Privacy Policy

ANTONIS FLANGOFAS LIMITED. Effective date 2nd May 2026. Version 1.0.

Contents

1. Introduction and scope

1.1 This Privacy Policy explains how ANTONIS FLANGOFAS LIMITED ("we", "us", "our", "the Company") collects and uses personal data. In our Terms and Conditions for the supply of the Appointment Scheduling and Client Management Service we are called "the Seller"; we are the same company.

1.2 We operate an online appointment scheduling and client management service (the "Service"). The Service has three parts:

1.3 The Service is supplied to persons established in the Republic of Cyprus who subscribe for the purposes of their business, trade, profession or employment. A subscriber may be a company, a partnership or an individual, and this Policy is written so that it works for a subscriber who is an individual: an individual subscriber is a data subject and has every right described in section 8.

1.4 This Policy covers the personal data we handle for our own purposes — running subscriber accounts, billing, security, support, complaints and legal compliance. Those purposes are ours, we decide them, and for them we are the controller.

1.5 This Policy does not govern the End Client data held in a subscriber's Workspace. When a subscriber records a client's details, or an End Client books through a subscriber's Booking Page, the subscriber decides why that data is held and what happens to it. The subscriber is the controller and we are its processor. That processing is governed by the Data Processing Agreement at Schedule 6 of our Terms and Conditions, not by this Policy. Section 4 explains the distinction and what it means for you.

1.6 If you are an End Client — that is, if you have booked or hold an appointment with a business that uses our Service, or have received an SMS or an electronic mail from us about such an appointment — the business you booked with, not us, decides how your personal data is used. Please read that business's own privacy notice, and address any request about your data to that business. Section 4.4 explains the limited circumstances in which we nevertheless handle End Client data as a controller in our own right.

1.7 Cookies and similar technologies used on our website and platform are described in section 12.

1.8 This Policy is provided free of charge and may be downloaded, stored and printed from https://payacal.com/privacy-policy/.

2. Who we are and how to contact us

2.1 The controller for the processing described in section 3 is:

2.2 For anything about personal data, including a request to exercise your rights under section 8, write to [email protected], or to the registered office above, marked for the attention of the privacy contact.

2.3 Data Protection Officer. Mr. Antonis Flangofas, Director. Contact details: [email protected].

2.4 Other contact points. The Terms and Conditions provide separate contact points for support, billing queries, complaints, export and switching requests, security reports, notices about unlawful content, and communications from public authorities. They are listed in Schedule 5 of the Terms and Conditions. You may write to us in Greek or in English.

2.5 The supervisory authority. The competent supervisory authority for the Republic of Cyprus is the Commissioner for Personal Data Protection (Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα). Contact details are in clause 14.3.

3. What personal data we collect, why, and on what legal basis

This section describes each activity for which we are the controller. For each we state the data, where it comes from, why we process it, our legal basis, who receives it, and how long we keep it. References to Articles are to Regulation (EU) 2016/679 (the GDPR).

3.1 Subscriber account and registration data

What we process. The business name supplied at signup and displayed to End Clients; the name of the individual who signs up and of each administrative user; the electronic mail address and telephone number; the stated place of establishment; the address and VAT registration number if supplied; information about the subscriber's profession or regulator if supplied; the subscription status; and the record we keep under clause 25.7 of the Terms and Conditions, being the version of the Terms displayed, the date and time of acceptance, the business purpose statement given and the place of establishment stated at signup.

Where it comes from. Directly from the subscriber, at signup and while the subscription continues.

Why. To create and administer the account; to conclude and perform the Terms and Conditions; to provision the Workspace and the Booking Page; to communicate with the subscriber about the Service, including notices, alerts and changes to the Terms; to evidence what was agreed and when; and to keep the records the law requires of us.

