Version: 2026-08-01
Effective date: 1 August 2026
This Notice explains how CABALLUS LIMITED, an Irish company with company number 790078 and registered office at 2 Bridge Street, Athlone, Co. Westmeath, Ireland (Caballus, we, us), handles personal data in connection with Clearslot.
Contact: clearslot-support@caballus.ie
1. When Caballus is controller or processor
Caballus is a controller for personal data used to operate accounts, administer subscriptions, secure and improve Clearslot, communicate with users, provide support, comply with law, and manage our business.
When a Clearslot business customer (Organiser) uses the Service to collect or manage information about its clients, prospects, staff, invitees or people who book (Bookers), the Organiser normally decides why and how that information is used. The Organiser is the controller and Caballus acts as its processor under the Clearslot Data Processing Addendum.
Bookers should first direct privacy questions about a booking, form or Organiser message to the relevant Organiser. We will assist the Organiser with requests as required by data-protection law.
Some providers, especially payment and customer-authorised integration providers, also process data as separate or joint controllers under their own privacy notices.
2. Personal data we handle
Depending on how you use Clearslot, we handle:
- Account and organisation data: name, email address, telephone number, profile image, organisation, role, language, time zone, account settings and identifiers.
- Booking and contact data: Booker name and contact details, company, time zone, requested service, appointment time, attendees, status, notes, cancellation reason, custom-form answers and related communications.
- Availability and integration data: availability rules, calendar identifiers and metadata, event details, conferencing links, connected-account identifiers, permissions and tokens needed to operate an integration.
- Subscription and transaction data: plan, billing address and tax information, Stripe customer/account identifiers, payment amount, currency, status, refunds and chargeback metadata. Caballus does not receive full payment-card numbers from Stripe.
- Content: booking-page text, images, branding, forms, routing rules, uploaded materials and messages supplied through the Service.
- Support and business communications: messages, attachments, feedback and records of how a request was handled.
- Technical and security data: IP address, device and browser information, timestamps, session identifiers, authentication and security events, request logs, error information and anti-abuse signals.
- Usage data: actions taken in the product and feature/configuration state needed to operate, troubleshoot and improve it. At launch we do not use third-party behavioural advertising or non-essential analytics cookies.
Clearslot is not designed for payment-card numbers in form fields, passwords, authentication secrets, government identity numbers, special-category data, special care-required personal information or criminal-offence data. Organisers must not request or submit that information at launch. US Organisers must not use Clearslot for healthcare or to collect, infer or process consumer health data.
3. Where data comes from
We receive data:
- directly from account users, Bookers and people who contact us;
- from the Organiser that configures a booking page or adds team members, contacts or bookings;
- from a connected service when a user enables an integration, such as Stripe, Google Calendar or Zoom;
- automatically from devices, browsers and our security and application systems; and
- from public sources, reporters, service providers or authorities where needed to prevent abuse, investigate a report or comply with law.
4. Why we use data and our legal bases
When Caballus is controller, we use personal data as follows:
| Purpose | Typical legal basis under GDPR |
|---|---|
| Create accounts, provide requested features, administer subscriptions and give support | Performance of a contract or steps requested before a contract |
| Operate booking flows for an Organiser | The Organiser's documented instructions under the DPA; the Organiser selects its own lawful basis |
| Authenticate users, prevent abuse, secure systems, diagnose faults and maintain service reliability | Legitimate interests in providing a safe and reliable business service; legal obligations where applicable |
| Process Caballus subscription billing and keep financial records | Contract and legal obligations |
| Send transactional account, booking and security messages | Contract; legitimate interests; or the Organiser's instructions, depending on the message |
| Improve product usability and performance using operational usage information | Legitimate interests, balanced against users' rights |
| Enforce terms, moderate content, handle disputes and establish or defend legal claims | Legitimate interests and legal obligations |
| Comply with lawful requests, sanctions, tax, accounting and regulatory requirements | Legal obligations and substantial public interests where applicable |
| Send optional marketing | Consent where required; otherwise legitimate interests where law permits, with an opt-out |
Where we rely on legitimate interests, we consider the necessity and impact of the processing and do not use that basis where a person's rights override our interests. You may ask for more information about a balancing assessment relevant to you.
If we ask for consent, you may withdraw it at any time. Withdrawal does not affect earlier lawful processing.
