Skip to content
CalMate
Magyar ← Back to home

CalMate Privacy Notice

Version: 1.3
Last updated: 2 August 2026
Effective date: 2 August 2026

1. Details of the data controller

Data controller: Turóczi Zsolt, sole proprietor
Registered office: 1118 Budapest, Rétköz utca 16. 1/5., Hungary
Registration number: 53750376
Tax number: 69832280-1-43
Privacy contact: privacy@calmate.hu

In this notice, the data controller may also be referred to as “CalMate”, “we”, “us” or the “controller”.

2. Scope of this notice and data protection roles

This notice applies to the CalMate iOS mobile application, the backend service supporting it, the public calmate.hu marketing website, and the workplace web administration interface accessible from the mobile application by QR code. The application is not intended for persons under the age of 16. If we become aware of an account belonging to a person under 16, please contact privacy@calmate.hu so that the account can be deleted.

CalMate’s role depends on the purpose of the processing:

  • In relation to user accounts, authentication, subscriptions, application security, customer support and operation of the platform, Turóczi Zsolt, sole proprietor, acts as an independent data controller.
  • Where workplace features are used by an employer, business or other organisation to manage employee schedules, workload data, leave requests or managerial decisions, the organisation determining the purposes of those operations is the data controller, while CalMate acts as a data processor on the organisation’s documented instructions. The organisation must also provide its own privacy information to the affected employees or contractors.
  • Where a shared workspace is created by an individual for their own purposes or for an informal group, CalMate acts as an independent controller in relation to the account and platform service. The creator and members are responsible for entering or sharing only data that may be processed lawfully. The GDPR household exemption may apply to processing carried out by an individual solely in the course of personal or household activity; this does not affect CalMate’s obligations under this notice.
  • For personal calendar, shift and earnings data recorded by the user for their own purposes, CalMate provides the service as an independent controller.

3. Data processing principles

We process only data necessary for the specified purposes. We do not sell personal data and do not use it to target third-party advertising. The CalMate mobile application and signed-in web interface do not use advertising or third-party analytics SDKs, cross-app or cross-service tracking, device or advertising identifiers, or location-based profiling. Product usage measurement required to improve the service, as described below, is performed by CalMate’s own backend. Google Analytics is used only for limited page and enquiry-funnel measurement on the public marketing website, with the consent settings described in Section 4.15.

We obtain data primarily from the user directly. Certain data may also originate from Sign in with Apple or Google sign-in, Apple subscription notifications, the user’s workplace, geocoding of the workplace address provided by the user through Geoapify, or technical events generated automatically while the service is used.

4. Individual processing activities

4.1. Registration, sign-in and account security

Item Description
Purpose Creating an account, identification, sign-in, verifying an email address, password reset, preventing abuse and protecting sessions.
Data processed Name, email address, securely generated password hash, selected language, email verification status, server-side timestamp and version recording acknowledgement of the privacy notice, hashes of one-time codes and reset tokens, number of failed attempts, authentication tokens, IP address and time of last activity.
Legal basis Performance of a contract (Article 6(1)(b) GDPR); for security and abuse-prevention data, legitimate interests (Article 6(1)(f) GDPR). Our legitimate interest is the secure operation of accounts and the service.
Retention Account data until the account is deleted; the authentication token for a given session until sign-out, revocation or account deletion; authentication codes are valid for 10 minutes and deleted within no more than 24 hours; technical security logs for no more than 30 days. Postmark stores email content and delivery activity data for the period configured in the Postmark account, by default 45 days. Bounced, spam-reported or blocked addresses may remain on a suppression list for as long as necessary to prevent delivery failures and abuse.

Passwords are not stored in readable form. A password reset request does not reveal whether an account exists for the specified email address.

Transactional emails required for email verification, password reset and other account or service operations are delivered through Postmark. For this purpose, the recipient’s email address and name, sender details, message subject and content, and technical metadata necessary for transmission and delivery verification are transferred.

When a user signs out, the current backend authentication token for that device is revoked and the associated push token link is removed. This does not automatically sign the user out on other devices.

4.2. Sign-in and account linking with an Apple or Google account

Item Description
Purpose Simplified sign-in, creation of a new account, and linking or unlinking an existing account.
Data processed Provider user identifier, email address, name, email verification status, Google profile image URL where applicable, the name and email address provided by Apple during the first authorisation, and token, authorisation code and nonce data required for authentication and later revocation of the connection. The Apple revocation token is stored by the backend in an encrypted database field.
Legal basis Performance of a contract at the user’s request (Article 6(1)(b) GDPR).
Retention Until the connection is unlinked or the account is deleted. Independent processing by Apple or Google is governed by the respective provider’s own privacy notice.

