Legal

Privacy Policy

Last updated 29 July 2026

This policy explains what personal data SystemOS collects when you use the service, why we process it, who we share it with, and the rights you have over it.

1. Who we are

SystemOS is operated by Boardly Systems OÜ, the controller of the personal data described here.

Company
Boardly Systems OÜ
Address
Tartu mnt 67/1-13b, 10115 Tallinn, Estonia
Registry code
17561458 (Estonian Business Register)
Contact
hello@board.ly

For any question about your data, or to exercise the rights in section 8, email us at the address above.

2. What we collect

  • Account data— your name, email address, a hashed password, and your organisation’s details.
  • Workspace content— the clients, intake forms, quotes, invoices, contracts, notes, files and finance records you create. This can include personal data about your own clients. For that content you are the controller and we act as your processor.
  • Payment data— handled by Stripe. We store your Stripe customer and subscription identifiers and your plan status; we never see or store full card numbers.
  • Connected Google Calendar data— only if you choose to connect it (see section 4).
  • Usage and technical data— log entries, IP address, browser and device information, and the actions you take, used to run and secure the service.
  • Cookies— essential session cookies only. We do not use advertising or cross-site tracking cookies.

3. Why we process it, and on what legal basis

  • To provide the service and your account — performance of a contract (Art. 6(1)(b) GDPR).
  • To bill you and keep accounting records — contract and legal obligation (Art. 6(1)(b) and (c)).
  • To secure the service, prevent abuse and keep audit logs — legitimate interests (Art. 6(1)(f)).
  • To send you service emails such as confirmations and password resets — contract. Product or marketing emails are sent only with your consent where consent is required, and you can opt out at any time.

4. Google user data

Connecting your Google Calendar is optional and powers the scheduling features. When you connect it, we request two scopes and use them only as follows:

  • See your calendars and events (calendar.readonly) — to read your free/busy times and your list of calendars, so your public booking page offers a slot only when you are actually available.
  • Create and manage events (calendar.events) — to place a booking on your calendar (with a Google Meet link) when a client books a call, and to update or cancel that event.

The access and refresh tokens Google issues are encrypted at rest. We use your Google data solely for the scheduling features above. We do not use it for advertising, we do not sell it, we do not share it with third parties, and we do not use it to train machine-learning or AI models.

SystemOS’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect at any time in your SystemOS settings, or revoke access directly at myaccount.google.com/permissions. Disconnecting deletes the stored tokens.

5. Who we share data with

We share data only with the processors we need to run the service, each under a data- processing agreement. We do not sell personal data.

  • Vercel — application hosting and delivery.
  • Neon — the managed PostgreSQL database that stores your workspace.
  • Amazon Web Services (SES) — delivery of transactional email.
  • Stripe — payment processing and subscription billing.
  • Anthropic— the AI features (for example, reading an uploaded receipt or PDF). Only the content you submit to an AI feature is sent, and it is not used to train their models.
  • Google — calendar integration, only if you connect it (see section 4).

6. International transfers

Some of these providers process data outside the European Economic Area, including in the United States. Where data leaves the EEA, the transfer is covered by an adequacy decision or by the European Commission’s Standard Contractual Clauses.

7. How long we keep it

We keep your account and workspace data for as long as your account is active. After you delete your account we delete or anonymise your personal data within 30 days, except where the law requires us to keep certain records longer — invoices, for instance, are subject to statutory accounting retention. Encrypted calendar tokens are deleted as soon as you disconnect.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to processing;
  • data portability — you can export your entire workspace as JSON at any time from within the app;
  • withdraw consent where processing is based on it.

To exercise any of these, email hello@board.ly. You also have the right to lodge a complaint with a supervisory authority — in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon) — or with the authority in your own country.

9. Security

Data is encrypted in transit (TLS) and at rest. Passwords are hashed, connected calendar tokens are encrypted separately, and every record is scoped to your workspace so one organisation can never read another’s data.

10. Children

SystemOS is a business tool and is not directed at children under 16. We do not knowingly collect their data.

11. Changes to this policy

We may update this policy from time to time. We will change the “last updated” date above, and for material changes we will notify you in the app or by email.

12. Contact

Boardly Systems OÜ · Tartu mnt 67/1-13b, 10115 Tallinn, Estonia · hello@board.ly

Questions about this page? Email hello@board.ly. See also Privacy, Terms and Imprint.