Skip to main content

Privacy Policy

Because we value your trust, protecting your data and respecting your right to privacy and informational independence in the collection, processing, and use of your personal data is of utmost importance to us. The following information is intended to provide you with a quick and easy overview of the data we collect and process about you in connection with your use of our website and services.

The company responsible for data protection on this website is Webink, Simon Pihler s.p. For any questions regarding privacy, you can contact us at the email address [email protected].

1. Subject Matter

The subject of this privacy statement is information explaining which personal data is collected on the etisia.com websites and within the Etisia application, and for what purpose it is processed. If we have links to other sites, we have neither influence nor control over the linked content or relevant data protection regulations. We recommend that you check the privacy policies on the linked websites to determine whether and to what extent personal data is collected, processed, used, and made accessible to third parties.

2. Definitions and Terms

Below is a selection of some legal definitions that will help you understand the privacy statement. The full text of the General Data Protection Regulation (GDPR) along with further definitions and terms can be found here.

Personal Data

All information relating to an identified or identifiable natural person ("data subject"). A natural person is considered identifiable if they can be directly or indirectly identified, particularly by reference to an identifier such as a name, identification number, location data, online identifier, or by reference to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.

Processing

Any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, combination, restriction, erasure, or destruction.

Controller

Refers to a natural or legal person, public authority, agency, or other body which alone or jointly with others determines the purposes and means of the processing of personal data. If the purposes and means of processing are prescribed in accordance with EU law or the law of Member States, the controller or certain criteria for its nomination may be provided for in accordance with EU law or the law of Member States.

Recipient

Refers to a natural or legal person, public authority, agency, or another body to which personal data can be disclosed, whether a third party or not. Authorities may obtain personal data in the context of a particular investigation in accordance with EU law or the law of Member States but are not considered recipients. The processing of these data by the designated authorities is carried out in accordance with the applicable data protection regulations and in accordance with the purposes of the processing.

Third Party

This is a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

3. Categories of Personal Data on the etisia.com Websites

Relevant Area: Visiting the Website

When you access the etisia.com website, so-called access data is collected, including the IP address, and stored in a log file. The log file also stores the name of the website you requested, the retrieved file, date and time of access, amount of data transferred, notification of successful retrieval, browser type and version, operating system, the so-called referrer URL (previously visited page), as well as the provider making the request. However, based on this data, you cannot be identified.

When you visit our website, cookies are also stored on your end device (laptop, tablet, smartphone, or personal computer).

To provide users with a seamless connection and comfortable use of our website, we collect log file data, including the IP address. The log file is used for analysis to evaluate system security and stability, as well as for administrative purposes. Cookies also help us make our services and website more user-friendly by helping us determine whether you have, for example, already visited a page on our website. Using the cookie identifier, we also receive information about user behavior on our website and search queries that lead you to our site, so we can tailor our offerings to users' interests for future visits.

Log files, including the IP address, serve only to optimize the technology and configuration of our website and the security of our systems (e.g., in the context of a system intrusion or security incident). When accessing our website, it is not possible to obtain any personal data from the log files, including the IP address. Personal reference only occurs when you log into your customer user account at the same time. In this case, we can link your IP address directly to you.

Data retention period: Log files, including IP addresses, are automatically deleted two (2) months after collection. Before that, the IP address is anonymized and stored only for administrative (technical) purposes.

Hosting: Our website is hosted by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare provides content delivery, DNS, and edge computing services. More information at: https://www.cloudflare.com/privacypolicy/.

Legal basis: Article 6(1)(f) of the General Data Protection Regulation.

Planned or required provision of data: The provision of the aforementioned personal data is neither legally nor contractually required. However, without the IP address or cookie identifier, the service and functionality of our website are not guaranteed, and individual applications and services may not be available or may be limited.

Relevant Area: Cookie Consent Management (Cookie Policy)

Personal Data: Cookie consent preferences stored in first-party cookies (analytics_consent, ads_measurement_consent, and ads_personalization_consent).

Description and purpose of data processing: We manage cookie consent ourselves, without a third-party consent provider. The banner offers “No thanks” (no optional cookies), “Analytics only,” or “Allow all” (analytics plus ads measurement and personalized advertising). Your choice is stored for 180 days in first-party cookies on the etisia.com domain so we can respect it on subsequent visits and across both our website and app. We do not share the consent-cookie values with a third-party consent manager, but we communicate the relevant granted or denied signals to configured analytics and advertising providers so they can respect your choice.

