Data Protection
Privacy
Introduction
Welcome to "Schedules" (the "Service"). This privacy policy outlines how we collect, use, and protect your personal data when you use our Service. By using the Service, you agree to the collection and use of information in accordance with this policy.
Who We Are
Devsym GmbH operates the Service. Depending on the data concerned we act as controller or as processor — see "Our Role: Controller and Processor" below. Our contact information is:
Company Name: Devsym GmbH
Address: Kastanienweg 3a, 82319 Starnberg, Germany
Email: info@devsym.de
Information We Collect
We store the following personal information in our database or storage:
- User's Name: To display names in the user interface.
- Email Addresses: Of the administrator who first sets up the Service and of the person who redeems a licence, for communication and licence administration. Where assignment e-mail notifications are switched on, the address of each recipient is used to deliver them. Team member records themselves hold no e-mail address.
- User's Entra ID Object ID: To identify the user in Microsoft Graph.
We do not store any passwords or other credentials (e.g. Access Tokens).
Data Residency
We store and process all data in Microsoft Azure in the Germany West Central region. Microsoft Azure is a secure cloud platform with various global compliance certifications.
Learn more about Microsoft Azure compliance: Azure Compliance
Use of Collected Information
We use the collected information for the following purposes:
- Service Provision: To provide and maintain the Service.
- Communication: To communicate with users regarding updates, support, and other relevant information.
Access to Microsoft Graph Scopes
To use all Schedules features, the app requests the following Microsoft Graph Scopes. All scopes are being requested as delegated permissions, meaning that the app can only access data on behalf of the signed-in user.
- User.ReadBasic.All (delegated):
Allows the app to read a basic set of profile properties of other users in your organization on behalf of the signed-in user. This includes display name, first and last name, email address and photo.
Learn more - Calendars.ReadBasic (delegated):
Allows the app to read events in user calendars, except for properties such as body, attachments, and extensions.
Learn more - TeamsActivity.Send (delegated):
Allows the app to send activity notifications to users in a team in the context of the signed-in user.
Learn more
This access is used to enhance the functionality of the Service and provide a seamless experience.
Our Role: Controller and Processor
Devsym GmbH is the controller for the data we process for our own purposes: account and contact details, licensing and billing, support correspondence, security and operational logs, and the use of this website.
For the content that users create inside the Service — appointments, projects, team members, roles and settings — the customer organization is the controller and Devsym GmbH acts as processor on its instruction. The terms of that processing are set out in subsection 2.3 of our Terms and Conditions, which constitutes the data processing agreement required by Article 28 GDPR and applies to every customer. We provide it as a standalone document on request.
Subprocessors
We use a small number of service providers to operate the Service. Each is bound by a data processing agreement and may process personal data only on our instruction.
- Microsoft (Azure): hosting, data storage, backup and operational monitoring — Germany West Central, Germany.
- Microsoft (Azure Communication Services): delivery of transactional service e-mails — European Union.
- Paddle: merchant of record for purchases made directly on schedulesforteams.com, covering payment processing, invoicing and licence delivery. Purchases made through Microsoft Marketplace are billed by Microsoft and do not involve Paddle.
We will inform customers at least 14 days before we engage a new subprocessor or replace an existing one. If you object to the change during that period, you may terminate the affected service without penalty.
Website Analytics
This website uses Plausible Analytics to understand how it is used. Plausible is a privacy-friendly analytics service: it sets no cookies, uses no browser storage, creates no persistent identifier and does not track visitors across websites or devices. It records page views together with the referring site, browser, operating system, device type and country. Raw IP addresses are not stored. All data is processed within the European Union by Plausible Insights OÜ, Estonia.
The Schedules application itself contains no analytics or tracking.
International Transfers
The data entered into the Service is stored and processed in the European Union and is not transferred to a third country in the course of normal operation. Where a transfer outside the European Union, European Economic Area or Switzerland does occur — for example through a payment provider — it is governed by the European Commission Standard Contractual Clauses or another approved safeguard.
Data Security
We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, use, or disclosure. All data is securely stored in Microsoft Azure in Germany. The measures we apply are described in detail on our security page.
Data Retention
We retain personal data for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law. After we receive a deletion request, we will delete the data within 30 days.
Backups are kept on a rolling basis for 90 days and operational logs for 90 days, after which both are deleted automatically. After a customer organization is deleted we keep two records: a minimal record of the organization — its identifier, e-mail domain, the name and e-mail address of the initial administrator, licence status and seat count, the reason for deletion and the relevant dates — for accounting and abuse-prevention purposes, and the deletion request itself, which names the administrator who submitted it.
Your Rights
You have the following rights regarding your personal data:
- Access: You have the right to request access to your personal data.
- Rectification: You have the right to request the correction of inaccurate or incomplete personal data.
- Erasure: You have the right to request the deletion of your personal data under certain circumstances.
- Restriction: You have the right to request the restriction of processing of your personal data under certain circumstances.
- Objection: You have the right to object to the processing of your personal data under certain circumstances.
Changes to This Privacy Policy
We may update our privacy policy from time to time. We will notify you of any changes by posting the new privacy policy on this page. You are advised to review this policy periodically for any changes.
Contact Us
If you have any questions or concerns about this privacy policy, please contact us at support@devsym.de.

