Privacy Policy
Last updated: 2026-06-10
1. Data Controller
CalSyncPro (“we”, “us”, “our”) is operated by C-ICAS Sp. z o.o., NIP: 1182226755, Poland (“Data Controller”). For calendar event data we process on your behalf, we act as your Data Processor and you remain the Data Controller. Contact: privacy@calsyncpro.com.
2. What Data We Process
- Account data: Microsoft 365 identifiers (tenant ID, user ID), Google account identifiers (Google user ID), and email address — provided during sign-in via Azure AD or Google OAuth 2.0.
- OAuth tokens: Microsoft and Google access & refresh tokens, stored encrypted (AES-256-GCM) so we can keep synchronizing on your behalf. Retained for the duration of your connection and deleted on disconnection (see Section 4).
- CalDAV credentials: If you connect a CalDAV account (e.g. Fastmail, iCloud, Yahoo), the app-specific password you provide is stored encrypted (AES-256-GCM) and used solely to access that calendar.
- Sync configuration: Calendar sync pair settings, selected calendars, sync rules, conflict-resolution preferences, sync direction (one-way / two-way).
- Calendar event content (Microsoft 365, Google, CalDAV, ICS): We process event data in transit to perform synchronization. We do NOT persistently store event titles, descriptions, locations, or attendee data. In the destination calendar, synced items appear as free/busy blocks (default label, or an optional custom label on Business+ plans) — the original event content is never copied.
- AI Assistant data: If you use the in-app AI Assistant, your chat messages and the assistant's replies are processed and stored (see Section 8).
- Push notification tokens: If you enable push notifications, your device token and platform (iOS / Android / Windows) are stored to deliver alerts.
- API keys & webhook configuration: For the Public API, we store a one-way hash of your API key (never the key itself) and the webhook endpoint URLs you configure (see Section 9).
- Operational logs: Sync activity logs, error logs, and audit trails — retained for up to 90 days.
- Usage data: Event counts, sync frequency, feature usage, and website analytics — anonymized and aggregated (session-based, no personal identifier).
3. Legal Basis for Processing (GDPR)
- Contract performance (Art. 6(1)(b) GDPR): Processing necessary to deliver the synchronization service, the AI Assistant, the Public API, and connected integrations you enable.
- Legitimate interest (Art. 6(1)(f) GDPR): Operational logs, security monitoring, and service-integrity measures.
- Consent (Art. 6(1)(a) GDPR): Analytics cookies and push notifications — where you have provided consent.
4. Data Retention
- Account and sync configuration data: retained for the duration of your subscription + 30 days after cancellation.
- OAuth tokens (Microsoft & Google) and CalDAV credentials: retained while the connection is active; deleted immediately on disconnection or within 30 days of subscription termination.
- AI Assistant conversations: 30 days. Aggregated, non-identifying improvement summaries may be retained longer.
- Operational logs: 90 days. Website analytics: 90 days.
- Anonymized usage statistics: up to 2 years.
- All Google OAuth tokens and any Google Calendar data are deleted immediately upon account disconnection or within 30 days of subscription termination.
5. Google API Data — Limited Use Disclosure
CalSyncPro integrates with the Google Calendar API to provide calendar synchronization between Google Calendar and other connected calendar providers.
When you connect a Google account, we request the following OAuth 2.0 scopes:
https://www.googleapis.com/auth/calendar.readonly— read-only access to list your calendars (used to identify which calendar to synchronize). No calendar settings or metadata are modified.https://www.googleapis.com/auth/calendar.events— read and write calendar events. Used to read source events and create free/busy placeholder events in destination calendars.
We also use the Google Calendar Push Notifications API (watch channels) to receive real-time change notifications when events are added, updated, or deleted. This mechanism uses the same scopes listed above — no additional permissions are granted. Notification channels are renewed automatically every 6 days and are terminated immediately when you disconnect your Google account.
Our use of Google Calendar data is strictly limited to providing the synchronization service. Specifically:
- Google Calendar event data is used only to synchronize events between connected calendars — for no other purpose.
- We do not store Google Calendar event content (titles, descriptions, attendees, locations) beyond the transit time required to complete the sync operation.
- We do not use Google Calendar data for advertising, user profiling, selling to third parties, or any purpose unrelated to delivering the sync service.
- Google Calendar data is not sent to the AI Assistant or to any artificial-intelligence / machine-learning model.
- We do not share Google user data with any third parties except as required to deliver the service (sub-processors listed in Section 12), or to an endpoint you yourself configure via the Public API (Section 9).
CalSyncPro's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Microsoft 365 Data and Permissions
When you connect a Microsoft account, we request the following Microsoft Graph (delegated) permissions:
Calendars.ReadWrite— read source events and create free/busy blocks in your calendar.Calendars.ReadWrite.Shared— same, for shared and delegated mailboxes you are authorized to access (not requested for personal Microsoft accounts).offline_access— a refresh token so sync continues without re-login.openid email profile User.Read— your identity and basic profile.