Legal basis. Article 6(1)(b) — performance of the contract with the subscriber and steps taken at its request before entering into it: account creation, provisioning and service communications. Article 6(1)(c) — legal obligation, for records we are required to keep, including under Cyprus tax and value added tax legislation. Article 6(1)(f) — our legitimate interests, being evidencing the terms on which each subscriber contracted and the business purpose statement it gave, so that we can establish, exercise and defend legal claims and demonstrate our own compliance, and preventing the Service being taken up by persons who are not eligible for it. We have weighed those interests against your interests, rights and freedoms: the data is limited to what you supplied at signup, it is not used to make decisions about you beyond the operation of the account, and you may object under clause 8.8 of this Policy.

Is it mandatory? The business name, the name and electronic mail address of the person signing up, the telephone number and the stated place of establishment are required to conclude the contract; without them we cannot supply the Service. The VAT registration number, billing address and information about profession or regulator are optional, but without a VAT number and address we cannot issue a value added tax invoice in the subscriber's name and will issue the other tax document Cyprus law requires.

Recipients. Our hosting provider and electronic mail delivery provider, as sub-processors; our professional advisers; and, where section 6 applies, public authorities and courts. Retention: clause 5.1.

3.2 Billing and payment records

What we process. The payment processor's customer identifier, the plan code, the subscription status, the date on which the current period ends, and whether a payment method is attached. Invoice and statement data: name or business name, address, VAT registration number if supplied, the amounts charged, the number of SMS messages recorded as sent in the subscription month, the message allowance and the number of chargeable messages above it.

We do not receive, process or store card numbers, security codes, cardholder names or billing addresses. Card details are entered on, and held by, our payment processor on its own hosted pages. We never see them.

Where it comes from. Generated by us and by the payment processor when a payment method is registered and each time a charge is made; the address and VAT number are supplied by the subscriber in the Workspace.

Why. To collect the fee and any charge for messages above the allowance; to issue the tax document Cyprus law requires for each charge; to keep accounting and tax records; to answer queries about a charge; and to recover amounts due.

Legal basis. Article 6(1)(b) — performance of the contract. Article 6(1)(c) — compliance with a legal obligation, in particular the obligation to issue the correct tax document for each supply and to preserve accounting and value added tax records. Article 6(1)(f) — our legitimate interest in recovering amounts owed to us and in defending disputed charges.

Is it mandatory? To move from the free trial to a paid subscription, a payment method must be registered with the payment processor; without it no charge can be made and no subscription begins. Address and VAT number are supplied at the subscriber's option, as described in clause 3.1.

Recipients. The payment processor; our accountants and auditors; the Tax Department of the Republic of Cyprus where the law requires; and, if we have to pursue an unpaid amount, our lawyers, a collection agency and the courts. Retention: clause 5.2.

3.3 Service usage, technical and security data

What we process. Sign-in timestamps and session data; internet protocol addresses; browser and device information captured for security purposes; rate-limiting and abuse-prevention data; internal system, application, security and audit logs; error-tracking records; records of security incidents; and, for billing purposes, the counts derived from the Dispatch Log, being the number of SMS messages recorded as sent for a subscriber in a subscription month.

A note on the Dispatch Log. The Dispatch Log records, for each message the Service has processed, the subscriber, the channel, the time of processing and the outcome recorded as sent, failed or skipped, together with the recipient's identifier. The individual entries, including the recipient's identifier, are the subscriber's content and we hold them as processor — see section 4. The counts we derive from them for metering and billing are our own record and we hold them as controller.

Where it comes from. Generated automatically by the Service as it is used. Not collected from you by a form.

Why. To keep the Service and every subscriber's Workspace secure; to detect, investigate and prevent fraud, abuse and unauthorised access; to maintain isolation between Workspaces; to investigate and respond to security incidents; to meter SMS messages so that charges above the allowance can be calculated and shown; and to diagnose faults and maintain the Service.

Legal basis. Article 6(1)(b) — performance of the contract, for the metering, because the amount payable cannot be calculated without it. Article 6(1)(f) — our legitimate interests for the remainder, being keeping a multi-tenant platform secure and available for every subscriber on it, preventing and detecting fraud, abuse and unauthorised access to Workspaces, and diagnosing and correcting faults. We have weighed those interests against your interests, rights and freedoms: security logging is directed at systems rather than at individuals, is not used to build any profile of you or to make decisions about you, and is retained for a limited period.

