Legal

Terms of Service

The agreement between you and Laysa when you use a Laysa account. Annex A is the data processing agreement that applies because your clients' data passes through us; Annex B names every company that data touches.

Version 1.3Last updated 20 September 2026In force from 20 September 2026
1

Who we are

Laysa is operated by Andrea Castoldi, a natural person established in Italy, in the European Union, and the controller of the account data of every professional who uses it. The service is reachable at hello@laysa.net for anything about itself, and at privacy@laysa.net for anything about personal data. Both addresses are answered by the same person.

A postal address is available on request, from either of those addresses. There is no phone line and no chat widget, and we would rather say so than pretend otherwise.

2

What the service does, and what it does not do

Laysa gives you a public booking page, records the sessions people book on it, keeps a client record built from those sessions, and tells you when a client has stopped booking. It sends transactional email in your name, with your own address as the reply-to.

Laysa does not take payments, hold deposits, issue invoices or touch money in any form. It does not contact your clients on your behalf beyond the confirmations and reminders listed in Annex A clause 3. It cannot prevent a client from failing to attend; reminders reduce that, and nothing in this agreement promises to eliminate it.

3

Free during beta

The service is free while it is in beta. There is no price, no trial period counting down, and no payment details held anywhere, because the product has no field in which to enter them. If and when paid plans are introduced you will be told by email at least thirty days before anything changes, and continuing to use the service after that date is what would make a plan apply to you. Nothing you have entered is held back if you decline: your export works during beta, after beta, and after you have decided to leave.

No paid plan is ever applied retroactively. Nothing you did while the service was free can be put behind a payment afterwards, and nothing you were already using is taken away and sold back to you. A plan applies from the day you accept it and never to the days before it.

4

Your clients' data, and who is responsible for it

The people who book sessions with you are your clients, not ours. In the language of the GDPR you are the controller of their personal data and Laysa is your processor: we handle it on your documented instructions and for no purpose of our own. What that obliges each of us to do is set out in Annex A, which forms part of this agreement and does not need to be signed separately.

Your clients are told this on the booking form, before they submit it, and they are given your name as the controller and privacy@laysa.net as the route to reach us.

5

Your account

One account, one person, one public address. You are responsible for what happens under it, and for the accuracy of the availability you publish — Laysa offers exactly the times you declare and cannot know about a commitment you never wrote down.

6

What you may do

Use the service for your own professional practice, publish your booking page anywhere you like, and export your data whenever you want. No permission is needed for any of that, including leaving.

7

What you may not do

Upload a cover image you have no right to use, publish a booking page for someone who has not agreed to it, resell access to the service, or use it to collect data you would not be allowed to collect elsewhere. Laysa has no custom fields, which removes most of the ways this goes wrong.

And you may not use Laysa for health data, or for any other special category of personal data under Article 9 of the GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic or biometric data, data concerning health, and data concerning a person's sex life or sexual orientation. There is no field in Laysa that invites any of it, which is the real defence; this clause covers the one place it could still be typed, which is a note. A note recording a diagnosis, a symptom or a treatment is the thing this clause forbids.

We may suspend or close an account that breaks this clause, and we will say which part.

8

Email sent in your name

Confirmations, reminders, reschedules and cancellations are sent from notifications@laysa.net with your name in the From line and your own address as the reply-to. They are transactional and carry no promotion of Laysa or of anything else. You cannot switch off a confirmation, because a session nobody was told about is not a session.

9

Availability and support

This is a beta operated by a small team. There is no uptime guarantee, no service credit and no support desk — there is one email address, answered by a person, usually within a working day. We would rather state that than publish a number we cannot hold to.

10

Ending your account

You may delete your account from Settings at any time. It is suspended immediately, your booking page stops answering, sessions ahead are cancelled and those clients are told, and everything is erased after thirty days. Until that date you can restore it. We may close an account that breaks clause 7, and we will say which part.

11

Our liability

Laysa is provided as it is, and nothing here excludes liability for death, personal injury or fraud, or any right you have as a consumer. Beyond that, and because the service is free, our liability is limited to what the law does not allow us to exclude. A missed session is not a loss Laysa can be asked to underwrite.

12

Changes to these terms

Material changes are emailed to you at least thirty days before they take effect, with the version number and the date they start applying. Superseded versions are kept. A change you do not accept is a reason to export and leave, and both are one click.

13

Governing law

This agreement is governed by the law of Italy, where Laysa is established, and the Italian courts have jurisdiction over any dispute arising out of it.

