CalMate Privacy Notice
Version: 1.0
Last updated: 22 July 2026
Effective date: 19 July 2026
1. Details of the data controller
Data controller: Turóczi Zsolt, sole proprietor
Registered office: 1118 Budapest, Rétköz utca 16. 1/5., Hungary
Registration number: 53750376
Tax number: 69832280-1-43
Privacy contact: privacy@calmate.hu
In this notice, the data controller may also be referred to as “CalMate”, “we”, “us” or the “controller”.
2. Scope of this notice and data protection roles
This notice applies to the CalMate iOS mobile application, the backend service supporting it, and the workplace web administration interface accessible from the mobile application by QR code. The application is not intended for persons under the age of 16. If we become aware of an account belonging to a person under 16, please contact privacy@calmate.hu so that the account can be deleted.
CalMate’s role depends on the purpose of the processing:
- In relation to user accounts, authentication, subscriptions, application security, customer support and operation of the platform, Turóczi Zsolt, sole proprietor, acts as an independent data controller.
- Where workplace features are used by an employer, business or other organisation to manage employee schedules, workload data, leave requests or managerial decisions, the organisation determining the purposes of those operations is the data controller, while CalMate acts as a data processor on the organisation’s documented instructions. The organisation must also provide its own privacy information to the affected employees or contractors.
- Where a shared workspace is created by an individual for their own purposes or for an informal group, CalMate acts as an independent controller in relation to the account and platform service. The creator and members are responsible for entering or sharing only data that may be processed lawfully. The GDPR household exemption may apply to processing carried out by an individual solely in the course of personal or household activity; this does not affect CalMate’s obligations under this notice.
- For personal calendar, shift and earnings data recorded by the user for their own purposes, CalMate provides the service as an independent controller.
3. Data processing principles
We process only data necessary for the specified purposes. We do not sell personal data and do not use it to target third-party advertising. CalMate does not use advertising SDKs or third-party analytics SDKs, cross-app or cross-service tracking, device or advertising identifiers, or location-based profiling. Product usage measurement required to improve the service, as described below, is performed by CalMate’s own backend.
We obtain data primarily from the user directly. Certain data may also originate from Sign in with Apple or Google sign-in, Apple subscription notifications, the user’s workplace, geocoding of the workplace address provided by the user through Geoapify, or technical events generated automatically while the service is used.
4. Individual processing activities
4.1. Registration, sign-in and account security
| Item | Description |
|---|---|
| Purpose | Creating an account, identification, sign-in, verifying an email address, password reset, preventing abuse and protecting sessions. |
| Data processed | Name, email address, securely generated password hash, selected language, email verification status, server-side timestamp and version recording acknowledgement of the privacy notice, hashes of one-time codes and reset tokens, number of failed attempts, authentication tokens, IP address and time of last activity. |
| Legal basis | Performance of a contract (Article 6(1)(b) GDPR); for security and abuse-prevention data, legitimate interests (Article 6(1)(f) GDPR). Our legitimate interest is the secure operation of accounts and the service. |
| Retention | Account data until the account is deleted; the authentication token for a given session until sign-out, revocation or account deletion; authentication codes are valid for 10 minutes and deleted within no more than 24 hours; technical security logs for no more than 30 days. Postmark stores email content and delivery activity data for the period configured in the Postmark account, by default 45 days. Bounced, spam-reported or blocked addresses may remain on a suppression list for as long as necessary to prevent delivery failures and abuse. |
Passwords are not stored in readable form. A password reset request does not reveal whether an account exists for the specified email address.
Transactional emails required for email verification, password reset and other account or service operations are delivered through Postmark. For this purpose, the recipient’s email address and name, sender details, message subject and content, and technical metadata necessary for transmission and delivery verification are transferred.
When a user signs out, the current backend authentication token for that device is revoked and the associated push token link is removed. This does not automatically sign the user out on other devices.
