Privacy Policy
Version date: 2026-09-10
PRIVACY POLICY – DaliCares
1. Who is the controller
The data controller is Ing. Dalibor Jakš, Kalinová 265/3, 612 00 Brno, Czech Republic, Company ID 72414537 (hereinafter "Provider").
Contact: info@dalicares.com
2. Scope of this document
This Privacy Policy describes the processing of personal data where the Provider is the controller (especially Website visitors and account users).
Client data (personal data of clients entered by the User into the application) are typically processed so that the User is the controller and the Provider is the processor; conditions are governed by the DPA in the ToS.
3. What data does the Provider process as controller
- Identification and contact data (name, email, possibly phone)
- Account data (role, settings)
- Billing data and payment data (without card numbers; those are typically processed by Stripe)
- Support communication
- Technical data and security logs (e.g., IP address, device, login)
- Cookies and web analytics data (if consent is given)
4. Purposes and legal bases
- Contract performance (account, Service operation, support) – Art. 6(1)(b) GDPR
- Legal obligations (accounting, taxes) – Art. 6(1)(c)
- Legitimate interests (security, abuse prevention, legal defense) – Art. 6(1)(f)
- Marketing/analytics – based on consent or law
5. Recipients and processors
The Provider may use vendors:
- Google Cloud – hosting and cloud infrastructure
- WEDOS – hosting
- Google Analytics – web analytics (based on consent)
- Email services – Google/WEDOS
- Stripe – handles payments; payment data (e.g., card numbers) are typically not stored by the Provider
6. Third countries
Some vendors may involve transfer outside the EEA (e.g., Google, Stripe). Appropriate safeguards (e.g., Standard Contractual Clauses - SCC) are used where relevant.
7. Retention (storage period)
- Account data: during the contract term and subsequently according to ToS (typically max. 90 days for export)
- Accounting documents: according to legal requirements
- Logs: typically up to 12 months (based on minimization)
- Cookies: according to settings and consents
8. Data subject rights
You have the following rights:
- Right of access – obtain information about processing of your data
- Right to rectification – correct inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent (if processing is based on consent)
Contact for exercising rights: info@dalicares.com
Note: For requests concerning Client data, the User is the primary controller; the Provider will provide reasonable assistance according to the DPA.
You also have the right to lodge a complaint with a supervisory authority (in the Czech Republic: Office for Personal Data Protection, www.uoou.cz).
9. Cookies
Details about cookie usage are in the Cookies Policy document and in the cookie banner on the website.
Google Calendar integration
DaliCares allows a user to voluntarily connect a Google Calendar account to the Service. The connection is used primarily to display busy times, check availability for bookings, synchronize events, and create, update or delete events created or managed through DaliCares.
When the integration is used, DaliCares may request the Google OAuth scopes https://www.googleapis.com/auth/calendar.readonly to read calendars and events and https://www.googleapis.com/auth/calendar.events to create, update and delete events.
In connection with the integration, DaliCares may process the Google account identifier or account email, calendar and event identifiers, event titles, start and end times, information required to determine availability, and data of events created or updated by DaliCares. For events managed by DaliCares, information related to a booking may be transferred to Google Calendar, such as the client name, booking type, booking note and technical DaliCares identifiers.
To provide synchronization, DaliCares stores OAuth credentials required for authorized access (access token and, where issued, refresh token), the primary calendar identifier, connection status, an event synchronization cache and technical metadata used for change notifications (watch/channel metadata). These data are used solely to provide and secure the Google Calendar functionality.
The connection can be explicitly disconnected at any time in DaliCares settings. Upon disconnection, DaliCares removes stored access credentials and related synchronization cache and metadata and attempts to revoke the OAuth authorization with Google. Events that have already been created in Google Calendar are not necessarily deleted automatically by disconnecting the integration.
In TEAM mode, an authorized workspace owner or an active assistant acting within their workspace permissions may manage the Google Calendar connection of the owner or an active therapist currently being managed. The OAuth consent itself always applies to the specific Google account that is authorized during the connection process.
We do not use Google Calendar data for targeted advertising, we do not sell it, and we do not disclose it to third parties for their own marketing purposes. Our use of information received from Google APIs is also subject to the Google API Services User Data Policy, including the Limited Use requirements.
Protection of sensitive data. DaliCares protects Google user data and other sensitive data through authenticated access, role- and permission-based access controls, HTTPS/TLS encryption in transit, and encryption at rest provided by the underlying Google Cloud/Firebase infrastructure where the data is stored. Access is limited according to the user account, workspace scope and the functionality required to provide the Service.
AI/ML and Google Workspace data. DaliCares may use the OpenAI API for optional AI-assisted processing of content that a user explicitly submits to an AI-enabled feature, such as extraction of data from laboratory results. Google Workspace API data, including Google Calendar data and data derived from it, is not sent to OpenAI or any other third-party AI/ML provider and is not used to develop, improve, or train generalized or non-personalized AI/ML models.
10. Changes
The current version of this Privacy Policy is always available on our website. We will inform you of substantial changes.
Last updated: September 10, 2026