Privacy policy

Updated 25 September 2026

Service provider
Salovuori Mikko Heikki
Business ID
2989730-9
Address
Länsisatamankatu 36, 00220 Helsinki
Email
mikko@calendo.com

Who is responsible

For bookings, the controller is the business or person you book with; their name is shown on the booking page. Calendo processes booking data on their behalf.

For Calendo user accounts, the controller is the service operator Salovuori Mikko Heikki (mikko@calendo.com).

What data is processed

  • People who book: name, email address, optional phone number, other attendees' email addresses, answers to booking questions, notes, the booked time, language and time zone.
  • Abuse prevention: a one-way hash derived from the network address and browser; deleted after 48 hours.
  • Calendo users: name, email address and account identifier from Google or Microsoft sign-in, settings, and encrypted calendar access tokens (Google or Microsoft). For paid plans also the plan, subscription status and Stripe customer identifier.
  • Team members: name, email address and encrypted calendar access tokens (Google or Microsoft).

Purpose and legal basis

Data is used to make, confirm, remind of, reschedule and cancel bookings (performance of a contract or steps before one) and to keep the service secure (legitimate interest). Data of Calendo users is used to provide the account and subscription (contract) and to meet bookkeeping obligations (legal obligation).

Processors and transfers

  • Cloudflare, Inc.: hosting and database.
  • Stripe Payments Europe, Ltd.: payments for Calendo subscriptions (card details are handled only by Stripe).
  • Twilio Inc.: text message reminders, when the organiser uses them and you gave a phone number.
  • Google LLC: calendar events, Google Meet links and confirmation emails, sent through the Google account the organiser has connected.
  • Microsoft Ireland Operations Ltd and Microsoft Corporation: calendar events, Microsoft Teams links and confirmation emails, sent through the Microsoft account the organiser has connected.

These processors may process data outside the EU/EEA; such transfers rely on the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.

Retention

Bookings are deleted automatically after the retention period set by the organiser (by default 365 days after the meeting). Calendar events created in the organiser's own calendar follow their calendar's settings. Calendo account data is deleted within 30 days of the account being deleted; bookkeeping records are kept for the period required by law.

Your rights

You may request access to, correction or deletion of your data, restrict or object to processing and ask for data portability. For bookings, contact the organiser; for Calendo accounts, contact mikko@calendo.com. You may also lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi).

Cookies and storage

People who book get no cookies. The booking form keeps an unsent draft in the browser's session storage until the tab is closed. Calendo users get strictly necessary sign-in cookies (a signed session cookie for 7 days and short-lived sign-in state cookies).

Security

All traffic is encrypted, the dashboard requires sign-in, calendar access tokens are stored encrypted and the booking form has abuse protection.

Changes

This policy may be updated when the service changes. The current version is always available at calendo.fi/privacy.