Privacy Information (Privacy Notice)

    Version 3.1

    Last updated: August 18, 2026

    New in version 3.1: clarified information about web statistics with Google Analytics 4 (consent required, no personal data sent) and a new section on public booking and event flows, where no cookie banner is shown and no analytics or marketing scripts are loaded.

    1. About this Privacy Notice

    This Privacy Notice describes how MeetSync AB processes personal data in connection with the MeetSync® platform (the "Service").

    This Privacy Notice does not constitute a data processing agreement and does not in itself govern customer organizations' instructions to MeetSync. When MeetSync processes personal data on behalf of a customer organization, the processing is governed by the applicable Data Processing Agreement (DPA).

    This document is an informational document, not an agreement. It does not constitute a general consent and you do not need to accept it to use the Service. Where a specific processing activity requires consent, it is obtained separately.

    The Service is primarily intended for organizations, but can also be used by individuals who register in their own name. This information applies to both situations. See the Terms of Use for contractual terms, including consumer-specific provisions.

    The document is version-controlled. Each published version has a version number, an effective date, and a document hash. Previous versions are preserved unchanged and can be accessed via a version-specific link. The page can be printed or saved as a PDF using the browser's print function.

    2. Data Controller and Contact Details

    MeetSync AB, org.nr 559582-2825, Kungsholms Hamnplan 5A, 112 20 Stockholm, Sweden.

    MeetSync AB has not appointed a data protection officer. Data protection matters are handled by the company's management at the address above.

    3. When MeetSync is the Data Controller

    MeetSync is the data controller when MeetSync itself determines the purposes of the processing. This includes, among other things:

    • account and user administration as well as organization administration
    • authentication and login
    • security, abuse and fraud prevention
    • audit, activity, and authentication logs
    • contract acceptance and legal evidence
    • support, contact forms, and feedback
    • subscription and billing metadata that MeetSync processes itself
    • technical operations, error and delivery logs
    • compliance with legal obligations and management of legal claims
    • necessary product and service communications

    3.1 Individuals using the Service in their own name

    When an individual registers an account in their own name and not as a representative of an organization, MeetSync is the data controller for the entire use of the Service for that person, including the meetings and bookings the person creates themselves. The legal basis is then performance of a contract, legal obligation, or legitimate interest according to the table in section 8.

    Consumers also have the rights that follow from mandatory consumer protection legislation. Information on the right of withdrawal and refunds can be found in the Terms of Use and the Refund Policy.

    4. When MeetSync is the Data Processor

    MeetSync is normally the data processor for data processed on behalf of a customer organization, for example:

    • booking data and booking form responses
    • meeting participants and their contact details
    • meeting requests and response options
    • calendar data retrieved from connected calendars
    • CRM data in customer-controlled integrations
    • the customer's own meeting messages, internal notes, and free text

    The customer organization determines the purposes and legal basis. MeetSync processes the data according to the customer's documented instructions and the DPA.

    MeetSync therefore does not specify its own legal basis under Article 6 of the GDPR for this processing. See the Data Processing Agreement.

    5. Customer Organization's Responsibility

    When a customer organization uses MeetSync to process personal data, the organization normally determines the purposes and the legal basis for the processing. The organization is responsible for ensuring the lawfulness of the processing and that data subjects receive necessary information. MeetSync processes such data in accordance with the customer's instructions and the applicable data processing agreement.

    The customer organization is specifically responsible for:

    • the purposes of the processing and the legal basis
    • providing necessary information to data subjects
    • ensuring that the instructions to MeetSync are lawful
    • ensuring that the data is relevant and proportionate
    • obtaining necessary consents or other permissions
    • which recipients and participants are added to a meeting
    • customer-controlled integrations and the use of CRM data
    • any further use of data after a meeting
    • ensuring that sensitive or prohibited personal data is not entered without a special agreement

    6. External Meeting Bookers

    An external meeting booker (Meeting Booker) is a person who books meetings via an organization's booking page or on behalf of an organization.

