Privacy Policy

Effective 1 September 2026 · Last updated 1 September 2026

Who we are

Slotly is a scheduling service operated by bifactory s.r.o., Czech Republic. The data controller for personal information processed by Slotly is bifactory s.r.o. You can reach us at hulin@bifactory.cz.

Data we collect

When you use Slotly we collect only what we need to run the service:

  • Account details — email address, first and last name, optional avatar and phone number. Provided by you at sign-up (or by Google / Microsoft if you sign in via SSO).
  • Working hours & unavailability — the weekly hours you are open for meetings and any "out of office" blocks you add.
  • Calendar free/busy data — busy intervals from calendars you connect (Google Calendar via OAuth, or ICS feed URLs you paste). We do not store event titles, attendees or bodies from your calendars; we only store the start/end times and whether the block is busy or free.
  • Booking metadata — meetings you create through Slotly or that someone books via your public link. We store the participants' emails, meeting time, and any title/notes you or the visitor provided.
  • OAuth tokens — when you connect Google or Microsoft, we store access and refresh tokens so we can create events on your behalf. Tokens are encrypted at rest with a per-deployment key.
  • Basic technical logs — IP address, user-agent, and timestamps for security and rate-limiting. Kept for at most 30 days.

How we use Google user data

Slotly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Google data is used only to:

  • Read free/busy times from your Google Calendar to compute your availability.
  • Create events in the calendar you selected as the write target, when you or a visitor books a meeting.
  • Display your name, email, and avatar (from Google userinfo) in your Slotly profile.

We do not sell, share, or use Google user data for advertising. We do not use it to train AI/ML models. Human review of this data only happens when strictly necessary to investigate abuse, debug a specific customer-reported bug you asked us to look into, or comply with law.

Sharing

We don't sell your data. We share it only with the third-party providers we need to run the service:

  • Google and Microsoft — for the OAuth connections you initiate and the calendar events you or your visitors create through Slotly.
  • Microsoft Azure (EU region) — our infrastructure provider (compute, database, blob storage, email).

When a visitor books time via your public link, the visitor's email and name are shared with your calendar provider so they can be added as an event attendee. That is the only outward sharing of visitor data.

Public booking link

When you enable your public booking link, anyone with the URL can see your free/busy availability for the next 8 weeks and, if you have a calendar connected, book time with you. They see your display name, country, and avatar; they never see your email or the titles of events on your calendar. You can turn the link off or rotate it at any time from your profile page.

Retention

  • Account data — for as long as your account exists.
  • OAuth tokens — until you disconnect the integration or delete your account.
  • Cached calendar events — up to 90 days after they end; older entries are purged automatically.
  • Booking requests — indefinitely, so you have a record; you can delete individual rows on request.
  • Technical logs — up to 30 days.

Your rights (GDPR)

You can access, correct, export, or delete your personal data at any time from your account settings. Full account deletion (Settings → Account → Delete account) removes all your data within 24 hours, except backups that expire on their own rolling schedule (max 30 days). You can also contact hulin@bifactory.cz to exercise any GDPR right, including lodging a complaint with the Czech data-protection authority (ÚOOÚ).

Changes

We'll update this policy when we materially change how Slotly handles data. When we do, we'll email active users and post the new effective date at the top of this page.