Last Updated: 25th September 2026
1. Introduction
Enbraun Technologies Private Limited (“Enbraun”, “we”, “our”, “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose and protect information when you use eResource Scheduler through:
- our web-based Software-as-a-Service (SaaS) platform,
- our official mobile applications for iOS and Android,
- our APIs, browser clients and integrations, and
- our MCP Server, which allows authorised users to connect the Service to third-party AI platforms of their choice,
- any related services (collectively, the “Service”).
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
This Privacy Policy forms part of our Terms of Service and incorporates our Data Processing Appendix (DPA), which is attached to those Terms, for customers where GDPR or other data protection laws apply.
For questions, contact us at: support@enbraun.com
2. Information We Collect
We collect information to deliver, improve and secure the Service. Categories of information include:
2.1 Information You Provide
- Account details: name, email, organisation name, login credentials (hashed), user role.
- Resource & scheduling data entered by authorised users.
- Support requests, messages, attachments and feedback.
- Billing & subscription information (managed through Stripe).
2.2 Automatic Data Collection (Web + Mobile)
When you access the Service through web or mobile:
- IP address, browser type/version, operating system.
- Device metadata (model, OS version, device identifier).
- Cookies, session identifiers & authentication tokens.
- App usage logs, feature usage, time spent, interactions.
- Crash logs, error reports, performance diagnostics.
2.3 Mobile App-Specific Data
Our mobile app may collect:
- Device model, OS version, app version
- Push notification tokens (if enabled)
- App crash logs, analytics (non-personally identifiable)
- Data necessary to synchronise offline/online functionality
We do not collect sensitive device data (contacts, photos, location, microphone, camera) unless explicitly required and authorised for a feature — and only with your permission.
2.4 Cookies and Similar Technologies
We use cookies and similar technologies to:
- keep users authenticated
- prevent fraud
- analyse usage patterns
- optimise performance
You may disable cookies in your browser/device settings, but some features may not function properly.
2.5 Webhooks and Event Delivery Data
If you enable Webhook functionality, the Service may transmit event-based data to endpoints or third-party systems configured by you. Such data may include system-generated event information, identifiers, timestamps, metadata and operational data associated with scheduling, resources, users, or system activity.
We may also process webhook delivery information such as endpoint URL, delivery attempts, response status, retry logs, timestamps, and usage metrics for purposes of service delivery, reliability, billing, diagnostics, abuse prevention and security monitoring.
You act as Data Controller for any personal data transmitted through Webhooks to your configured endpoints and are responsible for ensuring lawful processing, security and compliance with applicable data protection laws at your receiving systems.
We do not control processing performed by third-party systems or endpoints configured by you.
2.6 MCP Server and AI Platform Data
The MCP Server is an optional feature that is disabled by default. It can be enabled or disabled only by an administrator of your organisation’s account, and the setting applies to all users of that account. Once it is enabled, each authorised user decides whether to connect an AI platform (for example Anthropic Claude, Microsoft Copilot, OpenAI ChatGPT or Google Gemini) and authenticates the connection with their own eResource Scheduler account.
When an authorised user connects an AI platform, that AI platform can request data from, and make changes to, the Service within the user’s existing permissions. Data returned in response to those requests is sent to the AI platform chosen by the user.
In connection with the MCP Server, we may process:
- records of the MCP Server being enabled or disabled, and of acceptance of the applicable terms (who accepted, when, and which version);
- the identity of the authorised user who authenticated a connection, and the name or identifier of the connected AI platform or client;
- authentication and access tokens;
- the requests the AI platform sends to the MCP Server (such as the action requested, search terms, filters and values to be created or changed), and the data returned or changed in response;
- timestamps, IP addresses, error logs, request volumes and other usage metrics.
We process this information to operate the MCP Server, carry out the requested actions, keep the Service secure, prevent abuse, provide support, and measure usage for billing where charges apply. These records are not displayed within the Service.
We do not receive your full conversations with an AI platform. We receive only the requests the AI platform sends to the MCP Server, which may include text derived from your prompts. We do not use data received through the MCP Server to train artificial intelligence models.
Once data is delivered to an AI platform, it is processed by that AI platform’s provider under its own terms and privacy policy, and is outside our control. Your organisation acts as Data Controller for that transfer, and AI platform providers are not our sub-processors. Please review the privacy policy of any AI platform before connecting it, and check with your organisation which AI platforms you are permitted to use.
We do not use the MCP Server to make automated decisions about individuals. Any decision your organisation makes using an AI platform’s output is made by your organisation.
3. How We Use Your Information
We use your information to:
3.1 Provide the Service
- Authenticate users
- Deliver scheduling, project/resource management features
- Sync data between web and mobile apps
- Operate the MCP Server and carry out requests from AI platforms connected by authorised users
- Provide support, troubleshooting and communication
3.2 Improve and Develop the Service
- Analyse usage and performance trends
- Test new features (including beta features)
- Enhance usability, reliability and security
3.3 Administrative and Legal Purposes
- Billing and subscription management
- Enforcing Terms of Service
- Detecting fraud, abuse or security incidents, including misuse of MCP Server connections
- Compliance with legal obligations and regulatory requests
- Measuring usage for billing of optional or usage-based features (such as API usage, integrations and Webhooks, and the MCP Server)
3.4 Anonymised & Aggregated Analytics
We may anonymise data to remove personal identifiers and use it for:
- product analytics
- statistical reports
- performance optimisation
- industry and benchmarking insights
This anonymised data does not identify you or your organisation.