4.2. Sign-in and account linking with an Apple or Google account
| Item | Description |
|---|---|
| Purpose | Simplified sign-in, creation of a new account, and linking or unlinking an existing account. |
| Data processed | Provider user identifier, email address, name, email verification status, Google profile image URL where applicable, the name and email address provided by Apple during the first authorisation, and token, authorisation code and nonce data required for authentication and later revocation of the connection. The Apple revocation token is stored by the backend in an encrypted database field. |
| Legal basis | Performance of a contract at the user’s request (Article 6(1)(b) GDPR). |
| Retention | Until the connection is unlinked or the account is deleted. Independent processing by Apple or Google is governed by the respective provider’s own privacy notice. |
4.3. Profile and application settings
| Item | Description |
|---|---|
| Purpose | Displaying and personalising the profile and providing language, theme, calendar and security settings. |
| Data processed | Name, email address, optional profile image, language, interface and calendar settings, and whether biometric application lock is enabled. |
| Legal basis | Performance of a contract (Article 6(1)(b) GDPR); for an optional profile image, the user’s voluntary choice, which may be withdrawn at any time (Article 6(1)(a) GDPR). |
| Retention | Until modification, removal or account deletion. |
When Face ID or Touch ID is used, the biometric template is handled by Apple’s operating system. CalMate receives only the result of the local authentication; it does not receive the biometric template and does not transmit it to the server.
4.4. Personal shift, calendar, pay and statistical data
| Item | Description |
|---|---|
| Purpose | Recording shifts and templates, calculating earnings and working time, managing pay periods, deductions, tips, commission and statistics, and sending reminders. |
| Data processed | Shift name, date, start and end time, historical workplace name and logo, note, colour, base salary or hourly rate, currency, tip, commission, bonus, deduction name and note, pay schedule and calculated totals. |
| Legal basis | Performance of the contract with the user (Article 6(1)(b) GDPR). |
| Retention | Until deleted by the user or until the account is deleted. Historical workplace snapshots are retained for as long as the shift record containing them remains. |
CalMate’s calculations are for information only and do not constitute an official payslip or tax advice. Other members of a workplace do not gain access to a user’s personal earnings data merely because they belong to the same workplace.
4.5. Workplace, membership and shift planning
In the application, a “workplace” means a shared workspace; its creator is not necessarily an employer or organisation.
| Item | Description |
|---|---|
| Purpose | Creating and managing a workplace, connecting members, managing permissions, positions, workload limits, shift templates and workplace schedules, transferring ownership, maintaining an activity log, displaying the workplace location in calendar events and providing a local weather forecast. |
| Data processed | Workplace name, category, logo and join code; optional country, postal code, city, address and geographic coordinates derived from them; weather forecast associated with the workplace; member name, profile image, position, administrator role, weekly target and maximum workload; schedules, templates, planning versions, and the identity and timestamp of the person creating or modifying them. |
| Legal basis | For an informal shared workspace created by an individual, performance of the platform service requested by the users (Article 6(1)(b) GDPR). For employer or organisational use, the organisation determines the legal basis for processing employee data, and CalMate acts as processor in accordance with its documented instructions (Article 28 GDPR). |
| Retention | For the lifetime of the workplace, until the relevant data is deleted, or until instructed by the controller operating the workplace. Historical shift data retained in the user’s own calendar is governed by Section 4.4. |
Members may see one another’s names, profile images and shared shift data to the extent required by the feature. The workplace owner and authorised administrators may have broader access for managing schedules, positions, workload and absences.
Providing a workplace address is optional. The address entered is transmitted to the Geoapify geocoding service to determine geographic coordinates. The coordinates are sent to Apple WeatherKit to retrieve a local weather forecast; no CalMate user identifier is attached to them. When creating an informal group, please do not enter a private residential address unless it is necessary for use of the feature.
4.6. Absence and availability requests
| Item | Description |
|---|---|
| Purpose | Indicating days on which work cannot or should not be undertaken, managerial review of requests, and comparison with shift planning. |
| Data processed | Affected user, workplace, start and end date, request type and status, optional written reason, person creating and reviewing the request, decision and timestamps. |
| Legal basis | For an informal shared workspace, performance of the service requested by the user (Article 6(1)(b) GDPR). For employer or organisational use, the legal basis determined by the organisation; CalMate acts as the organisation’s processor. |
| Retention | For employer or organisational use, according to the controller organisation’s instructions, internal policy and applicable employment-law requirements; for informal use, until the shared workspace, the relevant data or the user account is deleted. |
The reason field is not intended for medical documentation. Please do not enter a diagnosis, medical record, religious or political information, or other special-category personal data unless this is strictly necessary and the workplace has provided appropriate prior information and a valid legal basis.
