Free Meeting Time

Privacy Notice

Last updated: May 25, 2026

This notice explains how personal data is handled when you create or respond to a meeting availability request.

Data Controller

The organization that operates this service is the data controller and is responsible for its GDPR obligations.

Contact: [email protected]

Data We Process

We process organizer and participant names and email addresses, meeting titles, descriptions, proposed times, availability responses, login/session data, API-key metadata and security/rate-limit logs.

Purpose And Legal Basis

Data is used to provide meeting scheduling, deliver invitations and reminders when enabled, support account and API access, and protect the service. The operator must identify the applicable GDPR legal basis, such as contract or legitimate interests, for its use of this service.

EU Storage And Transfers

This service is intended to store application data within the European Union and to be operated in accordance with GDPR. The operator must ensure that hosting, backups, mail delivery and log providers preserve this arrangement. If transfers outside the EEA are introduced, appropriate GDPR safeguards and updated information are required.

Retention

Meeting requests and related participant responses may be deleted by the organizer and are eligible for automatic deletion when the last proposed date is at least three months old. Sessions, login records, rate-limit records and revoked API-key metadata are kept only as needed for operation and security.

Recipients And Processors

Personal data is accessible to the organizer and relevant invited participants through their links. Service providers used for EU hosting, backups or configured email delivery may process data on the operator’s behalf under appropriate agreements.

Your Rights

Under GDPR, you may have rights to access, correct, erase or restrict your data, object to processing, request portability where applicable, and lodge a complaint with your data protection authority.

Security

The service applies access controls, hashed credentials, CSRF protection, request throttling and encrypted transport when deployed with HTTPS. Do not share private admin links or API keys.

Contact

Contact the organization operating this service to exercise privacy rights or ask how your data is handled. You may also contact your competent supervisory authority.

Operator note: before publishing this notice, provide your controller identity and contact details and verify the stated hosting location, retention periods, processors and legal bases.