GDPR

For Users in the European Economic Area (EEA) & United Kingdom

1. Lawful Basis for Processing

We process your personal data under the following legal bases:

PurposeLegal BasisDetails
Appointment bookingsConsentYou voluntarily provide data when booking via TidyCal.
Client communicationsContractual NecessityRequired to fulfill service requests.
Website analyticsLegitimate InterestTo improve our services securely.

You may withdraw consent at any time by contacting us (does not affect prior processing).

2. Your GDPR Rights

As an EEA/UK resident, you have the right to:

RightWhat It Means
AccessRequest a copy of your personal data we hold.
RectificationCorrect inaccurate or incomplete data.
Erasure (“Right to Be Forgotten”)Request deletion of your data under certain conditions.
Restriction of ProcessingLimit how we use your data (e.g., while disputing accuracy).
Data PortabilityReceive your data in a structured, machine-readable format.
ObjectionOpt out of processing based on legitimate interests or direct marketing.

To exercise these rights, email [email protected]. We respond within 30 days (may extend for complex requests).

3. International Data Transfers

Your data may be transferred outside the EEA/UK (e.g., to our service providers in the US). We ensure safeguards such as:

  • Standard Contractual Clauses (SCCs) with third parties.
  • Data Processing Agreements (DPAs) compliant with GDPR Article 28.

4. Data Retention

We retain personal data only as long as necessary:

  • Booking data: 3 years (unless you request deletion).
  • Analytics data: Anonymized after 12 months.

5. Complaints

If you believe we violate GDPR, you may lodge a complaint with:

  • Your local EEA Data Protection Authority (DPA).
  • The UK Information Commissioner’s Office (ICO).

We’d appreciate the chance to address your concerns first, please contact us at [email protected]