Privacy Policy

Privacy, data minimization, and processor obligations.

Last updated: August 28, 2026

This Privacy Policy describes how visua.link collects, uses, and protects personal data of users of the platform. We aim to apply data minimization and strict security standards across the products that remain active in the platform.

1. Data Controller

Invoices are issued from Portugal under the operator's current tax registration.

2. Data Collected

We collect only the data needed to provide the service.

  • Profile and account information: name, email, Google profile photo via OAuth, country of residence, business details where provided, legal-document acceptance records, and the user's marketing communication preference.
  • Connection information: IP address and an approximate country derived from the request, including country information supplied by our network provider Cloudflare.
  • Usage Data: operational logs of actions inside the platform.
  • Visitor Data: IP address and device information for public pages, forms, bio pages, and booking flows.
  • Form and Booking Responses: submitted data from respondents and guests, subject to the restrictions described below.
  • Digital product and tip data: purchaser or supporter email address, delivery/download records, transaction identifiers, amount, currency, and payment status. Card details are processed directly by Stripe and are not stored by visua.link.
  • Marketing Contact Data: professional contact details, the source or event through which they were obtained, consent or lawful-basis evidence supplied with that source, delivery status, opt-out status, and campaign attribution events.

2.1 Privacy Mode for Forms and Bookings

visua.link does not allow storage of protected, sensitive, private, or intimate categories of data in Visualink-managed form or booking storage.

  • Privacy Mode switch: enable it when a form may collect protected categories.
  • Database restriction: Visualink-managed storage is disabled in those sensitive scenarios.
  • External storage: customers must use Google Sheets, webhooks, or other supported integrations for those workflows.

See our Data Processing Agreement (DPA) .

2.2 Booking Guest Data

When a third party (a "guest") makes a booking through a Booking Calendar published by one of our customers (the "host"), we process the following categories of personal data on behalf of the host:

  • Identification: name and email address (required), phone number (optional, requested only when the host activates it or when the booking location is "Phone call").
  • Scheduling metadata: selected time slot, guest timezone, and the calendar/host the booking is associated with.
  • Booking form answers: any additional fields the host has configured in the booking form.
  • Payment metadata (paid bookings only): Stripe payment intent ID and payment status. Card details are never seen or stored by visua.link — they are collected directly by Stripe.
  • Google Calendar event reference: the ID of the calendar event created in the host's connected Google Calendar.

For the purposes of this data, the host acts as Controller and visua.link acts as Processor, in line with section 11.2 of this Policy.

3. Google Integration and Permissions

We apply a least-privilege approach and request only the permissions required for the features you activate.

  • drive.file: used by the Google Sheets integration to create and write rows into spreadsheets that visua.link itself created on the user's behalf. visua.link cannot read or modify any other files in the user's Drive.
  • calendar.calendarlist.readonly: used by the Google Calendar integration to list the calendars the host is subscribed to and identify the host's primary calendar, which is the current destination for booking events. It does not provide access to calendar events.
  • calendar.events: used only after the host explicitly connects Google Calendar. Google grants access to view and edit events across the connected account's calendars; visua.link uses that access only to create booking events in the host's primary calendar, retrieve an event it has just created when necessary to obtain its Google Meet link, and delete booking events whose IDs visua.link stored when they are cancelled. Google does not offer a scope limited to events created by an application.

We do not request calendar.readonly, calendar.events.freebusy, or the broader calendar scope. We do not display, analyze, modify, or delete unrelated calendar events. Disconnecting Google Calendar from the dashboard removes the stored encrypted credentials from our systems. Users can revoke the application's Google access at any time in their Google Account settings.

For each booking event, we send Google the event title, date and time, location, guest name and email address, and the event description configured by the host. The description can include booking-form answers and a cancellation link when the host has configured those details. Google sends the attendee invitation and cancellation updates as part of the Calendar event.

3.1 Google Workspace API Limited Use Compliance

The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

visua.link does not use, transfer, or disclose raw or derived Google Workspace user data to create, train, or improve artificial intelligence or machine learning models.

The AI image-generation features available through visua.link are separate, user-initiated features. They receive only the prompt explicitly entered by the user, together with technical image-generation parameters added by visua.link, such as the required dimensions and aspect ratio for Open Graph images. They do not access or process data obtained through Google Workspace APIs.

4. Purpose and Legal Basis

  • Provide and maintain the service on the basis of contract execution.
  • Process the customer's subscription to visua.link via Stripe on the basis of contract execution.
  • Facilitate payments from booking guests, buyers, and supporters to customers via Stripe Connect, where the customer is the merchant of record and visua.link acts as a technical facilitator.
  • Send transactional emails to booking guests confirming or cancelling a reservation, on the basis of the legitimate interest of the host in completing the service the guest has requested.
  • Comply with tax and legal obligations on the basis of legal obligation.
  • Protect the platform against spam and abuse on the basis of legitimate interest.
  • Measure aggregated visits to our corporate site and public customer pages on the basis of our legitimate interest in understanding and improving the service.
  • Send marketing communications to registered users who have opted in, or to other contacts where the documented source establishes an applicable lawful basis, and maintain the preference or suppression records needed to respect each choice.

