Política de privacidad actualizados: La versión legal vigente se muestra en inglés a continuación. La traducción anterior se retiró para evitar contradicciones mientras se prepara una traducción revisada. En la medida permitida por la ley, la versión inglesa prevalece.
La analítica opcional permanece desactivada hasta que la aceptas en el banner de privacidad. Puedes cambiar esta elección en cualquier momento.
Privacy Policy
Effective Date: August 10, 2026
This Privacy Policy explains how Spacebrain Inc. (“Spacebrain,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information when you visit our websites, use the Spacebrain platform, connect an integration, use a public form or booking page, communicate with us, or otherwise interact with our services (collectively, the “Service”).
It also explains the choices and privacy rights available to account holders, Authorized Users, leads, contacts, communication recipients, form respondents, webinar attendees, Booking Hosts, Booking Visitors, and other individuals whose information is processed through the Service.
1. Who we are
Spacebrain Inc.
225 Railway St E., Suite #360
Cochrane, Alberta, T4C 2C3
Canada
Spacebrain Inc. is incorporated federally in Canada. Our Privacy Officer can be reached at [email protected].
2. Scope and our role
This Policy applies to personal information processed by Spacebrain through the Service and our business operations. It does not govern a third-party website, calendar, meeting provider, payment provider, or other service that publishes its own privacy policy.
When Spacebrain decides why and how information is processed, such as for account administration, billing, product security, our websites, support, and our own business analytics, Spacebrain is the controller or organization responsible for that information.
When a Customer uses the Service to process its own contacts, communications, forms, calendar connections, bookings, or other Customer Data, the Customer generally decides the business purpose and Spacebrain processes the information on the Customer’s behalf. In that context, the Customer is the controller or responsible organization and Spacebrain is its processor or service provider. Our Terms of Service, including its Data Processing Addendum, govern that processing.
If you interact with one of our Customers—such as by booking an appointment or completing a form—the Customer’s privacy notice also applies to its use of your information. Contact that Customer first about its business purpose or decisions; you may also contact Spacebrain using the details below.
3. Personal information we collect
3.1 Information you provide directly
- Account and identity information: name, business email, telephone number, company, role, account identifiers, profile, authentication information, locale, preferences, and Authorized User details.
- Billing and transaction information: billing contact, address, tax information, plan, invoices, transaction status, and limited payment-method details supplied by our payment processor. Spacebrain does not store complete payment-card numbers.
- Customer Data and content: contacts, CRM records, files, prompts, instructions, forms, responses, funnels, tasks, messages, emails, social content, call information, recordings or transcripts when enabled, webinar data, support content, and information placed in configured workflows.
- Communications: messages and attachments you send to support, sales, privacy, or security teams; survey responses; feedback; and records of our relationship.
- Public-page information: information submitted through a public form, funnel, webinar registration, widget, or booking page, including name, contact details, responses, appointment purpose, preferences, time zone, and other fields selected by the Customer.
3.2 Calendar and scheduling information
When the Calendar module or a calendar integration is used, we may process:
- connected-account identifiers, provider, email address, calendars selected for conflict checking, and authorization status;
- OAuth access and refresh tokens or equivalent credentials;
- an opaque Calendar relay address assigned to a Booking Host and workspace so operational messages and replies can be routed to the host’s current Spacebrain account address without copying that account address into the scheduling service;
- calendar names, availability, free/busy blocks, working hours, time zones, event identifiers, event titles or descriptions where the selected feature requires them, locations, attendees, organizer information, recurrence, and event status;
- event types, booking-page settings, routing or qualification answers, booking and cancellation timestamps, rescheduling history, meeting links, reminders, and delivery status; and
- Booking Visitor name, email, telephone number, time zone, IP address and device information, responses, notes voluntarily submitted, and appointment communications.
We seek to use the narrowest provider permission that supports the feature. The exact data depends on the calendar provider, permission granted, and configuration selected by the Booking Host.
3.3 Information collected automatically
- Device and network data: IP address, browser, operating system, device type, language, referring URL, approximate region derived from IP, and identifiers associated with cookies or similar technology.
