Privacy Policy
The whole policy fits on one page because the whole dataset fits in one sentence: your name, your email, and the rooms you booked.
Who we are
Colega is a room-booking tool for shared buildings, operated by Andres Urena. For the data your building's members put in, the building is the controller and Colega is the processor — we hold it on the building's instructions, and only for running the service. Contact: privacy at meetcolega dot com.
What we collect
- Members: name, email address, role — and an end date if you're a guest. Added by your building's reception, never by public signup.
- Bookings: which room, when, who booked it and who it's for, whether you checked in.
- Waiting list: if you asked us to get in touch — name, email, building, and whatever note you wrote.
- One cookie: the session that keeps you signed in, plus a signed-in hint carrying nothing but a count. No tracking, advertising or fingerprinting cookies, so no consent banner.
- Product analytics: anonymous named events, counted server-side (a booking happened), never page-level tracking, never sold.
What we never collect
- Meeting subjects or content. There is no field for them. Every booking reads "Name's meeting" — to other members, to your admin, and to us.
- Your calendar. Colega never connects to Microsoft, Google or any calendar; it only sends invitations outward.
- Passwords (sign-in is by emailed link), payment cards (billing is invoiced), phone numbers, location profiles, or any special-category data.
Where it lives, who touches it
- Hosted on Cloudflare; the database is contractually pinned to the EU and read replication is off, so there are no copies elsewhere.
- Sub-processors: Cloudflare (hosting and database), Resend (sending email), PostHog EU (anonymous counts). That's the complete list; it changes only with notice to your building.
- Every record is scoped to your building. Being a member of one grants nothing anywhere else.
How long, and your rights
- Member and booking data is kept while your building uses Colega. Deactivated members stop being visible and their sessions end immediately.
- You can ask your building's admin — or us directly — for a copy of your data or its deletion. Buildings get a full export (CSV) or complete deletion of everything within 30 days of asking, normally the same week.
- If you believe we've mishandled something, write to privacy at meetcolega dot com; you also have the right to complain to your data-protection authority (in the UK, the ICO).
Changes
If this policy changes in a way that matters, your building's admin is told before it takes effect. The current version always lives at this address.