4.1 Marketing Communications and Attribution

Registered users may choose whether to receive commercial communications, promotions, and discounts from visua.link during onboarding, in account settings, or when prompted in the dashboard. This choice is optional, is stored with the account, and may be changed at any time in Account settings. Declining does not affect access to the service. Operational, security, billing, and other service messages are not marketing communications and may still be sent when necessary to provide the account.

A marketing contact may have been provided directly to visua.link or obtained from an event organizer or business partner whose notice covered the relevant disclosure and communication. Before activating a source, we record its origin and the supporting notice or consent evidence. The first message identifies visua.link and provides a direct way to stop further marketing messages.

Campaign links may contain a random attribution identifier. When a recipient follows such a link, visua.link stores that identifier in first-party browser storage for up to 90 days and records the landing path. If that visit results in a new account, the identifier associates the registration with the campaign and original recipient record even where the registration email differs. The identifier does not contain the recipient's email address. We do not need to place a tracking pixel in the message for this attribution.

Unsubscribing, objecting, or creating an account suppresses further acquisition emails to the relevant marketing contact. A minimal suppression record is retained so that the preference continues to be respected across later campaigns and imports.

5. Third-Party Services

We share data with service providers such as Cloudflare, Umami Cloud, Stripe, Google Cloud, Google reCAPTCHA, Amazon Web Services (Amazon SES), OpenAI, and Google Gemini where infrastructure or activated features require it.

5.1 Network Delivery and Security (Cloudflare)

Cloudflare helps deliver and protect visua.link. It may process request metadata such as IP address, device and network information, and an approximate country code. We use that country code to suggest an initial country of residence during account setup; users can review and change the stored country in Account settings.

5.2 Audience Measurement (Umami Cloud)

We use Umami Cloud to measure aggregated visits to the visua.link corporate site and public customer pages. Umami is configured without cookies, fingerprinting, visitor identification, or cross-site tracking. It receives limited technical and usage information needed to produce aggregate statistics, such as the page path (without query parameters), referrer, browser and device category, language, screen size, and approximate location derived from the request. We do not send names, email addresses, account identifiers, form responses, payment data, or other direct identifiers to Umami.

5.3 Email Delivery (Amazon SES)

We use Amazon Simple Email Service (Amazon SES) as a sub-processor to deliver transactional, notification, and authorized marketing emails (account, billing, security, and product communications). For this purpose, recipient email addresses, sender metadata, and the message content are processed by Amazon Web Services to enable delivery, bounce handling, and spam protection.

Email recipients include both registered users of visua.link and booking guests who have not signed up. Guests receive transactional emails (booking confirmation, cancellation, and any reminders) on the basis of the legitimate interest of the host in fulfilling the booking. Each email includes a link back to manage or cancel the booking, and a reply-to address pointing to visua.link.

We will never use booking guest email addresses for marketing communications merely because they completed a booking. If the same person independently appears in an approved marketing source, that separate source and its applicable lawful basis govern the communication.

5.4 Abuse and Spam Protection

We use a third-party service (reCAPTCHA) to protect our platform and your forms from spam, abuse, and automated attacks. This service may process user data as part of its operation. Such processing is strictly for the purpose of ensuring service security and integrity.

5.5 Payments (Stripe and Stripe Connect)

We use Stripe for two distinct purposes, with different legal roles:

  • Stripe (Visualink subscription): processes the customer's recurring subscription to visua.link. visua.link is the merchant of record. Stripe receives the customer's billing information and payment method details directly.
  • Stripe Connect (Bookings, Digital Products, and Tips): when a customer connects their Stripe account, the guest, buyer, or supporter payment is processed directly into that connected account. The customer is the merchant of record; visua.link acts only as a technical facilitator, does not receive or store card data, and processes the limited contact and transaction data needed for delivery, notification, fraud prevention, and platform operation. The customer is responsible for their privacy notice, tax obligations, and consumer-law disclosures.

6. International Data Transfers

Some data may be processed outside the EEA. In those cases, EU Standard Contractual Clauses or other approved safeguards apply.

7. Data Retention

Data is retained while the account remains active or while retention is legally required. When users cancel or close their account, visua.link may delete images, links, forms, and related records unless the law requires otherwise.

7.1 Booking Guest Data Retention

Data of booking guests is not "owned" by the host in the strict sense — the host acts as Controller, but the data subjects are third parties whose rights are independent of the host's account lifecycle.