    • A meeting booker does not need to create a MeetSync account to book a time slot.
    • A meeting booker does not become a customer or a contractual party to MeetSync AB by booking a meeting.
    • The customer organization behind the booking page is normally the data controller for the booking.
    • MeetSync is normally the data processor for this data.
    • The organization determines why the booking data is processed and is responsible for its own legal basis and privacy information.

    In the public booking flow, the organization's name, MeetSync's role as processor, and a link to this Privacy Information are displayed. See also Privacy Information for Public Booking.

    This Privacy Information does not describe each customer organization's own purposes. Contact the organization that provides the booking page for information about their processing.

    7. What personal data MeetSync processes as a data controller

    • Account data – name, email address, password in hashed form, profile picture, language and time zone settings, role, and organizational affiliation.
    • Organizational data – organization name, organization number, VAT number, address, and contact persons.
    • Authentication data – login events, session information, account locking, and token references for connected accounts.
    • Technical data and logs – IP address, user agent, timestamps, error and delivery logs, and operational data.
    • Audit and contract data – see section 7.1.
    • Support, contact, and feedback data – see section 14.
    • Subscription and payment metadata – see section 13.

    7.1 Audit and contract data

    To be able to demonstrate which agreement was valid at a specific time, MeetSync processes, among other things, document ID, document version, document hash, time of acceptance or presentation, user, organization, user role, authorization certification, the exact checkbox text or its hash, IP address, user agent, session ID, request ID, correlation ID, reference to a Paddle transaction, and notification history.

    The purposes are to administer agreements, to be able to prove which agreement was valid, prevent abuse, comply with law, and to establish, exercise, or defend legal claims.

    This data is not necessarily deleted at the same time as a user account. See section 16.

    8. Purposes and legal bases

    The table only applies to processing where MeetSync is the data controller.

    ProcessingPurposeLegal basis
    Account and organization administrationCreate and administer accounts, roles, and organizationsContract (art. 6.1 b)
    AuthenticationVerify identity and protect loginContract (art. 6.1 b) and legitimate interest (art. 6.1 f)
    Security, abuse, and fraudDetect and investigate abuse, unauthorized access, and fraudLegitimate interest (art. 6.1 f)
    Audit and activity logsTraceability and accountabilityLegitimate interest (art. 6.1 f) and legal obligation (art. 6.1 c)
    Contract acceptance and legal evidenceDemonstrate which agreement was validLegal obligation (art. 6.1 c) and legitimate interest (art. 6.1 f)
    Support, contact forms, and feedbackRespond to and document cases and improve the ServiceContract (art. 6.1 b) and legitimate interest (art. 6.1 f)
    Subscription and billing metadataAdminister subscriptions and comply with accounting and tax requirementsContract (art. 6.1 b) and legal obligation (art. 6.1 c)
    Technical operation and error logsOperate, troubleshoot, and secure the ServiceLegitimate interest (art. 6.1 f)
    Necessary service communicationsInform about operational disruptions, security, and material changesLegitimate interest (art. 6.1 f)
    Legal claimsEstablish, exercise, or defend legal claimsLegitimate interest (art. 6.1 f) and legal obligation (art. 6.1 c)

    For processing where MeetSync is a processor, no legal basis is stated here, as it is determined by the customer organization.

    9. Source of the personal data

    • from the data subject themselves
    • from the customer organization and its administrators
    • from other meeting participants
    • from connected calendars
    • from customer-controlled CRM systems
    • from authentication providers when logging in with Google, Microsoft or Apple
    • from Paddle in connection with subscriptions and payment
    • from communication providers, for example, delivery status for email
    • from technical logs in the Service
    • from support, contact, and feedback flows

    A person can be added as a participant by someone else and may therefore appear in MeetSync without having created an account themselves.

