01Who we are
Calmer Days Ahead is operated by We Are Zacapa Ltd (registered in England & Wales, company number 11278191), 35 Emmeline Lodge, 27 Kingston Avenue, Leatherhead, England, KT22 7FU. For anything in this policy, write to privacy@calmerdaysahead.com — a human reads it.
02What we collect
- Account — your name, email address, and a securely hashed password (or your Google sign-in).
- Team — names, work emails, and roles of the people an admin seats into an organisation.
- Calendar data — events from calendars you connect: titles, times, attendees, locations. Only when you connect them; see §4.
- Files — documents you attach to projects, kept in private storage.
- Call requests — what someone submits through your public request link (see §5).
- Technical — the ordinary logs any web service produces: IP address, browser type, request records, used for security and keeping the lights on.
03Why we use it
We process your data to provide the service (our contract with you), to keep it secure and prevent abuse, and to run team features your organisation sets up (our legitimate interest in workplace collaboration, for EU/UK law purposes). We send transactional emails — invites, confirmations, password resets — because the product doesn't work without them. We don't send marketing without asking first, we don't sell personal data, we don't run ads, and we don't use your content to train AI models.
04Connected calendars
When you connect Google Calendar (and, when available, Microsoft Outlook), we sync your events to build your unified diary and catch clashes. The authorisation tokens that make this possible are stored server-side in a locked table that no browser session can read. Disconnecting a calendar deletes the synced data and our access.
Calmer Days Ahead's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
05If you sent someone a call request
Our users can share a public link where anyone may request a call with them. If you use one, the details you provide — your name, how to reach you, and the shape of your ask — are stored so the recipient can respond, and are used for nothing else. To have a request corrected or deleted, ask the person you sent it to, or write to us directly.
06Who we share it with
| Provider | Role | Certifications |
|---|---|---|
| Supabase | Database, sign-in, file storage | SOC 2 Type 2 · ISO 27001 |
| Netlify | Hosting & delivery | SOC 2 Type 2 · ISO 27001 |
| Postmark | Transactional email | GDPR DPA |
| Google / Microsoft | Calendar sync — only when you connect them | Provider policies apply |
The live subprocessor list is maintained on our security page. We'd only ever disclose data beyond this list if the law genuinely required it, and we'd tell you unless legally prevented.
07Where it's stored
Application data is hosted in a single, fixed Supabase region and remains in-region. Where any provider processing involves transfers of EEA or UK personal data outside those areas, it takes place under GDPR-recognised safeguards such as Standard Contractual Clauses in our providers' data processing agreements.
08How long we keep it
Account and workspace data is kept for the life of your account and deleted within 30 days of account deletion. Synced calendar data is purged when you disconnect a calendar. Call requests are removed within 12 months, or 30 days after being actioned. Files are deleted with their project. Encrypted backups expire on a rolling cycle shortly after.
09Your rights
Wherever you are, you can ask us to access, correct, export, or delete your personal data, or to restrict or object to how we use it. Email privacy@calmerdaysahead.com; we'll verify it's you and respond within 30 days. If you're in the UK or EU, these are your rights under UK/EU GDPR, and you may also complain to a supervisory authority — in the UK, the Information Commissioner's Office (ICO).
10Cookies & storage
The app uses essential browser storage to keep your session alive and remember your settings. That's the list. If that ever changes, this section and a proper consent choice will arrive first.
11Security
Every table is protected by row-level security — the database, not just the application, enforces who can see what. Data is encrypted in transit (TLS) and at rest (AES-256). Calendar tokens are unreachable from any browser. The full picture, including our infrastructure providers' certifications and how to report a vulnerability, lives on the security page.
12Children
Calmer Days Ahead is not directed at children and we don't knowingly collect data from anyone under 16. If you believe we have, tell us and we'll delete it.
13Changes
We'll update this page when our practices change and update the date at the top. For material changes, we'll notify account holders by email or in the app before they take effect.
14Contact
Privacy questions and requests: privacy@calmerdaysahead.com
Security reports: security@calmerdaysahead.com
We Are Zacapa Ltd, 35 Emmeline Lodge, 27 Kingston Avenue, Leatherhead, England, KT22 7FU.