Privacy Policy

Last updated: 5 July 2026

This page is an English translation provided for convenience. In case of any discrepancy, the French version is the sole legally binding text. Read the French version

This policy describes how Daytio processes the personal data of registered professionals and of end clients who book an appointment. It is drafted in accordance with Regulation (EU) 2016/679 (the “GDPR”) and the French Data Protection Act.

1. Who processes your data?

The Daytio platform is published by Thomas Bonder, sole trader (EI, registered trading name: BATIbreizh), registered under SIREN number 106 652 977 (SIRET 106 652 977 00013), whose registered office is located at 5 rue Béatrix Beck, 29000 Quimper, France.

Two distinct roles coexist:

  • For professional accounts (the self-employed people who use Daytio): Daytio’s publisher is the data controller.
  • For end clients’ data (the people who book with a professional): each professional is the data controller of their client database, and Daytio acts as processor on their behalf (see the Data Processing Agreement).

Contact for any question relating to data: daytio.contact@gmail.com.

2. What data is collected, and why?

2.1 End clients (online booking)

  • Identity and contact details: first name, last name, phone number, email address — necessary to create and manage the appointment (confirmation, cancellation, rescheduling). Legal basis: performance of the contract (the booking).
  • Postal address (street, postcode, city, access details) — collected only for an at-home appointment, so that the professional can travel there. Legal basis: performance of the contract.
  • First names of members of a group (optional) — to identify each person’s service when booking for several people. Legal basis: performance of the contract.
  • Appointment history (dates, services, status) — management of the client relationship by the professional and statistics about their business. Legal basis: professional’s legitimate interest.
  • Consent to receive follow-up emails (and its date) — allowing the professional to invite you to book again. This consent is optional: the checkbox is never pre-ticked and declining it does not prevent you from booking. Each email contains a one-click unsubscribe link, and unsubscribing does not stop confirmations of your appointments. Legal basis: consent (art. 6.1.a GDPR), withdrawable at any time.

2.1 bis Frequency of follow-up emails

If you have given this consent, the professional may send you a message inviting you to book again. These sends are strictly regulated:

  • A threshold set by the professional (expressed in weeks since your last appointment) triggers the follow-up. You are only concerned beyond this period.
  • At most one follow-up per cycle. After a send, you are not contacted again until a full new cycle has elapsed. No repeated sends in quick succession are possible.
  • No follow-up if an appointment is already scheduled. Booking again automatically removes you from the list, and the period restarts from your most recent visit.
  • A single check per day on the server side, and a cap on sends per professional: these messages cannot be sent en masse.
  • Only the professional you consulted. Your consent applies to them alone. Daytio never uses it for its own purposes, never shares it with any other professional, and never resells any data.

Unsubscribing is immediate and unconditional, via the link in every email or your inbox’s button. It does not delete your record and does not affect your appointments or their confirmations.

Minimisation: no other data is requested from the end client. No account creation, no password, no payment data (payment takes place on site).

2.2 Professionals (Daytio accounts)

  • Identity, email, password (hashed — never stored in plain text), trading name, contact details, SIRET number, trade, opening hours, services, photos — to provide the Daytio service. The SIRET number is mandatory: Daytio is reserved for registered professionals (see article 4 of the Terms of Use). It is public data, viewable in the business directory. Legal basis: performance of the contract (Terms of Use/Terms of Sale).
  • Access tokens for connected calendars (Google Calendar) — synchronisation requested by the professional. Legal basis: consent (revocable by disconnecting the calendar).
  • Technical and audit logs — security and traceability. Legal basis: legitimate interest (security).

