Legal Document

Privacy Policy

Your privacy is fundamental to how we design and build our services. This policy explains how we collect, use, and protect your information.

Last updated: December 15, 2024

Introduction

At Bookitsy, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our booking management platform and related services.

By using Bookitsy, you consent to the data practices described in this policy. If you do not agree with the practices described in this policy, please do not use our services.

Information We Collect

Personal Information

  • • Name, email address, and phone number
  • • Profile information and preferences
  • • Payment and billing information
  • • Communication preferences
  • • Authentication credentials

Business Information

  • • Company name and business address
  • • Service offerings and descriptions
  • • Business hours and availability
  • • Staff and employee information
  • • Business registration details

Usage Data

  • • Booking patterns and appointment history
  • • Platform interaction and navigation data
  • • Feature usage and preferences
  • • Customer feedback and ratings
  • • Communication logs and support interactions

Technical Data

  • • IP address and location data
  • • Device information and browser type
  • • Cookies and tracking technologies
  • • Log files and analytics data
  • • Security and fraud prevention data

How We Use Your Information

Service Provision

Account management, booking processing, and platform functionality

Communication

Notifications, updates, customer support, and marketing communications

Payment Processing

Transaction processing, billing, and financial record keeping

Analytics & Improvement

Service optimization, feature development, and user experience enhancement

Legal Compliance

Regulatory requirements, dispute resolution, and legal obligations

Security & Fraud Prevention

Platform security, fraud detection, and abuse prevention

Information Sharing

We may share your information in the following circumstances:

Service Providers and Partners

We work with trusted third-party service providers to deliver our services, including:

  • • Payment processors and financial institutions
  • • Cloud hosting and infrastructure providers
  • • Analytics and marketing platforms
  • • Customer support and communication tools

Business Transactions

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the business transaction.

Legal Requirements

We may disclose information when required by law, court order, or government regulation, or to protect our rights and prevent fraud.

User Consent

We may share information with your explicit consent or at your direction, such as integrations with third-party applications.

Data Security

We implement comprehensive security measures to protect your information:

Technical Safeguards

  • • End-to-end encryption for data transmission
  • • Secure data storage with encryption at rest
  • • Regular security audits and penetration testing
  • • Multi-factor authentication for accounts

Operational Controls

  • • Access controls and role-based permissions
  • • Employee training on data protection
  • • Incident response and breach notification procedures
  • • Regular backup and disaster recovery testing

Your Privacy Rights

Under GDPR and other privacy regulations, you have the following rights:

Right of Access

Request copies of your personal data and information about how we process it

Right to Rectification

Request correction of inaccurate or incomplete personal data

Right to Erasure

Request deletion of your personal data under certain circumstances

Right to Data Portability

Receive your data in a structured, machine-readable format

Right to Restrict Processing

Request limitation of processing under specific conditions

Right to Object

Object to processing based on legitimate interests or direct marketing

Right to Withdraw Consent

Withdraw consent for processing where consent is the legal basis

To exercise these rights, please contact us using the information provided in the Contact section below.

International Data Transfers

Your information may be transferred to and processed in countries other than your own. When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:

  • • Standard Contractual Clauses approved by the European Commission
  • • Adequacy decisions for countries with adequate protection levels
  • • Certification schemes and codes of conduct
  • • Binding corporate rules for intra-group transfers

Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law. Our retention periods are based on:

Account Data

Retained while your account is active and for up to 7 years after account closure for legal and tax purposes.

Transaction Records

Maintained for 10 years to comply with financial regulations and audit requirements.

Communication Logs

Stored for 3 years for customer service quality and dispute resolution purposes.

Analytics Data

Aggregated and anonymized data may be retained indefinitely for business insights.

Children's Privacy

Our services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

If we become aware that we have collected personal information from children under 16 without verification of parental consent, we will take steps to remove that information from our servers.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:

  • • Update the "Last Updated" date at the top of this policy
  • • Notify you via email or through our platform
  • • For material changes, provide at least 30 days advance notice
  • • Obtain your consent where required by law

Your continued use of our services after any changes constitutes acceptance of the updated policy.

Contact Information

If you have any questions about this Privacy Policy or our data practices, please contact us:

Data Protection Officer

privacy@bookitsy.com
+420 773 039 796

Legal & Compliance

Bookitsy s.r.o.
Prague, Czech Republic
European Union

Jurisdiction: Czech Republic/EU

Response Time: We will respond to your privacy inquiries within 30 days as required by GDPR. For urgent matters, please call our support line.