Data Processing Agreement

    Last updated: 23 September 2026

    If you offer appointments, run scheduling polls or publish schedules with Calenytics, you process other people's data — and we do so on your behalf. This agreement under Art. 28 GDPR governs how. It applies automatically when you accept our Terms of Service; no separate signature is needed.

    1. Parties and applicability

    1.1 This agreement applies between the Calenytics user as controller (“customer”) and Seisl Benjamin, Am Grünen Prater 11, 1020 Vienna, Austria as processor (“processor” or “we”).

    1.2 It becomes part of the contract when the Terms of Service are accepted and applies for as long as the processor processes personal data for the customer. On data protection matters it takes precedence over the Terms of Service. A signed copy is available on request.

    1.3 It does not cover data for which we are ourselves the controller — such as the customer's account and billing data, server logs or data used to prevent abuse. Our Privacy Policy applies to that data.

    2. Subject matter, nature and purpose of processing

    We provide the customer with a platform for appointment booking, scheduling polls and publishing schedules. In doing so we store the data, make it available to the customer and — where the customer sets this up — to third parties through public pages and ICS feeds, send emails, protect public pages against abuse, generate access statistics and delete data. Any purpose other than providing the services is excluded.

    3. Types of data

    • Bookings: name, email address, optional message, selected time, time zone, location, status, management token
    • Scheduling polls: name, optional or required email address, answers per proposed time, optional note, time of the answer, check value of the personal link
    • Calendar subscriptions: content entered by the customer, which may include personal data (e.g. names of people involved)
    • Access statistics: non-reversible check values derived from IP address, user agent and calendar identifier, category of calendar app, time and number of requests
    • Communication data: recipient address, content and delivery status of emails sent

    Special categories of personal data (Art. 9 GDPR) are not intended. The customer ensures that such data is not collected through free-text fields unless there is a legal basis for it.

    4. Data subjects

    Guests who book an appointment; participants in scheduling polls; subscribers to published schedules; persons named by the customer in calendar subscriptions.

    5. Instructions

    5.1 We process the data only on the customer's documented instructions. Instructions are this agreement, the Terms of Service and the settings the customer makes in the web app; further instructions are given by email.

    5.2 If we are legally required to process data otherwise, we will inform the customer beforehand unless the law prohibits this.

    5.3 If we consider an instruction unlawful, we will inform the customer without delay and may suspend it until confirmed.

    6. Confidentiality

    Everyone at our end with access to the data is bound to confidentiality (data secrecy under § 6 Austrian Data Protection Act) and accesses it only as far as necessary for their task — for example to fix errors or, at the customer's request, in support.

    7. Technical and organisational measures

    In particular we take the following measures under Art. 32 GDPR:

    • Encryption of all connections with TLS; encryption of the database at rest at the database provider
    • Access control at database level (row level security): every record is restricted to its owner; public endpoints only return the fields intended for them
    • Passwords stored as hashes only; service keys used server-side only
    • Random, rotatable tokens for public links and feeds; personal answer links stored only as a non-reversible check value
    • Pseudonymisation of access statistics by secret-based check values; no storage of IP address or user agent
    • Bot protection on public pages
    • Access to infrastructure administration interfaces only for authorised persons
    • Regular backups at the database provider; recoverability after incidents
    • Data minimisation: required fields limited to what is necessary, deletion via foreign-key cascades on account deletion
    • Review of the measures whenever the application or infrastructure changes

    We may further develop these measures as long as the level of protection is not reduced.

    8. Sub-processors

    8.1 The customer authorises the use of the following sub-processors:

    Sub-processorServiceLocationSafeguards
    Supabase Inc., USADatabase, authentication, server functionsEU data centre; access from the USA possibleStandard contractual clauses
    Hosting provider of our serversRunning the web appEUDPA under Art. 28 GDPR
    Zoho Corporation B.V. (ZeptoMail), NetherlandsEmail deliveryEUDPA under Art. 28 GDPR
    Cloudflare, Inc., USABot protection of public pages (Turnstile)worldwideEU-US Data Privacy Framework, standard contractual clauses

    8.2 We contractually bind sub-processors to an equivalent level of data protection. We announce any new or replaced sub-processor at least 30 days in advance by email. The customer may object on important data protection grounds; if we cannot resolve the objection, the customer may terminate the agreement as of the date of the change.

    8.3 Services we use as independent services, such as telecommunications, and applications the customer connects through the MCP interface are not sub-processing.

    9. Transfers to third countries

    Transfers to countries outside the EEA take place only under the conditions of Art. 44 et seq. GDPR — on the basis of an adequacy decision (such as the EU-US Data Privacy Framework) or the European Commission's standard contractual clauses together with supplementary measures.

    10. Assisting the customer

    10.1 The web app lets the customer view, correct and delete data themselves; we provide an export on request. Beyond that, we assist the customer in fulfilling data subject rights (Art. 15 to 22 GDPR). If a data subject contacts us directly, we forward the request to the customer without delay and do not respond without the customer's instruction.

    10.2 We assist the customer as necessary with security, notification of personal data breaches, data protection impact assessments and prior consultations (Art. 32 to 36 GDPR).

    11. Personal data breaches

    We inform the customer without undue delay, where possible within 48 hours, after becoming aware of a breach affecting their data. As far as known, the notification includes the nature of the breach, the categories and approximate number of data subjects concerned, likely consequences and measures taken and proposed. We immediately take the necessary measures to secure the data and mitigate adverse effects.

    12. Deletion and return

    12.1 When the customer deletes individual data or their account, the data concerned is deleted from the database immediately; in the database provider's backups it is removed when these are overwritten in the regular cycle.

    12.2 Before deletion we provide the customer with an export of their data on request. If the agreement ends in another way, we will provide the data on request and delete it afterwards unless a statutory retention obligation applies.

    13. Evidence and audits

    On request we provide the customer with the information necessary to demonstrate compliance with this agreement, in particular a current description of the measures and evidence from our sub-processors. In addition, audits by the customer or an auditor bound to confidentiality are possible with reasonable notice, during normal business hours and without disrupting operations; the customer bears the costs unless the audit reveals a material breach.

    14. Customer obligations

    The customer is responsible for the lawfulness of the processing. They inform data subjects (Art. 13 and 14 GDPR), collect only data for which they have a legal basis, share secret links only deliberately and notify us without delay of any errors or irregularities they find when reviewing the results.

    15. Liability and final provisions

    15.1 Liability towards data subjects is governed by Art. 82 GDPR. Between the parties, the liability provisions of the Terms of Service apply.

    15.2 We notify the customer of changes to this agreement in the same way as changes to the Terms of Service. The final provisions of the Terms of Service apply otherwise. In case of discrepancies between the German and English versions, the German version prevails.