4.7. Workplace chat and user content
| Item | Description |
|---|---|
| Purpose | Sharing workplace messages, images and announcements, reactions, real-time delivery, unread status and notification management. |
| Data processed | Message text, uploaded image, announcement, author name and profile image, workplace, reaction, read timestamp, and creation and modification data. Image technical metadata may be modified or removed during processing before upload. |
| Legal basis | Performance of the service requested by the user (Article 6(1)(b) GDPR); where workplace communication is required by the workplace, the legal basis determined by the workplace and its processor instructions. After account deletion, preserving the continuity of the workplace conversation and the legitimate expectations of other participants may constitute a legitimate interest of the workplace or participants (Article 6(1)(f) GDPR). |
| Retention | Until the content or workplace is deleted, or until the controller workplace instructs its deletion. When an account is deleted, the link to the author’s account is removed and the author’s name and profile image disappear, but previously sent messages and image attachments remain in the workplace conversation under the author name “Deleted user”. |
Users are responsible for sharing only images or personal data that they are entitled to share. Chat content is visible to the relevant members of the workplace. Removing the link to the author’s account does not itself anonymise text or an image that can still be linked to a person based on its content. A data subject may therefore request an individual review and deletion of a specific identifying message or image attachment by contacting privacy@calmate.hu.
4.8. Shift handovers
| Item | Description |
|---|---|
| Purpose | Creating a shift handover request, recipient and managerial decisions, notifications and history. |
| Data processed | Person handing over the shift and recipient, affected shift data, workplace, status, decision-makers, timestamps and a historical snapshot of the shift. |
| Legal basis | Performance of the service, or the legal basis and processor instructions determined by the workplace. |
| Retention | Until the relevant account or workplace is deleted, or until instructed by the workplace. |
4.9. Notifications
| Item | Description |
|---|---|
| Purpose | Notifying users about schedule, earnings, shift handover, workplace, message and absence events in the application or by push notification. |
| Data processed | Notification type, title, text, language, related event identifiers, creation and read timestamps, category and channel settings, and Expo push token. |
| Legal basis | For in-app notifications necessary for the service, performance of a contract (Article 6(1)(b) GDPR); for optional push notifications, consent (Article 6(1)(a) GDPR). |
| Retention | In-app notifications for no more than 12 months; push token until permission is withdrawn, sign-out, token change or account deletion. |
Push permission can be disabled in the operating system settings, while category-specific push delivery can be disabled in CalMate’s notification settings.
4.10. Calendar feed and external calendar providers
| Item | Description |
|---|---|
| Purpose | Displaying shifts in Apple Calendar, Google Calendar, Outlook or another calendar application selected by the user. |
| Data processed | Secret calendar feed token, shift name, date, start and end time, and related data required for the calendar event. |
| Legal basis | Performance of the service at the user’s explicit request (Article 6(1)(b) GDPR). |
| Retention | Until the feed token is revoked or the account is deleted. Retention of data already downloaded to an external calendar is controlled by the selected provider and the user. |
The calendar feed URL must be treated as a secret link. Anyone with access to it may view the shift data available through the URL. The user is responsible for sharing the link only with a trusted service or person.
4.11. Apple subscriptions
| Item | Description |
|---|---|
| Purpose | Purchasing a subscription, verifying and restoring entitlement, and processing renewal and refund events. |
| Data processed | App account token associated with the CalMate account, product identifier, original and latest transaction identifier, subscription status, expiry, revocation, environment, and the necessary data from Apple-signed transactions and server notifications. CalMate does not receive bank card details. |
| Legal basis | Performance of a contract (Article 6(1)(b) GDPR); for accounting and tax data, compliance with a legal obligation (Article 6(1)(c) GDPR). |
| Retention | For as long as required to manage service entitlement, and for data subject to accounting or legal obligations, for up to 8 years. |
Deleting a CalMate account does not automatically cancel an auto-renewing Apple subscription. The subscription can be managed and cancelled in the Apple account subscription settings.