Depending on the features you enable, the same calendar permissions may also be used to read room and equipment mailboxes, Microsoft 365 Group (Teams) calendars, SharePoint calendars, and Microsoft Bookings that you are authorized to access. As with all sync, only free/busy availability is written to destinations — never the original content.
7. Additional Calendar Sources — CalDAV and ICS
- CalDAV (e.g. Fastmail, iCloud, Yahoo): You provide an app-specific password, which we store encrypted (AES-256-GCM) and use only to read your events and write free/busy blocks. We do not access any data beyond your calendars.
- ICS subscriptions: You provide a public iCalendar (.ics) URL. We fetch it periodically and use only start/end times and the unique event ID to create free/busy blocks — titles, descriptions, and attendees are discarded.
8. AI Assistant
The optional in-app AI Assistant helps you configure and troubleshoot the service. It is powered by Microsoft Azure OpenAI Service hosted in the EU (Sweden Central).
- The Assistant receives only operational context — your organization, email, plan, sync-pair status, and sync logs (operation, status, timing). It does not receive your calendar event titles, descriptions, attendees, or locations.
- Conversations (your messages and the replies) are stored for 30 days to provide chat history and improve support quality, then automatically deleted.
- Your data is not used to train Azure OpenAI or any foundation model. Microsoft does not use Azure OpenAI customer data to train its models.
9. Public API, Webhooks and Power Automate
- Public API & webhooks (optional): If you create an API key and configure outbound webhooks, we deliver event metadata (e.g. event ID, title, start, end, location, source) to the endpoint URL you specify. You control that destination and are responsible for its security and lawful use. Payloads are signed (HMAC-SHA256). This is the only case in which event content leaves our systems, and only to a recipient you have chosen.
- Power Automate integration (optional): If you enable it, we provision automation flows within your own Microsoft tenant and store the delegated token needed to operate them. Data is exchanged with the Microsoft Power Automate API on your behalf.
10. Email Communications
We send transactional emails (e.g. token-expiry warnings, sync-paused alerts, billing notices) via Microsoft Azure Communication Services. We do not send marketing email without your consent.
11. Data Transfers
Our core infrastructure (application, database, email) runs in the European Economic Area — Microsoft Azure West Europe (Netherlands). The AI Assistant runs in Microsoft Azure OpenAI Sweden Central (EU).
Some transfers leave the EEA by design: Google OAuth tokens are exchanged directly with Google's servers (USA) under Standard Contractual Clauses; CalDAV and ICS requests reach the providers whose accounts/URLs you connect; and Public API webhooks reach the endpoint you configure — which may be in any country and is under your control.
12. Sub-Processors
- Microsoft Azure — cloud infrastructure, database (Cosmos DB), Key Vault (EU, West Europe)
- Microsoft Graph API — Microsoft 365 calendar data access on your behalf
- Microsoft Azure OpenAI Service — AI Assistant (EU, Sweden Central)
- Microsoft Azure Communication Services — transactional email (EU)
- Microsoft Azure Notification Hubs — push notifications (relays to Apple APNs, Google FCM, Windows WNS)
- Microsoft Power Automate — optional automation flows on your behalf
- Google Calendar API (Google LLC) — Google Calendar data access on your behalf; governed by Google's Privacy Policy
- Stripe — payment processing
- Microsoft Commercial Marketplace — licensing & billing, if you subscribe through the Marketplace
13. Your Rights (GDPR)
- Right of access (Art. 15): Request a copy of your personal data.
- Right to rectification (Art. 16): Correct inaccurate data.
- Right to erasure (Art. 17): Request deletion of your data.
- Right to restriction (Art. 18): Limit how we process your data.
- Right to data portability (Art. 20): Receive your data in a machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3)): Withdraw consent at any time without affecting prior processing.
To exercise your rights, contact: privacy@calsyncpro.com. We respond within 30 days. You also have the right to lodge a complaint with your national data protection authority (in Poland: UODO, uodo.gov.pl).
14. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (Art. 33 GDPR). If the breach poses a high risk to you personally, we will also notify you directly without undue delay (Art. 34 GDPR).
15. Cookies
We use the following cookies:
- Necessary: Authentication state, locale preference, cookie consent. Cannot be disabled — required for the service to function.
- Analytics (optional): Anonymized usage statistics to improve performance. Only set with your explicit consent.
We do not use advertising or tracking cookies.
16. Security
We implement appropriate technical and organizational measures including: TLS 1.3 encryption in transit, AES-256 encryption at rest (including OAuth tokens and CalDAV credentials), Azure AD and Google OAuth 2.0 authentication, role-based access control, and incident response procedures.
17. Changes to This Policy
We may update this policy periodically. Material changes will be notified via email at least 30 days in advance. Continued use of the service after the effective date constitutes acceptance. If you disagree with changes, you may terminate your account before the changes take effect.