    10. Recipients

    Personal data may be disclosed to the following categories of recipients:

    • MeetSync's sub-processors and technical suppliers (section 11)
    • customer-controlled third-party integrations (section 12)
    • independent data controllers, for example, Paddle (section 13)
    • professional advisors such as lawyers and auditors
    • public authorities and courts when MeetSync is obligated to disclose data
    • counterparties and advisors in the event of a business transfer (section 25)

    11. MeetSync's sub-processors

    MeetSync engages sub-processors for the operation of the Service. MeetSync is responsible for its own sub-processors in accordance with the DPA and GDPR.

    A current list with supplier, role, country, hosting region, third-country transfer, and transfer mechanism can be found in the List of Sub-processors.

    At the time of publishing this version, the reviewed sub-processors include hosting, database, authentication, storage and edge functions, application platform, transactional email, and AI-based translation. The list is the governing source and is updated continuously.

    12. Customer-controlled third-party integrations

    When the customer or user chooses to connect an external service, MeetSync is instructed to transfer relevant data to that service. The external provider may thereafter process the data under its own terms and data protection rules.

    Examples of integrations activated by the customer:

    • Google Calendar and Google Meet
    • Microsoft 365, Outlook calendar and Microsoft Teams
    • Apple Calendar via CalDAV
    • HubSpot, Salesforce, Microsoft Dynamics 365 and Upsales

    MeetSync is not responsible for the external provider's independent processing after data has been transferred according to the customer's or user's instruction. This limitation applies only to customer-controlled third-party services and not to MeetSync's own sub-processors.

    OAuth or equivalent authorization is used to technically grant MeetSync access to a third-party service. The technical authorization does not in itself mean that GDPR consent is the legal basis for the customer organization's processing.

    13. Paddle and Payment Information

    Orders are handled by MeetSync's reseller, Paddle.com. Paddle is the Merchant of Record for all orders and may be an independent data controller for payment, tax, invoicing, and fraud prevention.

    MeetSync does not store full card details. However, as a data controller, MeetSync processes certain subscription and transaction metadata, such as Paddle customer ID, subscription ID, transaction ID, plan, status, renewal date, organization number, VAT number, receipt reference, and refund status.

    This processing is separate from Paddle's own independent processing. Paddle is not MeetSync's sub-processor for all payment data.

    14. Communication, Support, and Feedback

    14.1 Email

    MeetSync sends transactional messages, such as booking confirmations, invitations, reminders, and account notifications. For these, the recipient address, message category, booking reference, organization reference, sending time, delivery status, bounce data, error data, and the provider's message ID are processed.

    The purposes are to deliver messages, troubleshoot delivery issues, prevent abuse, and document communication. MeetSync does not use open or click tracking in transactional messages.

    14.2 SMS and WhatsApp

    If an organization enables messages via SMS or WhatsApp, the phone number, channel, message content, booking reference, delivery status, as well as opt-in and opt-out information are processed. Such messages may be delivered via a communications provider and telecommunications operators, which may involve international data flows. Any opt-in for WhatsApp is separate, never pre-checked, version-logged, can be revoked, and does not include marketing.

    14.3 Support, Contact Forms, and Feedback

    In support, contact, and feedback cases, the name, email address, organization, message text, technical context, the page in the Service from which the case was sent, any attachments, support reference, and delivery status are processed.

    Users should not send passwords, authentication tokens, payment card details, or sensitive personal data via support or feedback fields unless this is explicitly requested through a secure channel.

    15. International Transfers

    MeetSync strives to use European hosting regions. The production database and associated services are hosted in a European region.

    Certain providers, their group companies, or further sub-processors may process data or have access to it outside the EU/EEA. International transfers may therefore occur also through MeetSync's own providers. Customer-controlled integrations may involve additional international transfers governed by the respective provider's terms.

    When data is transferred to a third country, this is done based on an applicable mechanism, such as an adequacy decision, the EU–US Data Privacy Framework for certified recipients, the EU's Standard Contractual Clauses 2021/914, Binding Corporate Rules, or another legal mechanism.

    Which mechanism applies to each provider is stated in the List of Sub-processors, which shows the provider, role, country, hosting region, third-country transfer, and transfer mechanism.

