Skip to content

Records of processing (Art. 30)

FieldValue
Controller name and contact[operator] (the same as OPERATOR_NAME / PRIVACY_CONTACT_EMAIL)
Representative in the EU, if required[operator]
Data protection officer, if appointed[operator]
Security measures (Art. 32)Passwords hashed with argon2id; Google OAuth tokens and notification-channel URLs encrypted at rest; TLS and secure cookies in production. Host, database and backup security: [operator]

People who book a meeting through a public booking page.

FieldValue
Categories of dataName, email address, answers to the host’s custom booking fields (free text, may include anything the host asks for), the booking’s title and description when the invitee edits them, the video-meeting link, the booking’s time and language, and emails addressed to the invitee
Where it is heldbooking (invitee_name, invitee_email, answers, meet_link, title, description); email_outbox (recipient, subject, html_body, ics_bytes)
PurposeScheduling the meeting and sending confirmations, reminders and changes
Lawful basis[operator]
RecipientsThe host; Google Calendar when the host connected Google; the SMTP provider; any notification channel the host configured; Cloudflare Turnstile when enabled. See sub-processors
RetentionBOOKING_RETENTION_DAYS or the host’s own window, measured from the meeting’s end: [operator: your window, or “kept until removed”]. Queued email: about 30 days after it is sent, or after it was queued if never sent
Erasure routeSelf-service from the manage link: the booking row is anonymised in place, its queued email deleted. Email queued before migration V34 is cleared only by the 30-day purge. See the operator guide

Addresses an invitee adds to a booking.

FieldValue
Categories of dataEmail address, response status, emails addressed to the guest
Where it is heldbooking_guest (email); email_outbox
PurposeInviting the guest and keeping their calendar in step with the meeting
Lawful basis[operator]
RecipientsAs for invitees
RetentionAs for the booking the guest belongs to
Erasure routeGuest rows are deleted when the booking is erased or anonymised by retention, and removed with the booking when the host’s account is deleted

Users with an account on the deployment.

FieldValue
Categories of dataUsername, password hash, Google and SSO subject identifiers, display name, email address, timezone, the text of their meeting types (name, description, location) and booking-field labels, connected Google account email, calendar ids and names, OAuth tokens, notification-channel URLs and labels, password-reset and sign-in tokens
Where it is heldapp_user, owner_settings, meeting_type, booking_field, google_credential, google_calendar, notification_channel, password_reset_token, login_ticket, deleted_username
PurposeRunning the host’s scheduling page and signing them in
Lawful basis[operator]
RecipientsGoogle when connected; the SSO identity provider when OIDC_ENABLED is on; the SMTP provider; the host’s own notification channels
RetentionFor the life of the account. Password-reset, invitation and sign-in tokens: about a day after they expire. deleted_username: permanently
Erasure routeAccount deletion (/me/settings/delete, or /me/users for a site admin) deletes app_user, and every other table cascades away with it. deleted_username keeps a SHA-256 hash of the username permanently, so the name can never be re-registered. email_outbox rows queued before migration V34 have no owner link, so they survive deletion until the age purge

Tables with no personal data of their own (reminder, meeting_type_host, availability_rule, date_override, date_override_window, notification_channel_meeting_type, meeting_type_duration) are removed with their parent rows.

RecipientTransfer mechanism
[operator: one row per sub-processor outside the EEA][operator]