Effective date: August 21, 2026
Last updated: August 21, 2026

This Privacy Policy explains how Jivalabs d.o.o. processes personal data through the Schedito website and scheduling service.


1. Who operates Schedito

Jivalabs d.o.o.
Šmarska Cesta 7c
6000 Koper, Slovenia
Registration number: 8974632000
VAT number: SI73478776
Email: support@schedito.com
Phone: +386 70 179 333

For account, website and service-administration data described in this policy, Jivalabs d.o.o. generally acts as the data controller.


2. Workspace operators and booking customers

Organizations and professionals that use Schedito to receive bookings decide why and how they collect personal data from their own customers. For that booking data, the workspace operator is generally the data controller and Jivalabs d.o.o. processes the data to provide Schedito on the operator's behalf.

If you are an end customer who made a booking through a Schedito-powered calendar, you should normally contact the organization with which you booked for questions about the booking itself or its use of your personal data.


3. Information we process

Depending on how you use Schedito, we may process:

  • Account information: name, email address, language, authentication and account-status information.

  • Workspace information: organization name, configuration, plan, users, services, resources, availability rules and branding settings.

  • Booking information: booking time, service, resource, status and customer details provided through the booking flow.

  • Billing information: subscription plan, billing interval, Paddle customer, subscription and transaction identifiers, transaction status and related billing metadata. Full card details are handled by Paddle and are not stored by Schedito.

  • Integration information: identifiers and authorization data needed to operate external-calendar connections that you choose to enable.

  • Communications: support messages, service emails, verification messages and notification-delivery information.

  • Technical information: IP address, browser or device information, request metadata, security events and operational logs needed to deliver and protect the service.


4. Why we use personal data

We process personal data to:

  • create and authenticate accounts and workspaces;

  • provide calendars, availability, booking and workspace-management functionality;

  • send verification, operational and configured booking notifications;

  • operate paid subscriptions and reconcile billing state;

  • connect supported third-party calendar services when requested;

  • provide customer support and respond to requests;

  • secure, troubleshoot, monitor and improve Schedito; and

  • meet legal, accounting, tax, fraud-prevention and compliance obligations.


5. Legal bases

Where the EU General Data Protection Regulation or similar law applies, our legal bases may include:

  • Contract: processing necessary to provide the Schedito service you request.

  • Legitimate interests: securing the service, preventing abuse, supporting customers and improving reliability where those interests are not overridden by your rights.

  • Legal obligations: records, compliance and lawful requests from competent authorities.

  • Consent: where a feature or applicable law requires your consent, including optional integrations or analytics where relevant.


6. Payments and Paddle

Paddle.com acts as Merchant of Record for paid Schedito orders. Paddle processes payment details, transaction taxes, receipts, billing support and refund handling under its own buyer terms and privacy notices.

Schedito receives the billing identifiers and transaction or subscription status needed to activate and manage the correct plan, but does not receive your full payment-card details.


7. External calendar integrations

If a workspace connects a supported external calendar service, Schedito processes the account and calendar identifiers, authorization information and scheduling data required to provide the selected synchronization features.

External providers process information under their own privacy policies. You can disconnect an integration from the available Schedito controls, subject to the provider's own authorization and retention behavior.


8. Email and notification services

Schedito uses email infrastructure to send account verification, operational messages and booking notifications. Workspace operators on eligible plans may also configure their own supported mail transport.

Email providers may process recipient addresses, delivery metadata and message contents as necessary to transmit those communications.


9. Website analytics and cookies

The public Schedito website may use essential browser storage and first-party analytics to understand site usage and maintain service functionality. Where consent is required for non-essential analytics, those technologies should follow the consent choice presented on the website.

Authentication and security features may also use session or similar technical storage that is necessary to provide the requested service.


10. Service providers and disclosures

We use infrastructure, database, email, analytics, security and payment providers where necessary to operate Schedito. They receive only the information reasonably required for their role and are subject to applicable contractual and legal safeguards.

We may also disclose information where required by law, a court or competent authority, or where reasonably necessary to protect Schedito, our customers or other people from fraud, abuse or security threats.

We do not sell personal data for advertising purposes.


11. International transfers

Schedito is operated by a company established in Slovenia and is designed to serve customers internationally. When a provider processes personal data outside the European Economic Area, we use or rely on a legally recognized transfer mechanism where required, such as an adequacy decision or standard contractual clauses.


12. Retention

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing active accounts, maintaining required business and billing records, resolving disputes, preventing abuse and complying with legal obligations.

Retention periods may differ between account records, bookings, billing records, security logs and support correspondence. Workspace operators are responsible for setting lawful retention practices for the customer data they control.


13. Security

We use technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration and disclosure. No online service can guarantee absolute security, but we continuously aim to reduce operational and security risk.


14. Your rights

Depending on the law that applies to you, you may have rights to access, correct, delete or restrict personal data; object to certain processing; receive certain data in a portable format; withdraw consent; and lodge a complaint with a competent supervisory authority.

For data controlled directly by Jivalabs d.o.o., requests may be sent to support@schedito.com. For booking data controlled by a Schedito workspace operator, please contact that operator first.

In Slovenia, the supervisory authority is the Information Commissioner of the Republic of Slovenia.


15. Children

Schedito workspace accounts are intended for businesses, professionals and other persons able to enter into the relevant service agreement. The service is not directed to children as account holders.

A workspace operator that uses Schedito to book services involving minors is responsible for establishing an appropriate legal basis and collecting any consent required for that booking data.


16. Changes to this policy

We may update this policy when Schedito, our providers or applicable law changes. The current version and its update date will be published on this page.


17. Contact

Privacy questions and requests can be sent to:

Jivalabs d.o.o.
Šmarska Cesta 7c, 6000 Koper, Slovenia
support@schedito.com
+386 70 179 333