Privacy Policy
Last updated: June 18, 2026
1. Data Controller
This Privacy Policy is prepared by RandevuAI (“Platform”, “we”, “us”). We act as the data controller for personal data processed through our services.
Contact: privacy@randevuai.net
2. Data We Collect
Depending on how you use the Platform, different categories of personal data may be processed:
Business Account Holders
- Identity: Name, surname, email address
- Contact: Phone number, business address
- Business info: Business name, sector, tax ID (for invoicing)
- Payment data: Card details (stored encrypted by our payment processor — never transmitted to us)
- Usage data: Session logs, IP address, device information
End Customers (via Business)
- Identity: Name, surname
- Contact: Phone number, email address
- Appointment data: Service, date, time, staff
- Health data (where applicable, with explicit consent): Clinical notes, diagnosis drafts
3. How We Use Your Data
- Providing the appointment management service
- Sending appointment reminders via SMS/email
- Invoicing and legal compliance
- AI-powered features (copilot, analytics) — with your consent
- Security and fraud prevention
- Service improvement and analytics
4. Data Transfers
Personal data is transferred only to the service partners necessary to provide the service:
- Neon (PostgreSQL): Database hosting (EU data center, GDPR compliant)
- Vercel: Application hosting (US, SCCs compliant)
- iyzico: Booking payment processing (PCI DSS compliant)
- Paddle: Subscription billing (PCI DSS compliant)
- Twilio: SMS and voice notifications
- Google (Gemini AI): AI features (EU servers, DPA)
- Resend: Email notifications
International data transfers are made only to countries with an adequate level of protection or under Standard Contractual Clauses (SCCs).
5. Retention Periods
- Account data: While active + 30 days after cancellation
- Appointment records: 5 years
- Invoice records: 10 years (legal obligation)
- Health data: Minimum 10 years (applicable regulations)
- Security & log data: 2 years
6. Security
- All data transmitted over HTTPS/TLS encryption
- Passwords hashed with bcrypt (never stored in plain text)
- Session management via JWT HttpOnly cookies
- Multi-tenant architecture: Each business’s data is isolated
- Rate limiting and CSRF protection on all API endpoints
- Regular security scanning and automated backups
7. Your Rights
You have the following rights regarding your personal data:
- Right to access: Request a copy of your data
- Right to rectification: Correct inaccurate or incomplete data
- Right to erasure: Request deletion of your data under certain conditions
- Right to object: Object to automated processing and profiling
- Right to portability: Receive your data in a structured format
- Right to complain: Lodge a complaint with your local data protection authority
To exercise your rights, email privacy@randevuai.net. Requests are answered within 30 days, free of charge.
8. Cookies
- Essential cookies: Session management — no consent required
- Analytics cookies: PostHog usage analytics — with consent
- Preference cookies: Language, theme
You can disable non-essential cookies in your browser settings.
9. Contact
Privacy inquiries: privacy@randevuai.net
Data breach reporting: security@randevuai.net
This document is provided in multiple languages. In case of any inconsistency or dispute, the English text prevails.