Privacy statement
Last updated on 25 September 2026. Nook is a product by Elevait.
This is an English translation of the Dutch privacy statement, provided for convenience. If the two versions differ, the Dutch version prevails.
Nook is an online scheduling platform by Elevait. This statement explains which data we process, why, with whom we share it, where it is stored, how long we keep it and which rights you have.
Nook has two kinds of users, and the responsibility is different for each of them. Chapter 1 explains that. If you ended up here because you just wanted to book an appointment with a company, be sure to read chapters 1 and 11.
1. Who is responsible
1.1. Elevait is the trade name under which Nook is offered. Elevait is not a separate legal entity. Behind that name are two companies:
- H-Invest BV, registered office Herfstlaan 65, 3010 Leuven, Belgium, company and VAT number BE 0660.838.333, RPR Leuven. Responsible for customers outside Suriname.
- Elevait Services N.V., a public limited company under Surinamese law, file number 173701, Limesgracht 143, Paramaribo, Suriname. Responsible for customers in Suriname.
Which of the two companies acts for you depends on the country of your business or, if you are a private individual, where you live. Article 2 of the terms of service describes this. Where this statement says "we" or "Elevait", it means that company.
1.2. We wear two hats. It matters that you see the difference.
We are the controller for the data of our own customers: the people who hold a Nook account, their users, the billing details and whatever we need to keep the platform secure. For that data we decide ourselves why and how we process it. You can contact us directly about it.
We are a processor for the data of visitors who book an appointment through a booking page. That data belongs to the customer you book with, not to us. That customer decides which questions to ask, why, and how long the answers are needed. We only store and send that data on the customer's instructions and never use it for ourselves.
1.3. The arrangements between us and our customers about that second role are set out in the data processing agreement, Annex 1 to our terms of service.
2. Which data we process
2.1. From account holders and users
- name and e-mail address;
- an encrypted form of the password, which we cannot read back;
- the name of the workspace, the company name, the logo, the website and the accent colour;
- the language, the theme (light or dark) and the currency that have been set;
- the working hours, time zones, days off, locations and appointment types that have been set;
- the login sessions, with the time of the last sign-in;
- the role within the workspace.
2.2. From visitors who book an appointment
- name and e-mail address (always);
- company name and telephone number (only if the customer asks for them);
- the answers to the customer's own questions;
- the choice between an online and an in-person appointment and, for an in-person appointment, the chosen location;
- the time, the duration and the time zone of the appointment, plus the visitor's own time zone;
- the language in which the booking page was used;
- the origin parameters of the link through which the visitor arrived, if they were in the link;
- if the appointment is cancelled: when, by whom and the reason, if any.
2.3. From the calendar and video connections
- the e-mail address at Google, Microsoft (once that connection is available) or Zoom;
- the names and properties of the calendars that were ticked;
- an encrypted key with which Nook may read and write on the customer's behalf;
- the last error message of a connection, so that we can see whether it still works.
2.4. For billing
- the company name, the VAT number, the billing address and the country;
- the chosen plan, the period, the currency, the number of users, the date paid up to and the invoice number.
2.5. Technical
- per appointment, a trace of what happened: which e-mails went out, whether the calendar entry was created, whether the webhook succeeded;
- an internal log of what we changed to a subscription and who did it;
- the ordinary server logs of the web server.
2.6. For a demo request
- name, company, e-mail address, telephone number, the message and the language.
3. What we use it for, and on which legal basis
The table below lists, per processing activity, what we do, which data we use for it and why that is allowed.
| What we do | Which data | Why it is allowed |
|---|---|---|
| Creating and managing an account | 2.1 | Performance of the contract with the customer |
| Showing free slots and recording appointments | 2.2, 2.3 | On the customer's instructions; the customer has its own legal basis |
| Sending confirmation, reminder, change and cancellation e-mails | 2.2 | On the customer's instructions |
| Adding the appointment to the customer's calendar and keeping it up to date | 2.2, 2.3 | On the customer's instructions |
| Creating a video call | 2.2, 2.3 | On the customer's instructions |
| Invoicing and bookkeeping | 2.1, 2.4 | Performance of the contract and a legal obligation |
| Providing support and fixing faults | 2.1, 2.5 | Legitimate interest in keeping the service working |
| Securing the platform and preventing abuse | 2.1, 2.5 | Legitimate interest in a secure service |
| Following up a demo request | 2.6 | Legitimate interest in being able to answer a question |
| Loading conversion tracking on the booking page | See chapter 10 | The visitor's consent, requested on behalf of the customer |
We do not sell data, do not use it for advertising and do not take decisions about you based solely on automated processing.
