Guest & Participant Terms
Effective 2026-08-17 · Version 1.9If someone used Lonzo to email you about their meeting, this page is for you. The message reached you from their email address, not from an address of ours — the assistant that wrote and sent it acts through their account. You do not have an account with us, you did not sign up for anything, and you are not on a marketing list. This page explains who we are, where we got your email address, what we do with what you send back, and how to make the contact stop — permanently, without an account and without asking anyone's permission.
The Service is operated by Vista del Lago Software LLC, a Delaware limited liability company, of 18381 Vista del Lago, Yorba Linda, CA 92886, USA, which offers it under the Lonzo name. Data-protection contact: privacy@lonzo.ai.
1. What these Terms are, and who they bind
These Guest & Participant Terms (the "Terms") govern your interaction with Lonzo (the "Service," "we," "us," "our") as a participant in someone else's meeting coordination — not as an account holder. If you hold your own Lonzo account, the Terms of Use and Privacy Policy govern that relationship in addition to these Terms.
In these Terms:
- "Organizer" means the Lonzo account holder who is trying to schedule a meeting and on whose behalf the assistant acts. The Organizer is the human authority for the outreach; the assistant is an automated agent operating under the Organizer's direction and cannot send you anything the Organizer has not asked it to arrange.
- "Participant" means any person the assistant contacts by email to collect availability for the Organizer's meeting, whether or not that person ever responds.
- "Guest" means a Participant who has opened a link we sent and thereby activated a scoped session (Section 3). Every Guest is a Participant; not every Participant becomes a Guest — and today none of them does, because no such link is sent (Section 3). The definition stands for the mechanism, not for anyone currently using it.
These Terms bind you as a Participant and, if you open the link, as a Guest. They do not purport to bind the Organizer, whose obligations to you are a matter between you and the Organizer.
2. Email only
The Service sends no SMS or text messages. Everything described here concerns email. If we later add a text-messaging channel, it will carry its own terms and its own consent requirements, and this page will say so before it does.
3. How you answer: by reply. There is no guest link today
You reply to the message. That is the whole route, and it works: your reply arrives in the Organizer's own mailbox — the message came from their address, not ours — and the assistant reads it there to record the times you gave. You need no account, no login, no app and no link, and nothing is lost by not clicking anything.
We are not sending you a link, and until 2026-08-17 this section said we were. It described a /g/<token> guest link that opened a page where you could see the meeting details and submit or update your availability. That page is written but not connected to anything — opening the link would have shown you nothing about the meeting and offered you nothing to submit — and a second form of the link, for recipients who already have a Lonzo account, pointed at a URL our own site does not serve. So we removed the link from the message rather than keep sending a door with no room behind it. Describing a response surface you cannot use would be the worse of the two errors: it invites you to wait for something to load instead of just replying.
What we hold about you does not depend on that link. Section 4 is the notice we owe you either way, Section 6 is how you exercise your rights, and Section 7 is how you stop the contact — all three work today and none of them needs a page.
If and when the page is built, the terms it will run under are the ones this section always set out, and they are the reason it is worth building rather than dropping: no account, no login and no password; an identity bound to a key your own browser generates rather than to anything we issue; a session scoped to one coordination and refused everything else — not another coordination, not the Organizer's account or mailbox, not another Participant's response, not any account surface; not transferable to another device or person; and expiring after 7 days, after which it grants nothing. One link per participant per meeting, reused on a follow-up rather than re-minted. We will publish the change here before any such link is sent, and we will not send one that reaches less than that.
4. What we hold about you, where it came from, and why (GDPR Article 14 notice)
Because your details reached us from someone else rather than from you, Article 14 of the GDPR (and analogous laws) requires us to tell you specific things without your having to ask. This section is that notice. The main points — who we are, that your address came from the sender's own contacts, what we use it for, and where to read the rest — also appear in short form in the message itself, so you have them before you open anything.
| Data | Source | Why we have it |
|---|---|---|
| Your name and email address | The Organizer — from the Organizer's Google Contacts and mailbox, which the Organizer connected to the Service. Not supplied by you to us. | To reach you about the Organizer's meeting and to relay the outcome. |
| A one-way hash of your email address | Derived by us from the address above | Held in the guest-link record instead of the address itself, so that link can be matched to you and to your opt-out without the record being a directory of contact details. |
| Your availability response | Your reply to the message (Section 3) | To record the times you gave and relay them to the Organizer for this meeting (Section 5). |
| A key generated by your browser, and session and technical data — a link token, timestamps, and the IP address of the session | Your device and our servers, only if you ever open a guest link | Not collected today: no guest link is sent (Section 3), so no such session exists to generate any of it. Listed because the token record in the row above is real and because this is what a session would hold if one is ever offered — to bind it, authenticate submissions without a password, and expire it on schedule. |
| Delivery and opt-out signals | The Organizer's mail provider (Google, which carries the message), our own email provider for account mail, and you | To know whether a message reached you, and to stop sending if you opt out (Section 7). |
Controller. Vista del Lago Software LLC acts as a controller for the outreach, for your reply once the assistant reads it, and for any guest session we ever open under Section 3, alongside the Organizer, who is a controller of their own contact list and mailbox. Our EU/UK Article 27 representative designation is in progress and is not yet complete; until it is, write to privacy@lonzo.ai and we will handle the request directly rather than routing it.
