The security page for your IT person
Colega books meeting rooms in shared buildings. This page exists so your review can be one read, not one meeting.
The short version
- No calendar integration. No OAuth, no scopes, no access to any company's Microsoft or Google tenant — the product is built so this is impossible, not merely disabled. Calendar events flow one way, outward: an emailed invitation file and a personal read-only feed each member can subscribe to.
- No meeting subjects. A member has nowhere to write what a meeting is about. Every booking is stored and shown as "Name's meeting", so there is no confidential meeting data in the system. The one exception is reception's: a short label on a guest booking or a standing hold ("Guest — tour", "Cleaning").
- No passwords. Sign-in is by single-use email link (15-minute expiry; the link in a first invitation lasts 7 days). There is no password database to breach.
- No tracking cookies. One essential session cookie (HttpOnly, Secure, SameSite=Lax), plus a signed-in hint that holds only a number. No advertising, no fingerprinting, no consent banner needed. Product analytics are named events counted against a random ID — never a name or an email, never page-level tracking.
- No public signup. Members are added by your site's reception. Nobody can join by finding a URL. Visitors can be given a guest pass with an end date — it stops working on that day by itself, their sessions end and their future bookings are released.
- No domain lock, and no domain trust. Any email address can be invited, because access comes from being on your member list — never from what the address ends in. Being on one building's list grants nothing anywhere else.
What we store
| Per member | Name, email address, role (member, reception or admin), and — for a guest pass — the date it ends. Beyond members: the name reception types for a guest booking, the addresses a building chooses to send its usage report to, and reception's own contact email and phone if the building adds them. That is the complete list of personal data. |
| Per room | Name, seat count, and an optional free-text list of what's in it (a TV size, a conference speaker). Set by your admin; no device is ever connected to. |
| Per booking | Room, start, end, who booked it, check-in time, and — if reception cancels a booking — an optional one-line note from reception explaining why. No subject, no attendees, no description. |
| Waiting list | If someone asks to be contacted about Colega, we keep the name, email, building name, room count, location and any note they wrote — until they ask us to delete it. Separate from member data; it grants access to nothing. |
| Admin statistics | Your building's admins can see how often each member books, cancels and fails to check in, by name, for a date range. Names are shortened until an admin presses Reveal, and every reveal is recorded. |
| Never | Meeting subjects or content, calendar contents, passwords, payment card data (billing is invoiced), members' phone numbers, IP-based location profiles. |
Where it runs
- Hosting: Cloudflare Workers and Cloudflare D1. The database is pinned to the EU — created with a jurisdiction constraint on where it may run and store data, which can only be set at creation and so can't be quietly changed later. Read replication is switched off, so there are no copies of it in other regions. Served over TLS, HSTS enforced.
- Sub-processors: Cloudflare (hosting & database), Resend (transactional email), PostHog EU (pseudonymous product analytics, EU region).
- Access: per-site data isolation — every record is scoped to your site; sessions are revoked instantly when reception deactivates a member or a guest pass reaches its end date.
- Sign-in: a single-use link, valid 15 minutes (7 days for the link in a first invitation). If one address belongs to more than one building, the email offers a separate link per building — Colega never guesses which one you meant, and the sign-in form is never told where you're a member.
Leaving, exporting, deleting
Your admin downloads a full export of your site's members, rooms and bookings (CSV) from the admin screen, any time, without asking us. Complete deletion of the site and every record in it: gone from the live service at once, and out of the platform’s 30-day recovery window after that. An admin can also start it themselves, in which case it waits 7 days first so any admin can call it off — normally same-week. No lock-in, no retention games. Email privacy at meetcolega dot com.
Going through a formal approval?
The IT approval pack answers the standard software-assessment questions in the order the forms ask them — cost, authentication, user counts, data types, data location — plus a short section on what we can't claim. Written to be forwarded unedited.
Questions this page didn't answer
Email privacy at meetcolega dot com and you'll get an answer from the person who wrote the code, not a ticket queue.