in iOS Settings.

    Recipients and processors

    We share personal data only with service providers that help us operate our services, and only to the extent necessary. We have agreements under Art. 28 GDPR with all processors.

    ProviderTaskLocation
    Supabase Inc., USADatabase, sign-in, server functions of the web appEU data centre; access from the USA possible
    Hosting provider of our serversRunning the website, web app, content management system and UmamiEU
    Zoho Corporation B.V. (ZeptoMail), NetherlandsSending emailsEU
    Cloudflare, Inc., USABot protection (Turnstile)worldwide, DPF-certified
    Armitage Labs OÜ (Creem), EstoniaSelling and billing paid plans — independent controllerEU; payment processing via Stripe
    Apple Inc. / Apple Distribution International Ltd.Distribution of the iOS app — independent controllerIreland / USA

    Beyond that we only disclose data where we are legally obliged to (for example to authorities or courts) or where it is necessary to enforce our rights.

    Transfers to third countries

    Where data is transferred to or accessible from countries outside the EEA — in particular the USA — this is based on the adequacy decision for the EU-US Data Privacy Framework where the recipient is certified, and otherwise on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR) together with supplementary safeguards. You can request a copy of these safeguards.

    Your rights

    You have the following rights with respect to us:

    • Access to your data (Art. 15 GDPR)
    • Rectification of inaccurate data (Art. 16 GDPR)
    • Erasure (Art. 17 GDPR) — for your account also at any time yourself in the settings
    • Restriction of processing (Art. 18 GDPR)
    • Data portability (Art. 20 GDPR)
    • Objection to processing based on our legitimate interest (Art. 21 GDPR)
    • Withdrawal of consent with effect for the future (Art. 7(3) GDPR), for example via the cookie settings

    To exercise them, write to contact@codequadrat.com. We respond within one month; we may ask questions to verify your identity.

    You also have the right to lodge a complaint with a data protection supervisory authority. In Austria this is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, www.dsb.gv.at.

    Security

    All connections are encrypted with TLS. In the database, row level security restricts every record to its owner; public endpoints only read the fields released for them. Passwords are stored as hashes only. Secret links — booking pages, scheduling polls, personal answer links and ICS feeds — are based on random tokens that you can rotate at any time. Treat these links like passwords.

    No automated decision-making

    We do not make automated decisions within the meaning of Art. 22 GDPR and do not carry out profiling. Available slots are calculated purely by rules from the host's settings.

    Children

    Calenytics is not directed at children. Only persons aged 14 or over may create an account, minors with the consent of their parents or guardians. If we learn that data of a child under 14 is being processed without such consent, we delete it.

    Changes

    We update this privacy policy when our services, providers or the law change. The version published here applies. We additionally inform registered users of material changes by email or in the web app.