Legal
Privacy Statement
Last updated: 2026-06-26
On this page
- 1. Identity and contact details
- 2. Controller and processor roles
- 3. Categories of personal data
- 4. Purposes and legal bases
- 5. Google Calendar data
- 6. Subprocessors and providers
- 7. Retention
- 8. Security
- 9. Data-subject rights and complaints
- 10. International transfers
- 11. Cookies and local storage
- 12. Changes
1. Identity and contact details
CasBizz Holding B.V. operates WantToBook. Public business and contact details are listed on the contact page and in the footer when configured.
Privacy questions can be sent to info@casbizz.nl.
2. Controller and processor roles
The SaaS provider is generally controller for account, contract, billing, platform security, and service communication data.
The customer organization is generally controller for its own booking/customer data. The SaaS provider processes customer and booking data on behalf of that organization as processor.
3. Categories of personal data
- organization account data, including organization name, authorized users, roles, and subscription status;
- staff-user data, including names, email addresses, access roles, and notification preferences;
- customer and booking data processed on behalf of organizations, such as customer contact details, selected services, requested dates, notes, and appointment status;
- online shop order data processed on behalf of organizations, including ordered products, order status, contact details, and a delivery address when shipping is selected;
- marketing subscription data, including the selected email, SMS, or WhatsApp channel, a protected contact destination, organization, consent source and version, subscription status, and consent, confirmation, and unsubscribe timestamps;
- payment-related references, including Mollie customer, payment, subscription, and mandate references where billing is enabled;
- technical logs, audit data, security events, browser/session data, and system diagnostics.
4. Purposes and legal bases
Data is processed to provide the booking service, administer accounts and subscriptions, process payments, secure the platform, communicate service messages, comply with legal obligations, and support customers.
Legal bases may include contract performance, legitimate interests, legal obligations, and consent where a specific feature requires it.
A newsletter or other marketing by email, SMS, or WhatsApp is sent only after an explicit subscription, channel selection, and confirmation of the relevant email address or mobile number. Booking, client, and waitlist contact details are not automatically enrolled. Marketing messages include a channel-specific unsubscribe method; STOP messages suppress SMS or WhatsApp marketing for that mobile number.
5. Google Calendar data
When an authorized organization administrator chooses to connect Google Calendar, WantToBook requests read-only access to the calendar list and events in the calendars they select. This access is used only to identify busy periods, calculate appointment availability, and prevent overlapping bookings.
WantToBook stores the selected calendar identifiers, names and time zones, encrypted OAuth access and refresh tokens, and the identifiers, start times, end times, and all-day status of imported events. Event titles, descriptions, attendees, locations, and attachments are not stored.
Google user data is not sold or disclosed to advertising platforms, data brokers, information resellers, or lenders, and is not used for advertising, credit decisions, or training generalized artificial intelligence or machine-learning models. It is not transferred or disclosed to third parties except to service providers that supply the hosting, database, storage, backup, and security infrastructure needed to operate the requested calendar synchronization service, or when disclosure is required by law. Those providers process the data only on our instructions and may not use it for their own purposes.
Access to Google user data is restricted to authorized users and service processes. OAuth tokens are encrypted at rest and data is protected in transit. When an organization disconnects Google Calendar, the OAuth tokens, calendar selections, and imported event data for that connection are deleted from active systems. Residual backup copies expire under the backup-retention period described below.
WantToBook's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Subprocessors and providers
Hosting, email delivery, backup/storage, Mollie payment processing, and Twilio SMS and WhatsApp services may be used depending on the deployment and enabled features.
- Mollie: Payment processing.
- Twilio: SMS verification and notifications.
- DigitalOcean: Object storage and encrypted backups.
7. Retention
Account, billing, security, and operational records are retained only as long as needed for the service, legal obligations, dispute handling, and security monitoring.
Booking/customer data is retained on the instructions of the customer organization. A deletion request does not override a legal retention obligation, a binding preservation requirement, or a legal hold. Where only part of a record must be retained, data that is not required should be deleted or anonymized where reasonably possible.
Newsletter delivery stops immediately after unsubscribe. Consent and unsubscribe evidence may be retained for the period reasonably needed to demonstrate compliance and prevent accidental re-enrolment.
Data is retained for 30 days after termination.
8. Security
The platform uses access controls, role separation, encrypted transport, audit-relevant logs, backups, and operational monitoring. No statement on this page should be read as an absolute guarantee of GDPR compliance or uninterrupted security.
9. Data-subject rights and complaints
Data subjects may request access, correction, deletion, restriction, portability, or objection where applicable. Booking/customer data requests should usually be directed to the customer organization that controls that data.
The right to deletion is not absolute. The responsible controller will assess each request and may retain data where storage is required by law or necessary for the establishment, exercise, or defense of legal claims. The requester will be informed when a request cannot be fully carried out, unless notification is legally restricted.
Complaints may be submitted to the Dutch Data Protection Authority.
10. International transfers
Where providers process data outside the European Economic Area, appropriate safeguards must be assessed and documented before production approval.
12. Changes
This statement may be updated when the service, legal requirements, or providers change. The last updated date shows the maintained publication date.