Recipients. Our hosting provider and our error-tracking provider, as sub-processors; and, where a security incident requires it, the affected subscribers, the Commissioner for Personal Data Protection and any other authority the law requires us to inform. Retention: clause 5.3.

3.4 Support, complaints, and notices about content

What we process. Name and electronic mail address; the content of support requests, billing queries, complaints and correspondence; our replies; the records of our internal complaint-handling system, being each complaint, how it was handled and how it was decided; and, where a person notifies us of content on the Service which that person considers to be unlawful, the name and electronic mail address of that person, the explanation given, the location of the content, and our decision and reasons.

Where it comes from. Directly from the subscriber; from an End Client who contacts us; or from a third party who submits a notice about content.

Why. To answer support requests and billing queries; to operate the internal complaint-handling system described in clause 23 of the Terms and Conditions; to receive and act on notices about unlawful content, to acknowledge them, to decide them and to inform the notifying person of the decision and of the redress available; to give a statement of reasons to a subscriber or an End Client when we restrict, remove or disable content or suspend or terminate the Service; to improve the Service; and to protect our legal position.

Legal basis. Article 6(1)(b) — performance of the contract, for support given to a subscriber. Article 6(1)(c) — compliance with a legal obligation, for the notice-and-action mechanism, statements of reasons and related duties under Regulation (EU) 2022/2065 (the Digital Services Act). Article 6(1)(f) — our legitimate interests in handling complaints properly, in enforcing our Terms and Conditions, and in establishing, exercising and defending legal claims.

Is it mandatory? A person submitting a notice about content must give a name and electronic mail address if the notice is to be one on which we are obliged to act, except where the notice concerns an offence relating to child sexual abuse or exploitation, in which case no name or address is required.

Recipients. Where a notice concerns content: the subscriber whose Workspace or Booking Page the content is on and, so far as we can reach them, the End Client who provided it; our advisers; and, where section 6 applies, public authorities and courts. Retention: clause 5.4.

3.5 Legal compliance, claims and dealings with authorities

What we process. Any personal data contained in correspondence with a regulatory or supervisory authority — including the Commissioner for Personal Data Protection and the Radio Television and Digital Services Authority, which is the Digital Services Coordinator for the Republic of Cyprus — in an order of a court or of an administrative authority, or in a notification of a security incident or personal data breach; and any personal data we need to establish, exercise or defend a legal claim.

We also disclose information to a competent authority of the Republic in the following two situations, which we set out expressly because they override the confidentiality we otherwise owe:

We will tell the subscriber that we have acted in this way unless the law, the order or the authority prohibits or defers that notification, or unless telling the subscriber would prejudice an investigation.

Legal basis. Article 6(1)(c) — compliance with a legal obligation, including obligations under Regulation (EU) 2022/2065 and orders of judicial and administrative authorities. Article 6(1)(f) — our legitimate interest in establishing, exercising and defending legal claims and in reporting suspected unlawful activity.

Recipients. The authority or court concerned; our lawyers and other advisers. Retention: clause 5.5.

3.6 The Booking Page and End Client data

What is processed. The name, telephone number and electronic mail address an End Client supplies through a Booking Page, the service selected and the appointment time chosen; the appointment and contact records a subscriber creates in its Workspace; the free text a subscriber enters against an appointment or a contact; and the messages dispatched to End Clients.

Our role. We process this data as processor on the instructions of the subscriber, who is the controller. We do not decide why it is held or what is done with it. That processing is governed by the Data Processing Agreement at Schedule 6 of the Terms and Conditions.

What we do not do with it. We do not use it to train any machine-learning or artificial-intelligence model. We do not pool or aggregate it across subscribers for any purpose. We do not read, index, analyse or re-use free text for any purpose other than supplying the Service, complying with the law and exercising our rights under the Terms and Conditions. We do not monitor content and we do not review free text.

If you are an End Client, the business you booked with is responsible for telling you how it uses your data, for having a lawful basis for holding it and for sending you messages, and for answering your requests. Please contact that business. If you send us a request directed at a subscriber's processing, we will pass it to the subscriber without undue delay and will not answer it on the subscriber's behalf.

