Data Processing Agreement
These data processing terms govern the processing of personal data where Calendra processes data on behalf of a business customer or platform tenant.
Important note
1. Parties and roles
The Calendra service provider is Hospit, David Mirc s.p., Cesta Toneta Tomšiča 78a, 4270 Jesenice, Slovenia.
A tenant using Calendra for its own customers, guests, employees or business processes generally acts as controller. Calendra generally acts as processor for such processing.
For data where Calendra independently determines the purpose and means of processing, such as subscription billing, support, website security and communication with prospects, Calendra acts as controller as described in the Privacy Policy.
2. Subject matter, purpose and duration
The subject matter of processing is the provision of the Calendra platform, including booking, calendar, notifications, billing, invoices, wallet/entitlements, courses, messages, integrations and support.
Processing lasts while the tenant uses the service and after termination for as long as needed for lawful account closure, export, deletion, anonymisation, backups, claims or legal obligations.
3. Categories of data subjects and data
- tenants and their users,
- guests and tenant customers,
- participants in appointments, courses, events or programmes,
- payers, invoice recipients and contact persons,
- appointment, order, invoice, payment, entitlement, message, delivery log, file and integration data.
4. Calendra obligations as processor
- process personal data only on documented tenant instructions, unless the law requires otherwise,
- ensure that persons with access are bound by confidentiality,
- apply appropriate technical and organisational measures,
- assist the tenant with data subject requests where reasonably possible,
- assist with security incidents and data protection obligations where applicable,
- after service termination, delete, anonymise or return data according to settings, technical possibilities and legal obligations.
5. Subprocessors
The tenant gives general authorisation to use subprocessors required to provide the platform, infrastructure, payments, communications, mobile features and enabled integrations.
The current subprocessor list is published publicly and may be updated.
6. Security, incidents and transfers
Calendra applies appropriate technical and organisational measures based on the nature of the service, risks and available technologies. A public summary is published on the Security page.
If Calendra detects a personal data breach concerning data processed on behalf of the tenant, Calendra will notify the tenant without undue delay once the incident is confirmed and basic information is available.
Transfers outside the EEA are performed only where appropriate safeguards or another valid legal basis are in place.
7. Audits, information and changes
Calendra will provide the tenant with reasonably necessary information to demonstrate compliance with these terms, taking into account security, confidentiality and protection of other tenants.
These terms may be updated. If a change materially affects personal data processing, Calendra will notify tenants in an appropriate way.