Privacy Policy
Magyar változatEffective 25 September 2026.
1. Who we are
Scheduler is operated by Rebit Software Kft. (registered seat: 1112 Budapest, Virágkertész utca 4., building C, 2nd floor 6., Hungary; company registration number: 01-09-326911; tax number: 26374826-2-43). We are the controller of the personal data described here. Send questions and requests about your data to support@rebitsoft.com.
This policy covers everyone whose data Scheduler handles: people with an account, visitors who book a time on someone’s booking page, people added to a meeting, and people invited to join Scheduler.
2. In short
- Scheduler finds meeting times across Google and Microsoft calendars and books the meeting in the organizer’s own calendar.
- To know when you are busy, we ask your calendar provider only when you are busy, not what the event is. We do not read, store or process the titles, descriptions, locations or attendees of your events.
- When you are busy is not stored. It is read when needed and discarded as soon as the answer has been worked out.
- Other people never see when you are busy, only times that are free for booking, and only as far as your own settings allow.
- We do not sell personal data, show advertising, use analytics or tracking, or build profiles of you.
3. What we collect
If you have an account
- Account: your email address, whether you confirmed it, the display name you choose, your time zone, and a salted hash of your password (never the password itself). If you joined through an invitation link, we record who invited you.
- Calendar connections: the provider (Google or Microsoft), the email address and identifier of the connected account, the permissions you granted, the connection’s status, and an encrypted refresh token that lets us act on your calendar. We also store the names of the calendars in that account and which of them you chose to use.
- When you are busy: read live from your calendar provider as the start and end of busy periods (on Microsoft also a status, such as tentative or out of office). It is held in memory only while an answer is computed, and never stored.
- Availability and booking page: your meeting hours, buffers, notice and other rules; your booking page handle, display name and bio; and your event types. Your booking page is public to anyone with its link.
- Access settings: who may book with you or see your availability, including any email addresses or domains you list in your rules, whether people can find you by the address of a connected calendar account, and the requests you send and receive to see someone’s availability.
- Meetings: for each meeting booked through Scheduler, its time, title, description, location, video-call link, calendar, status, and the provider’s identifier for the calendar event. The attendees’ addresses are sent to Google or Microsoft as part of the event; we do not keep them with the meeting.
- Contacts: the addresses you invited to meetings through Scheduler, so that the planner can suggest them to you. Only you can see them.
- Invitations you send: addresses you invite from the Invite page, so that you can see what you sent (see “If someone invites you to Scheduler” below).
- Notifications: notices shown to you inside Scheduler, such as a new request or a booking on your page.
If you book a time on someone’s booking page
- You give us your name, email address and, if you wish, a note. We use them to book the meeting with the page’s owner, whose settings decide whether it is booked straight away, waits for their approval, or cannot be accepted.
- If the meeting is booked, it is created in the owner’s calendar with you as an attendee, and Google or Microsoft sends you the invitation. The event’s title contains your name, and its description contains your name and note. We do not keep your email address with the booking.
- If the request waits for the owner’s approval, we keep your name and email address with the request, so that the owner can decide.
- Your network (IP) address is used briefly, in memory only, to limit how many requests can be made. We do not store it.
If someone adds you to a meeting or looks up your address
- A Scheduler user can type your email address into the planner to arrange a meeting. We receive your address from that user.
- If you have no account, we record only a pseudonymised (hashed) form of the address, for that day, to limit how many addresses one person can check. If the user books the meeting, your address is sent to their calendar provider as an attendee, and kept in their contacts (see section 8).
- If you have an account, the user is told whether they can schedule with you and, if you allow it, which times suit you (see section 6). Each such check and lookup is recorded, and you can see the lookups on your Access page.
If someone invites you to Scheduler
- A Scheduler user can ask us to email you an invitation to join, beside a meeting or on its own. We receive your address from that user, who is responsible for having a reason to contact you.
- The email names the person who invited you and their confirmed address, says why you received it, and contains a link to create an account. Nobody creates an account for you.
- For an invitation beside a meeting, we keep only a pseudonymised form of your address for 30 days, to enforce the limits on invitations. For an invitation from the Invite page, we keep your address so that the inviter can see what they sent, until you join, until you opt out, or until 90 days after the invitation expired or was withdrawn, whichever is first.
- Every invitation email contains a link to never receive another Scheduler invitation from anyone. To honour it, we keep a pseudonymised form of your address on a do-not-invite list, and remove your address from any open invitation.