Limited processing as controller: clause 4.4. Retention: clause 5.6.

3.7 Cookies and similar technologies

We use cookies and similar technologies on our website and on the platform. They are described, with their purposes and durations, in section 12. Where the law requires your consent to a cookie, we ask for it and you may withdraw it at any time.

4. Our two roles: controller and processor

4.1 The distinction in plain terms. A controller decides why personal data is held and what is done with it. A processor holds and handles it on the controller's instructions and for the controller's purposes. The same company can be a controller for one set of data and a processor for another.

4.2 Where we are the controller. We decide why we hold subscriber account, contract and billing records, our security and technical logs, our support and complaints records, and the records we keep for legal compliance and to defend claims. Section 3 describes them. For those, we owe you the information in this Policy and you exercise your rights against us.

4.3 Where we are the processor. We do not decide why a subscriber holds its clients' details. The subscriber decides that. It chooses what to record, what to write in the free text field, when a reminder is sent and what it says. We supply the software and we carry out those instructions. For that data we are the processor, and:

4.4 The exception — where we handle End Client data as controller. In three narrow situations we determine the purposes and means of processing End Client data ourselves, and we are the controller of that processing:

4.5 A note for individual subscribers. If you subscribe as an individual — a sole trader or a professional practising in your own name — then the business name, business profile, telephone number, address and any logo you choose to publish on your Booking Page or include in a message may be your own personal data, and it is published to the public. You decide what to publish and you can change or remove it in the Workspace at any time. We publish it because you instruct us to. The same information, held in your account record so that we can administer your subscription and bill you, is held by us as controller under clause 3.1.

5. How long we keep personal data

5.1 Subscriber account and registration data, including the acceptance record kept under clause 25.7 of the Terms and Conditions: for as long as the subscription continues, and afterwards for a maximum of 6 years from the end of the subscription. The criterion is the general limitation period for a claim founded on contract in the Republic of Cyprus, so that we can defend a claim brought within that period and prove what was agreed.

5.2 Billing, accounting and tax records: for 7 years from the end of the accounting period to which they relate, or such longer period as Cyprus tax and value added tax legislation requires. We keep the payment processor's customer identifier for the duration of the subscription and afterwards only so far as those records require.

5.3 Service usage, technical and security data: for 12 months from the date the entry is created. Where an entry relates to a security incident, an investigation, a suspected abuse or an actual or threatened claim, we keep it until that matter is concluded and afterwards for the period in clause 5.1.

5.4 Support, complaints and content-notice records: for 6 years from the date the matter is closed. The criterion is the same limitation period as in clause 5.1.

5.5 Legal compliance and claims records: for as long as the obligation or the claim requires, and afterwards for the period in clause 5.1.

5.6 End Client data in a Workspace (held as processor): governed by the Data Export and Switching Schedule at Schedule 4 of the Terms and Conditions and by the Data Processing Agreement at Schedule 6. In outline:

5.7 Backups. Personal data may persist in our backups for a short period after it has been erased from the live systems. It is not restored to the live systems except in a recovery, and it is overwritten in the ordinary backup cycle.

5.8 Legal holds. Where personal data is relevant to an actual or reasonably anticipated claim, investigation, regulatory proceeding or order, we retain it until that matter is concluded, notwithstanding the periods above.

6. Who we share personal data with

6.1 We share personal data only with the following.

6.2 We do not sell personal data. We do not share personal data with third parties for their own marketing purposes. We do not use personal data to train any machine-learning or artificial-intelligence model. We do not aggregate subscribers' content across subscribers for any purpose.

7. Transfers outside the European Economic Area

7.1 Our application servers and databases are operated in Frankfurt, Germany, within the European Economic Area. That is where subscriber accounts and subscriber content are stored.

7.2 Some of our sub-processors may be established outside the European Economic Area, or may route data through a country outside it. This is most likely to happen in the transmission of an SMS message, where a carrier or an aggregator may route the message through networks outside the European Economic Area in order to deliver it. Where that occurs, the message and the recipient's number are transmitted.

