Meetimely Privacy Notice
This notice explains how personal data is processed on meetimely.com, in business accounts, and when public booking pages are technically provided. For booking data belonging to a real business, that business is generally the controller and Meetimely processes the data as its processor.
1. Controller
Controller for processing carried out by Meetimely for its own purposes:
Meetimely operated by Meetimely Mustermannstrasse 1, 10115 Berlin, Germany Email: hello@meetimely.com
2. Allocation of roles
Meetimely acts as controller for business-account registration and administration, authentication, platform operation, security, abuse prevention, support, and management of the free beta.
When a business publishes a booking page, the business determines the purposes and means of processing its customer and appointment data and is the controller. Meetimely processes that data on the business's documented instructions as processor. The Data Processing Agreement governs the details.
Meetimely may process limited technical security and evidence data as a separate controller where necessary to operate the platform securely or establish, exercise, or defend legal claims.
3. Website access and technical logs
When the website is accessed, Meetimely may process the IP address, date and time, requested URL, referrer, browser and device information, response status, and security-related events. This is necessary to deliver the website, diagnose errors, prevent attacks, and secure the service.
The legal basis is Article 6(1)(f) GDPR. Meetimely's legitimate interest is the secure and reliable operation of the platform. Logs are deleted after 30 days unless a security incident or the establishment, exercise, or defence of legal claims requires longer retention.
4. Business accounts
For registration, login, and account administration, Meetimely processes information including name, business email address, password hash, verification status, sessions, account role, accepted document versions, and acceptance timestamps.
Processing is necessary to provide the free beta and take pre-contractual steps under Article 6(1)(b) GDPR. Security and evidentiary data may additionally be processed under Article 6(1)(f) GDPR.
Required fields are necessary to provide an account. A business account cannot be created without them.
5. Business profile and public booking page
Meetimely processes business information entered by the account holder, including the business name, description, contact details, address, opening hours, services, prices, duration, team or role information, images, logo, and page settings. Information approved for publication is publicly accessible.
The business is responsible for providing lawful and accurate content suitable for publication and for holding the necessary rights to images, trademarks, and text.
6. Customer and booking data
A booking request may contain the customer's name, email address, phone number, selected services, preferred time, assigned team role, message or note, booking status, and technical transmission data.
For bookings made with a real business, the business is the controller and determines the legal basis and information provided to the customer. Meetimely processes the data under the Data Processing Agreement and the business's instructions.
Meetimely does not use booking content for its own advertising and does not sell booking data. Health information, religious information, or other special-category data should not be entered into free-text fields unless strictly necessary and legally supported.
7. Service emails
Meetimely processes email addresses and delivery information to send verification messages, password resets, security notices, and technically necessary booking or account communications. The legal basis is Article 6(1)(b) GDPR; security notices may rely on Article 6(1)(f) GDPR.
Marketing messages are sent only on a separate legal basis. Consent to marketing must not be required to use the beta.
8. Support and privacy requests
When a person contacts Meetimely, Meetimely processes the contact details, request content, and any necessary evidence to handle the request, perform the contract, comply with legal duties, or establish, exercise, or defend legal claims.
Do not send an identity document unless Meetimely specifically asks for it. Only information necessary to verify identity will be requested.
9. Cookies and local storage
Meetimely uses only cookies or similar storage technologies that are strictly necessary for login, session management, security, language settings, and the booking flow. They are necessary to provide the service expressly requested by the user.
Analytics, marketing, or advertising technologies may be activated only after valid consent. If such technologies are introduced, this notice will be updated before activation and an appropriate consent mechanism will be implemented.
10. Recipients and processors
Personal data is made available only to parties that need it for operation, hosting, databases, backups, email delivery, error analysis, or support. The current providers, purposes, locations, and transfer mechanisms are published in the Subprocessor List.
Meetimely enters into the required data-protection agreements and limits access to what is necessary.
11. Processing outside the EEA
Where a recipient processes data outside the European Economic Area, the transfer takes place only on the basis of an adequacy decision or appropriate safeguards, particularly Standard Contractual Clauses, together with supplementary measures where required. Details are provided in the Subprocessor List.
12. Retention
Account data is generally processed for the lifetime of the account. After account closure, production data is deleted or anonymised within 30 days unless a legal obligation or legitimate reason requires continued retention. Backup copies are overwritten according to the backup cycle and no later than 30 days.
Sessions and verification or reset data are deleted after use or expiry. Booking data is deleted on the controller business's instruction, when the account closes, or when the configured retention period expires. Security data may be retained until an incident is resolved.
13. Data-subject rights
Subject to the GDPR, individuals may have rights of access, rectification, erasure, restriction, portability, and objection. Consent may be withdrawn at any time with effect for the future.
Requests may be sent to hello@meetimely.com. Where the request concerns a booking with a business, that business is generally the first point of contact. Meetimely assists the business in responding.
14. Right to complain
Individuals may lodge a complaint with a competent data-protection supervisory authority. This right is without prejudice to other administrative or judicial remedies.
15. Security
Meetimely applies appropriate technical and organisational measures, including encrypted transmission, secure password storage, role-based access, separation of business accounts, secret management, logging of security-relevant events, and procedures for backup, restoration, deletion, and incident handling. The published Technical and Organisational Measures describe the controls that have been confirmed as implemented.
16. Changes to this notice
This notice will be updated when features, providers, or legal bases change. The current version and version date will be published on this page. Material changes will be communicated to business accounts in an appropriate manner.