Penndulo Privacy Policy
At Penndulo ("we" or "the Platform"), we take the protection of your personal data seriously. This Privacy Policy explains how we collect, use, and protect your information when you use our public website and the application available at app.penndulo.com.
1. Data controller
The data controller is Penndulo LLC (EIN: 35-2961135). For any questions regarding this policy or the processing of your data, contact us at info@penndulo.com.
2. Data we collect
Depending on how you use Penndulo, we may process the following categories of data:
- Account data: name, email address, and access credentials.
- Billing data (if applicable): information required for payment and invoice management.
- Platform usage data: account settings, preferences, and basic in-app activity.
- Google Calendar data: calendar and event information, only when you explicitly grant permission through Google OAuth.
3. Use of Google data (Google Calendar)
Penndulo integrates with Google Calendar via Google OAuth so you can manage your schedule from the Penndulo dashboard.
When you connect your Google account, Penndulo may:
- Read your Google Calendar calendars and events to display and sync them on the platform.
- Create, update, and delete events in your Google calendars to reflect changes made from the Penndulo dashboard.
This access is used exclusively to let you manage appointments from Penndulo. We do not access other Google products (such as Gmail or Google Drive) beyond what is strictly necessary for Google Calendar integration.
Secure infrastructure and use of Nylas
To ensure secure and reliable synchronization with Google Calendar, we use Nylas as a technical processor and integration infrastructure provider. Nylas acts as a data processor and processes calendar data solely to provide calendar synchronization between Penndulo and Google Calendar.
Nylas applies advanced security measures and complies with data protection standards appropriate for processing sensitive calendar information.
Limited Use clause (Google API Services)
Penndulo's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements.
No sale or AI training without consent
Penndulo does not sell personal or calendar data to third parties. We also do not use Google Calendar data or other personal data we process to train artificial intelligence models without your prior, free, and informed consent.
4. Purposes of processing
We process your personal data for the following purposes:
- Provide access to the platform and your user account.
- Enable management and synchronization of appointments and external calendars.
- Manage the commercial relationship and billing, where applicable.
- Improve platform security, stability, and user experience.
- Respond to support inquiries sent through our contact channels.
5. Legal basis
The main legal basis for processing your data is contract performance (provision of the Penndulo service) and your consent when connecting external services such as Google Calendar via OAuth.
6. Data retention
We retain your data while you maintain an active Penndulo account and for as long as necessary to comply with legal obligations or resolve potential liabilities. You may request deletion of your account and associated data as described in the rights section.
7. Data sharing
We do not share your data with third parties except when necessary to provide the service (for example, with Nylas as a technical processor or cloud infrastructure providers) or when required by law. In all cases, we require such providers to comply with appropriate security and confidentiality measures.
8. Information security
We implement reasonable technical and organizational measures to protect your data against unauthorized access, loss, alteration, or improper disclosure. However, no system is completely inaccessible, so we cannot guarantee absolute security, although we maintain a level of security consistent with industry best practices.
9. User rights
As a user, you have the right to:
- Access your personal data.
- Request correction of inaccurate or incomplete data.
- Request deletion of your data when it is no longer necessary.
- Restrict or object to processing in certain circumstances.
- Request data portability to another provider when technically feasible.
To exercise any of these rights, contact us at info@penndulo.com.
10. Revoking Google Calendar access
You may revoke Penndulo's access to your Google Calendar data at any time from your Google account settings, in the third-party apps section. Once access is revoked, Penndulo will no longer be able to read or modify your calendars.
11. Updates to this policy
We may update this Privacy Policy when necessary to reflect legal or functional changes to the service. We will publish the updated version at this same URL and indicate the last update date.
If you have any questions about this Privacy Policy or how we process your data, contact us at info@penndulo.com.