Privacy Policy

Your Data,
Your Control

Enterprise-grade security meets transparent data practices. Built by NextGenCode, designed for your privacy.

Last Updated: November 17, 2025

πŸ‡ͺπŸ‡Ί
GDPR Compliant
πŸ‡ΊπŸ‡Έ
CCPA Compliant
πŸ›‘οΈ
SOC 2 Type II
βœ…
OWASP Verified

Information We Collect

Account Information

When you create a NEXTGEN SCHEDULER account, we collect your name, email address, timezone, and work preferences to provide personalized scheduling services.

Calendar Data

With your explicit consent, we access your Google Calendar data to sync availability, detect conflicts, and optimize scheduling. This data is encrypted and processed securely.

Usage Analytics

We collect anonymized analytics data to improve our AI models and user experience. This includes scheduling patterns, feature usage, and performance metrics.

Payment Information

Payment data is processed securely through Stripe and PayPal. We never store complete credit card numbers on our servers.

How We Use Your Information

Service Delivery

Your data powers our Smart Calendar AI, no-show prediction models, and reactive availability features to provide intelligent scheduling.

AI Improvements

Anonymized data trains our machine learning models to enhance prediction accuracy and optimize scheduling algorithms.

Communication

We send essential service notifications, booking confirmations, and optional product updates (you can opt out anytime).

Security & Compliance

We monitor for suspicious activity, prevent fraud, and ensure GDPR, CCPA, and OWASP Top 10 compliance.

Data Protection & Security

Enterprise-Grade Encryption

All data in transit uses TLS 1.3 encryption. Data at rest is encrypted with AES-256. Calendar tokens are stored using secure encryption methods.

Access Controls

Role-based access control (RBAC) ensures only authorized personnel can access sensitive data. All access is logged and monitored.

Regular Security Audits

Our infrastructure undergoes quarterly penetration testing and security audits following OWASP Top 10 standards.

Data Isolation

Each user's data is logically isolated. Multi-tenant architecture ensures no cross-user data leakage.

Data Storage & Retention

Storage Location

Data is stored in secure, SOC 2 Type II certified data centers in the EU and US, depending on your region.

Retention Period

Active account data is retained for the duration of your subscription. After account deletion, data is permanently removed within 30 days.

Backup Policy

Encrypted backups are maintained for 90 days for disaster recovery purposes only.

Right to Deletion

You can request complete data deletion at any time from your account settings or by contacting support.

Your Rights & Control

Access Your Data

Download a complete copy of your data in JSON format from account settings at any time.

Data Portability

Export your scheduling data, preferences, and settings to use with other services.

Opt-Out Options

Disable analytics tracking, marketing emails, and AI features individually from settings.

Account Deletion

Delete your account and all associated data permanently with one click. No questions asked.

Third-Party Services

Google Calendar API

We use Google Calendar API to sync your availability. Review Google's privacy policy for details on their data handling.

Payment Processors

Stripe and PayPal process payments according to their respective privacy policies. We receive only transaction confirmations.

Analytics Services

We use privacy-focused analytics (Vercel Analytics) that don't use cookies or track personal information.

AI Services

OpenAI GPT-4 processes meeting summaries. Data is sent encrypted and not used for model training.

Questions About Privacy?

Our security team is here to help. Contact us for any privacy-related inquiries.

Related: Terms of Service β€’ Security β€’ NextGenCode