PRIVACY POLICY

A clear account of how we handle personal data.

Effective date: 3 October 2026

Version: 1.1

On this page

1. Who is responsible for your personal data?

HL Sverige AB, organisation number 556885-8715, is the controller for the personal data described in this policy. Address: Finspångsvägen 131, 602 10 Norrköping, Sweden Privacy contact: privacy@timecue.eu timecue is the product name used on this website. It is not a separate legal entity.

This Privacy Policy applies when you browse the timecue website, submit a contact or pilot form, sign up for product updates, book a meeting, or email us.

2. What data do we use, why, and on what basis?

PurposeData we may useLegal basis
Review contact and pilot requests Name, email, company, country, topic, message and the optional details you submit, the privacy-notice version you acknowledged and its timestamp, and your marketing choice. Our legitimate interest in receiving and answering business enquiries (GDPR Art. 6(1)(f)), and steps at your request before a possible pilot agreement (Art. 6(1)(b)).
Arrange a meeting you book Name, email, optional company and message, chosen host, date, time and time zone, the Google Meet link, and the status of the booking. Steps at your request before a possible agreement (Art. 6(1)(b)) and our legitimate interest in organising the meeting (Art. 6(1)(f)).
Send product updates Email address, language, where you signed up, the consent text version and the time you gave consent. Your consent (Art. 6(1)(a)), which you can withdraw at any time.
Prevent spam and abuse Technical data processed by Cloudflare Turnstile to check that a submission comes from a person, including your IP address and browser signals, and short-lived counters keyed by a one-way hash of your IP address or email. Our legitimate interest in protecting the forms, the booking service and our users (Art. 6(1)(f)).
Operate and secure the website and services IP address, requested page, time, browser or device information and security events in technically necessary server logs. Our legitimate interest in delivering, securing and troubleshooting the website (Art. 6(1)(f)).
Handle privacy and security requests Contact details, the content of your request, information reasonably needed to verify your identity, and our response. Our legal obligations under data-protection law (Art. 6(1)(c)).

3. Where the data comes from

We receive personal data directly from you when you submit a form, sign up for product updates, book a meeting or email us. Cloudflare Turnstile processes limited technical data when you submit a form or a booking, and our hosting providers create technically necessary server and security logs.

4. What information is required?

Forms and bookings require the fields marked as required, including a working email address. Contact and pilot forms also require your acknowledgement of this policy so we can review and answer the request. Without that information we cannot answer you or arrange the meeting. Product updates are optional. Please do not submit passwords, access tokens, payment-card details, sensitive personal data, customer records or confidential project documents.

5. Cookies and similar technologies

The website does not use analytics, advertising pixels, session replay or non-essential cookies, so it does not show a cookie banner. Fonts are served from our own website. When you book a meeting, your browser’s session storage keeps the booking in progress and your private management link for that session, so the booking is not lost or sent twice; it is cleared when you close the tab. Cloudflare Turnstile checks submissions without setting tracking cookies. We will ask for consent before using any technology that requires it.

6. Who receives the data?

Access within our team is limited to the people who handle your request or host your meeting. The website and business email are provided by cal.pl, operated by INFOCAL sp. z o.o. in Poland. Form submissions and bookings are stored by the timecue application on servers operated for us by our hosting provider. Files and encrypted database backups are stored with Cloudflare R2 in Cloudflare's EU jurisdiction. Cloudflare, Inc. processes Turnstile verification data. For meeting bookings, Google (Google Calendar and Google Meet) processes the booking details placed in the host's calendar event and sends the calendar invitation. Our email delivery provider sends booking confirmations and internal notifications. We may also disclose data where the law requires it or where necessary to establish, exercise or defend legal claims.

7. International transfers

Cloudflare, Inc. and Google LLC are based in the United States, and some service providers may process data outside the EU/EEA. Where that happens, we rely on the EU–US Data Privacy Framework for certified providers or on the European Commission’s standard contractual clauses, with supplementary measures where needed. You can ask us for more information about these safeguards at privacy@timecue.eu.

8. How long do we keep data?

We keep personal data only as long as needed for the purpose it was collected for, our legal obligations and the establishment or defence of legal claims.

DataRetention period
Contact and pilot requests Up to 12 months after our last meaningful exchange, then deleted, unless a longer period is needed for a legal obligation or a legal claim.
Meeting bookings Up to 12 months after the meeting date, then deleted. The same period applies to the calendar entry in the host’s work calendar.
Product-update subscriptions Until you unsubscribe or withdraw consent. After that we keep only your email address on a suppression list, so we do not contact you again.
Anti-abuse counters Between 15 minutes and 24 hours. They contain only one-way hashes, not your IP address or email.
Server and security logs For a limited period needed for security and troubleshooting, then deleted or overwritten.
Encrypted backups Overwritten on a rolling 30-day cycle, so deleted data can remain in a backup for up to 30 days.
Privacy and legal requests Up to 3 years after the request is closed, or longer only where needed to establish, exercise or defend a legal claim or to comply with law.

9. Your rights

Under the GDPR you have the right to information, access, rectification and erasure, to restrict processing, to object to processing based on legitimate interests, to data portability where it applies, and to withdraw consent at any time without affecting earlier processing. You can always object to direct marketing. To exercise a right, or to stop product updates, email privacy@timecue.eu. Each product-update message will also contain an unsubscribe link. We may ask only for information reasonably needed to verify your identity, and we normally respond within one month. You can lodge a complaint with the Swedish Authority for Privacy Protection (IMY): https://www.imy.se/privatperson/utfora-arenden/lamna-ett-klagomal/, or with the authority where you live or work, for example the Polish UODO: https://uodo.gov.pl/pl/138/155.

10. Automated decisions and AI

We do not make decisions with legal or similarly significant effects solely by automated means. People at timecue review every pilot request and booking. The website and the current product do not use AI scoring, worker monitoring or automated recommendations about you. If we introduce such features, we will update this policy before they go live.

11. Security

We use technical and organisational measures suited to the risk, including encrypted connections, encrypted backups, access limited to the people who need it, and anti-abuse checks that store only hashed identifiers. No internet service is completely secure. To report a security concern, email privacy@timecue.eu.

12. Children

The website and pilot are intended for people acting in a professional or business context, not for children. We do not knowingly collect children's personal data.

13. Changes to this policy

We update this policy when our processing, providers, product or legal obligations change, and publish each new version with its effective date. If a change affects processing based on your consent, we will ask for new consent where required. We keep earlier versions on record.

14. Contact

Questions or requests about this policy may be sent to: HL Sverige AB Finspångsvägen 131 602 10 Norrköping Sweden privacy@timecue.eu

Back to top
01 / 03

Who would you like to meet?

Who would you like to meet?