Privacy Policy
Last updated: March 2026
1. Responsible Entity
The entity responsible for data processing on this website is:
ANY Lifestyle Marketing GmbH
Nibelungenplatz 3
60318 Frankfurt am Main
Deutschland
Managing Director: Tim Lauth
Email: info@any-lifestyle.de
Amtsgericht Frankfurt, HRB 124269
2. Data Protection Officer
Our Data Protection Officer is:
Dominic Baum
Nibelungenplatz 3
60318 Frankfurt am Main
Email: datenschutz@any-lifestyle.de
3. Collection and Storage of Personal Data and Type and Purpose of Their Use
a) When Visiting the Website
When you access our website, the browser on your device automatically sends information to the server of our website. This information is temporarily stored in a so-called log file. The following information is collected without your intervention and stored until automatic deletion:
- IP address of the requesting computer
- Date and time of access
- Name and URL of the retrieved file
- Website from which the access was made (referrer URL)
- Browser used and, if applicable, the operating system of your computer as well as the name of your access provider
The aforementioned data is processed by us for the following purposes:
- Ensuring a smooth connection to the website
- Ensuring comfortable use of our website
- Evaluating system security and stability
- For other administrative purposes
The legal basis for data processing is Art. 6 Abs. 1 S. 1 lit. f GDPR. Our legitimate interest follows from the above-listed purposes for data collection. Under no circumstances do we use the collected data for the purpose of drawing conclusions about you personally.
b) When Registering and Using the Service
When registering for our service Calentix, we collect the following personal data:
- First and last name
- Email address
- Password (stored encrypted)
- Optional: profile picture, company, phone number
This data is collected and processed for the fulfillment of the contract in accordance with Art. 6 Abs. 1 S. 1 lit. b GDPR. It is necessary to provide you with our service.
c) When Booking an Appointment
When third parties book an appointment through Calentix, the following data is collected:
- Name of the person booking
- Email address of the person booking
- Selected appointment and time zone
- Additional information that the Calentix user requests through custom forms
The legal basis is Art. 6 Abs. 1 S. 1 lit. b GDPR (initiation of a contract) or Art. 6 Abs. 1 S. 1 lit. f GDPR (legitimate interest of the user in appointment management).
4. Data Sharing
Your personal data will not be transmitted to third parties for purposes other than those listed below. We only share your personal data with third parties if:
- You have given your explicit consent in accordance with Art. 6 Abs. 1 S. 1 lit. a GDPR
- The disclosure is necessary for the assertion, exercise, or defense of legal claims in accordance with Art. 6 Abs. 1 S. 1 lit. f GDPR
- There is a legal obligation for the disclosure in accordance with Art. 6 Abs. 1 S. 1 lit. b GDPR
- This is legally permissible and necessary for the processing of contractual relationships with you in accordance with Art. 6 Abs. 1 S. 1 lit. b GDPR
5. Processors and Third-Party Providers
To provide our service, we use the following processors:
a) Hosting: Vercel Inc.
Our website is hosted by Vercel Inc. Data processing is based on Art. 6 Abs. 1 S. 1 lit. f GDPR. A Data Processing Agreement (DPA) in accordance with Art. 28 GDPR has been concluded. The servers are located in the EU (Frankfurt am Main, Germany).
b) Database: Supabase Inc.
For data storage, we use Supabase with servers in the EU (Frankfurt am Main). A DPA in accordance with Art. 28 GDPR has been concluded. The legal basis is Art. 6 Abs. 1 S. 1 lit. b and f GDPR.
c) Email Delivery: Resend
For sending confirmation and notification emails, we use Resend, Inc. (USA). The transfer of data to the USA is based on EU Standard Contractual Clauses (SCCs) pursuant to Art. 46 para. 2 lit. c GDPR. A Data Processing Agreement (DPA) pursuant to Art. 28 GDPR has been concluded. The legal basis is Art. 6 Abs. 1 S. 1 lit. b GDPR.
d) Authentication: Supabase Auth
For user authentication, we use Supabase Auth. Email address and encrypted password are stored in the EU. Optionally, you can sign in via Google OAuth or Microsoft OAuth. When signing in with Google, Google transmits the following data to us: your name, email address, and profile picture. This data is used exclusively to create and manage your Calentix account.