- Usage data: pages and features viewed, actions taken, timestamps, session duration, navigation, integration status, API usage, plan and entitlement checks, and interaction with emails or public pages.
- Security and diagnostic data: authentication events, audit records, request metadata, crash and error information, performance data, webhook and delivery status, rate-limit events, suspected abuse, and technical logs.
3.4 Information from Customers and third parties
Customers may provide information about their personnel, customers, prospects, contacts, attendees, or communication recipients. We may receive information from connected services at the Customer’s direction, including Google, Microsoft, Zoom, social networks, email services, payment providers, meeting providers, advertising platforms, and other integrations. We may also receive business-contact or account-verification information from lawful public or commercial sources where a Service feature requires it.
4. Why we process personal information
We process personal information for the following purposes:
- Provide and administer the Service: create accounts, authenticate users, provide requested features, synchronize integrations, process bookings, route forms, perform configured workflows, deliver communications, and provide support.
- Perform our contract: manage plans, entitlements, usage, payments, invoices, renewals, support, and the customer relationship.
- Secure the Service: prevent fraud and abuse, verify requests and webhooks, protect accounts and tenants, detect incidents, troubleshoot, maintain backups, enforce policies, and preserve integrity and availability.
- Improve and understand the Service: analyze feature adoption and performance, debug, conduct research using aggregated or de-identified data, and develop improvements consistent with user expectations and provider restrictions.
- Communicate: send account, transaction, security, booking, support, and legal notices; and send marketing where permitted and subject to opt-out rights.
- Comply with law and protect rights: meet tax, accounting, privacy, sanctions, legal-process, recordkeeping, and regulatory obligations; establish or defend legal claims; and protect individuals, Spacebrain, Customers, and the public.
- At a Customer’s direction: process Customer Personal Data under the Customer’s documented instructions and Data Processing Addendum.
Legal grounds
Canada: We identify reasonable purposes before or at collection, obtain meaningful consent where required, and otherwise collect, use, or disclose personal information as permitted or required by PIPEDA, Alberta’s Personal Information Protection Act, and other applicable Canadian privacy laws. We do not rely on European “legitimate interests” terminology as a substitute for consent where Canadian law requires consent.
European Economic Area and United Kingdom: Where applicable, our legal grounds are performance of a contract; compliance with legal obligations; consent, which may be withdrawn; and legitimate interests such as securing, supporting, and improving the Service, preventing fraud, and managing our business, where those interests are not overridden by individual rights. Customer determines the legal ground for Customer Personal Data that it controls.
Other regions: We process information with consent or under another basis recognized by applicable law. Where law requires a more specific notice or consent, we will provide it at the relevant collection point.
5. Calendar module and public bookings
5.1 Booking Hosts
A Booking Host chooses its availability, event types, questions, routing, connected calendars, communication settings, and appointment purpose. We use Calendar Data to check conflicts, offer times, create or update events, generate meeting links, send operational messages, and manage cancellation or rescheduling. We do not expose the details of a private conflicting event to a Booking Visitor merely to show that a time is unavailable.
5.2 Booking Visitors
When you book with a Booking Host, information you submit is shared with that host and its permitted team members and integrations. The booking page should identify the host and provide or link to relevant privacy information. Spacebrain processes the information to provide and secure the scheduling service and for its limited controller purposes described in this Policy. Do not place sensitive information in a free-text booking field unless the Booking Host specifically requests it through an appropriate, lawful workflow.
5.3 Disconnecting a calendar
A Booking Host can disconnect a provider through available settings or the provider’s security controls. We then stop new API access using that authorization and delete or disable the corresponding token within the period described below. Events already created in an external calendar may remain there and must be managed with that provider or calendar owner.
5.4 Required in-product notices
This Policy supplements, but does not replace, concise notices shown at sensitive collection points. Before requesting a calendar permission or a Booking Visitor’s information, the Service will identify the data requested and the feature for which it is used where platform policy or applicable law requires a just-in-time notice.
