Privacy Policy of Terminarz24.pl

This is an informational English translation. The legally binding version is the Polish one available at https://terminarz24.pl/polityka-prywatnosci; in case of any discrepancy the Polish version prevails. The section on Google user data is § 10.

1. General information

1.1 This Privacy Policy sets out how personal data provided by Users of the Terminarz24.pl online service (the "Service") is processed and protected.

1.2 The data controller is JDPL Damian Lalewicz, ul. Siedliski 12B, 32-082 Bolechowice, Poland, VAT ID (NIP): 8661653884, REGON: 369145787 (the "Controller").

1.3 The Controller processes personal data lawfully and securely, in accordance with Regulation (EU) 2016/679 (GDPR).

1.4 The Controller processes data provided on registration, subscription and contact: name, e-mail address, phone number, company name, tax ID, business address (invoice data), account login data and payment history (without full payment card data), as well as automatically collected data described in § 4.

1.5 Providing data is voluntary but necessary to create an Account and conclude the agreement. Consents are given by ticking checkboxes that are never pre-ticked.

1.6 Requests concerning personal data, including the rights described in § 6, can be sent to the address given in § 6.7.

2. Purposes and legal bases

2.1 Providing the Service (Account, subscription) — Art. 6(1)(b) GDPR (performance of a contract).

2.2 Legal obligations (invoicing, accounting) — Art. 6(1)(c) GDPR.

2.3 Handling complaints and enquiries — Art. 6(1)(b) and (f) GDPR.

2.4 Analytics and statistics used to improve the Service — Art. 6(1)(f) GDPR.

2.5 Direct marketing of the Controller's own services — Art. 6(1)(f) GDPR.

2.6 The Controller does not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

3. Recipients and transfers outside the EEA

3.1 Personal data may be disclosed to the following categories of recipients:

  • a. Hosting provider (OVH SAS) — server hosting.
  • b. File storage and database backups (Cloudflare, Inc. — Cloudflare R2).
  • c. Payment operator (ING Bank Śląski S.A. — imoje); full card data is not stored by the Controller.
  • d. Accounting office / accounting system (e.g. wFirma) — invoicing and tax settlements.
  • e. Communication providers: JUSTSEND Sp. z o.o. (SMS) and Zoho Corporation B.V. (ZeptoMail, transactional e-mail).
  • f. Error monitoring (Functional Software, Inc. — Sentry).
  • g. Abuse protection and rate limiting (Arcjet Limited — Arcjet).
  • h. Analytics (Google LLC — Google Analytics).
  • i. Session replay and heatmaps (Microsoft Corporation — Microsoft Clarity).
  • j. Calendar service (Google Ireland Limited / Google LLC — Google Calendar) — only for Users who have enabled the optional integration, to synchronise booking times. Details: § 10.

3.2 Some data may be transferred outside the European Economic Area (mainly to the USA). Such transfers are based on Standard Contractual Clauses adopted by the European Commission and, for US recipients certified under it, on the EU-US Data Privacy Framework adequacy decision of 10 July 2023.

4. Automatically collected data

4.1 When the Service is used, technical data is collected automatically: IP address, browser type and version, operating system, screen resolution, browser language, date and time of the visit, pages visited and the referrer.

4.2 This data is processed under Art. 6(1)(f) GDPR to operate the Service, keep it secure and produce statistics.

5. Retention

5.1 Data is kept for as long as necessary for the purpose for which it was collected and afterwards for the period required by law, in particular:

  • Account data — for the term of the agreement plus 30 days after account deletion;
  • invoice and billing data — 5 years from the end of the tax year;
  • Google Analytics data — 14 months; Microsoft Clarity data — 12 months;
  • backups and server logs — 30 days; application logs — 90 days;
  • end-customer booking data — until deleted by the User or 30 days after the User's account is closed;
  • contact form data — up to 12 months from the last contact;
  • session data — until logout, at most 30 days;
  • cookie consent log — 3 years from the last change of consent;
  • GDPR audit log of anonymisation and deletion operations — indefinitely (accountability, Art. 5(2) GDPR).

5.2 Free-plan accounts with no activity for 12 consecutive months are archived after three e-mail warnings (90, 30 and 7 days before) and a 30-day grace period during which the account can be restored and a CSV copy of the data requested. Afterwards personal data is irreversibly anonymised, or fully deleted on explicit request. Billing documents are kept for 5 years regardless of archiving. Trial accounts without any payment can be deleted by the User directly in the panel. See § 8.4 and § 8.5 of the Terms of Service (in Polish).

