Last updated September 1, 2026
Privacy Policy
How Calendia handles personal data for business customers using the platform and consumers booking services through those businesses.
1. Who we are
Calendia is operated by Carnivore AS, a Norwegian company with organisation number 824533342. You can contact us at [email protected].
This Privacy Policy explains how Calendia handles personal data for business customers that use the platform and for consumers who book, pay for, communicate about, or otherwise receive services through a business using Calendia.
2. Our role and the business role
For business account administration, subscriptions, platform security, support, billing, product analytics, website visitors, and Calendia marketing, Carnivore AS is normally the data controller.
When a business uses Calendia to manage its own customers, staff, bookings, forms, messages, payments, journals, reviews, marketing lists, finance integrations, or related records, that business normally decides why and how the data is processed. In those cases, the business is normally the controller and Carnivore AS acts as processor or service provider on the business customer instruction.
Some processing may involve separate or independent controllers, including payment processors, terminal providers, finance integration providers, email and SMS providers, authentication providers, and public authorities. Their own privacy terms may apply.
3. Personal data we collect
- Business customer data, such as company name, organisation number, billing details, account owner details, staff profiles, roles, access rights, schedules, services, locations, logos, public page content, support requests, and subscription information.
- Consumer and appointment data, such as name, email, phone number, booking history, selected service, selected employee, location, appointment time, customer notes, preferences, cancellation and rescheduling records, gift card details, review content, and marketing consent status.
- Sensitive or special category data only when a business configures Calendia for forms, disclaimers, approvals, consultations, health-adjacent records, or customer notes that may contain such data. The business is responsible for having a lawful basis and providing required notices for that collection.
- Payment and finance data, such as payment status, refunds, transaction references, terminal events, checkout sessions, reconciliation information, invoices, accounting connector metadata, tax codes, and finance sync logs. Calendia does not need full card numbers to operate the platform.
- Cash register and fiscal records, such as receipts, X and Z reports, the electronic journal, and cash register operator activity, for businesses that use the Calendia cash register. The electronic journal is append-only by design and cannot be edited or deleted, cash register operator actions are audited, and fiscal receipts, Z-reports, and the journal are retained for the statutory bookkeeping period. Where law requires that retention, this data cannot be erased on request.
- National eID data, such as the verified name, date of birth, and, where the relevant country eID returns one, a national identity number, collected when a business enables eID identity verification for a customer or staff member. The eID provider acts as an independent controller for its own part of the verification.
- Technical data, such as IP address, device and browser data, cookie identifiers, logs, security events, approximate location from network data, referral URLs, and analytics events.
- Provider mobile app data, such as push notification tokens, device identifiers, and session tokens, collected from staff who install and sign in to the Calendia provider mobile app.
- Communications data, such as emails, SMS, WhatsApp or other messages, notification records, unsubscribe events, support conversations, and operational alerts.
- AI voice receptionist data, such as call audio, transcripts, and the booking actions taken during the call, collected when a business enables the Calendia AI voice receptionist and an inbound call to that business is answered by the AI agent. Retention of call audio and transcripts is configurable by the business.
- Shared-workstation quick switch data, such as PIN hashes and an audit trail of who accessed a shared device or till, collected where a business enables PIN quick switching on a shared workstation.
4. How we use personal data
- To provide the Calendia platform, including booking, scheduling, reminders, payments, terminals, forms, public pages, gift cards, campaigns, consultations, finance integrations, reports, and support.
- To create and manage business accounts, authenticate users, apply access controls, enforce tenancy boundaries, calculate subscriptions, process invoices, manage trials, and respond to billing questions.
- To send transactional communications, such as appointment confirmations, reminders, booking management links, payment receipts, form links, security notices, account notices, and subscription notices.
- To help businesses send marketing only where they configure Calendia to do so and where they are responsible for lawful consent, opt-outs, sender identity, and message content.
- To operate a business cash register where enabled, including issuing receipts, producing X and Z reports, maintaining the append-only electronic journal, and auditing operator activity, so the business can meet its fiscal record-keeping obligations.
- To verify identity for the business where the business enables eID login, using the verified name, date of birth, and national identifier the eID provider returns.
- To operate the AI voice receptionist where a business enables it, including answering inbound calls, understanding and transcribing what is said, and taking the resulting booking actions.
- To operate the Calendia provider mobile app, including delivering push notifications and maintaining device and session state for staff who use it.
