Terms and Conditions

Last updated: 31 July 2026

1. Acceptance of Terms

By accessing or using Scisso (the "Service"), you - the business owner or authorised representative (the "Customer") - agree to be bound by these Terms and Conditions ("Terms"). If you do not agree, do not use the Service.

These Terms form a legally binding agreement between you and KodeKind S.R.L., CIF RO54603957, Reg. Com. J2026028952000, with registered office at Str. Mihail Kogalniceanu, Camera 1, Bl.C8, Et.4, Ap.16, Timisoara, Timis, Romania ("KodeKind", "we", "us", "our"), the developer and operator of Scisso. Use of the Service by your employees is subject to these Terms and you are responsible for ensuring their compliance.

By creating an account, you confirm that you are acting for purposes relating to your trade, business, craft, or profession, and that you have the authority to bind the business entity you represent.

2. Description of Service

Scisso is a business-to-business appointment coordination tool. It provides:

  • Appointment scheduling and management, including single and recurring appointments
  • Google Calendar synchronisation for connected employee accounts, including automatic event matching and two-way sync
  • Automated SMS notifications delivered via third-party SMS gateway providers or, when configured, via an Android relay device on the premises, including: appointment confirmations, 24-hour reminders, rescheduling notices, cancellation notices, post-appointment follow-ups, and birthday greetings
  • Client record management, including duplicate detection, record merging, and data subject request handling
  • The ability to block time on employee calendars for non-appointment activities
  • Client self-registration via time-limited registration links that can be shared with clients
  • Online booking via a public booking page where clients can select a service, choose an employee, pick a date and time, and submit a booking request for the business to confirm or reject
  • Personalised employee booking URLs (e.g., book.example.com/john) that link directly to a specific employee's availability
  • QR code generation for booking pages, client registration links, and client record update links, which can be downloaded and printed for display in the business premises
  • A waitlist for prospective users when the Service is not yet available in their region
  • Basic appointment statistics (anonymised monthly counts)
  • Customer promotions allowing businesses to define time-limited percentage or fixed-amount discounts on services, applied automatically during appointment creation and displayed on the booking page
  • Real-time push notifications for employees about new online booking requests and booking expiry warnings (via Web Push, no third-party push services)
  • Online payment collection during booking (deposits and prepayments) processed via Stripe Connect on the business's own Stripe account, with optional self-service cancellation and refund management for clients
  • Client self-service appointment management via secure one-time links, including appointment status viewing and policy-based cancellation

The Service is provided to businesses only. It is not a consumer product and is not intended for personal, family, or household use. Where these Terms nonetheless reference consumer protection rights (for example, withdrawal rights in Sections 7.5 and 7.10), those provisions apply only to the extent that applicable law treats you as a consumer despite the business nature of this Service.

Scisso facilitates appointment coordination between you and your clients. KodeKind is a technology provider and is not a party to any appointment, service agreement, or service transaction between you and your clients. When online payments are enabled, payments are processed on your own Stripe account via Stripe Connect (Standard). You are the merchant of record for all charges. KodeKind does not charge any platform fee or commission on payment transactions and does not act as a payment intermediary, merchant of record, or party to the payment transaction between you and your client. Any disputes between you and your clients regarding services, pricing, payments, refunds, availability, or appointment fulfilment are solely between you and the client.

3. Eligibility and Authorised Use

You may use the Service only if:

  • You are operating a legitimate appointment-based business
  • You have the legal authority to enter into this agreement on behalf of that business
  • All individuals who will hold employee accounts are at least 18 years of age
  • You will use the Service in compliance with all applicable laws, including GDPR, the ePrivacy Directive, and national electronic communications regulations

4. Account Responsibilities

You are responsible for:

  • Maintaining the confidentiality of your login credentials and those of your employees
  • All activity that occurs under your account, including actions by your employees and receptionists
  • Promptly notifying us of any unauthorised account access at the contact email below
  • Ensuring that employees granted access use the Service only for legitimate business purposes
  • Keeping your contact information accurate and up to date
  • The physical security of the Android relay device used for SMS delivery, and keeping it available: powered on, charged, connected to the internet, running the relay application (including excluding that application from Android battery optimisation), and fitted with an active SIM card on a mobile plan that is suitable for your message volume and that permits automated SMS sending (see Section 8.1)

Users may enable two-factor authentication (TOTP) for additional account security. Changing your password or modifying MFA settings will sign you out of all other devices.

By creating an account and providing your phone number, you acknowledge that KodeKind may send you operational SMS messages (such as a welcome message upon signup) from KodeKind's own phone number. These are transactional platform communications, not marketing, and are limited to essential account lifecycle events.

5. Data Protection Responsibilities

Under GDPR, you (the business owner) are the Data Controller for all client personal data processed through Scisso. This means:

  • You determine why and how client data is collected and used
  • You are responsible for having a valid lawful basis for processing (e.g., legitimate interest for appointment management, or consent where required by national law for electronic communications)
  • You are responsible for informing your clients that their contact details are stored for appointment management, that they may receive SMS notifications, and, when online payments are enabled, that their billing details and payment data are processed for payment purposes (verbally, via a visible notice in your shop, or via the self-registration flow)
  • You are responsible for responding to client data subject rights requests (access, erasure, portability, rectification, restriction, objection) within the timeframes required by GDPR
  • By accepting these Terms, you accept the Data Processing Agreement set out in Section 6 below, which governs how KodeKind processes personal data on your behalf
  • If you enable birthday SMS, you are responsible for ensuring that collecting and using client birthdays for this purpose complies with your local data protection requirements
  • If you upload photos to your booking page gallery, you acknowledge that the Service stores these images and publishes them on your public booking page, served through a content delivery network, where they are accessible to anyone with the page link. You are solely responsible for having a valid lawful basis to publish each photo. Where a photo shows an identifiable person (for example a client's face or a before-and-after result), you must obtain that person's prior, informed, and specific consent to public display before you upload it, and keep evidence of that consent. Where a photo may reveal information about a person's health (including before-and-after treatment results), you must obtain that person's explicit consent for that purpose. You must not upload photos depicting minors without the verifiable consent of a parent or guardian. You confirm you hold the required consent and rights each time you add a photo, you remain the Data Controller for all personal data those images contain (including any special-category data), and you are responsible for promptly removing any photo upon a withdrawal of consent or objection by a depicted person.

KodeKind acts as your Data Processor and will process client data only on your documented instructions and in accordance with the Data Processing Agreement (Section 6). We will not process client data for our own purposes.

Separately, KodeKind acts as an independent Data Controller in two limited cases: (1) KodeKind uses Google Analytics 4 on the application and website to collect anonymised usage statistics for the purpose of improving the service, based on user consent (analytics cookies are only placed after the user clicks "Accept all" in the cookie banner); (2) KodeKind may send operational SMS messages to the account owner's phone number (such as a welcome message upon signup) from KodeKind's own phone number, based on the contractual relationship (Art. 6(1)(b) GDPR). Neither case involves client personal data. See the Privacy Policy for details.

Reporting a photo. Any person who believes a photo published through the Service infringes their rights (including image, privacy, or data-protection rights) may notify us using the contact details in Section 21, or through the reporting option on the booking page, giving the photo's location and the reason. In accordance with Regulation (EU) 2022/2065 (the Digital Services Act), upon receiving a sufficiently substantiated notice we will act without undue delay to disable access to or remove the reported photo and will inform the business, which remains responsible for the lawfulness of the content it uploads.

Important: You are solely responsible for ensuring your use of the Service complies with GDPR and any other applicable data protection or electronic communications laws in your jurisdiction. KodeKind provides technical tools (including encryption, audit logging, erasure workflows, and opt-out management); legal compliance is your responsibility as Data Controller.

6. Data Processing Agreement

This section constitutes the Data Processing Agreement ("DPA") between you, the business owner ("Controller"), and KodeKind ("Processor"), pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR"). By accepting these Terms, you accept this DPA. This DPA applies to all processing of personal data that the Processor carries out on behalf of the Controller through the Service.