4.3. Profile and application settings

Item Description
Purpose Displaying and personalising the profile and providing language, theme, calendar and security settings.
Data processed Name, email address, optional profile image, language, interface and calendar settings, and whether biometric application lock is enabled.
Legal basis Performance of a contract (Article 6(1)(b) GDPR); for an optional profile image, the user’s voluntary choice, which may be withdrawn at any time (Article 6(1)(a) GDPR).
Retention Until modification, removal or account deletion.

When Face ID or Touch ID is used, the biometric template is handled by Apple’s operating system. CalMate receives only the result of the local authentication; it does not receive the biometric template and does not transmit it to the server.

4.4. Personal shift, calendar, pay and statistical data

Item Description
Purpose Recording shifts and templates, calculating earnings and working time, managing pay periods, deductions, tips, commission and statistics, and sending reminders.
Data processed Shift name, date, start and end time, historical workplace name and logo, note, colour, base salary or hourly rate, currency, tip, commission, bonus, deduction name and note, pay schedule and calculated totals.
Legal basis Performance of the contract with the user (Article 6(1)(b) GDPR).
Retention Until deleted by the user or until the account is deleted. Historical workplace snapshots are retained for as long as the shift record containing them remains.

CalMate’s calculations are for information only and do not constitute an official payslip or tax advice. Other members of a workplace do not gain access to a user’s personal earnings data merely because they belong to the same workplace.

4.5. Workplace, membership and shift planning

In the application, a “workplace” means a shared workspace; its creator is not necessarily an employer or organisation.

Item Description
Purpose Creating and managing a workplace, connecting members, managing permissions, positions, workload limits, shift templates and workplace schedules, transferring ownership, maintaining an activity log, displaying the workplace location in calendar events and providing a local weather forecast.
Data processed Workplace name, category, logo and join code; optional country, postal code, city, address and geographic coordinates derived from them; weather forecast associated with the workplace; member name, profile image, position, administrator role, weekly target and maximum workload; schedules, templates, planning versions, and the identity and timestamp of the person creating or modifying them.
Legal basis For an informal shared workspace created by an individual, performance of the platform service requested by the users (Article 6(1)(b) GDPR). For employer or organisational use, the organisation determines the legal basis for processing employee data, and CalMate acts as processor in accordance with its documented instructions (Article 28 GDPR).
Retention For the lifetime of the workplace, until the relevant data is deleted, or until instructed by the controller operating the workplace. Historical shift data retained in the user’s own calendar is governed by Section 4.4.

Members may see one another’s names, profile images and shared shift data to the extent required by the feature. The workplace owner and authorised administrators may have broader access for managing schedules, positions, workload and absences.

Providing a workplace address is optional. The address entered is transmitted to the Geoapify geocoding service to determine geographic coordinates. The coordinates are sent to Apple WeatherKit to retrieve a local weather forecast; no CalMate user identifier is attached to them. When creating an informal group, please do not enter a private residential address unless it is necessary for use of the feature.

4.6. Absence and availability requests

Item Description
Purpose Indicating days on which work cannot or should not be undertaken, managerial review of requests, and comparison with shift planning.
Data processed Affected user, workplace, start and end date, request type and status, optional written reason, person creating and reviewing the request, decision and timestamps.
Legal basis For an informal shared workspace, performance of the service requested by the user (Article 6(1)(b) GDPR). For employer or organisational use, the legal basis determined by the organisation; CalMate acts as the organisation’s processor.
Retention For employer or organisational use, according to the controller organisation’s instructions, internal policy and applicable employment-law requirements; for informal use, until the shared workspace, the relevant data or the user account is deleted.

The reason field is not intended for medical documentation. Please do not enter a diagnosis, medical record, religious or political information, or other special-category personal data unless this is strictly necessary and the workplace has provided appropriate prior information and a valid legal basis.