4.12. AI-assisted shift planning
| Item | Description |
|---|---|
| Purpose | Creating an editable monthly shift schedule proposal based on staffing requirements entered by an authorised user. |
| Data processed | Month and daily staffing requirements; pseudonymised internal user identifiers and positions; shift template identifier, name, start time, end time and colour; dates and template identifiers of existing shifts; and the schedule proposal returned by the AI. We do not send names, email addresses, profile images, pay data or free-text shift notes to the AI provider. |
| Legal basis | For an informal shared workspace, performance of the service requested by the user (Article 6(1)(b) GDPR). For employer or organisational use, the legal basis determined by the organisation; CalMate acts as processor and OpenAI as sub-processor. |
| Recipient | OpenAI Ireland Limited and sub-processors involved in operating the OpenAI API. |
| Retention | The proposal becomes a saved schedule only after an authorised user applies it. Request and response data contained in CalMate’s technical logs is subject to the maximum 30-day period set out in Section 4.13. OpenAI API’s default abuse-monitoring logs may retain inputs, outputs and associated metadata for up to 30 days, unless a longer period is required by law. |
AI-generated results are proposals and may be inaccurate or unsuitable. An authorised person always decides whether to save and publish the schedule. By default, OpenAI does not use inputs and outputs transmitted through the API to train its models, unless the administrator of the API account explicitly enables data sharing.
4.13. Technical operation, logging and administrative actions
| Item | Description |
|---|---|
| Purpose | Troubleshooting, performance monitoring, availability, preventing attacks and abuse, permission management, user suspensions and administrator accountability. |
| Data processed | IP address, URL and request time, user identifier, last activity, application and operating system data, technical details of errors and slow requests; administrator and affected user identifier/email address, action, reason, user agent and metadata. Request content is logged only where necessary to investigate a specific error or security incident. |
| Legal basis | Legitimate interests (Article 6(1)(f) GDPR); for legal claims and obligations imposed by authorities, compliance with a legal obligation (Article 6(1)(c) GDPR). Our legitimate interest is the secure and auditable operation of the service. |
| Retention | General technical and security logs for no more than 30 days; Laravel Pulse performance data for 7 days; administrator audit logs for 5 years. |
4.14. First-party product analytics
| Item | Description |
|---|---|
| Purpose | Understanding which main features signed-in users use, where they encounter difficulties in onboarding, personal, Workplace and subscription flows, and measuring aggregated daily, weekly and monthly activity and retention. |
| Data processed | Internal user identifier; for server-side Workplace milestones, internal workplace identifier; allowed event type and timestamp; logical screen name; iOS or Android platform; application and build version; selected language; subscription product family, product identifier and production or sandbox environment; subscription entry source; normalised technical error code. Analytics do not include name, email address, pay amount, workplace name, shift date or note, chat message, invitation code, full URL, advertising identifier or device identifier. |
| Legal basis | Legitimate interests (Article 6(1)(f) GDPR). Our legitimate interest is improving the usability, stability and business processes of the service based on minimal event data that does not contain content. A user may object at any time on grounds relating to their particular situation by contacting privacy@calmate.hu. |
| Recipient | No external analytics provider is used. The data is processed by CalMate’s own backend and database located in the EU/EEA; only the global system superuser has access to the detailed dashboard. |
| Retention | Raw events linkable to a user are stored for no more than 90 days. Daily aggregates that do not contain user or workplace identifiers are retained for no more than 24 months. Segmented aggregates involving fewer than five data subjects are not retained permanently. |
The mobile application sends product analytics events only after successful sign-in and email verification. The application does not create an anonymous installation profile and does not store events persistently for later transmission if a network error occurs.
Where an objection is accepted, CalMate excludes the user from future product analytics and deletes raw events that can be linked to them. Previously generated aggregated statistics that can no longer be linked back to the data subject may be retained.
