Skip to content

DPA template

Use this when you run a calit deployment on someone else’s behalf: an agency hosting it for a client, or an IT team hosting it for another company. The client is the controller; you are the processor. If you run calit for yourself, you do not need a DPA with yourself; see the operator guide instead.


Between [client name and address] (“Controller”) and [your name and address] (“Processor”).

The Processor hosts and operates a calit scheduling service at [URL] for the Controller, for the term of [main agreement].

Hosting, storing and transmitting booking data so the Controller’s users can offer bookable meeting times, and sending the related email and notifications.

As listed in the Controller’s records of processing: invitees, invitees’ guests, and the Controller’s own account holders.

Special categories of data (Art. 9): [none expected / list]. The Controller is responsible for not asking for such data in custom booking fields unless it has a lawful basis.

The Processor will:

  1. process personal data only on the Controller’s documented instructions;
  2. ensure that people with access to the data are bound by confidentiality;
  3. apply the security measures in Annex 1;
  4. engage sub-processors only as listed in Annex 2, and inform the Controller of any change [n] days in advance;
  5. help the Controller answer data subject requests. The software provides self-service download and erasure on each booking’s manage link, and export and deletion for account holders; requests outside those are handled by the Processor within [n] days;
  6. notify the Controller of a personal data breach without undue delay and within [n] hours of becoming aware of it (see the breach checklist);
  7. configure the retention window the Controller sets: [n days after the meeting ends / none];
  8. at the end of the service, delete or return all personal data as the Controller chooses, and delete existing copies, including backups within [n] days;
  9. make available the information needed to demonstrate compliance, and allow audits [terms].

Erasure in the software cannot reach copies that have left the server: delivered email, messages already sent to notification channels, calendar invites in recipients’ calendars, and Google’s ~30-day trash for deleted events. Account deletion does not revoke a Google authorisation; the account holder does that in their Google account.

  • Hosting location: [operator]
  • Encryption in transit: TLS [details]
  • Encryption at rest: application-level for OAuth tokens and notification-channel URLs; disk or database encryption [details]
  • Access control to servers and database: [details]
  • Backups and their retention: [details]
  • Logging: PRIVACY and audit log lines kept for [period]

See the sub-processor list: [attach the completed table].

Signatures: [Controller] [Processor] [date]