4.7. Workplace chat and user content

Item Description
Purpose Sharing workplace messages, images and announcements, reactions, real-time delivery, unread status and notification management.
Data processed Message text, uploaded image, announcement, author name and profile image, workplace, reaction, read timestamp, and creation and modification data. Image technical metadata may be modified or removed during processing before upload.
Legal basis Performance of the service requested by the user (Article 6(1)(b) GDPR); where workplace communication is required by the workplace, the legal basis determined by the workplace and its processor instructions. After account deletion, preserving the continuity of the workplace conversation and the legitimate expectations of other participants may constitute a legitimate interest of the workplace or participants (Article 6(1)(f) GDPR).
Retention Until the content or workplace is deleted, or until the controller workplace instructs its deletion. When an account is deleted, the link to the author’s account is removed and the author’s name and profile image disappear, but previously sent messages and image attachments remain in the workplace conversation under the author name “Deleted user”.

Users are responsible for sharing only images or personal data that they are entitled to share. Chat content is visible to the relevant members of the workplace. Removing the link to the author’s account does not itself anonymise text or an image that can still be linked to a person based on its content. A data subject may therefore request an individual review and deletion of a specific identifying message or image attachment by contacting privacy@calmate.hu.

4.8. Shift handovers

Item Description
Purpose Creating a shift handover request, recipient and managerial decisions, notifications and history.
Data processed Person handing over the shift and recipient, affected shift data, workplace, status, decision-makers, timestamps and a historical snapshot of the shift.
Legal basis Performance of the service, or the legal basis and processor instructions determined by the workplace.
Retention Until the relevant account or workplace is deleted, or until instructed by the workplace.

4.9. Notifications

Item Description
Purpose Notifying users about schedule, earnings, shift handover, workplace, message and absence events in the application or by push notification.
Data processed Notification type, title, text, language, related event identifiers, creation and read timestamps, category and channel settings, and Expo push token.
Legal basis For in-app notifications necessary for the service, performance of a contract (Article 6(1)(b) GDPR); for optional push notifications, consent (Article 6(1)(a) GDPR).
Retention In-app notifications for no more than 12 months; push token until permission is withdrawn, sign-out, token change or account deletion.

Push permission can be disabled in the operating system settings, while category-specific push delivery can be disabled in CalMate’s notification settings.

4.10. Calendar feed and external calendar providers

Item Description
Purpose Displaying shifts in Apple Calendar, Google Calendar, Outlook or another calendar application selected by the user.
Data processed Secret calendar feed token, shift name, date, start and end time, and related data required for the calendar event.
Legal basis Performance of the service at the user’s explicit request (Article 6(1)(b) GDPR).
Retention Until the feed token is revoked or the account is deleted. Retention of data already downloaded to an external calendar is controlled by the selected provider and the user.

The calendar feed URL must be treated as a secret link. Anyone with access to it may view the shift data available through the URL. The user is responsible for sharing the link only with a trusted service or person.

4.11. Apple subscriptions

Item Description
Purpose Purchasing a subscription, verifying and restoring entitlement, and processing renewal and refund events.
Data processed App account token associated with the CalMate account, product identifier, original and latest transaction identifier, subscription status, expiry, revocation, environment, and the necessary data from Apple-signed transactions and server notifications. CalMate does not receive bank card details.
Legal basis Performance of a contract (Article 6(1)(b) GDPR); for accounting and tax data, compliance with a legal obligation (Article 6(1)(c) GDPR).
Retention For as long as required to manage service entitlement, and for data subject to accounting or legal obligations, for up to 8 years.

Deleting a CalMate account does not automatically cancel an auto-renewing Apple subscription. The subscription can be managed and cancelled in the Apple account subscription settings.

4.12. AI-assisted shift planning

Item Description
Purpose Creating an editable monthly shift schedule proposal based on staffing requirements entered by an authorised user.
Data processed Month and daily staffing requirements; pseudonymised internal user identifiers and positions; shift template identifier, name, start time, end time and colour; dates and template identifiers of existing shifts; and the schedule proposal returned by the AI. We do not send names, email addresses, profile images, pay data or free-text shift notes to the AI provider.
Legal basis For an informal shared workspace, performance of the service requested by the user (Article 6(1)(b) GDPR). For employer or organisational use, the legal basis determined by the organisation; CalMate acts as processor and OpenAI as sub-processor.
Recipient OpenAI Ireland Limited and sub-processors involved in operating the OpenAI API.
Retention The proposal becomes a saved schedule only after an authorised user applies it. Request and response data contained in CalMate’s technical logs is subject to the maximum 30-day period set out in Section 4.13. OpenAI API’s default abuse-monitoring logs may retain inputs, outputs and associated metadata for up to 30 days, unless a longer period is required by law.

