Data Processing Addendum.
This Data Processing Addendum (the “DPA”) explains how CalGet handles the personal data you put into the platform. It applies whenever we process personal data on your behalf, and it forms part of our Terms of Service.
The short version
The sections below are the binding terms. This summary is here to help you read them — it doesn't replace them.
Your data stays yours
You decide what goes into CalGet and why. We only process it to run the service for you and to follow your instructions.
We don't sell it
We don't sell or share your data for advertising, and we don't use it to build profiles or train anything of our own.
You can see who helps
Every company that touches your data is listed on our Subprocessors page, and each one is under contract with us.
Contents
- 1. Definitions
- 2. Roles and responsibilities
- 3. Your instructions
- 4. Confidentiality
- 5. Subprocessors
- 6. Security
- 7. Data incidents
- 8. Individual rights requests
- 9. Assessments and audits
- 10. International transfers
- 11. Return and deletion of data
- 12. Deidentified data
- 13. Additional CCPA terms
- 14. Liability
- 15. Term and relationship with the Agreement
- 16. Governing law
- — Annex A — Details of processing
- — Annex B — Security measures
- — Annex C — Jurisdiction-specific terms
This DPA is between CalGet LLC (“CalGet”, “we”, “us”) and the customer that has agreed to our Terms of Service or another signed agreement with us (“Customer”, “you”). It takes effect on the date you first accept those terms, and it is incorporated into them. Where this DPA and the rest of the agreement disagree about personal data, this DPA wins.
1Definitions
We've kept these to the ones the rest of the document actually relies on. Terms like controller, processor, service provider, business, data subject, personal data, process, sell and share carry the meaning given to them by the applicable Data Protection Laws.
- Agreement — our Terms of Service, or another written agreement covering your use of CalGet.
- Customer Personal Data — personal data you upload, submit or otherwise make available to CalGet, which we process on your behalf under the Agreement.
- Data Protection Laws — the privacy and data security laws that apply to the processing, including the CCPA and other US state privacy laws; the GDPR, UK GDPR and Swiss FADP; Canadian federal and provincial privacy laws such as PIPEDA and Quebec's Law 25; Brazil's LGPD; and Australia's Privacy Act 1988.
- Europe — the European Economic Area, Switzerland and the United Kingdom.
- SCCs — the European Commission's Standard Contractual Clauses (Decision 2021/914, Module Two: controller to processor), together with the UK International Data Transfer Addendum where UK data is involved.
- Services — the CalGet event pages, calendar and RSVP features and everything else we provide under the Agreement.
- Subprocessor — a third party we engage to process Customer Personal Data on our behalf.
2Roles and responsibilities
For Customer Personal Data, you are the controller (or business) and we are the processor (or service provider). Annex A sets out what we process, why, for how long and about whom. Each of us is responsible for meeting the obligations that Data Protection Laws place on our own role.
You're responsible for how you collected the data in the first place: having a lawful basis, giving the notices and obtaining the consents that apply to you, and making sure your instructions to us are lawful. Please don't send us sensitive categories of personal data — health, biometric, financial account, government ID and similar — as the Services aren't designed to handle them.
This DPA doesn't cover situations where CalGet acts as a controller in its own right, such as managing our own account holders, billing records and website analytics. Our Privacy Policy covers that.
3Your instructions
We process Customer Personal Data only on your documented instructions. By entering into this DPA, you instruct us to process it to provide, secure and support the Services, as described in the Agreement and Annex A, as set out in any further written instructions you give us, and as otherwise permitted by Data Protection Laws.
If we think an instruction would break Data Protection Laws, we'll tell you promptly rather than carry it out. If a law requires us to process data beyond your instructions, we'll let you know first unless that law forbids it.
4Confidentiality
Access to Customer Personal Data is limited to the people who need it to run or support the Services. Everyone with access is bound by a duty of confidentiality and is trained on handling personal data appropriately.
5Subprocessors
You give us general authorization to engage subprocessors. Our current list is published on our Subprocessors page. Before a subprocessor handles Customer Personal Data, we put a written contract in place that holds them to data protection obligations at least as protective as those in this DPA. We stay responsible to you for their performance.
We'll update that page before adding or replacing a subprocessor; updating it counts as notice to you. If you have a reasonable, data-protection-related objection, tell us within 15 days of the change and we'll work with you in good faith to find a solution. If we can't, you may stop using the affected part of the Services and terminate the affected subscription under the Agreement.
