Skip to content
AVUM
HomeEducationContactOur TeamPricingFAQLaunching soon

Launching soon. We’re putting the finishing touches on Avum—explore what’s coming.

Contact us

Privacy Policy

Effective and last updated: July 23, 2026

The short version. Avum processes calendar information only to provide, secure, and support the calendar-sync service you request. We do not sell personal data, use calendar content for advertising, or use it to train general-purpose artificial intelligence or machine-learning models. Automated systems normally process calendar events without anyone at Avum reading them. Human review of event content is exceptional and subject to the support and security safeguards in Section 7.

1. Scope and who is responsible for your data

This Privacy Policy explains how Avum Calendar Sync ("Avum," "we," "us," or "our") collects, uses, stores, discloses, and protects personal data when you visit avum.io, create an Avum account, connect a Google or Microsoft account, configure calendar synchronization, or contact us (collectively, the "Service").

Avum is operated by Pentatope Technologies Kft., company registration number 07-09-032526, with its registered office at Ravasz Erzsébet utca 1., Dunaújváros, Hungary. Pentatope Technologies Kft. is the data controller for the account, billing, website, support, and service-operation data described in this Policy.

If an organization provides or manages your Avum account, that organization may be a separate controller of personal data associated with your use of the Service. Where Avum processes calendar data solely on a business customer's documented instructions, the customer is the controller and Avum acts as its processor under the applicable agreement. Contact your organization for details about its practices.

2. Personal data we collect

Account and authentication data

We collect information such as your name, email address, account identifier, account status, subscription tier, and authentication records. Avum uses passwordless sign-in links and does not ask for or store the password to your Google or Microsoft account.

Connected-account and authorization data

When you connect an account, we receive and store the provider account identifier and email address, OAuth access and refresh tokens, token expiry information, granted permissions, and connection status. These credentials let Avum act on your instructions without receiving your provider password.

Calendar metadata

We retrieve and store the calendars available through the connected account and information needed to display and use them, including calendar names and descriptions, provider identifiers, time zones, colors, primary-calendar status, and read/write access levels.

Calendar event data

To run your sync configurations, Avum reads, transforms, and writes calendar events. Depending on the event and the settings you select, the data processed can include event identifiers, title, description or body, location, start and end times, time zone, all-day status, recurrence, availability, visibility, confirmation status, color or category, reminders, and provider synchronization metadata. Event content may contain personal data about organizers, invitees, or other people even when Avum does not receive their details as separate contact records.

Avum may store event snapshots, changes, deletion markers, event identifiers, and provider delta tokens in its operational systems. This state is used to detect changes, prevent duplicate copies, recover from interrupted operations, and keep connected calendars consistent. It is not used to build an advertising profile or a separate permanent calendar product.

Configuration and service-operation data

We store your sync configurations, selected source and destination calendars, privacy and transformation settings, rule status, execution history, error classifications, watch-subscription status, and limited operational logs. These records may include internal identifiers and counts associated with a sync operation.

Billing and transaction data

Our payment provider processes payment-card and checkout information. Avum receives the customer, subscription, plan, transaction, price, status, tax, and billing metadata needed to provide and administer your subscription. Avum does not store complete payment-card details.

Support and communications data

If you contact us, we collect your message, contact details, attachments, ticket history, and information you choose to provide. With the scoped authorization described in Section 7, support data may also include diagnostic records or selected calendar data necessary to investigate the reported issue.

Website, device, and security data

Our systems and hosting providers may automatically process IP address, request time, browser and device type, operating system, referring page, requested URL, cookie or session identifiers, and security and error events. We use these data to deliver the website, maintain sessions, diagnose failures, prevent abuse, and protect the Service.

3. Where the data comes from

We obtain personal data:

  • directly from you when you register, configure the Service, purchase a plan, or contact us;
  • from Google or Microsoft when you authorize a connection and while Avum performs the operations you request;
  • from your organization if it creates, purchases, or administers your account;
  • from payment, email-delivery, hosting, security, and other service providers; and
  • automatically from your browser, device, and interactions with the Service.

4. Why we use personal data and our legal bases

Where the GDPR, UK GDPR, or similar law applies, Avum relies on the legal bases below. The particular basis depends on the context and the data involved.

PurposeTypical legal basis
Register users, authenticate accounts, list calendars, and run configured sync configurationsPerformance of our contract with you or steps requested before entering into it
Process subscriptions, administer billing, and keep required financial recordsContract and legal obligation
Provide support, diagnose errors, maintain reliability, and improve user-facing featuresContract and our legitimate interests; consent where specifically requested or required
Prevent fraud, investigate abuse or security incidents, and protect users and the ServiceOur legitimate interests and, where applicable, legal obligation
Send sign-in links, service notices, support replies, and subscription messagesContract and our legitimate interests in communicating about the Service
Send optional marketing communicationsConsent, or legitimate interests where permitted by law; you may opt out at any time
Comply with law, enforce agreements, and establish, exercise, or defend legal claimsLegal obligation and our legitimate interests

Our legitimate interests include operating a reliable and secure subscription service, responding to users, detecting misuse, understanding service performance, and protecting our legal rights. We balance those interests against the rights and reasonable expectations of affected individuals.

