Privacy Policy

Last updated: August 15, 2026

This policy explains what personal data we collect when you use this application, why we collect it, and what rights you have over it.

Who we are

AstoSeMas operates this application. It is an internal tool used by our own staff to plan work orders, schedule appointments, and record the outcome of the visits our technicians make to our customers. There is no public sign-up, and we are the controller of all the personal data described below.

Information we collect

  • Staff account data. For each member of staff, the name, email address, profile picture, role, and password hash or passkey credentials. Accounts are created by an administrator; nobody can register one. If a member of staff signs in with Google, we receive their name, email address, profile picture, and Google account identifier from Google.
  • Customer and job data. Information our staff enter while serving a customer, such as contact details and addresses, work orders, appointments, technician reports, comments, and the signature a customer gives at the end of a visit.
  • Google Calendar data. For a technician who connects their own Google account, the calendar identifier and the events we create for their appointments. We never ask customers to connect a calendar.
  • Technical data. Server and security logs, including your IP address, browser type, and the pages you request, plus diagnostic reports when the application encounters an error.

How we use your information

  • To provide, operate, and secure the application.
  • To authenticate you and keep your session signed in, including two-factor authentication and passkeys.
  • To schedule appointments and publish them to your Google Calendar when you have connected it.
  • To send service messages such as password resets, email verification, and appointment notifications.
  • To detect, investigate, and prevent abuse, fraud, and technical faults.
  • To comply with our legal obligations, including tax and accounting rules.

We do not sell your personal data, and we do not use it for advertising or to train generalized artificial intelligence or machine learning models.

Google user data and Google Calendar

Google is used only by our own staff, and connecting it is optional. Signing in with Google uses the basic profile and email scopes to identify a staff account. Calendar synchronisation uses the Google Calendar scope so that a technician can see their work schedule in their own calendar. Customers are never asked to connect a Google account.

  • We create a separate calendar in the connected Google account, dedicated to work appointments, and we create, update, and delete events in it that correspond to the appointments assigned to that technician.
  • Each event contains the appointment time, the customer name and address, the tasks to be performed, any notes, and a link to the report form for that visit.
  • We do not read, analyse, or store the other events in your Google Calendar.
  • We store the refresh token Google issues so that synchronisation continues without asking you to sign in again. It is encrypted at rest and never shared with third parties.
  • You can disconnect Google at any time from the integrations page in your settings, or by removing access from your Google account permissions page. Disconnecting deletes the stored token; events already written to your calendar remain yours to keep or delete.

Our use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Read the Google API Services User Data Policy.

Cookies

We use strictly necessary cookies, and we ask for your consent before setting anything else. They are all listed in our cookie policy, where you can change your choice at any time. Cookie Policy

Legal bases for processing

Where the General Data Protection Regulation applies, we rely on the performance of a contract to provide the application to you, on our legitimate interest in keeping the service secure and reliable, on your consent where you choose to connect an optional integration such as Google Calendar, and on compliance with legal obligations where the law requires us to keep records.

Who we share data with

We share personal data only with service providers that process it on our instructions, under contract, and only as far as needed to run the application.

  • Our hosting and database providers, which store the application data.
  • Google, for sign-in and for the calendar events you have asked us to create.
  • Our address lookup and mapping provider, which receives the address text you type in order to return suggestions and coordinates.
  • Our error monitoring and email delivery providers, which receive diagnostic data and the messages we send you.

We may also disclose data where we are legally required to do so, or to establish or defend legal claims.

International transfers

Some of our providers are located outside the European Economic Area. Where that is the case, transfers are covered by an adequacy decision or by the European Commission standard contractual clauses.

How long we keep data

We keep account and operational data for as long as the account is active and the business relationship lasts, and afterwards only as long as needed for legal, accounting, or dispute resolution purposes. Server logs and diagnostic reports are kept for a short period and then deleted. Google tokens are deleted as soon as you disconnect the integration.

Security

Traffic is encrypted in transit, passwords are stored as salted hashes, and sensitive credentials such as Google refresh tokens and two-factor secrets are encrypted at rest. Access to production data is limited to the people who need it, and the application supports two-factor authentication and passkeys.

Your rights

Subject to the conditions of the applicable law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, and you may object to processing based on our legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting past processing. You can also lodge a complaint with your national data protection authority.

This applies both to our staff and to the customers whose details our staff record in the application. Write to us at the address below and we will answer within the time limits set by the law.

Children's data

The application is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.

Changes to this policy

We may update this policy as the application changes. The date at the top always shows when the current version took effect, and we will tell you about material changes before they apply. Terms of Service

Contact us

For any question about this document, or to exercise your rights, contact AstoSeMas at info@astosemas.gr.