AI-generated results are proposals and may be inaccurate or unsuitable. An authorised person always decides whether to save and publish the schedule. By default, OpenAI does not use inputs and outputs transmitted through the API to train its models, unless the administrator of the API account explicitly enables data sharing.

4.13. Technical operation, logging and administrative actions

Item Description
Purpose Troubleshooting, performance monitoring, availability, preventing attacks and abuse, permission management, user suspensions and administrator accountability.
Data processed IP address, URL and request time, user identifier, last activity; a non-reversible, user-scoped hash derived from the mobile application’s random installation identifier; iOS or Android platform, device model, operating-system, application and build version, first and last use; technical details of errors and slow requests; administrator and affected user identifier/email address, action, reason, user agent and metadata. We do not collect the device name chosen by the user. Request content is logged only where necessary to investigate a specific error or security incident.
Legal basis Legitimate interests (Article 6(1)(f) GDPR); for legal claims and obligations imposed by authorities, compliance with a legal obligation (Article 6(1)(c) GDPR). Our legitimate interest is the secure and auditable operation of the service.
Retention General technical and security logs for no more than 30 days; Laravel Pulse performance data for 7 days; account-linked device records for no more than 12 months after last use and no later than account deletion; administrator audit logs for 5 years.

4.14. First-party product analytics

Item Description
Purpose Understanding which main features signed-in users use, where they encounter difficulties in onboarding, personal, Workplace and subscription flows, and measuring aggregated daily, weekly and monthly activity and retention.
Data processed Internal user identifier; for server-side Workplace milestones, internal workplace identifier; allowed event type and timestamp; logical screen name; iOS or Android platform; application and build version; selected language; subscription product family, product identifier and production or sandbox environment; subscription entry source; normalised technical error code. Analytics do not include name, email address, pay amount, workplace name, shift date or note, chat message, invitation code, full URL, advertising identifier or device identifier.
Legal basis Legitimate interests (Article 6(1)(f) GDPR). Our legitimate interest is improving the usability, stability and business processes of the service based on minimal event data that does not contain content. A user may object at any time on grounds relating to their particular situation by contacting privacy@calmate.hu.
Recipient No external analytics provider is used for this first-party product analytics. The data is processed by CalMate’s own backend and database located in the EU/EEA; only the global system superuser has access to the detailed dashboard.
Retention Raw events linkable to a user are stored for no more than 90 days. Daily aggregates that do not contain user or workplace identifiers are retained for no more than 24 months. Segmented aggregates involving fewer than five data subjects are not retained permanently.

The mobile application sends product analytics events only after successful sign-in and email verification. The application does not create an anonymous installation profile and does not store events persistently for later transmission if a network error occurs.

Where an objection is accepted, CalMate excludes the user from future product analytics and deletes raw events that can be linked to them. Previously generated aggregated statistics that can no longer be linked back to the data subject may be retained.

4.15. Public marketing website measurement

First-party store redirect measurement

The internal calmate.hu/app-store, calmate.hu/play-store and calmate.hu/en/download routes use first-party measurement that cannot be linked to a person to aggregate how often visitors are redirected to CalMate’s App Store or Google Play product page. The /en/download route selects a destination store based on the visitor’s platform category and otherwise displays a store selector; viewing that selector does not itself count as a click. This measurement does not use cookies or browser storage and is independent from the Google Analytics consent state.

Processing element Description
Purpose Measuring the aggregated performance of store CTAs, the platform-aware download route and campaign sources.
Data processed Predefined destination store and CTA placement; visitor platform category; website language; timestamp; and utm_source, utm_medium, utm_campaign and utm_content values limited to 120 characters. In the restaurant email campaign, utm_content may only be a random anonymous recipient code; it must not contain a name or email address. We do not store the IP address, user agent, referring page, CalMate account identifier or session identifier.
Legal basis The controller’s legitimate interest in understanding aggregated marketing-site performance (Article 6(1)(f) GDPR).
Recipient No external analytics provider is used; the data is processed by CalMate’s own backend and database located in the EU/EEA, and only the global system superuser can access the report.
Retention Raw redirect records are retained for no more than 90 days.

The mapping between the anonymous recipient code and a restaurant is held by the campaign mailing list, not by the CalMate website or application. Restaurant-level attribution ends at the store redirect: the code is not linked to any later registration, user account or subscription.

