AxerioBookAxerioBookSrpski

Privacy Policy

Last updated: 2026.

Who we are and what this covers

AxerioBook is an online appointment scheduling system. The operator of the service is Axerio Web (“AxerioBook”, “we”). For data-protection questions, write to us at axerioweb@gmail.com.

This policy covers our website, the admin panel used by businesses, and the booking form their clients use to book appointments.

Controller and processor

  • For client data: the business is the controller and AxerioBook is the processor — we process it on the business's behalf and on its instructions.
  • For the business's own accounts (owner and staff): AxerioBook is the controller.

What data we collect

Business clients (booking form)

DataRequiredNote
First and last nameYes
Email / phoneDependsThe business chooses how clients are recognized
Booking noteNoFree text the client enters
Consent (GDPR)YesStored with every booking
Booking historyService, staff, location, date, price, status
Cancellations & no-showsSo the business can flag clients who often cancel; such a client can be blocked

Business accounts: name, email, role and permissions, working hours and password (stored hashed — we never see it in readable form).

Technical data: temporary rate-limit records tied to an IP address (self-deleting), error logs, and cookies strictly necessary for session and security. No third-party marketing or analytics cookies.

Google data

If a business enables Google features, there are two separate and optional flows.

1. “Continue with Google” (client)

  • Scope: openid, email, profile — we read first name, last name and email.
  • Purpose: solely to fill the booking form fields and confirm the email is valid.
  • We store no Google token; the data is used once and the client sees it before submitting the booking.

2. Google Calendar (business and staff)

  • Scope: https://www.googleapis.com/auth/calendar — we store a refresh token and the selected calendar's ID, per staff member.
  • Purpose: we write a confirmed booking to the staff member's calendar, and delete it on cancellation.
  • Why the full “calendar” scope: the system must list existing calendars and create a new one when needed — the narrower permission (calendar.events) does not cover this.
  • You disconnect with one click in the panel; the token is then revoked at Google and deleted from our database.

AxerioBook's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We do not sell Google data, do not use it for advertising, do not share it with third parties (except to provide the service itself) and do not use it to train artificial-intelligence models.

Who we entrust with processing

We rely on trusted service providers that process data solely on our behalf:

  • Data storage and user authentication (a cloud database)
  • Application hosting
  • Sending email notifications
  • Google Calendar and Google sign-in — only if the business enables it
  • WhatsApp reminders — only if the business enables it

How long we keep data

  • Bookings and client history: while the business uses the service (reports up to 5 years back).
  • In-panel notifications: deleted after 7 days.
  • Rate-limit records: deleted on expiry.
  • Google refresh token: until the connection is broken or the account is closed.

Your rights

You have the right to access, rectification, erasure, restriction of processing, portability and objection.

If you are a business's client, you contact that business — it is the controller and has an anonymization button in the panel that irreversibly removes your personal data (bookings remain as an anonymous record for report accuracy). For platform questions, write to us at axerioweb@gmail.com. You may lodge a complaint with a supervisory authority: in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection; in the EU, your competent authority.

Security and cookies

Each business's data is isolated, communication runs over an encrypted (HTTPS) connection, and only authorized users can access data according to their roles. We use only cookies necessary for sign-in, session and security.

Data transfers and changes to this policy

Our service providers may process data on servers in the EU or other countries, with appropriate safeguards. We may update this policy from time to time; the date of the last change is shown at the top, and we notify users of significant changes.

Contact

Operator: Axerio Web

Email: axerioweb@gmail.com

Home
Privacy Policy | AxerioBook