Purpose, and the limit on it. Your details are used only for the transactional coordination purpose — contacting you about, and collecting and relaying your availability for, the Organizer's specific meeting. We do not send you marketing, we do not add you to any list of ours, we do not sell or share Participant data, and we do not use your address to create an account for you. Our own commitment on this point is in the Acceptable Use & Anti-Spam Policy, Section 5.3.
Legal basis. Our legitimate interests, and the Organizer's, in arranging a meeting with someone the Organizer already has a relationship with — balanced against your rights, and resting on the Organizer having a lawful basis to share your details with the Service in the first place. The Organizer's obligation to have that basis is a term of their agreement with us (Acceptable Use & Anti-Spam Policy, Section 5.2), not a courtesy. Your right to object to processing on this basis is in Section 6, and an objection is honored as an immediate and permanent opt-out.
Retention. Set out in Section 8.
5. Your response goes to the Organizer
Your reply is shared with the named Organizer so they can schedule the meeting. It is not shown to other Participants in the same meeting — each of them was written to separately and none of them is sent your answer.
Be aware of what that means in practice, because it is stronger than a policy: your reply goes to the Organizer's own mailbox, since the message you are answering was sent from their address rather than ours. The assistant reads it there, works out the times you gave, and records them on that meeting. So anything you write reaches the Organizer — a whole reply, not just the part about times. Please do not write anything you would not want them to read, and note that we cannot unsend it from their mailbox for you.
6. Your rights, and how to use them
Subject to applicable law, you may have the right to access, correct, or delete the personal data we hold about you for this coordination, to object to or restrict its processing, to receive a copy of it, and to stop further contact. Because you have no account and no login, we keep the path short:
- To stop hearing from us, use the mechanisms in Section 7. That is immediate and permanent and needs no explanation from you.
- For anything else — access, correction, deletion, objection, restriction, or a copy — write to privacy@lonzo.ai. There is no self-service control for this, because you have no account to hold one; a person handles it. We aim to respond within the time applicable law allows, and within 30 days where no shorter period applies.
- Because your address is held in the guest-link record only as a hash, we may need you to tell us which coordination you mean — forwarding the message you received is the easiest way.
We action these requests ourselves for the outreach and the guest-session data, rather than only telling you to go to the Organizer. For data the Organizer independently controls — their own address book, their own mailbox, and the record of the meeting in their account — you may also need to ask the Organizer, and we will tell you so plainly rather than leaving you between two parties.
You are not required to respond to anything. Ignoring the message is a complete answer, and we place no consequence on it.
7. How to stop hearing from us
Where the message came from, because it decides which controls work. A coordination message reaches you from the Organizer's own email account — their address in the From line, their mailbox, their sending reputation. We do not send it from an address of ours, and it names them because it is from them. What we add to it is the opt-out machinery below: it travels with every message, and the Organizer cannot turn any of it off.
Every coordination message carries all of the following:
- a visible unsubscribe link in the footer, which needs no login and no account: it opens a page that asks you to confirm, and confirming means sending the one prefilled message that page offers you;
- a List-Unsubscribe header, which many mail apps surface as a one-click "unsubscribe" button; and
- an
unsubscribe+<token>@lonzo.aiaddress, carried in that header, which you can also write to directly.
Why the visible link asks you to confirm, when your mail app's button does not. Opting out is permanent and has no undo you can reach yourself, and plenty of things follow links in your mail without you: scanners, previewers, link-rewriters. If merely opening that page stopped your mail, one of them could stop it without you ever having decided — so the page changes nothing until you send the message it offers. Your mail app's own "unsubscribe" button is different: it does not open the page, it tells us directly, and that we act on at once.
Two further limits on that list, stated rather than left for you to discover. Replying to the message does not reach the unsubscribe address — a reply goes to the Organizer's mailbox, because that is where the message was sent from; what happens to a reply that asks us to stop is the next paragraph. And a coordination message carries no postal address of ours, because it is not our message to footer: the Organizer sent it, from their own account, about their own meeting. Mail the Service sends from its own lonzo.ai address — account and service mail — does carry our postal address, as the Acceptable Use & Anti-Spam Policy, Section 6.1, describes.