6.1 Subject Matter and Duration

The Processor provides Scisso, an appointment coordination and SMS notification platform, to the Controller. The Processor processes personal data on behalf of the Controller for the duration of the Controller's use of the Service. Upon termination, data is handled in accordance with Section 6.10 below.

6.2 Nature and Purpose of Processing

The Processor processes personal data for the following purposes, solely on the Controller's documented instructions:

  • Storing and managing client records (names, contact details, appointment history)
  • Sending SMS notifications (confirmations, reminders, rescheduling notices, cancellation notices) via the Controller's on-premises Android relay device or, when configured by the Controller, via third-party SMS gateway providers
  • Synchronising appointments with Google Calendar when enabled by the Controller
  • Matching Google Calendar events to existing client records using email addresses, calendar colour codes, or event title keywords
  • Sending promotional SMS messages to clients who have provided explicit opt-in consent via the booking form or other mechanisms configured by the Controller
  • Generating anonymised appointment statistics
  • Processing data subject requests (access, erasure, portability) on behalf of the Controller
  • Facilitating online payment collection during booking by creating payment objects (SetupIntents, Invoices) on the Controller's connected Stripe account, storing encrypted client billing details for returning-client pre-fill, and processing refunds and cancellations per the Controller's configured refund policy

6.3 Types of Personal Data

  • Client names (first name, last name)
  • Client phone numbers (encrypted at rest using AES-256-GCM)
  • Client email addresses (encrypted at rest using AES-256-GCM)
  • Client date of birth (encrypted at rest using AES-256-GCM), when collected by the Controller
  • Client language preference
  • Client profile notes entered by staff (free-text service preferences or remarks, stored on the client record)
  • Appointment dates, times, and associated services
  • SMS notification metadata (type, status, timestamp). Message content and recipient phone number are deleted immediately after sending.
  • Staff comments on individual appointments (encrypted at rest using AES-256-GCM). These are internal notes left by staff members on specific appointments. They may contain personal data. They are included in data exports and permanently deleted upon customer erasure.
  • Client billing address (street, city, county/state, postal code, country), encrypted at rest using AES-256-GCM, when collected during online booking with payment
  • Client company details (company name, tax identification number, trade register number), encrypted at rest using AES-256-GCM, when the client identifies as a company during payment booking
  • Phone and email verification timestamps, recording when a client verified ownership via OTP during booking
  • Stripe customer identifier on the Controller's connected Stripe account, linking the client record to Stripe for payment processing
  • Payment metadata on appointments: payment status, payment amount, Stripe reference identifiers (opaque IDs, not card details), manage token for client self-service, and card-on-file consent timestamp

6.4 Categories of Data Subjects

  • Clients of the Controller's business who have appointments or are registered in the system
  • Individuals whose contact details are entered by the Controller's staff for appointment management purposes

6.5 Processor Obligations

In accordance with Article 28(3) GDPR, the Processor shall:

  • (a) Process only on documented instructions. The Processor shall process personal data only on the Controller's documented instructions, including with regard to transfers of personal data to a third country, unless required to do so by EU or Member State law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest. If the Processor considers that an instruction infringes GDPR or other applicable data protection law, the Processor shall promptly inform the Controller and may suspend the relevant processing until the Controller confirms or modifies the instruction.
  • (b) Ensure confidentiality. The Processor shall ensure that all persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • (c) Implement security measures. The Processor shall implement all measures required pursuant to Article 32 GDPR (security of processing), as described in Section 6.7 below.
  • (d) Respect sub-processor conditions. The Processor shall not engage another processor without the Controller's prior general written authorisation. The conditions for engaging sub-processors are set out in Section 6.6 below.
  • (e) Assist with data subject rights. The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights under Chapter III GDPR. The Service provides built-in tools for data access, export (portability), erasure, and rectification.
  • (f) Assist with compliance obligations. The Processor shall assist the Controller in ensuring compliance with Articles 32 to 36 GDPR (security of processing, notification of a personal data breach, communication to data subjects, data protection impact assessment, and prior consultation), taking into account the nature of processing and the information available to the Processor.
  • (g) Delete or return data. At the choice of the Controller, the Processor shall delete or return all personal data after the end of the provision of services, and delete existing copies unless EU or Member State law requires continued storage. See Section 6.10.
  • (h) Demonstrate compliance. The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. See Section 6.9.

6.6 Sub-processors

The Controller grants the Processor general written authorisation to engage sub-processors for the purposes described in this DPA. The Processor currently uses the following sub-processors:

Sub-processorPurposeData location
VPS hosting providerInfrastructure: servers, database, cacheEuropean Union
Google LLCCalendar synchronisation (Google Calendar API)EU/US (Standard Contractual Clauses)
Resend, Inc.Transactional email delivery (staff invitations, password resets, admin notifications)US (DPA with SCCs in place)
Stripe, Inc.Subscription billing for KodeKind; online payment processing on the Controller's connected Stripe account (Stripe Connect Standard) for client deposits, prepayments, and card-on-file charges. Client billing details and card data are collected directly by Stripe.US (DPA with SCCs in place)
Cloudflare, Inc.(1) Bot protection on the online booking form (Cloudflare Turnstile); (2) Object storage (Cloudflare R2) and CDN delivery of images uploaded by the business (logos, staff avatars, and public booking-page gallery photos), which may contain personal data of the business's clients. The R2 storage bucket is located in the European Union.R2 storage: European Union. Turnstile and CDN edge: global network (DPA with SCCs in place).
SMSAdvert (S.C. SMSAdvert S.R.L.)Fallback SMS delivery when the Android relay is unavailable. Processes recipient phone number and message content for transmission only.Romania (European Union)
Google LLC (Google Analytics 4)Anonymised website and application usage analytics. No client personal data is processed. Used by KodeKind as independent controller to improve the service.US (Data Processing Amendment, SCCs, EU-U.S. Data Privacy Framework)
SmartBill (S.C. Intelligent IT S.R.L., Visma group)Invoice generation and PDF delivery for subscription and SMS credit purchases. Processes billing entity name, tax ID, VAT number, billing address, and invoice line items.European Union (AWS Ireland/Germany)
Scaleway SASAI-assisted classification of Google Calendar event titles, to detect likely client appointments among events marked busy (optional feature; disabled via the per-organisation AI setting). Only the event title and the Controller's own service-catalogue labels are sent for inference; a title may contain a client's first name in the employee's shorthand. No client lists, phone numbers, or email addresses are sent. Inputs are processed transiently for inference only and are not used to train models. No prompt or response content is stored by the sub-processor or by KodeKind.France (European Union)
Google LLC (Firebase Cloud Messaging)Push notification delivery to staff mobile devices (iOS and Android apps). Processes a device push token and the notification title and body, which may contain a client's first name and a service name. Notification contents are visible to the sub-processor in transit. On iOS, Firebase relays the notification to Apple's Push Notification service using credentials supplied by KodeKind.US (Firebase Data Processing and Security Terms; EU-U.S. Data Privacy Framework, with Standard Contractual Clauses as fallback)
Apple Distribution International Ltd.Delivery of push notifications to staff iOS devices via the Apple Push Notification service, reached by Firebase on KodeKind's behalf. Processes the device push token and the notification title and body.Ireland (European Union), with delivery infrastructure operated by Apple Inc. in the US under Standard Contractual Clauses
Web push services operated by browser vendors (Mozilla, Google, Microsoft, Apple)Delivery of push notifications to staff web browsers and the installed web app. The receiving service is determined by the browser the staff member chooses, not by KodeKind, and there is no direct contractual relationship with it. Notification contents are encrypted end to end under RFC 8291 and cannot be read by the push service, which receives only an opaque endpoint identifier, ciphertext, and delivery timing.Varies by browser vendor; typically outside the European Union

When the Controller's Android relay device is used, SMS messages are delivered via the device's native SMS system and no third-party gateway processes the recipient's phone number or message content. When a third-party SMS gateway (SMSAdvert) is used as a fallback, the recipient's phone number and message content are transmitted to the gateway for delivery. The gateway deletes the phone number and message content after transmission in accordance with its data processing agreement. The Controller can configure which providers are active and their priority order.

