z
Legal

Privacy Policy

Last updated: May 14, 2026 · Effective: May 14, 2026

Perizer, Inc. (“Perizer,” “we,” “us,” or “our”) operates Calen360, a scheduling and calendar management platform. This Privacy Policy explains how we collect, use, disclose, and protect personal information about you when you use our services. We are committed to transparency and to respecting your privacy rights under applicable law, including the General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act (“CCPA”).

Short version: We collect only the information necessary to provide and improve the Service. We do not sell your personal data. You have the right to access, correct, or delete your data at any time.

1. Information We Collect

We collect several categories of information to deliver and improve the Service. The types of information we collect depend on how you interact with Calen360.

1.1 Information You Provide Directly

CategoryExamples
Account InformationName, email address, username, password (hashed)
Profile DetailsProfile photo, time zone, locale preferences, work hours
Workspace DataOrganization name, logo, team member roles
Event ConfigurationEvent type titles, durations, booking rules, custom fields
Availability SettingsAvailable hours, buffer times, date overrides
CommunicationsSupport emails, feedback submissions
Payment InformationBilling name, address (card data processed by Stripe)

1.2 Information Collected Automatically

When you use the Service, we automatically collect:

  • Log data: IP address, browser type and version, operating system, referring URLs, pages visited, and timestamps
  • Device information: device type, screen resolution, hardware model
  • Usage data: features used, clicks, navigation paths, session duration, error logs
  • Performance data: load times, API response times, crash reports
  • Cookies and similar tracking technologies (see Section 8 for details)

1.3 Information from Third-Party Integrations

When you connect Calen360 to external calendar or video conferencing services, we receive:

  • Google Calendar: event titles, attendees, start/end times, free/busy status, video conference links
  • Microsoft Outlook / Exchange: calendar events, contacts (limited), free/busy data
  • Zoom / Google Meet / Microsoft Teams: meeting room links and conference metadata
  • OAuth tokens: access tokens and refresh tokens required to maintain the integration (stored encrypted at rest)

We access only the data scopes required for the integration features you have enabled. We do not read the contents of personal emails or non-calendar documents.

1.4 Information from Booking Guests

When a third party books a meeting through your public Calen360 booking page, we collect information they voluntarily submit, which may include their name, email address, and responses to any custom questions you have configured. This data is collected on your behalf and is subject to your own privacy obligations toward your guests.

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1 Providing and Operating the Service

  • Creating and managing your account and authentication sessions
  • Processing and displaying event types, availability, and bookings
  • Sending booking confirmation, reminder, and cancellation notifications
  • Synchronizing with connected calendar and conferencing platforms
  • Enabling team collaboration and workspace management

2.2 Improving and Personalizing the Service

  • Analyzing usage patterns and feature engagement to identify improvements
  • Developing and testing new features and product capabilities
  • Personalizing your experience based on your preferences and settings
  • Training and improving AI-assisted scheduling features using aggregated, de-identified data

2.3 Communications

  • Sending transactional emails (booking confirmations, password resets, email verification)
  • Delivering in-app and email notifications based on your preferences
  • Sending product updates, changelogs, and feature announcements (opt-out available)
  • Responding to your support inquiries and feedback

2.4 Security and Compliance

  • Detecting, preventing, and investigating fraud, abuse, and security incidents
  • Enforcing our Terms of Service and Acceptable Use Policy
  • Complying with applicable legal obligations, court orders, and regulatory requests
  • Maintaining audit logs for security and compliance purposes

2.5 Aggregated and De-Identified Data

We may derive aggregated or de-identified insights from user data (e.g., “X% of bookings use video conferencing”) for internal analytics and reporting. Such data does not identify you individually and is not subject to this Privacy Policy.

3. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, Perizer processes your personal data under the following legal bases:

  • Contract performance: Processing necessary to provide the Service you have subscribed to (e.g., creating your account, processing bookings)
  • Legitimate interests: Processing for security monitoring, fraud prevention, service improvement, and direct marketing to existing customers, where your rights and interests do not override ours
  • Legal obligation: Processing required to comply with applicable law, including tax and financial regulations
  • Consent: Processing for non-essential cookies, marketing communications to non-customers, or any processing where we have requested your explicit consent — you may withdraw consent at any time without affecting prior processing
You have the right to object to processing based on legitimate interests at any time by contacting us at [email protected].

4. Information Sharing and Disclosure

We do not sell, rent, or trade your personal information to third parties for their independent marketing purposes. We may share your information in the following limited circumstances:

4.1 Service Providers

We engage trusted third-party vendors who process data on our behalf, under contractual obligations equivalent to or stricter than this policy:

  • Cloud infrastructure and hosting (e.g., AWS, Google Cloud)
  • Payment processing (Stripe — card data never touches our servers)
  • Transactional email delivery (e.g., SendGrid, Postmark)
  • Error monitoring and performance analytics (e.g., Sentry, Datadog)
  • Customer support tooling (e.g., Intercom)

4.2 Your Invitees and Booking Guests

When a guest books a meeting through your public booking page, we share relevant scheduling information (meeting time, conference link) with that guest. Your name, booking page description, and any fields you have configured as visible are shared with guests as part of the booking flow.

4.3 Team Members

If you are part of a Calen360 workspace, workspace administrators may have access to your profile information, team event configurations, and aggregated booking statistics, depending on the permissions you or the workspace owner have configured.

4.4 Legal Requirements

We may disclose your information if required by applicable law, regulation, legal process, or government authority, or if we reasonably believe disclosure is necessary to protect the rights, property, or safety of Perizer, our users, or the public. We will notify you of such disclosures to the extent permitted by law.

4.5 Business Transfers

In connection with a merger, acquisition, asset sale, financing, reorganization, bankruptcy, or similar transaction, your information may be transferred to a successor entity. We will notify you via email or prominent in-app notice at least 30 days before your data becomes subject to a different privacy policy.

5. Third-Party Integrations and Data Flows

The Calen360 integrations with Google, Microsoft, Zoom, and other providers involve bidirectional data flows. The following summarizes how data moves:

  • Google Calendar / Outlook: We read your existing calendar events to check availability and prevent conflicts. We write new events to your calendar when a booking is confirmed. We do not read the full content of existing events — only titles, times, attendees, and free/busy status.
  • Zoom / Google Meet / Microsoft Teams: We generate or retrieve meeting room links on your behalf and embed them in booking confirmations. We do not record, access, or process the content of your video meetings.
  • OAuth tokens: Access and refresh tokens are stored encrypted at rest using AES-256. Tokens are scoped to the minimum permissions required and are never shared with other users.

Each connected Third-Party Service is governed by its own privacy policy, which you should review independently. Links to relevant policies: Google · Microsoft · Zoom.

6. Data Retention

We retain personal information for as long as your account is active or as needed to provide the Service. Specific retention periods:

  • Account data: Retained for the duration of your account and deleted within 90 days of account closure
  • Booking records: Retained for 2 years following the booking date for operational and dispute-resolution purposes
  • Payment records: Retained for 7 years to comply with financial and tax regulations
  • Security and audit logs: Retained for 12 months
  • Marketing communications preferences: Retained until you unsubscribe or request deletion
  • De-identified analytics data: May be retained indefinitely as it does not contain personal information

Where we are required by applicable law to retain data for longer periods (e.g., tax records), we will do so. You may request earlier deletion of your personal data as described in Section 7.