An opt-out is checked before every send, is permanent, and is not limited to the meeting that prompted it — once you opt out, that address stops receiving coordination mail from that Organizer's account, not just from that one thread.
Reporting the message as spam is not the same control, and we would rather say so than let you rely on it. If you report a message the Service sent from its own address, our email provider adds yours to a suppression list that stops that mail service-wide. A coordination message went through the Organizer's Gmail, so a spam report on it goes to Google and to that Organizer's own reputation — we never see it, and it suppresses nothing here. The unsubscribe link is the one we act on.
"Wrong person." If you reply that you are the wrong person — "wrong number," "not me," "wrong person," "you have the wrong person," "I don't know this person" — we treat it as an immediate opt-out, stop contacting the address, and tell the Organizer that their contact record is wrong, without asking you to prove anything. A reply asking us to stop is treated the same way: "unsubscribe," "stop emailing me," "take me off." We read these from a fixed list of phrasings rather than by interpretation, which is why the ones we name are honored every single time and why we name them: a phrasing we do not recognize reaches the Organizer as an ordinary reply instead. If you want certainty rather than a good chance, use the unsubscribe link — that path cannot be missed.
About the record we keep of your opt-out, and the one gap in it. Honoring an opt-out means remembering it, so we keep a small record — the fact that you opted out and the medium it applies to, nothing more — and we keep it for as long as the account that could send to you exists. It never expires on its own, no setting turns it off, and it is checked before every send.
What it is not is a service-wide list of addresses held apart from any account. The record lives inside that Organizer's account data, because that is where their record of you lives, so two things follow and you should hear both. First, it does not silence a different Organizer who independently has your address — that person has to be told separately, and Section 6 is how you tell us. Second, if that Organizer's account is deleted, the record goes with it; nothing can be sent to you from an account that no longer exists, so the outcome you asked for still holds, but the memory of your request does not outlive it. The narrow case that leaves open is the same person opening a new account and adding your address again. We have not closed that case. Until 2026-08-17 this section said the record survives the deletion of the Organizer's account and is the one thing we will not delete on request; that was not true, and if you read it and relied on it you were owed this correction rather than a quiet edit. Doing it properly means holding a record outside every account, and we will say so here when it exists.
Two other things do not depend on any of that. Adding back an address that opted out, in order to contact it again, is a violation of the Acceptable Use & Anti-Spam Policy on the Organizer's part, whatever account they do it from. And a request you make to us under Section 6 is handled by a person, not by that account. The Data Retention & Deletion Policy sets out both records and their different lives. If you would rather we hold nothing at all, tell us and we will explain the trade-off before doing anything.
These messages are not marketing, and we do not treat them as such: they are transactional coordination for one meeting, initiated by the Organizer. Even so, they carry the full set of elements above, and an opt-out is honored before the next send rather than within the ten business days CAN-SPAM would allow.
8. How long we keep it
We want to be straight about this rather than quote a number we do not enforce.
- The guest-link record expires 7 days after issue. It is created for each participant we email — that is where the one-way hash of your address lives — even though the link itself is not sent to you (Section 3). The expired record is retained no longer than needed to keep an expired link from being reused and to answer a dispute about the coordination.
- Your name, address, and availability response live inside the Organizer's account data, because that is what they are — the Organizer's record of a meeting they arranged. They are removed when the Organizer deletes that record, and they are removed when the Organizer's account is deleted, on the schedule and with the limits described in the Data Retention & Deletion Policy. They are also within reach of a deletion request you make to us under Section 6.
- There is currently no automated sweep that deletes inactive Participant data on a fixed schedule. We are not going to promise one before it exists. Until it does, we keep this data only as long as the coordination purpose and our legal obligations require, and a request under Section 6 is the reliable way to have it removed sooner.
- An opt-out you give us is kept for as long as the account that could have sent to you exists, for the reason given in Section 7 — it never expires on its own, no setting turns it off, and nothing re-enables the sending while that account is there. It sits inside that account's data, like the rest of the record above, so if the Organizer's account is deleted it goes with it — and so does anything that could have sent to you from it. If the Organizer's account is deleted while your opt-out is on file, the outcome you asked for still holds; the record just no longer needs to.
- A suppression entry our email provider holds — created when an address bounces or reports as spam a message we sent from one of our addresses, not the Organizer's (Section 7) — is kept indefinitely and is keyed to the address rather than to any account, so it is not affected by any account being deleted.
- Technical and delivery logs age out on the bounded schedule in the Data Retention & Deletion Policy.
9. If you decide to create your own account
You may, but nothing here pushes you to, and declining costs you nothing.
- Creating an account always creates a new, separately verified account. It is never an in-place upgrade of a guest identity, and a guest identity is not a thing that can be "converted."
