Skip to content
Lobbly

Privacy Policy

How Lobbly handles personal data

This policy explains how CODE BARRES - BARCODE processes personal data when you visit Lobbly, create an account, join a workspace, use collaboration features or receive service emails.

Data controller

  • Controller: CODE BARRES - BARCODE
  • Registered office: CS 20005, 29 boulevard de la Ferrage, 06400 Cannes, France
  • Privacy contact: hello@lobbly.io

Data we process

  • Account data: name, email address, encrypted password, avatar choices, language or interface preferences.
  • Workspace data: workspace name, URL slug, members, roles, invitations, room ownership and room settings.
  • Real-time presence data: online status, room location, device state, speaking indicators and network quality.
  • Contact, support and service emails: contact-form requests, verification, password reset, invitation and product communications.
  • Technical data: authentication cookies, security logs, IP address, browser information and error logs.
  • Audience measurement data: cookieless Matomo events and page statistics without user, workspace or room identifiers.
  • Billing data: subscription, invoicing and payment information when a paid plan is used.
  • Optional Google sign-in data: stable Google account identifier and verified email address used to link an existing Lobbly account.
  • Optional connected-calendar data: account identity, calendar names, events, participants and synchronization metadata selected by the user.
  • Files data: uploaded documents, folder names, ownership, sharing permissions, size, media type and storage metadata.

Optional Google sign-in

Google sign-in is optional and is available only for an existing, verified Lobbly account using the same verified email address. Lobbly stores the stable Google account identifier needed to recognize later sign-ins, but does not store the temporary Google sign-in access token. Google sign-in does not by itself authorize access to Google Calendar.

Optional Google Calendar connection

Connecting Google Calendar is optional. Lobbly requests access only after an explicit action by the user and uses the authorized data to display, create, update and delete calendar events inside Lobbly. OAuth access and refresh tokens are encrypted at rest and are never exposed to workspace members or the browser after the authorization exchange.

Calendar data is not used for advertising, profiling or training, and is not sold or transferred to third parties except as required to provide the requested synchronization with Google. Disconnecting the account revokes access when the provider permits it and removes its synchronized calendars and events from Lobbly. Lobbly's use of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

How we protect Google user data

  • Google authorization and API exchanges use HTTPS encryption in transit.
  • OAuth access and refresh tokens are encrypted at rest with authenticated AES-256-GCM encryption.
  • The token-encryption key is held in protected server configuration, separately from the encrypted tokens and application data.
  • OAuth tokens are processed only by the Lobbly server, are never returned to the browser after authorization and are excluded from application logs and analytics.
  • Access to synchronized calendars and events is checked for the authenticated user and workspace on every request. Workspace administrators do not receive automatic access to another member's calendar.
  • Lobbly requests only the Google scopes required for the visible sign-in and calendar synchronization features.
  • When a user disconnects Google Calendar, Lobbly requests revocation of the Google authorization and deletes the corresponding tokens, synchronized calendars and synchronized events from its active database.

Audio, video and screen sharing

Lobbly provides real-time audio, video and screen sharing. These streams are transmitted to provide the meeting experience and are not recorded by Lobbly by default.

Files storage

Files uploaded to the Pro universe are stored in private Object Storage hosted by Scaleway in France. They remain private to their owner unless the owner explicitly shares a file or folder with active members of the same workspace. Short-lived signed URLs are issued only after a server-side access check; storage credentials are never sent to the browser.

Purposes and legal bases

  • Providing the service, workspaces, rooms, accounts and billing: performance of a contract.
  • Securing the service, preventing abuse and maintaining logs: legitimate interest and legal obligations.
  • Sending transactional emails: performance of a contract and legitimate interest.
  • Measuring aggregate product usage and improving the service with self-hosted, cookieless Matomo analytics: legitimate interest, with a right to object.
  • Sending optional product updates: consent, where requested.
  • Complying with accounting, tax or legal obligations: legal obligation.

Processors

Lobbly uses Scaleway for hosting in France, Mailjet for transactional email and Google Workspace for email and internal productivity. Any payment provider used for online billing will be identified before that service is activated.

Audience measurement is performed with a self-hosted Matomo instance operated for Lobbly. The script and measurement requests are enabled by default in a cookieless, aggregate configuration. Tracked URLs use a generic host and contain no query, fragment or workspace subdomain. Events accept only controlled, non-identifying values. Measurement is not used for advertising, cross-site tracking or individual profiling. You can object at any time on the Cookies page.

Retention

  • Pending signup verification codes expire after 1 hour.
  • Workspace invitations are retained for up to 30 days after expiry or revocation.
  • Guest workspace access expires 30 days after the corresponding invitation is created.
  • Account and workspace data are retained while the account or workspace is active.
  • Uploaded files and their access metadata are retained while the owning workspace is active or until they are deleted under the applicable product retention flow.
  • Contact-form requests are retained only as long as needed to answer and for no more than 3 years after the last exchange, unless a legal obligation requires longer retention.
  • After a verified deletion request, account data is deleted or anonymized within 30 days, unless retention is required by law.
  • Security and connection logs may be retained for up to 12 months.
  • Matomo audience measurement data is retained for no longer than 25 months.
  • Backups are overwritten within a maximum of 90 days.
  • Invoices and accounting records are retained for 10 years as required by French accounting rules.

Your rights

You may request access, rectification, deletion, restriction, portability or objection to the processing of your personal data. You may object to audience measurement on the Cookies page and withdraw consent where another processing activity is based on consent. Contact hello@lobbly.io. You may lodge a complaint with the CNIL if you believe your rights are not respected.

International transfers

Lobbly hosts product data in France. Some processors, such as Google Workspace or Mailjet, may process limited data outside France or the European Union under their contractual and legal transfer mechanisms.

Version: 2026-08-19.