4. What happens when someone books an appointment
This sequence explains where a visitor's data ends up. It helps to understand why the parties in chapter 6 are on the list.
- The visitor opens the booking page. Nook asks Google (or Microsoft) at which times the customer's calendar is busy and shows the free slots.
- The visitor fills in the form, picks a slot and chooses whether the appointment takes place online or at one of the customer's locations.
- If it is an online appointment via Zoom, Nook first creates the Zoom meeting. The topic of that meeting contains the name of the appointment type and the visitor's name, plus the visitor's company name if it was filled in.
- Nook writes the appointment into the customer's calendar. The title contains the visitor's name and company. The description contains the visitor's name, e-mail address, company, telephone number and answers, plus the link to reschedule or cancel. The visitor is added to the calendar entry as an invitee.
- Nook sends the confirmation e-mail to the visitor and a notification to the customer, through the mail service. A calendar file is attached to the e-mail.
- If the customer has set up a webhook, Nook also sends the appointment data to the address the customer provided.
- If step 4 fails, the appointment does not exist and nothing else happens.
What stands out here, and what we do not want to hide: the visitor's data ends up in the customer's calendar, and therefore also at Google or Microsoft. That is the core of what a scheduling platform does, but it does mean that those parties see that data. We advise customers to inform their visitors about this in their own privacy statement.
5. The calendar connection
5.1. The customer connects their own Google account or, once available, their Microsoft 365 account. In doing so they give explicit consent on Google's or Microsoft's own screen. We only store an encrypted key, never the password.
5.2. At Google, Nook requests exactly three calendar permissions, no more:
- the list of calendars of the account, so that the customer can choose which ones Nook may use;
- the free/busy information per calendar, so that Nook knows which slots are still free;
- the right to create, move and delete events, so that Nook can put the booked appointments into the calendar.
Nook deliberately does not request the right to read the calendar. The app only asks, per period, which blocks are busy and does not read the titles, descriptions or attendees of existing events. The right to manage events would technically also allow reading existing events; Nook does not do that and uses that right only for the events Nook created itself.
5.3. At Microsoft, once that connection is available, Nook requests the right to read and write the calendar, because Microsoft offers no narrower permission that also allows writing events. There too, Nook only uses the free/busy information and its own events.
5.4. Limited use of Google data.
Nook's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice: we use Google data solely to connect the customer's calendar, show free slots and add and update appointments in that calendar. We do not transfer it to third parties, except where necessary to provide those functions, where the customer explicitly asks for it, or where the law requires it. We do not use it for advertising and do not allow humans to read it, unless the customer explicitly asks for it, it is necessary for security or to comply with the law, or the data has been aggregated so that it can no longer be traced to a person.
5.5. The customer can withdraw their consent at any time, in Nook or directly at Google, Microsoft or Zoom. We then delete the key on our side.
6. With whom we share data
We engage the following parties. We do not sell data to anyone and do not pass it on for purposes other than those listed below.
| Party | What they do | Which data they receive | Where | Transfer |
|---|---|---|---|---|
| Amazon Web Services EMEA SARL | The server and the database on which Nook runs, plus the backups | Everything in chapter 2: accounts, appointments, visitors' answers, encrypted keys, logs | European Union (Frankfurt, Germany) | Within the European Economic Area, no transfer needed |
| Google Ireland Limited | Google Calendar and Google Meet | The customer's e-mail address, their calendar data, plus per appointment the visitor's name, e-mail address, company, telephone number and answers | Ireland and the United States | EU-US Data Privacy Framework and Google's standard contractual clauses |
| Microsoft Ireland Operations Limited (once the connection is available) | Outlook and Microsoft 365 calendar, plus Microsoft Teams | The same data as with Google, for customers who connect Microsoft | Ireland and the United States | EU-US Data Privacy Framework and Microsoft's standard contractual clauses |
| Zoom Video Communications, Inc. | Video calls via Zoom, for customers who connect Zoom | The customer's Zoom account, plus per meeting the topic (name of the appointment type, name of the visitor and their company if filled in), the time and the duration | United States | EU-US Data Privacy Framework and Zoom's standard contractual clauses |
| One.com Group AB | The outgoing e-mail of the platform and of the appointments | The recipient's e-mail address and the content of the e-mail, with the appointment details and the calendar file | European Union | Within the European Economic Area, no transfer needed |
6.1. The customer's own webhook. If a customer sets up a webhook, Nook sends the appointment data to the address the customer provides, for example their own system. The customer chooses that address. What happens afterwards is the customer's responsibility. That recipient is not a sub-processor of ours.