4.15. Privacy and customer support enquiries
| Item | Description |
|---|---|
| Purpose | Responding to questions, bug reports and data subject requests, demonstrating compliance and handling legal claims. |
| Data processed | Name, email address, message and attachments, data required for identification, responses and timestamps of actions taken. |
| Legal basis | Compliance with a legal obligation (Article 6(1)(c) GDPR); for non-privacy support, performance of a contract (Article 6(1)(b) GDPR); for legal claims, legitimate interests (Article 6(1)(f) GDPR). |
| Retention | For 5 years after closure of the matter, unless a shorter period is sufficient or a longer period is required by law. |
5. Device permissions and locally stored data
The mobile application may request the following device permissions:
- Camera: to scan a workplace or web administration QR code, or to take a chat image at the user’s choice.
- Photo library: to select a profile image, workplace logo or chat image.
- Notifications: to display push notifications.
- Face ID/Touch ID: to unlock the application locally.
The application may store the sign-in token and push token, the biometric application-lock setting, theme, calendar settings, workplace category cache and certain cached home-screen summaries in secure storage on the device. As a rule, these are not transmitted for any other purpose and may be deleted on sign-out or when the related feature is reset.
CalMate’s currently active features do not request access to contacts or the device’s precise location. An optionally provided workplace address and the coordinates derived from it do not originate from the device’s location services. The active features covered by this notice do not use the microphone.
6. Recipients and processors
Personal data is transferred or made accessible only to the extent necessary for the relevant purpose:
| Recipient or category | Role and purpose | Location of processing |
|---|---|---|
| Contabo GmbH (Aschauer Straße 32a, 81549 Munich, Germany) | Server infrastructure managed by CalMate in Germany. The backend, database, file storage and Reverb real-time connection run on the same server. | Germany (EU/EEA) |
| AC PM LLC (Postmark; 1 N Dearborn Street, Suite 500, Chicago, IL 60602, United States) and its sub-processors | Transmission of transactional emails—including email verification, password reset, security and service notifications, and customer support messages—and management of delivery status. Data transferred may include the recipient’s name and email address, sender details, message subject and content, and delivery, bounce and spam-complaint metadata. | United States; data centres of infrastructure providers involved in the service |
| 650 Industries, Inc. (Expo) and its sub-processors | EAS Update, Expo push token and transmission of push messages | EU/EEA and United States |
| Apple group companies | Sign in with Apple, App Store subscriptions, APNs push delivery; provision of WeatherKit weather forecasts based on workplace coordinates | EU/EEA and other countries, including the United States |
| Google group companies | Google sign-in; external Google Calendar where selected by the user | EU/EEA and other countries, including the United States |
| KEPTAGO LTD (Geoapify; N. Nikolaidi and T. Kolokotroni, ONISIFOROU CENTER, 8011 Paphos, Cyprus) | Converting a workplace address provided by the user into geographic coordinates | Primarily European Union; may also depend on the provider’s sub-processor network |
| OpenAI Ireland Limited and its sub-processors | Creating AI-assisted shift planning proposals from pseudonymised scheduling data | Ireland, EU/EEA and other countries, including the United States |
| Calendar provider selected by the user | Calendar feed subscription initiated by the user | Depends on the selected provider |
| Workplace members, owner and authorised administrators | Providing scheduling, membership, absence and workplace communication features | Depends on the location of the workplace and its members |
| Accountant, legal representative, authority or court | Compliance with a legal obligation, legal claim or official request | Depends on the relevant recipient |
The current list of each provider’s sub-processors and details of its independent processing are available in the provider’s own privacy information.
7. Transfers to third countries
CalMate’s primary server and the database, file storage and Reverb service operating on it are located in Germany, within the European Economic Area. However, through Apple, Google, Expo, Postmark and OpenAI services, certain data may also be processed outside the European Economic Area, particularly in the United States. Data contained in emails transmitted through Postmark may be processed in the United States by AC PM LLC and its sub-processors. Depending on the provider and data flow concerned, the lawfulness of the transfer is ensured by a European Commission adequacy decision, the EU–US Data Privacy Framework, Standard Contractual Clauses adopted by the European Commission, or another appropriate safeguard under Chapter V GDPR.
Detailed provider information:
- Contabo Privacy Policy
- Postmark / ActiveCampaign Privacy Policy
- Postmark Data Processing Addendum
- Postmark EU privacy and subprocessors
- Expo Privacy Policy
- Expo Subprocessors
- Apple Privacy Policy
- Google Privacy Policy
- Google data transfer frameworks
- Geoapify Privacy Policy
- OpenAI business data privacy
- OpenAI API data controls
- OpenAI Data Processing Addendum
- OpenAI sub-processor list
Users may request further information about the safeguard used for a specific transfer by contacting privacy@calmate.hu.
