Privacy Policy
Last updated: 28 July 2026
1. Who we are
Calio (calio.nl) is an online appointment scheduler from the Netherlands and a trading name of Admix Communicatie B.V., registered with the Dutch Chamber of Commerce under number 91110203 and established at Kratonkade 17, 3024 ES Rotterdam. Calio is the data controller for the data of account holders and the data processor for the data our customers collect through their booking pages. Questions about privacy? Email support@calio.nl.
2. What data we process
Account data
- Name, email address and password (stored encrypted as a hash).
- Organisation name and settings such as time zone and availability.
Booking data
- Name, email address, optional phone number and answers to questions the guest fills in when booking an appointment.
- Date, time and type of the appointment.
Calendar data (only with a calendar connection)
- If you connect your Google Calendar or Microsoft 365 calendar, we read your calendar events solely to determine when you are busy and we write confirmed appointments back as calendar events.
- We only store start and end times of busy blocks in our cache, so no titles, descriptions or attendees of your existing events.
AI search help when booking (only if you use it)
- If you describe on a booking page, in your own words, when you would like to meet, we send that sentence, and nothing else, to our language model at Mistral AI in France to extract a date and time preference. Your name, email address and the rest of your booking are not sent there.
- Which times you are then shown is decided by Calio itself, based on the organiser's real calendar. The language model does not pick times and your text is not used to train models.
The mail agent (only if the organiser switches it on)
- An organiser can copy their scheduling assistant into an email exchange with you. Of that message we keep the first part of the text, the sender, the subject and the participants, for as long as it takes to arrange the appointment and at most 90 days. The email itself is removed from our mailbox after processing; we do not open attachments.
- To work out what is being asked, that piece of text goes to the same language model at Mistral AI in France. That is more than with the search help above: it is the content of your email, not one sentence you typed into a box. Which times are then suggested is decided by Calio itself from the real calendar; the model does not pick times and your text is not used to train models.
- If you would rather not, the answer is simple: take the assistant address out of the cc. Without that address in the headers your message never reaches us.
Technical data
- Log files (IP address, browser type, timestamp) for security and debugging.
3. What we use your data for
- Providing the service: scheduling, confirming and sending reminders for appointments (performance of the contract).
- Preventing double bookings via your connected calendar (performance of the contract).
- Security, abuse prevention and debugging (legitimate interest).
- Legal obligations, such as record-keeping and invoicing.
We do not use your data for advertising and never sell it to third parties.
4. Google user data and Limited Use
For the Google Calendar integration, Calio uses the Google Calendar API. Calio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice this means:
- We use calendar data solely to determine your availability and to add confirmed Calio appointments to your calendar.
- We do not display, sell or share this data with third parties.
- We do not use Google user data for advertising and do not use it to train (generative) AI models.
- No humans have access to this data, except with your explicit consent, for security purposes, or when required by law.
You can revoke the connection at any time in Calio or via your Google account settings. The same restrictions apply to a Microsoft 365 connection.
5. How long we keep data
- Account data: for as long as your account exists. After deletion we erase your data within 30 days.
- Booking data: for as long as the organiser's account exists, or until the organiser deletes it.
- Calendar connections: access tokens and the availability cache are deleted immediately when you disconnect the calendar.
- Log files: at most 90 days.
6. Where your data lives and who we work with
Calio runs entirely on European infrastructure; your data is stored within the EU. We only engage sub-processors that are necessary to provide the service, and we sign GDPR-compliant data processing agreements with them:
- Hosting and database: data centre in Amsterdam (the Netherlands).
- Email delivery: Resend, for confirmations, reminders and password reset emails.
- Language model: Mistral AI (France). For the AI search help only the sentence a guest types themselves; for the mail agent also the first part of the text of the email it was copied into. See above.
The full list of sub-processors, including the party that stores our backups, is in our data processing agreement. If you are a customer processing your own guests' data through Calio, that agreement applies to you automatically.
7. Security
- All connections use TLS (https).
- Passwords are stored as a strong hash (Argon2), never in readable form.
- Access tokens for calendar connections are stored encrypted.
- Customer data is separated at the database level.
8. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction, data portability and objection. Email your request to support@calio.nl; we respond within 30 days. If you are not satisfied with how we handle your request, you can file a complaint with the Dutch Data Protection Authority ( Autoriteit Persoonsgegevens).
9. Cookies
Calio only uses functional cookies that are required to log in and make the service work. We do not place tracking or advertising cookies.
For our own website we do count how many visitors arrive each day, through which channel (search engine, AI assistant, link or direct) and on which page. This involves no cookie and no browser storage: we keep a daily counter only, no IP address, no browser details and nothing that identifies you.
10. Changes
We may update this privacy policy. For significant changes we notify account holders by email. The current version is always available on this page.
Also see our terms of service. Deze pagina is ook beschikbaar in het Nederlands.
Read next
- Does a booking page need a cookie banner?Often not. The law hinges not on “cookies” but on storing and reading on someone else’s device, and a booking page barely needs to. When it is required.
- The CLOUD Act explained: what “data in Europe” does and doesn’t meanA 2018 US law can compel American providers to hand over data, even when it sits in Amsterdam. What that means for your scheduling software.