6.2. The customer's conversion tracking. See chapter 10. Those services belong to the customer. Elevait and the customer are joint controllers for the loading of those scripts; see chapter 10 for the division of responsibilities.
6.3. We only pass data on when the law or a court decision requires us to.
7. Where the data is stored
7.1. Nook runs on a server at Amazon Web Services in the European Union, in the eu-central-1 region (Frankfurt, Germany). The database with all accounts, appointments and answers is stored there, as are the nightly backups. For that storage there is no transfer outside the European Economic Area.
7.2. Google, Microsoft and Zoom also process part of the data in the United States. That only happens for customers who switch on such a connection themselves, and only with the data needed for that connection. For each of those transfers we rely on the EU-US Data Privacy Framework and, where needed, on the standard contractual clauses of the European Commission.
7.3. Outgoing e-mail goes through one.com, a provider within the European Union.
8. How long we keep it
| What | How long |
|---|---|
| Appointments and visitors' answers | As long as the customer's workspace exists, in practice as long as the customer uses Nook. After the end of the subscription the periods below apply. The customer, as controller, may request earlier deletion; we carry it out within thirty days. A visitor can ask the customer to have their data deleted earlier (chapter 11). |
| The log per appointment (e-mails, calendar actions, webhooks) | Disappears together with the appointment. |
| Server logs of the web server | Limited to a fixed size per log file; the oldest lines are continuously overwritten. In practice they are kept for a few weeks. |
| Account details and settings | As long as the account exists. |
| After the end of the subscription: dashboard readable, account recoverable | 30 days after the end date. |
| After the end of the subscription: final deletion of workspace, appointments and connections | No later than 60 days after the end date. |
| Login sessions | 30 days, extended each time they are used. |
| One-time links | The link to confirm an e-mail address expires after 72 hours; the link to reset a password after 1 hour; both also after use. |
| Encrypted keys of calendar and video connections | Until the connection is disconnected or the account is removed. |
| Database backups | 14 days. |
| Invoices and accounting records | 7 years (statutory retention period in Belgium for H-Invest BV). |
| Demo requests | 30 days after the request, then deleted automatically. |
| Trial accounts in which nothing ever happened | 30 days after creation, then deleted automatically. |
| Internal log of subscription changes | As long as the account exists, then deleted with it. |
8.1. Appointments that Nook has already written into the customer's calendar stay there. That calendar belongs to the customer and we delete nothing from it, not even after cancellation.
9. Cookies and local storage by Nook itself
9.1. On the booking pages Elevait itself places no cookies at all and does not measure visitor behaviour. There is no analytics service of ours, no tracking pixel and no visitor statistics. Booking is therefore possible without anything of ours being placed on the visitor's device.
9.2. On the website and in the Nook dashboard we only use what is technically necessary:
| Name | Purpose | How long |
|---|---|---|
| nook_sessie | Keeping you signed in | 30 days, extended each time it is used |
| nook_taal | Remembering whether you want the site in Dutch or English | Until you delete it |
| nook_thema | Remembering whether you want light or dark mode | Until you delete it |
| nook_munt | Remembering in which currency you want to see prices | Until you delete it |
9.3. If a customer switches on conversion tracking on their booking page, the visitor's browser additionally stores their answer to the consent question (nook_meting), so that the question does not come back on every visit. That choice stays on the visitor's own device and never reaches us.
10. The customer's conversion tracking
10.1. Customers on a suitable plan can put Google Analytics, Google Tag Manager or a Meta pixel on their booking page themselves.
10.2. The tracking belongs to you, the customer. You are the controller for everything that happens with the tracking data once the scripts have been loaded. You decide what is measured and you are responsible for your own cookie policy and the information you give to visitors.