Google Analytics

Google Analytics operates only on the calmate.hu marketing home page, publicly available workplace-category pages and the /en/download store-selector page. Automatic /en/download redirects do not send a Google Analytics event. It is not loaded on the sign-in or signed-in web interfaces, the Privacy Notice or Cookie Notice page, or any account-deletion request or confirmation page.

Item Description
Purpose Measuring aggregated marketing-site traffic, campaign sources, interest in Personal and Workplace content, views of important restaurant-landing sections, CTA use, the enquiry funnel, and enquiries successfully stored or delivered by email.
Data processed Consent state; after consent, a randomly generated browser identifier and session cookie; sanitised page path and page title; referring page; timestamp; website language; browser, device and approximate geographic information; allow-listed campaign parameters; predefined event name; Personal, Workplace or general audience marker; CTA location; workplace category; allow-listed enquiry type; and the 1–3, 4–5, 6–10, 11–25, 26–50 or 51+ team-size band instead of the exact team size. Names, email addresses, workplace names, messages, lead or user identifiers and form-field values are not sent to Google Analytics.
Legal basis Consent for analytics cookies and full measurement (Article 6(1)(a) GDPR). Before consent or where consent is declined, Consent Mode may transmit limited cookieless measurement signals; the purpose is aggregated marketing-site performance measurement and the legal basis is the controller’s legitimate interest (Article 6(1)(f) GDPR). Advertising storage, Google Signals, remarketing and personalised advertising are disabled.
Recipient Google Ireland Limited and the Google group companies and sub-processors involved in operating Google Analytics.
Retention The CalMate consent cookie and Google Analytics _ga cookies remain valid for no more than 12 months. GA4 event- and user-level data retention is 14 months. Google’s standard aggregated reports may be subject to different provider retention rules.

Consent can be given or withdrawn at any time through the “Cookie settings” button on any CalMate web interface. On withdrawal, future analytics storage is disabled and _ga cookies belonging to the calmate.hu host are deleted. Declining consent does not restrict use of the marketing website or the CalMate service. The Cookie Notice contains the detailed list of cookies, browser storage and Advanced Consent Mode behaviour.

4.16. Restaurant enquiries and reCAPTCHA protection

The short form on the restaurant landing page does not create a record in CalMate’s lead database. After a successful security check, the submitted content is delivered directly to CalMate’s support address as an email notification.

Item Description
Purpose Receiving requests for a personal demonstration, a tailored solution above 50 people or a branded application; preventing automated abuse and unsolicited submissions.
Data processed Email address and selected enquiry type; optionally restaurant name, team size and message; source page and allow-listed utm_source, utm_medium, utm_campaign and utm_content; technical interaction and browser information, token, hostname, action name and risk score required by reCAPTCHA. The server does not send a separate remoteip field for reCAPTCHA verification.
Legal basis Taking steps at the interested person’s request before entering into a contract (Article 6(1)(b) GDPR); preventing spam and abuse is the controller’s legitimate interest (Article 6(1)(f) GDPR).
Recipient Postmark for delivery of the enquiry email; Google Ireland Limited, Google group companies and sub-processors acting as processors for reCAPTCHA risk analysis.
Retention No lead record is created in the CalMate application database. The delivered email and related correspondence may be retained for up to 5 years after the matter is closed; retention of reCAPTCHA data is governed by Google’s service terms.

reCAPTCHA may use the necessary _GRECAPTCHA cookie for risk analysis. It is a security cookie and therefore does not depend on analytics consent. Names, email addresses, restaurant names, messages and exact team sizes submitted in the form are not sent to reCAPTCHA.

4.17. Privacy and customer support enquiries

Item Description
Purpose Responding to questions, bug reports and data subject requests, demonstrating compliance and handling legal claims.
Data processed Name, email address, message and attachments, data required for identification, responses and timestamps of actions taken.
Legal basis Compliance with a legal obligation (Article 6(1)(c) GDPR); for non-privacy support, performance of a contract (Article 6(1)(b) GDPR); for legal claims, legitimate interests (Article 6(1)(f) GDPR).
Retention For 5 years after closure of the matter, unless a shorter period is sufficient or a longer period is required by law.

5. Device permissions and locally stored data

The mobile application may request the following device permissions:

  • Camera: to scan a workplace or web administration QR code, or to take a chat image at the user’s choice.
  • Photo library: to select a profile image, workplace logo or chat image.
  • Notifications: to display push notifications.
  • Face ID/Touch ID: to unlock the application locally.

