Privacy Policy
Last updated:
At Schedio, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our appointment scheduling platform.
1. Introduction
1.1 Who We Are
Schedio ("we," "us," "our") is the data controller responsible for your personal information. We provide a cloud-based appointment scheduling platform for businesses of all sizes.
1.2 Scope of This Policy
This Privacy Policy applies to:
- Our website and web application
- Our mobile applications (if applicable)
- Our APIs and integrations
- Any other services we provide
1.3 Last Updated
This policy was last updated on January 1, 2025. We will notify you of material changes as described in Section 11.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Name and email address
- Business name and details
- Phone number (optional)
- Billing and payment information
- Account preferences and settings
2.2 Customer Data
If you are a business using Schedio (a "Tenant"), you may collect information from your customers through our platform, including:
- Customer names and contact information
- Appointment history and notes
- Any other information you choose to collect
Important: As a Tenant, you are the data controller for your customers' data. You are responsible for ensuring you have appropriate consent and legal basis to collect this information.
2.3 Usage Data
We automatically collect certain information when you use our Service:
- Log data (IP address, browser type, pages visited)
- Device information (device type, operating system)
- Feature usage and interaction data
- Error reports and performance data
2.4 Cookies and Tracking
We use cookies and similar technologies to enhance your experience. For detailed information, please see our Cookie Policy.
3. How We Use Information
We use the information we collect to:
3.1 Provide and Improve Services
- Operate and maintain the Service
- Process appointments and send notifications
- Provide customer support
- Analyze usage to improve features
- Develop new products and services
3.2 Communications
- Send transactional emails (confirmations, reminders)
- Respond to your inquiries
- Send marketing communications (with your consent)
- Notify you of updates to our Service or policies
3.3 Security and Fraud Prevention
- Detect and prevent fraud and abuse
- Monitor for security threats
- Enforce our Terms of Service
3.4 Legal Compliance
- Comply with legal obligations
- Respond to legal requests and court orders
- Protect our rights and interests
4. Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), we process your personal data based on the following legal grounds:
4.1 Contract Performance
Processing necessary to provide the Service you've requested, such as creating your account and processing appointments.
4.2 Legitimate Interests
Processing necessary for our legitimate business interests, such as improving our Service, preventing fraud, and marketing our products (where you haven't opted out).
4.3 Consent
Processing based on your explicit consent, such as sending marketing emails or using certain cookies.
4.4 Legal Obligations
Processing necessary to comply with legal requirements, such as tax reporting or responding to lawful government requests.
5. Data Sharing
We do not sell your personal information. We may share your information in the following circumstances:
5.1 Service Providers
We share data with trusted third parties who help us operate our Service:
- Hosting providers: To store and serve our application
- Email services: To send transactional and marketing emails
- Payment processors: To process payments securely
- Analytics providers: To understand Service usage
All service providers are bound by data processing agreements and may only use your data as instructed by us.
5.2 Legal Requirements
We may disclose information if required by law or in response to valid legal requests (e.g., subpoenas, court orders).
5.3 Business Transfers
If Schedio is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
5.4 With Your Consent
We may share your information for other purposes with your explicit consent.
6. Data Retention
6.1 Active Accounts
We retain your data for as long as your account is active and as necessary to provide the Service.
6.2 After Account Closure
Upon account termination, we retain your data for a limited period (typically 30 days) to allow for reactivation. After this period, data is deleted or anonymized, except where retention is required by law.
6.3 Legal Hold
We may retain certain data longer if required for legal compliance, dispute resolution, or to enforce our agreements.
7. Data Security
We implement robust security measures to protect your data:
7.1 Encryption
- In transit: All data is encrypted using TLS 1.3
- At rest: Sensitive data is encrypted using AES-256
7.2 Access Controls
- Role-based access controls for employees
- Multi-factor authentication available for accounts
- Regular access reviews and audits
7.3 Infrastructure Security
- Hosted on secure, certified data centers
- Regular security assessments and penetration testing
- 24/7 monitoring for security threats
8. Your Rights
Depending on your location, you may have the following rights:
8.1 Access
Request a copy of the personal data we hold about you.
8.2 Rectification
Request correction of inaccurate or incomplete data.
8.3 Erasure
Request deletion of your personal data ("right to be forgotten"), subject to legal requirements.
8.4 Restriction
Request that we limit how we use your data.
8.5 Portability
Request your data in a structured, machine-readable format.
8.6 Object
Object to certain processing activities, including direct marketing.
8.7 Withdraw Consent
Where processing is based on consent, you may withdraw it at any time.
To exercise these rights, please visit our GDPR Rights page or contact us at privacy@schedio.com.
9. International Transfers
9.1 Where We Process Data
Your data may be processed in countries where our service providers are located. These countries may have different data protection laws than your country of residence.
9.2 Safeguards
When transferring data outside the EEA, we implement appropriate safeguards such as:
- Standard Contractual Clauses approved by the European Commission
- Data processing agreements with all service providers
- Technical and organizational measures to protect your data
10. Children's Privacy
Our Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child without parental consent, we will delete that information promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on our website with a new "Last Updated" date
- Sending an email to registered users
- Displaying a prominent notice within the Service
We encourage you to review this policy periodically.
12. Contact & Data Protection Officer
If you have questions about this Privacy Policy or our privacy practices:
General Inquiries
- Email: privacy@schedio.com
- Address: [Company Address]
Data Protection Officer
Our Data Protection Officer can be reached at: dpo@schedio.com
Supervisory Authority
If you are in the EEA and believe we have not addressed your concerns satisfactorily, you have the right to lodge a complaint with your local data protection authority.
Questions about this policy?
If you have any questions about this document, please contact us.
legal@schedio.com