7.3 Where personal data is transferred outside the European Economic Area we do so only on one of the bases the GDPR permits, namely:

7.4 The published sub-processor list at https://payacal.com/terms-and-conditions/ states, for each sub-processor, where it processes data and, for the SMS carrier or aggregator, the regions through which messages may be routed.

7.5 You may obtain a copy of the safeguards we rely on, or information about where to obtain them, by writing to the address in clause 2.2.

8. Your rights

8.1 You have the following rights in respect of personal data for which we are the controller. Some are qualified: they apply on certain grounds and are subject to exceptions, and we explain the main ones below.

8.2 Access (Article 15). You may ask us to confirm whether we process personal data about you and, if we do, to give you a copy of it and to tell you about the purposes, the categories of data, the recipients, the retention period, your rights and the source of the data.

8.3 Rectification (Article 16). You may ask us to correct inaccurate personal data about you and to complete data that is incomplete. Much of the account data can be corrected by you directly in the Workspace.

8.4 Erasure (Article 17). You may ask us to erase personal data about you. This right applies where, for example, the data is no longer necessary for the purpose, you have withdrawn consent and there is no other basis, you have objected successfully under clause 8.8 of this Policy, or the data has been processed unlawfully. It does not apply where we are required to keep the data to comply with a legal obligation — accounting and tax records are the clearest example — or where we need it to establish, exercise or defend a legal claim. In those cases we will tell you which exception applies.

8.5 Restriction (Article 18). You may ask us to stop using personal data, while continuing to store it, where you contest its accuracy, where the processing is unlawful but you do not want it erased, where we no longer need it but you need it for a legal claim, or while we consider an objection under clause 8.8 of this Policy.

8.6 Notification (Article 19). Where we rectify, erase or restrict personal data, we will tell each recipient to whom we disclosed it, unless that proves impossible or involves disproportionate effort. We will tell you who those recipients are if you ask.

8.7 Portability (Article 20). Where we process personal data by automated means on the basis of your consent or of a contract with you, you may ask us to give it to you in a structured, commonly used, machine-readable format, and to transmit it to another controller where that is technically feasible. This right does not extend to data we process on the basis of a legal obligation or of our legitimate interests. Separately from this right, the Terms and Conditions give every subscriber a standing right to export its content at any time, free of charge and without giving a reason, and the categories excluded from that export function do not limit any right you have by law to obtain your data.

8.8 Objection (Article 21). Where we process personal data on the basis of our legitimate interests, you may object at any time on grounds relating to your particular situation. We will stop unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or unless we need the data to establish, exercise or defend a legal claim. You may object to direct marketing at any time and we will stop, without exception. We do not at present send direct marketing to subscribers other than service communications, which are not marketing.

8.9 Withdrawal of consent (Article 7(3)). Where we rely on your consent — in practice for cookies, and for any optional communication you have opted into — you may withdraw it at any time. Withdrawal does not affect the lawfulness of what we did before you withdrew it.

8.10 Automated decision-making (Article 22). See section 10.

8.11 Complaint to the supervisory authority. See clause 14.3.

How to exercise your rights

8.12 Write to us at the address in clause 2.2. You do not need to use a particular form of words. Tell us which right you are exercising and, if it is not obvious, what data you mean.

8.13 There is no charge. We do not charge for dealing with a request. If a request is manifestly unfounded or excessive, in particular because it is repetitive, we may charge a reasonable fee reflecting our administrative costs, or refuse to act on it. If we do either, we will tell you why and you may complain to the Commissioner.

8.14 Time. We will respond within one month of receiving the request. We may extend that by up to two further months where the request is complex or where we have received a number of requests from you; if we do, we will tell you within the first month and say why.

8.15 Identity. Where we have reasonable doubts about the identity of the person making a request, we will ask for the further information we need to confirm it. We will ask for no more than is necessary, and the time in clause 8.14 runs from when we receive it.

8.16 If we do not act on your request, we will tell you within one month why, and tell you that you may complain to the Commissioner and seek a judicial remedy.

8.17 If you are an End Client, address a request about the data a subscriber holds about you to that subscriber. If you send it to us we will pass it on to the subscriber without undue delay. The rights described above are exercisable against us only in respect of the processing described in clause 4.4.

