This Privacy Policy explains what personal data Empi collects, why we collect it, who processes it on our behalf, and the rights you have. It applies to the Empi website and Service. For a focused summary of your rights under the GDPR, see our GDPR notice.
1. Who is responsible
The data controller is Empi, France. For any privacy question, contact [email protected].
2. Data we collect
- Account data: email address, name, password hash (or your identity provider's token if you sign in with a partner), language and theme preferences.
- Your Content: tasks, notes, projects, comments, and similar material you create.
- Calendar data: when you connect Google Calendar or Microsoft 365, the events and availability needed to compute your capacity.
- Booking data: when you request a meeting through a public Empi booking page, the organizer, purpose, date and time, your name and email address, any form answers, additional guests, consent evidence, and files you choose to provide.
- Billing data: plan, billing country, and the limited payment metadata our payment processor returns. We do not store full card numbers.
- Usage and device data: log data, approximate location from IP, device and browser type, and product analytics events.
Google Calendar data
When you choose to connect Google Calendar, Empi reads your calendars and events to show availability, calculate capacity, and schedule tasks around existing commitments. Empi creates, updates, or deletes only reservation events that you explicitly ask Empi to schedule, and only in the calendar you select.
Google Calendar data and OAuth credentials are retained only as needed to provide the connected-calendar feature and are subject to the retention rules in section 7. OAuth credentials are encrypted at rest. Empi does not sell Google user data, use it for advertising, or use it to train models. We do not transfer Google user data to third parties except to provide the connected-calendar feature through our contracted service providers, at your direction, or where necessary for security or to comply with law. Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.
Empi for Gmail browser extension
The Empi for Gmail Chrome extension reads the subject, Gmail permalink, visible email body, and any visible Gmail AI overview from the message open in your browser. This data stays in the extension until you explicitly create an Empi task or note. Before sending it, you can choose the source and edit the title and content.
- Data sent to Empi: the title, selected or edited email content, Gmail permalink, whether you create a task or note, and the Empi properties you select.
- Data stored in Chrome: a revocable Empi access token, the Empi service address, and the connection time. The token is used only to load your available Empi properties and create the item you request.
- Retention: submitted email content becomes Your Content and follows the retention rules in section 7. The local connection remains until you disconnect it in Empi or remove the extension.
The extension does not use the Gmail API, continuously transmit your mailbox, sell email data, or use it for advertising. Empi uses the submitted data only to provide, secure, and support the email-capture feature, subject to the limited exceptions required by law or security described in this Policy.
3. Why we use it and our legal bases
- To provide the Service (perform our contract with you): run your account, store and sync Your Content, schedule your week, connect your calendar.
- To process a meeting request (steps requested by you and performance of the booking service): check availability, create the meeting and invitation, notify its participants, and let you reschedule, cancel, export, or erase the request.
- To bill and prevent fraud (contract and legal obligation): process Subscriptions, taxes, and chargebacks.
- To secure and improve the Service (legitimate interests): diagnostics, abuse prevention, aggregated analytics. We balance these against your rights.
- Communications and non-essential analytics (consent, where required): product emails you can opt out of, and analytics or cookies that need consent.
4. Processors and sub-processors
We use a small set of vetted providers to run the Service. They process data only on our instructions and under data-processing agreements.
| Provider | Purpose | Region |
|---|---|---|
| Scaleway | Hosting, key management (KMS), object storage | EU (France) |
| Google Calendar integration; route estimates for commute buffers | EU / US (SCCs) | |
| Microsoft | Microsoft 365 calendar integration | EU / US (SCCs) |
| Clerk | Authentication, when you sign in with a partner identity | EU |
| PostHog | Product analytics | EU |
| Sentry | Error monitoring | EU |
This list may change as the Service evolves. We keep an up-to-date list and will give notice of material changes.
5. How we protect your data
Your task and note content, including Google OAuth credentials, is encrypted at rest using per-tenant envelope encryption: a per-tenant key, wrapped by a master key held in our key management service, with AES-256-GCM on the stored fields. Each Workspace is isolated at the database boundary so one tenant cannot read another's data. Access to production systems is restricted and logged.
Booking identities, answers, consent evidence, private locations and filenames use the same per-tenant encryption. Uploaded booking files remain private, are checked by file signature and antivirus scanning before attachment, and are served only as downloads to an authorised organizer or through a valid booking management request. Public booking pages do not load marketing analytics.
6. International transfers
Your data is hosted in the European Union. Where a processor is outside the EU/EEA, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses, with additional safeguards where appropriate.
7. Retention
We keep Your Content while your account is active. If your account stays inactive for an extended period (around three months with no sign-in), we email you one or more advance warnings and then delete the account and its content; signing in at any time keeps the account active and stops the deletion. When you delete content or close your account, we delete or anonymise it within a reasonable period, except for backups (kept for a limited window) and records we must retain by law (for example, invoices). Where you request a GDPR crypto-shred, the tenant key is destroyed and the corresponding ciphertext becomes permanently unrecoverable, backups included.
Public booking data is kept by default for 12 months after the meeting. The organizer may instead choose 30 days, 90 days, 6 months, 12 months, or 24 months; the selected period is shown before confirmation. After that deadline we erase the guest identity, answers, consent evidence, private location, management token, and attached files. Unattached upload staging expires after one hour. A guest may also erase the booking data earlier with the secret management link.
8. Cookies and local storage
We use strictly necessary cookies and browser storage to keep you signed in and to
remember your theme (empi_theme) and language (empi_lang).
Non-essential analytics or cookies are used only with your consent where required.
9. Your rights
Subject to the GDPR, you have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent. Our GDPR notice explains each right and how to exercise it. Contact [email protected].
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
11. Changes
We may update this Policy. For material changes we will give reasonable notice. The "last updated" date above reflects the current version.
x12. Contact
Empi, France. Privacy: [email protected].