Data Processing Terms
Status: in force for everyone using this service. Written by the people who built it and not yet reviewed by a lawyer — we would rather say so than imply a review that has not happened. Version 1.0, effective 2026-08-29.
These terms apply where we process personal data on your behalf — that is, the details of the people who book meetings through your pages. They form part of the Terms of Service. Where you require a signed agreement on your own paper, write to admin@pumasi.ai.
These terms take effect when you use the service; no signature is required for them to bind us. The operator is ATX APPLE LLC (Texas, United States), and processing takes place in the United States — see Transfers below.
Roles
You are the controller. We are the processor. We process personal data only on your documented instructions, which consist of these terms, the Terms of Service, and your use of the service's features.
Subject matter, duration, nature and purpose
Categories, including the ones you choose. We process what the booking form collects — a booker's name, email address, chosen time and timezone — and, where you add your own questions to a booking page, whatever those questions collect. We do not choose, review or limit what you ask. You are the controller for it, you are responsible for having a lawful basis for it (see *Your obligations*), and we process it only to run the service for you.
Subject matter, duration, nature and purpose
The subject matter is the operation of scheduling software for you. It lasts as long as your account. Its nature and purpose is arranging meetings: offering times, recording a booking, notifying both parties, and — where you connect one — reflecting the booking in your calendar.
Types of personal data
Bookers' names, email addresses, the timezone their browser reported, the times they booked, any private note you record about a booking, and — where you use those features — poll voters' names, addresses and selections, and contact records derived from bookings.
Categories of data subjects
The people who book meetings with you, the people who vote in your meeting polls, and the members of your own team who hold accounts.
Our obligations
1. Instructions. We process only on your instructions, and will tell you if we believe an instruction breaks applicable data-protection law. 2. Confidentiality. Everyone with access is bound to confidentiality. 3. Security. We maintain the measures described in the privacy notice: encryption in transit, encryption at rest for calendar credentials, digest-only storage of API credentials, per-customer database isolation, and no password store at all. 4. Subprocessors. You give general authorisation for the subprocessors listed in the register. We will announce additions to account holders before they take effect, and you may object; if you object and we cannot offer an alternative, you may terminate. 5. Assistance. We will help you respond to data subjects' requests, and with your obligations on security, breach notification, and assessments — taking account of the nature of processing and what is available to us. 6. Breach. We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with what we know and what we are doing. 7. Deletion and return. On termination, or on your request, we delete the personal data. Deletion is immediate and verified by absence. We keep no backups of our own today; if we introduce them, the retention period will be published before they hold anything. 8. Audit. We will make available the information needed to demonstrate compliance with these terms. Because the software is open source, the code handling your data can be inspected directly rather than taken on trust.
Transfers
The service is operated from the United States and personal data you entrust to it is processed there. If your own obligations require standard contractual clauses or an equivalent mechanism, write to admin@pumasi.ai before you rely on this service for that data — we would rather have that conversation than let you assume a safeguard is in place.
Your obligations
You warrant that you have a lawful basis for the personal data you collect through the service, that you have given the people concerned the information they are owed, and that your instructions do not require us to break the law.