5. Who receives personal data
We disclose only what is reasonably necessary to the following recipients:
| Recipient | Use |
|---|---|
| Hetzner Online GmbH | European compute, networking and PostgreSQL hosting |
| Cloudflare, Inc. and affiliates | DNS, CDN, web security, traffic delivery, Pages/edge functions, R2 object storage, Email Routing and Turnstile anti-abuse checks |
| Scaleway S.A.S. | Client-side encrypted database backup storage in France |
| Plus Five Five, Inc. (Resend) | Transactional email delivery and processing |
| Google Cloud EMEA Limited and relevant Google affiliates | Google Workspace hosting for the Caballus support mailbox and support correspondence |
| Stripe entities | Caballus subscription billing and, where enabled by an Organiser, booking payments, refunds, fraud prevention and legally required payment compliance |
| Google and Zoom entities | Optional calendar, meeting and video-conferencing integrations enabled by a user |
Stripe may act as processor, independent controller or joint controller depending on the payment activity. For an Organiser's connected payment account, Stripe also contracts directly with the Organiser. Google and Zoom process data under their own terms when a user enables their integrations.
We may also disclose data to professional advisers and auditors under confidentiality; to a buyer, investor or successor in a genuine corporate transaction; to competent authorities where law requires it; and to another person where necessary to protect rights, safety or the Service.
We do not sell personal data. We do not share it for cross-context behavioural advertising.
The current list of processors used for Customer Personal Data is in the subprocessor schedule to our DPA.
6. International transfers
Our primary application database and compute are hosted in the European Economic Area, and encrypted backups are stored in France. Some providers, including Cloudflare, Resend, Stripe, Google and Zoom, may process data in the United States or other countries.
Where GDPR restricts a transfer outside the EEA, we use an available legal mechanism appropriate to the provider and transfer, such as an adequacy decision, the EU-US Data Privacy Framework for a participating US recipient, or the European Commission's Standard Contractual Clauses, together with supplementary measures where required. Provider-specific transfer details are available on request or in the relevant provider's data-processing terms.
7. How long we keep data
We keep personal data only for as long as needed for the purpose collected, including providing the Service, following the Organiser's instructions, maintaining security, complying with law, resolving disputes and enforcing agreements.
The launch retention schedule is:
| Data | Retention approach |
|---|---|
| Active account, organisation, booking, contact and configuration data | While the account is active or until the Organiser deletes it, subject to legal holds and product dependencies |
| Deleted individual account profile | Direct identifiers are scrubbed and active sessions/profile access are removed; limited pseudonymous identifiers and historical records may remain where needed for integrity, security, bookings or legal obligations |
| Authentication and security audit events | Up to 365 days, unless a legal hold or active investigation requires longer |
| Stripe webhook processing records | Normally 30 days after processing; underlying billing and payment records follow the separate rules below |
| Encrypted database backups | Daily generations up to 30 days, weekly generations up to 84 days and monthly generations up to 365 days; deleted live data ages out as those backups expire |
| Caballus contracts, invoices, tax and accounting records | For the period required by applicable company, tax and accounting law |
| Booking-payment records and disputes | For as long as needed for settlement, refunds, chargebacks, fraud prevention and payment/legal obligations; Stripe retains its own records under its notice |
| Support correspondence | 24 months after the request is closed, or longer where needed for an unresolved dispute, security issue or legal obligation |
| Closed-account Customer Personal Data not covered above | Deletion or irreversible anonymisation from active systems within 90 days after closure, with residual copies expiring through the backup schedule |
An Organiser may set shorter or longer retention for its own booking records where the Service permits. Caballus may retain a minimal suppression record after deletion to honour an opt-out or prevent re-creation of an abusive account.
We may preserve relevant data during a legal hold, dispute or investigation. When the hold ends, the ordinary schedule resumes.
8. Account closure is not instantaneous erasure of every record
Closing an account revokes access and begins the applicable deletion or de-identification process. It does not necessarily erase every record immediately. For example, we may retain invoice and transaction records required by law; security evidence; records needed to protect Bookers or resolve disputes; historical booking references that must remain consistent; and encrypted backup copies until automatic expiry.
Where Caballus acts as processor, the Organiser controls deletion instructions subject to the DPA. A Booker requesting deletion should contact the Organiser first.
9. Your data-protection rights
Subject to the conditions and exceptions in applicable law, you may have rights to:
- access your personal data and receive information about its use;
- correct inaccurate data;
- erase data;
- restrict processing;
- object to processing based on legitimate interests or to direct marketing;
- receive data in a portable format; and
- withdraw consent.
