Privacy statement for businesses and visitors
Version 2026-10-02. A lawyer is reviewing this document; any change is posted here with its date before it applies.
This statement is for people who run a business on Prytan and their teams, for visitors to prytan.ai, and for booking platforms and others who write to us. Prytan is run by [Company name, kennitala, registered address, Iceland] ("Prytan", "we"). Questions and requests go to support@prytan.ai.
If you book appointments through your AI, read the privacy policy for people who book. A business account and a personal account are separate accounts, even when they use the same email address.
1. Owners and their teams: what we hold
- Your account: your email address, your name, a small profile picture if you add one, and a sign-in record kept by our sign-in provider. You sign in with a link sent to your email, or a password you choose. A password is kept, hashed, by the provider, never by Prytan.
- Your settings: theme, language, date format, timezone, whether you want email alerts, and whether you have seen the first-time walkthrough.
- Your organisation: its name, who belongs to it, and your referral code. If another business signed up through your link, we keep that link between you (its name and whether it connected and paid), to count your free months.
- Your businesses: the name, the optional details you add for agents (a description, languages, accessibility, parking, payment methods), each business's share code and short code, and how often its share page was opened. The services, prices, staff names, hours, address and contact details come live from your booking system and are not stored in Prytan's database.
- Your connections: the access token your booking system gave Prytan, or the key you pasted, stored encrypted with a key held outside the database; the account's name and id; when Prytan last checked it and what went wrong if it failed.
- The activity log: every request an AI agent made about your business: the time, what was asked for, the name the agent gave itself, its network address and the outcome.
- Notifications in the app, and the emails we sent you.
- What you accepted: which version of the terms for businesses and the data-processing terms you accepted, in which language, and when.
- A suspension, if any: if we suspend a business account, we keep when, and our own short note of why, until it is restored or the account is deleted.
2. Why, and the legal basis
| Purpose | Legal basis |
|---|---|
| Your account, your businesses, your connections, the dashboard, notifications | the contract with you (Article 6(1)(b) GDPR) |
| Email alerts about bookings and things that need attention | the contract with you; switch them off in Settings |
| The activity log's network addresses, rate limits, suspension for misuse | our legitimate interest in keeping the service secure and fair (Article 6(1)(f)) |
| Referral and sharing counts | our legitimate interest in crediting free months correctly (Article 6(1)(f)) |
| The record of what you accepted | our legal duty to be able to show it (Article 6(1)(c)) |
3. Your customers in bookings made through Prytan
When a person books at your business through Prytan, Prytan sends the booking to your booking system and keeps a booking record so that you can see what happened.
- Prytan is the controller of the person's own Prytan account and of collecting their details and sending them to you.
- You are the controller of the booking from the moment your booking system receives it, and of everything in that system.
- Prytan is your processor for what it keeps and shows to you about those bookings: the dashboard, notifications and the log. The data-processing terms govern that.
In Prytan you see the customer's name and the booking. You never see their phone number or email in Prytan, because your booking system already holds them. Prytan never reads your customer list or your other appointments. It reads back only the bookings it made, each by its own id, to notice when one was changed or cancelled.
4. "My business insights": your own AI
You can let your own AI read your businesses' figures. When you add Prytan to an AI and sign in on Prytan's page with the email address of your business account, you can tick "My business insights".
- We keep a pass for that AI: its name, what you allowed, when it was connected and last used, and its tokens, stored only as hashes.
- The AI can read, for your own businesses only, the figures your dashboard shows: look-ups, which agents, what they asked about, bookings made through Prytan, busiest times and what needs attention.
- Bookings are shown with the customer's name, never their phone or email. For a booking of a health service the name is left out.
- It is read-only. Nothing can be changed through it.
- What you ask your AI, and what it answers, stays with your AI provider under its terms. That provider is yours, not Prytan's. Prytan sees only which figures were requested.
- Change or remove this access in My Prytan, or in Settings in the business app, at any time.
The same connection can also book for you personally if you tick "Book for me". The two stay separate.
5. Visitors to prytan.ai
- The website uses no analytics, no advertising and no trackers, and sets no cookie for visitors who do not sign in or follow an invitation link. Cookies and browser storage lists everything.
- Fonts and images are served by Prytan itself. No request goes to another company when you read a page.
- The server keeps a short technical log of requests to the application (the time, the address requested, the network address and the answer). It is used to find faults and stop abuse, and it is cleaned of email addresses and phone numbers as it is written.
- Opening a business's share page adds one to a count of visits for that business. Nothing about the visitor is kept with it.
6. Booking platforms, and people who write to us
- The developers page. If you ask for the standard and the test kit, we keep your name, company, work email, website and message, and our decision. We use them only to answer you and to work with you. Ask us to delete them at any time.
- Email to support@prytan.ai. We keep your message for as long as it takes to answer and follow up.
- Partners. The terms for booking platforms say how data is shared between a platform and Prytan.
7. Who else handles the data
Companies that work for Prytan are listed, with the contracting company, its country, where the data sits and the safeguard for any transfer, in the sub-processor list. Today:
| Who | For what | Contracting company | Where the data sits |
|---|---|---|---|
| Supabase | the database, and owners' sign-in | Supabase Pte. Ltd, Singapore | Frankfurt, Germany |
| DigitalOcean | the server and its disk | DigitalOcean, LLC, USA | Amsterdam, Netherlands |
| Resend | every email | Plus Five Five, Inc., USA | sent from Ireland; stored in the USA for 30 days |
Your booking system is your own provider, not ours. Prytan sends bookings to it on your instruction, wherever it keeps its data.
8. How long we keep it
A nightly job enforces these periods.
- Bookings: 24 months after the appointment, then deleted.
- Activity log: 12 months, then deleted.
- Notifications: 12 months, then deleted.
- Connection tokens and keys: cleared the moment a connection is disconnected.
- AI passes: revoked at once when disconnected; expired ones deleted the next day.
- When you remove a business: its connections, bookings and notifications are deleted at once; log rows lose their link to it.
- When you delete your account (Settings, Account): the account and its sign-in record at once. If nobody else belongs to the organisation, the organisation too, with its businesses (offline for agents at once), connections, bookings and notifications. Log rows lose their link and follow the log period. The free-period record of each booking account is kept, because it belongs to the booking account, not to you.
- Encrypted backups are kept for up to 14 days, so deleted data leaves them within that time.
9. Your rights
You may see the data we hold about you, have it corrected or deleted, receive a copy, object to a use, restrict it, and withdraw a consent.
| You want to | How |
|---|---|
| See it | the app shows your account, businesses, log and notifications; for a full copy, write to us |
| Correct it | Settings in the app |
| Delete it | remove a business, or delete the whole account, in Settings, Account |
| Stop email alerts | Settings in the app |
| Object or restrict | write to support@prytan.ai |
We answer within one month. You can also complain to the Icelandic Data Protection Authority, Persónuvernd (personuvernd.is), or to the authority in your own country.
10. Security
Tokens and keys are encrypted at rest with a key held outside the database. All traffic is over HTTPS. Every request is limited to your own organisation, and that is covered by automated tests. The database is closed to the public key that the sign-in page uses. Logs are cleaned of email addresses and phone numbers as they are written. Database backups are encrypted. Your sign-in token is kept in your browser's storage; sign out on a shared computer.
11. Changes
We post changes here with the date. Material changes are announced in the app and by email before they apply.
Questions: support@prytan.ai. Report a bug.