The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors at least 14 days in advance by email, giving the Controller the opportunity to object to such changes. If the Controller objects on reasonable data protection grounds, the parties shall negotiate in good faith to find a resolution. If no resolution is reached within 30 days, either party may terminate the Service.

Where the Processor engages a sub-processor, the same data protection obligations as set out in this DPA shall be imposed on the sub-processor by way of a contract, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. The Processor remains fully liable to the Controller for the performance of the sub-processor's obligations.

6.7 Technical and Organisational Measures

The Processor implements the following measures pursuant to Article 32 GDPR to ensure a level of security appropriate to the risk:

  • Encryption at rest. Client phone numbers, email addresses, dates of birth, and billing details (address, company name, tax ID) are encrypted using AES-256-GCM with unique random initialisation vectors per record. Staff comments on appointments are encrypted using the same method. SMS job phone numbers and message bodies are similarly encrypted. Google OAuth refresh tokens are encrypted at rest. Encryption keys are stored separately from the database.
  • Encryption in transit. All data is transmitted over HTTPS/TLS between browser and server. The connection between server and Android relay device uses an encrypted WebSocket (WSS) connection.
  • Access control. Role-based access control restricts data visibility. Employees can only access client records for which a direct working relationship exists. Administrative functions (employee management, settings, GDPR tools) are restricted to owners and receptionists.
  • Authentication. Passwords are hashed using bcrypt (12 rounds). Sessions use httpOnly, Secure, SameSite JWT cookies with 7-day expiry. Two-factor authentication (TOTP) is available for all users. TOTP secrets and backup codes are encrypted at rest using AES-256-GCM. Changing a password or modifying MFA settings invalidates all existing sessions on other devices. Android relay devices authenticate via API keys stored as bcrypt hashes on the server.
  • Data minimisation. SMS message content and recipient phone numbers are deleted immediately after the message is sent, or after all retry attempts are exhausted, and are never retained while awaiting a delivery report. When a third-party SMS gateway is used, only the recipient phone number and message body are shared with the gateway. No internal identifiers, client profile data, or organisation metadata is transmitted. Personal data is automatically redacted from application logs. Audit logs contain only event types, record identifiers, and timestamps.
  • Infrastructure security. All servers are hosted within the European Union. Database access is restricted to the application server. Rate limiting is applied to all public-facing endpoints to prevent abuse.
  • Resilience and recovery. Database backups are performed regularly. The SMS delivery system includes automatic retry with exponential backoff (up to 10 attempts). A daily cleanup job runs as a safeguard to remove any sensitive data that was not cleared in real time.
  • Audit trail. All personal data access, mutations, erasures, and exports are recorded in an append-only audit log. The audit log itself never contains personal data.

6.8 Data Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's data. "Becoming aware" means the point at which the Processor has a reasonable degree of certainty that a security incident has resulted in personal data being compromised, not mere suspicion. The notification shall include, to the extent available:

  • A description of the nature of the breach, including the categories and approximate number of data subjects and personal data records concerned
  • The name and contact details of the point of contact from whom more information can be obtained
  • A description of the likely consequences of the breach
  • A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects

The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of any data breach. The Processor shall document all personal data breaches, including the facts, effects, and remedial actions taken.

6.9 Audit Rights

The Controller has the right to audit the Processor's compliance with this DPA. Audits may be conducted by the Controller or a qualified third-party auditor bound by confidentiality obligations, subject to the following conditions:

  • Audit requests must be made in writing with at least 30 days' notice
  • Audits shall be conducted during normal business hours and shall not unreasonably disrupt the Processor's operations
  • The Controller shall bear the costs of any audit it initiates, unless the audit reveals a material breach of this DPA by the Processor
  • No more than one audit may be conducted per 12-month period, unless a supervisory authority requires additional audits or a personal data breach has occurred
  • All information obtained during an audit shall be treated as confidential

The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and shall cooperate fully with audit activities.

6.10 Data Return and Deletion

Upon termination of the Service, the Processor shall:

  • Make the Controller's data available for export in a structured, commonly used, machine-readable format (JSON) for a period of 30 days following termination
  • After the 30-day export window, permanently delete all personal data from active systems. Personal data in encrypted backups will be deleted in accordance with the standard backup rotation schedule, not to exceed 90 days. During this period, backup data remains encrypted and access-restricted, and will not be restored to active systems.
  • Provide written confirmation of deletion upon the Controller's request

Anonymised, aggregate statistical data (total appointment counts per service category at the organisation level, not attributable to any individual employee or client) may be retained indefinitely as it does not constitute personal data under GDPR Recital 26. Per-employee statistics are aggregated to organisation-level totals upon termination.

6.11 Controller Obligations

The Controller warrants and undertakes that:

  • It has a valid lawful basis under GDPR Article 6 for all personal data provided to the Processor for processing
  • It has informed its clients, by appropriate means, that their data will be processed through the Service for appointment management and SMS notification purposes
  • It will comply with all applicable data protection laws in its capacity as Data Controller, including responding to data subject rights requests within the timeframes required by GDPR
  • It will not instruct the Processor to process personal data in a manner that would violate GDPR or any other applicable law
  • It will promptly notify the Processor if it becomes aware of any circumstance that may affect the Processor's ability to comply with its obligations under this DPA

6.12 International Data Transfers

The Processor stores and processes all personal data within the European Union. Where sub-processors located outside the EU are engaged (see Section 6.6), the Processor ensures that appropriate safeguards are in place in accordance with GDPR Chapter V, such as Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Article 46(2)(c) GDPR, or an adequacy decision by the European Commission pursuant to Article 45 GDPR.

6.13 Liability

Each party shall be liable for damages caused by processing that infringes GDPR in accordance with Article 82 GDPR. The Processor shall be liable for damage caused by processing only where it has not complied with obligations of GDPR specifically directed to processors, or where it has acted outside of or contrary to the Controller's lawful instructions.

Where either party has paid full compensation to a data subject under Article 82(4) GDPR, it is entitled to claim back from the other party that portion of the compensation corresponding to the other party's share of responsibility, in accordance with Article 82(5) GDPR. The general limitation of liability in these Terms (Section 15) does not limit either party's obligations under this Section 6.13 or under GDPR Article 82.

6.14 AI-Assisted Calendar Classification (Optional Feature)

Scisso offers an optional feature that helps the Controller identify Google Calendar events that are likely client appointments but were left unclassified (for example, where an employee's freeform event title did not match a configured rule). To do this, the event title and the Controller's own service-catalogue labels are sent for analysis to an AI sub-processor. The following terms apply to this processing:

  • (a) Data sent. Only the event title and the Controller's service-catalogue labels are transmitted. An event title may contain a client's first name written in the employee's shorthand. Client contact lists, phone numbers, email addresses, and Scisso record identifiers are never sent. The feature extracts a candidate name from the title; matching that name to a client is performed locally by Scisso, not by the sub-processor.
  • (b) Purpose and lawful basis. The purpose is limited to classifying the Controller's own calendar events so that genuine appointments are not silently lost. The Controller determines the lawful basis for this processing; KodeKind considers the Controller's legitimate interest under Article 6(1)(f) GDPR (accurate operation of the Controller's own booking records) to be the applicable basis. The Processor performs this processing solely on the Controller's documented instructions and for no other purpose.
  • (c) Sub-processor and location. Inference is performed by Scaleway SAS on infrastructure located in France (European Union), using the Mistral Small 3.2 model authored by Mistral AI (a French company). The model author does not receive the data: only Scaleway's European inference infrastructure processes it. No data is transferred outside the European Union for this feature.
  • (d) Retention. Titles are processed transiently for inference only. Neither Scisso nor the sub-processor stores the prompt or the response content. Scisso retains only non-personal telemetry about each call (token counts, cost, status, timestamps) for cost control and reliability; this telemetry contains no titles, names, or other personal data.
  • (e) No model training. Per the sub-processor's data-processing terms, the data sent is not used to train, retrain, or improve any model, and the content of inputs and outputs is not read, reused, or analysed by the sub-processor.
  • (f) Controller control and opt-out. The feature is governed by a per-organisation AI setting that an owner can switch off at any time in Settings. While the feature is enabled, the Controller authorises the sub-processing described above on the basis of this disclosure; switching it off stops all such processing.
  • (g) Flow-down and liability. The data protection obligations in this DPA are imposed on the sub-processor by way of its data processing agreement, including the security and confidentiality obligations in Section 6.7. The Processor remains fully liable to the Controller for the sub-processor's performance, as set out in Section 6.6.