6. Your rights

6.1 Right of access to your data.

6.2 Right to rectification.

6.3 Right to erasure ("right to be forgotten"), unless the law requires further storage (e.g. invoices for 5 years).

6.4 Right to restriction of processing.

6.5 Right to data portability.

6.6 Right to object to processing.

6.7 To exercise these rights, contact the Controller at [email protected].

6.8 You may lodge a complaint with the Polish supervisory authority — the President of the Personal Data Protection Office (PUODO).

7. Cookies and analytics

7.1 The Service uses cookies: strictly necessary cookies (login and session, cannot be disabled), analytics cookies (Google Analytics, Microsoft Clarity — only with consent) and a marketing category that currently activates no tools.

7.2 The full list of cookies is in § 7.3 of the Polish version and in the Cookie Policy (in Polish). Cookies can also be restricted in your browser settings.

8. Security

8.1 The Controller applies technical and organisational measures appropriate to the risks and categories of data.

8.2 Accounts are password-protected and all communication between the device and the server is encrypted (TLS).

9. End-customer data (people booking appointments)

9.1 Terminarz24.pl acts solely as a software (SaaS) provider for business Users (service companies of various industries).

9.2 For personal data of end customers who book services through the platform, the controller within the meaning of the GDPR is the specific User (company) with which the appointment is booked.

9.3 Terminarz24.pl acts as a processor on the basis of a separate Data Processing Agreement (in Polish).

9.4 Requests concerning booking data should be addressed directly to the company with which the appointment was made.

10. Google Calendar integration

10.1 Scope and purpose. The Service offers an optional Google Calendar integration that is disabled by default and is enabled separately for each employee, only on the User's explicit request (OAuth 2.0). Terminarz24.pl requests a single scope — https://www.googleapis.com/auth/calendar.events — and uses it only to create, update and delete events that correspond to bookings assigned to the employee, and to read the employee's existing events in order to block the matching time in the Service and prevent double bookings. Terminarz24.pl does not access Gmail, Google Drive, contacts or any other Google Account data.

10.2 Data sent to Google. For each booking the Service sends to the employee's Google Calendar only: the service name, the customer's first name (no surname), the customer's contact phone number (if provided), the date and time of the appointment, and a technical marker that identifies events created by the Service. The event title has the form "[Terminarz24] service name — first name". The customer's surname and booking notes are not sent, and the customer is not added as an event attendee, so Google sends them no invitation.

10.3 Data received from Google. From events in the employee's calendar the Service stores and uses only the date, time, title and ID of the event (the ID is needed to update or remove the block), solely to create a block in the employee's schedule. Other event fields (description, attendees, location, attachments) are neither stored nor used. Events created by the Service itself are ignored.

10.4 Storage, protection and sharing. The Service stores the e-mail address of the connected Google account, the calendar ID, access and refresh tokens (encrypted with AES-256-GCM), the IDs of events created by the Service and of events received from Google and, for events received from Google, the date, time and title needed to block the slot. The title of a Google event is visible in the Service schedule, as the description of the block, to people who have access to the schedule within the given company. Apart from that, the data is not disclosed to anyone other than Google and the infrastructure processors listed in § 3 (hosting and backups).

10.5 Limited Use. Terminarz24.pl's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, the Controller does not use this data for advertising, including targeted advertising, marketing or profiling; does not sell it or transfer it to third parties, data brokers or advertising networks; does not use it to develop, improve or train generalized artificial intelligence or machine learning models; and allows humans to read it only when necessary for security purposes, to comply with applicable law, or with the User's explicit consent (e.g. when reporting a problem to technical support).

10.6 Retention, deletion and revoking access. Google data is kept for as long as the connection exists. The User can disconnect the integration at any time in the Service panel (Employees → edit employee → Google Calendar → Disconnect) or at myaccount.google.com/permissions. Disconnecting in the Service panel — like deleting the Account — permanently deletes from the Service database the tokens, the links to Google events and the schedule blocks created from Google events. Events previously created by the Service in Google Calendar remain there until the User deletes them. Requests to delete Google data can also be sent to [email protected].

11. Final provisions

11.1 This Privacy Policy is publicly available to fulfil the information obligations under the GDPR.

11.2 The Controller may amend this Policy when the law or technology changes. Users will be informed of material changes by e-mail or by a notice in the Service.

11.3 Effective date: 27.03.2026. Last updated: 24.09.2026.