This Notice explains how Software Programming Group LLC, located at 5 Independence Way, Suite 300, Princeton, New Jersey 08540, United States (we, us, or Provider), handles Personal Data in connection with CalendNow at calendnow.ai. Contact privacy@calendnow.ai for privacy questions and requests.
1. Our role and the Host’s role
We determine the purposes and means of processing account relationships, billing, support for our own operations, website administration, and service security. For those activities we act as a controller or equivalent business under applicable law. This Notice addresses those activities and explains the boundary with Customer-controlled information.
When a Host uses CalendNow to collect booking details, manage invitee contacts, or send a scheduling workflow, the Host generally determines the purpose of that processing and we process on its behalf under the DPA. The Host’s notice governs its own use. Contact the Host for requests concerning its booking records. We will assist the Host as required and will handle any independent processing within our own responsibility. An employer or organization may also administer a user’s workspace and permissions.
2. Information processed
Account and organization information includes names, email addresses, account identifiers, organization and workspace details, roles, profile settings, authentication and recovery information, and subscription entitlements. We use this information to establish accounts, manage access, and communicate about the service.
Booking information may include a Host’s availability and time zone; event descriptions, times, durations, and meeting links; invitee names and contact details; responses to configured booking questions; booking history; and changes or cancellations. The fields collected depend on the Host’s configuration. Booking content is processed for the Host, except where a specific independent purpose such as investigating abuse or responding to a direct support request applies.
Integration information includes connected account identifiers, granted permissions, authorization tokens or credentials necessary for the selected connection, and event or meeting information exchanged to deliver the chosen function. Custom SMTP configuration may include server settings and credentials. The actual scopes are presented in the relevant authorization process. Do not provide a third-party account password unless an authorized configuration explicitly requires that credential.
Billing information includes billing contact and address, Plan, payment status, invoice and transaction records, and payment-method information supplied through the approved payment flow. The payment provider’s own notice governs its independent fraud prevention and other processing.
Technical and usage information includes IP address, browser and device characteristics, access times, account and event activity, diagnostic records, and information needed to detect misuse or investigate faults. An IP address may indicate an approximate location. Cookie and similar-technology processing is described in the Cookie Policy.
Support information includes the contact details, issue descriptions, correspondence, and any attachments or examples a person chooses to supply. Do not include unnecessary sensitive information or credentials in a support request. Where an administrator opens a ticket for a Customer, relevant account and troubleshooting details may be included.
3. Sources and purposes
We receive information directly from users and participants, from Hosts and organization administrators, from authorized integrations, from billing providers, and from technical activity on the website and service. We do not assume that information was collected with consent merely because a Customer supplied it.
We use information to deliver and support scheduling, administer accounts and memberships, process purchases, issue invoices, communicate service changes, maintain security, prevent fraud, investigate misuse, meet legal obligations, and resolve disputes. We may analyze appropriate operational information to understand service reliability and improve usability, subject to applicable law and the limits of the DPA for Customer Personal Data.
If we send our own promotional communications, we do so under the permission or other lawful basis applicable to the recipient and provide an opt-out. Transactional account and booking messages are distinct from promotional messages. Optional cookies or advertising processing require the choices described in the Cookie Policy and applicable law.
We do not obtain a general-purpose AI training license to Customer Data through the Customer Terms. The supplied scheduling service does not, by this Notice, establish meeting recording, transcription, or an AI assistant. If a new function changes data collection or use, its disclosures and legal basis must be addressed before that processing begins.
4. Legal bases where required
Where a law requires a legal basis, we process account and purchase information as necessary to perform a contract with the individual concerned; meet legal duties such as accounting and lawful requests; pursue legitimate interests such as secure administration, fraud prevention, support, and service improvement after considering individuals’ rights; or rely on consent where required, including certain marketing or optional browser technologies.