e) Calendar Integration: Nango
For connecting to Google Calendar and Microsoft Outlook, we use Nango as an OAuth token manager. With your consent, we access your Google Calendar to read and write the following data: existing calendar entries to check your availability (read access), new calendar entries for confirmed bookings (write access), and calendar metadata (e.g. calendar name, time zone). Nango exclusively stores the OAuth access tokens, not the calendar content itself. This calendar content is processed by Calentix solely for scheduling purposes and is not stored permanently on our servers. The legal basis is Art. 6 Abs. 1 S. 1 lit. b GDPR as well as your explicit consent pursuant to Art. 6 Abs. 1 S. 1 lit. a GDPR.
f) Payment Processing: Stripe
For paid bookings and subscriptions, we use Stripe, Inc. Stripe processes payment data at its own discretion in compliance with PCI DSS. The legal basis is Art. 6 Abs. 1 S. 1 lit. b GDPR. For more information, please refer to the Stripe Privacy Policy.
g) Use of Google API Services
Calentix's use of information received from Google APIs complies exclusively with the Google API Services User Data Policy, including the Limited Use Requirements. In particular: Google user data is used solely to provide and improve Calentix features (scheduling, calendar synchronization). Google user data is not shared with third parties for advertising purposes, not sold to data brokers, not used to train AI models, and not used for any purpose outside the core application functionality. Access to Google user data is limited to the minimum necessary to provide the service.
6. Cookies
Calentix exclusively uses technically necessary cookies that are required for the operation of the website and the service. These include:
- Session cookies: To maintain your login session
- CSRF cookies: To protect against cross-site request forgery
We do not use tracking cookies, analytics cookies, or third-party cookies for advertising purposes. The legal basis is Art. 6 Abs. 1 S. 1 lit. f GDPR.
7. Rights of the Data Subject
You have the right:
- to request information about your personal data processed by us in accordance with Art. 15 GDPR
- to request the immediate correction of inaccurate or completion of your personal data stored by us in accordance with Art. 16 GDPR
- to request the deletion of your personal data stored by us in accordance with Art. 17 GDPR
- to request the restriction of processing of your personal data in accordance with Art. 18 GDPR
- to receive your personal data in a structured, commonly used, and machine-readable format (data portability) in accordance with Art. 20 GDPR
- to revoke your consent at any time in accordance with Art. 7 Abs. 3 GDPR
- to lodge a complaint with a supervisory authority in accordance with Art. 77 GDPR
8. Right to Object
If your personal data is processed on the basis of legitimate interests in accordance with Art. 6 Abs. 1 S. 1 lit. f GDPR, you have the right to object to the processing of your personal data in accordance with Art. 21 GDPR, insofar as there are grounds relating to your particular situation.
If you wish to exercise your right to object, simply send an email to: datenschutz@any-lifestyle.de
9. Data Security
We use the widely adopted SSL (Secure Socket Layer) procedure in conjunction with the highest level of encryption supported by your browser during your visit to the website. All passwords are stored hashed and salted. Our infrastructure is hosted in German data centers.
10. Updates and Changes to this Privacy Policy
This privacy policy is currently valid as of March 2026. Due to the further development of our website and offerings, or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy. The current version of the privacy policy can be accessed and printed at any time on our website.
11. Competent Supervisory Authority
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Postfach 3163
65021 Wiesbaden
Telefon: +49 611 1408-0
E-Mail: poststelle@datenschutz.hessen.de
12. Data Retention and Deletion
We store your data only for as long as required for the respective processing purposes or as mandated by statutory retention periods. The following retention periods apply:
- Account data: stored for as long as your account is active. After account deletion, all personal data is irrevocably deleted within 30 days.
- Booking data: retained for up to 10 years for tax law compliance (§ 257 HGB, § 147 AO).
- Google Calendar data: processed only within the context of active appointment management and not stored permanently on our servers. Upon disconnecting the calendar integration, OAuth access tokens are immediately and irrevocably deleted.
- Server log files: automatically deleted after a maximum of 90 days.
To delete your account and all associated data, you can contact us at any time: datenschutz@any-lifestyle.de