Data Processing Agreement
This Data Processing Agreement ("DPA") applies automatically — no signature required — whenever an organization ("Customer") uses ZagCal and our processing of personal data on the Customer's behalf is subject to the GDPR, the UK GDPR, or the Swiss FADP. It forms part of our Terms of Service. A countersigned copy is available on request from support@zagcal.com.
1. Roles and scope
For personal data that Customer's use of ZagCal entrusts to us — member accounts, availability data, and booking-page submissions belonging to the Customer's organization — the Customer is the controller and ZAGRAL LLC (Arizona, United States, operating ZagCal) is the processor. Where individuals use ZagCal personally, ZagCal is an independent controller and our Privacy Policy applies instead of this DPA.
2. Details of processing
- Subject matter & nature: operating the ZagCal service — mirroring busy/free availability between connected calendars, publishing booking pages, and administering the Customer's organization and subscription.
- Duration: the life of the Customer's account, plus the deletion window in §7.
- Data subjects: the Customer's organization members, and people who book time through the Customer's booking pages.
- Categories of data: account identifiers (name, email), encrypted calendar credentials/tokens, availability data (busy/free time ranges and the placeholder events we create — never event titles, guests, notes, or locations, unless a member enables the optional per-sync full-detail mode, and even then event content is copied between the member's own calendars without being stored by us), booking submissions (name, email, chosen time, any notes the booker adds, and the booker's IP address kept for abuse prevention), billing metadata (plan, subscription state — card details are handled by Stripe and never touch our systems), and limited technical/log data (such as IP addresses and request metadata) used for security, rate-limiting, and reliability.
- Frequency: continuous, for as long as the Customer uses the service.
- Special categories: none are requested or knowingly processed.
3. Our obligations as processor
- Process personal data only on the Customer's documented instructions — given through the service's settings and features — unless law requires otherwise (in which case we inform the Customer unless legally barred).
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement the technical and organizational measures in §8 (GDPR Article 32).
- Assist the Customer, insofar as reasonably possible, in fulfilling data-subject rights (access, rectification, erasure, portability, restriction, objection) — most are self-serve in the product — and with the Customer's Article 32–36 obligations.
- Notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer's data.
- Inform the Customer without delay if, in our opinion, an instruction infringes the GDPR, UK GDPR, or other applicable data-protection law.
- Make available the information reasonably necessary to demonstrate compliance with GDPR Article 28 and, with reasonable notice and no more than annually, allow audits limited to that purpose.
4. Sub-processors
The Customer grants general authorization to engage the sub-processors below. We will post changes to this list on this page at least 14 days before a new sub-processor processes Customer data; the Customer may object on reasonable data-protection grounds, and if we cannot resolve the objection the Customer may terminate and receive a pro-rated refund of prepaid fees. We engage each sub-processor under a written contract imposing data-protection obligations equivalent to those in this DPA — including the security measures in §8 — and we remain fully liable to the Customer for each sub-processor's performance of those obligations.
- Stripe, Inc. (United States) — payment processing and subscription billing.
- ZAGRAL-operated hosting infrastructure (United States) — servers on which ZagCal runs.
- Email delivery provider — transactional email sent on our behalf (booking confirmations and reminders, account and organization emails). The provider will be named here before it first processes Customer data, per the notice commitment above.
The Customer's own calendar providers (Google, Microsoft, Apple) are not our sub-processors: we access them at each member's direction, under the member's own account with that provider. The server-side Google Ads conversion signal described in the Privacy Policy concerns our own marketing attribution and involves no Customer organization data.
5. International transfers
Where the Customer's use involves a transfer of personal data subject to GDPR Chapter V to ZAGRAL LLC in the United States, the parties incorporate the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller → processor), into this DPA by reference, with: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorization, 14-day notice); Clause 11 optional language not used; Clause 17 Option 1 with Irish law governing the Clauses; Clause 18 courts of Ireland. Annex I is completed by §1–§2 and the parties' details (exporter: the Customer; importer: ZAGRAL LLC, Arizona, United States, privacy@zagcal.com); Annex I.C (competent supervisory authority) is the supervisory authority of the EEA member state in which the Customer is established or, where the Customer is not established in the EEA, the Irish Data Protection Commission; Annex II is completed by §8; Annex III is the list in §4. For UK transfers the parties adopt the UK International Data Transfer Addendum to the SCCs, and for Swiss transfers the FDPIC's recognized adaptations, in each case with the minimum changes those instruments require.
6. Data-subject requests
If a data subject contacts us directly about the Customer's data, we will refer them to the Customer and will not respond on the Customer's behalf except as self-serve product features already allow (e.g. a member exporting or deleting their own account) or as law requires.
7. Deletion and return
Members can export their data and delete their accounts self-serve at any time; deleting an account erases its personal data and tears down the placeholder events ZagCal created, with routine backups cycling out thereafter. On termination of the Customer's organization — at the Customer's choice — we return the organization's personal data (via export) or delete it, and in either case delete remaining copies on the same backup-cycling schedule, unless law requires retention.
8. Technical and organizational measures (Annex II)
- Data minimization by design: the service reads and stores busy/free time ranges, not event content — the most privacy-consequential measure we offer.
- Encryption: calendar credentials and tokens are encrypted at rest with envelope encryption under versioned, rotatable key-encryption keys; all traffic is encrypted in transit with TLS.
- Isolation and least privilege: strict organization-level isolation; access scoped to what each feature needs.
- Fail-closed operation: production refuses to start without its encryption keys and security configuration.
- Self-serve rights: in-product data export and account deletion.
- No payment-card data: card details go directly to Stripe and never transit or rest on our systems.
More detail: Security & privacy.
9. Precedence, term, and law
This DPA applies for as long as we process personal data for the Customer and prevails over the Terms for data-processing matters; the incorporated SCCs prevail over this DPA where they conflict. Except where the SCCs require otherwise, this DPA is governed by the same law as the Terms of Service. Questions: privacy@zagcal.com.