Privacy Policy
Effective and last updated: July 31, 2026
The short version. Avum processes calendar information only to provide you with the features you request and does not retain event details during ordinary operation. We do not sell data or use calendar content for advertising or AI training. Event processing is automated. Human review is exceptional and subject to Section 7.
1. Scope and who is responsible for your data
This Privacy Policy explains how Pentatope Technologies Kft. ("we," "us," or "our") handles personal data when you visit avum.io or use Avum ("Avum") and related support (collectively, the "Service").
We operate Avum and are the data controller for the account, subscription-administration, website, support, and service-operation data described in this Policy. Our company registration number is 07-09-032526.
If an organization provides or manages your Avum account, that organization may be a separate controller of your data. Where we process calendar data solely on a business customer's documented instructions, that customer is the controller and we are its processor. Contact the organization about its practices.
2. Personal data we collect
Account and authentication data
We collect identity, contact, account, subscription, and authentication information. Avum uses passwordless sign-in and does not store your Google or Microsoft password.
Connected-account and authorization data
When you connect an account, we receive and store connected-account identity information and OAuth credentials so Avum can act on your instructions.
Calendar metadata
We store calendar metadata and permissions needed to identify, display, and use connected calendars.
Calendar event data
To run your Sync Rules, Avum reads, transforms, and writes calendar events. Depending on the event and the settings, it processes event details and provider metadata. Event details may include other people's personal data.
The Unified Calendar processes event details transiently to display, search, or perform an operation.
Avum does not retain event details in its application storage during ordinary operation. It may retain provider cursors and content-free operational records. A restricted support capture may include event details only under Section 7.
Configuration and service-operation data
We store Sync Rules, settings, calendar selections, service state, limited logs, and related technical identifiers.
For Unified Calendar operations, Avum may store a content-free mutation ledger for up to 90 days to prevent duplicates and recover incomplete moves.
Billing and transaction data
Paddle is the merchant of record and processes and retains payment-card, checkout, invoice, billing, and tax records. Avum stores only subscription and transaction status needed to provide the plan and reconcile deletion. It does not store complete card details, invoices, or Paddle's billing and tax records.
Trial eligibility and account-deletion safeguards
When a connected-account email is used during a trial, the trial record can initially include the email and related identifiers. We calculate a deterministic HMAC-SHA-256 digest using an Avum-controlled secret key. This allows repeat matching after account deletion without keeping the email. On deletion, we similarly digest normalized Paddle identifiers to prevent delayed messages from recreating the account. We treat them as pseudonymous personal data used only for trial eligibility and deletion integrity, subject to Sections 9 and 12.
Support and communications data
If you contact us, we collect your communications, contact information, and related materials. With the authorization in Section 7, this may include diagnostics or selected calendar data needed for the issue.
Website, device, and security data
To operate and secure the Service, we and our providers automatically process browser, device, network, session, request, and related security data. When you request a passwordless sign-in link, Google reCAPTCHA processes this data and your interaction with the page, including your IP address, on our behalf and returns an abuse-risk result that we may use to allow or refuse the request. We do this for our legitimate interests in preventing fraud and abuse and retain our resulting security records as described in Section 9.
3. Where the data comes from
We obtain personal data:
- directly from you when you register, configure the Service, purchase a plan, or contact us.
- from Google or Microsoft when you connect an account and use calendar features.
- from your organization if it creates, purchases, or administers your account.
- from service providers, including Paddle.
- automatically from your browser, device, and interactions with the Service.
4. Why we use personal data and our legal bases
Where the GDPR, UK GDPR, or similar law applies, we rely on the legal bases below. The particular basis depends on the context and the data involved.
| Purpose | Typical legal basis |
|---|---|
| Provide and administer the Service | Performance of our contract with you or steps requested before entering into it |
| Activate plans and administer subscription status with Paddle | Performance of our contract and our legitimate interests in reconciling subscription status |
| Support, maintain, and improve the Service | Contract and our legitimate interests, with consent where specifically requested or required |
| Prevent fraud, investigate abuse or security incidents, and protect users and the Service | Our legitimate interests and, where applicable, legal obligation |
| Enforce one-trial eligibility and prevent delayed billing messages from recreating a deleted account | Our legitimate interests in preventing abuse and preserving the effect of account deletion |
| Send transactional and service communications | Contract and our legitimate interests in communicating about the Service |
| Send optional marketing communications | Consent, or legitimate interests where permitted by law. You may opt out at any time |
| Comply with law, enforce agreements, and establish, exercise, or defend legal claims | Legal obligation and our legitimate interests |
Our legitimate interests include operating a reliable and secure subscription service, responding to users, detecting misuse, measuring performance, and protecting legal rights. We balance them against affected individuals' rights and expectations.
When calendar data concerns someone other than an Avum user, the applicable legal basis depends on our role rather than our contract with the Avum user. A business customer determines the basis where we are its processor. Where we are the controller, we rely on legitimate interests in providing the user-requested calendar function, subject to the balancing and rights described here.