5. Google and Microsoft account connections

Connecting a provider account is optional, but Avum cannot list or synchronize that account's calendars without the required permissions. Provider consent screens describe the permissions requested before you grant them.

Google

Avum requests basic identity information, permission to read your calendar list, and permission to view and manage calendar events. We use Google data to identify the connected account, show available calendars, detect event changes, and create, update, or delete synchronized events according to your sync rules.

Avum's use and transfer of information received from Google Accounts adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular, Google user data is used only to provide or improve prominent user-facing features, maintain security, comply with law, and provide support under the human-access rules in Section 7. We do not transfer Google user data for advertising, data-broker, lending, or surveillance purposes.

Microsoft

Avum requests basic profile information, offline access, permission to read and write calendars, and mailbox settings needed to read and maintain Outlook category and color definitions associated with synchronized events. These are delegated permissions: Avum acts on behalf of the signed-in user and can access only data that account is permitted to access. We do not request permission to read or send email. Microsoft's own handling of information is described in its Privacy Statement.

Disconnecting and revoking access

You can disconnect an account in Avum and can separately revoke Avum's authorization in your Google or Microsoft account settings. Revocation prevents future provider access once it takes effect. Disconnecting does not necessarily delete event copies that were already written to another calendar; those items remain subject to your settings and the destination provider's retention practices. To request deletion of your Avum account or retained data, contact us as described in Section 15.

6. Your calendar privacy controls

You choose which accounts and calendars to connect, which calendars are sources and destinations, and which event fields a sync configuration copies or replaces. Depending on the settings available in your plan, you can limit a synchronized event to availability or selected details instead of copying its full contents. You are responsible for choosing settings appropriate for the people, organizations, and confidential information represented in your calendars.

Please do not instruct Avum to copy information to a calendar whose viewers should not receive it. If you use a work, school, shared, or delegated calendar, your organization's administrators and other authorized users may be able to access event data written there under that provider's policies and your organization's settings.

7. Technical support and exceptional human access

A support request is not blanket permission for anyone at Avum to browse your calendars. It authorizes trained personnel to access the account, configuration, connection status, execution history, error records, and other operational information reasonably necessary to investigate that specific request. We keep access limited to the affected account, issue, and time period wherever practicable.

Ordinary support work should not require a person to read event content. If reviewing event content is reasonably necessary, one of the following must apply:

  • you voluntarily include the specific event information in your support message;
  • we explain the requested scope and you affirmatively authorize us to view or capture the specific calendar data, affected sync run, event, calendar, or relevant time window; or
  • access is necessary to investigate a security incident, prevent abuse, or comply with applicable law.

Your support authorization is limited to diagnosing, reproducing, and resolving the identified problem. It does not authorize use of calendar content for unrelated product analysis, marketing, or AI training. Only personnel or contractors with a need to know may receive access, and they are subject to confidentiality, least-privilege, and security obligations. We may create a restricted diagnostic capture containing relevant source events, transformed output, or provider-facing event data when live inspection would be insufficient. Such a capture is used only for the ticket and retained only as long as reasonably necessary to investigate and verify the resolution, after which it is deleted or de-identified unless law requires otherwise.

You may withhold authorization, ask us to use redacted examples, limit its scope, or withdraw it before or during the investigation by replying to the support conversation. This may prevent us from reproducing or fully resolving the issue. Withdrawal does not affect processing already performed lawfully, and we may retain a minimal audit record showing that authorization was requested, granted, limited, or withdrawn.

8. When we disclose personal data

We disclose personal data only as reasonably necessary in the following circumstances:

  • Connected providers. We exchange information with Google and Microsoft to authenticate connections and carry out the calendar operations you configure.
  • Service providers. Vendors process data on our behalf for cloud hosting and storage, content delivery, monitoring and security, transactional email, customer support, and related technical operations. Our providers include Microsoft Azure, Cloudflare, and Brevo (formerly Sendinblue).
  • Payments. Paddle acts as our payment and subscription provider and may act as merchant of record. It processes checkout, billing, tax, fraud-prevention, and refund data under its own privacy notice.
  • Your organization. If your account is organization-managed, authorized administrators may receive account, subscription, configuration, and usage information consistent with the applicable agreement.
  • Legal and safety reasons. We may disclose data when we reasonably believe it is necessary to comply with law or legal process, protect rights or safety, investigate fraud or abuse, or secure the Service.
  • Corporate transactions.Data may be disclosed under appropriate confidentiality protections in connection with a financing, merger, acquisition, restructuring, or sale of assets. Where Google user data is involved, we will obtain prior consent when Google's Limited Use requirements demand it.
  • At your direction. We disclose information when you instruct us to do so or otherwise give valid consent.

We do not sell or rent personal data. We do not share calendar content with advertising networks or data brokers, use it for targeted advertising, or use it to train general-purpose AI or machine-learning models.

