Datenschutzerklärung für Tidalic
Tidalic von Chamomile AI
Datenschutzerklärung für Tidalic
At Chamomile AI, we take your privacy seriously. This Privacy Policy applies to all personal information collected by MMC Research Pty. Ltd. (trading as Chamomile AI) (we, us or our) through Tidalic, including the website located at tidalic.com, the Tidalic web application, browser extension, and related services (together, Tidalic).
- What information do we collect?
The kind of Personal Information that we collect from you will depend on how you use Tidalic. The Personal Information which we collect and hold about you may include:
Account information, such as your name, email address, login method, and account settings
Feedback, support messages, or other communications you send us
Limited usage data, such as app open events, feature use events, device or browser information, and diagnostic information used to operate, secure, and improve Tidalic
Learning or scheduling information that you choose to add to Tidalic, including learning items, titles, URLs, estimated time, scheduling preferences, and events created or managed through Tidalic
Connected calendar data from Google Calendar or Microsoft Outlook Calendar, if you choose to connect a calendar account
OAuth tokens and related technical information required to maintain calendar connections that you authorize
2. Types of information
The Privacy Act 1988 (Cth) (Privacy Act) defines types of information, including Personal Information and Sensitive Information.
Personal Information means information or an opinion about an identified individual or an individual who is reasonably identifiable:
(a) whether the information or opinion is true or not; and
(b) whether the information or opinion is recorded in a material form or not.
If the information does not disclose your identity or enable your identity to be ascertained, it will in most cases not be classified as “Personal Information” and will not be subject to this privacy policy.
Sensitive Information is defined in the Privacy Act as including information or opinion about such things as an individual’s racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.
Tidalic is not designed to collect Sensitive Information. However, calendar events, event descriptions, support messages, or other information that you choose to provide may include Sensitive Information. For example, a calendar event may reveal health, religious, political, or other sensitive details depending on what you or another calendar user entered.
Sensitive Information will be used by us only:
(a) for the primary purpose for which it was obtained;
(b) for a secondary purpose that is directly related to the primary purpose; and
(c) with your consent or where required or authorised by law.
- How we collect your Personal Information
(a) We may collect Personal Information from you whenever you input such information into Tidalic or provide it to us in any other way.
(b) If you connect a Google Calendar or Microsoft Outlook Calendar account, we collect connected calendar data through the relevant provider’s OAuth authorization process and calendar APIs, based on the permissions you grant.
(c) We may collect technical and usage information when you use Tidalic, including information collected through cookies or similar technologies. This helps us operate, secure, customize, and improve Tidalic. We may collect technical and usage information through cookies, local storage, server logs, or similar technologies where reasonably necessary to authenticate users, maintain sessions, secure Tidalic, understand feature use, and improve service reliability.
(d) We generally do not collect Sensitive Information, but when we do, we will comply with the preceding paragraph.
(e) Where reasonable and practicable, we collect your Personal Information from you only. However, sometimes we may be given information from a third party. In cases like this, we will take reasonable steps to make you aware of the information that was provided by a third party.
- Connected calendar accounts: Google Calendar and Microsoft Outlook Calendar
Tidalic allows you to connect calendar accounts from Google Calendar and Microsoft Outlook Calendar. Calendar connection is optional. If you choose to connect a calendar account, Tidalic uses OAuth to request access to the calendar data needed to provide Tidalic’s calendar and scheduling features.
Depending on the provider you connect and the permissions you grant, Tidalic may access connected calendar data including your calendar account email address, calendar identifiers, calendar names, calendar list metadata, calendar access roles, free/busy availability, event titles, event start and end times, descriptions, locations, attendees, recurrence information, other event metadata, events created or modified through Tidalic, your selected primary calendar, and OAuth tokens required to maintain the connection.