8. Automated decision-making and profiling
CalMate does not make decisions based solely on automated processing that produce legal effects concerning the user or similarly significantly affect them within the meaning of Article 22 GDPR.
The shift planner may use conventional calculations or AI to create proposals based on the shifts, staffing requirements, workload limits and absences entered, but an authorised person decides whether to save and publish the plan. Such a proposal does not constitute an automated employment decision.
9. Data security
To protect data, we use measures including encrypted network connections, password hashing, token-based authentication, role- and workplace-based permissions, logged administrator actions and local storage protected by the operating system.
No IT system can guarantee complete security. In the event of a personal data breach, we act in accordance with Articles 33–34 GDPR and, where there is a high risk, also inform the affected data subjects.
10. Account deletion
Users may initiate deletion of their account in the application settings or, without signing in, at https://calmate.hu/remove-my-account. The web process verifies access to the account’s email address by sending a one-time link to the registered email address that is valid for 60 minutes. Opening the link does not itself delete the account: permanent deletion must be confirmed through a separate action on the next page.
If a confirmed request cannot be completed automatically—for example because the user owns a workplace or secure revocation of the Apple connection requires further action—we record the request and provide assistance by email with the necessary steps. Reinstallation of the mobile application is not required. Minimal audit data demonstrating completion of the request is retained for no more than 5 years after the matter is closed.
If the user owns a workplace, they must transfer ownership or delete the workplace before deleting the account.
Deletion covers the account, authentication tokens, profile image, personal shift and pay data, settings and notifications. A deleted account and its data cannot be restored. Messages and image attachments previously sent in workplace chat remain to preserve the continuity of the conversation, but the link to the author’s account, name and profile image are removed, and the author is displayed as “Deleted user”. Data necessary for accounting, security audits or legal claims may be retained separately for the limited periods specified in Section 4 and will not be used for any other purpose.
Before deleting a CalMate account linked to an Apple account, the backend revokes the Sign in with Apple connection. If a revocation token is not yet available for a previously created account, the application requests one-time Apple re-authentication as part of deletion; if this fails, account deletion does not take place.
Where Sign in with Apple is used, CalMate also revokes the associated developer connection. Deletion of a Google or Apple account independently of CalMate must be handled by the user with the relevant provider.
An Apple subscription may continue independently of deletion of the CalMate account and must therefore be cancelled separately in the Apple account subscription settings.
11. Rights of data subjects
Subject to the applicable conditions, you have the right to:
- request information about and access to your personal data processed by us;
- request correction of inaccurate data or completion of incomplete data;
- request deletion of your data (“right to be forgotten”);
- request restriction of processing;
- object to processing based on legitimate interests;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
- receive personal data you have provided, where processed by automated means on the basis of a contract or consent, in a structured, commonly used and machine-readable format, and request its transmission to another controller;
- lodge a complaint with a supervisory authority and seek a judicial remedy.
Requests may be sent to privacy@calmate.hu. We request only the additional information necessary to verify identity. We respond without undue delay and, as a rule, within one month. For complex or multiple requests, this period may be extended by a further two months; we will inform you of the extension within one month.
Where a request concerns processing determined by an employer or another organisation, we may forward the request to that organisation as controller or fulfil it in cooperation with the organisation.
12. Complaints and legal remedies
Please first send any complaint to privacy@calmate.hu so that we can investigate it directly.
You have the right to lodge a complaint with the supervisory authority:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
Postal address: 1363 Budapest, P.O. Box 9., Hungary
Email: ugyfelszolgalat@naih.hu
Website: https://www.naih.hu
A data subject may also bring proceedings before the competent regional court based on their place of residence or stay, or before the court competent for the controller’s registered office.
13. Amendments to this notice
We update this notice when a new feature or processor is introduced, the law changes, or the processing is materially modified. The current version is made available on CalMate’s public privacy page. Where necessary, we also provide notice in the application or by email of material changes affecting users’ rights or choices.