Privacy Policy
Last updated: 11/10/2026
Translation provided for information only: only the French version is legally binding.
1. Who we are
For any question about your personal data, you can contact us at: contact@calendrio.fr.
2. What data we collect
Depending on whether you use Calendrio as a professional or as a client of a professional, we collect:
- If you are a professional: last name, first name, email, phone, company name, business sector, address, the hours and services you set up, as well as the data of your own clients that you enter in the app.
- If you are a client of a professional: last name, first name, email, phone, and the history of your appointments with this professional.
- If you buy a gift card or a package: your name and email, and those of the recipient if you enter one, to send them the card and manage its use (payment is processed by Stripe).
- Invitations and documents: if someone invites you to an event, we keep your email address (and the name given by the person inviting you) and your reply, to send you the invitation and a reminder the day before. Documents attached to an appointment or event (PDF or photo) are stored in a protected space, accessible only through a secret link sent to the people concerned, until they are deleted by the person who added them or that person's account is deleted. Avoid including health data unless it is necessary.
- For your appointment reminders: if you turn on notifications, your device's technical address (provided by your browser or by Google Firebase for the Android app), to send them to you; your consent for WhatsApp and your choice to accept reminder calls or not. During a reminder call, the key you choose (confirm, unable to come, stop being called) is recorded; the conversation is not recorded. You can change everything in your client area, under “My reminders”.
- If you call a professional who uses missed-call response: your phone number, to send you an SMS with their booking link, and the voice message you choose to leave, passed on to the professional.
- If you send a business request (“Find a pro” page): the contact details and the description of the need, passed on to no more than 3 professionals so they can reply to you.
- Directory: if a professional agrees, their business name, profession and business address appear in Calendrio's public directory.
- If you sign up for a waiting list: first name, email and, if you provide it, phone number, only to let you know that a spot has opened up on the chosen date. The sign-up is deleted no later than 30 days after that date.
- If you connect your Google account: we access your Google Calendar only as far as needed to create events matching your Calendrio appointments, generate a Google Meet video link automatically, and prevent Calendrio from offering a slot that is already taken in your personal calendar. We only read and display the times of your personal events (to avoid double bookings and let you see them), never their detailed content beyond the title.
- If you connect your Microsoft account (Outlook.com or Microsoft 365): we read and write to your Outlook calendar only to show your appointments in your Calendrio calendar, add your Calendrio appointments to it and avoid double bookings. This data is used for nothing else and is never passed on to third parties. You can remove this access at any time from your Settings (“Disconnect” button) or from your Microsoft account settings.
- If you use the Calendrio assistant (AI): the messages you write to it and the account information needed to answer them (for example your time slots, your appointments or your client list if you ask it to look them up). No action is taken without your confirmation.
- If you use the mobile app: the same data as on the website. The app does not access your location, contacts or photos, and uses no advertising identifier.
- Technical data: IP address, connection data, technical error logs, for security purposes and to keep the service running properly.
3. Use of data from your Google account
Calendrio's use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
In practice, this means that:
- Your Google Calendar data is only used to provide the features you have explicitly enabled (creating events, generating a Meet link, detecting busy slots) — never for advertising purposes.
- We never transfer this data to third parties, unless required by law.
- No human at Calendrio manually views the content of your Google Calendar, except where technically necessary for support with your explicit prior consent.
- You can revoke this access at any time from your Profile page ("Disconnect" button), or directly from your Google account's security settings.
4. Why we use this data
- Performance of the contract: providing the appointment booking, client management and reminder service you subscribed to.
- Legitimate interest: improving the service, preventing fraud, ensuring the security of the platform.
- Consent: for sending marketing communications (client follow-up campaigns), always with a simple way to opt out.
- The professional's legitimate interest: messages related to your past appointments with them (a spot opened up at your usual time, an offer to book your usual time again, a review request after a visit). Each message contains a link to stop receiving them.
5. Who we share this data with
We never sell your data. It may be passed on to the following categories of providers, strictly to keep the service running:
- Hosting — hosting of the database and website, within the European Union.
- Third-party calendar providers — only if you connect your account, for calendar sync.
- Payment provider — for secure processing of payments and subscriptions. We never store your bank details.
- Email, SMS, WhatsApp and call providers (including Twilio) — to send confirmations, reminders and follow-up campaigns, reminder calls by a voice assistant (a synthetic voice that states it is an artificial intelligence), and to answer missed calls (voice message, SMS).