This feature is advisory only. It surfaces suggestions for the Controller's staff to review; it never automatically modifies, reclassifies, or sends messages for an appointment. The Controller may disable it at any time without affecting any other part of the Service.

6.15 AI-Assisted Service Catalogue Import (Optional Feature)

Scisso offers an optional feature that lets the Controller build its service catalogue from photographs or screenshots of an existing price list, instead of typing every entry by hand. Images uploaded by the Controller are sent for analysis to an AI sub-processor, which returns a draft catalogue for the Controller to review. The following terms apply to this processing:

  • (a) Data sent. Only the images the Controller chooses to upload. These are expected to contain the Controller's own commercial information: service names, durations and prices. The Controller must not upload images containing client personal data; the feature does not need it and does not extract it. Image metadata, including any location recorded by the camera, is removed before transmission.
  • (b) Purpose and lawful basis. The purpose is limited to converting the Controller's own price list into catalogue entries in the Service. The Controller determines the lawful basis for this processing; KodeKind considers the Controller's legitimate interest under Article 6(1)(f) GDPR (setting up and maintaining its own service catalogue) to be the applicable basis. The Processor performs this processing solely on the Controller's documented instructions and for no other purpose.
  • (c) Sub-processor and location. Inference is performed by Scaleway SAS on infrastructure located in France (European Union), using the Mistral Small 3.2 model authored by Mistral AI (a French company). The model author does not receive the data. No data is transferred outside the European Union for this feature.
  • (d) Retention. Images are processed transiently for inference only. No image is stored by Scisso or by the sub-processor, and no model response is retained beyond the draft catalogue the Controller is actively editing, which exists only until the Controller confirms or discards it. Scisso retains only non-personal telemetry about each call (token counts, cost, status, timestamps) for cost control and reliability.
  • (e) No model training. Per the sub-processor's data-processing terms, the data sent is not used to train, retrain, or improve any model, and the content of inputs and outputs is not read, reused, or analysed by the sub-processor.
  • (f) Controller control and opt-out. The feature is governed by the same per-organisation AI setting as Section 6.14, which an owner can switch off at any time in Settings. While the feature is enabled, the Controller authorises the sub-processing described above on the basis of this disclosure; switching it off stops all such processing.
  • (g) Flow-down and liability. The data protection obligations in this DPA are imposed on the sub-processor by way of its data processing agreement, including the security and confidentiality obligations in Section 6.7. The Processor remains fully liable to the Controller for the sub-processor's performance, as set out in Section 6.6.

This feature is advisory only. It produces a draft that the Controller reviews and edits; nothing is added to the catalogue until the Controller confirms it. Existing services, categories and prices are never modified or deleted by an import. The Controller may disable the feature at any time without affecting any other part of the Service.

7. Subscription and Billing

Scisso is a subscription service. By subscribing, you agree to pay the recurring fees associated with your chosen plan. All fees are in euros (EUR). The applicable VAT treatment is described in Section 7.9.

7.1 Plans and Pricing

Scisso offers multiple subscription plans that differ in the number of included employees and SMS volume. All plans include access to every feature. Current plan details and pricing are displayed during sign-up and on the billing page within the application.

7.2 Free Trial

  • New accounts receive a 30-day free trial with full access to all features.
  • A valid payment method is required to start the trial. You will not be charged during the trial period.
  • Before the trial ends, we will notify you by email that the trial is expiring. If you do not cancel before the trial ends, your subscription will automatically convert to a paid plan and your payment method will be charged at the rate displayed during sign-up.
  • You may cancel at any time during the trial without being charged.
  • By providing a payment method and starting the trial, you expressly consent to the automatic conversion to a paid subscription at the end of the trial period, and you acknowledge that you will be charged unless you cancel before the trial ends.

7.3 Billing and Renewal

  • Subscriptions are billed monthly on the same day each month (your billing anchor date, set at account creation).
  • Charges are processed automatically via Stripe. Scisso does not store your card details. All payment data is handled directly by Stripe in accordance with PCI DSS standards.
  • Adding employees beyond your plan's included amount will result in additional per-employee charges, prorated for the remaining billing period.

7.4 Payment Failure

  • If a payment fails, your subscription enters a 7-day grace period during which the service remains fully functional.
  • Stripe will retry the payment automatically during this period.
  • If payment is not resolved within 7 days, your subscription will be cancelled. SMS dispatch will be paused and the application will become read-only.
  • Your data will not be deleted. You may resubscribe at any time to restore full access.

7.5 Cancellation

  • You may cancel your subscription at any time from the billing page.
  • Cancellation takes effect at the end of the current billing period. You will retain full access until then.
  • No partial refunds are issued for unused time within a billing period, except as required by applicable law.
  • After the billing period ends, SMS dispatch will be paused and the application will become read-only until you resubscribe.
  • If you are entitled to a statutory right of withdrawal under applicable consumer protection law, you may exercise it within 14 days of your initial subscription by contacting us at the email address below. If you have used the Service during this period, you will be charged proportionally for the time used.

7.6 Refunds

Subscription fees are non-refundable except where required by applicable law. If you believe you have been charged in error, contact us at [email protected] within 14 days of the charge.

7.7 Price Changes

We may adjust subscription pricing to reflect changes in our operating costs, infrastructure costs, regulatory requirements, or general market conditions. Prices will not increase more than once per 12-month period.

We will notify you by email at least 30 days before any price increase takes effect. The notification will state the new price and the date it takes effect. If you do not agree to the new pricing, you may cancel your subscription before the new price takes effect and will not be charged the increased amount. New pricing applies only from the next billing cycle after the notice period ends.

7.8 Promotional Codes

  • Scisso may offer promotional codes that provide a percentage discount on subscription fees. Promotional codes are issued at our sole discretion and may be subject to conditions such as plan restrictions, single-use limits, expiration dates, or maximum redemption caps.
  • Promotional discounts apply exclusively to recurring subscription charges: the base plan fee and additional per-employee fees. They do not apply to any pay-per-use fees, usage-based charges, or third-party service costs such as SMS delivery fees.
  • Time-limited promotional discounts apply for the stated number of billing periods. Once the promotional period ends, your subscription will automatically renew at the standard rate for your plan. The applicable post-discount price is displayed during sign-up.
  • Promotional codes have no cash value, are non-transferable, and cannot be combined with other offers or codes unless explicitly stated.
  • We reserve the right to deactivate or revoke any promotional code at any time for any reason, including suspected abuse or fraud. If a code is revoked before its stated promotional period ends, the discount will continue to apply for the remainder of the originally stated duration.
  • Promotional discounts do not survive cancellation. If you cancel your subscription and later resubscribe, the standard pricing for your chosen plan will apply unless a new promotional code is used.

7.9 Billing Data and VAT

To generate invoices, we collect billing details during sign-up: billing type (company or individual), company name, tax identification number, VAT number (if applicable), and billing address. This information is stored on your account and shared with Stripe for payment processing and invoice generation. You may update your billing details at any time from the billing page.

The operator is registered for VAT in Romania. All prices displayed during sign-up and within the application are exclusive of VAT. The applicable VAT is calculated automatically at checkout based on your billing country, business status, and VAT number (if provided), and is shown before you confirm any purchase. If you provide a valid EU VAT identification number, it will be verified and recorded on your account. Intra-EU B2B transactions where the customer provides a valid VAT number are subject to the reverse charge mechanism. You are responsible for any local taxes, duties, or levies applicable in your jurisdiction beyond what is collected by us.

