Privacy
Last updated 29 July 2026.
Draft — not yet legally reviewed
This document describes how Kalio actually behaves, but it has not been checked by a qualified lawyer and 12 values are still unfilled, highlighted below. Do not rely on it, and do not put it in front of customers, until both are resolved.
What is still outstanding
- legal entity name
- registered address
- governing jurisdiction
- data protection authority and contact details
- hosting provider
- email provider
- safeguard for transfers outside the EEA
- how long server logs are kept
- how long after closure data is deleted
- notice given before a change takes effect
- limit of liability
- real contact domain
This explains what personal data Kalio holds, why it holds it, how long it keeps it, and what you can ask us to do with it. It is written to be read rather than to be defensible, and we have tried not to say anything here that the software does not actually do.
Who is responsible for what
There are two different relationships here, and they matter for your rights.
- For the businesses using Kalio — we decide how account data is handled, so we are the controller. That covers the email address you sign up with, your business details, and records of signing in.
- For a business’s customers — the business decides what it collects and why. It is the controller; we process that data on its instructions. If you booked an appointment and want your details changed or removed, ask the business you booked with first. We will help them do it, and we will act on a request sent directly to us where the law requires it.
The legal entity operating Kalio is [legal entity name], registered at [registered address].
What we hold
If you run a business on Kalio
- Your email address, and your name if you give one.
- Passkey credentials — a public key and an identifier for each device you enrol. Your fingerprint or face never leaves your device and is never sent to us; we could not reconstruct it from what we store.
- Your business details: name, address, contact details, opening hours, services, prices, photographs you upload.
- Sessions, so you stay signed in, and enough of a record of sign-ins to investigate suspicious access.
If you booked an appointment
- Your name and phone number, which is what the appointment is attached to.
- Your email address, if you gave one, so a confirmation and reminder can be sent.
- The appointment itself: what was booked, with whom, when, at what price, and any note you added.
- A short verification code, stored only as a one-way hash and only until it is used or expires.
Automatically
- A session cookie. It is what keeps you signed in and is not used for advertising or tracking across other sites.
- Ordinary server logs, including IP addresses, kept to keep the service running and to detect abuse. IP addresses are also counted, without being tied to your identity, to limit how many verification codes can be requested from one place.
We do not use advertising trackers, and we do not sell personal data.
Why we are allowed to hold it
- To perform a contract — you asked us to run your booking page, or you asked a business to hold an appointment for you.
- Legitimate interests — keeping the service secure, preventing abuse of the verification system, and diagnosing failures.
- Legal obligation — where we are required to retain something.
How long we keep it
- Customer details are anonymised automatically twelve months after a person’s last appointment. The appointment history survives; the name, phone number and email attached to it do not. This runs on its own, without anyone asking for it.
- Verification codes are deleted once used or expired — minutes, not months.
- Business and account data is kept while the account is open, and deleted on request.
- Logs are kept for [how long server logs are kept].
Who else sees it
Only the suppliers needed to run the service, and only as much as they need:
- [hosting provider] — where the application and database run.
- [email provider] — which delivers confirmations, reminders and sign-in links.
Where a supplier processes data outside the European Economic Area, that transfer is covered by [safeguard for transfers outside the EEA].
Your rights
You can ask us for a copy of your data, ask for it to be corrected, ask for it to be deleted, ask us to restrict what we do with it, object to processing based on legitimate interests, or ask for it in a portable form. Exercising any of these costs nothing.
Write to privacy@kalio.example. If you are not satisfied with our answer, you may complain to your national data protection authority — in Romania, that is [data protection authority and contact details].
Security
Sign-in uses passkeys rather than passwords, so there is no password of yours for us to leak or for anyone to guess. Data is transmitted over encrypted connections and stored on managed infrastructure. Verification codes are stored hashed, never in a form we could read back.
No system is perfect. If you believe you have found a weakness, please tell us at security@kalio.example before telling anyone else.
Children
Kalio is intended for businesses and is not directed at children. We do not knowingly collect data from a child except as a customer’s appointment details supplied by an adult booking on their behalf.
Changes
If this policy changes in a way that affects you, we will say so by email before the change takes effect rather than quietly editing the page. The date at the top always reflects the current version.
See also our terms of service.