Privacy policy
Last updated Friday, 11 September 2026
This policy explains what personal data Psalmly collects, why we hold it, who we share it with and what you can ask us to do about it. It is written for the United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who we are
Psalmly is a booking platform operated from the United Kingdom. Throughout this policy, “we” and “us” mean the operator of Psalmly, and “you” means either a person who visits this website or a person who uses an account on the platform.
We act in two different capacities, and it matters which one applies:
- We are the controller for the data we hold about our own customers and website visitors — the person who signs up, their account, their subscription and their support conversations.
- We are a processor for the data an organisation puts into its own workspace about its customers, staff and bookings. That organisation is the controller for it, and it decides what is collected and how long it is kept.
What we collect
Account data: your name, email address, hashed password or sign-in method, preferred language, time zone and the organisations you belong to.
Organisation data: the name, address, time zone, currency and branding of an organisation you create, and the plan it is on.
Booking data: services, schedules, bookings, attendance, notes, waitlists, packages and credit balances created inside an organisation. Where you are a customer of an organisation using Psalmly, this data belongs to that organisation.
Payment data: subscription and invoice records. Card details are never seen or stored by us — they are entered directly with Stripe, our payment processor.
Technical data: IP address, browser and device type, pages requested, and the timestamps of security-relevant actions such as sign-in, password change and API key use.
Communications: the content of messages you send us through the contact form or by email, and the delivery status of notifications we send on your behalf.
What we use it for
- Providing the service: creating accounts, showing calendars, taking and confirming bookings, sending reminders and processing payments.
- Keeping it secure: authentication, rate limiting, fraud prevention, audit logging and investigating abuse.
- Billing: charging subscriptions, issuing invoices and collecting overdue amounts.
- Support: answering your messages and diagnosing faults.
- Improving the product: aggregated, non-identifying usage statistics and error reports.
- Legal obligations: keeping accounting records and responding to lawful requests.
We do not sell personal data, and we do not use your booking data to train third-party models.
Our lawful bases
- Contract: providing the service you or your organisation signed up for, and billing for it.
- Legitimate interests: securing the platform, preventing abuse, keeping audit logs, and telling existing customers about material changes to the service. We have balanced these against your rights and you can object at any time.
- Legal obligation: tax, accounting and statutory record keeping.
- Consent: optional marketing email and any non-essential cookies. Consent can be withdrawn at any time without affecting anything done before you withdrew it.
International transfers
Our infrastructure is operated in the United Kingdom and the European Economic Area wherever we can choose. Some processors are established in the United States. Where personal data leaves the UK or the EEA, the transfer is covered by UK adequacy regulations, the International Data Transfer Addendum to the European Commission’s standard contractual clauses, or an equivalent safeguard, together with technical measures such as encryption in transit and at rest.
How long we keep it
- Account data: for as long as your account exists, then deleted within 30 days of the account being closed.
- Organisation and booking data: for as long as the organisation exists. An organisation scheduled for deletion is kept for a short grace period so it can be recovered by mistake-proofing, then permanently removed.
- Invoices and accounting records: six years, as UK tax law requires.
- Audit logs: for the retention period of the organisation’s plan.
- Support messages: two years from the last message in the conversation.
- Server and security logs: 90 days.
Your rights
Under the UK GDPR you have the right to access your data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive your data in a portable format, and not to be subject to a decision based solely on automated processing. We do not carry out automated decision-making that produces legal effects.
Most of these are available without asking: your account settings let you correct your details, export your data and delete your account. For anything else, write to us and we will respond within one month.
If you are a customer of an organisation that uses Psalmly, ask that organisation first — they are the controller for your booking data. We will help them respond.
How we protect it
Data is encrypted in transit with TLS and at rest by our infrastructure providers. Each organisation’s data is isolated by database row-level security, so a query can only ever see the organisation it is scoped to. Access to production data is limited to the people who need it, protected by multi-factor authentication and recorded. Passwords are hashed, integration tokens are encrypted with rotating keys, and every significant change is written to an append-only audit log.
No system is perfect. If a breach affects your rights and freedoms we will tell the Information Commissioner’s Office within 72 hours and tell you without undue delay.
Children
The platform is sold to organisations and is not directed at children. Organisations that teach children often store a child’s name and lesson history under a parent or guardian’s account; that data belongs to the organisation, and it is responsible for the lawful basis and for any consent required.
Changes to this policy
We update this policy when the service or the law changes. The date at the top always reflects the current version, and we email account owners before any change that materially reduces your rights.
Complaints
If you are unhappy with how we have handled your data, please tell us first — most problems are a misunderstanding we can fix quickly. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk or on 0303 123 1113.
How to contact us
For anything in this document, write to support@psalmly.co.uk. Every message is answered by a person, from a real address.