Account, authentication, and subscription information is needed to enter into and provide the contract. Provider connections are optional, but connected-calendar features cannot work without the permissions they require.
Automated checks may determine eligibility for a trial or discount. They can deny or end that offer but do not prevent access to an otherwise available paid plan. Contact us to contest a result, express your view, or request human review.
5. Google and Microsoft account connections
Connecting a provider account is optional, but Avum cannot list, synchronize, or provide Unified Calendar features without the required permissions shown on the provider's consent screen. Sync Rules and the Unified Calendar use the same OAuth tokens and permissions.
Avum requests basic identity information, permission to read your calendar list, and permission to view and manage calendar events, solely to identify the account and provide the requested features.
Avum's use and transfer of information received from Google Accounts adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular, Google user data is used only to provide or improve prominent user-facing features, maintain security, comply with law, and provide support under the human-access rules in Section 7. We do not transfer Google user data for advertising, data-broker, lending, or surveillance purposes.
Microsoft
Avum requests basic profile information, offline access, permission to read and write calendars, and mailbox settings needed for Outlook event categories and colors. These are delegated permissions, so Avum can access only what the signed-in account may access. We do not request permission to read or send email. Microsoft's handling is described in its Privacy Statement.
Disconnecting and revoking access
You can disconnect an account in Avum and can separately revoke Avum's authorization in your Google or Microsoft settings. Disconnecting an account in Avum initiates removal of synced event copies created by Avum. Once that process is complete, Avum deletes the locally stored OAuth credentials from active systems. Neither action necessarily deletes event copies already written to a provider. Account and data deletion are described in Sections 9 and 15.
6. Your calendar privacy controls
Sensitive calendar information
Calendar information may incidentally reveal health information, religious or philosophical beliefs, political opinions, trade-union membership, sexual orientation, or other sensitive information. Avum does not prohibit an ordinary calendar event merely because it refers to such a matter. Avum processes event information automatically and transiently during ordinary operation, only to perform the calendar operations you configure. Human access is exceptional and governed by Section 7.
Avum does not use the sensitive nature of calendar information for advertising, profiling, eligibility decisions, data brokerage, or general-purpose AI training. Where availability-only information is sufficient, minimize the event details you copy.
You choose which accounts and calendars to connect, which calendars are sources and destinations, and which event details a Sync Rule copies or replaces. Available settings may let you limit what is copied. Choose settings appropriate for the people and confidential information in your calendars.
Review Unified Calendar operations before submitting them, and do not copy information to a calendar whose viewers should not receive it. If you use a work, school, shared, or delegated calendar, your organization's administrators and other authorized users may be able to access information written there.
7. Technical support and exceptional human access
A support request is not blanket permission for anyone at Avum to browse your calendars. It authorizes trained personnel to access information reasonably necessary for that request, limited where practicable by account, issue, and time.
Ordinary support work should not require a person to read event details. If reviewing event details is necessary, you must have supplied them, affirmatively authorized scoped access, or the access must be necessary for security, abuse prevention, or legal compliance.
Your support authorization is limited to resolving the identified problem and does not authorize unrelated use. Access is need-to-know and subject to confidentiality and security controls. If live inspection is insufficient, we may create a restricted capture used only for the ticket and deleted or de-identified after investigation, unless law requires retention.
You may withhold authorization, ask us to use redacted examples, limit its scope, or withdraw it before or during the investigation. This may limit support. Withdrawal does not affect prior lawful processing, and we may retain a minimal authorization audit record.
8. When we disclose personal data
We never disclose calendar content to a third party for that party's own purposes unless required by law. Exchanges with connected providers at your direction and processing by service providers on our behalf are limited to providing the Service and do not authorize those parties to use calendar content for their own purposes.
We disclose personal data only as reasonably necessary in the following circumstances:
- Connected providers. We exchange information with Google and Microsoft to authenticate connections and carry out the calendar operations you configure.
- Service providers. Vendors process data on our behalf for cloud hosting and storage, communications, monitoring, security, support, and related service operations. Our processors include Microsoft Azure, Cloudflare, Brevo (formerly Sendinblue), and Google Cloud EMEA Limited. Current provider roles and transfer information are available in our Subprocessors and Other Providers list.
- Payments. Paddle acts as the merchant of record and our payment and subscription provider. It processes and retains billing and transaction data under its own privacy notice and provides Avum with the limited subscription status needed to supply the Service.
- Your organization. If your account is organization-managed, authorized administrators may receive relevant account and usage information consistent with the applicable agreement.
- Legal and safety reasons. We may disclose data when we reasonably believe it is necessary to comply with law or legal process, protect rights or safety, investigate fraud or abuse, or secure the Service.
- At your direction. We disclose information when you instruct us to do so or otherwise give valid consent.
We do not sell or rent personal data. We never disclose calendar content for advertising, data brokerage, targeted advertising, or general-purpose AI or machine-learning training.