- Notification services (your browser's service: Google, Mozilla, Apple or Microsoft; Google Firebase for the Android app) — only to deliver the notifications you have turned on. Their content is end-to-end encrypted for browsers.
- Artificial intelligence provider — to process the messages you send to the Calendrio assistant. This provider does not use this data to train its models.
- Mapping service — for entering addresses and calculating travel time for home appointments.
Some of these providers are located outside the European Union (in particular in the United States). These transfers are covered by the safeguards provided by the GDPR (European Commission standard contractual clauses or Data Privacy Framework).
Linked accounts (professionals). If you agree to link your account to another Calendrio account, that other account can see the times of your appointments and group sessions as “Busy”, without your clients' names or contact details, and your page can be shown on theirs if you have chosen this. Your Google or Outlook calendars are never passed on to them. You can remove the link at any time from your Settings.
Calendrio Prospection. For a client of this service, we keep the professional email address they connect and its password, encrypted, used only to send their campaigns and detect replies. Their target list is made of companies from the public business register (Sirene) and the professional address they publish themselves; the client reviews and approves it. Each email carries the client's identity and a simple way to stop being contacted (reply “STOP”), applied immediately. For these sends, Calendrio acts on behalf of the client.
6. Directory, appointment requests and referral partners
Professional directory. The “Find a pro” page shows, in addition to the professionals registered on Calendrio, active establishments from the public business register (INSEE's Sirene database, open data): name or trading name, establishment address and activity. Establishments with restricted disclosure are never shown, and a sole proprietor without a trading name only appears with their first name, the initial of their last name and their city. Legal basis: our legitimate interest in allowing clients to contact these professionals. Any professional can object at any time, without giving a reason, from the Remove my establishment page or the link included in each message.
Appointment requests. When you send a request to a professional who does not use Calendrio yet, we keep your first name, your email address, your phone number, the service, your availability and your message. We pass on to the professional your first name, the service and your availability; your contact details and your message are only shared with them if they create their account to reply to you. To notify them, we only use their public professional contact details (or the number you give us), only when a client contacts them, with a link to stop being contacted. If we don't know them, they are searched for automatically on the web (the establishment's website, public professional pages and directories) using an artificial intelligence service (Anthropic), and their replies receive an automatic response; they can reply STOP at any time. Requests with no follow-up are closed after 30 days and deleted no later than 12 months after they were sent.
Referral partners. For people registered in the referral partner program, we process their identification and contact data, as well as the list of professionals they recommended and the corresponding commission amounts (legal basis: performance of the contract; accounting retention: 10 years). A referral partner sees the name and subscription status of the professionals they recommended, never their clients or their appointments.
7. How long we keep your data
Your data is kept for the entire duration of your relationship with Calendrio (or with the professional who registered you), then archived or deleted in accordance with the applicable legal retention periods. You can delete your account at any time from the app or the website: see Delete your account.
8. Your rights
In accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act (loi Informatique et Libertés), you have the following rights over your personal data:
- Right to access, correct and erase your data.
- Right to restrict and object to processing.
- Right to data portability.
- Right to withdraw your consent at any time, when processing is based on it.
You can delete your account yourself (see how). To exercise your other rights, contact us at contact@calendrio.fr. You also have the right to lodge a complaint with the CNIL (French Data Protection Authority).
9. Cookies
Calendrio only uses cookies that are strictly necessary for the service to work (keeping you logged in, protection against CSRF attacks and, in the mobile app, remembering your login for up to 6 months so you aren't asked for your password again; it is cleared as soon as you log out). When you follow a partner's referral link (address containing “?ap=”), a cookie only stores that partner's code for 90 days, in order to credit them with any sign-up you make; it does not track your browsing. We use no advertising cookies or third-party trackers for commercial audience measurement. To know which pages are useful, we simply count the pages viewed (page viewed, referring site such as “Google”, device type), with no cookie, no IP address and no identifier: these anonymous counters cannot identify anyone and are not shared.
10. Security
We implement reasonable technical and organizational measures to protect your data (encrypted HTTPS connections, hashed passwords, restricted database access). Since no system is 100% foolproof, we encourage you to use a strong and unique password for your account.
11. Changes to this policy
This policy may be updated from time to time. The date of the last update is shown at the top of this page. In the event of a substantial change, we will inform you by email or by a notification on the platform.