PrytanPrytan
Privacy policyTerms of serviceData-processing terms

A lawyer is reviewing this page. Any change is posted here with its date before it applies.

Data-processing terms

Last updated 30 September 2026. Modelled on Article 28 of the GDPR. A lawyer is reviewing these terms; any change is posted here with its date before it applies.

These terms apply whenever Prytan handles the personal data of your customers on your behalf. They are part of the terms of service. You are the business (the controller). Prytan, [Company name, kennitala, registered address, Iceland], is the processor.

A person who books through their AI may also have a personal Prytan account (My Prytan). For that account Prytan is the controller, under its privacy policy; these terms cover only what Prytan does with your customers' data for you.

1. What is processed, and why

Whose dataWhich dataPurposeFor how long
Your customers who book through an AI agentfull name, phone number, email address where required, service, time, the agent's self-declared name and network address, the outcometo create the appointment in your booking system, show it to you (name only), and tell you if it changed24 months after the appointment, or at once when you remove the business
Your customer records in your booking system, for staff you set to take only existing customersone question per check: has this phone number, verified by Prytan with a text code, booked with this staff member? (yes or no). Not made while texts are switched off, which is the case todayto apply your own "existing customers only" rule when a signed-in person asks to book such a staff membernot stored; used only to allow or refuse that booking

Prytan does not receive or process any other customer of yours. It reads back only the appointments it created, each by its own id, to learn when one was changed or cancelled, and it asks the question above only as described.

2. Your instructions

Prytan processes this data only to make the booking the customer's agent asked for, to show it to you, to tell you if it changed, to apply your "existing customers only" setting, and to keep the service secure. Setting a staff member to take only existing customers in your booking system is your instruction to apply that rule as in section 1. The check is made only with a phone number Prytan verified by a text code, never with one a person merely saved; while texts are switched off it is not made at all. Anything else needs your written instruction. If we believe an instruction breaks the law, we will say so.

3. Confidentiality

Only people who need to, under a duty of confidentiality, can access the data. Prytan is currently one person; this section is written for the day that changes.

4. Security

Access tokens and keys are encrypted at rest with a key held outside the database. Traffic is encrypted in transit. Access is limited to your organisation and tested automatically. Logs are cleaned of email addresses and phone numbers as they are written. Database backups are encrypted. We keep a log of what agents did and show it to you.

5. Sub-processors

Sub-processorFor whatWhere
Supabasethe databaseFrankfurt, Germany (EU)
DigitalOceanthe serverAmsterdam, Netherlands (EU)
Resend (Plus Five Five, Inc.)email (alerts to you)sent from Ireland (EU); stored in the USA; standard contractual clauses and the EU–US Data Privacy Framework
46elkstext messages: switched off, no data is sent to itSweden (EU)

We will tell you before adding or switching on a sub-processor; you may object, and if we cannot resolve it you may end the service.

Your own booking system (for example Noona or Cal.com) is not our sub-processor: it is yours, and Prytan hands the data to it on your instruction.

6. Helping you

We will help you answer a customer who exercises their rights (access, correction, deletion and the rest), help with any security incident, and help with a data-protection impact assessment if one is needed, at no charge beyond reasonable effort.

7. Incidents

If we learn of a breach affecting your customers' data we tell you without undue delay, and in any case within 48 hours of learning of it, with what we know.

8. Deletion

When you remove a business, its bookings are deleted at once. When the agreement ends, we delete the data within 30 days, unless the law requires us to keep some of it; encrypted backups age out within a further 14 days.

9. Audit

Once a year, on reasonable notice, you may ask us to show how we meet these terms. We will answer in writing; an on-site audit needs a serious reason and a confidentiality agreement.

10. Transfers

The database and the server are in the EU/EEA. Email is handled by Resend, which stores it in the USA; for that, and for any other provider outside the EU/EEA, we rely on the European Commission's standard contractual clauses or an adequacy decision (for Resend, both: its data-processing agreement includes the clauses, and it is certified under the EU–US Data Privacy Framework).

11. Liability

The liability rules in the terms of service apply to these terms too.

Questions: support@prytan.ai. Report a bug.