1. Who we are
Hitrate Technologies Sweden AB ("Hitrate", "we", "us") provides a sales platform for outbound sales teams: a predictive dialer with voice, CRM, signing and meeting booking.
Address: Drottninggatan 18B, 702 10 Örebro, Sweden
Email: [email protected]
This policy covers people whose Google or Microsoft calendar is connected to Hitrate ("calendar owners"), and the users of the Hitrate application. When our customers use Hitrate to work with their own contacts, we handle that data on the customer's behalf under a data processing agreement. The customer is then responsible for that data, and requests about it should go to the customer.
2. What we collect
When a calendar owner connects a Google or Microsoft calendar:
- Hitrate stores a connection record: provider, the name and email address of the calendar owner as entered by the customer's administrator, the owner's time zone, the chosen calendar, and the access credentials (access and refresh tokens) issued by Google or Microsoft.
- Hitrate reads calendar information from Google or Microsoft when it is needed to provide the features in section 5: the list of calendars, and events with their title, description, start and end time, time zone, location, status, organizer, attendees and their responses, and meeting link. This is shown to the owner's colleagues in Hitrate while they book meetings, and is not copied into our systems.
- When a meeting is booked in Hitrate, we store booking details in the customer's Hitrate account: the event identifier, title, start and end time and status.
We do not request or receive your Google or Microsoft password, and we do not read your email, files or contacts.
3. Google user data
This section describes exactly how Hitrate handles data it receives from Google when a calendar owner connects a Google account.
Data accessed. Hitrate requests one Google permission: Google Calendar (https://www.googleapis.com/auth/calendar). With it Hitrate accesses:
- the list of calendars in the account (name, identifier, time zone, access level), and the primary calendar's identifier, which is usually the account's email address;
- calendar events: title, description, start and end time, time zone, location, status, organizer, attendees (name, email address, response) and meeting link;
- the access and refresh tokens Google issues when the owner approves access.
Hitrate does not access the Google account's profile, Gmail, Drive, Contacts or any other Google service.
How we use it. Only to provide the calendar features the owner approved:
- show the owner's schedule to colleagues in the same Hitrate account when they book meetings with the owner (events not booked through Hitrate are shown only as "Busy" unless the account administrator has chosen to show all events);
- create, update, cancel and delete the meetings booked through Hitrate, including adding a Google Meet link and sending invitations to the attendees the booker entered;
- accept or decline meeting invitations when the owner does this through Hitrate;
- check regularly that the connection still works.
How we store it. Calendar events are read from Google when needed and are not stored by Hitrate. Hitrate stores only the connection record and tokens described in section 2, and, for meetings booked through Hitrate, the event identifier, title, start and end time and status.
Who we share it with. Google user data is shown only to users of the Hitrate account the calendar is connected to, and is processed on Hitrate's own servers in Stockholm, Sweden. It is not sold or shared with any other third party. See section 6.
How we protect it. See section 8.
Retention and deletion. Tokens are kept until the connection is removed. Booking details follow the customer's retention settings. A calendar owner can have their Google data deleted at any time as described in section 9.
4. Google API Services User Data Policy (Limited Use)
Hitrate's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms, for data we receive from your Google Calendar:
- We use it only to provide and improve the calendar features described in this policy: showing your schedule to colleagues who book meetings with you, and creating, updating and deleting the meetings booked through Hitrate.
- We do not sell it, and we do not use it for advertising, including personalised or retargeted ads.
- We do not use it to develop, improve or train generalised AI or machine-learning models.
- We do not allow people at Hitrate to read it, except with your consent, where needed for security (for example investigating abuse), where needed to comply with law, or where needed to provide support you have asked for.
- We do not transfer it to others, except as needed to provide the feature, to comply with law, or as part of a merger or sale of the business with notice to you.
5. Why we use the data
- Calendar features (performance of the service our customer has ordered): show availability, book, change, cancel and complete meetings, send the invitation through Google or Microsoft, add Google Meet or Microsoft Teams links, and check regularly that the connection still works.
- Security and fault finding (legitimate interest in keeping the service secure and working).