9. Retention and deletion
We keep personal data only as long as needed to provide and protect the Service, comply with law, or resolve claims. Event details are not retained during ordinary operation. Other data is retained as follows:
- account, connection, calendar metadata, configuration, and execution history: while the relevant account, connection, or rule is active, then until final account deletion.
- OAuth credentials: while connected and during removal of synced event copies after disconnection. Deleted from active systems when that process completes, with provider-side revocation available at any time.
- content-free Unified Calendar mutation ledger: up to 90 days, or earlier with the account.
- support records are retained while needed to provide support and document the resolution.
- diagnostic, security, and operational telemetry: a rolling maximum of 60 days, unless a specific record is isolated for a legal requirement, security investigation, or claim.
- Avum subscription status: while needed to administer the subscription and deletion. Paddle separately retains its billing and transaction records.
Operational telemetry is a time-ordered monitoring dataset rather than part of the account record and is not routinely rewritten entry by entry on account deletion. It is designed to exclude direct identifiers, credentials, and event details, but may contain linkable technical data. Linkable entries remain personal data. Where an entry can be located and law requires earlier action, we delete or restrict it. We do not collect new identifiers merely to locate otherwise unlinkable telemetry.
A deletion request immediately disables synchronization and starts a seven-day restoration period. During it, credentials may be used only for deletion and best-effort removal of Avum-created events. At the deadline, directly linked account and service data, including OAuth credentials, is deleted from live systems. Provider-held copies may remain, and existing telemetry expires under the 60-day rule.
After local deletion, Avum retains the deterministic trial-email digest and provider type while the one-trial rule remains in effect, subject to necessity reviews. Keyed digests of Paddle identifiers remain as long as needed to reject delayed messages. These contain no raw identifier or calendar data but remain pseudonymous. Raw Paddle identifiers may remain temporarily only for unresolved reconciliation.
Data deleted from live systems may remain temporarily in encrypted, access-restricted backups. Backups are isolated from ordinary use and overwritten on the documented cycle. Deletion is reapplied after disaster recovery. Genuinely anonymous aggregate statistics may be kept indefinitely, but pseudonymous information is not treated as anonymous.
10. Security
We use technical and organizational safeguards designed to protect personal data against unauthorized or unlawful access, alteration, disclosure, loss, or destruction, including encryption, access controls, monitoring, and recovery safeguards.
No internet service can guarantee absolute security. You should protect access to your email account, review connected-app permissions, select appropriate calendar privacy settings, and notify us promptly if you suspect unauthorized access.
11. International data transfers
We are established in Hungary and use service providers that may process data in the European Economic Area, the United Kingdom, the United States, and other countries. Where personal data is transferred from the EEA, United Kingdom, or Switzerland to a country not recognized as providing adequate protection, we use an approved safeguard, such as the European Commission's Standard Contractual Clauses or the relevant UK addendum. Contact us for information about a particular transfer.
12. Your privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to request access to, correction of, deletion of, or a portable copy of your personal data, restrict or object to certain processing, and withdraw consent without affecting prior lawful processing. Marketing emails include an opt-out.
You may object to our use of the pseudonymous trial-eligibility and deletion-integrity digests described in Sections 2 and 9 because that processing relies on legitimate interests. We will erase or stop using them where the right to erasure or objection applies, unless we demonstrate compelling legitimate grounds or must retain them to establish, exercise, or defend legal claims.
To exercise a right, email contact@avum.io. We may verify identity and authority. If your organization controls the data, we may refer the request to it or assist it. We respond within the period required by law.
EEA residents may lodge a complaint with the supervisory authority in their country of residence, place of work, or where they believe an infringement occurred. You may also contact the Hungarian National Authority for Data Protection and Freedom of Information (NAIH). UK residents may contact the Information Commissioner's Office. We encourage you to contact us first so we can try to resolve your concern.
13. Information about other people
Calendar events can contain personal data about other people. If you use Avum to process calendar data, you must have authority and a lawful basis, give any required notice, and appropriately protect sensitive information.
14. Cookies and age restriction
Cookies and similar technologies
Avum uses only cookies and similar technologies necessary to provide and secure the Service. These include first-party technologies that complete sign-in, protect requests, and maintain an encrypted authentication session until sign-out or for up to 30 days after issue or renewal, and Google reCAPTCHA's necessary_GRECAPTCHA cookie, set when you request a passwordless sign-in link to perform risk analysis. If we introduce non-essential technologies, we will provide any required choices and obtain consent where required.
Age restriction
The Service is intended only for adults aged 18 or older. We do not knowingly permit anyone under 18 to create or use an account. If you believe a person under 18 is using the Service, contact us so we can investigate and take appropriate action.
15. Changes and contact
We may update this Policy when relevant circumstances change. We will post the revised version with a new effective date and, where a change is material, provide additional notice through the Service or by email. If a new use of Google user data requires renewed consent under Google's policies, we will obtain that consent before using the data in the new way.
For privacy questions, rights requests, account-deletion requests, or complaints, contact:
Pentatope Technologies Kft. (operator of Avum)Email: contact@avum.io