6. Google Workspace and Microsoft data
6.1 Google Workspace API data
Spacebrain uses information received from Google Workspace APIs only to provide or improve prominent user-facing features that the user authorizes, such as Google Calendar availability and event management, Google Meet webinar or meeting features, and connected Gmail features. Spacebrain requests the narrowest practical scopes for the selected feature and provides controls to disconnect the account and request deletion.
Spacebrain’s use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell Google Workspace API data, use it for advertising, transfer it to data brokers, use it to determine creditworthiness, or use raw or derived Workspace data to create, train, or improve a generalized AI or machine-learning model. Human access is limited to documented user consent for a specific support purpose, security or abuse investigation, legal obligations, or appropriately aggregated and de-identified internal operations, as permitted by Google’s policy.
6.2 Microsoft data
For Microsoft identity, Outlook, Calendar, Teams, and Graph integrations, we disclose the permissions requested in the consent experience and use the resulting data only for the selected user-facing features, security, support, and lawful obligations. Users can revoke consent through Spacebrain settings where available or their Microsoft account or organization administrator. Microsoft may independently process information under Microsoft’s own privacy statement and terms.
7. AI processing
When a Customer invokes an AI feature, Spacebrain may transmit the minimum content reasonably needed for that request to the configured AI provider. This can include prompts, messages, documents, CRM context, meeting or call content, or other Customer Data selected for the workflow. The Customer determines whether to enable the feature and is responsible for lawful instructions and human review.
Spacebrain does not use Customer content to train a generalized Spacebrain model unless we first provide a separate clear notice and obtain any consent required by law and contract. We do not use Google Workspace API data for generalized model training. We may use de-identified, aggregated operational metrics that cannot reasonably identify a person or Customer to measure and improve reliability.
8. Cookies, analytics, and session replay
We use essential cookies and similar technologies for authentication, security, preferences, load balancing, and core functionality. Where permitted—and with consent where required—we use analytics technologies to understand use, measure conversions, diagnose problems, and improve the Service.
Our analytics provider may process pseudonymous identifiers, page views, clicks, feature events, device and browser information, approximate region, and performance data. Session replay may capture visible interactions, but fields and routes likely to contain passwords, payment details, communications, form responses, calendar content, or other sensitive Customer Data must be masked or excluded. Analytics and replay are not intended to collect OAuth tokens, passwords, payment-card data, message bodies, call content, prompts, documents, or Booking Visitor answers.
You can manage non-essential cookies through our privacy preference controls. Where we are required to honor a browser-based opt-out signal, such as Global Privacy Control, we will do so for the relevant processing. Disabling non-essential analytics does not disable core account, booking, security, or transaction functions.
9. How we disclose personal information
We may disclose personal information to:
- Customers and their users: a Booking Host, account administrator, workspace member, agency, end customer, or other Customer-designated recipient when needed for the configured workflow.
- Connected services: calendar, meeting, email, social, advertising, payment, CRM, storage, or other providers that a Customer chooses to connect.
- Service providers and subprocessors: providers of cloud hosting, infrastructure, databases, content delivery, communications, email delivery, identity, payment, analytics, observability, support, AI, calendar sync, meeting, backup, and security services. Depending on enabled features, these may include providers such as Cloudflare, Hetzner, Stripe, Postmark, PostHog, Sentry, Telnyx, Ultravox, OpenAI, Anthropic, Google, Microsoft, and Zoom. A current subprocessor list is available on request.
- Professional advisers: auditors, accountants, insurers, lawyers, and consultants subject to confidentiality duties.
- Authorities and affected parties: when reasonably necessary to comply with law or legal process, protect rights and safety, investigate abuse, respond to an emergency, or establish or defend claims.
- Business transactions: potential or actual parties and advisers in a financing, merger, acquisition, reorganization, or sale, subject to appropriate confidentiality and lawful-use restrictions.
We require processors and subprocessors to protect personal information and use it only for authorized purposes. Some connected providers act independently under their own terms rather than solely as Spacebrain’s processor.