The banner controls optional cookies and the additional analytics features that depend on them. Choosing “No thanks,” or not choosing yet, does not mean that no technical data is processed: the limited, cookieless Microsoft Clarity mode described below may operate on eligible Etisia app pages. Accepting the Terms of Use is a separate action. Accepting the Terms does not grant analytics consent, and a cookie choice does not accept or withdraw the Terms.

Legal basis: Article 6(1)(c) of the General Data Protection Regulation (legal obligation to obtain consent).

Relevant Area: Web Analytics

Personal Data: IP address and IP-derived approximate location; page URL; browser, device, operating-system, display, and language information; page structure and performance or script diagnostics; and interactions such as clicks, taps, pointer movement, scrolling, and time on the page. The cookieless mode uses a new, non-persistent page-view identifier. Persistent cookie identifiers and Etisia account-linked pseudonymous identifiers are added only in the consented cookie-based mode described below.

Description and purpose of data processing: We use web analytics tools, including Google Analytics 4 (GA4) and Microsoft Clarity, to diagnose technical and usability problems, understand how pages are used, produce behavioral metrics and heatmaps, improve Etisia, and, where separately permitted, measure and improve advertising. Microsoft Clarity has two distinct operating modes on eligible pages of the Etisia app.

Masked cookieless diagnostics when analytics-cookie consent is unknown or denied: Clarity may load on eligible Etisia app pages after receiving ConsentV2 with ad_Storage and analytics_Storage set to denied. Clarity sets no first-party or third-party cookies in this mode. Etisia configures the capture as fully masked, and Microsoft assigns a new identifier to each page view. The resulting diagnostic is isolated to one page: it cannot be joined into a continuous multi-page journey or used to recognize a returning visitor.

This limited mode is not fully anonymous and we do not describe it as collecting no personal data. Microsoft may still process technical data such as IP-derived location, browser and device information, page structure, performance or script diagnostics, and masked page interactions. In this mode, Etisia does not send Clarity your Etisia account identity, hashed replay identity, audience tags, or cross-page journey linkage. Sensitive public-link pages are excluded from Clarity entirely, so neither Clarity mode operates on those pages.

Consented cookie-based analytics, identity linkage, and continuous replay: If you choose “Analytics only” or “Allow all,” Clarity receives analytics storage permission and may set analytics cookies, link page views into continuous multi-page journeys, and recognize a browser on later visits. On eligible signed-in app pages, Etisia may also send a hashed replay identity and permitted audience tags so diagnostics can be connected to the relevant Etisia account experience. The hash is a pseudonymous identifier, not anonymous data. Masking remains in place for forms, sensitive fields, and user-generated tool outputs. Advertising storage and advertising uses remain denied unless you separately choose “Allow all.”

Withdrawal and controls: You can reopen “Cookie settings” from the footer and choose “No thanks” at any time. Etisia then sends denied ConsentV2 signals to Clarity. Clarity stops using and removes its cookies, ends the linked session, and returns future eligible app pages to the fully masked, cookieless, isolated single-page mode. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal and does not change your acceptance of the Terms of Use.

Recipient and data processor: The following providers of tracking tools and web analytics tools process access data on our behalf for user analysis and statistical processing:

  • Google Analytics 4 (GA4) & Google Ads: Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA. More information at policies.google.com/privacy
  • Microsoft Clarity: Microsoft Ireland Operations Limited for EEA customers, together with Microsoft Corporation and other Microsoft group companies where applicable. Microsoft is a recipient and processes Clarity data on our behalf in both modes described above. More information at privacy.microsoft.com/privacystatement

Data retention period: Microsoft states that Clarity playback data is retained for 30 days. Click and aggregated page data, heatmaps, and labeled or favorited sessions are retained for up to 9 months. Microsoft deletes data from its servers, including backups, after the applicable retention period. Other providers' retention information is available through the links above.

Legal basis: Article 6(1)(a) of the General Data Protection Regulation (consent via the cookie banner) applies to consented GA4 processing and Clarity's cookie-based analytics mode. The cookieless Clarity mode operates without relying on analytics-cookie consent. Its Article 6 legal basis remains subject to Etisia privacy/legal approval; this draft does not assign one.

Planned or required provision of data: The provision of the aforementioned personal data is neither legally nor contractually required.

Relevant Area: Advertising

Personal Data: IP address, cookie identifier, order identifier, browsing behavior.

Description and purpose of data processing: The website uses advertising tracking tools. With the help of these advertising tracking tools, we can display or arrange the display of individual advertisements on our websites, which are selected (automatically) based on visitor preferences. Technically, advertising tracking is usually carried out via advertising identification tags through which cookies, among others, are used by advertising network providers to create user profiles and display ads based on cookie profiles when the website is accessed. Through such remarketing offers, the user can be shown relevant offers across the internet.