3. Who has access to the data?

  • An end client’s data is only visible to the professional they booked with. Professional accounts are strictly isolated from one another (multi-tenant isolation enforced at the database level).
  • The public booking page never exposes your name, your contact details, or your address, under any circumstance.
  • Booked slots and city. A professional working at clients’ homes can enable the display of their already-booked slots together with the city concerned (“Booked — Quimper”), so that another client in the same area can choose a nearby time and reduce travel. In this case, and only in this case, the city of an appointment is visible publicly — never associated with a name, a street or a number, and never for an appointment at the professional’s own home. This option is disabled by default and is each professional’s choice; you are informed of it when you enter your address. If you would rather not, tell the professional: they can disable it. Legal basis: professional’s legitimate interest (organising their rounds), with prior information given to the client.
  • The address of an at-home appointment only appears in the professional’s own space, in confirmation emails, and in the “location” field of their synced calendar.

4. Sub-processors and recipients

Daytio relies on the following providers:

  • Supabase (database, authentication, file storage) — data hosted in the European Union (AWS eu-west-1 region, Ireland).
  • Vercel (Vercel Inc., United States — web application hosting). Personal data is stored with Supabase within the European Union; any transfers outside the EU related to application hosting are governed by the European Commission’s standard contractual clauses.
  • Resend (Resend, Inc., United States — sending of transactional emails: confirmations, cancellations, alerts). The data transmitted (recipient’s name and email address, message content) is limited to what is strictly necessary; transfers outside the EU are governed by standard contractual clauses.
  • Google (Google Calendar) — only if the professional connects their calendar; appointment titles and times are then sent to Google for synchronisation.

No data is sold or transmitted to third parties for advertising purposes.

4.1 Data from Google accounts (Google API)

When a professional connects their Google account to synchronise their calendar, Daytio requests the following scopes:

  • openid and .../auth/userinfo.email: used only to identify the connected Google account and to show the professional “Connected as firstname@gmail.com” in their settings. This data is shared with no one and used for no other purpose.
  • .../auth/calendar.events (Google Calendar): used exclusively to synchronise appointments between Daytio and Google Calendar — creating, updating and deleting events corresponding to Daytio appointments, and reading existing events to avoid double bookings.

Storage: the Google account’s email address and the OAuth access/refresh tokens are stored encrypted in our database (Supabase, European Union). Calendar events are not duplicated in our database: they stay in Google Calendar and are read/written on demand via the API.

Sharing: this data is never sold, never shared with third parties, never used for advertising or profiling purposes, and never used to train general-purpose artificial intelligence or machine-learning models. It is only viewed by a human (Daytio support) in the event of a technical incident, at the professional’s request, or where required by law.

Retention and deletion: access tokens are retained for as long as the Google calendar remains connected. The professional can revoke this access at any time from their Daytio account settings or from myaccount.google.com/permissions; the tokens are then immediately deleted.

Daytio’s use of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

5. How long is data retained?

  • End clients: inactive client records are automatically anonymised 36 months after the last appointment (name, first name, email, phone, address and notes erased; only anonymous statistics remain).
  • Professionals: data retained for the duration of the contract, then deleted or anonymised within 12 months of account closure, except for legal obligations (invoicing: 10 years).
  • Audit logs: rolling 12 months.

6. Your rights

In accordance with articles 15 to 22 of the GDPR, you have the following rights: access, rectification, erasure, restriction, objection and portability of your data.

  • You are a professional’s client: contact them directly first (data controller of their client database) — their contact details are in your confirmation email. The professional can delete your record from their space in one click. You can also write to daytio.contact@gmail.com: we will forward your request to the professional concerned.
  • You are a registered professional: write to daytio.contact@gmail.com.

We respond within one month. You can also refer the matter to the CNIL (the French data protection authority, cnil.fr) if you believe your rights are not being respected.

7. Security

  • Encryption of communications (HTTPS/TLS) across the whole site;
  • Passwords hashed with a robust algorithm (bcrypt) — never stored or transmitted in plain text;
  • Strict isolation of data between professional accounts, enforced by database-level security rules (Row Level Security);
  • No personal data in URLs; data access via least-privilege keys.

8. Cookies

Daytio only uses strictly technical cookies (professionals’ login session). No advertising or audience-measurement cookie is set — which is why no consent banner is shown. Details: cookie policy.

9. Changes to this policy

Any substantial change will be flagged on this page (update date at the top) and, for professionals, by email.