10. No sale or behavioural-advertising sharing
Spacebrain does not sell personal information for money. We do not share personal information for cross-context behavioural advertising or targeted advertising based on activity across unaffiliated services. We do not use Booking Visitor information, Customer content, Calendar Data, or Google Workspace API data for advertising. If these practices change, we will update this Policy and provide any required notice and opt-out before the change applies.
10.1 Supplemental United States state notice
During the preceding 12 months, depending on the features used, Spacebrain may have collected the following statutory categories: identifiers; customer-record information; commercial and transaction information; internet or other electronic-network activity; approximate geolocation; audio, electronic, visual, or similar information; professional or employment-related information; inferences used for product or security functions; and sensitive personal information such as account credentials or the content of communications where Spacebrain is not the intended recipient. Sections 3 and 4 describe the sources and purposes, Section 9 describes the categories of recipients to which information may be disclosed for business purposes, and Section 12 describes retention criteria.
Spacebrain does not use or disclose sensitive personal information to infer characteristics about an individual. Spacebrain has not sold personal information or shared it for cross-context behavioural advertising during the preceding 12 months. The rights in Section 15 apply where the relevant state law covers Spacebrain and the request.
11. International processing and transfers
Spacebrain is based in Canada. Personal information may be processed in Canada, the United States, the European Economic Area, and other countries where Spacebrain, Customers, connected providers, or subprocessors operate. Those countries may have different laws, and information may be accessible to courts, law enforcement, or national-security authorities under local law.
We use contractual, organizational, and technical safeguards appropriate to the transfer. Where required, these include adequacy decisions, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or International Data Transfer Agreement, and contractual protections for service providers outside Canada. The Data Processing Addendum contains additional transfer terms for Customer Personal Data.
12. Retention and deletion
We retain personal information only as long as reasonably necessary for the identified purpose, Customer instructions, the account relationship, security, dispute resolution, and legal obligations. Retention can vary by configuration and contract. Our default criteria and targets are:
- Account profiles and settings: while the account is active and ordinarily up to 12 months after closure where needed for reactivation, support, fraud prevention, or disputes; essential contract and consent records may be retained longer.
- Customer Data, bookings, and appointment records: while maintained by the Customer in an active account, then ordinarily deleted from active systems within 30 days after valid deletion instructions or termination, subject to contract and legal holds.
- Calendar credentials and OAuth tokens: while the connection is active, then revoked or disabled and deleted from active systems promptly, ordinarily within 30 days after disconnection or account termination.
- Temporary availability, free/busy, and synchronization data: only as long as needed to perform and troubleshoot synchronization, generally on a rolling basis and ordinarily no longer than 30 days unless it becomes part of a booking record.
- Billing, tax, and transaction records: generally seven years or the period required by applicable tax, accounting, and anti-fraud law.
- Support records: ordinarily two years after resolution, unless needed for an ongoing relationship or dispute.
- Security, audit, and diagnostic logs: ordinarily up to 90 days, with selected security or audit records retained up to 12 months or longer when needed to investigate an incident or meet a legal obligation.
- Product analytics: ordinarily up to 12 months; session replay, where enabled with required consent, ordinarily up to 30 days.
- Backups: deleted or overwritten on a protected rotation, ordinarily within 90 days, and isolated from ordinary use until deletion.
We may retain de-identified information that cannot reasonably identify a person. A Customer may establish a different lawful retention period for data it controls. Deleting information from Spacebrain does not delete a copy already delivered to a Customer, Booking Host, recipient, or connected third-party service.
13. Security
We use administrative, technical, and organizational safeguards designed for the sensitivity and risk of the information. Depending on the system, these include access controls, authentication and credential management, tenant separation, encryption in transit, risk-appropriate encryption at rest, secure development and deployment practices, logging and monitoring, backups, vulnerability management, incident response, vendor diligence, and personnel confidentiality obligations.
No internet transmission or storage system is completely secure. You are responsible for using strong authentication, controlling Authorized Users and integrations, protecting endpoints, granting minimum permissions, and promptly reporting suspected compromise to [email protected].
