Privacy
Privacy policy | Kalends
Effective from 3 September 2026.
Who is responsible?
Kalends is provided by Asset Media JL, sole trader, registration no. 750929-4992 (”we”). Contact support@kalends.io with privacy questions.
When you contact us
When you use the contact form or email us, we process your name, email address and message to answer your enquiry, handle a support case or follow up on your interest in Kalends. We do not use contact details for unsolicited marketing.
- We do not share contact details with others for their own marketing.
- We retain an enquiry only as long as needed to handle it and provide reasonable follow-up.
- Do not send sensitive personal data or passwords through the contact form.
When you use Kalends
We process necessary contact and operational information for account, subscription and security administration. Where a business or organisation enters personal data in its Kalends account, that customer is normally the controller and Kalends the processor. That processing is governed by our data processing agreement. Different data-protection rules may apply to purely private use depending on how the service is used.
Website analytics and advertising measurement
We use self-hosted, cookieless Umami analytics to understand how the website is used. If you actively allow measurement, we also load the Google Ads tag, LinkedIn Insight Tag and OpenAI Ads Measurement Pixel to measure visits and beta applications originating from our ads. When a trial actually starts, Kalends may also send a server event to OpenAI to measure the same advertising journey. Advertising measurement does not take place before you give permission. We keep personalised advertising disabled, and you can change your choice at any time through the Measurement settings link on the website.
- Your choice and related advertising references are stored locally in your browser so the choice can be followed between kalends.io and app.kalends.io.
- Google, LinkedIn and OpenAI may process measurement data outside the EU/EEA under their own terms and data-protection safeguards.
- We do not send names, email addresses or the content of a beta application to Google Ads or LinkedIn. For OpenAI, an email address and internal organisation ID may be normalized and SHA-256 hashed for conversion matching; advertising references, IP address and browser information may also be included, but free-text content is not sent as conversion data.
Recipients and where data is processed
Customer data in Kalends is stored with Hetzner in Helsinki, Finland, within the EU/EEA. We also use Cloudflare for DNS, proxying and traffic encryption, Brevo for outbound transactional email within the EU/EEA, and Stripe for payment and subscriptions. Cloudflare passes traffic through without storing it; Kalends application data is stored with Hetzner. We do not disclose data to anyone else except where it is needed to run the service or required by law.
- Each customer organisation's data is separated from every other organisation at the database level.
- History and sign-offs are append-only: rows are added, never rewritten.
- The built-in AI chat uses the organisation's own API key. Questions and relevant context then go to the provider the organisation has chosen, under that organisation's own agreement with them.
Your rights
You can contact us to request access, rectification, erasure, restriction, objection or portability where GDPR gives you that right. You may also complain to the Swedish Authority for Privacy Protection.
Changes
We may update this policy when our practices or service change. The current version is published on this page with a new effective date.