The application may store the sign-in token and push token, the biometric application-lock setting, theme, calendar settings, workplace category cache and certain cached home-screen summaries in secure storage on the device. As a rule, these are not transmitted for any other purpose and may be deleted on sign-out or when the related feature is reset.

CalMate’s currently active features do not request access to contacts or the device’s precise location. An optionally provided workplace address and the coordinates derived from it do not originate from the device’s location services. The active features covered by this notice do not use the microphone.

6. Recipients and processors

Personal data is transferred or made accessible only to the extent necessary for the relevant purpose:

Recipient or category Role and purpose Location of processing
Contabo GmbH (Aschauer Straße 32a, 81549 Munich, Germany) Server infrastructure managed by CalMate in Germany. The backend, database, file storage and Reverb real-time connection run on the same server. Germany (EU/EEA)
AC PM LLC (Postmark; 1 N Dearborn Street, Suite 500, Chicago, IL 60602, United States) and its sub-processors Transmission of transactional emails—including email verification, password reset, security and service notifications, and customer support messages—and management of delivery status. Data transferred may include the recipient’s name and email address, sender details, message subject and content, and delivery, bounce and spam-complaint metadata. United States; data centres of infrastructure providers involved in the service
650 Industries, Inc. (Expo) and its sub-processors EAS Update, Expo push token and transmission of push messages EU/EEA and United States
Apple group companies Sign in with Apple, App Store subscriptions, APNs push delivery; provision of WeatherKit weather forecasts based on workplace coordinates EU/EEA and other countries, including the United States
Google Ireland Limited, Google group companies and sub-processors Google sign-in; external Google Calendar where selected by the user; consent-controlled Google Analytics measurement on the public marketing website; reCAPTCHA spam and abuse protection for the restaurant enquiry form EU/EEA and other countries, including the United States
KEPTAGO LTD (Geoapify; N. Nikolaidi and T. Kolokotroni, ONISIFOROU CENTER, 8011 Paphos, Cyprus) Converting a workplace address provided by the user into geographic coordinates Primarily European Union; may also depend on the provider’s sub-processor network
OpenAI Ireland Limited and its sub-processors Creating AI-assisted shift planning proposals from pseudonymised scheduling data Ireland, EU/EEA and other countries, including the United States
Calendar provider selected by the user Calendar feed subscription initiated by the user Depends on the selected provider
Workplace members, owner and authorised administrators Providing scheduling, membership, absence and workplace communication features Depends on the location of the workplace and its members
Accountant, legal representative, authority or court Compliance with a legal obligation, legal claim or official request Depends on the relevant recipient

The current list of each provider’s sub-processors and details of its independent processing are available in the provider’s own privacy information.

7. Transfers to third countries

CalMate’s primary server and the database, file storage and Reverb service operating on it are located in Germany, within the European Economic Area. However, through Apple, Google, Expo, Postmark and OpenAI services, certain data may also be processed outside the European Economic Area, particularly in the United States. Data contained in emails transmitted through Postmark may be processed in the United States by AC PM LLC and its sub-processors. Depending on the provider and data flow concerned, the lawfulness of the transfer is ensured by a European Commission adequacy decision, the EU–US Data Privacy Framework, Standard Contractual Clauses adopted by the European Commission, or another appropriate safeguard under Chapter V GDPR.

Detailed provider information:

  • Contabo Privacy Policy
  • Postmark / ActiveCampaign Privacy Policy
  • Postmark Data Processing Addendum
  • Postmark EU privacy and subprocessors
  • Expo Privacy Policy
  • Expo Subprocessors
  • Apple Privacy Policy
  • Google Privacy Policy
  • Google data transfer frameworks
  • Google Analytics privacy safeguards
  • Geoapify Privacy Policy
  • OpenAI business data privacy
  • OpenAI API data controls
  • OpenAI Data Processing Addendum
  • OpenAI sub-processor list

Users may request further information about the safeguard used for a specific transfer by contacting privacy@calmate.hu.

8. Automated decision-making and profiling

CalMate does not make decisions based solely on automated processing that produce legal effects concerning the user or similarly significantly affect them within the meaning of Article 22 GDPR.