- To detect abuse, prevent fraud, investigate payment errors, debug failed finance integrations, secure the service, enforce our Terms, comply with law, and protect our rights, customers, users, and consumers.
- To improve Calendia through product analytics, diagnostics, aggregated reporting, and testing. Where practical, we use aggregated or de-identified information for these purposes.
5. Legal bases and compliance
Where GDPR, UK GDPR, or similar law applies and Carnivore AS is controller, we rely on legal bases such as contract performance, legitimate interests, consent, legal obligations, and the establishment, exercise, or defence of legal claims. The applicable basis depends on the activity.
Where we act as processor for a business customer, the business customer is responsible for identifying its lawful basis, issuing privacy notices, collecting valid consent where required, handling end-customer requests, and ensuring its use of Calendia complies with GDPR, ePrivacy, CCPA/CPRA, CAN-SPAM, marketing, health, payment, accounting, tax, and consumer protection rules that apply to it.
6. Sharing and third-party services
We share personal data with the business that provides or receives the relevant service, with authorised staff and users, and with processors and service providers that help us run Calendia. This can include hosting, storage, email, SMS, WhatsApp, analytics, support, authentication, fraud prevention, payment, terminal, finance integration, and accounting services.
If you connect a payment provider, finance integration, terminal, calendar, marketing account, or similar third-party service, Calendia may send and receive data needed to operate that integration. Third-party failures, incorrect credentials, provider downtime, rejected webhooks, payment errors, finance sync errors, and connector mapping issues may affect how data appears or moves through Calendia.
We may disclose information if required by law, court order, regulator request, tax authority request, law enforcement request, corporate transaction, security incident response, or to protect rights, safety, and the integrity of Calendia.
7. Marketing, cookies, and CAN-SPAM
Calendia may use cookies and similar technologies for security, session management, preferences, analytics, and advertising measurement where enabled. Consumers may also encounter tracking configured by a business on that business public booking or website experience.
Businesses using Calendia for campaigns, reminders, win-back flows, newsletters, referral links, or promotional messages are responsible for message legality. That includes having appropriate consent or another lawful basis, identifying the sender, avoiding deceptive headers and subject lines, including required postal or business details where required, and honouring unsubscribe and opt-out requests.
Consumers can use unsubscribe links where provided or contact the relevant business for business-controlled marketing. For Calendia marketing from Carnivore AS, contact [email protected].
8. CCPA and California privacy rights
If the CCPA/CPRA applies to you, you may have rights to know what personal information is collected, used, disclosed, sold, or shared; to access it; to request deletion; to correct inaccurate information; to opt out of sale or sharing; to limit certain uses of sensitive personal information; and to be free from discrimination for exercising those rights.
Calendia does not sell personal information in the ordinary meaning of selling data for money. If any advertising or analytics activity is considered a sale or sharing under California law, we will provide the choices required by law. If you exercise a CCPA request about data a business controls in Calendia, we may direct you to that business or help the business respond as its service provider.
9. GDPR and other privacy rights
Depending on where you live and how the data is processed, you may have rights to access, rectify, erase, restrict, port, object to processing, withdraw consent, and complain to a data protection authority. For direct marketing, you may object at any time.
If the request concerns data controlled by a business customer, please contact that business first. We will assist the business where required by our agreement and applicable law. If the request concerns Calendia account, billing, platform, or marketing data controlled by Carnivore AS, contact [email protected]. We may need to verify your identity before acting on a request.
10. Retention, security, and transfers
We retain personal data for as long as needed to provide Calendia, comply with legal, accounting, tax, payment, audit, and security obligations, resolve disputes, enforce agreements, and support business customer instructions. Businesses control many retention choices for the customer data they place in Calendia.
We use technical and organisational measures designed to protect personal data, including access controls, tenant separation, logging, and secure service providers. No online service, payment flow, finance integration, or communication channel can be guaranteed to be error-free, uninterrupted, or immune from unauthorised access.
Calendia may process or transfer data outside your country, including to countries that may not have the same privacy laws. Where required, we use appropriate safeguards such as contractual protections or other transfer mechanisms.
11. Children, changes, and contact
Calendia is not intended for children to create business accounts. Consumers under the age required by local law should only use booking flows with the involvement of a parent, guardian, or the relevant business where required.
We may update this Privacy Policy to reflect product, legal, operational, or security changes. The updated version will be posted on this page with a new effective date.
Contact: Carnivore AS, organisation number 824533342, email [email protected].