We use connected calendar data only to provide and improve Tidalic’s user-facing calendar and scheduling features. This includes connecting calendars, listing available calendars, helping you select a calendar, checking whether a calendar is suitable for scheduling, showing availability, creating a separate Tidalic-specific calendar to be used for Tidalic state data including Tidalic-created events, creating scheduled learning events, updating or deleting events created or managed through Tidalic, and, where you opt in to AI-assisted scheduling, analysing calendar entries and relationships between events to generate scheduling recommendations or actions requested by you.
The separate Tidalic-specific calendar that Tidalic creates remains in the user’s calendar account unless the user deletes it, including after the calendar connection is disconnected. It may be used again if the user later reconnects the account.
Tidalic may access calendar permission metadata, such as whether you have free/busy, reader, writer, or owner access to a calendar. We use this only to determine whether a calendar may contribute availability information and whether events can be created, read, updated, or deleted on that calendar. Tidalic does not access or modify calendar access-control lists or sharing settings.
We do not sell connected calendar data. We do not use connected calendar data for advertising, retargeting, personalised advertising, direct marketing, credit-worthiness, lending, or unrelated analytics. We do not transfer connected calendar data to data brokers, advertising platforms, or information resellers.
We may share connected calendar data with service providers only where necessary to provide, operate, secure, or maintain Tidalic’s user-facing calendar and scheduling features, and only under appropriate confidentiality, security, and data-use obligations.
Artificial intelligence processing
If you choose to enable an AI-assisted scheduling feature, Tidalic may send relevant connected calendar data to a third-party artificial intelligence or machine-learning service provider through its business or API service. This processing may include analysing event timing, availability, event characteristics, scheduling constraints, and relationships between events to generate scheduling recommendations or perform scheduling actions requested by you. We limit the information sent to what is reasonably necessary to provide the feature.
AI-assisted processing is optional and is enabled only after Tidalic provides an in-product disclosure and you affirmatively opt in. Once enabled, the feature may process relevant connected calendar data as needed to provide the AI-assisted scheduling functionality you use, without requiring a separate consent prompt for each individual scheduling request.
We use service arrangements under which the provider is not permitted to use raw or derived connected calendar data to create, train, fine-tune, or improve foundational, generalised, or shared artificial intelligence or machine-learning models, or for the provider’s own advertising, marketing, profiling, or other independent purposes.
Tidalic does not use, transfer, or sell raw or derived Google Calendar data to create, train, fine-tune, or improve foundational, generalised, or shared artificial intelligence or machine-learning models. This restriction also applies to aggregated, anonymised, and otherwise derived information originating from Google Calendar data. Tidalic does not opt in to service-provider programs that use API inputs or outputs for generalised model training or improvement.
Human access to connected calendar data is restricted to authorised personnel and occurs only where reasonably necessary to provide support requested by the user, troubleshoot or maintain the service, investigate security or misuse, comply with law, respond to a privacy request, or address an incident. Aggregated or de-identified information is used where practicable.
If you disconnect a Google Calendar or Microsoft Outlook Calendar account, Tidalic stops accessing the account, revokes the connection with the provider where supported, deletes the OAuth tokens and connection information held by Tidalic, and clears calendar information held in connection with that active connection.
Disconnecting a calendar does not delete events or separate Tidalic calendars already created in the user’s Google Calendar or Microsoft Outlook account. Those items remain under the user’s control and may be manually deleted through the relevant calendar provider. They may also be available again to Tidalic if the user later reconnects the calendar account.
Tidalic applies these commitments to connected calendar data from both Google Calendar and Microsoft Outlook Calendar.
Tidalic’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Tidalic’s access to Microsoft Outlook Calendar data through Microsoft APIs is limited to the permissions needed to provide the calendar features requested by the user, and Tidalic does not sell, redistribute, sublicense, or use Microsoft API data for advertising or marketing purposes.
- Purpose of collection
(a) We collect Personal Information to provide, operate, secure, maintain, and improve Tidalic, including its calendar connection, scheduling, learning planning, support, and account management features.
(b) We use connected calendar data only for the user-facing calendar and scheduling purposes described in section 4.
