DPA template
Use this when you run a calit deployment on someone else’s behalf: an agency hosting it for a client, or an IT team hosting it for another company. The client is the controller; you are the processor. If you run calit for yourself, you do not need a DPA with yourself; see the operator guide instead.
Data processing agreement
Section titled “Data processing agreement”Between [client name and address] (“Controller”) and [your name and address] (“Processor”).
1. Subject matter and duration
Section titled “1. Subject matter and duration”The Processor hosts and operates a calit scheduling service at [URL] for the Controller, for the term of [main agreement].
2. Nature and purpose of processing
Section titled “2. Nature and purpose of processing”Hosting, storing and transmitting booking data so the Controller’s users can offer bookable meeting times, and sending the related email and notifications.
3. Categories of data subjects and data
Section titled “3. Categories of data subjects and data”As listed in the Controller’s records of processing: invitees, invitees’ guests, and the Controller’s own account holders.
Special categories of data (Art. 9): [none expected / list]. The Controller is responsible for not asking for such data in custom booking fields unless it has a lawful basis.
4. Processor obligations
Section titled “4. Processor obligations”The Processor will:
- process personal data only on the Controller’s documented instructions;
- ensure that people with access to the data are bound by confidentiality;
- apply the security measures in Annex 1;
- engage sub-processors only as listed in Annex 2, and inform the Controller of any change [n] days in advance;
- help the Controller answer data subject requests. The software provides self-service download and erasure on each booking’s manage link, and export and deletion for account holders; requests outside those are handled by the Processor within [n] days;
- notify the Controller of a personal data breach without undue delay and within [n] hours of becoming aware of it (see the breach checklist);
- configure the retention window the Controller sets: [n days after the meeting ends / none];
- at the end of the service, delete or return all personal data as the Controller chooses, and delete existing copies, including backups within [n] days;
- make available the information needed to demonstrate compliance, and allow audits [terms].
5. Limits the Controller accepts
Section titled “5. Limits the Controller accepts”Erasure in the software cannot reach copies that have left the server: delivered email, messages already sent to notification channels, calendar invites in recipients’ calendars, and Google’s ~30-day trash for deleted events. Account deletion does not revoke a Google authorisation; the account holder does that in their Google account.
Annex 1: Security measures
Section titled “Annex 1: Security measures”- Hosting location: [operator]
- Encryption in transit: TLS [details]
- Encryption at rest: application-level for OAuth tokens and notification-channel URLs; disk or database encryption [details]
- Access control to servers and database: [details]
- Backups and their retention: [details]
- Logging:
PRIVACYandauditlog lines kept for [period]
Annex 2: Sub-processors
Section titled “Annex 2: Sub-processors”See the sub-processor list: [attach the completed table].
Signatures: [Controller] [Processor] [date]