Capturing your email address is essential for delivering our sync to calendar service;
Email serves as the unique identifier for your ECAL calendar subscription – it’s how we know which events and schedules to sync to your personal calendar and to ensure we provide a smart, dynamic and interactive calendar marketing and communications service.
For users who sync with Google Calendar or Outlook/Office 365, the requirement is also technical. These platforms use OAuth, a secure authentication standard I’m sure you know.
When you grant ECAL permission to sync events to your calendar, those platforms (Google/Microsoft) authenticate your identity using your email address.
To maintain that active “sync” connection – ensuring events update automatically if times or details change – our system must maintain a token associated with that unique identity. The email address acts as the unique identifier that anchors this secure connection.
The “Intimate Space” Security Principle
We recognise that a personal calendar is a highly private and intimate digital space. Unlike a social media profile, there is no “public address” for your calendar; in this instance, the connection exists solely via ECAL.
Because this channel is so unique and the data so sensitive, our security obligations are significantly higher than those of a standard website. We treat your calendar with the same level of protection as a financial or personal communication tool.
As detailed in our Privacy Policy, we take additional steps to strengthen user privacy and security. These include a restriction in our system to only ever be able to access events that are published by ECAL (not your primary or work or family events). We also provide a ‘Manage My ECAL‘ function in every event to help users self-manage their calendar subscriptions.
To satisfy the specific requirements of GDPR, we collect your email address based on Legitimate Interest (Security). This ensures a “security line” to your private calendar; if a platform breach or malicious access is detected, we have an immediate way to alert you and secure your account. Without this contact method, we cannot effectively protect your privacy in this intimate digital space.