Privacy Policy.

Last updated 22 July 2026

Who we are

Booqit is a booking backend operated by Katoa GmbH, Stanserstrasse 100, 6064 Kerns, Schweiz (registered in the Swiss commercial register, UID CHE-469.243.715; “we”, “us”). We are the data controller for the personal data described here. For contact details see our support page and imprint.

What we collect

  • Account data — the email address and name you provide when you sign up, and authentication metadata.
  • Booking data — the polls, booking pages, options, and responses you and your invitees create. Invitees may submit a name, an email, and their availability to respond to a link.
  • API keys — we store a hash of each key, never the secret itself, plus its name, scopes, and timestamps.
  • Billing data — subscription status and a customer reference. Card details are handled by our payment processor; we never see or store full card numbers.
  • Technical data — basic request logs and session metadata (IP address, user-agent) needed to run the service securely and debug problems.
  • Optional summary/suggestion features — if you use the optional poll-summary feature, the poll title and invitees’ free-text notes (not their names) are sent to an automated text-processing / inference subprocessor. The suggestion feature sends only a title and constraints, with no participant data.

Guest names, emails and notes are stored encrypted at rest (AES-256-GCM).

Why we process it (legal bases)

We process account and booking data to provide the service you asked for (Art. 6(1)(b) GDPR — performance of a contract), billing data to take payment and meet legal obligations, and technical data on the basis of our legitimate interest in operating a secure, reliable service (Art. 6(1)(f)). We do not sell your data and we do not run advertising or third-party tracking.

Where your data is processed

We use service providers who process personal data on our behalf as processors under a data processing agreement (Art. 28 GDPR). Some of them operate outside Switzerland or the EU, and we do not claim EU-only hosting or data residency. Where a transfer goes to a third country, it relies on appropriate safeguards, in particular the EU Standard Contractual Clauses (Art. 46 GDPR). The GDPR applies to the personal data of people in the EU/EEA regardless of where the processing happens, and we honour it accordingly. The categories below describe what each type of provider processes.

CategoryData processedThird-country transfer & safeguard
Cloud hosting & computeAll request data passing through the service: account, booking and guest data, IP addresses, server logsSome providers operate outside Switzerland/the EU; transfers rely on appropriate safeguards (Standard Contractual Clauses, Art. 46 GDPR)
Database hostingAll stored application data: name, email, session metadata, hashed tokens, encrypted guest data, votes, bookings, billing reference, API-key hashes, admin auditAccess from outside Switzerland/the EU may occur; safeguards in place (SCCs, Art. 46 GDPR)
Payment processingAccount holder name and email, user ID, card/payment data sent directly to the processor (we never store full card numbers)Onward transfer outside the EU may occur; SCCs (Art. 46 GDPR)
Transactional email deliveryGuest name and email, booking details, notes, calendar attachment (.ics) — only when email delivery is configuredProvider may be outside Switzerland/the EU; SCCs (Art. 46 GDPR)
Optional text-processing / inference (summary & suggestion features)Suggestions: title and constraints only, no participant data. Summary: poll title and participants’ free-text notes, no names. Only when you use these featuresProcessed outside Switzerland/the EU; SCCs (Art. 46 GDPR)

A current list of our sub-processors is available on request — contact us via our support page.

How long we keep it

We keep account and booking data for as long as your account is active. Delete a poll or booking page to remove its responses, or close your account to remove your account data, subject to retention we are legally required to keep (e.g. invoicing records).

Your rights

Under the GDPR you have the right to access, correct, delete, port, and restrict processing of your personal data, and to object to processing based on legitimate interests. To exercise any of these, contact us via the support page. You may also lodge a complaint with a data protection supervisory authority.

Changes to this policy

We may update this policy as the service evolves. Material changes will be reflected in the “last updated” date above.

This page is provided for transparency and is not legal advice.