For security and to run the service, about everyone
- Audit records: a record of security- and privacy-relevant actions, such as sign-ins, connecting or disconnecting a calendar, every lookup of someone’s availability (who, whose, which period, and the result), access requests and decisions, bookings and cancellations, invitations, changes to settings, and every action of our staff. Audit records never contain calendar contents, passwords or tokens.
- Technical logs: one line per request, with an identifier, the page or function called, the result and how long it took. Email addresses, passwords, tokens and cookies are removed before a line is written. The application does not log IP addresses or the contents of requests.
4. Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing Scheduler to account holders: connecting calendars, working out free times, booking and cancelling meetings, the booking page, the planner, notifications, and keeping your settings | Performance of a contract with you, Article 6(1)(b) |
| Booking a meeting you asked for on someone’s booking page | Legitimate interest: yours and the page owner’s, in arranging the meeting you requested, Article 6(1)(f) |
| Handling addresses that account holders enter: meeting attendees, contacts, addresses in access rules, telling an organizer whether they can schedule with someone | Legitimate interest: the account holder’s, in arranging meetings with the people they work with, and ours, in providing that service, Article 6(1)(f) |
| Sending an invitation to join Scheduler at a user’s request, enforcing the limits on invitations, and keeping the do-not-invite list | Legitimate interest, Article 6(1)(f). The inviting user is responsible for having a reason to contact you, and you can opt out with one click. |
| Security, preventing abuse, rate limits, audit records and technical logs, answering questions about who did what | Legitimate interest in a secure and reliable service, Article 6(1)(f) |
| Meeting legal obligations, such as answering lawful requests from authorities | Legal obligation, Article 6(1)(c) |
Where we rely on legitimate interest, you may object (section 11). Giving us your email address and a password is necessary to create an account; without them we cannot provide it.
5. Your Google or Microsoft calendar
To connect a calendar, you sign in at Google or Microsoft and approve the permissions we ask for there. We use them only to read when you are busy, to list your calendars so that you can choose which ones to use, and to create, change and cancel the meetings you book through Scheduler, with a Google Meet or Microsoft Teams link if you ask for one.
| Provider | Permission | What we use it for |
|---|---|---|
calendar.freebusy | Reading when you are busy. It gives no access to event contents. | |
calendar.calendarlist.readonly | Listing your calendars, so that you can choose which ones to use | |
calendar.events.owned | Creating, changing and cancelling the meetings you book, on calendars you own | |
openid, email | Showing which account is connected | |
| Microsoft | Calendars.Read.Shared | Reading when you are busy |
| Microsoft | Calendars.ReadWrite | Creating, changing and cancelling the meetings you book |
| Microsoft | offline_access | Keeping the connection working without you signing in each time |
| Microsoft | User.Read, openid, profile, email | Showing which account is connected |
Please note: the permissions needed to create meetings technically allow reading events as well, and on Microsoft even the permission for reading when you are busy does. That we do not read, store or process the contents of your events is our commitment, kept by how Scheduler is built, not a limit that Google or Microsoft places on us. We never gain access to Google calendars you do not own.
Scheduler’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google or Microsoft calendar data for advertising, do not sell it, do not transfer it to anyone except as needed to provide the features described here or as required by law, and do not let people read it.
You can disconnect a calendar at any time in Scheduler. We then withdraw our access at the provider and delete the stored token and the list of your calendars. You can also withdraw our access in your Google or Microsoft account settings. Meetings already booked stay in the calendars, but Scheduler can no longer change or cancel them.
6. What other people can see
- Your booking page (display name, bio, event types) is public to anyone with its link. Visitors see only the times they can book, never when you are busy or why a time is unavailable. Booking pages ask search engines not to index them.
- People who add you in the planner. A signed-in user who types your address is told whether you are on Scheduler and whether they can schedule with you, need to ask you, are waiting for your answer, or cannot ask. One person can check at most 200 addresses a day, and each check of a registered person is recorded. Pages that need no sign-in, such as the booking page, sign-up and password reset, never reveal whether an address has an account.
- Who can make a time. If you allowed someone’s request, or you share an organization in Scheduler, the planner shows them for each time how many people can make it and names those who cannot. It never shows your busy periods.
- Access requests. When someone asks to see your availability, you see their primary address. They see only whether the request is waiting or cannot be made, never why.
