Data Processing Agreement
How we process personal data on your behalf, and the commitments that come with it
This Data Processing Agreement (the "DPA") is part of the Terms of Service between Calenzy Pte. Ltd. ("Calenzy") and the customer that holds a Calenzy account (the "Customer"). It applies whenever Calenzy processes personal data on the Customer's behalf while providing the Services: the personal data of the Customer's own clients, guests, contacts and correspondents that the Customer records in the dashboard, collects through its booking pages, menus, websites and reservation flows, sends messages to, or keeps in mailboxes and hosting provided by Calenzy ("Customer Data").
It is written to meet article 28 of the EU General Data Protection Regulation ("GDPR") and the obligations of a data intermediary under Singapore's Personal Data Protection Act ("PDPA"). It applies automatically to every Customer; no signature is needed. A Customer that needs a signed copy can ask dpo@calenzy.com.
Last updated: 5 September 2026. The English text governs; the French version is a translation for convenience.
Contents
- Roles and scope
- Instructions
- Confidentiality
- Security
- Subprocessors
- Assistance
- Personal data breaches
- Deletion and return
- Information and audits
- International transfers
- Term, liability and precedence
- Annex I: description of the processing
- Annex II: technical and organisational measures
- Annex III: subprocessors
1. Roles and scope
For Customer Data, the Customer is the controller (under the PDPA, the organisation responsible) and Calenzy is the processor (under the PDPA, a data intermediary). The Customer decides why and how Customer Data is processed and is responsible for its lawfulness, for the notices it gives to the people concerned and for their rights. Calenzy processes Customer Data only to provide the Services, as described in Annex I.
For the data of the Customer's own account and users (names, emails, billing, usage), Calenzy is the controller; the Privacy Policy applies to that data and not this DPA.
2. Instructions
Calenzy processes Customer Data only on the Customer's documented instructions. The Terms of Service, this DPA, the settings the Customer chooses in the dashboard and the actions its users take in the Services are those instructions. Calenzy will not process Customer Data for any other purpose, in particular not for its own marketing, not to profile the people concerned, and not to train artificial intelligence models. If the law that applies to Calenzy requires other processing, Calenzy informs the Customer beforehand unless the law forbids it. If Calenzy believes an instruction infringes data protection law, it tells the Customer.
3. Confidentiality
Calenzy limits access to Customer Data to the people who need it to provide, support and secure the Services. Those people are bound by confidentiality, by contract or by law. Calenzy staff open a Customer's account only for support, investigation of a problem or security, and only to the extent needed.
4. Security
Calenzy implements the technical and organisational measures in Annex II, appropriate to the risk, and reviews them as the Services and the state of the art evolve. Changes do not lower the overall level of protection.
5. Subprocessors
The Customer gives Calenzy a general authorisation to use the subprocessors listed on the subprocessors page, which is Annex III of this DPA. Calenzy binds each subprocessor by contract to data protection obligations equivalent to those in this DPA and remains responsible to the Customer for their performance.
Calenzy emails the Customer's Owner at least 30 days before adding or replacing a subprocessor that will process Customer Data. If the Customer has reasonable data protection grounds to object, it tells Calenzy within those 30 days; Calenzy then proposes a way to avoid the change for the Customer or, if none is available, the Customer may end the affected Services and receive a refund of any prepaid period not used.
6. Assistance
The Services let the Customer see, correct, export and delete Customer Data itself, which is how most requests from the people concerned are answered. If a person addresses a request to Calenzy about Customer Data, Calenzy forwards it to the Customer without answering on the merits. Calenzy assists the Customer, to the extent reasonably possible, in answering such requests, in meeting its security, breach notification and impact assessment obligations, and in consulting a supervisory authority. Assistance that goes materially beyond the Services may be charged at Calenzy's then current rates, agreed beforehand.
7. Personal data breaches
Calenzy notifies the Customer's Owner by email without undue delay, and at the latest 48 hours after becoming aware of a personal data breach affecting Customer Data. The notice describes, as far as known, the nature of the breach, the data and people concerned, the likely consequences, the measures taken or proposed, and a contact for more information; details that are not yet known follow as they become known. Calenzy does not notify authorities or the people concerned on the Customer's behalf unless the Customer asks or the law requires it.
8. Deletion and return
During the contract the Customer can download its files and export its data as described in the Terms. When the Customer's account is deleted at its request, or after the retention period for locked accounts stated in the Terms, Calenzy deletes Customer Data from its live systems within 30 days and from backups within the backup rotation period, except what Calenzy must keep by law. On request Calenzy confirms deletion in writing.