We do not make automated decisions about you, and we do not use calendar data for profiling.
6. Who we share data with
- Google and Microsoft, as the provider of your calendar. Meeting details that Hitrate writes to your calendar are processed by them under their own terms. Invitations sent from your calendar go to the attendees the seller entered.
- Our customer (your employer or the company that engaged you), who controls the Hitrate account and decides who is a calendar owner and who can book against it.
- No hosting providers. We run Hitrate on our own servers in several data centres in Stockholm, Sweden. No outside hosting or cloud provider has access to the data.
- Authorities if we are legally required to.
We do not sell personal data.
7. How long we keep it
- Calendar events: not stored by us. They are read from Google or Microsoft when needed.
- Connection record and tokens: kept until the connection is removed. We remove the stored access if the connection is deleted by the customer's administrator or by us on request, and also if access repeatedly fails (for example because you revoked it).
- Booking details in the customer's account: kept according to the customer's own retention settings and agreement with us.
- Operational logs: detailed logs are kept for 2 weeks and summary logs for 2 months, then deleted. Logs are used for security and fault finding.
- Unused connections: a calendar connection that has not been used for 30 days is deleted, unless the customer has asked us to keep it longer.
8. Security
We protect calendar data and access tokens with these measures:
- Tokens stay on our servers. Google and Microsoft access and refresh tokens are held only in our calendar service's database. They are never sent to web browsers, to Hitrate users, or to other customers.
- Separation between customers. Every request to the calendar service must be authenticated with the Hitrate account's own credentials, and each connected calendar belongs to exactly one Hitrate account. One customer's users cannot reach another customer's calendars.
- Least data. Calendar events are not written to our database; they are fetched from Google or Microsoft when needed and passed straight to the Hitrate user who asked for them.
- Encryption in transit. All traffic between Hitrate, Google and Microsoft uses HTTPS (TLS).
- Restricted access. Only authorised Hitrate staff who operate the service can access its servers and database.
- Automatic clean-up. Access is checked regularly. If Google or Microsoft rejects access repeatedly, for example because the owner revoked it, the stored token is removed.
- Encryption at rest. The databases that hold connection records and tokens are encrypted at rest.
- Own infrastructure. Hitrate runs on its own servers in several data centres in Stockholm, Sweden, not on shared third-party platforms.
9. Your choices: disconnect and delete
You can stop Hitrate's access at any time:
- At Google: go to myaccount.google.com/permissions, choose Hitrate, and select "Remove access".
- At Microsoft: go to account.microsoft.com, Privacy, Apps and services (or myapps.microsoft.com for work and school accounts), and remove Hitrate.
- At Hitrate: ask your Hitrate administrator to delete you as a calendar user, or email [email protected]. We will delete the connection record and tokens within 30 days of the request and confirm by email.
Removing access at Google or Microsoft ends Hitrate's ability to read or change your calendar. Meetings that were already created stay in your calendar until you delete them.
10. Your rights
If you are in the EU/EEA you have the right to access, correct, delete, restrict or object to our processing, and to data portability, to the extent GDPR gives you these rights. For data we handle for a customer, please contact that customer first; we will help them respond. Send requests to [email protected]. You also have the right to complain to the Swedish Authority for Privacy Protection (IMY, imy.se).
11. Transfers outside the EU/EEA
Hitrate stores and processes data in Sweden. We do not transfer personal data outside the EU/EEA. Google and Microsoft, as providers of your calendar, may process calendar data in other countries under their own terms and safeguards.
12. Cookies
The Hitrate application uses cookies only to keep you signed in and to check that your session is still valid. These cookies are necessary for the service to work. Hitrate does not set advertising or tracking cookies, and the calendar integration does not place any Google or Microsoft cookies.
13. Children
Hitrate is a business service and is not directed at children.
14. Changes to this policy
We will publish updates on this page and change the effective date. If a change is significant, we will tell calendar owners in advance.
15. Contact
Hitrate Technologies Sweden AB
Drottninggatan 18B, 702 10 Örebro, Sweden
[email protected] · +46 20 11 33 40