Legal
Privacy Policy
Effective: September 8, 2026
1. Who we are
AlwaysOnTime is operated by Talistech BV, Oudenaardsesteenweg 368, 9420 Erpe-Mere, Belgium, VAT number BE1009.245.408. Contact: hello@alwaysontime.io. Talistech is the controller for your account, billing, security and service-management data and operates the hosting and email infrastructure used by AlwaysOnTime. For recipient data entered by a business customer, Talistech acts as processor and that customer remains controller.
2. What we collect
We collect only what is needed: account identity and login data, including a Google account identifier and verified email when Google sign-in is used; names, email addresses and phone numbers of recipients; reminders, message content, dates and time zones; consent, opt-in and opt-out records; channel and delivery status; billing profile, invoices and payment references; support and privacy requests; security, audit and technical logs; and analytics data only after consent.
3. Why and on which basis
We process data to provide the service and fulfil contracts, authenticate accounts, comply with tax and accounting obligations, send reminders selected by the account holder, protect the service and prevent abuse based on legitimate interests, and use optional analytics only with consent. We do not use recipient or WhatsApp data for advertising, profiling or unrelated enrichment.
4. Identity and delivery providers
Google may be used as an identity provider. When you choose Google sign-in, Google receives the authentication request and provides AlwaysOnTime with your stable Google account identifier, verified email and basic profile name. We do not retain Google access or refresh tokens. When WhatsApp is selected, the recipient’s phone number, approved reminder template data, delivery identifier, delivery status and errors are sent to Meta/WhatsApp. WhatsApp is used only for wanted, transactional reminders. Recipients can send STOP, UNSUBSCRIBE or CANCEL to opt out. Talistech operates the AlwaysOnTime hosting and email infrastructure. Google, Meta/WhatsApp, Stripe and optional Google Analytics are external providers and receive only the data needed for their service. Current provider details are maintained in our Data Processing Addendum.
5. Retention
Account and reminder data is kept while the account is active and deleted after a verified deletion request, except where retention is required by law. Google sign-in links are deleted with the account. Delivery and operational records are normally kept for up to 12 months. Temporary request tokens expire after 24 hours. Invoices, payment records and accounting evidence are retained for the statutory Belgian period, currently ten years, and are restricted to that purpose. Security and dispute records may be retained for as long as reasonably necessary.
6. Your rights
You may request access, correction, deletion, restriction, portability or object to processing. Use the Privacy Center or email hello@alwaysontime.io. We verify identity before releasing or deleting data and respond without undue delay and normally within one month. You may also complain to the Belgian Data Protection Authority.
7. Security and changes
We use access controls, secure transport, secret protection, rate limits, audit logging and least-privilege operational access. No internet service can guarantee absolute security. We may update this policy when our processing changes; the effective date above identifies the current version.