Last updated: May 16, 2026 · 🇨🇭 Schedly, Switzerland
On this page
This Privacy Policy describes how Schedly processes personal data when you use our website and service. DSG refers to the Swiss Federal Act on Data Protection (revDSG, in force since 1 September 2023) and applies to persons in Switzerland. GDPR refers to the EU General Data Protection Regulation and applies to persons in the European Union who use our service.
Schedly is a scheduling tool that helps you find shared free time across multiple iCalendar feeds. We take your privacy seriously and are committed to full transparency. In short: we do not store the contents of your calendar events.
The controller within the meaning of data protection law is:
SchedlySchedly uses only strictly necessary cookies. No consent banner is required for these:
.AspNetCore.Antiforgery.* -
a CSRF protection token required for form submissions. Contains no personal data; deleted when you close your browser.
.AspNetCore.Identity.Application -
an encrypted authentication session cookie set when you sign in. Deleted on sign-out or browser close.
We do not set any marketing, analytics, or third-party cookies. You can manage cookies in your browser settings, but disabling the above cookies will prevent you from signing in.
Data is processed primarily in Switzerland. The Swiss Federal Council has determined that Switzerland provides an adequate level of data protection. Where processors operate outside Switzerland/EU, we ensure appropriate safeguards (e.g. EU Standard Contractual Clauses) are in place.
Infrastructure & Hosting
Schedly is hosted exclusively on Hostfactory.ch, a Swiss hosting provider. The application server and database are physically located in Switzerland. No user data is transferred outside Switzerland for storage or processing.
Encryption in Transit
All connections to schedly.ch are enforced over HTTPS / TLS. Plain HTTP requests are automatically redirected to HTTPS; unencrypted access is not possible. Calendar feeds are fetched by our server over HTTPS only - webcal:// links are silently converted to https:// before the request is made.
Encryption at Rest & Password Security
Passwords are hashed using PBKDF2 with SHA-512 via ASP.NET Core Identity and are never stored in plain text. Access to the production database is restricted to the operator only.
Application Logs
The application writes technical logs for operational and debugging purposes (e.g. "calendar feed could not be reached", "SMTP connection established"). These logs do not contain calendar event contents, calendar URLs, or email addresses of recipients. Application logs are retained for up to 30 days.
Server Access Logs
Standard web-server access logs (IP address, timestamp, requested URL path, HTTP status code) are retained for up to 7 days for security and operational purposes, then deleted. See §3 for the legal basis.
Account Security
Sign-in is protected by account lockout: five failed attempts trigger a five-minute lockout. A verified e-mail address is required before any account becomes active. All forms are protected against cross-site request forgery (CSRF) via anti-forgery tokens.
Under Swiss data protection law (revDSG) and, where applicable, the EU GDPR, you have the following rights. To exercise any of them, contact us at privacy@schedly.ch. privacy@schedly.ch.
If you believe that the processing of your personal data violates applicable law, you have the right to lodge a complaint with a supervisory authority.
We may update this policy from time to time. The date at the top of this page reflects the most recent revision. We will notify registered users of material changes by email. Continued use of Schedly after changes are published constitutes acceptance of the revised policy.
Questions or requests regarding your data can be sent to:
Schedly