Privacy Policy
1. Introduction
This policy explains how OnTime collects, uses, stores and protects the personal data recorded through the application, in line with applicable local laws.
2. Data collection and processing
Using OnTime involves collecting personal data, in particular about clients (first and last name, contact details, appointment history, professional notes) and about the platform's users (professionals, assistants). This data is entered and managed by the professionals themselves, under their sole responsibility.
3. Purpose of processing
Data is collected only to provide the Services OnTime offers, namely:
- - Managing appointments,
- - Tracking visit and waiting times,
- - Keeping a history of interactions with clients,
- - Taking professional notes,
- - Analysing figures about the professional's activity.
4. Consent and responsibilities
Professionals must obtain their clients' consent before entering anything in the application. OnTime is not responsible if users fail to obtain consent.
The professional is solely responsible for:
- - Informing their clients and obtaining their consent to the processing of their data,
- - Complying with applicable local data protection laws.
The professional is also solely responsible for setting up the custom fields added to client records. These fields are visible only to them and, where relevant, to other professionals in the same organisation, provided they have expressly granted them access. Assistants never have access to this sensitive information. The professional agrees to collect only the data strictly necessary to manage the client relationship and to comply with local data protection regulations. OnTime plays no part in defining, validating or checking the content of these custom fields.
5. Hosting and security
OnTime applies appropriate technical and organisational measures to keep data secure, including:
- - Encrypted communications (HTTPS),
- - Encryption of clients' notes and documents with a key unique to each organisation,
- - Access to data restricted according to each user's role in the organisation,
- - Protection of public forms against bots.
6. Roles and legal bases (GDPR)
For their clients' data (records, appointments, notes, documents), the professional is the data controller. OnTime processes this data on their behalf, as a processor, solely to provide the service.
For account data (name, email, phone and billing details of professionals and their colleagues), OnTime is the data controller. The publisher of OnTime can be reached at contact@on-time.pro.
This processing is based on:
- - Performance of the contract: providing the service subscribed to,
- - A legal obligation: issuing and keeping invoices,
- - Legitimate interest: securing the service and measuring its audience anonymously,
- - Consent: recordings used by AI notes are only made with the client's agreement, which the professional collects and records in OnTime.
7. Processors
OnTime uses the following providers, each for a specific purpose:
- - Convex: the application's database,
- - Cloudflare: website hosting, bot protection, PDF invoice generation and temporary storage of AI notes recordings,
- - Resend: sending emails,
- - SendText, Africa's Talking and Telnyx: sending SMS, depending on the country,
- - Stripe and PawaPay: card and mobile money payments,
- - PostHog: audience measurement, without cookies for visitors,
- - ElevenLabs (via fal.ai) and Google Gemini: transcribing recordings and writing AI notes. The recording is deleted as soon as the note is written.
8. Transfers outside the European Union
Some of these providers process data outside the European Union, in particular in the United States. These transfers are covered by the European Commission's standard contractual clauses included in their contracts, or by the EU-US Data Privacy Framework where they are certified under it.
9. Your rights
Anyone concerned can, at any time:
- - Access their data and get a copy of it,
- - Have it corrected if it is wrong,
- - Ask for it to be deleted, subject to legal retention obligations,
- - Ask for processing to be restricted, or object to it,
- - Receive their data in a readable format (portability),
- - Withdraw their consent, in particular for AI notes.
A professional's client should first contact that professional, who manages their data in OnTime. For account data, or if the professional does not respond, write to contact@on-time.pro: we reply within one month.
You can also lodge a complaint with the data protection authority in your country, for example the CNIL in France or the CDP in Senegal.
10. Cookies and audience measurement
OnTime uses only two cookies, both needed for it to work: the session, to keep you logged in, and your chosen language. On the public website, audience is measured without cookies and without storing anything on your device, so no consent is requested. Once you are logged in, the application keeps your measurement ID to follow how the service is used.
11. Retention period
Data is kept for as long as the professional's organisation uses the service. If the whole organisation's account is closed, data may be kept for up to 2 years, unless deletion is requested earlier or the law requires otherwise. Invoices are kept for as long as the law requires.
12. Changes to this policy
This policy may change at any time. Any significant update will be announced in the application or by email.
Last updated: 28 September 2026.