[operator] (the same as OPERATOR_NAME / PRIVACY_CONTACT_EMAIL)
Representative in the EU, if required
[operator]
Data protection officer, if appointed
[operator]
Security measures (Art. 32)
Passwords hashed with argon2id; Google OAuth tokens and notification-channel URLs encrypted at rest; TLS and secure cookies in production. Host, database and backup security: [operator]
People who book a meeting through a public booking page.
Field
Value
Categories of data
Name, email address, answers to the host’s custom booking fields (free text, may include anything the host asks for), the booking’s title and description when the invitee edits them, the video-meeting link, the booking’s time and language, and emails addressed to the invitee
Scheduling the meeting and sending confirmations, reminders and changes
Lawful basis
[operator]
Recipients
The host; Google Calendar when the host connected Google; the SMTP provider; any notification channel the host configured; Cloudflare Turnstile when enabled. See sub-processors
Retention
BOOKING_RETENTION_DAYS or the host’s own window, measured from the meeting’s end: [operator: your window, or “kept until removed”]. Queued email: about 30 days after it is sent, or after it was queued if never sent
Erasure route
Self-service from the manage link: the booking row is anonymised in place, its queued email deleted. Email queued before migration V34 is cleared only by the 30-day purge. See the operator guide
Username, password hash, Google and SSO subject identifiers, display name, email address, timezone, the text of their meeting types (name, description, location) and booking-field labels, connected Google account email, calendar ids and names, OAuth tokens, notification-channel URLs and labels, password-reset and sign-in tokens
Running the host’s scheduling page and signing them in
Lawful basis
[operator]
Recipients
Google when connected; the SSO identity provider when OIDC_ENABLED is on; the SMTP provider; the host’s own notification channels
Retention
For the life of the account. Password-reset, invitation and sign-in tokens: about a day after they expire. deleted_username: permanently
Erasure route
Account deletion (/me/settings/delete, or /me/users for a site admin) deletes app_user, and every other table cascades away with it. deleted_username keeps a SHA-256 hash of the username permanently, so the name can never be re-registered. email_outbox rows queued before migration V34 have no owner link, so they survive deletion until the age purge
Tables with no personal data of their own (reminder, meeting_type_host, availability_rule,
date_override, date_override_window, notification_channel_meeting_type,
meeting_type_duration) are removed with their parent rows.