    16. Storage, Deletion, and Backup

    Personal data is retained only for as long as it is needed for the relevant purpose, according to the customer's instructions, applicable agreements, legal obligations, documented security needs, and the need to establish, exercise, or defend legal claims.

    MeetSync maintains a central retention model per data category. The following periods are verified in the technical implementation at the time of this version:

    CategoryRetention Period
    Email logs90 days, automatic purge
    Operational history for scheduled jobs30 days, automatic purge
    Account data after subscription termination90 days in a locked state before deletion
    Audit logsNo automatic deletion; retained for accountability and legal claims
    Legal acceptances and evidenceNo automatic deletion; retained for legal claims

    For other categories – including booking data, meeting requests, calendar data, CRM sync, authentication logs, integration logs, security incidents, support, feedback, contact forms, Paddle data, SMS logs, and data subject requests – the retention period is governed by the customer's instructions, agreements, and the general principle above. These categories are reviewed continuously in the retention register and will be supplemented with exact periods only once they are technically verified.

    Deleting a user account does not automatically mean that all data is deleted if MeetSync still has a documented legal, security, or contractual basis to retain it.

    16.1 Backup

    Deleted data may remain for a limited time in backups. Backups are not used as a normal active system but only for restoration in case of failure or incident, and are overwritten according to the hosting provider's documented backup cycle.

    17. Security

    MeetSync uses technical and organizational measures intended to provide a level of security appropriate to the risks of the processing.

    The measures may, depending on the system and processing, include:

    • database-level access control with Row Level Security
    • role-based access control
    • authentication with hashed passwords and login via Google, Microsoft, and Apple
    • encryption of traffic with TLS
    • management of secrets in a separate key management system
    • audit and authentication logging
    • HMAC signing is used to verify the integrity of certain signed links
    • documented process for handling security incidents
    • documented procedures for deletion

    The status of the measures is monitored in MeetSync's internal control register. Measures that have not yet been fully implemented are not described here as existing. No security measure can guarantee complete protection.

    18. Personal Data Breaches

    18.1 When MeetSync is the Data Controller

    Incidents are documented and risk-assessed. Notification is made to the competent supervisory authority when required by the GDPR, where feasible within 72 hours of MeetSync becoming aware of the breach. Data subjects are informed when the breach is likely to result in a high risk to their rights and freedoms and the GDPR requires such information.

    18.2 When MeetSync is the Data Processor

    MeetSync shall notify the affected customer organization without undue delay after becoming aware of a personal data breach affecting the customer's personal data.

    The customer organization is normally responsible for decisions regarding notification to the supervisory authority and communication to data subjects. MeetSync shall assist the organization in accordance with the DPA with appropriate and proportionate measures.

    19. Your Rights

    You may have the right to request access, rectification, erasure, restriction, data portability, and to object to processing. You may also withdraw consent you have given, without affecting the lawfulness of processing before the withdrawal.

    We handle requests without undue delay and normally within one month of receipt. Where permitted by the GDPR, the time limit may be extended by two further months, taking into account the complexity and number of the requests.

    • We may need to verify your identity before a request is handled.
    • The rights are not absolute and may be limited by law or by the rights of other persons.
    • Manifestly unfounded or excessive requests are handled in accordance with the GDPR, which may involve a reasonable fee or the refusal to act on the request.

    Requests should be sent to privacy@meetsync.nu.

    20. Requests Concerning Customer Organization Data

    If a request concerns personal data that MeetSync processes on behalf of a customer organization, MeetSync will normally refer or forward the request to the data controller organization and assist the organization in accordance with the DPA.

    MeetSync does not make its own decisions regarding the erasure or disclosure of customer data outside of the customer's documented instructions.

    21. Cookies and similar technologies

    Certain technologies are strictly necessary for authentication, security, or functionalities expressly requested by the user. Other technologies are used only after consent when consent is required.

    MeetSync maintains a register of the cookies and similar storage technologies used, including purpose, category, storage period, and provider. Detailed information is available in the Cookie Information, where settings can also be changed.

