Data Processing Agreement

1. Roles and scope

For personal data that Customer's use of ZagCal entrusts to us — member accounts, availability data, and booking-page submissions belonging to the Customer's organization — the Customer is the controller and ZAGRAL LLC (Arizona, United States, operating ZagCal) is the processor. Where individuals use ZagCal personally, ZagCal is an independent controller and our Privacy Policy applies instead of this DPA.

2. Details of processing

3. Our obligations as processor

4. Sub-processors

The Customer grants general authorization to engage the sub-processors below. We will post changes to this list on this page at least 14 days before a new sub-processor processes Customer data; the Customer may object on reasonable data-protection grounds, and if we cannot resolve the objection the Customer may terminate and receive a pro-rated refund of prepaid fees. We engage each sub-processor under a written contract imposing data-protection obligations equivalent to those in this DPA — including the security measures in §8 — and we remain fully liable to the Customer for each sub-processor's performance of those obligations.

The Customer's own calendar providers (Google, Microsoft, Apple) are not our sub-processors: we access them at each member's direction, under the member's own account with that provider. The server-side Google Ads conversion signal described in the Privacy Policy concerns our own marketing attribution and involves no Customer organization data.

5. International transfers

Where the Customer's use involves a transfer of personal data subject to GDPR Chapter V to ZAGRAL LLC in the United States, the parties incorporate the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller → processor), into this DPA by reference, with: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorization, 14-day notice); Clause 11 optional language not used; Clause 17 Option 1 with Irish law governing the Clauses; Clause 18 courts of Ireland. Annex I is completed by §1–§2 and the parties' details (exporter: the Customer; importer: ZAGRAL LLC, Arizona, United States, privacy@zagcal.com); Annex I.C (competent supervisory authority) is the supervisory authority of the EEA member state in which the Customer is established or, where the Customer is not established in the EEA, the Irish Data Protection Commission; Annex II is completed by §8; Annex III is the list in §4. For UK transfers the parties adopt the UK International Data Transfer Addendum to the SCCs, and for Swiss transfers the FDPIC's recognized adaptations, in each case with the minimum changes those instruments require.

6. Data-subject requests

If a data subject contacts us directly about the Customer's data, we will refer them to the Customer and will not respond on the Customer's behalf except as self-serve product features already allow (e.g. a member exporting or deleting their own account) or as law requires.

7. Deletion and return

Members can export their data and delete their accounts self-serve at any time; deleting an account erases its personal data and tears down the placeholder events ZagCal created, with routine backups cycling out thereafter. On termination of the Customer's organization — at the Customer's choice — we return the organization's personal data (via export) or delete it, and in either case delete remaining copies on the same backup-cycling schedule, unless law requires retention.

8. Technical and organizational measures (Annex II)

More detail: Security & privacy.

9. Precedence, term, and law

This DPA applies for as long as we process personal data for the Customer and prevails over the Terms for data-processing matters; the incorporated SCCs prevail over this DPA where they conflict. Except where the SCCs require otherwise, this DPA is governed by the same law as the Terms of Service. Questions: privacy@zagcal.com.