LEGAL
Privacy Policy
How ANIMAS Meeting Scheduler handles account, booking, and connected calendar data.
Last updated: August 27, 20261. Who controls your data
ANIMAS Meeting Scheduler is operated by SIA Animas, registration number 40203360721, legal address “Kaktiņi”, Vecsaikava, Praulienas pagasts, Madonas novads, LV-4825, Latvia. Privacy enquiries and data requests can be sent to animas@animas.lv.
2. What this policy covers
This policy covers the Meeting Scheduler website, organization accounts, public booking pages, subscriptions, and optional Google Calendar, Microsoft 365, and Telegram connections.
3. Data we collect
- Account and organization data: name, email address, profile image, organization membership, time zone, availability rules, and account settings.
- Calendar connection data: provider account identifier and email, selected calendar identifiers and names, ownership and access role, encrypted OAuth credentials, free/busy intervals processed on demand, and identifiers and meeting URLs returned for events created through the Scheduler.
- Booking data: meeting title, description, participants, offered and confirmed times, and the booking client's name and email address.
- Billing data: Stripe customer and subscription identifiers, plan, payment status, and billing period. Payment-card details are handled by Stripe and are not stored by the Scheduler.
- Optional feature data: Telegram account details and meeting requests, or audio submitted for transcription, only when those features are used.
4. Why we use the data
We use the data to:
- authenticate users and manage organization access;
- calculate shared availability without exposing colleagues' private calendar details;
- show signed-in users anonymous busy blocks without event titles or descriptions;
- create booking links and confirmed calendar events;
- send invitations, calendar notifications, and booking confirmations;
- provide subscriptions, support, security, and service administration; and
- process meeting instructions or voice transcription when a user explicitly invokes those optional features.
5. Google user data and permissions
The Scheduler requests the following Google permissions:
openid,email, andprofileto sign the user in and identify their connected account;calendar.freebusyto calculate available meeting times;calendar.events.ownedto create confirmed meeting events in a calendar owned by the organizer; andcalendar.calendarlist.readonlyso the user can choose which subscribed calendars are included and the Scheduler can read primary-calendar properties.
Google user data is used only to provide and improve user-visible scheduling functionality. It is not sold, used for personalized advertising, used to determine creditworthiness, or used to train general-purpose AI models. Human access is limited to security or support needs, with user consent, when required by law, or when data has been aggregated and anonymized.
The Scheduler does not read Google Calendar event titles, descriptions, attendees, or locations. Free/busy intervals are processed on demand to calculate availability and are not stored as event details in the Scheduler database. The Scheduler stores encrypted OAuth credentials, the connected account and selected-calendar metadata, and the identifiers and meeting URLs returned for meetings it creates. When a booking is confirmed, its title, description, time, attendee email addresses, and conference request are sent to Google so Google Calendar can create the requested event and Google Meet link.
The Scheduler's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Read that policy at Google API Services User Data Policy.
6. Storage, security, and sharing
Calendar access and refresh tokens are encrypted before storage. Data is transmitted over HTTPS, and tenant-aware access controls separate organizations. We share data only with service providers needed to operate requested features: Google and Microsoft for calendars, Supabase for authentication and database services, Railway for hosting, Stripe for subscriptions, Resend for transactional email, Telegram for a connected bot, and OpenAI only when a user invokes meeting-instruction or voice-transcription features. Google Calendar lists, free/busy intervals, OAuth credentials, and calendar event data are not sent to OpenAI. These providers process data under their own terms and privacy notices. We do not sell personal or Google user data.
7. Retention and deletion
We retain account, organization, booking, and billing records only for as long as needed to provide the service, meet legal obligations, resolve disputes, and maintain security. Calendar credentials are retained while the connection is active. Users can revoke access in their Google or Microsoft account, and may request account or personal-data deletion by emailing animas@animas.lv. Some records may be retained where required by law.
8. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may also withdraw consent where consent is the legal basis. Contact us at the email above. You may lodge a complaint with the Latvian Data State Inspectorate or another competent supervisory authority.
9. Changes
We may update this policy as the service changes. The current version and update date will remain available on this page. Material changes will be communicated through the service or by email where appropriate.