Privacy Policy

Last Updated: September 19, 2026

StudyQR FZ-LLC ("we," "our," or "us") operates StudyQR (the "Platform"). We are committed to protecting your privacy and handling your data transparently in accordance with the General Data Protection Regulation (GDPR) (EU 2016/679), the EU-U.S. Data Privacy Framework, and Google / Microsoft API policies.

1. Data Controller & Contact Information

Under the GDPR, StudyQR FZ-LLC is the Data Controller responsible for your personal data.

  • Legal Entity: StudyQR FZ-LLC
  • Registered Address: In5 Tech, Dubai Internet City, Dubai, United Arab Emirates
  • Privacy & Support Email: [email protected]
2. Information We Collect

A. Account & Profile Data
  • Name, professional email address, job title, and institution/school affiliation.
  • Profile credentials and authentication tokens via OAuth 2.0.
B. Google Calendar & Microsoft Graph API Data

When you explicitly grant permission to connect your Google Workspace or Microsoft 365 Outlook Calendar, we collect and process:

  • Calendar Metadata: Calendar IDs, time zones, and availability/busy slots.
  • Event Details: The titles, start/end times and locations of events on your calendar, used only to show when you are busy; and the title, time, description and meeting link of the StudyQR meetings and availability slots we add to your calendar. We do not add attendees to these events, so no invitations are sent on your behalf.
  • OAuth Access & Refresh Tokens: Encrypted credentials used strictly to maintain your calendar synchronization.
3. How We Use Calendar Data & Legal Basis (GDPR)

We process your data only when we have a valid legal basis under GDPR Article 6:

Purpose / Service FunctionData Types InvolvedGDPR Legal Basis
Schedule Matchmaking & Booking (Checking availability to prevent double-booking)Calendar busy status, Event Start/End timesContract Performance (Art. 6(1)(b))
Inserting Summit Meetings (Writing confirmed 1-on-1 agendas into your calendar)Event Title, Description, Location, AttendeesConsent via OAuth Prompt (Art. 6(1)(a))
Security & AuthenticationEncrypted Tokens, Audit logsLegitimate Interest (Art. 6(1)(f))
4. Google API Limited Use Disclosure

Mandatory Google Policy Clause:

StudyQR's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We do not use Google Calendar data for serving advertisements (including personalized, retargeted, or interest-based ads).
  • We do not share, sell, or rent Google Calendar data to third parties, data brokers, or ad networks.
  • We do not use Google Calendar data to train machine learning or AI models.
  • Human access to your Google Calendar data is strictly prohibited, except when explicitly requested by you for technical troubleshooting, required by law, or as part of a security investigation.
5. Microsoft Graph Data Usage Disclosure

We access Microsoft 365 / Outlook calendar data exclusively via official Microsoft Graph APIs using least-privilege permissions (e.g., Calendars.ReadWrite). We do not mine, sell, or use Microsoft Graph data for advertising or market research. Data protection extends to all cached calendar records in full compliance with the Microsoft API Terms of Use.

6. Data Sharing & Sub-processors

We never sell your personal or calendar data. We share data only with necessary third-party sub-processors bound by strict Data Processing Agreements (DPAs) under GDPR:

  • Cloud Infrastructure & Hosting: Google Cloud Platform / AWS (Data hosting in EU/AES-256 encrypted data centers).
  • Identity & Authentication: Firebase Authentication.
  • System Monitoring: Firebase Crashlytics / Sentry (No raw calendar content processed).
7. International Data Transfers

If personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are implemented in accordance with GDPR Chapter V, including:

  • Transferring to countries recognized by the European Commission as providing adequate data protection.
  • Executing Standard Contractual Clauses (SCCs) approved by the European Commission with international vendors.
8. Data Retention & Revocation

  • Active Retention: Calendar data is retained only as long as your account remains connected to the Platform. Cached calendar events are automatically updated or purged.
  • Instant Revocation & Deletion: You can disconnect your Google or Microsoft Calendar at any time via your Account Settings, or directly through your Google Security Account Settings / Microsoft Apps & Services Portal.
  • Permanent Eradication: Upon disconnecting your calendar or deleting your account, stored OAuth tokens, cached event items, and sync logs are permanently deleted within 30 days.
9. Your Rights Under GDPR

If you are located in the EEA, UK, or Switzerland, you hold the following rights regarding your data:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate personal data.
  • Right to Erasure / "Right to be Forgotten" (Art. 17): Request permanent deletion of your data.
  • Right to Restrict Processing (Art. 18): Limit how we use your data.
  • Right to Data Portability (Art. 20): Export your data in a structured, machine-readable format (JSON/CSV).
  • Right to Withdraw Consent (Art. 7(3)): Revoke calendar OAuth authorization at any time.

To exercise any of these rights, email us at [email protected]. You also have the right to lodge a complaint with a European Data Protection Authority (DPA).

10. Security Measures

We employ technical and organizational safeguards to protect your data:

  • In Transit: All data sent between your browser, our servers, and Google/Microsoft APIs is encrypted using TLS 1.2 or TLS 1.3.
  • At Rest: Stored data is encrypted using AES-256 disk-level encryption. OAuth refresh tokens are encrypted at the application layer with separate key management systems.
11. Updates to This Policy

We may update this Privacy Policy periodically. If we make material changes affecting how calendar data is processed, we will notify you by email or via a prominent notice inside the Platform at least 14 days prior to implementation.