Privacy policy
This policy explains how Appointment & Resource Scheduler ("we") handles personal data. It is written with the EU and UK General Data Protection Regulation (GDPR) in mind.
Who is responsible
For account data of our customers (the businesses that use the service), we are the controller. For the data a business stores about its own clients and appointments, the business is the controller and we act as its processor, following its instructions.
What we collect
Account details (name, email, password hash or Google account identifier), workspace settings, the appointments, clients, services and rooms you enter, billing status from Stripe (we never see full card numbers), and security logs such as IP addresses of sign-in attempts. Clients who book provide their name, email, optional phone number and optional notes.
Why we use it
To provide the service (contract), to keep it secure and prevent abuse (legitimate interest), to send booking confirmations and reminders requested by the business, and WhatsApp or SMS messages only when the client has opted in (consent), and to meet legal obligations such as tax records.
Cookies
We use only strictly necessary cookies: a session cookie to keep you signed in, a security token against forged requests, and an optional "remember me" cookie. We do not use advertising or analytics cookies, third-party fonts or trackers, so no cookie banner is needed.
Who we share it with
Service providers that help us run the service: our hosting provider, our email provider, Stripe for payments, Google if you choose Google sign-in, and Twilio or Meta if a business enables WhatsApp or SMS. Each is bound by a data processing agreement. Where data leaves the EU/UK, standard contractual clauses or an adequacy decision apply.
How long we keep it
While the account is active. After an account is closed we delete workspace data within 90 days, except records we must keep by law. Security logs are kept for up to 12 months.
Your rights
You can access, correct, export, restrict or delete your data, object to processing and withdraw consent at any time. Businesses can export everything with one click and erase a client's personal details from the client page. Clients of a business should contact that business first; we will help it respond. You can also complain to your data protection authority.
Security
Encrypted connections (HTTPS), hashed passwords, two-factor sign-in for our staff, strict access controls between workspaces, and nightly backups.
Contact
Email support@diagnostack.cloud. Last updated September 2026.