9. Children

9.1 The Service is not directed at children. Subscribers warrant on signup that, if an individual, they are aged 18 or over. We do not knowingly collect personal data of a person under 18 in our capacity as controller.

9.2 Under Article 8 of Law 125(I)/2018, where an information society service is offered directly to a child in the Republic of Cyprus and the processing is based on the child's consent, that processing is lawful if the child is at least 14 years old; below that age it is lawful only with the consent of, or authorisation by, the holder of parental responsibility for the child.

9.3 If we become aware that we hold, as controller, the personal data of a child under 14 collected on the basis of consent without that authorisation, we will erase it without undue delay.

9.4 A Booking Page may be used by a person under 18 — for example where a subscriber's practice sees younger patients or clients. Where that happens the subscriber, not we, is the controller of that data, and it is for the subscriber to satisfy itself that its processing is lawful, including as to the age of the person concerned and the consent of a parent or guardian where consent is the basis relied on. We provide the booking form; we do not decide who may use it.

10. Automated decision-making and profiling

10.1 We do not carry out profiling. We do not build profiles of subscribers or of End Clients, we do not score or rank them, and we do not evaluate personal aspects of any individual by automated means.

10.2 We do not take content-moderation decisions by automated means. We use no automated means to detect, filter, rank, classify or remove content. Every decision to restrict, remove or disable content is taken by a member of our personnel who reviews the content and the ground relied on.

10.3 One process is automated: the metering of SMS messages. The Service counts the SMS messages recorded in the Dispatch Log as sent for a subscriber in a subscription month, deducts the message allowance, and charges the balance at the published unit price. Messages recorded as failed or skipped are not counted. A message accepted by the carrier and later reported as undelivered is counted, because the count is taken when the message is submitted.

10.4 That count produces the amount a subscriber owes. Where the subscriber is an individual, that is a decision producing legal effects concerning that individual, taken solely by automated means. It is permitted because it is necessary for entering into and performing the contract between us: an allowance-and-overage model cannot be operated by counting messages by hand. We do not rely on your consent for it, and we do not use any special category of personal data in it.

10.5 The safeguards. Under clause 8.8 of the Terms and Conditions you may at any time:

If the count was wrong we will correct it and repay or credit the amount over-charged. The Dispatch Log is evidence of the count but is not conclusive of it, and you may show by any means that it is wrong. There is no time limit on your right to query a charge or to bring proceedings.

10.6 The Workspace shows you, at all times, the number of SMS messages recorded as sent in the current subscription month, the balance of your allowance and the charges accrued.

11. Security and personal data breaches

11.1 We maintain technical and organisational measures appropriate to the risk. They are described in the Security Schedule at Schedule 2 of the Terms and Conditions, and cover encryption of content in transit and at rest, access control, isolation between Workspaces, and rate limiting.

11.2 Each subscriber's Workspace is isolated from every other at database level. Content is not pooled with, and is not accessible from, another subscriber's Workspace.

11.3 We calibrate our measures on the footing that content may contain special categories of personal data notwithstanding that our Terms and Conditions prohibit subscribers from entering it. That is a precaution about how we secure data. It is not permission to enter such data, and it is not a representation that the Service is suitable for processing it. The Service is not a clinical record system and must not be used as one.

11.4 No system is immune. We do not warrant that the Service will not be compromised.

11.5 Personal data breaches — our own controller processing. Where a personal data breach occurs in respect of personal data for which we are the controller, we will notify the Commissioner for Personal Data Protection without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33). Where the breach is likely to result in a high risk to those rights and freedoms, we will also communicate it to the individuals affected without undue delay (Article 34).

11.6 Article 34(3) provides for cases in which that communication to individuals is not required. Separately, Article 12 of Law 125(I)/2018 allows a controller to be exempted, in whole or in part, from the obligation to communicate a breach to data subjects for one or more of the purposes in Article 23(1) of the GDPR; an exemption requires an impact assessment and prior consultation with the Commissioner, and the Commissioner may impose conditions on it. We record that possibility for completeness. Our practice is to tell people when a breach affects them.

