Legal

Privacy Policy

What Laysa holds, why, for how long, and how to make it stop. If you booked a session with someone and arrived here from their email, section 6 is the one you want.

Version 1.3Last updated 20 September 2026
1

Who is responsible for what

Laysa is operated by Andrea Castoldi, a natural person established in Italy, in the European Union, reachable at privacy@laysa.net. A postal address is available on request from that address.

If you are a professional using Laysa, we are the controller of your account data and you can act on it in Settings. If you booked a session with a professional, they are the controller of your data and Laysa processes it for them. In both cases privacy@laysa.net reaches us, and we will tell you which of the two you are if it is unclear.

2

What is held about a client

Name, email address, the timezone the booking page detected, the sessions booked and their times, whether each one happened, and a private note the professional may write. That is the entire list and it is closed by design: Laysa has no custom fields, so nobody can add a health field, a goal or a measurement to it. If you typed something into the optional note on the booking form, it is held too, and it is the one field with no fixed shape — which is why it never travels out of Laysa by email.

3

What is held about a professional

Your name, email address, the headline and picture you publish, your working hours, your timezone, your public address, and — if you connect it — an encrypted token that lets Laysa read when you are busy and write the sessions people book. Never your calendar’s contents, and never a payment detail, because there is nowhere in the product to enter one.

4

Why we are allowed to hold it

To perform the contract you entered when you created an account, and, for your clients, on the instructions of the professional who is their controller. Analytics run on legitimate interest, without cookies and without identifying anyone across sites.

The weekly summary runs on legitimate interest rather than on the contract. It is the one email Laysa sends on a schedule rather than because a session was booked, moved or cancelled. It goes to you as the account holder and never to one of your clients, it counts only sessions and people you already have, and it carries no promotion of Laysa or of anything else. Stopping it takes one click in its own footer, or one in Settings › Notifications, and it takes effect immediately. It is also the only Laysa email that can be turned off, because the others are how the people you work with find out what was booked.

Keeping the booking pages safe runs on legitimate interest too. To stop a page being scraped or flooded, the hosting provider counts the requests that come from each IP address over a minute and turns away the ones over the limit. Laysa's own records store no IP address.

The founding member list runs on your consent. If you accepted the founding member offer and confirmed it by email, Laysa keeps that answer and uses it for one thing: to offer you a paid plan when paid plans arrive. It is kept until you take it back, which is one click in Settings › Privacy and data.

5

How long it is kept

For as long as the account exists. Delete it and everything is erased after thirty days, including from backups on their own rotation. A client record is deleted with the account that holds it.

An account nobody signs in to is not kept forever. After 24 months without a sign-in Laysa emails you, and again at 25 months. At 26 months it emails a third time and suspends the account, and at 27 months it deletes it exactly as if you had asked. Signing in before the third email resets the count; after it, signing in shows the account suspended, with one button that restores it, until the deletion date.

Product analytics events are kept for 90 days and then deleted. Each one carries a one-way hash of the account it belongs to, never a name or an address.

Three records survive the deletion, and none of them names you. The first is a pseudonymous record of each acceptance of these documents: a one-way hash of the account identifier, the version of the document that was accepted, and the moment it was accepted. It holds no email address, no name, no IP address and no reversible identifier — the hash cannot be turned back into the account it came from, and once the account is gone nothing that names you is left to join it to. It is deleted five years after the acceptance.

The second records that the deletion happened: the same one-way hash, why the account was deleted, when, and whether it completed. It is deleted five years after the deletion. The third is the product analytics events described above, which run out on their own 90 days.

The first two are kept under Article 17(3)(e) of the GDPR, which allows personal data to be held where it is needed to establish or defend a legal claim — here, that somebody agreed to these terms on a particular day, and that their account was then erased. Keeping the whole record would have been easier and would have kept a name; keeping the hash keeps the proof and not the person.

6

Your rights, and where the button is

Access, rectification, erasure, restriction, portability and objection. Two of them are not a request you have to make and wait for — they are controls you already have.

Take everything with youSettings › Privacy and data · CSV or JSON, immediate
Delete your account and everything in itSettings › Privacy and data · 30 days to change your mind
Anything else, or you are a client rather than a professionalprivacy@laysa.net · answered within 30 days

A client asking us to erase their record is passed to the professional who is the controller of it, and we tell you we have done so. We do not delete a professional’s records on a third party’s say-so, and we do not sit on the request either.

7

Who else sees it

The companies in Annex B of the Terms, each doing one job, all named — and Google, only if you connect your calendar, as the note under Annex B explains. Nobody buys this data, nobody is sold it, and no advertising network is involved at any point.

8

Where it is stored

In the European Union. The database and its file storage are hosted by Supabase in Frankfurt; the application and the scheduled jobs run on Vercel in Frankfurt. Some of the companies involved are based in the United States and process data there as part of what they do, under the Standard Contractual Clauses. Annex B of the Terms names every one of them and where each holds what it holds — one list, in one place, rather than a sentence here that would go stale on its own.

Everything is encrypted in transit and at rest. Your calendar tokens carry a second layer: Laysa encrypts them itself before they are written, with a key that is not in the database, so a copy of the database on its own does not open your calendar. Laysa never reads what is in your calendar events — only the intervals in which you are busy.

A backup is taken every night, encrypted, and held outside the hosting provider, so that losing the provider does not mean losing the data. Backups are kept for fourteen days and then destroyed, which is why a deletion reaches them on their own rotation rather than at once.

9

Cookies and analytics

There is no cookie banner anywhere in Laysa, and that is a design decision rather than an omission: a banner exists to collect consent for cookies that need it, and Laysa sets none of those. The cookie policy names every cookie, says what each is for and how long it lasts.

Product analytics run without cookies and without a script in your browser. No analytics or advertising code loads on any Laysa page. An event is written by Laysa’s own server against a one-way hash of the account it belongs to, so your browser never talks to an analytics service. A booking page, and everything on it, comes from laysa.net; signing in uses the code of the company that runs Laysa’s accounts, served from a laysa.net address.

A visitor to a booking page has no identifier of any kind, not even a pseudonymous one. Laysa can count that a page was opened and cannot count how many people opened it, and that is the intended trade.

10

How to reach us

privacy@laysa.net, for anything on this page. It reaches the controller rather than a queue, and a postal address is available on request from it. A request about your own data is answered within thirty days.

And you can complain about us without going through us. If you think Laysa has handled your personal data wrongly you can go to the supervisory authority of the EU country you live or work in, or to the Italian Garante per la protezione dei dati personali, where Laysa is established. Telling us first is not a step you have to take.

privacy@laysa.net · you also have the right to complain to your national supervisory authority.