Data processing agreement
Where you use Calenday to take bookings, you are the controller of your invitees’ data and Calenday is your processor. These are the terms of that relationship.
1. Roles
Where you use Calenday to receive bookings from your own clients, you are the controller of the personal data of those invitees, and {{PUBLISHER_LEGAL_NAME}} acts as your processor within the meaning of Article 28 of the GDPR.
For the data of your own account — your email address, your name, your purchase — the publisher is the controller, and the privacy policy applies.
2. Subject matter and duration
The publisher processes personal data solely to provide the Calenday service: computing availability, recording bookings, sending confirmations and reminders, and, where you enable it, processing payment for a booking.
Processing lasts for as long as your account is active, and ends with its deletion.
3. Categories of data and data subjects
Data subjects: the invitees who book an appointment with you, and the members you invite into your organisations.
Categories of data: name, email address, time zone, the answers to the questions you configure on your booking page, booking history, and, where applicable, the payment identifier issued by Stripe or PayPal.
You undertake not to configure booking-page questions that collect special categories of data within the meaning of Article 9 of the GDPR unless you have your own legal basis for doing so and have satisfied yourself that Calenday's technical measures are adequate for that purpose.
4. Instructions
The publisher processes personal data only on your documented instructions, which consist of these terms and your use of the service's functions. The publisher informs you if, in its view, an instruction infringes data protection law.
5. Confidentiality
Any person authorised to process the data is bound by an appropriate confidentiality undertaking.
6. Security measures
- Encryption in transit (TLS) and encryption at rest of third-party tokens with AES-GCM.
- Row-level security on every database table, isolating data by organisation at the database layer.
- Optional TOTP two-factor authentication on accounts.
- Rate limiting on public booking endpoints.
- Signature verification and de-duplication of payment webhooks.
- Backups of the database, retained for BACKUP RETENTION.
The publisher holds no SOC 2, ISO 27001 or HIPAA certification, and does not represent otherwise.
7. Sub-processors
You give general authorisation to the use of the following sub-processors:
- {{DATABASE_PROVIDER}} — database, authentication, storage — DATA REGION
- {{HOSTING_PROVIDER}} — application hosting — HOSTING REGION
- AcumbaMail — transactional email — European Union
- Stripe — payment processing — where you enable payment collection
- PayPal — payment processing — where you enable payment collection
- Google, Microsoft, Zoom — only where you have connected the corresponding integration
The publisher informs you of any planned addition or replacement of a sub-processor at least thirty days in advance. You may object on reasonable grounds relating to data protection; where no solution is found, you may terminate your use of the service.
8. International transfers
Where a sub-processor processes data outside the European Economic Area, the transfer is governed by the European Commission's standard contractual clauses or by an adequacy decision.
9. Assistance
The publisher assists you, taking into account the nature of the processing:
- in responding to requests from data subjects exercising their rights;
- in carrying out a data protection impact assessment, where required;
- in notifying a personal data breach.
The publisher notifies you without undue delay, and at the latest within forty-eight hours of becoming aware of a personal data breach affecting your data, together with the information needed for you to make your own notification.
10. Fate of the data
On deletion of your account, the publisher deletes the personal data processed on your behalf within thirty days, save where retention is required by law.
Before deletion, you may export your contacts and your booking history to CSV from your dashboard at any time.
11. Audit
The publisher makes available to you the information needed to demonstrate compliance with the obligations in this agreement, and allows audits carried out by you or by an auditor you appoint, at reasonable frequency and after reasonable notice.
12. Self-hosting
Where you deploy Calenday on your own infrastructure, no processing is carried out by the publisher on your behalf and this agreement does not apply: you are the sole controller and sole operator of the data concerned.