14. Privacy and security incidents
We maintain an incident-response process to contain, investigate, mitigate, remediate, and document suspected breaches. We notify affected Customers, individuals, regulators, or other organizations when required by applicable law and contract. Under Canadian law this can include reporting a breach that creates a real risk of significant harm and maintaining required breach records. Where Spacebrain acts as a processor, we notify the responsible Customer as described in the Data Processing Addendum.
15. Your privacy rights
Depending on where you live and our role, you may have the right to:
- know whether and how we process your personal information and receive a copy;
- correct inaccurate or incomplete information;
- request deletion, anonymization, restriction, or cessation of processing;
- withdraw consent, subject to legal or contractual limits and reasonable notice;
- object to processing based on legitimate interests or to direct marketing;
- receive certain information in a structured, commonly used, machine-readable format and request portability where applicable;
- request information about automated decision-making and, where applicable, human review;
- request de-indexation or re-indexation in circumstances recognized by Québec law;
- opt out of sale, behavioural-advertising sharing, or certain profiling where applicable—although Spacebrain does not currently engage in sale or cross-context behavioural-advertising sharing;
- limit certain uses of sensitive personal information where applicable; and
- complain to a privacy regulator and not be discriminated against for exercising a right.
15.1 How to submit a request
Email our Privacy Officer at [email protected] with the subject “Privacy Request.” Describe the right and account, workspace, booking, email address, or interaction involved. We may request information reasonably necessary to verify identity and authority. An authorized agent may submit a request where law permits, subject to proof of authorization.
We will respond within the period required by applicable law, generally within 30 days under Canadian law and one month under the GDPR, subject to permitted extensions. If we deny a request, we will explain the applicable reason and appeal or complaint route where required. We do not charge a fee unless law permits one for a manifestly unfounded, excessive, or repetitive request.
15.2 Customer-controlled information
If your information was submitted by a Spacebrain Customer, Booking Host, employer, or organization, contact that organization first because it controls the business purpose and may need to respond. We will assist it as required. Spacebrain may still respond directly regarding information we control for our own purposes.
15.3 Complaints
We encourage you to contact our Privacy Officer first. You may also complain to the Office of the Privacy Commissioner of Canada, the Office of the Information and Privacy Commissioner of Alberta, the Commission d’accès à l’information du Québec, a European or UK supervisory authority, a United States state privacy authority, or another regulator with jurisdiction over your concern.
16. Automated decisions
Spacebrain may use automated systems for fraud detection, abuse prevention, security, routing, scoring, scheduling suggestions, and product features. Spacebrain does not use solely automated processing for its own decisions that produce legal or similarly significant effects about an individual. Customers may configure automated workflows and are responsible for required notice, lawful basis, testing, human review, and appeal rights. Where applicable, you may request information about the principal factors and human review.
17. Children
Spacebrain accounts are for business users who are at least 18. The Service is not directed to children under 13, and public booking pages are not designed to solicit children’s personal information. Customers must not intentionally use the Service to collect personal information from children under 13—or a higher age where local law requires parental consent—without Spacebrain’s prior written approval and a compliant parental-consent program. If we learn that information was collected from a child in violation of this section, we will take reasonable steps to delete or return it and disable the affected workflow.
18. Third-party links and services
The Service may link to or interoperate with third-party services. Their privacy practices apply to information they process independently. Review the provider’s terms and privacy settings before connecting it. A Customer’s booking page, product, professional service, or external website is also governed by that Customer’s practices, not solely by this Policy.
19. Changes to this Policy
We may update this Policy to reflect product, legal, security, or operational changes. We will post the revised Policy and effective date. If a change materially affects how we use information already collected, we will provide reasonable advance notice and obtain consent where law requires it. We will not use information for a materially incompatible new purpose without the notice or consent required by law.
20. Contact us
Privacy Officer
Spacebrain Inc.
225 Railway St E., Suite #360
Cochrane, Alberta, T4C 2C3
Canada
Email: [email protected]
This Policy is provided in English. A translation is for convenience unless mandatory law requires otherwise. To the extent permitted by law, the English version controls if translations conflict.