Privacy notice
How Bloomod handles personal data on behalf of the businesses that send calendar invitations through it.
Last updated 30 July 2026 · Version 1.0
Template content. This page is placeholder wording written to demonstrate the layout and to reflect how the product actually works. It has not been reviewed by a lawyer and is not legal advice. Replace it with your own reviewed notice before launch.
1. Roles
Bloomod is operated by Bloomod. Where you use Bloomod to send calendar invitations, your business is the controller of the event-attendee records you collect or import, and Bloomod is the processor acting on your instructions. Where we handle your own account data — the person who signed up, billing contact, support correspondence — we are the controller.
The processing terms that govern the first relationship are set out in the data processing agreement.
2. What we collect
Account data
- Name, work email address and password credential of each account member
- Business name, sending identity and verified domain
- Role and permission assignments
- Support correspondence
Event-attendee records
- Recipient name and email address
- The event the attendee registered for or was imported into, and their source
- Verification status and the time a magic link was used, where applicable
- Calendar-invite delivery and RSVP state for that event
Technical data
- Log data for requests to the application and API, including IP address
- Delivery and RSVP events returned by calendar providers
- Campaign, consent and account activity records
We do not ask for, and Bloomod is not intended to store, special category data, payment card numbers or government identifiers inside attendee records.
3. How it is used
Personal data is processed to:
- Save attendees to the specific event they registered for or were imported into
- Send and validate email magic links for public-form and landing-page registration
- Deliver calendar invitations only to attendees marked Verified when that event’s automation is enabled
- Return delivery and RSVP state to your account
- Enforce sending limits, verification and anti-spam review
- Maintain security and investigate misuse
- Provide support and account communication
We do not sell personal data. We do not use attendee records to build profiles for our own purposes, to train models, or to market to your customers.
4. Legal basis
For account data we rely on performance of a contract and, for security and abuse prevention, our legitimate interests. For attendee records processed on your behalf, the legal basis is yours to establish and document. You are responsible for ensuring that your event collection and imports are lawful.
5. Sharing
Personal data is shared only with:
- Calendar and mail providers — necessarily, to deliver the invitation to the recipient
- Infrastructure providers — hosting, storage and monitoring under contract
- Authorities — where we are legally required, and where permitted we will tell you first
A current list of subprocessors is available on request from the address below.
6. Retention
- Attendee records are retained while their event and your account are active, or until you delete them
- Verification and delivery records may be retained for a defined period to support audit, security and dispute resolution
- Activity records are retained for a defined period to support audit and dispute resolution
- On account closure, attendee records are deleted or returned within a defined window
7. Your rights
Depending on where you are, you may have rights of access, correction, deletion, restriction, objection and portability. If you are a recipient of an invitation sent through Bloomod, the business that invited you is the controller — we will pass your request to them and support them in answering it.
If you are an account holder, write to the address below and we will respond within the period required by applicable law.
8. Security
Attendee names and email addresses are encrypted in transit and at rest. They are accessible only to the event owner; Bloomod cannot view attendee email data. Important activity is recorded. The controls in place are described on the security page. No platform can promise perfect security, and this notice does not claim otherwise.
9. International transfers
Data may be processed outside your country by our infrastructure providers. Where that happens, transfers are made under a recognised transfer mechanism. Calendar providers necessarily receive the invitation in the region where the recipient's account is held.
10. Contact
Questions, requests or complaints: hello@bloomod.com. If you are not satisfied with our response you may complain to your local supervisory authority.