Privacy Policy
Last updated: 2026-05-26
1. Data Controller
The data controller is ScheduleBox s.r.o., ID: 12345678, registered at Příkladná 1, 110 00 Praha 1 (hereinafter "Controller").
2. Role of ScheduleBox and the Business You Book With
This Policy describes how personal data is processed by the operator of the ScheduleBox platform as Controller — in relation to account holders and visitors of this website. If you book with a specific business (salon, restaurant, sports venue, etc.) that uses ScheduleBox for its operations, that business is the Controller of those booking data; ScheduleBox acts only as a Processor under a data processing agreement (DPA). Specific terms and Controller contact details are available in the privacy policy of the business whose page or booking widget you used to book.
3. What Data We Collect
We collect the following categories of personal data: identification data (first name, surname), contact data (email, phone), booking and payment data, technical data (IP address, browser type), and cookie data.
4. Purpose of Processing
We process personal data for the purpose of providing the ScheduleBox service, managing user accounts, processing payments, sending booking notifications, improving the service through analytics, and fulfilling legal obligations.
5. Legal Basis
Processing is based on performance of a contract (Art. 6(1)(b) GDPR), legitimate interests of the controller (Art. 6(1)(f) GDPR), consent of the data subject (Art. 6(1)(a) GDPR), and compliance with legal obligations (Art. 6(1)(c) GDPR).
6. Sub-Processors
We engage the following processors and transfer the necessary personal data to them in order to operate the service: application and database hosting (PostgreSQL via Neon, cache via Upstash Redis) — EU regions; Comgate Payments, a.s. (CZ) for payment processing and recurring charges; an SMTP provider configured by the operator for email delivery; Twilio Inc. (US) for SMS notification delivery; Have I Been Pwned (UK) for k-anonymity password breach checks (the full password is never transmitted); OpenAI (US) for generation of reminder and follow-up email text and assistive AI features. A current detailed list of sub-processors including legal safeguards is available on request at privacy@schedulebox.cz.
7. Transfers Outside the EEA
Some of the sub-processors listed above (particularly OpenAI and Twilio) are established outside the European Economic Area, typically in the United States. For these transfers we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission (Implementing Decision 2021/914) as the legal safeguard providing an adequate level of protection under Art. 46 GDPR. A copy of these safeguards is available on request; where appropriate we apply supplementary technical measures (e.g. minimization, pseudonymization) in line with the Schrems II ruling.
8. Automated Processing and Profiling
In providing the service we use algorithms and machine-learning models for assistive tasks, including: estimating the probability that a customer will not show up to a booking (no-show prediction), estimating customer lifetime value (CLV), suggesting dynamic pricing, and generating the text of reminder and follow-up emails. None of these outputs constitutes a final automated decision producing legal effects on the data subject within the meaning of Art. 22 GDPR — they serve as suggestions that the business operator approves or modifies (human-in-the-loop). You have the right to obtain information about the logic involved, express your point of view, and contest the result at privacy@schedulebox.cz.
9. Data Retention
Retention depends on the category of data and the purpose of processing. User account data (name, email, phone, authentication credentials) is retained for the lifetime of the account and 30 days after its cancellation, after which it is permanently erased. Booking records are retained for 3 years from the most recent booking (the limitation period for contractual claims and complaints). Payment and invoicing records are retained for 10 years pursuant to Czech VAT Act No. 235/2004 Coll. and the Accounting Act. Marketing data and consents are retained until consent withdrawal, up to a maximum of 2 years from the last interaction. Security audit logs are retained for 18 months. After soft-deletion a 30-day window precedes hard-delete; a daily clean-up job runs to enforce this. After the applicable period, data is securely deleted or anonymized.
10. Data Subject Rights
You have the right to access your personal data, the right to rectification, erasure, restriction of processing, data portability, and the right to object to processing. You can exercise your rights by contacting the Controller at privacy@schedulebox.cz. You also have the right to lodge a complaint with the Office for Personal Data Protection.
11. Cookies
We use technical cookies necessary for the operation of the service. We store analytical and marketing cookies only with your explicit consent, which you can withdraw at any time. Details can be found in the cookie banner on our website.
12. Data Protection Contact
For questions regarding the processing of personal data, contact us at privacy@schedulebox.cz.