SYCTRA
Privacy policy
Last updated · 1 September 2026
1. Data controller
SYCTRA, 19 rue de Meudon, 92100 Boulogne-Billancourt, France, is the controller for the processing described below.
For data you process about your own invitees through the service, you act as controller and SYCTRA acts as processor.
2. Data collected
Account: name, email address, hashed password, language, time zone, organisation.
Bookings: the invitee's name and email address, phone number where requested, answers to your intake questions, time and time zone.
Technical: connection logs, IP address, and the data strictly necessary to run the service.
Connected calendars: only busy periods and the events created by the service, if you enable synchronisation.
3. Purposes and legal bases
Providing the service, managing accounts and bookings: performance of the contract.
Sending confirmations and reminders: performance of the contract.
Security, abuse prevention and logging: legitimate interest.
Accounting and tax obligations: legal obligation.
4. Recipients and processors
Data is never sold or handed to third parties for advertising.
Processors: Google Cloud (hosting), Stripe (payments) and the email delivery provider, each under a contract compliant with article 28 GDPR.
If you connect Google Calendar or Outlook, the data exchanged is limited to what synchronisation requires.
5. Transfers outside the European Union
Primary hosting is located in the European Union (Belgium).
Where a processor may access data from a third country, the transfer is covered by the European Commission's standard contractual clauses.
6. Retention periods
Account: for as long as it is used, then twelve months after the last sign-in.
Bookings: thirty-six months from the date of the meeting.
Technical logs: twelve months.
Accounting records: ten years, as legally required.
7. Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability.
Exercise them at contact@syctra.com. You will receive an answer within one month.
If you are someone's invitee, send your request to that organiser; we will pass it on where needed.
8. Security
Traffic encrypted with TLS, passwords stored only as hashes, strict data separation between organisations, and logging of administrative access.
API keys are stored only as hashes and cannot be read back after creation.
9. Cookies
Only the cookies and local storage needed to operate are used: session, language and display preferences. No advertising tracker is set.
10. Contact and complaints
For any question: contact@syctra.com.
You may lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75007 Paris.