- Who has looked. On your Access page you can see each time someone looked up your availability and what they got.
- Finding you. Off unless you turn it on. When on, people can find you in the planner by the address of a connected calendar account, not only by your Scheduler address.
- Suggestions. The planner suggests people only to someone who already has a relationship with them: a person they invited to a meeting in the last twelve months, a person in the same organization, or a person on the other side of an allowed request.
- Meeting attendees receive the calendar event from the organizer’s calendar. It carries the organizer’s instructions, a booking-page visitor’s name and note, and a short line saying that the meeting was booked with Scheduler.
7. Who else receives personal data
- Microsoft Azure hosts Scheduler, its database, its logs and the key that protects calendar tokens, in the European Union (Poland Central region).
- Brevo (Sendinblue SAS, France) delivers the emails Scheduler sends, from the European Union. The emails carry no tracking of opens or clicks.
- Google and Microsoft provide your calendar under your own agreement with them. They are not our processors. We exchange data with them only on your instruction: when you connect a calendar, when availability is looked up as your settings allow, and when a meeting is booked or cancelled.
- Our staff can see account details, the status of calendar connections, and meeting details when needed to run the service or answer a request. Any view that names a person requires a recorded reason and is logged. Staff cannot see calendar contents or tokens, and cannot sign in as you.
Our hosting and email providers act on our instructions under data processing agreements. We store your data in the European Union. If a provider or one of its sub-processors accesses data from outside the European Economic Area, the transfer is covered by the safeguards the GDPR requires, such as the European Commission’s standard contractual clauses.
We do not use analytics, advertising or tracking services, and the site loads nothing from other companies.
8. How long we keep it
| Data | Kept |
|---|---|
| Account, settings, booking page, access settings and requests, list of calendars | While your account exists |
| Calendar token | Until you disconnect the calendar or delete your account; then deleted, and our access withdrawn at the provider |
| When you are busy | Not stored; held in memory only while an answer is computed |
| Meetings and booking requests, including a visitor’s details on a request | 12 months after the meeting took place or was cancelled, unless a law requires longer |
| Contacts | 12 months after you last invited the person |
| Notifications | 90 days |
| Addresses checked in the planner (pseudonymised) | The day of the check |
| Invitations beside a meeting (pseudonymised) | 30 days |
| Invitations from the Invite page | Until the person joins or opts out, at most 90 days after the invitation expired or was withdrawn |
| Do-not-invite list (pseudonymised) | As long as needed to honour the request |
| Audit records | 12 months, unless a law requires longer |
| Technical logs | 90 days |
Deleted data can remain in database backups for up to 35 days before the backups themselves are overwritten.
9. How we protect it
- Every connection is encrypted (TLS), and browsers are told to use only secure connections.
- Calendar refresh tokens are encrypted (AES-256-GCM), and the key is kept apart from the database. Short-lived access tokens are never written to disk.
- Passwords are stored only as a salted hash. Confirmation, reset and invitation links expire and work only once.
- Each person’s data is separated in the database itself, not only by the application. The database cannot be reached from the internet.
- Limits on requests, sign-in attempts, address checks and invitations make misuse harder.
- Every lookup of another person’s availability and every staff action is recorded, and the application cannot change or delete those records.
- Our staff administration site is separate from Scheduler and reachable only from our office network.
10. Automated decisions
When someone asks to book time with you, the rules you set decide automatically whether the meeting is booked, waits for your approval, or is declined. We do not score or profile anyone, and no decision is made about you that has legal or similarly significant effects.
11. Your rights
You may ask for access to your data and a copy of it, its correction or erasure, restriction of its processing, and a portable copy. You may object to processing based on legitimate interest. Until self-service tools are available, send your request to support@rebitsoft.com. We answer within one month, and may ask you to confirm that the request comes from you.
- You can disconnect a calendar yourself at any time, which ends our access to it.
- If you received an invitation and have no account, the link at the bottom of the email stops all future invitations.
- If you think we have handled your data unlawfully, you may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, 1055 Budapest, Falk Miksa utca 9–11, naih.hu) or to the supervisory authority where you live or work, and you may also go to court.
12. Children
Scheduler is not intended for anyone under 16, and we do not knowingly collect their data.
13. Cookies
We use only the cookies the service needs to work. See the Cookie Policy.
14. Changes
When this policy changes, we update the date at the top. For material changes, we tell account holders by email before the change takes effect.