    Web statistics and Google Analytics (GA4)

    MeetSync® uses Google Analytics 4 (GA4) on the public marketing site to understand how the pages are used and to improve content and performance. GA4 is activated only after you have chosen to allow statistics in our consent solution. Before such a choice, Google's consent signals analytics_storage, ad_storage, ad_user_data and ad_personalization are set to "denied" and no analytics cookies are set.

    The data processed is technical and behavioural information about the visit, such as page address, referrer, language, approximate location at city/country level, device and browser type, and interactions such as button clicks. MeetSync® never sends names, e-mail addresses, calendar names, meeting titles or form answers to GA4. You can change or withdraw your choice at any time via Cookie settings.

    Google acts as a processor for the measurement. Data may be processed outside the EU/EEA; the transfer mechanism and the exact retention period configured in the GA4 account are stated in our sub-processor list and verified against Google's terms.

    Public bookings and events

    When an external person uses a public booking link, answers a meeting poll, registers for an event or reschedules/cancels, MeetSync® processes the data provided – such as name, e-mail address, company, requested time and answers in the booking form – in order to carry out and administer the requested booking. The processing is performed on behalf of the customer organisation that owns the booking link; that organisation is the controller and MeetSync® is the processor.

    Booking does not require you to accept statistics or marketing cookies, and this privacy notice is not an agreement you accept by booking. No cookie banner is shown in these flows and no analytics or marketing scripts are loaded.

    22. Automated meeting logic

    MeetSync uses automated logic to calculate available times, validate bookings, and suggest or select times according to the users' configuration. This functionality is intended for scheduling and is not intended to make decisions that produce legal effects or similarly significantly affect a person within the meaning of Article 22 GDPR.

    Certain flows may, according to the organization's own configuration, automatically confirm a time when the conditions for a meeting are met. Such bookings can be modified or canceled by authorized users.

    23. Children and special categories of data

    MeetSync is primarily a service for professional meeting booking and is not directed at children. Customer organizations shall not use the Service to systematically process children's personal data without a specific agreement and an appropriate legal basis.

    The Service is not intended for users to enter the following in free-text fields without a specific agreement:

    • special categories of personal data according to Article 9 GDPR
    • health data
    • complete national identity numbers
    • copies of passports or other identity documents
    • complete payment card details
    • security-classified information
    • other specially protected information

    24. Legal claims

    MeetSync may process and retain relevant personal data when it is necessary to establish, exercise, or defend legal claims, investigate suspected misuse or fraud, and to comply with binding requests from a court or public authority.

    This includes, for example, disputes, breaches of contract, requests from public authorities, fraud, chargebacks, security investigations, and misuse. Such data may be retained for longer than the normal retention period as long as the need persists.

    25. Business Transfers

    In the event of a potential or actual business transfer, financing, merger, or restructuring, relevant personal data may be disclosed to advisors and potential or actual counterparties when this is necessary and is subject to appropriate confidentiality and data protection measures.

    This may include investment, due diligence, merger, restructuring, and the sale of business or assets.

    26. Changes to this Privacy Notice

    MeetSync may update this Privacy Notice when the processing, the Service, or legislation changes. In the event of material changes, MeetSync will provide information in an appropriate manner via the Service, email, or another appropriate channel.

    If an actual new processing activity requires consent, separate consent will be obtained. The presentation and notification of a new version are logged with the version, document hash, channel, and time, and do not constitute proof of consent.

    Previous versions are archived unchanged and can be requested from privacy@meetsync.nu.

    27. Complaints to the IMY

    If you believe that MeetSync is processing your personal data in violation of data protection regulations, you can file a complaint with the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, imy@imy.se. You can also contact the supervisory authority in the EU country of your habitual residence.

    28. Contact

    MeetSync AB, Kungsholms Hamnplan 5A, 112 20 Stockholm, Sweden. Data protection matters: privacy@meetsync.nu. General contact: info@meetsync.nu.

    Related documents: Terms of Service, Data Processing Agreement and TOM Appendix, List of Sub-processors, Cookie Information and Refund Policy.