That does not take away anything you have as a consumer. If you use Laysa outside your trade, business or profession, you keep every mandatory protection of the country you live in, including the right to bring proceedings before its courts and to be sued only there. A clause about which law applies cannot remove those, and this one does not try to.

Annex A

Data Processing Agreement

Twelve clauses, under Article 28(3) GDPR. They apply from the moment your booking page receives its first session and require no separate signature.

A.1
Subject matter and durationLaysa processes your clients' personal data solely to operate your booking page and client record, for as long as your account exists and thirty days beyond its deletion.
A.2
Nature and purposeStoring bookings and sessions, deriving the client record from them, and sending the transactional email listed in clause 3. No other purpose, and no use of your clients' data to train anything.
A.3
Categories of data and of data subjectYour clients: name, email address, timezone, session times and outcomes, and any note either of you wrote. No special-category data is collected, and the field list is closed by design.
A.4
Documented instructionsLaysa acts only on your instructions, which are the settings you choose and the actions you take in the product. If a law obliges us to do otherwise we tell you first, unless that law forbids it.
A.5
ConfidentialityEveryone with access is bound by confidentiality. Access to production data is limited to the person who operates Laysa and to what is needed to keep the service running, and every connection to the database is recorded by the hosting provider.
A.6
Security measuresEncryption in transit and at rest, per-tenant isolation at the database, application-level encryption of calendar tokens, nightly backups held outside the hosting provider, and a restore that is tested rather than assumed.
A.7
Sub-processorsThe current list is Annex B. You are told by email thirty days before anyone is added, and you may object; if we cannot resolve the objection you may terminate and export.
A.8
International transfersThe database and its files are held in the European Union, in Frankfurt, and the application runs there. Some of the companies in Annex B are based in the United States and process data there as part of what they do; those transfers rely on the Standard Contractual Clauses, and on the EU–US Data Privacy Framework where the company is certified. Annex B says which.
A.9
Assistance with data-subject requestsThe product answers most requests without us: export and deletion are controls in your settings. Where a request reaches us instead, we pass it to you and help you answer it.
A.10
Personal data breachWe notify you without undue delay and in any case within 48 hours of becoming aware, with what we know, what we do not yet know, and what we are doing. A late notification with a complete story is worse than an early one with gaps. Where your use of Laysa calls for a data protection impact assessment, or a prior consultation with a supervisory authority, we give you what we know to help you carry it out.
A.11
Deletion or returnOn the deletion of your account everything is erased after the thirty-day grace period, backups included on their own rotation. Sessions already written to your own calendar stay there — they are yours, and they were never only ours to delete.
A.12
Audit and informationWe provide the information needed to demonstrate compliance with this annex, and accept an audit where the law requires one. For a service of this size that normally means answering a questionnaire honestly.
Annex B

Sub-processors

Every company that processes personal data on Laysa's behalf, what it does, and where the data is. This list is public and versioned; you are told by email thirty days before anyone is added, and you may object. Sentry is listed before it receives anything, so that turning it on is not an addition.

Sub-processorWhat it doesWhere the data is
VercelHosting, application functions, scheduled jobs, rate limiting and bot filteringFrankfurt, EU for the application; the company is in the United States, under the Standard Contractual Clauses
SupabaseDatabase and file storageFrankfurt, EU
ClerkSign-in and account authentication (professionals only)United States, under the EU–US Data Privacy Framework and the Standard Contractual Clauses
ResendDelivery of transactional emailSent from Ireland, EU; the company is in the United States, under the EU–US Data Privacy Framework and the Standard Contractual Clauses
GitHubMakes the nightly backup and keeps it for fourteen days, encrypted with a key GitHub does not holdUnited States, under the EU–US Data Privacy Framework and the Standard Contractual Clauses
SentryError reporting, with personal data scrubbedGermany, EU

Google is not on this list, because it does not act on Laysa's behalf. If you connect your calendar, the sessions Laysa writes there are held by Google under your own Google account, and Google's API terms make it an independent controller of what it receives. Disconnecting withdraws the permission the same day; the events already written to your calendar stay there, because they are yours.

16

How to reach us

hello@laysa.net for anything about the service, privacy@laysa.net for anything about personal data. Both reach the same person, and a postal address is available on request from either.

There is no ticket number and no queue. Clause 9 says what the reply time is worth: it is what happens, not a level you can hold us to.

Questions about this document: hello@laysa.net · about personal data: privacy@laysa.netVersion 1.3 · superseded versions are kept and are available on request.