Data Processing Agreement
This Data Processing Agreement ("DPA") supplements the CALENDARguardian™ EULA or other agreement between the customer ("Controller" or "Customer") and DealDoctor PLLC ("Processor" or "DealDoctor") when DealDoctor processes Personal Data on Customer's behalf through CalendarGuardian.
1. Scope and roles
Customer is Controller of Personal Data contained in or associated with calendars and optionally authorized mailboxes connected by Customer, except where Customer acts as a processor for another controller. DealDoctor acts as Processor to the extent it processes such Personal Data to provide CalendarGuardian. Each party will comply with applicable data-protection law. DealDoctor separately acts as controller for its own account administration, fraud prevention, billing and statutory obligations, as described in the Privacy Policy. Customer determines the lawful basis, notices and authority for its instructions.
2. Processing instructions and purpose
DealDoctor will process Personal Data only on Customer's documented instructions as reflected in the agreement, this DPA, product configuration, and Customer's use of CalendarGuardian, unless law requires otherwise. DealDoctor will inform Customer before legally required processing unless prohibited, and promptly flag instructions it considers unlawful. Processing is limited to authentication, calendar and email-invitation protection, scoring, user-directed or configured actions, review/restoration functionality, support, security, billing administration, and legal compliance.
3. Data subjects and data types
| Categories of data subjects | Authorized Users; calendar organizers; attendees; employees; contractors; customers; vendors; candidates; and other persons whose information appears in calendar events or authorized invitation emails. |
|---|---|
| Types of Personal Data | Names, email addresses, account identifiers, organization information, calendar event subjects and bodies, event times, locations, attendee information, meeting links, recurrence information, response status, organizer/domain information, protection rules, mailbox and message identifiers, invitation-email subjects and senders, transient message bodies and calendar attachments, encrypted provider credentials, approval fingerprints, email-action records, and service/security records. |
| Processing operations | Collection through authorized APIs; retrieval; analysis and scoring; storage of rules and flagged/reported event records; modification or deletion of calendar events when authorized; optional mailbox retrieval and invitation-only moves to Trash or Deleted Items under separate cleanup consent; authentication; logging; support; security; and deletion. |
| Duration | For the term of the service and applicable retention periods described in the Privacy Policy, subject to earlier deletion where available. |
4. Confidentiality and security
DealDoctor will ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations. DealDoctor will maintain appropriate technical and organizational measures proportionate to the service, including encrypted transport, protected credential storage, least-privilege permissions, access control, application-secret management, and security monitoring appropriate to the deployed environment.
5. Subprocessors
Customer authorizes the subprocessors listed at CalendarGuardian Subprocessors. DealDoctor will require subprocessors that process Personal Data on its behalf to be subject to data-protection obligations appropriate to their services. DealDoctor will give affected Customers advance notice of intended additions or replacements, allowing reasonable data-protection objections before engagement. Subprocessors must receive equivalent applicable processing obligations by written contract. DealDoctor remains responsible for their performance of those obligations.
6. Data-subject requests
Taking into account the nature of processing, DealDoctor will provide reasonable assistance to Customer with requests for access, correction, deletion, restriction, portability, or objection where required by applicable law and where DealDoctor is able to act on the relevant data.
7. Security incidents
DealDoctor will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data and will provide information reasonably available to DealDoctor to assist Customer with legally required notifications. Notification does not constitute an admission of fault or liability. Taking account of the processing and available information, DealDoctor will assist Customer with security, breach duties, impact assessments and required supervisory consultation.
8. Deletion and return
Upon termination or verified request, DealDoctor will, at Customer's choice, return or delete Personal Data and delete remaining copies unless applicable law requires retention, subject to ordinary-course backups, legal retention obligations, and data that has already been deleted or is no longer reasonably identifiable. CalendarGuardian provides account-data deletion functionality as described at Data Deletion.
9. International transfers
Where Personal Data is transferred from the EEA, United Kingdom, or Switzerland to a country not recognized as providing adequate protection, the parties will use an applicable lawful transfer mechanism, including Standard Contractual Clauses where required. Any required transfer instrument and its annexes must be completed for the relevant parties and transfers before that processing begins. Publication of this DPA does not itself execute Standard Contractual Clauses. Business customers can request transfer documentation from privacy@dealdoctor.pro.
10. Audits and information
Upon reasonable written request, DealDoctor will provide information reasonably necessary to demonstrate compliance with this DPA. If legally required and such information is insufficient, Customer may conduct or commission an audit at its expense on reasonable notice, subject to reasonable confidentiality, security, and non-disruption arrangements that do not prevent legally required audits or inspections.
11. Precedence and law
If this DPA conflicts with the EULA or Order concerning Personal Data processing, this DPA controls. Otherwise, the governing-law and dispute provisions of the EULA or applicable agreement apply.