- The new account is governed by the Terms of Use and Privacy Policy, which you agree to separately, and by the Subscription & Billing Terms if you subscribe.
- Nothing about your participation is silently merged into a pre-existing identity.
10. Acceptable use by Guests
Even in a scoped session, you agree not to: impersonate anyone or misrepresent who you are; submit unlawful, abusive, harassing, or infringing content in an availability note or any other free-text field; probe, scan, attack, overload, or try to circumvent the guest endpoint or its access controls; use automated means to scrape or harvest from the Service; or use the link for anything other than responding to the Organizer's request. We may suspend or revoke a session for a violation, or where we reasonably believe revocation is needed to protect the Service, the Organizer, or others.
11. Children
This feature is meant for adults, and we do not knowingly direct outreach to children. We recognize the structural problem honestly: Participant addresses come from an Organizer's address book, so a first message can reach a minor before anyone has represented anything about age — and no checkbox after the fact cures that. So:
- We do not rely on a "you represent that you are an adult" click to legitimize having contacted you.
- On any indication that a recipient is a child that reaches a person here — a report to abuse@lonzo.ai or privacy@lonzo.ai, a note from the Organizer, a reply someone forwards to us — we suppress that recipient by hand, on every medium, and it is then checked before every send exactly as an opt-out is. The suppression is deliberately not the same record an unsubscribe writes: an unsubscribe can be undone by a later reply from the same address or number, and this one cannot be undone that way at all. Lifting it takes two of us and a reason.
- The suppression is recorded in the account that contacted you, because that is where the address exists — we do not keep a list of addresses of our own (see the Privacy Policy). If more than one Organizer's account reached the same child, tell us that, and each one is a separate act on our side.
- We do not scan replies for signs that the writer is a child, and we will not claim to. The automated reading of a reply covers the opt-out phrasings named in Section 7 and nothing else. So the sentence above is a commitment about what we do when told, not a detector.
- We do not knowingly continue outreach to a person we understand to be a child.
If you believe we have contacted a child or hold a child's data, write to privacy@lonzo.ai. Tell us the address or number and, if you know it, who contacted them. We will suppress that recipient on every medium in the account that reached them, and delete what we hold.
12. Disclaimers
The Service, including the guest link and the coordination features, is provided to you "AS IS" and "AS AVAILABLE," without warranties of any kind, whether express, implied, or statutory, including any implied warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service will be uninterrupted, timely, secure, or error-free, or that any message will be delivered. Some jurisdictions do not allow the exclusion of certain warranties, so some of these exclusions may not apply to you.
13. Limitation of liability
To the maximum extent permitted by law, we will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of data, profits, or goodwill, arising out of or relating to your use of the Service as a Participant or Guest, even if advised of the possibility of such damages. Our total aggregate liability arising out of or relating to these Terms will not exceed US $100. Nothing in this Section limits liability that cannot be limited under applicable law, including liability for death or personal injury caused by negligence, for fraud, or for any other liability a mandatory consumer-protection rule in your country of residence does not permit us to exclude. This Section survives termination.
14. Changes; governing law; disputes; survival
- Changes. We may update these Terms. If we make a material change we will update the effective date and version above, and the change will be visible on this page — which is the page you are reading and the one every message we send links to, so it needs no session and no link of yours to reach. Continuing to correspond with the Service after an update means you accept the updated Terms.
- Governing law and venue. These Terms are governed by the laws of the State of Delaware, USA, without regard to conflict-of-laws rules, and the courts located in New Castle County, Delaware have jurisdiction. Nothing here deprives a consumer resident in the EEA, the UK, or Switzerland of the protection of mandatory consumer-protection provisions, or of the right to bring proceedings in their country of residence.
- No arbitration, no class-action waiver. These Terms do not impose binding arbitration or a class-action waiver on you. You never signed up for an account and you pay us nothing; we do not think it is right to compel a non-contracting party into arbitration, and we have not. This differs deliberately from the account-holder Terms of Use, which does contain an arbitration agreement.
- Survival. Sections 4, 6, 7, 8, 10, 12, 13, and this Section 14 survive the expiry of your link or session.
15. Contact
Vista del Lago Software LLC 18381 Vista del Lago, Yorba Linda, CA 92886, USA
- Participant privacy and data rights: privacy@lonzo.ai
- General questions: support@lonzo.ai
- Abuse or unwanted contact: abuse@lonzo.ai
Messages the assistant sends on an Organizer's behalf come from that Organizer's own email address, not from an address on lonzo.ai; the Organizer is the human authority for the coordination, and the opt-out mechanisms carried in the message are ours and cannot be removed by them (Section 7). Mail from an address on lonzo.ai is mail the Service sent about an account of its own — which, as a Participant, you do not have.