7.10 SMS Credits

Third-party SMS providers (such as SMSAdvert) require prepaid SMS credits. Credits are abstract service units, not stored monetary value or electronic money. They are redeemable only for SMS delivery through Scisso and cannot be transferred, cashed out, or used for any other purpose.

  • Credits are purchased in fixed packs via a one-time Stripe payment. Available pack sizes and prices are displayed on the SMS settings page within the application.
  • Credits are non-expiring. Purchased credits remain on your account indefinitely.
  • Credits are non-transferable between organisations.
  • Each SMS consumes credits based on the destination country and the number of message segments. The applicable credit cost per segment for each country is published within the application and may be updated from time to time (see Section 7.11).
  • Credits are deducted at the time a message is routed to a paid provider. If a message permanently fails after all retry attempts, the credits consumed for that message are automatically refunded to your balance.
  • If your credit balance is insufficient to cover a message, the paid provider is skipped. If no other provider is available (e.g., the Android relay is offline), the message will fail.

Withdrawal right and waiver. When you purchase SMS credits, you have the right to withdraw from the purchase within 14 days without giving any reason, in accordance with Directive 2011/83/EU (transposed in Romania by OUG 34/2014). However, because credits are digital content delivered immediately to your account, you will be asked to provide express consent to immediate performance and to acknowledge that you lose your right of withdrawal. This consent is collected via a separate, unticked checkbox before each purchase. A confirmation of your purchase, including your consent and acknowledgment, is provided via invoice.

Refund policy. Subject to the withdrawal waiver above, SMS credit purchases are non-refundable. This does not affect your rights under Directive 2019/770 (transposed in Romania by OUG 141/2021): if the SMS delivery service is materially impaired or discontinued and you are unable to use your credits, you are entitled to a proportionate price reduction or, where the lack of conformity is not minor, termination and a refund for unused credits. If you believe you have been charged in error, contact us at [email protected].

VAT treatment. SMS credits are treated as a prepayment for a known service. VAT (where applicable) is charged at the time of purchase and reflected on the invoice.

7.11 SMS Credit Rate Changes

The number of credits consumed per SMS segment varies by destination country. We may adjust these rates to reflect changes in our upstream provider costs. Rate adjustments are not retroactive and do not affect credits already consumed.

We will notify you by email at least 30 days before any rate increase takes effect. The notification will state the affected countries, the new rates, and the effective date. If you do not agree to the new rates, you may request a refund of your remaining unused credits at the per-credit price you originally paid, provided the request is made before the new rates take effect. After the new rates take effect, remaining credits are consumed at the new rates.

7.12 SMS Credit Auto-Reload

You may optionally enable auto-reload, which automatically purchases a credit pack when your balance drops below a threshold. Auto-reload is disabled by default and requires explicit activation from the SMS settings page.

  • The reload threshold is calculated dynamically based on your organisation's country (approximately 10 messages worth of credits).
  • When auto-reload is triggered, your stored payment method is charged for the selected credit pack. A Stripe invoice is generated for each auto-reload charge.
  • By enabling auto-reload, you provide express consent to immediate performance for each auto-reloaded credit pack and acknowledge that you lose your right of withdrawal for those purchases, on the same terms as Section 7.10.
  • You may disable auto-reload at any time from the SMS settings page. Disabling auto-reload does not affect credits already purchased.

7.13 Online Payments

When you enable online payments via Stripe Connect, payments are processed directly on your connected Stripe account. Scisso does not charge any platform fee or commission on payment transactions. The only fees that apply are Stripe's own processing fees, which are charged by Stripe directly to your connected account according to Stripe's published pricing.

  • Online payments support deposits and prepayments processed through the booking widget.
  • On refunds, the full payment amount is returned to the client. Stripe's processing fee is not refunded (this is Stripe's standard policy and is not within our control).
  • You may disconnect your Stripe account at any time from the payments settings page. All outstanding payments on upcoming appointments will be automatically refunded before the disconnect is finalised. Disconnecting disables all payment modes on your services.
  • Online payments are available on all subscription plans. No additional monthly fee is charged for the payment feature.
  • KodeKind reserves the right to introduce a platform fee on payment transactions in the future. Any such change will be communicated at least 30 days in advance via email and will require your continued use of the payment feature to constitute acceptance.

8. SMS Delivery and Costs

Scisso supports multiple SMS delivery methods, configured by you in order of priority:

8.1 Android Relay (Free)

The Android relay uses a device physically located on your premises (the "Relay") to send SMS via your mobile carrier's SIM card. Messages are sent from your own business phone number. This method is free within Scisso, but you are solely responsible for all carrier costs (per-message charges, bundle usage, and any carrier fees). You should ensure your mobile plan is suitable for your message volume.

Relay delivery depends on factors outside our control, including: the device being powered on and connected to the internet, mobile network availability, recipient phone number being active and reachable, SMS not being filtered by the recipient's carrier, and the Android operating system not terminating the relay application due to battery optimisation or system updates.

The Relay is your equipment, on your premises, under your control. Keeping it available is your responsibility, as set out in Section 4. We do not operate the Relay and we do not guarantee any level of Relay availability or uptime. Scisso displays the Relay's connection status in your settings and sends best-effort notifications when the device has appeared offline for an extended period or reports a low battery. Those notifications depend on the device reporting its status and on push delivery reaching you, are provided as a convenience only, are not guaranteed, and do not transfer responsibility for Relay availability to us.

The Relay will be unavailable at times, for reasons including power cuts, loss of internet or mobile coverage, the device being switched off, moved, or taken off the premises, the operating system terminating or updating the relay application, device failure, and carrier issues. A paid provider can be configured as a backup in your chain (Sections 8.2 and 8.3) precisely so that messages continue to be sent while the Relay is offline, subject to your SMS credit balance. Whether to keep a funded backup provider active is your decision. If you operate the Relay as your only provider, or your credit balance is insufficient while the Relay is offline, messages will not be sent. We are not liable for any consequence of the Relay being unavailable, for any reason and however caused, including messages never sent, sent late, or sent after the appointment they refer to, missed appointments, lost revenue, client dissatisfaction, and client replies (such as STOP or HELP keywords) that the Relay does not receive while it is offline.

Your mobile plan must permit automated sending. Mobile operators across the EEA commonly limit ordinary mobile subscriptions, consumer and business alike, to personal or manual use. These limits frequently name automated or bulk SMS sending, telemarketing and customer-service messaging as prohibited, and some define improper use to include any message that is not written and sent by hand. The Relay sends messages automatically and may fall within such limits.

The contract with your mobile operator is yours, not ours. Before enabling the Relay, it is your responsibility to check your operator's terms and, where they require it, to move to a plan or product that permits automated messaging. Operators commonly sell a dedicated bulk-SMS or business-messaging product for exactly this purpose.

If your operator restricts, suspends or terminates your subscription, or charges you differently, because messages were sent automatically, that is a matter between you and your operator. We are not liable for it, nor for any message that is not sent as a result. A paid SMS provider can be configured instead of or alongside the Relay (Sections 8.2 and 8.3); those routes do not use your own SIM and are not subject to your mobile plan's terms.

8.2 Third-Party SMS Gateway (Paid)

When configured, Scisso can route SMS through a third-party SMS gateway (currently SMSAdvert) as a fallback or primary provider. Messages sent via the gateway are delivered from a generic short code (not your business phone number), but the message content identifies your business by name.

Gateway delivery requires prepaid SMS credits (see Section 7.10). Credits are deducted when a message is routed to the gateway. The cost per message depends on the destination country and message length (number of segments). If your credit balance is insufficient, the gateway is skipped and the next available provider in your chain is tried.

Gateway delivery depends on the third-party provider's infrastructure and the downstream carrier networks they use. We do not operate or control the gateway infrastructure.

8.3 Provider Chain and Fallback

You configure which providers are active and their priority order. When an SMS is dispatched, Scisso selects the first available provider in your chain. Once a provider is selected for a message, all retry attempts for that message use the same provider. This prevents duplicate deliveries that could occur if a message were re-routed mid-lifecycle.