9. Retention and deletion

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Service, maintain synchronization state, comply with legal obligations, resolve disputes, enforce agreements, and protect the Service. The retention period depends on the type of data:

  • account, connected-account, calendar metadata, configuration, and operational sync data are generally kept while the relevant account, connection, or sync configuration remains active;
  • OAuth credentials are used only while a connection remains authorized; after disconnection, account deletion, provider revocation, or invalidation, we stop using them and remove them from active systems in accordance with our deletion process;
  • event snapshots and deltas are retained for the operational history reasonably needed to maintain and recover synchronization, and are deleted or de-identified when no longer needed for that purpose;
  • support records are retained while needed to provide support and document the resolution;
  • security and technical logs are retained for a limited period appropriate to troubleshooting, fraud prevention, audit, and security purposes; and
  • billing, tax, transaction, and legal records are retained for the period required by applicable law or needed to establish, exercise, or defend legal claims.

Deletion from live systems may not immediately remove data from encrypted, access-restricted backups. Backed-up data is isolated from ordinary use and deleted or overwritten on the applicable backup cycle, unless it must be restored for disaster recovery. We may retain aggregated or irreversibly de-identified information that no longer identifies an individual.

A self-service deletion request immediately disables synchronization and restricts ordinary account use, followed by a seven-day grace period. During that period we retain only the configuration and provider credentials needed for best-effort removal of Avum-created events and cancellation. At the deadline we destroy provider credentials and delete Avum application data even if inaccessible provider-side copies cannot be removed. Paddle may separately retain merchant, invoice, tax, payment, and transaction records for its legal responsibilities.

After local deletion, Avum retains only keyed HMAC digests of historical Paddle customer and subscription identifiers to prevent late webhooks from recreating the deleted account, plus a keyed digest used to enforce one-trial eligibility. These tombstones do not retain the raw identifiers or calendar data. A minimized deletion record may temporarily retain raw Paddle identifiers only while a past-due cancellation or qualifying recurring-renewal refund still requires reconciliation.

10. Security

We use technical and organizational safeguards designed to protect personal data against unauthorized or unlawful access, alteration, disclosure, loss, or destruction. Measures include encrypted transport, at-rest protections provided by our infrastructure, access controls, separation of production systems, confidentiality obligations, secret management, monitoring, backups, and least-privilege access practices.

No internet service can guarantee absolute security. You should protect access to your email account, review connected-app permissions, select appropriate calendar privacy settings, and notify us promptly if you suspect unauthorized access.

11. International data transfers

Avum is established in Hungary and uses service providers that may process data in the European Economic Area, the United Kingdom, the United States, and other countries. Where personal data is transferred from the EEA, United Kingdom, or Switzerland to a country not recognized as providing adequate protection, we use an approved transfer mechanism where required, such as the European Commission's Standard Contractual Clauses, the relevant UK addendum, or another lawful safeguard. You may contact us for information about the safeguards applicable to a particular transfer.

12. Your privacy rights

Depending on where you live and subject to legal exceptions, you may have the right to request access to, correction of, deletion of, or a portable copy of your personal data; restrict or object to certain processing; and withdraw consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal. You may also opt out of marketing emails using the unsubscribe link in the message.

To exercise a right, email contact@avum.io. We may need to verify your identity and authority before fulfilling a request. If data is controlled by the organization that provides your account, we may direct your request to that organization or assist it in responding. We will respond within the period required by applicable law.

EEA residents may lodge a complaint with the supervisory authority in their country of residence, place of work, or where they believe an infringement occurred. You may also contact the Hungarian National Authority for Data Protection and Freedom of Information (NAIH). UK residents may contact the Information Commissioner's Office. We encourage you to contact us first so we can try to resolve your concern.

13. Information about other people

Calendar events can contain personal data about other people. If you connect or synchronize a calendar, you must have the authority and a lawful basis to permit the processing and disclosure directed by your sync settings. Where appropriate, you are responsible for giving those individuals any required notice. Avoid placing highly sensitive information in event fields or copying it to other calendars unless doing so is necessary, authorized, and protected by suitable privacy settings.

14. Cookies and children

Cookies and similar technologies

Avum uses cookies and similar technologies that are necessary to authenticate users, maintain sessions, protect forms, remember security or service preferences, and operate the website. If we introduce non-essential analytics or advertising technologies, we will provide the choices and obtain the consent required by applicable law.

Children

The Service is intended for adults and is not directed to children under 16. We do not knowingly collect personal data from a child under 16. If you believe a child has provided personal data to us without valid authorization, contact us so we can investigate and take appropriate action.

15. Changes and contact

We may update this Policy to reflect changes to the Service, our practices, providers, or applicable law. We will post the revised version with a new effective date and, where a change is material, provide additional notice through the Service or by email. If a new use of Google user data requires renewed consent under Google's policies, we will obtain that consent before using the data in the new way.

For privacy questions, rights requests, account-deletion requests, or complaints, contact:

Pentatope Technologies Kft. (Avum)
Ravasz Erzsébet utca 1.
Dunaújváros, Hungary
Email: contact@avum.io
HomeEducation OfferTerms & ConditionsPrivacy PolicyContact UsSupport