Privacy Policy
This privacy policy was updated on July 10, 2026
1. Introduction
Virtosoftware UAB, a legal entity established in Lithuania, along with its group companies (collectively "VirtoSoftware", "we", "us", and "ours"), is committed to protecting your privacy.
This Privacy Policy describes our practices concerning the information that we collect through https://www.virtosoftware.com and any other websites operated by us (the "Websites"), our social media pages, email communications, and through our software applications for Microsoft 365 (collectively, the "Services").
This Privacy Policy describes how VirtoSoftware processes Personal Data in its capacity as a controller or as a processor. By using the Services, you agree to this Privacy Policy.
2. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person.
- Processing: Any operation performed on Personal Data.
- Controller: The entity that determines the purposes and means of processing.
- Processor: The entity that processes Personal Data on behalf of the Controller.
- Data Subject: The individual to whom Personal Data relates.
- GDPR: General Data Protection Regulation (EU) 2016/679.
3. What Personal Data do we collect?
When you use our Services, we may collect:
- Contact information such as name, email, address, phone number, company name, job title
- Billing information such as credit card number, PayPal details, billing address
- Feedback information such as name and email when you provide feedback
- Unique identifiers such as username, account number, password
4. What do we use your Personal Data for?
We use Personal Data for legitimate business purposes including:
- To provide the Service(s) and fulfill your requests
- To send communications and respond to inquiries
- To administer your account and provide customer service
- To send periodic emails with important notices
- To personalize your experience
- To facilitate billing and payment transactions
- For data analysis and improving our Services
- To develop new products and services
5. Legal Basis for Processing
Under GDPR, we process Personal Data based on:
- Article 6(1)(b) – Contractual Necessity
- Article 6(1)(c) – Legal Obligation
- Article 6(1)(f) – Legitimate Interest
- Article 6(1)(a) – Consent
6. To whom do we disclose your Personal Data?
Your Personal Data may be disclosed to our affiliates, third-party service providers, and as required by law. Contact support@virtosoftware.com for a list of service providers.
7. Cookies and Tracking Technologies
For details on cookies, please see our Cookie Policy.
8. Processing Customer Information
We process Customer Information on behalf of our Customers as a data processor under GDPR. A Data Processing Agreement (DPA) compliant with GDPR Article 28 is available to all Customers.
9. Data Subject Rights
If you reside in the EEA, you have rights including: access, rectification, erasure, objection, restriction, data portability, withdrawal of consent, and the right to lodge a complaint. We respond within thirty (30) days.
10. Retention of Personal Data
We retain Personal Data as long as needed for the purposes for which it was obtained.
11. Protection of Your Information
We have implemented reasonable technical and organizational measures to maintain the safety of your Personal Data.
12. Data Breach Notification
In the event of a confirmed data breach, we will notify you without undue delay.
13. Disclosure Outside the EEA
Your Personal Data may be transferred to countries outside the EEA. We use standard contractual clauses to protect your data.
14. Sign-in Services
You can log in using GitHub, Google, Facebook, and others.
15. Third-Party Links
We may include third-party links. This Privacy Policy does not apply to third parties.
16. Children and Minors
Services are not directed to individuals under sixteen (16).
17. Automated Decision-Making
VirtoSoftware does not engage in automated decision-making with legal effects.
18. California Privacy Rights
California residents have specific rights under CCPA. Contact us to exercise them.
19. Google User Data
This section applies to Virto Calendar (the "App"), published by VirtoSoftware UAB, and governs Google user data only. It applies solely when you choose to connect a Google Calendar data source inside the App. If you do not connect a Google Account, the App neither requests nor accesses any Google user data.
VirtoSoftware processes Google user data to provide the connected-calendar feature you request. The legal basis for this processing is the performance of that service (Article 6(1)(b) GDPR); the OAuth authorization you grant is the technical means by which access is enabled, not itself the legal basis. Our role and responsibilities for this data are as described in Section 8 of this Policy.