Processing may be based on performance of contract, legal obligation, or legitimate interest such as security, fraud prevention, service reliability and product improvement.
4. How We Share Information
We do not sell your personal information.
We share information only as needed to provide the Service:
4.1 Trusted Service Providers (Sub-Processors)
Examples include:
- Cloud hosting (AWS, Google Cloud Platform)
- Customer support platforms (e.g., Zendesk)
- CRM or communication tools
- Email processors (e.g., Send Grid)
- Payment processors (Stripe)
All sub-processors are bound by confidentiality and data protection obligations. These may include cloud infrastructure providers, logging systems, notification delivery services, analytics platforms and event delivery infrastructure used for mobile applications and webhook functionality. AI platforms connected through the MCP Server are not our sub-processors (see section 4.2).
4.2 Third-Party Integrations (Optional)
If you connect with external tools or integrations, their data use is governed by their privacy policies. We do not control third-party processing. This includes AI platforms connected through the MCP Server. When an authorised user connects an AI platform, we transmit data to it at the user’s direction and within the user’s permissions. The AI platform’s provider processes that data under its own terms and privacy policy, and we are not responsible for how it stores, uses, retains or shares that data, including whether it uses the data to train its own models.
4.3 Legal, Safety and Compliance
We may disclose information if required to:
- comply with laws or government requests
- protect our rights, users or the public
- investigate fraud or security threats
5. Data Storage, Security and Retention
5.1 Data Security
We implement industry-standard security measures, including:
- encryption in transit (HTTPS / TLS)
- encryption at rest (database/data storage encryption)
- access controls & authentication safeguards
- audit logs and intrusion detection
- secure software development practices
Webhook delivery and mobile communications are transmitted over encrypted channels; however, the security of third-party endpoints configured by customers remains their responsibility.
Connections to the MCP Server are encrypted and authenticated with each user’s own credentials, and requests are limited to that user’s permissions in the Service. The security of AI platforms, and of the accounts users hold with them, is the responsibility of the AI platform provider, the user and their organisation.
5.2 Data Retention
We retain your data for as long as:
- your account remains active, or
- required by law or legitimate business purposes.
After subscription termination, data may be deleted or anonymised after a scheduled retention period, unless otherwise required by law. Operational logs, webhook delivery logs, MCP Server request logs, security logs and usage metrics may be retained for a limited period as necessary for security, diagnostics, billing, legal compliance and service reliability. Disabling the MCP Server, or deleting data from the Service, does not delete copies of data already sent to an AI platform; these must be managed with the AI platform provider.
5.3 Data Breach Notification
If we become aware of a security breach affecting personal data, we will notify affected customers without undue delay, as required by applicable law (including within 72 hours under GDPR).
6. International Data Transfers
Your data may be stored or processed in countries where we or our sub-processors operate. We ensure transfers comply with applicable laws (e.g., Standard Contractual Clauses under GDPR). Data sent to an AI platform through the MCP Server may be processed in the countries where that AI platform’s provider operates. Your organisation is responsible for any safeguards required for such transfers.
7. GDPR and Global Data Protection Rights
If you are located in the EU/EEA, UK or regions with similar laws, you have the right to:
- Access your data
- Correct inaccurate data
- Delete personal data
- Restrict or object to processing
- Port (export) your data
- Withdraw consent (if consent is the basis of processing)
Requests may be submitted to: support@enbraun.com
We act as Processor for customer-submitted data and Controller for account, billing and operational data, including records of MCP Server connections and usage described in section 2.6.
For details, please review our Data Processing Appendix (DPA), attached to our Terms of Service.
For data held by an AI platform connected through the MCP Server, please contact that AI platform’s provider or your organisation. For data processed by the MCP Server itself, you may contact us as set out above. Nothing in our Terms of Service limits any rights you have under applicable data protection law.
8. Mobile App Permissions & Controls
Depending on your platform (iOS/Android), the mobile app may request permissions such as:
- Notifications
- Storage access (temporary app data only)
You can manage these permissions in your device settings. The app will continue working except for features dependent on the disabled permission.
We do not access location, photos, contacts, camera, microphone, or other sensitive data unless a specific feature requires it AND you explicitly grant permission.
9. Children’s Privacy
The Service is intended for business use only. We do not knowingly collect personal data from children below the minimum age required in their jurisdiction.
10. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in technology, law or business practices. When we make material changes, we will:
- update the “Last Updated” date
- notify you via email or in-app notice where appropriate
Continued use of the Service after such changes constitutes acceptance.
11. Contact Us
For privacy inquiries, data protection requests or legal questions, contact:
Enbraun Technologies Private Limited
C 78 Sewar Area, Bapu Nagar, Jaipur 302015, Rajasthan, India
support@enbraun.com
www.eresourcescheduler.com