If no provider in your chain is available (e.g., the relay is offline and your credit balance is insufficient for the gateway), the message will fail after all retry attempts are exhausted. We are not liable for any loss, including missed appointments, lost revenue, or client dissatisfaction, resulting from undelivered SMS messages regardless of the delivery method used.

8.4 Delivery Disclaimer

We do not guarantee SMS delivery via any method. Undelivered messages are retried automatically (up to 10 attempts with increasing delays). Factors affecting delivery include mobile network conditions, carrier filtering, recipient phone status, and third-party provider availability. Scisso is an appointment coordination platform, not a telecommunications provider. SMS delivery is a feature of the platform, not a standalone communications service.

8.5 Opt-Out and Automated Replies

Clients can opt out of SMS at any time using the methods described below. Once a client opts out, Scisso will not send them further SMS from your business, even if their phone number is re-entered into the system.

8.5.1 Opt-Out Link

Scisso appends an opt-out link to the body of SMS messages sent to your clients. The link directs the client to a confirmation page before their preference is saved. This link is required by EU electronic communications regulations (ePrivacy Directive, Article 13) and cannot be disabled.

The opt-out link behaviour differs by message type:

  • Transactional SMS (confirmations, reminders, rescheduling notices, cancellation notices, booking received, booking rejected): the opt-out link is appended to the first message sent to a client from each sender number. Because different providers send from different numbers (your relay SIM vs. a gateway short code), the link may appear once per provider.
  • Follow-up, promotional, and birthday SMS: the opt-out link is appended to every message, as these messages may contain marketing content subject to the ePrivacy Directive.

The appended link increases the length of the message body. If the additional characters cause the message to exceed a single SMS segment, the message will be sent as multiple segments. You are responsible for and accept all costs resulting from the increased message length, whether incurred as carrier charges on your relay SIM or as additional SMS credit consumption on a paid provider. This is a regulatory requirement and is not configurable.

8.5.2 STOP and START Keywords (Android Relay Only)

When messages are sent via the Android relay (from your business phone number), clients can reply STOP to that number. The relay app detects the keyword and processes the opt-out automatically. Replying START re-enables transactional SMS only. Promotional SMS consent must be re-granted separately through the appropriate consent mechanism. The STOP keyword mechanism is not available for messages sent via a third-party gateway short code; for those messages, the opt-out link in the message body is the primary opt-out method.

8.5.3 HELP Keyword Auto-Reply (Android Relay Only)

When a client replies HELP (or equivalent keywords in supported languages) to your business phone number, the relay automatically sends a single informational SMS reply identifying the business and explaining how to opt out. This auto-reply is required to comply with electronic communications regulatory expectations and cannot be disabled.

To prevent abuse, HELP replies are rate-limited to one reply per phone number per hour. Each HELP reply is a standard outbound SMS sent from your relay SIM. You are responsible for and accept all carrier costs incurred by these automated replies. This is a regulatory obligation and is not configurable.

9. Google Calendar Integration

Scisso integrates with Google Calendar via the Google Calendar API. When an employee connects their Google account, Scisso obtains read and write access to the selected calendar. This is a two-way sync: Scisso both reads from and writes to the connected Google Calendar.

9.1 What Scisso Does in Your Google Calendar

By connecting a Google Calendar, you authorise Scisso to perform the following actions on the connected calendar:

  • Create events when an appointment is created in Scisso (including from online booking requests), with appointment details such as client name, service, and time
  • Update events when an appointment is rescheduled, confirmed, or modified in Scisso (including updating titles, times, descriptions, and status indicators)
  • Delete events when an appointment is cancelled or a pending booking is rejected in Scisso
  • Set extended properties (private metadata) on events created by Scisso, used to link events back to Scisso records (e.g., customer ID, service ID). These properties are not visible in the Google Calendar UI but are stored on the event.
  • Read events from the connected calendar via webhook notifications, to detect appointments created or modified directly in Google Calendar and sync them into Scisso
  • Match events to clients using attendee email addresses, calendar colour codes, or event title keywords. This matching is best-effort and may require manual review.

In short: creating, rescheduling, confirming, or cancelling appointments in Scisso will create, modify, or delete corresponding events in the connected Google Calendar. Changes made directly in Google Calendar will also be synced back into Scisso.

9.2 Dedicated Calendar Recommendation

Important recommendation

You should connect only a dedicated work calendar to Scisso, not a personal calendar that contains private events, medical appointments, or other sensitive information. Scisso reads all events from the connected calendar (within the sync window) to detect scheduling conflicts and match appointments. Connecting a personal calendar may expose private event data to Scisso and to other staff members who share the calendar view within the application.

KodeKind is not responsible for any privacy implications, data exposure, or unintended consequences resulting from connecting a personal or shared calendar. You are solely responsible for choosing which calendar to connect.

9.3 Third-Party Dependency and Disclaimers

The Google Calendar API is a third-party service operated by Google LLC and subject to Google's own terms and availability. We make no representations or warranties regarding:

  • The continued availability of the Google Calendar API
  • The accuracy or timeliness of calendar data synchronisation
  • Webhook delivery delays or failures caused by Google's infrastructure
  • Changes Google makes to its API that may affect Scisso functionality

Loss of Google Calendar integration due to causes attributable to Google is not a breach of these Terms by KodeKind.

9.4 Limitation of Liability for Calendar Data

While Scisso is designed to sync calendar data accurately, software bugs, network failures, API changes, or race conditions may occasionally cause unintended outcomes, including but not limited to:

  • Events being created, modified, or deleted in your Google Calendar in error
  • Duplicate events, missing events, or events with incorrect details
  • Extended properties being set, modified, or lost on events
  • Sync delays causing stale data to be displayed or acted upon
  • Recurring event series being partially or incorrectly updated

To the maximum extent permitted by applicable law, KodeKind shall not be liable for any loss or damage arising from unintended modifications to your Google Calendar data, including lost events, corrupted event data, scheduling conflicts, or any downstream consequences thereof. This limitation applies regardless of whether the issue was caused by a bug in Scisso, a change in the Google Calendar API, a network failure, or any other cause.

You are responsible for maintaining your own backups or records of critical scheduling information and for verifying that calendar data is accurate. You may disconnect your Google Calendar at any time from your profile settings.

10. Client Self-Registration and Online Booking

Scisso allows you to generate time-limited registration links that can be shared with clients. When a client uses such a link:

  • The link expires after 15 minutes for security purposes
  • The client must explicitly accept the Privacy Policy and Terms of Service before submitting their data
  • SMS notifications are opt-in during self-registration (not enabled by default)
  • You remain the Data Controller for the data collected through these links
  • You are responsible for sharing registration links only with individuals who have a legitimate reason to receive them (e.g., clients with upcoming appointments)

10.1 Online Booking

Scisso provides a public booking page where prospective and existing clients can browse your services, select an employee, choose a date and time slot, and submit a booking request. Online booking is subject to the following:

  • Booking requests are submitted as pending and require explicit confirmation or rejection by the business within the configured expiry period (default: 8 business hours). Scisso does not automatically confirm bookings on your behalf.
  • Pending bookings that are neither confirmed nor rejected within the expiry period are automatically cancelled. Scisso is not liable for bookings that expire due to inaction.
  • A booking request does not create a binding appointment or any contractual obligation between Scisso and the client. The booking is a request only. The business decides whether to accept or reject it. When a payment-enabled service requires a deposit or prepayment at booking, the payment is a transaction between the client and the business (see Section 2). The business's configured refund policy applies if the booking is rejected or cancelled.
  • When a booking is submitted, a corresponding event is created in the assigned employee's Google Calendar (if connected) with a visual pending indicator. The indicator is removed upon confirmation and the event is deleted upon rejection.
  • The online booking form is protected by Cloudflare Turnstile (an invisible bot verification service) to prevent automated abuse. No personal data is shared with Cloudflare beyond the verification token.
  • The booking page displays your business name, logo, address, phone number, employee names, employee titles and biographies, service names with descriptions and pricing, and available time slots. You are responsible for ensuring this information is accurate and up to date. Scisso is not liable for any inaccuracies in the information you provide.
  • Available time slots are calculated based on your configured shop hours, existing appointments, and blocked time. Slot resolution (15, 30, or 60 minutes) is configurable. For services with online payment enabled, a temporary slot reservation is created when the client reaches the payment step, preventing double-booking during the payment window. For services without payment, Scisso does not guarantee that displayed time slots are still available at the time of submission, and simultaneous bookings for the same slot may result in double bookings that you must resolve manually.
  • The booking form collects optional consent for SMS appointment notifications and promotional messages. You are responsible for honouring these consent choices and for ensuring that any promotional messages comply with applicable electronic communications regulations (including the ePrivacy Directive).
  • Clients may include a free-text note with their booking request. This note is visible to your staff. You are responsible for ensuring that notes are handled appropriately and not used to collect sensitive personal data beyond what is necessary.
  • You may enable or disable online booking at any time from the settings page. When disabled, the booking page displays a message directing visitors to contact the business directly.
  • When a service has a payment mode configured (deposit, prepayment, or card-on-file) and your Stripe account is connected, the booking form includes additional steps: billing details (address, optional company information), a Stripe payment form, and your cancellation/refund policy. Email becomes required for payment-enabled services. Billing details are encrypted and stored on the client record for future bookings (pre-filled only after phone OTP verification). Card details are collected directly by Stripe and never pass through Scisso servers.
  • After a successful online booking, the client receives a secure manage link (via SMS and/or email) that allows them to view appointment details and, after phone verification, cancel the appointment subject to your configured refund policy. Cancellations via the manage link follow the same refund rules as cancellations initiated by the business. You are notified of every client-initiated cancellation via push notification and email.

10.2 Employee Booking URLs

Each employee may have a personalised booking URL (a "booking slug") that links directly to their availability on the booking page. Booking slugs are auto-generated from the employee's name and can be customised. These URLs are publicly accessible when online booking is enabled.

10.3 Booking SMS Notifications

When a client submits a booking, Scisso may send the following SMS notifications on behalf of the business:

  • Booking received - sent to the client confirming that their booking request has been received and is pending review by the business
  • Booking rejected - sent to the client if the business rejects their booking request

If the booking is confirmed, the standard appointment confirmation SMS is sent (see Section 8). Each SMS type can be individually enabled or disabled by the business.

10.4 QR Codes and vCards

Scisso generates QR codes that encode URLs for the booking page, client registration forms, and client record update forms. QR codes are generated entirely within the browser and are not transmitted to or stored on Scisso servers. You may download and print QR codes for display in your business premises. The business is solely responsible for the placement, display, and removal of printed QR codes.

When the business is outside of its configured shop hours, the booking page may offer visitors the option to save the business contact details as a vCard file (.vcf). The vCard contains only the business name and phone number. vCard files are generated in the browser and are not stored on Scisso servers.

11. Acceptable Use

You agree not to use the Service to:

  • Send unsolicited commercial messages (spam) to individuals who have not booked appointments at your business or who have opted out of SMS
  • Process personal data of individuals without a valid lawful basis under GDPR
  • Circumvent or disable SMS opt-out mechanisms
  • Attempt to reverse-engineer, decompile, or extract source code from the Service
  • Interfere with or disrupt the Service's infrastructure or security
  • Use the Service for any purpose that is unlawful or harmful to others
  • Transfer your account credentials or access rights to any third party
  • Represent that the Service is your own product or misrepresent its origin
  • Use registration links for purposes other than legitimate client self-registration
  • Operate the Service under a name that misrepresents your business as a public authority, a bank, a healthcare provider, or any organisation you are not, or that is likely to mislead a message recipient about who is contacting them

We reserve the right to suspend or terminate accounts that violate these restrictions without notice.

Where we suspend or terminate an account under this Section, we may refuse further registrations using the same email address or the same connection, for the periods set out in our Privacy Policy. We will not do so where the account was suspended for non-payment alone.

12. Intellectual Property

The Service, including its software, design, trademarks, and documentation, is owned by KodeKind and protected by applicable intellectual property laws. These Terms do not transfer any ownership rights to you.

You retain full ownership of your business data (client records, appointment data, SMS templates, organisation settings) stored in the Service. We claim no intellectual property rights over your data.

13. Service Availability and Force Majeure

We will make reasonable efforts to keep the Service available. However, we do not guarantee any specific uptime, availability level, or response time. The Service may be temporarily unavailable due to:

  • Scheduled maintenance (we will endeavour to provide advance notice where possible)
  • Unplanned outages caused by infrastructure failures
  • Third-party service dependencies (hosting provider, Google Calendar API, DNS providers) that are beyond our direct control. We will use commercially reasonable efforts to select reliable providers and minimise downtime.
  • Force majeure events (see below)

Temporary unavailability does not constitute a breach of these Terms. Messages awaiting delivery are queued on our servers, not on the Relay device, and are retried automatically once the Service is restored, subject to the retry limits described in Section 8.4. If the Relay is offline when a message is due, the message is retried from our servers and is sent only if the Relay reconnects, or another provider in your chain takes over, before the retry attempts are exhausted. Retry attempts are finite, so a message may be abandoned undelivered.

Force majeure. Neither party shall be liable for failure or delay in performing its obligations where such failure or delay results from a force majeure event: an external event that was unpredictable at the time these Terms were accepted, and that is absolutely irresistible and unavoidable (as defined by Article 1351 of the Romanian Civil Code). Examples include natural disasters, war or armed conflict, government-imposed sanctions or embargoes, pandemic-related government orders, and widespread internet backbone outages beyond either party's control. The affected party must notify the other party within 72 hours of the event, providing details and expected duration. If a force majeure event persists for more than 90 days, either party may terminate these Terms without liability.

14. Service Warranty and Limitations

We warrant that the Service will perform substantially in accordance with its documentation and the description in Section 2. We will use commercially reasonable efforts to maintain the Service's availability, security, and accuracy.

Important - please read carefully

Beyond the warranty above, and to the maximum extent permitted by applicable law, we do not make additional representations or guarantees regarding:

  • Uninterrupted or error-free operation of the Service
  • That defects will be corrected within any specific timeframe, or that the Service will meet your specific business requirements beyond the features described in Section 2
  • SMS delivery, delivery timing, or delivery success rates via any provider (Android relay or third-party gateway), which depend on factors outside our control as described in Section 8
  • Third-party SMS gateway availability, performance, or delivery quality, which depend on the gateway operator and downstream carrier networks
  • Google Calendar synchronisation accuracy, timeliness, or the correctness of calendar write operations (event creation, modification, deletion, or extended property updates)
  • The accuracy of calendar event matching, duplicate client detection, or inferred client names (which are best-effort features that may require manual review)
  • Online booking time slot availability, which may change between display and submission
  • Payment processing availability, timing, or success rates via Stripe, which depend on Stripe's infrastructure, the client's payment method, and the client's bank. This includes deposit captures, refund timing, chargeback outcomes, and card-on-file charge success

These limitations describe the inherent characteristics of the Service. Your statutory rights under applicable law are not affected.