To exercise a right concerning a Clearslot account or Caballus's own processing, contact clearslot-support@caballus.ie. To exercise a right concerning an Organiser's booking page or records, contact that Organiser. We may need information to verify identity and authority. Authorised agents must show their authority.
You may complain to the data-protection supervisory authority where you live, work or believe an infringement occurred. You may also bring a court claim. We would appreciate the opportunity to address the concern first.
10. Cookies and device storage
Clearslot uses cookies or similar device storage that are necessary to:
- maintain sign-in sessions and remember security state;
- protect forms and requests against forgery, bots and abuse;
- retain language or essential interface preferences; and
- route and secure traffic through Cloudflare.
These technologies are used because they are necessary to provide or secure the service you request, rather than for advertising. Blocking them may prevent sign-in, booking or other core functions.
At launch we do not set non-essential analytics or advertising cookies. If that changes, we will update this Notice and request consent where applicable before setting them.
11. Security
We use technical and organisational measures intended to protect personal data in proportion to the risk. They include TLS in transit, restricted administrative access, authentication and session controls, network and application security controls, logging and monitoring, vulnerability and patch management, encrypted off-site backups, secrets management, and documented incident and restoration procedures.
No internet service is completely secure. Customers must protect credentials, configure user access appropriately and notify us promptly at clearslot-support@caballus.ie about suspected compromise.
12. Children
People under 18 may not hold a Clearslot account. The Service is not directed to children.
An Organiser that permits appointments for or concerning children is responsible for an appropriate legal basis, age-appropriate transparency, guardian authority where required, data minimisation and all other safeguards. Organisers must not use general-purpose fields to collect sensitive information about children without Caballus's written approval.
13. Automated decisions
We may use technical signals to detect spam, fraud, account takeover and prohibited use and to prioritise review. We do not currently use solely automated decisions that produce legal or similarly significant effects on individuals. A human may review and act on relevant signals. If this changes, we will provide the information and rights required by law.
14. European Union information
Caballus is established in Ireland. For processing where Caballus is controller, the purposes, legal bases, recipients, retention and rights information required by Articles 13 and 14 GDPR are set out above. You may complain to the Irish Data Protection Commission or the supervisory authority where you live, work or believe an infringement occurred.
Where an Organiser controls Booker data, the Organiser must provide its own complete privacy information. The layered notice on a booking page identifies that Organiser and links to its notice. Caballus does not use consent as the legal basis merely because a user acknowledges this Notice.
15. Japan information
The Act on the Protection of Personal Information (APPI) may apply when we provide Clearslot to people in Japan. Caballus's identity, contact details, purposes of use, data categories, recipients, safeguards and retention are described above.
Personal data relating to Japan is primarily hosted in the EEA. Cloudflare, Resend, Stripe, Google and Zoom may process relevant data in other countries as described in sections 5 and 6. We obtain contractual protections and information about provider security and foreign data-protection systems where required. The EU and Japan recognise each other's data-protection frameworks for relevant transfers, subject to the applicable supplementary rules.
Subject to APPI, a person may request notification of purpose, disclosure, correction, addition, deletion, suspension of use, erasure or suspension of third-party provision of retained personal data. Contact clearslot-support@caballus.ie. We may verify identity and may refuse or limit a request where APPI permits. If a reportable leak or similar incident affects people in Japan, we will make the required report and individual notification.
An Organiser in Japan is independently responsible for its APPI notice and, for paid consumer services, the seller disclosures and final-order information required by Japanese consumer law.
16. United States information
We do not sell personal data, share it for cross-context behavioural advertising, use it for targeted advertising or offer financial incentives for personal data. At our current scale and data practices, we do not provide a separate state-law opt-out portal. If a law that applies to a particular person requires a request right, that person may contact clearslot-support@caballus.ie and we will respond as required.
US Organisers may not use Clearslot for healthcare or to collect, infer or process consumer health data. Clearslot is not directed to children under 13, and a child under 13 must not submit a booking form. An authorised adult may submit a booking concerning a child where lawful and without prohibited sensitive information.
We use safeguards appropriate to the nature of the information we process and maintain an incident process that accounts for applicable US breach-notification duties.
17. Changes and contact
We may update this Notice to reflect changes in law, providers or the Service. We will post the current version and give additional notice of material changes where appropriate.
Privacy questions and rights requests: clearslot-support@caballus.ie
Support: clearslot-support@caballus.ie
Postal address: CABALLUS LIMITED, 2 Bridge Street, Athlone, Co. Westmeath, Ireland