Privacy Policy
Last updated: 28 July 2026
1. Who we are
Calio (calio.nl) is an online appointment scheduler from the Netherlands. Calio is the data controller for the data of account holders and the data processor for the data our customers collect through their booking pages. Questions about privacy? Email support@calio.nl.
2. What data we process
Account data
- Name, email address and password (stored encrypted as a hash).
- Organisation name and settings such as time zone and availability.
Booking data
- Name, email address, optional phone number and answers to questions the guest fills in when booking an appointment.
- Date, time and type of the appointment.
Calendar data (only with a calendar connection)
- If you connect your Google Calendar or Microsoft 365 calendar, we read your calendar events solely to determine when you are busy and we write confirmed appointments back as calendar events.
- We only store start and end times of busy blocks in our cache — no titles, descriptions or attendees of your existing events.
AI search help when booking (only if you use it)
- If you describe on a booking page, in your own words, when you would like to meet, we send that sentence — and nothing else — to our language model at Mistral AI in France to extract a date and time preference. Your name, email address and the rest of your booking are not sent there.
- Which times you are then shown is decided by Calio itself, based on the organiser's real calendar. The language model does not pick times and your text is not used to train models.
Technical data
- Log files (IP address, browser type, timestamp) for security and debugging.
3. What we use your data for
- Providing the service: scheduling, confirming and sending reminders for appointments (performance of the contract).
- Preventing double bookings via your connected calendar (performance of the contract).
- Security, abuse prevention and debugging (legitimate interest).
- Legal obligations, such as record-keeping and invoicing.
We do not use your data for advertising and never sell it to third parties.
4. Google user data and Limited Use
For the Google Calendar integration, Calio uses the Google Calendar API. Calio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice this means:
- We use calendar data solely to determine your availability and to add confirmed Calio appointments to your calendar.
- We do not display, sell or share this data with third parties.
- We do not use Google user data for advertising and do not use it to train (generative) AI models.
- No humans have access to this data, except with your explicit consent, for security purposes, or when required by law.
You can revoke the connection at any time in Calio or via your Google account settings. The same restrictions apply to a Microsoft 365 connection.
5. How long we keep data
- Account data: for as long as your account exists. After deletion we erase your data within 30 days.
- Booking data: for as long as the organiser's account exists, or until the organiser deletes it.
- Calendar connections: access tokens and the availability cache are deleted immediately when you disconnect the calendar.
- Log files: at most 90 days.
6. Where your data lives and who we work with
Calio runs entirely on European infrastructure; your data is stored within the EU. We only engage sub-processors that are necessary to provide the service, and we sign GDPR-compliant data processing agreements with them:
- Hosting and database — data centre in Amsterdam (the Netherlands).
- Email delivery — Resend, for confirmations, reminders and password reset emails.
- Language model for the AI search help — Mistral AI (France), and only the sentence a guest types themselves. See above.
The full list of sub-processors, including the party that stores our backups, is in our data processing agreement. If you are a customer processing your own guests' data through Calio, that agreement applies to you automatically.
7. Security
- All connections use TLS (https).
- Passwords are stored as a strong hash (Argon2), never in readable form.
- Access tokens for calendar connections are stored encrypted.
- Customer data is separated at the database level.
8. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction, data portability and objection. Email your request to support@calio.nl; we respond within 30 days. If you are not satisfied with how we handle your request, you can file a complaint with the Dutch Data Protection Authority ( Autoriteit Persoonsgegevens).
9. Cookies
Calio only uses functional cookies that are required to log in and make the service work. We do not place tracking or advertising cookies.
10. Changes
We may update this privacy policy. For significant changes we notify account holders by email. The current version is always available on this page.
Also see our terms of service. Deze pagina is ook beschikbaar in het Nederlands.