For an organization’s personnel who are not personally parties to the subscription contract, relationship administration generally relies on an applicable legitimate interest or other appropriate basis, rather than treating the organization’s contract as a contract with every individual. Consent may be withdrawn prospectively without affecting earlier lawful processing. Customer-directed processing follows the Customer’s instructions and legal basis under the DPA.
5. Recipients and disclosures
We disclose information to vendors that provide relevant hosting, infrastructure, communications, payment, support, security, and operational services, subject to appropriate contractual protections and role classification. The completed Subprocessor Register identifies vendors processing Customer Personal Data on our behalf.
Hosts and authorized organization personnel receive booking and workspace information according to their permissions. A meeting or calendar connection sends information to the selected provider as required by the requested function. A Host’s group invitation settings or external service may disclose attendee information to other participants. Review those settings before using a group workflow for a confidential meeting.
We may disclose information where legally required, to protect rights and safety, investigate credible fraud or abuse, or establish or defend legal claims, using proportionate measures. In a merger, acquisition, or asset transfer, relevant information may be disclosed under confidentiality restrictions and transferred subject to applicable law and appropriate notice. Corporate affiliation alone does not authorize unrestricted data sharing.
6. Retention and deletion
We retain independent account information while necessary to administer the relationship and for a reasonable period afterward to resolve support issues and disputes. Billing and tax records are retained for applicable legal periods. Security and diagnostic information is kept for the period reasonably needed to detect, investigate, and prevent misuse, taking account of risk and legal obligations. Cookie lifetimes are listed in the completed Cookie Policy inventory.
We do not keep identifiable information indefinitely merely because storage is available. A legal hold may delay deletion only for the relevant information and purpose. Information retained under an exception remains protected and restricted to that purpose.
Customer-controlled information is retained and deleted under the DPA and the Customer’s instructions. The proposed contractual process permits a 30-day return request after termination, active-system deletion within 60 days after termination absent an earlier lawful instruction, and backup expiry within 90 days after active deletion. These periods must be adopted consistently with the final DPA and actual technical operation. Disconnection of an integration does not delete independently retained copies at that provider.
7. International processing
Personal Data may be processed in a country with different legal protections. Where a restricted transfer requires safeguards, we use an applicable approved mechanism and any necessary supplementary protections. Details or copies of relevant safeguards, subject to lawful redactions, may be requested at privacy@calendnow.ai.
8. Your rights and choices
Depending on applicable law and our role, you may request access, a copy or portability of information, correction, deletion, restriction, objection, or withdrawal of consent. Some US state laws provide opt-outs from sale, sharing, targeted advertising, or certain profiling, and limits on specified sensitive-information use. The California supplement explains relevant California rights. Rights may be subject to lawful exceptions.
Submit requests by email to privacy@calendnow.ai. We may request information reasonably necessary to verify a request or an authorized agent’s authority; we will not request more information than reasonably needed. We respond within applicable statutory periods and explain any lawful extension or denial. Where an appeal right applies, reply to the decision with an appeal. You may also contact your competent privacy regulator. We will not unlawfully discriminate for exercising privacy rights.
For Host-controlled records, contact the Host. If you contact us, we may identify or forward the request to the relevant Host where appropriate and assist it under the DPA. To unsubscribe from our marketing, use the message’s opt-out or contact us. Cookie and browser choices are explained in document 2.3.
9. Children and security
The standard service is intended for adult use, subject to the Children and Education Privacy Notice. We do not knowingly invite children under 13 to supply information through the standard service. Contact us if you believe a child has provided information improperly.
We use safeguards appropriate to the nature and risks of the processing and restrict access according to operational need. No online system is immune from risk. Report suspected compromise through security@calendnow.ai. The Security Statement and completed DPA security schedule provide the applicable information without implying unverified certifications.
10. Updates and contact
We will update this Notice when relevant practices or legal requirements change and provide additional notice where a material change requires it. A new purpose requiring consent or another lawful basis will not be authorized merely by updating this page. Our contact is privacy@calendnow.ai, Software Programming Group LLC, 5 Independence Way, Suite 300, Princeton, New Jersey 08540, United States.