Interest in data processing: With the help of advertising tracking tools, we can better target our offers to our customers, visitors, and interested parties. Common advertising methods include retargeting and remarketing campaigns, in which users can be re-addressed at other times and places on the internet with potentially interesting products.

Recipients of the aforementioned data:

  • Google Ads: Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA. More information at policies.google.com/privacy

Data retention period: Information about this can be found in the links mentioned above.

Legal basis: Article 6(1)(a) of the General Data Protection Regulation (consent via cookie banner).

Planned or required provision of data: The provision of the aforementioned personal data is neither legally nor contractually required.

Relevant Area: Live Chat Support

Personal Data: Chat messages, IP address, browser information, name and email (if provided).

Description and purpose of data processing: We use Tidio to provide live chat support on our website. If you initiate a chat conversation, messages you send and associated metadata are processed to provide you with real-time customer support.

Recipient and data processor: Tidio LLC, 149 New Montgomery Street, 4th Floor, San Francisco, CA 94105, USA. More information at https://www.tidio.com/privacy-policy/.

Legal basis: Article 6(1)(a) and (f) of the General Data Protection Regulation.

Relevant Area: Contact Form and Email Communication

Personal Data: Name, email address, message content.

Description and purpose of data processing: When you submit our contact form, the data you provide (name, email address, and message) is sent to us via Mailgun, our transactional email service. We use this data solely to respond to your inquiry.

Recipient and data processor: Mailgun Technologies, Inc. (a Sinch company), 112 E. Pecan Street #1135, San Antonio, TX 78205, USA. Mailgun processes email data on our behalf. More information at https://www.mailgun.com/legal/privacy-policy/.

Data retention period: Contact form submissions are retained for the duration necessary to handle your inquiry and for a reasonable period thereafter for follow-up purposes.

Legal basis: Article 6(1)(b) and (f) of the General Data Protection Regulation.

Relevant Area: AI-Powered SMS Template Generation

Personal Data: Business name, industry, service type, and other form inputs provided by you.

Description and purpose of data processing: Our website offers an SMS template generator feature that uses artificial intelligence to create customized SMS templates for your business. When you use this feature, the information you provide in the form (such as business name, industry, and service details) is sent to an AI language model to generate the template. No personally identifiable information beyond what you voluntarily provide in the form is collected.

Recipient and data processor: OpenRouter, Inc. provides API access to AI language models. The data you submit is processed to generate the requested SMS templates. More information at https://openrouter.ai/privacy.

Data retention period: Form data is processed in real time and is not stored on our servers after the template is generated.

Legal basis: Article 6(1)(a) and (b) of the General Data Protection Regulation.

Relevant Area: Google Calendar Integration

The Etisia application uses integration with Google Calendar to synchronize calendar events. When you connect your Google account with our application, you permit us to access your calendar data in accordance with the approved permissions. This data may include event titles, descriptions, event times, and other relevant information, which we use solely to inform customers about their appointments or events and to update the calendar in case of changes or cancellations.

We obtain your consent to access this data when you connect your Google account. You can revoke this consent at any time in our application's settings or by disconnecting your Google account. Your data is stored in a secure environment and is accessible only to authorized persons. We use the latest security standards and technologies to ensure the protection of your data. We do not share your data with third parties unless it is necessary to provide our services or required by law.

The use and transfer of information received from Google APIs to the Etisia application and other applications will comply with the Google API Services User Data Policy, including the Limited Use requirements.

We are committed to transparency in the processing of your personal data. You have the right to access, correct, delete, and restrict the processing of your data related to your Google account. You also have the right to information about how your data is used and for what purposes. If you wish to exercise any of these rights or have questions regarding privacy and data protection, please contact us at [email protected].

Relevant Area: Subscription to Cloud Service and Payment Processing

Personal Data: Email address, first and last name, billing address, payment information (excluding credit card details), login data (in case of registered customers), IP address, cookie identifier.

Description and purpose of data processing: We process data within the framework of the initial order or, if you are an existing customer, to provide you with your customer user account on the etisia.com platform. If you have created a customer user account, we will need your login data to verify your account.

Recipient and data processor: We share your data with recipients exclusively based on contracts relating to order processing and only to the extent necessary to fulfill the contractual provisions of the service.

