Data Processing Agreement
This Data Processing Agreement ("DPA") supplements the CALENDARguardian™ EULA or other agreement between the customer ("Controller" or "Customer") and DealDoctor PLLC ("Processor" or "DealDoctor") when DealDoctor processes Personal Data on Customer's behalf through CalendarGuardian.
1. Scope and roles
Customer is Controller of Personal Data contained in or associated with calendars connected by Customer, except where Customer acts as a processor for another controller. DealDoctor acts as Processor to the extent it processes such Personal Data to provide CalendarGuardian. Each party will comply with applicable data-protection law.
2. Processing instructions and purpose
DealDoctor will process Personal Data only on Customer's documented instructions as reflected in the agreement, this DPA, product configuration, and Customer's use of CalendarGuardian, unless law requires otherwise. Processing is limited to authentication, calendar protection, scoring, user-directed or configured actions, review/restoration functionality, support, security, billing administration, and legal compliance.
3. Data subjects and data types
| Categories of data subjects | Authorized Users; calendar organizers; attendees; employees; contractors; customers; vendors; candidates; and other persons whose information appears in calendar events. |
|---|---|
| Types of Personal Data | Names, email addresses, account identifiers, organization information, calendar event subjects and bodies, event times, locations, attendee information, meeting links, recurrence information, response status, organizer/domain information, protection rules, and service/security records. |
| Processing operations | Collection through authorized APIs; retrieval; analysis and scoring; storage of rules and flagged/reported event records; modification or deletion of calendar events when authorized; authentication; logging; support; security; and deletion. |
| Duration | For the term of the service and applicable retention periods described in the Privacy Policy, subject to earlier deletion where available. |
4. Confidentiality and security
DealDoctor will ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations. DealDoctor will maintain appropriate technical and organizational measures proportionate to the service, including encrypted transport, protected credential storage, least-privilege permissions, access control, application-secret management, and security monitoring appropriate to the deployed environment.
5. Subprocessors
Customer authorizes the subprocessors listed at CalendarGuardian Subprocessors. DealDoctor will require subprocessors that process Personal Data on its behalf to be subject to data-protection obligations appropriate to their services. DealDoctor will update the public list when material subprocessors are added or replaced.
6. Data-subject requests
Taking into account the nature of processing, DealDoctor will provide reasonable assistance to Customer with requests for access, correction, deletion, restriction, portability, or objection where required by applicable law and where DealDoctor is able to act on the relevant data.
7. Security incidents
DealDoctor will notify Customer without undue delay after becoming aware of a confirmed Personal Data breach affecting Customer Personal Data and will provide information reasonably available to DealDoctor to assist Customer with legally required notifications. Notification does not constitute an admission of fault or liability.
8. Deletion and return
Upon termination or verified request, DealDoctor will delete or return Personal Data as required by the agreement and applicable law, subject to ordinary-course backups, legal retention obligations, and data that has already been deleted or is no longer reasonably identifiable. CalendarGuardian provides account-data deletion functionality as described at Data Deletion.
9. International transfers
Where Personal Data is transferred from the EEA, United Kingdom, or Switzerland to a country not recognized as providing adequate protection, the parties will use an applicable lawful transfer mechanism, including Standard Contractual Clauses where required. Customer authorizes DealDoctor to implement the applicable controller-to-processor or processor-to-processor modules as appropriate to the parties' roles.
10. Audits and information
Upon reasonable written request no more than once annually, DealDoctor will provide information reasonably necessary to demonstrate compliance with this DPA. If legally required and such information is insufficient, Customer may conduct or commission an audit at its expense on reasonable notice, subject to confidentiality, security, and non-disruption requirements.
11. Precedence and law
If this DPA conflicts with the EULA or Order concerning Personal Data processing, this DPA controls. Otherwise, the governing-law and dispute provisions of the EULA or applicable agreement apply.