Privacy Policy
Your privacy is important to us. Learn how we protect your data.
1. About Zenchronity
Zenchronity provides online HR software as SaaS (Software as a Service) that helps organisations manage leave, performance, and time tracking.
This Privacy Policy explains how we collect, use, and protect personal data in connection with our Service.
For privacy inquiries, contact: [email protected]
2. Data We Collect
Account Information: Personal and company-related information. All sensitive data is securely encrypted.
Billing Information: payment data, billing address, tax/VAT details.
Usage Data: IP, device, browser type, log files, access times.
Customer Data: any HR-related information entered by users (e.g., leave records, evaluations, attendance).
Communications: support requests, feedback, emails.
Cookies: see Cookie Policy for more details.
3. How We Use Data
We use personal data to:
- deliver and operate the Service (contractual necessity);
- process billing and payments (legal obligation);
- ensure security, detect misuse or fraud (legitimate interest);
- communicate service updates or notifications (contractual necessity);
- send optional marketing information (consent-based).
4. Data Sharing
We may share limited data with trusted service providers that support our operations, such as:
- payment processors;
- our hosting provider, which runs the servers and databases in the European Union;
- our email provider, which delivers confirmations, reminders and calendar invitations;
- a meeting provider you have connected yourself, which receives the appointment time, duration and title in order to create the meeting.
We do not sell personal data, and we do not share it for advertising. All partners comply with the GDPR or equivalent privacy standards.
4a. Zenchronity Calendar and connected meeting accounts
Zenchronity Calendar is our appointment scheduling product. A host publishes a booking link; a member of the public picks a free time and confirms it with a code sent to their email address. Where the host has connected a meeting account, the video meeting for that appointment is created there.
Data collected through a booking page
From the person booking we collect their name and email address, which are needed to confirm and deliver the appointment, their time zone so that times are shown correctly, a phone number and answers to further questions where the host asks for them, and the IP address the booking came from, which is used only to stop one visitor from flooding a host's calendar.
Names, email addresses, phone numbers, notes and answers are encrypted at rest with a key unique to the host's account, and that key is itself encrypted with a master key held outside the database. Appointment records are deleted 730 days after the appointment ends. These details belong to the host, who decides what to ask for and why; we process them on their instructions.
Zoom
A host may connect their own Zoom account. We request permission only to create a meeting, to move it when an appointment is rescheduled, to delete it when the appointment is cancelled, and to read the connected user's own id and email address once at connection time so we know whose connection it is. We request no access to recordings, participants, chat, webinars or account settings, and we store no meeting content.
Google Calendar and Google Meet
A host may connect their own Google account. We request exactly two Calendar scopes and no others:
calendar.app.created, which lets us create a calendar of our own inside the host's account and read or change only what we put in it. We cannot see, change or delete anything in the host's personal calendars.calendar.freebusy, which returns the intervals in which the host is busy. It carries no event titles, attendees, locations or descriptions.
We use this access for one purpose only: to keep a calendar event and its Google Meet link in step with an appointment booked on the host's page, and to avoid offering a time at which the host is already busy.
Zenchronity's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertising, we do not sell it, we do not transfer it to others except as needed to provide this feature or where required by law, and we allow no human to read it except with the host's explicit permission, for security purposes, or to comply with applicable law.
Credentials and disconnecting
The access and refresh tokens for a connected account are stored encrypted, in the same way as everything above, together with the connected account's user id and email address. Disconnecting from Settings revokes our access and deletes the stored tokens. Removing the application from the Zoom or Google account has the same effect: the provider notifies us and we delete them.
5. Data Retention
Zenchronity retains account, billing, and Customer Data only as long as necessary to operate the Service, comply with legal obligations, or resolve disputes.
After that period, data is securely deleted..
6. Data Security
We apply appropriate technical and organisational measures, including encryption, access controls, and regular monitoring, to protect data from loss, alteration, or unauthorised access.
7. User Rights
Users have the right to:
- access, correct, or delete their personal data;
- request data portability;
- withdraw consent at any time.
Requests can be sent to [email protected].
8. Children's Data
Zenchronity does not knowingly collect or process personal data from individuals under 16 years of age. If we become aware that a user is under the minimum age required by law, we will take steps to delete their account and any personal data collected.
9. Updates
We may update this Privacy Policy periodically. The most recent version will always be available at zenchronity.com/privacy.