Virto Calendar's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
19.1 What Google user data the App accesses
After you grant consent on Google's OAuth consent screen, the App requests the following OAuth scopes and accesses the corresponding data:
https://www.googleapis.com/auth/calendar– the Google Calendars you can access and the events they contain. The App uses this scope to retrieve the list of your calendars, to read event data (such as event titles, descriptions, start and end times, locations, and attendees), and to create, move, and delete events on your behalf when you take actions in the App that add, reschedule, or remove events.https://www.googleapis.com/auth/userinfo.email– the primary email address of your Google Account, used at the time you connect the account to identify which Google Account the connection is being established for.openid– your Google Account identifier, used to associate the OAuth authorization with your Google Account.
The App does not request access to Gmail, Google Drive, Google Contacts, or any other Google service.
19.2 How the App uses Google user data
The App uses Google user data solely to provide the user-facing calendar features that are prominent in its interface:
- to display your Google Calendar events alongside your Microsoft 365, SharePoint, and Exchange calendars in a single overlay view;
- to refresh that view with current data from Google Calendar;
- to create, move, and delete Google Calendar events in response to actions you take inside the App.
We do not use Google user data for advertising, and we do not sell it. We do not use Google user data to develop, train, or improve any generalized or non-personalized machine-learning or artificial-intelligence model, including large language models. We do not use Google user data for any purpose other than the features described above.
19.3 With whom we share, transfer, or disclose Google user data
We do not sell Google user data, and we do not transfer or disclose it to third parties for any purpose other than providing the features you requested.
Google user data is retrieved through VirtoSoftware application servers hosted on Microsoft Azure. Microsoft Corporation acts as VirtoSoftware's infrastructure sub-processor under contractual data-protection obligations, and any international transfers of this data are governed by the safeguards described in Section 13 of this Policy. We may disclose Google user data where required by applicable law or in response to a valid legal request, or where necessary to protect against fraud, abuse, or security threats. In the event of a merger, acquisition, or sale of assets involving the transfer of Google user data, we will carry out such a transfer only with your explicit prior consent, as required by the Google API Services User Data Policy (Limited Use). All such transfers remain within the Limited Use requirements.
19.4 How we protect Google user data
We apply technical and organizational measures to protect Google user data in transit and at rest:
- all traffic between your browser, VirtoSoftware servers, and the Google APIs is encrypted in transit using industry-standard TLS (HTTPS);
- Google OAuth access and refresh tokens are stored in Microsoft Azure Table Storage and encrypted at rest using 256-bit AES;
- Google Calendar requests are made from VirtoSoftware servers rather than from your browser, so that OAuth tokens are never exposed to the browser;
- Google Calendar event content is processed in server memory to render your calendar view and is not written to VirtoSoftware databases, caches, or application logs;
- access to production systems is restricted to authorized personnel on a least-privilege, role-based basis;
- we handle suspected security incidents under our internal procedures and notify affected customers of any personal-data breach without undue delay, in line with applicable law.
19.5 Retention and deletion of Google user data
The only Google-derived data that VirtoSoftware stores is:
- the OAuth access and refresh tokens issued for your Google Account; and
- the identifier of the Google calendar you selected for display. For a primary Google calendar, this identifier is the email address of the Google Account.
Google Calendar event content is not retained. It is processed transiently in server memory and is not persisted to VirtoSoftware databases, caches, or application logs. Apart from the calendar identifier described above, we do not store your Google Account email address or Google Account identifier.
The tokens and the calendar identifier are retained only for as long as the corresponding Google Calendar data source exists in the App. When you delete that data source, they are deleted immediately from our systems.
You may stop the App from using your Google Account at any time by deleting the Google Calendar data source in the App, which deletes the OAuth tokens we store. To fully revoke the grant on Google's side, you can also remove the App through your Google Account settings at https://myaccount.google.com/permissions. You may request deletion of any Google user data we hold by contacting dpo@virtosoftware.com, and we will respond to such requests within thirty (30) days.
20. Changes to our Privacy Policy
We may change this Privacy Policy at any time. Changes become effective when posted.
21. How to Contact Us
Email: support@virtosoftware.com
Address: VirtoSoftware UAB, Penta Technopolis, Ozo g. 12A, Vilnius, Lithuania 08200
Phone: +1 (877) 892-7775
DPO: dpo@virtosoftware.com
Complaints: State Data Protection Inspectorate, L. Sapiegos str. 17, LT-10312 Vilnius, Lithuania.
Talk to our team
Need clarity on our app's suitability for you? Set up a quick call with us or chat via Microsoft Teams.