11.7 Personal data breaches — data we hold as processor. Where a breach affects personal data we process on a subscriber's behalf, we notify the subscriber without undue delay and within the period stated in the Security Schedule, describing the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, a contact point, the likely consequences, and the measures taken or proposed. The subscriber, as controller, is responsible for notifying the Commissioner and any affected individual. We do not do so on its behalf.

11.8 Security incidents affecting the Service are notified to subscribers under paragraph 4 of the Security Schedule. That is a separate obligation from the notification of a personal data breach and one does not discharge the other.

11.9 You are responsible for the security of your own credentials, devices and administrative user accounts. Please tell us without undue delay, at the security contact in Schedule 5 of the Terms and Conditions, if you suspect unauthorised access to your Workspace.

12. Cookies

12.1 The following cookies and similar technologies are set on our website and on the platform.

NameSet byPurposeDuration
ph_<project>_posthog PostHog, our product-analytics provider, processing in the European Union Measures how the website and the Workspace are used, so that we can see which pages and features are used and where people stop. It holds a device identifier and a session identifier. 365 days
oauth_origin Us Records which Workspace a sign-in started from, so that we can return you to it after you sign in with a Google account. It is set only when you use that sign-in method. Until the browser is closed

12.2 We also store information in your browser which is not a cookie: the sign-in token for the Workspace, and small preferences such as the calendar view you last used and whether you have dismissed a notice. That information stays in your browser, is not sent to us except where it authenticates you, and is removed when you sign out or clear your browser storage.

12.3 Our pages load fonts from Google's font service. Your internet protocol address is disclosed to that service when a page is loaded so that it can serve the font.

12.4 Where the law requires your consent to a cookie, we ask for it and you may withdraw it at any time. You may also block or delete cookies in your browser settings. If you block the analytics cookie the Service continues to work.

13. Changes to this Privacy Policy

13.1 We may change this Policy — for example if we change how the Service works, engage a different sub-processor, or need to reflect a change in the law or in the guidance of the Commissioner.

13.2 The current version is always published at https://payacal.com/privacy-policy/ with its effective date and version number. We keep every previous version and will supply one on request.

13.3 Where a change is material — in particular a change to the purposes for which we process personal data, to the legal basis for a purpose, to the categories of recipient, or to a retention period — we will tell subscribers by electronic mail to the address registered in the Workspace, not fewer than 30 days before it takes effect. Where the change also amounts to a change to the Terms and Conditions, clause 22 of those Terms applies and the subscriber may terminate without charge and without penalty before the change takes effect.

13.4 A change does not have retrospective effect.

14. Governing law, the supervisory authority and complaints

14.1 This Privacy Policy, and our processing of personal data, are governed by Regulation (EU) 2016/679, by Law 125(I)/2018 and by the other law of the Republic of Cyprus.

14.2 Complain to us first if you wish. Write to the address in clause 2.2. We will deal with your complaint under section 8 and, where it concerns the Service, under the internal complaint-handling system in clause 23 of the Terms and Conditions. Using that system is not a condition of, and does not delay, any other right you have.

14.3 You may complain to the supervisory authority at any time, whether or not you have complained to us. The competent supervisory authority for the Republic of Cyprus is:

14.4 Complaining to the Commissioner is without prejudice to any other administrative or judicial remedy. You may also bring proceedings in the courts of the Republic of Cyprus, and you may claim compensation for damage suffered as a result of an infringement.

14.5 A decision of the Commissioner may be challenged by a recourse to the Administrative Court of the Republic of Cyprus, under Article 28 of Law 125(I)/2018.

14.6 Infringement of the GDPR and of Law 125(I)/2018 may expose a controller to administrative fines imposed by the Commissioner under Article 83 of the GDPR and to criminal penalties under Article 33 of Law 125(I)/2018. We record this because compliance is a matter we take seriously, and not to suggest that any such matter arises.

Version history

VersionDateDescription
1.02nd May 2026Initial publication.

Controller: ANTONIS FLANGOFAS LIMITED – HE 432879