Privacy Policy

Last updated: 24 September 2026

Pamio is a booking and management platform for businesses. Business administrators and team members use Pamio to schedule and manage appointments; customers interact with the business through chat (Telegram, WhatsApp) and, where enabled, phone calls. This policy explains what personal data we process, why, and your rights over it.

This policy covers the Pamio web application, the Pamio Android and iOS apps (wrappers around the same web application), and the chat/voice channels customers use to reach the business.

1. Who is responsible for your data

Pamio Limited (“Pamio”) provides the platform. Each business decides what customer information to enter and how to use it — for that information the business is the data controller and Pamio acts as its data processor. For the accounts of business staff (administrators and team members) and for running and improving the service, Pamio is the controller. Questions either way: info@pamio.io.

2. Who can use the app

The Pamio app is for business administrators and team members (adults). Customers do not use the app — they interact with the business through Telegram, WhatsApp, or phone. There is no consumer/customer sign-up in the app.

3. What we collect

Whose dataWhatWhy
Business staff (admins / team members) Name, email address, phone number; a password (stored only as a secure hash) or a Google account used to sign in; the business’s details; sign-in and usage activity; usage analytics (pages viewed, features used) and session recordings of the app interface, with customer details and typed input masked. To create and secure accounts, sign you in, and operate the app.
Customers (entered by the business) Name, phone number, email; appointment and booking history; messages exchanged with the business’s assistant over chat; transcripts of phone calls (text only, where calls are enabled). To schedule appointments, send reminders/confirmations, and let staff manage the customer’s bookings and conversation history.
Learner drivers (Ireland — driving schools only) Where a driving school uses Pamio to log Essential Driver Training (EDT) lessons: the learner’s date of birth and driver number (both from the learner permit), the logbook number the instructor issued, which EDT modules have been completed, and — for each lesson the instructor logs — the Road Safety Authority’s reply (whether it was accepted, already recorded, or refused, and why). The learner may enter their own permit details on the school’s setup form; the instructor may enter or correct them. Only to log the learner’s EDT lessons with the Road Safety Authority on the instructor’s behalf, and to keep a record of what was logged. Not used for anything else.
Business staff — support requests Messages you send to Pamio support from inside the app, and any screenshot, video or voice message you choose to attach. Pamio keeps the text of the conversation with your account. Attachments are relayed to the Pamio team and are not stored on Pamio’s servers (see “Telegram” under service providers). To answer your support requests.
Business staff — “Import from phone” When you add a customer with “Import from phone”, the app opens your phone’s own contact picker and reads only the one contact you pick — their name and phone number — to fill in the form. Nothing else is read from your contacts, no contact list is uploaded, and those details are saved to your business’s account only if you then add that customer. To save you typing a customer’s details.
Everyone Basic technical data needed to run a web service (e.g. request and security logs). Security, reliability, and abuse prevention.

Phone permissions. The mobile apps ask for microphone access only while you record a voice message for support, and for photo-library access only so you can pick a photo or video to send to support. Nothing is read or sent until you pick or record it, and every feature of the app works without granting either.

Card payments. Where a driving school offers to take payment for a lesson through Pamio, the payment page and your card details are handled by Stripe, our payment processor, under Stripe’s own privacy policy. Pamio never sees or stores your card number; we keep a record of the payment (amount, date, the last four digits and card brand Stripe reports, the lesson it paid for, and the instructor it was paid to) so your instructor, the school and you can see what was paid and so refunds can be made. The Booking Terms explain who you are paying.

We do not collect payment-card details ourselves, precise device location, health data, or special-category data through the app. We do not record call audio — only a text transcript where calling is enabled. The only audio the app handles is a voice message you record yourself for support.

4. How we use personal data

We do not sell personal data, and we do not use it for third-party advertising.

5. Legal bases (GDPR)

6. Service providers we rely on

We use a small set of trusted providers (sub-processors) to run Pamio. They process data only on our instructions and under contract:

Where a provider processes data outside the EU/EEA, that transfer is covered by appropriate safeguards (such as Standard Contractual Clauses).

The Road Safety Authority (RSA), Ireland. When an instructor logs an EDT lesson, Pamio sends the learner’s driver number, date of birth, logbook number, the module and the lesson date to the RSA’s ADI portal — exactly what the instructor would type into it by hand. The RSA is not a Pamio service provider: it is a separate public body running its own portal under the instructor’s own account, and it holds that record under its own rules. Pamio cannot alter or remove a lesson once the RSA has recorded it.

The instructor’s RSA portal login is never stored by Pamio. It lives only on the instructor’s own phone, in the phone’s secure store, and is used on that phone to sign in to the portal. Pamio’s servers hold only that a phone is connected and when the login was last checked — never the password.

7. Where data is stored, and for how long

Pamio’s data is stored in the European Union (AWS Ireland). We keep personal data for as long as the relevant account is active and as needed to provide the service. When a business deletes its account, the associated data is removed; staff and customer records can also be deleted on request. Some limited records may be retained where required by law.

8. Security

Data is encrypted in transit (HTTPS/TLS). Passwords are stored only as secure hashes. Access is restricted and the platform runs inside a private network. No system is perfectly secure, but we take reasonable measures to protect personal data.

9. Your rights

Subject to applicable law, you can request to access, correct, delete, export, or restrict your personal data, and you can object to certain processing. Account holders can delete their account from within the app. To exercise any right, contact info@pamio.io — for customer data, the relevant business (as controller) may need to action the request, and we will assist.

If you are in the EU/EEA and have a concern, you may also lodge a complaint with your local data protection authority. In Ireland, this is the Data Protection Commission (dataprotection.ie).

10. Children

Pamio is not directed at children, and the app is used by adult business staff. Customer records are entered and managed by the business.

11. Changes to this policy

We may update this policy from time to time. We’ll change the “Last updated” date above and, for material changes, take reasonable steps to let account holders know.

12. Contact

Pamio · info@pamio.io