All payment processing and subscription billing is handled by Paddle.com Market Limited, which acts as the Merchant of Record for all transactions. This means Paddle is responsible for processing your payment, handling invoicing, managing applicable sales taxes (VAT, GST, sales tax), and processing refunds. Paddle collects and processes your payment data directly. Responsibility for your payment data lies with Paddle. More information about Paddle's data handling practices can be found at paddle.com/legal/privacy.

Data retention period: We process and/or delete invoices and order confirmations according to appropriate tax and business retention periods unless you have expressly consented to further use of your data. Deletion of your customer user account is possible at any time and can be requested by sending a message to [email protected].

Legal basis: Article 6(1)(a), (b), (f) of the General Data Protection Regulation.

Planned or required provision of data: The provision of the aforementioned personal data for subscription is contractually required. Otherwise, the order cannot be executed.

Relevant Area: SMS Appointment Reminders and Website Demo

Personal Data: Client or demo visitor mobile phone number and, where relevant, client name and appointment details (date, time, service type, business name). For the website demo, we also process the selected country, generated message, source page and origin, IP address (hashed before storage) and anonymous identifier, consent choice and evidence, and delivery, follow-up, and opt-out status.

Description and purpose of data processing: Etisia sends SMS appointment reminders, booking updates, and cancellation notices to end consumers on behalf of businesses that use the Etisia platform. All messages are sent from Etisia - individual businesses do not send messages directly. Phone numbers are provided to Etisia by the subscribing business, which is responsible for obtaining client consent before adding any phone number to the platform. Appointment-related messages sent on behalf of subscribing businesses are not marketing or promotional messages. All appointment-related message content is monitored through automated AI moderation and human oversight to ensure compliance with carrier guidelines.

Website demo and optional product SMS: When you enter your own mobile number in an Etisia website demo, we use it to send the demo SMS you requested. If you separately tick the optional marketing checkbox, Etisia may send one promotional follow-up SMS about automated reminders and the 50-free-SMS offer. The checkbox is off by default, leaving it unticked does not affect the requested demo, and the follow-up contains an unsubscribe link. We do not infer this consent from requesting the demo, creating an account, or consent collected by a business for appointment reminders. After the demo request is accepted, we set a 30-day first-party cookie containing an opaque demo identifier for conversion attribution; the cookie does not contain your phone number. The unsubscribe link applies to promotional follow-ups sent through this website-demo flow and does not change appointment-message preferences held by a business.

Consent: Clients consent to receiving SMS reminders through the business they book with. Consent is obtained by the business at the time of booking, either verbally during in-person or phone bookings, or through an online booking form. For more details, see our SMS consent page.

Opt-out: Clients can opt out of SMS messages at any time. Where keyword replies are supported, replying STOP is the fastest option. Opt-out requests are processed immediately. For help, contact [email protected]. Etisia does not provide a conversational SMS support inbox.

SMS delivery providers: SMS messages are delivered by third-party messaging providers acting as our sub-processors. Which provider delivers a given message depends on the recipient's country:

These providers process phone numbers and message content on our behalf solely to deliver appointment-related SMS messages, requested website demo messages, and the single optional follow-up described above. Each provider is bound by a data processing agreement and processes data only as instructed by Etisia.

Sharing limitation for mobile data: No mobile information will be shared with third parties or affiliates for their own marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties except vendors that support SMS delivery on our behalf and are contractually restricted from using that information for any purpose other than enabling the messaging services described in this section.

Data retention period: Phone numbers and message records for subscribing businesses are retained for as long as the business maintains an active Etisia account and the client has not opted out. For a website demo, the message content is erased after the requested SMS is processed. The plain phone number is erased after that send unless an optional follow-up is armed; if armed, it is retained only until the follow-up is sent, blocked, or fails, and is then erased. Hashed anti-abuse and opt-out records, consent metadata, and delivery and follow-up status may be retained to enforce limits, attribute conversions, document consent, and honor opt-outs.

Legal basis: Article 6(1)(b) and (f) for appointment-related messages, and Article 6(1)(a) for the website demo and optional promotional follow-up where the General Data Protection Regulation applies. For US recipients, consent is obtained in compliance with the Telephone Consumer Protection Act (TCPA).

Message frequency and rates: Appointment-message frequency varies based on the appointment schedule. A website demo visitor receives one requested demo SMS and, only if separately consented and eligible, no more than one promotional follow-up for that demo. Message and data rates may apply.

Relevant Area: SEO Optimization

Personal Data: IP address, browser information, page interaction data.

Description and purpose of data processing: We use Writesonic SEO tools to audit and optimize our website's search engine performance. This tool may collect page-level interaction data to provide optimization recommendations.