The shift planner may use conventional calculations or AI to create proposals based on the shifts, staffing requirements, workload limits and absences entered, but an authorised person decides whether to save and publish the plan. Such a proposal does not constitute an automated employment decision.

9. Data security

To protect data, we use measures including encrypted network connections, password hashing, token-based authentication, role- and workplace-based permissions, logged administrator actions and local storage protected by the operating system.

No IT system can guarantee complete security. In the event of a personal data breach, we act in accordance with Articles 33–34 GDPR and, where there is a high risk, also inform the affected data subjects.

10. Account deletion

Users may initiate deletion of their account in the application settings or, without signing in, at https://calmate.hu/en/delete-account. The web process verifies access to the account’s email address by sending a one-time link to the registered email address that is valid for 60 minutes. Opening the link does not itself delete the account: permanent deletion must be confirmed through a separate action on the next page.

If a confirmed request cannot be completed automatically—for example because the user owns a workplace or secure revocation of the Apple connection requires further action—we record the request and provide assistance by email with the necessary steps. Reinstallation of the mobile application is not required. Minimal audit data demonstrating completion of the request is retained for no more than 5 years after the matter is closed.

If the user owns a workplace, they must transfer ownership or delete the workplace before deleting the account.

Deletion covers the account, authentication tokens, profile image, personal shift and pay data, settings and notifications. A deleted account and its data cannot be restored. Messages and image attachments previously sent in workplace chat remain to preserve the continuity of the conversation, but the link to the author’s account, name and profile image are removed, and the author is displayed as “Deleted user”. Data necessary for accounting, security audits or legal claims may be retained separately for the limited periods specified in Section 4 and will not be used for any other purpose.

Before deleting a CalMate account linked to an Apple account, the backend revokes the Sign in with Apple connection. If a revocation token is not yet available for a previously created account, the application requests one-time Apple re-authentication as part of deletion; if this fails, account deletion does not take place.

Where Sign in with Apple is used, CalMate also revokes the associated developer connection. Deletion of a Google or Apple account independently of CalMate must be handled by the user with the relevant provider.

An Apple subscription may continue independently of deletion of the CalMate account and must therefore be cancelled separately in the Apple account subscription settings.

11. Rights of data subjects

Subject to the applicable conditions, you have the right to:

  • request information about and access to your personal data processed by us;
  • request correction of inaccurate data or completion of incomplete data;
  • request deletion of your data (“right to be forgotten”);
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
  • receive personal data you have provided, where processed by automated means on the basis of a contract or consent, in a structured, commonly used and machine-readable format, and request its transmission to another controller;
  • lodge a complaint with a supervisory authority and seek a judicial remedy.

Requests may be sent to privacy@calmate.hu. We request only the additional information necessary to verify identity. We respond without undue delay and, as a rule, within one month. For complex or multiple requests, this period may be extended by a further two months; we will inform you of the extension within one month.

Where a request concerns processing determined by an employer or another organisation, we may forward the request to that organisation as controller or fulfil it in cooperation with the organisation.

12. Complaints and legal remedies

Please first send any complaint to privacy@calmate.hu so that we can investigate it directly.

You have the right to lodge a complaint with the supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
Postal address: 1363 Budapest, P.O. Box 9., Hungary
Email: ugyfelszolgalat@naih.hu
Website: https://www.naih.hu

A data subject may also bring proceedings before the competent regional court based on their place of residence or stay, or before the court competent for the controller’s registered office.

13. Amendments to this notice

We update this notice when a new feature or processor is introduced, the law changes, or the processing is materially modified. The current version is made available on CalMate’s public privacy page. Where necessary, we also provide notice in the application or by email of material changes affecting users’ rights or choices.

14. Legal and regulatory references

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)
  • NAIH – information on data subject rights
  • NAIH – data protection authority procedure
  • Apple – offering account deletion in your app
  • Apple – managing App Store privacy information
CalMate Cookie Notice

Privacy control

Your choices stay in your hands.

CalMate uses essential storage to keep the website secure. With your permission, we can also remember interface preferences and use Google Analytics on the public marketing pages.

If analytics storage is declined, Advanced Consent Mode may still send limited cookieless measurement signals to Google from the marketing pages.

Read the Cookie Notice

Privacy control

Choose what CalMate may remember

Your choice applies to the public website and the CalMate web administration interface. You can change it here at any time.

01

Essential

Authentication, security, forms and your consent choice. These cannot be disabled.

Always active
02
03
Read the Cookie Notice