For loading the tracking scripts on the booking page we serve, Elevait and you are joint controllers within the meaning of Article 26 of the General Data Protection Regulation. Elevait takes care of the consent question, of blocking the scripts as long as there is no consent and of the technical operation of the loading. You choose which scripts are loaded and for what purpose, you provide the information in your own privacy and cookie policy and you are responsible for what the tracking service does with the data afterwards. What Google or Meta do afterwards is outside our control. For processing by Google, see the privacy policy at policies.google.com/privacy; for Meta, see privacycenter.fb.com.
If you are a visitor with a question about the tracking, first contact the company of the booking page. About the consent question and the loading itself you can also reach us at nook@elevaitservices.com. The full division of tasks is in article 13 of the terms of service.
10.3. Nook loads nothing before the visitor has given consent, in accordance with Article 129 of the Belgian Electronic Communications Act. A question with two buttons appears at the bottom of the booking page. If the visitor refuses, nothing is loaded and they can simply book. Their choice is stored on their own device. The consent question contains a link to your own privacy policy; you enter that URL in your dashboard. If you have not entered a URL, no tracking scripts are loaded on your booking page until you have.
10.4. If the visitor does give consent, the Google or Meta scripts are loaded and, after a successful booking, one event goes to the customer's tracking, with the name of the appointment type. With Google Analytics the IP address is truncated.
10.5. If you want to know what a particular customer measures, ask that customer. We have no access to their tracking.
11. For visitors: whom to contact
11.1. If you booked an appointment through a booking page and want to know which data is stored about you, or want it changed or deleted, contact the company you booked with. That company decides about your data, not we.
11.2. If you no longer know whom you booked with, or you get no answer, e-mail nook@elevaitservices.com. We will not answer your question ourselves, but we will help you find the right company and inform that company of your request.
11.3. If you want to reschedule or cancel a planned appointment, use the link in your confirmation e-mail. You do not need an account for that.
12. Security
12.1. What we do:
- all connections run over https;
- the server and the database are in the European Union, at a provider with the usual data centre certifications;
- passwords are stored as scrypt hashes and cannot be read by us;
- the keys of the calendar and video connections are encrypted with AES-256-GCM;
- session tokens are stored only as hashes and expire after thirty days;
- each customer's data is strictly separated per workspace;
- a backup is made every night and kept for fourteen days;
- access to the servers is limited to a small number of people, with key authentication;
- the webhooks to customers' systems are signed, so that the recipient can verify the origin.
12.2. Our staff can access a customer's data to provide support and fix faults. That does not happen systematically and never for other purposes.
12.3. We have not appointed a data protection officer. That is not mandatory for an organisation of this size with these processing activities.
12.4. If something does go wrong with data, we inform the affected customer without undue delay and, where reasonably possible, within 48 hours of becoming aware of it. If we do not yet know everything at that point, we send a first notification and complete it as soon as we have more information. You, as controller, notify the supervisory authority and the data subjects. We provide the information you need for that. For our own account data we make that notification ourselves.
13. Your rights
13.1. You have the right to access your data, to have it corrected or deleted, to have processing restricted, to object, and to receive your data in a common format (portability).
13.2. Where processing is based on your consent, you can withdraw it at any time. That does not affect what happened before.
13.3. If you are a Nook customer, e-mail nook@elevaitservices.com. We reply within one month. You can do much of this yourself in your dashboard.
13.4. If you are a visitor who booked an appointment with a company, read chapter 11.
13.5. If you are not satisfied with how we handle your data, in Belgium you can lodge a complaint with the Data Protection Authority, Drukpersstraat 35, 1000 Brussels (gegevensbeschermingsautoriteit.be). Customers and visitors in Suriname can address any question or complaint directly to us at the same address.
14. Changes
We update this statement when our way of working or the regulations change. The date at the top shows when that last happened. For a material change, we inform our customers by e-mail.
15. Contact
- Questions about this statement and about your data: nook@elevaitservices.com
- Invoices and accounting: boekhouding@elevaitservices.com
- If you get no reply at nook@, you can also reach us at info@elevaitservices.com
- H-Invest BV, Herfstlaan 65, 3010 Leuven, Belgium, company and VAT number BE 0660.838.333, RPR Leuven
- Elevait Services N.V., a public limited company under Surinamese law, file number 173701, Limesgracht 143, Paramaribo, Suriname