6Security
We maintain appropriate technical and organizational measures to protect Customer Personal Data against unauthorized access, disclosure, alteration, loss and destruction. Annex B describes the measures currently in place. We may change them as technology and threats change, but not in a way that materially reduces the overall level of protection.
Your side matters too: keeping account credentials safe, managing who on your team has access, and deciding what personal data you upload in the first place are your responsibility.
7Data incidents
A data incident is a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data on systems we control. Unsuccessful attempts that don't compromise data — blocked login attempts, port scans, pings and similar — aren't data incidents.
If a data incident happens, we'll notify you without undue delay after becoming aware of it, and no later than 72 hours where the GDPR applies. Our notice will describe what we know, what we're doing about it, and what we recommend you do. We'll take reasonable steps to contain the incident and limit harm, and we'll assist you with your own notification duties.
Notifying you isn't an admission of fault. Deciding whether you need to notify regulators or individuals, and doing so, is your call as the controller.
8Individual rights requests
The Services give you tools to access, correct, export and delete the personal data in your account, so in most cases you can handle a request yourself. Where you can't, we'll give you reasonable assistance, taking into account the nature of the processing and what's available to us.
If someone contacts us directly about data we hold on your behalf, we won't respond substantively. We'll point them to you and let you know, unless the law says otherwise.
9Assessments and audits
On reasonable request, we'll give you the information you need to show that we're meeting our obligations under this DPA, and reasonable help with data protection impact assessments and any consultation with a supervisory authority that you're required to undertake.
You may audit our compliance no more than once a year, and additionally after a data incident that affected your data or where a supervisory authority requires it. Audits happen during business hours, on at least 30 days' notice, under confidentiality, and in a way that doesn't disrupt the Services or expose another customer's data. We may satisfy an audit request by providing a current third-party assessment or security documentation covering the same ground.
10International transfers
CalGet operates from the United States, and Customer Personal Data may be processed there and in any other country where we or our subprocessors operate. We make those transfers in line with Data Protection Laws.
Europe, the UK and Switzerland
Where we receive personal data protected by European Data Protection Laws and no adequacy decision covers the transfer, the SCCs apply and are incorporated into this DPA. Module Two applies, with the docking clause (Clause 7) and general authorization for subprocessors under Clause 9(a) — the notice period being the 15 days set out in section 5. Annex A completes Annex I of the SCCs and Annex B completes Annex II. For UK data, the UK Addendum applies alongside the SCCs. For Swiss data, references to the GDPR are read as references to the Swiss FADP, and the Swiss Federal Data Protection and Information Commissioner is the supervisory authority.
Other regions
For Canadian, Brazilian and Australian personal data, the jurisdiction-specific terms in Annex C apply. If a transfer mechanism we rely on stops being valid, we'll adopt a lawful alternative rather than continue the transfer without one.
11Return and deletion of data
You can export or delete your data at any time while your account is active. When the Agreement ends, we delete Customer Personal Data from our production systems within 90 days, and from backups as those backups age out on their normal schedule. We'll delete it sooner on your written request, and we'll confirm deletion if you ask.
We may keep data for longer where the law requires it, in which case we keep it only for that purpose and continue to protect it under this DPA.
12Deidentified data
We may create aggregated or deidentified data — usage counts, performance metrics and similar — and use it to operate and improve the Services. Where we do, we maintain it in deidentified form, don't attempt to reidentify it, and don't publish or share anything that identifies you, your guests or your events.
13Additional CCPA terms
Where the CCPA applies, we act as your service provider and we:
- don't sell or share Customer Personal Data, as those terms are defined by the CCPA;
- don't retain, use or disclose it except to provide the Services and for the business purposes set out in the Agreement and this DPA, or as the CCPA otherwise permits;
- don't use it outside our direct business relationship with you;
- don't combine it with personal information from other sources, except as the CCPA permits for service providers;
- provide the level of privacy protection the CCPA requires, and tell you promptly if we determine we can no longer do so; and
- let you take reasonable steps to confirm we're using the data consistently with your obligations, and to stop and remediate unauthorized use.
14Liability
Each party's liability under this DPA, including under the SCCs, is subject to the exclusions and limits on liability in the Agreement. Nothing here limits any individual's rights under Data Protection Laws.