Recipient and data processor: Writesonic, Inc. More information at writesonic.com/privacy-policy.

Legal basis: Article 6(1)(f) of the General Data Protection Regulation.

Relevant Area: Web Fonts

Personal Data: IP address, browser information.

Description and purpose of data processing: Our website uses Google Fonts to ensure consistent and visually appealing typography. When you visit our website, your browser downloads the required font files from Google's servers. In doing so, your IP address and browser information are transmitted to Google.

Recipient and data processor: Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA. More information at policies.google.com/privacy.

Legal basis: Article 6(1)(f) of the General Data Protection Regulation.

4. International Data Transfers

Some of the third-party service providers mentioned above are based in the United States or other countries outside the European Economic Area (EEA). Where personal data is transferred to countries outside the EEA, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on the EU-U.S. Data Privacy Framework where applicable. For Clarity, Microsoft states that EEA customers contract with Microsoft Ireland Operations Limited and that transfers to Microsoft Corporation in the United States are covered by SCCs. Clarity data is stored in Microsoft Azure and may be accessed or processed by Microsoft group companies outside the EEA under the applicable safeguards.

5. Your Rights Regarding the Processing of This Data

Under the General Data Protection Regulation, you have the following rights:

  • Right of access (Article 15 GDPR): You have the right to request confirmation of whether we process your personal data and to obtain information about this data.
  • Right to rectification (Article 16 GDPR): You have the right to request the correction of inaccurate personal data.
  • Right to erasure (Article 17 GDPR): You have the right to request the deletion of your personal data under certain conditions.
  • Right to restriction of processing (Article 18 GDPR): You have the right to request the restriction of data processing under certain conditions.
  • Right to data portability (Article 20 GDPR): You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to object (Article 21 GDPR): You have the right to object to the processing of your personal data at any time.
  • Right to withdraw consent (Article 7(3) GDPR): You have the right to withdraw your consent for data processing at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

The rights above apply to personal data processed through Clarity in either mode, subject to the conditions in applicable law. Use “Cookie settings” in the footer to change or withdraw a cookie choice. For any request for access, correction, deletion, restriction, portability, withdrawal, or objection, please email [email protected]. Additionally, you have the right to lodge a complaint with the relevant supervisory authority. In Slovenia, this is the Information Commissioner (Informacijski pooblaščenec), available at www.ip-rs.si.

6. Changes to This Privacy Policy

We reserve the right to update this privacy policy from time to time to reflect changes in our data processing practices or legal requirements. We encourage you to review this page periodically for the latest information on our privacy practices. Significant changes will be communicated through a notice on our website.

Last updated: 25 August 2026

Google Calendar owner-only test messages

Personal data: the verified account owner’s mobile number, the rendered test message, sender and route metadata, transmission timestamps, and delivery state.

Purpose and authorization: If this feature is released after the checks below, the account owner will explicitly confirm one test before Etisia submits exactly one test message to that owner’s verified phone. The message will be clearly marked as a test, active links will be disabled, and no customer message credits will be used. This one-time authorization will not authorize appointment-recipient messages. Owner-only test sending is not currently available.

SMS delivery provider and intended data fields: Etisia has not yet verified or named the exact contracted legal entity that would receive data for this owner-only test. A provider’s public website or legal notice is not evidence of Etisia’s executed contract or data processing agreement (DPA) and must not be treated as a subprocessor disclosure. The intended minimum data set, still subject to contract, DPA, and exact field-manifest verification, is the verified owner destination, rendered test text, and the sender, routing, timing, and correlation metadata needed to submit the message and obtain delivery evidence. The raw Google Calendar event, the appointment recipient’s phone number, customer credits, and Etisia account identifiers are outside that intended data set.

Release status: Release remains blocked until Etisia verifies the executed contract and DPA, the exact contracted legal entity and route, the exact field manifest, and a matching deployed privacy disclosure. Only after those checks will this notice name the exact contracted legal entity. No test message is submitted while this block remains.

Replies and opt-out: Where the configured sender supports replies, an ordinary reply does not authorize or change any appointment action. A recognized STOP-family request enters Etisia’s global SMS suppression flow. Etisia does not provide a conversational SMS inbox.

Retention and export: The verified destination and rendered test copy become logically inaccessible at the earlier of seven days after the attempt is created or 24 hours after a terminal outcome. Sanitized lifecycle and delivery evidence is kept for no longer than 90 days. Linked records are removed on account deletion. While retained and still accessible, user-visible test history is included in the authenticated Workspace add-on data export in the Etisia profile.

For privacy questions or to exercise your rights, contact [email protected].