(c) We may disclose Personal Information to service providers, contractors, professional advisers, and authorised personnel where reasonably necessary to provide, operate, secure, support, or maintain Tidalic. We may also disclose information where required or authorised by law, to investigate security or misuse, to protect legal rights, or in connection with a proposed or completed corporate transaction. Where connected calendar data is involved, the processing, use, and disclosure restrictions described in section 4 continue to apply.
(d) We may send you product updates or marketing communications where permitted by law, where you have consented, or where you would reasonably expect to receive them. We do not use connected calendar data from Google Calendar or Microsoft Outlook Calendar for direct marketing, advertising, retargeting, or personalised advertising. Our direct marketing material will include a simple means by which you can request not to receive further communications of this nature, such as an unsubscribe link.
- Security, Access and correction
(a) We store your Personal Information in a way that reasonably protects it from unauthorised access, misuse, interference, loss, modification, or disclosure. We use technical and organisational safeguards appropriate to the nature of the information we hold, which may include encryption in transit, access controls, restricted production access, secure cloud infrastructure, and monitoring or logging designed to protect the security and integrity of Tidalic.
(b) When we no longer require your Personal Information for the purpose for which we obtained it, we will take reasonable steps to destroy it or anonymise or de-identify it, unless we are required or permitted by law to retain it.
(c) If you disconnect a connected calendar account, we stop accessing that calendar account and delete stored OAuth tokens associated with the connection. We may retain limited records where required for security, legal, accounting, dispute-resolution, or operational purposes.
(d) Most of the Personal Information that is stored in our client files and records will be kept for a maximum of 7 years to fulfill our record keeping obligations.
(e) The Australian Privacy Principles:
(i) permit you to obtain access to the Personal Information we hold about you in certain circumstances (Australian Privacy Principle 12); and
(ii) allow you to correct inaccurate Personal Information subject to certain exceptions (Australian Privacy Principle 13).
(f) Where you would like to obtain such access or request correction or deletion, please contact us in writing on the contact details set out at the bottom of this privacy policy.
- Complaint procedure
If you have a complaint concerning the manner in which we maintain the privacy of your Personal Information, please contact us on the contact details set out at the bottom of this policy. All complaints will be considered by our Privacy Officer and we may seek further information from you to clarify your concerns. If we agree that your complaint is well founded, we will, in consultation with you, take appropriate steps to rectify the problem. If you remain dissatisfied with the outcome, you may refer the matter to the Office of the Australian Information Commissioner. - Overseas transfer
We may process or disclose Personal Information using service providers or authorised personnel located outside Australia, including in the United States, Singapore, Malaysia, and other countries in which our service providers process data.
The countries involved depend on the services and features used. Where practicable, we will maintain current information about the principal countries in which our service providers process Personal Information.
Before disclosing Personal Information to an overseas recipient, we take reasonable steps as required by applicable law to ensure that appropriate privacy and security protections apply.
- Privacy rights outside Australia
Tidalic is offered internationally. Depending on your location and the circumstances in which Tidalic is offered to you, privacy and data-protection laws outside Australia may apply to our processing of your Personal Information.
Where the United Kingdom General Data Protection Regulation, the European Union General Data Protection Regulation, or another applicable privacy law applies, we will process Personal Information in accordance with the applicable requirements. These requirements may include providing additional information about the legal bases for processing, international transfers, retention, and applicable rights.
Subject to applicable law, you may have rights to request access, correction, deletion, restriction, objection, or portability of your Personal Information, or to withdraw consent where processing is based on consent. You may contact us using the details below to exercise an applicable right.
Some rights are subject to legal conditions, limitations, and exceptions. You may also have the right to complain to the privacy or data-protection regulator in your jurisdiction.
- How to contact us about privacy
If you have any queries, if you seek access to your Personal Information, if you want to request correction or deletion of your Personal Information, or if you have a complaint about our privacy practices, you can contact us through: tidalic-support@chamomile.ai.