Skip to main content

Legal

Privacy Policy

Effective 1 September 2026

This Privacy Policy explains how Rizonesoft operates Systific and how Systific accesses, uses, stores, shares, and deletes information.

1. Scope

Systific is a business operations service provided to authorized users of customer organizations. Your organization may also have its own privacy notices and responsibilities for information entered into Systific.

2. Information we process

  • Account information, such as your name, email address, profile settings, role, permissions, authentication records, and security settings.
  • Business operations information entered by authorized users, including client, contact, project, deliverable, task, time, service, billing, reporting, note, and attachment information.
  • Technical and security information, such as session information, IP address, browser and device information, application logs, error records, and audit activity needed to secure and operate the service.
  • Google Calendar information, but only when an authorized user chooses to connect a Google account as described below.

3. Google Calendar data

Systific uses Google OAuth to request the account identity scopes openid and email, plus the read-only Google Calendar scope https://www.googleapis.com/auth/calendar.readonly.

After you authorize access, Systific receives and stores your Google account identifier and email address, OAuth access and refresh credentials, the identifiers, names, and time zones of calendars available to you, and your explicit calendar selections.

For calendars you select, Systific may import event identifiers, recurrence identifiers, title or Busy status, visibility, event status, start and end times, all-day dates, a Google Calendar link when allowed by the event privacy setting, and the provider update time. Private events are represented as Private event, and the Busy setting removes imported titles and links.

Systific uses this data only to provide the user-facing, one-way calendar import, display imported availability in Systific, keep selected events synchronized, maintain the connection, secure the OAuth flow, and diagnose redacted synchronization outcomes. Systific does not create, edit, or delete events in Google Calendar.

Systific's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. How we use information

  • Provide, maintain, secure, and support Systific and its requested features.
  • Authenticate users, apply permissions, protect accounts, investigate failures, and prevent misuse.
  • Present operational workflows, schedules, notifications, reports, exports, and audit history to authorized users.
  • Improve reliability, performance, usability, and support based on service operations and user feedback.
  • Meet contractual and legal obligations and enforce applicable service terms.

We do not sell Google user data, use it for advertising, or use it to train generalized artificial intelligence or machine-learning models.

5. When information is shared

Information is available to authorized users and administrators according to their Systific permissions. We may use hosting, infrastructure, email, monitoring, backup, and security providers that process information only as needed to operate and protect the service. We may also disclose information when required by law, to protect rights and safety, or as part of a properly governed business transfer.

Google user data is not transferred to third parties except where necessary to provide or secure the user-facing integration, with the user's consent, or where legally required.

6. Retention and deletion

Business and account information is retained according to the customer organization's service arrangements, operational needs, legal requirements, backup cycles, and administrator actions.

Google connection credentials, selected calendar records, and imported events are retained in Systific's active database while the integration remains connected. Using Disconnect Google Calendar attempts to revoke the Google credential and removes the connection, selected calendars, and imported events from the active database. Redacted synchronization outcomes, containing status, counts, and safe error information rather than raw event details, are automatically removed from the active database after 90 days.

Encrypted database backups may temporarily retain copies after active-data deletion. Backups are isolated from normal product use, are used only for security and disaster recovery, and are subject to a separate backup retention schedule. Under the current schedule, a reduced set of recovery points may remain for up to two years.

You may also revoke Systific access through your Google Account's third-party connections page. Revoking access at Google stops future access, but you should also disconnect inside Systific to remove locally stored imported data promptly.

7. Security

Systific uses role-based access controls, authenticated sessions, transport encryption, audit controls, and application-level encryption for Google account identities, OAuth credentials, calendar identifiers, synchronization tokens, event identifiers, and stored Google event links. No system can guarantee absolute security, and users must protect their credentials and report suspected compromise promptly.

8. Your choices and requests

You can choose whether to connect Google Calendar, which calendars to import, whether event titles or only Busy information is displayed, the import window, and when to disconnect. For account access, correction, export, restriction, or deletion requests, contact your organization's Systific administrator or the contact below. Some records may need to be retained where required by law or a valid customer agreement.

9. International processing

Service providers may process information in countries other than the country where you work. Where required, appropriate contractual, organizational, and technical safeguards are used for such processing.

10. Children

Systific is a business service intended for authorized workplace users and is not directed to children.

11. Changes to this policy

We may update this Privacy Policy to reflect changes in Systific, legal requirements, or data practices. The effective date above will be updated when material changes are published.

12. Contact

For privacy questions or requests, email derick@rizonetech.com.