Privacy Policy
Last updated 2 October 2026
This policy explains how ACCLER8 AUTOMATION LIMITED (“Acceler8”, “we”) handles personal data in acceler8appointments: the appointment software we provide to businesses, and this website.
1. Who we are
The controller for the processing described in sections 3 to 5 is ACCLER8 AUTOMATION LIMITED, registered in Cyprus under number HE497826, with its registered office at Zaloggou 4, Ypsonas 4183, Limassol, Cyprus. You can reach us about anything in this policy at contact@acceler8.cy.
2. Two roles: ours, and the businesses'
Businesses use acceler8appointments to take bookings from their own clients. For those clients’ details — names, phone numbers and appointments — the business is the controller: it decides why and how they are used. We process them only on the business’s instructions, as its processor, under our Data Processing Agreement.
If you booked an appointment with a business, see the privacy notice for clients who book, and contact that business about your details. We will pass on any request that reaches us.
3. Business customers and their teams
When a business uses acceler8appointments, we process:
- Account details: the name and email address of each person who signs in, their role, and a password stored only as a one-way hash.
- Business details: the business name, address of its booking page, opening hours, services, prices and branding.
- Billing: the plan, the number of seats and the subscription status. Card and payment details are collected and held by Stripe, never by us.
- Security records: failed sign-in attempts and the address they came from, kept for 15 minutes to stop password guessing.
Why and on what basis: to provide the service the business signed up for and to bill for it (performance of a contract, GDPR Art. 6(1)(b)); to keep accounts secure and prevent abuse (our legitimate interest, Art. 6(1)(f)); and to keep accounting records (legal obligation, Art. 6(1)(c)).
4. Enquiries from the Get started form
When you ask us to set up your business, we keep the details you send — your name, phone number, business name, type and team size, and optionally your email, what you need, when to call and which plan — to call you back and set the business up, along with our own notes from that call. We also keep a one-way hash of your connection’s address, to limit repeated submissions. We use these details for nothing else.
Basis: steps you asked us to take before a contract (Art. 6(1)(b)). Kept: [retention period for enquiries that do not become customers, e.g. 12 months].
5. Visitors to this website
We do not use analytics, advertising or tracking cookies, and we do not load fonts, scripts or images from other companies’ servers. The booking form a business embeds on its own website sets no cookies at all. The only cookies are the ones needed to sign in and the theme you choose; they are listed on the Cookies page.
Like any website, our hosting provider handles your IP address to deliver each page, and keeps short technical logs to run the service securely (our legitimate interest, Art. 6(1)(f)).
6. Who receives personal data
We use a small number of service providers (sub-processors) to run acceler8appointments. Each one receives only what its job needs, under a written agreement. The full list — who they are, what they receive and where — is in the Data Processing Agreement. We do not sell personal data and do not share it for advertising.
7. Transfers outside the European Economic Area
Our database is in the European Union. Some providers are based in, or may access data from, the United States. Where that happens, the transfer is covered by the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses (GDPR Art. 45 and 46). You can ask us for a copy of the safeguards that apply.
8. How long we keep data
- Account and business data: for as long as the business uses the service, then [deletion period after an account closes, e.g. 30 days], except what we must keep for accounting.
- Invoices and billing records: as long as Cypriot tax law requires ([e.g. 7 years]).
- Failed sign-in records: 15 minutes. Booking-form abuse counters: at most one day.
- Records of actions taken by Acceler8 staff in the operator console, with the address they acted from: [retention period for the operator audit log].
9. Security
Data is encrypted in transit (HTTPS only) and at rest by our database provider. Passwords are stored as one-way hashes. Each business sees only its own data, and team members only what their role allows. Acceler8 staff sign in to their own console with two-factor authentication, and every change they make is recorded.
10. Your rights
You have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format (GDPR Articles 15 to 21). Where we rely on consent, you can withdraw it at any time. Write to contact@acceler8.cy; we answer within one month.
You can also complain to the Office of the Commissioner for Personal Data Protection, Iasonos 1, 1082 Nicosia, Cyprus (dataprotection.gov.cy), or to the supervisory authority where you live or work.
11. Children
acceler8appointments is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 14 (the age set by Cyprus Law 125(I)/2018) except as a business’s client, where the business is responsible.
12. Changes
When we change this policy we update the date at the top. If a change affects how we use data we already hold, we tell business customers by email before it takes effect.