15. Limitation of Liability

Important - please read carefully

To the maximum extent permitted by applicable law, KodeKind, its directors, employees, agents, and contractors shall not be liable to you for any:

  • Indirect, incidental, special, consequential, or punitive damages of any kind, however caused and regardless of the theory of liability (contract, tort, negligence, or otherwise), including lost revenue, lost profits, loss of data, loss of goodwill, business interruption, or cost of substitute services;
  • Damages arising from undelivered or delayed SMS messages, regardless of the reason for non-delivery, including missed appointments or client dissatisfaction;
  • SMS costs incurred on your mobile carrier plan as a result of messages sent through the Android relay;
  • SMS credits consumed on messages that fail to deliver via a third-party gateway due to carrier network issues, recipient phone status, or other factors outside our control, except where credits are automatically refunded upon permanent failure as described in Section 7.10;
  • Damages arising from third-party SMS gateway outages, delivery failures, or service degradation, which depend on infrastructure operated by the gateway provider and downstream carriers;
  • Damages arising from SMS credit auto-reload charges that you authorised by enabling the auto-reload feature;
  • Damages arising from Google Calendar API outages, delays, or changes beyond our control;
  • Damages arising from unintended modifications to your Google Calendar, including events created, modified, or deleted in error, duplicate or missing events, corrupted event data, lost extended properties, or any downstream scheduling conflicts, regardless of whether the cause was a bug in Scisso, a Google API change, a network failure, or any other cause;
  • Damages arising from connecting a personal calendar rather than a dedicated work calendar, including exposure of private events to Scisso or other staff members;
  • Damages arising from online booking requests that expire, are rejected, or are not confirmed in time, including missed appointments, lost clients, or double bookings;
  • Damages arising from your failure to comply with GDPR or other data protection obligations in your capacity as Data Controller;
  • Damages arising from unauthorised access to your account caused by your failure to protect your credentials or secure the Relay device;
  • Loss or corruption of data caused by hardware failure, software errors, or actions of third parties;
  • Damages arising from payment processing failures, including declined cards, failed 3D Secure verifications, Stripe outages, or delays in payment settlement or refund processing, which depend on Stripe's infrastructure, the client's bank, and card network processing times;
  • Damages arising from chargebacks or payment disputes initiated by your clients. Chargebacks are resolved between you, your client, and Stripe. Scisso provides tools to compile evidence but does not guarantee dispute outcomes;
  • Damages arising from your failure to comply with fiscal obligations, including e-Factura, invoice generation, VAT reporting, or any other tax or regulatory obligation related to payments received through your connected Stripe account. KodeKind provides guidance but does not verify or enforce fiscal compliance;
  • Damages arising from automatic refunds triggered by your configured refund policy, by client self-service cancellation within the policy window, or by the disconnect of your Stripe account while outstanding payments exist.

In all cases, our total aggregate liability to you for any claim arising out of or relating to these Terms or your use of the Service, regardless of the form of action, shall not exceed EUR 100 (one hundred euros) or the total fees paid by you to KodeKind in the three (3) months preceding the event giving rise to the claim, whichever is greater.

What this limitation does not affect. Nothing in these Terms excludes or limits either party's liability for:

  • Death or personal injury caused by negligence
  • Fraud or fraudulent misrepresentation
  • Intentional misconduct or gross negligence (culpă gravă)
  • Obligations under GDPR Article 82 (right to compensation for data protection violations), as further specified in Section 6.13
  • Any other liability that cannot be excluded or limited under applicable law

Your statutory rights under applicable law are not affected by these Terms.

16. Indemnification

Your indemnification obligations. You agree to indemnify, defend, and hold harmless KodeKind and its directors, employees, and agents from and against any third-party claims, liabilities, damages, losses, costs, and expenses (including reasonable legal fees) arising out of or relating to:

  • Your use of the Service in violation of these Terms
  • Your violation of any applicable law or regulation, including GDPR and electronic communications regulations, in your capacity as Data Controller
  • Any claim by a third party (including your clients) arising from your processing of their personal data through the Service
  • Any claim arising from SMS messages sent through your account via any delivery method (Android relay or third-party gateway), including complaints about message content, frequency, or unsolicited promotional messages
  • Your failure to honour SMS opt-out requests or data subject rights requests
  • Your failure to review, confirm, or reject online booking requests in a timely manner
  • Your negligence or wilful misconduct
  • Your failure to comply with fiscal and tax obligations related to online payments processed on your connected Stripe account, including e-Factura, invoice generation, VAT reporting, and advance payment (avans) documentation
  • Any claim by a third party (including a person depicted in a photo you upload, or a holder of rights in such a photo) arising from your publication of images through the Service, including claims under data-protection law, image or personality rights, or intellectual-property rights.

Our indemnification obligations. KodeKind agrees to indemnify, defend, and hold harmless you and your business from and against any third-party claims, liabilities, damages, losses, costs, and expenses (including reasonable legal fees) arising out of or relating to:

  • KodeKind's infringement of a third party's intellectual property rights through the Service itself (excluding infringement caused by your data or content)
  • KodeKind's violation of applicable data protection law in its capacity as Data Processor, to the extent the violation was not caused by your instructions or your failure to comply with your obligations as Data Controller

17. Termination

Either party may terminate use of the Service at any time by written notice. Upon termination:

  • Your access to the Service will cease
  • We will make your business data available for export for 30 days following termination, after which it will be permanently deleted in accordance with Section 6.10 of the Data Processing Agreement
  • Employee accounts will be anonymised (all personal fields nulled, Google Calendar connections revoked) in accordance with our data retention policy
  • Client records will remain available for export during the 30-day window and will be deleted thereafter, unless a longer retention period is required by law
  • Pending SMS messages will be cancelled and their content deleted. Any remaining SMS credit balance will be forfeited unless a refund is required under Section 7.10
  • Provisions of these Terms that by their nature should survive termination (including Sections 6, 7 (including SMS credit refund obligations under 7.10), 14, 15, 16, and 20) will continue to apply

If you breach these Terms, we will notify you and provide 15 days to remedy the breach. If the breach is not remedied within that period, we may suspend or terminate your account. We may suspend or terminate immediately without a cure period only in cases of: (a) fraud or illegal use of the Service, (b) non-payment after two consecutive payment reminders, (c) actions that pose an imminent security threat to other users or the Service's infrastructure, or (d) where continued provision of the Service would expose us to legal liability. Our liability in connection with any termination shall be governed by Section 15.

18. Changes to These Terms

We may update these Terms (including the DPA in Section 6) from time to time. We will update the "Last updated" date at the top of this page. For material changes, we will notify you by email at least 14 days before the changes take effect. Your continued use of the Service after the effective date of the changes constitutes your acceptance of the revised Terms.

If you do not agree to the revised Terms, you may cancel your subscription before the changes take effect. Previous versions of these Terms are available upon request by emailing [email protected].

19. Governing Law and Disputes

These Terms are governed by and construed in accordance with the laws of the European Union and the laws of Romania, without regard to conflict of law principles.

Any dispute arising out of or relating to these Terms or the Service shall first be subject to good-faith negotiation between the parties. If the dispute cannot be resolved within 30 days of written notice, it shall be submitted to the competent courts in Romania.

If you are a consumer under applicable law (and not using the Service in the course of a business), you may also have the right to use the EU Online Dispute Resolution platform at ec.europa.eu/consumers/odr. However, as noted in Section 2, this Service is intended for businesses only.

20. General Provisions

Severability. If any provision of these Terms is found to be invalid or unenforceable by a court of competent jurisdiction, that provision will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will continue in full force and effect.

Entire agreement. These Terms, together with the Privacy Policy and the Data Processing Agreement in Section 6, constitute the entire agreement between you and KodeKind regarding the Service and supersede all prior agreements or understandings, whether written or oral.

Assignment. You may not assign or transfer your rights or obligations under these Terms without our prior written consent. We may assign our rights and obligations to an affiliate or in connection with a merger, acquisition, or sale of all or substantially all of our assets, provided the assignee assumes all obligations under these Terms including the Data Processing Agreement.

Waiver. No failure or delay by either party in exercising any right or remedy under these Terms shall constitute a waiver of that right or remedy. A waiver on one occasion shall not be construed as a waiver on any subsequent occasion.

Notices. All notices under these Terms shall be sent by email to the email address associated with your account (for notices to you) or to [email protected] (for notices to us). Notices are deemed received on the business day after sending, provided no delivery failure notification is received by the sender.

Language. These Terms are drafted in English. If these Terms are translated into any other language, the English version shall prevail in case of any inconsistency.

21. Contact

For any questions about these Terms or the Data Processing Agreement, please contact us at:

Scisso by KodeKind S.R.L.

CIF: RO54603957 | Reg. Com.: J2026028952000

Str. Mihail Kogalniceanu, Camera 1, Bl.C8, Et.4, Ap.16, Timisoara, Timis, Romania

Email: [email protected]

We use cookies

We use essential cookies to keep you signed in and protect against bots. With your consent, we also use analytics to improve the experience, and advertising cookies to see which ads bring people here. Privacy Policy