GDPR Data Processing Policy
Last updated: 22 June 2026
1. Data Controller
SoftImply OÜ (registry code 16776329), a company registered in Estonia, is the data controller responsible for the processing of personal data within narada ("Service"), a scheduling product.
- Company
- SoftImply OÜ
- Registry code
- 16776329
- Address
- Sepapaja tn 6, 15551 Tallinn, Estonia
- privacy@softimply.tech
2. What Personal Data We Process
The Service processes the following categories of personal data:
- Account data — name, email address, profile photo, username, timezone, and organization or team membership of registered users (meeting organizers).
- Calendar connections — when you connect a Google or Microsoft calendar, we process event titles, times, attendees, busy/free metadata, and the OAuth access and refresh tokens needed to read availability and create events on your behalf.
- Booking data — meeting details, scheduled times, and the data of invitees who book through your pages.
- Invitee personal data — the name, email address, timezone, answers to custom booking questions, and any files invitees upload when booking a meeting.
- Contacts — names, email addresses, and notes for contacts you save or that are created from your bookings.
- Technical data — IP address, device/browser information, and usage logs collected automatically for security and product improvement.
We do not intentionally collect special categories of personal data (Art. 9 GDPR). Please do not include such data in booking notes or uploaded files.
3. Legal Basis for Processing
We process personal data on the following legal bases under Article 6 of the GDPR:
- Consent (Art. 6(1)(a)) — invitees consent to the processing of their personal data, including any uploaded files, by submitting a booking form and checking the consent box.
- Contract performance (Art. 6(1)(b)) — processing necessary to provide the scheduling service to registered users and to fulfil bookings.
- Legitimate interest (Art. 6(1)(f)) — securing the Service, preventing fraud and abuse, and improving the product.
- Legal obligations (Art. 6(1)(c)) — compliance with applicable laws.
4. Data Storage and Security
Data is stored on Microsoft Azure infrastructure within the European Union. We apply the following measures:
- All data is transmitted over HTTPS (TLS 1.2 or higher).
- Uploaded files are stored in private Azure Blob Storage containers with no public access.
- Calendar OAuth tokens are stored securely and used only to provide scheduling features.
- Access to stored data is restricted to authorized personnel and to the relevant meeting organizer.
5. Data Retention
We retain personal data only for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Booking data, contacts, and associated files are retained for the duration of the organizer's account. When an account is deleted, associated data and files are removed within a reasonable timeframe. You can request deletion of uploaded files at any time.
6. Data Sharing and Transfers
We do not sell personal data. We share data with processors that help us operate the Service:
- Microsoft Azure — cloud hosting, data storage, and file storage (data processed within the EU) under a GDPR-compliant Data Processing Agreement.
- Google & Microsoft — calendar and conferencing providers you connect, used to sync availability and create meeting links.
- Zoom — for creating conferencing links when selected.
- Azure Communication Services — for sending booking confirmations, reminders, and notifications.
- Stripe — for subscription billing (US-based; transfers covered by the EU-US Data Privacy Framework and Standard Contractual Clauses).
- Amplitude — for anonymised product analytics (US-based; covered by the EU-US Data Privacy Framework). Amplitude does not receive booking-form content.
Your booking data and uploaded files are also shared with the relevant meeting organizer as necessary to fulfil the booking.
7. Your Rights Under GDPR
As a data subject, you have the following rights:
- Right of access (Art. 15) — request a copy of the personal data we hold about you.
- Right to rectification (Art. 16) — request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17) — request deletion of your personal data.
- Right to restrict processing (Art. 18) — request that we limit how we use your data.
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3)) — withdraw consent at any time, without affecting prior lawful processing.
To exercise any of these rights, contact us at privacy@softimply.tech. We will respond within 30 days.
8. Supervisory Authority
If you believe your data protection rights have been violated, you may lodge a complaint with a supervisory authority. As SoftImply OÜ is registered in Estonia, the relevant authority is:
- Authority
- Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
- Website
- www.aki.ee
- info@aki.ee
9. Cookies and Tracking
We use essential cookies and local storage for site operation (e.g. session, theme, and palette preferences). Amplitude analytics uses cookies and local storage to track anonymised usage. We do not use advertising or third-party ad-targeting cookies.
10. Changes to This Policy
We may update this GDPR policy from time to time to reflect changes in our practices or legal requirements. Changes will be posted on this page with an updated date.
See also: Privacy Policy · Terms of Service