  • While the host's account is active, guest data is retained for as long as it is operationally needed (i.e. for the host to manage and look back at their bookings).
  • When the host closes their account, guest records associated with past bookings are anonymized rather than deleted: the guest's name, email address, phone number, and free-text answers are replaced with non-reversible placeholders, while non-identifying scheduling and payment metadata (date, amount, currency, refund status) is preserved for the legally required period.
  • Guests may exercise their data subject rights (access, rectification, deletion, etc.) by contacting either the host directly or visua.link at the address in section 1, and we will route or fulfill the request as appropriate under section 11.6.

7.2 Conservazione dei dati degli acquirenti di prodotti digitali

Conserviamo l’email dell’acquirente, l’istantanea dell’acquisto, lo stato di consegna, i registri temporanei di accesso e l’attività di download necessari per consegnare il prodotto, consentire il recupero dell’accesso, gestire i reclami, prevenire gli abusi e documentare la transazione. Un record di acquisto può rimanere dopo che il creatore ritira o elimina il prodotto; la risorsa scaricabile potrebbe non essere più disponibile. I codici di accesso, le sessioni dell’acquirente e le autorizzazioni di download scadono automaticamente secondo i periodi indicati nel flusso del prodotto.

7.3 Conservazione dei contatti di marketing

Marketing source evidence, campaign delivery records, and attribution records are retained only for as long as needed to document and operate the communication or to establish, exercise, or defend legal claims. Suppression records may be retained longer in a minimized form because deleting them could cause an opted-out address to be contacted again.

A registered user's current marketing preference is retained with the account so that visua.link can apply and demonstrate the user's choice. When no choice has yet been made, the preference remains unset until the user answers.

8. User Rights

  • Access, rectify, or delete data
  • Request restriction or objection to processing
  • Request data portability

To exercise these rights, contact [email protected].

9. Security

We implement technical and organizational measures to protect data against loss, misuse, or unauthorized access.

9.1 Protection Mechanisms for Sensitive Data

  • Encryption in transit over HTTPS/TLS
  • Server-side credential handling for OAuth tokens
  • Encrypted storage of user-provided AI API keys
  • Access restriction to production systems and credentials
  • Rate limiting, reCAPTCHA, logging, and monitoring

9.2 Image Compliance and Processing

Images uploaded for public preview use must comply with applicable law and these legal documents. For compatibility and storage optimization, images may be processed by an image cropper or optimizer pipeline before storage.

10. Changes to This Policy

We may update this policy at any time. The updated version will be posted on this page with the update date.

11. Data Processing Agreement (DPA)

This DPA forms part of the Terms between visua.link as Processor and the customer as Controller whenever the customer uses the service to process personal data from third parties.

11.1 Definitions

  • Personal Data: information relating to an identified or identifiable person submitted through the service.
  • Processing: any operation performed on personal data, including collection, storage, use, or disclosure.
  • GDPR: Regulation (EU) 2016/679.
  • Data Subject: the individual to whom the personal data relates.

11.2 Scope and Roles

When you use visua.link to collect or process data from third parties, you act as Controller and visua.link acts as Processor.

  • Ensure a lawful basis for collection and processing
  • Provide appropriate privacy notices
  • Respond to Data Subject requests
  • Comply with applicable data protection law

11.3 Processor Obligations

  • Process data only on documented customer instructions
  • Bind authorized personnel to confidentiality
  • Implement appropriate security measures
  • Assist with Data Subject rights requests where reasonably possible
  • Notify the customer without undue delay in case of breach
  • Delete or return personal data when the service relationship ends, unless legal retention applies

11.4 Sub-processors

visua.link may use Google Cloud, Umami Cloud (for aggregate audience measurement), Stripe (including Stripe Connect for paid bookings), Amazon Web Services (Amazon SES, for email delivery), and a third-party abuse protection service (reCAPTCHA) as sub-processors when required by the service.

11.5 International Transfers

  • EU Standard Contractual Clauses
  • Adequacy decisions
  • Other legally recognized transfer mechanisms

11.6 Data Subject Rights

As Processor, visua.link assists the customer in fulfilling rights requests using the tools available in the service, while the customer remains legally responsible for those responses.

11.7 Security Measures

  • Encryption in transit
  • Access controls and authentication
  • Security reviews and updates
  • Logging and monitoring around access to personal data

11.8 Data Breach Notification

In the event of a personal data breach, visua.link notifies the customer without undue delay and provides reasonable assistance.

11.9 Audit Rights

Upon reasonable written request and subject to confidentiality obligations, visua.link provides information necessary to demonstrate compliance with this DPA.

11.10 Term and Termination

  • Customers may export their data using tools provided in the service.
  • After voluntary termination, visua.link may delete or anonymize personal data and related records unless legal retention applies.

11.11 Contact

For questions related to data processing, contact [email protected].