7. Your Privacy Rights

Depending on your jurisdiction, you may have some or all of the following rights regarding your personal data:

7.1 Rights Under GDPR (EEA / UK / Switzerland)

  • Right of Access: Obtain a copy of the personal data we hold about you
  • Right to Rectification: Correct inaccurate or incomplete personal data
  • Right to Erasure ('Right to be Forgotten'): Request deletion of your personal data where there is no overriding legal basis for retention
  • Right to Restriction: Request that we limit processing of your data in certain circumstances
  • Right to Data Portability: Receive your data in a structured, machine-readable format and transfer it to another controller
  • Right to Object: Object to processing based on legitimate interests or for direct marketing
  • Rights Related to Automated Decision-Making: Not be subject to decisions based solely on automated processing that produce significant legal effects
  • Right to Lodge a Complaint: File a complaint with your local supervisory authority (e.g., ICO in the UK, CNIL in France)

7.2 Rights Under CCPA (California Residents)

  • Right to Know: Know what personal information we collect, use, disclose, and sell
  • Right to Delete: Request deletion of personal information we have collected from you
  • Right to Opt-Out: Opt out of the sale of personal information (Note: we do not sell personal information)
  • Right to Non-Discrimination: Not receive discriminatory treatment for exercising your CCPA rights
  • Right to Correct: Request correction of inaccurate personal information

7.3 How to Exercise Your Rights

To exercise any of these rights, please submit a request to [email protected] with your name, email address, and a clear description of the right you wish to exercise. We will respond within 30 days (or within the timeframe required by applicable law). We may request identity verification before fulfilling certain requests.

8. Cookies and Tracking Technologies

Calen360 uses cookies and similar technologies to operate the Service and understand how you use it. Below is a summary of cookie categories we use:

CategoryExamples
Strictly NecessarySession cookies, authentication tokens (accessToken, onboarding_step)
FunctionalLanguage preference, time zone, sidebar state
AnalyticsPage views, feature usage, session duration
PerformanceLoad times, error rates

You can control non-essential cookies through your browser settings. Disabling certain cookies may affect Service functionality. We do not use cookies to serve third-party advertisements. We do not participate in cross-site behavioral advertising networks.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction:

  • Encryption in transit: All data is transmitted over HTTPS using TLS 1.2 or higher
  • Encryption at rest: Sensitive fields (OAuth tokens, payment metadata) are encrypted using AES-256
  • Password security: User passwords are hashed using bcrypt with a per-account salt — we never store plaintext passwords
  • Access controls: Internal access to production data is restricted to authorized personnel on a need-to-know basis, with full audit logging
  • Vulnerability management: We conduct regular security reviews and dependency audits, and operate a responsible disclosure program
  • Incident response: We maintain a documented incident response plan and will notify affected users and regulators within 72 hours of a qualifying breach, where required by law
No system is 100% secure. If you suspect unauthorized access to your account, change your password immediately and notify us at [email protected].

10. International Data Transfers

Perizer is based in the United States. If you are accessing the Service from the EEA, UK, or another jurisdiction with data transfer restrictions, please be aware that your personal data may be transferred to, stored in, and processed in the United States or other countries where our service providers operate.

Where required by applicable law, we rely on lawful transfer mechanisms including the EU-U.S. Data Privacy Framework, Standard Contractual Clauses (SCCs) approved by the European Commission, and UK International Data Transfer Agreements (IDTAs). A copy of applicable SCCs is available upon request at [email protected].

11. Children's Privacy

Calen360 is not directed at children under the age of 16. We do not knowingly collect, use, or disclose personal information from individuals under 16 years of age. If we become aware that we have inadvertently collected personal data from a child under 16, we will promptly delete it. If you believe we may have collected information from a child, please contact us at [email protected].

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will:

  • Update the 'Last Updated' date at the top of this page
  • Notify registered users via email for material changes at least 30 days before they take effect
  • Display a prominent in-app banner for significant policy changes

Your continued use of the Service after the effective date of any revised policy constitutes your acceptance of the changes. If you do not agree with the changes, you should stop using the Service and may request deletion of your account and data.

13. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact our Privacy Team:

Perizer, Inc. — Privacy Team

Privacy inquiries: [email protected]

Data deletion requests: [email protected]

General support: [email protected]

Website: calen360.com

We will acknowledge receipt of your inquiry within 5 business days and endeavor to resolve it within 30 days. EEA/UK residents who are not satisfied with our response have the right to lodge a complaint with their local data protection supervisory authority.