Privacy notice
How Bloomod handles personal data on behalf of the businesses that send calendar invitations through it.
Last updated 9 August 2026 · Version 1.1
1. Roles
In this notice, “Bloomod”, “we”, “us” and “our” refer to the operator of the Bloomod service. Where you use Bloomod to send calendar invitations, your business is the controller of the event-attendee records you collect or import, and Bloomod is the processor acting on your instructions. Where we handle your own account data — the person who signed up, billing contact, support correspondence — we are the controller.
The processing terms that govern the first relationship are set out in the data processing agreement.
2. What we collect
Account data
- Name, work email address and authentication method of each account member
- Organisation name, connected sending identity and verified Business domain where used
- Role and permission assignments
- Support correspondence
Event-attendee records
- Recipient name and email address
- The event the attendee registered for or was imported into, and their source
- Verification status and the time a magic link was used, where applicable
- Calendar-invite delivery and RSVP state for that event
Technical data
- Log data for application requests and any API access provided in future, including IP address
- Delivery and RSVP events returned by calendar providers
- Event invitation, verification, consent and account activity records
We do not ask for, and Bloomod is not intended to store, special category data, payment card numbers or government identifiers inside attendee records.
3. How it is used
Personal data is processed to:
- Save attendees to the specific event they registered for or were imported into
- Send and validate email magic links for public-form and landing-page registration
- Deliver calendar invitations only to attendees marked Verified when that event’s automation is enabled
- Return delivery and RSVP state to your account
- Enforce sending limits, verification and anti-spam review
- Maintain security and investigate misuse
- Provide support and account communication
We do not sell personal data. We do not use attendee records to build profiles for our own purposes, to train models, or to market to your attendees.
4. Legal basis
For account data we rely on performance of a contract and, for security and abuse prevention, our legitimate interests. For attendee records processed on your behalf, the legal basis is yours to establish and document. You are responsible for ensuring that your event collection and imports are lawful.
5. Sharing
Personal data is shared only with:
- Calendar and mail providers — necessarily, to deliver the invitation to the recipient
- Infrastructure providers — hosting, storage and monitoring under contract
- Authorities — where we are legally required, and where permitted we will tell you first
A current list of subprocessors is available on request from the address below.
6. Retention
- Attendee records are retained while their event and your account are active, or until you delete them
- Verification and delivery records may be retained for a defined period to support audit, security and dispute resolution
- Activity records are retained for a defined period to support audit and dispute resolution
- On account closure, attendee records are deleted or returned within a defined window
7. Your rights
Depending on where you are, you may have rights of access, correction, deletion, restriction, objection and portability. If you are a recipient of an invitation sent through Bloomod, the business that invited you is the controller — we will pass your request to them and support them in answering it.
If you are an account holder, write to the address below and we will respond within the period required by applicable law.
8. Security
Attendee data is available only to authorised organisation members and authorised Bloomod personnel where operationally required. Data is protected in transit and at rest where supported by the deployed infrastructure. Relevant controls are described on the security page. No platform can promise perfect security, and this notice does not claim otherwise.
9. International transfers
Data may be processed outside your country by our infrastructure providers. Where that happens, transfers are made under a recognised transfer mechanism. Calendar providers necessarily receive the invitation in the region where the recipient's account is held.
10. Contact
Questions, requests or complaints: hello@bloomod.com. If you are not satisfied with our response you may complain to your local supervisory authority.