Getholda
Home

Privacy Policy

Last updated: 13 July 2026

1. Who we are

Getholda is a booking and practice-management tool for independent therapists and coaches, operated by Nikolaj Saslawski, sole proprietor (Einzelunternehmer), Derfflingerstr. 46, 40470 Düsseldorf, Germany. Contact: [email protected]. This English policy summarises how we handle data; our German Datenschutzerklärung is the binding version for EU/GDPR purposes.

2. What we process and why

We process personal data only as needed to provide the service: account and profile data (name, optional username), appointment and booking data, notes a professional enters about their own clients and sessions, communication and reminder data, and technical access data (e.g. IP address, time, browser). Legal bases are contract performance, our legitimate interest in a secure, working service, and, where applicable, your consent.

3. Sign-in via Telegram

Sign-in uses Telegram login / the Telegram bot. We receive the account data Telegram transmits (Telegram ID, first name, optional last name and username). Telegram is responsible for its own processing.

4. Payments (Stripe)

Subscription payments are handled by Stripe. Only the data required for payment is transmitted to and processed by Stripe. We do not store full card data. See stripe.com/privacy.

5. Google Calendar / Google Meet (optional)

If a professional connects their Google account, we use the OAuth access they grant to write appointments to their Google Calendar and, where applicable, generate Google Meet links. We request the openid and email scopes (to identify the connected account) and the https://www.googleapis.com/auth/calendar.events scope (to create and manage the session events we generate). Access tokens are stored encrypted (AES-256-GCM). The connection can be revoked at any time in Getholda or at myaccount.google.com/connections.

Sharing, transfer and disclosure of Google user data. We do not sell, rent, or share Google user data (OAuth tokens, the connected account's email address, or calendar event identifiers) with any third parties, and we do not use it for advertising, profiling, or any purpose other than providing the calendar features described above. This data is stored on our own server in Germany and is transmitted only to Google's APIs. The only parties that technically process it on our behalf are our infrastructure providers — the hosting provider of our server and Cloudflare (acting as network proxy/CDN) — strictly as processors under data-processing agreements; they do not access or use this data for their own purposes. We would disclose data to public authorities only where required by applicable law.

Getholda's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Retention and deletion of Google user data. If you disconnect Google or delete your account, we delete the stored OAuth tokens; calendar events already created remain in your own Google Calendar under your control. You can also request deletion at any time via [email protected].

6. Zoom (optional)

If a professional connects their Zoom account, we use the OAuth access they grant to Getholda to:

From Zoom we store only the meeting ID and join URL, linked to the relevant booking, and the professional's OAuth refresh token, which is stored encrypted at rest (AES-256-GCM). We do not access, request or store meeting recordings, transcripts, participant lists or meeting content, and we do not use Zoom data for advertising or profiling.

Disconnecting / deauthorization. The professional can disconnect Zoom at any time in Getholda, or remove the app from the Zoom App Marketplace. On either event we delete the stored Zoom OAuth token and stop creating meetings for that account. When Zoom notifies us of a deauthorization, we delete the associated Zoom data we hold and confirm compliance back to Zoom.

7. Hosting, Cloudflare and security

The platform runs on a dedicated server behind Cloudflare as reverse proxy/CDN, which processes technical connection data (including IP addresses). Sensitive text content (client and session notes, questionnaire answers, signed agreements) is stored encrypted with AES-256. Backups are kept encrypted and off the main server.

For traffic measurement we use Cloudflare Web Analytics — a cookieless, anonymised statistic that does not track individual visitors or build user profiles; we only see aggregated figures (page views, referrers, countries, device types). No consent banner is required as no cookies are set and no personal data is collected. In addition, we count page visits on our own server; only the date, referral source (where the browser provides one), country (as reported by Cloudflare), pages opened, time spent on them and device type are stored. Page views within one visit are linked by a random session number that is not stored in the browser, cannot be traced back to an IP address or a person, and expires after 30 minutes of inactivity. No IP addresses, device identifiers or cookies are kept for this.

8. International transfers

Some providers (e.g. Telegram, Google, Zoom, Stripe, Cloudflare) may process data outside the EU/EEA. Where they do, transfers rely on appropriate safeguards, in particular EU Standard Contractual Clauses or a valid adequacy decision.

9. Retention

We keep personal data only as long as needed for the purposes described or as required by law. After the purpose ends or an account is deleted, data is deleted unless legal obligations require otherwise.

10. Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction, data portability and objection, and you may withdraw consent at any time with future effect. To exercise your rights, email [email protected]. You also have the right to lodge a complaint with a data-protection supervisory authority.

11. Role regarding client data

When a professional enters data about their own clients, that professional is the controller for such data and we act as a processor (Art. 28 GDPR). The data-processing agreement (AVV, Art. 28 GDPR) is part of the service contract and available online (German).

Terms of Use · Support · Zoom setup · Datenschutz (DE) · Home