15Term and relationship with the Agreement
This DPA takes effect when you accept the Agreement and continues for as long as we process Customer Personal Data on your behalf. It replaces any earlier data processing agreement between us for the Services.
If there's a conflict, the order of precedence is: the SCCs, then this DPA, then the rest of the Agreement. We may update this DPA to reflect changes in law or our practices; if a change materially affects your rights, we'll give you reasonable notice before it takes effect.
16Governing law
This DPA is governed by the law and jurisdiction set out in the Agreement, except where Data Protection Laws require the law of another jurisdiction to apply.
Annexes
Annex A — Details of processing
Subject matter and nature
Hosting and running the CalGet Services: creating and publishing event pages, collecting RSVPs and registrations, sending event and account email, and supporting you when you contact us. Processing includes collecting, storing, organizing, using, disclosing to subprocessors, and deleting.
Purpose
- Providing, maintaining and securing the Services.
- Sending event-related email such as confirmations, reminders and updates.
- Applying the settings and options you choose in your account.
- Responding to your support requests.
Categories of data subjects
- Account users — you and the people on your team with access to your CalGet account.
- Guests — people who view your event pages, RSVP, register or subscribe to your calendar.
Categories of personal data
- Account users — name, email address, password credentials, organization and role, billing contact details.
- Guests — name, email address, RSVP status and responses to any questions you add to your form, and technical data such as IP address, device and browser information and timestamps.
We don't ask for special category or sensitive personal data, and the Services aren't designed to process it.
Frequency and duration
Processing is continuous for as long as the Agreement is in place, and ends with deletion as described in section 11.
Subprocessors
The current list is published on our Subprocessors page.
Annex B — Security measures
The measures below are current as of the date at the top of this page and may be updated as long as protection isn't materially reduced.
- Encryption — data encrypted in transit with TLS, and at rest on our servers and backups.
- Access control — least-privilege access to production systems, individual accounts, multi-factor authentication for administrative access, and access removed promptly when someone leaves.
- Passwords — account passwords stored only as salted hashes, never in readable form.
- Network protection — firewalling, DDoS and bot mitigation, and rate limiting at the edge.
- Segregation — customer data logically separated so one account can't reach another's data.
- Backups and recovery — encrypted backups taken on a regular schedule and restore procedures tested periodically.
- Logging and monitoring — access and system logs retained and monitored for unusual activity.
- Secure development — code review, dependency and vulnerability monitoring, and prompt patching of the platform and its dependencies.
- Vendor management — subprocessors reviewed before engagement and bound by written data protection terms.
- People — confidentiality obligations for everyone with access, and security and privacy training.
- Incident response — a documented process for detecting, investigating, containing and notifying data incidents.
Annex C — Jurisdiction-specific terms
These terms apply on top of the rest of the DPA where the relevant law applies. If they conflict with anything above, these terms win for that jurisdiction.
Europe and the UK
- Supervisory authority. For the SCCs, the competent authority is the one for the EU member state where you're established. If you're not established in the EU, it's the Irish Data Protection Commission. For Swiss data it's the FDPIC, and for UK data the Information Commissioner's Office.
- Government access requests. We don't give government or law enforcement agencies voluntary access to customer accounts or data. If we receive a legally binding demand for data we hold on your behalf, we'll review whether it's valid, tell the agency we're a processor and direct them to you, notify you so you can seek a protective order, and disclose no more than the request reasonably requires. We'll do this unless the law forbids us from telling you — in which case we'll seek a waiver — or unless there's an urgent risk of serious harm to someone.
Canada
Where personal data about people in Canada is transferred outside the country, you confirm you've given them appropriate notice, and we agree the measures in this DPA are designed to give that data protection comparable to what it would have in Canada. For Quebec, you confirm you've carried out the privacy impact assessment that Law 25 requires for such transfers.
Brazil
Where the LGPD applies and no adequacy decision or other approved mechanism covers a transfer out of Brazil, the Brazilian standard contractual clauses approved by the ANPD are incorporated into this DPA and take precedence over conflicting terms for those transfers.
Australia
Where the Privacy Act 1988 (Cth) applies, we may process personal data outside Australia in line with this DPA and the Australian Privacy Principles.
Questions about this DPA?
This DPA applies automatically when you accept our Terms — there's nothing to sign. If you have questions about it or how we handle your data, email us at [email protected]. You can also read our Privacy Policy and Subprocessors page.