9. Information and audits
Calenzy makes available the information needed to show compliance with this DPA: this document, the Privacy Policy, the subprocessors page, Annex II, and written answers to reasonable questions. Once in any 12 month period, or after a breach affecting Customer Data, the Customer may audit Calenzy's compliance, itself or through an independent auditor bound by confidentiality, with at least 30 days' written notice, during business hours, without disrupting the Services, and at its own cost. Audit reports and certifications from Calenzy's infrastructure providers satisfy the audit for the parts they cover.
10. International transfers
Customer Data is stored in Singapore or in Paris, France, depending on the region of the Customer's account, and is accessed by Calenzy's team from Taiwan and Singapore. Some subprocessors process data in other countries as stated in Annex III.
Customers in the European Economic Area. Where Customer Data is transferred from the EEA to Calenzy in Singapore, the parties conclude the standard contractual clauses adopted by the European Commission in Decision (EU) 2021/914 of 4 June 2021 (the "SCCs"), Module Two (controller to processor), which are incorporated in this DPA by reference and available at eur-lex.europa.eu/eli/dec_impl/2021/914/oj. For the SCCs: the Customer is the data exporter and Calenzy the data importer; clause 7 (docking) applies; option 2 of clause 9 (general authorisation) applies with the 30 day period in section 5; the optional wording of clause 11 does not apply; clause 13 applies with the supervisory authority of the Customer's member state; clause 17 chooses the law of France; clause 18 chooses the courts of France; Annexes I and II of the SCCs are completed by Annexes I and II of this DPA; Annex III of the SCCs is Annex III of this DPA. Where the SCCs conflict with this DPA, the SCCs prevail. Onward transfers by Calenzy to subprocessors outside the EEA rest on the SCCs (Module Three) or on the equivalent clauses those subprocessors offer.
Customers in Switzerland and the United Kingdom. The SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner and by the UK International Data Transfer Addendum respectively.
Customers in Singapore. Calenzy transfers Customer Data outside Singapore only to recipients bound by contract to a standard of protection comparable to the PDPA, as section 26 of the PDPA requires.
11. Term, liability and precedence
This DPA lasts as long as Calenzy processes Customer Data. Each party's liability under this DPA is subject to the limitations in the Terms of Service, except where the SCCs or mandatory law provide otherwise. In case of conflict, the SCCs prevail over this DPA, and this DPA prevails over the Terms of Service for the processing of Customer Data. Calenzy may update this DPA as the law or the Services change; material changes are notified to the Customer's Owner by email at least 30 days before they take effect.
Annex I: description of the processing
Parties. Data exporter and controller: the Customer, identified by its account details, represented by its Owner. Data importer and processor: Calenzy Pte. Ltd., 160 Robinson Road, Singapore 068914, contact dpo@calenzy.com, Data Protection Officer Jerome Seidita, representative in the EU Marine Larmier, 11 avenue des Moulins, 06670 Saint-Martin-du-Var, France.
Subject matter and purpose. Provision of the Calenzy Services to the Customer: appointment and booking management, client records, invoicing and quotes, email and SMS messaging, digital menus, website building and hosting, file storage, mailboxes, domain names and hosting, analytics of the Customer's pages, AI assisted content, and the related support.
Nature. Collection through the Customer's pages, storage, organisation, retrieval, display, transmission (emails, SMS, notifications), transfer to subprocessors needed for a feature, backup, and deletion.
Duration. The life of the Customer's account plus the retention period for locked accounts in the Terms, then deletion.
People concerned. The Customer's clients, guests, prospects and contacts; visitors of the Customer's pages; the Customer's suppliers and correspondents where invoicing or mailboxes are used; the Customer's staff where they appear in bookings.
Categories of data. Identity and contact details (name, email, phone, address); appointment and booking details (dates, services, amounts, answers to the Customer's questions, notes); payment status and references (never card numbers, which stay with Stripe); message content and delivery status; opt in and unsubscribe status; invoice and quote content; mailbox content for hosted email; files the Customer uploads; IP address and browser of visitors who book or pay.
Special categories. None requested by the Services. The Customer may record health related or other sensitive notes about its clients where its business requires it; the Customer is responsible for the lawfulness of doing so, and such notes are protected like all Customer Data.
Frequency. Continuous, as the Customer and its clients use the Services.
Competent supervisory authority (SCCs, clause 13). The authority of the EEA member state where the Customer is established.
Annex II: technical and organisational measures
- Encryption in transit. All connections to the Services, to the APIs and between the Services and subprocessors use TLS. Mail is served over IMAP and SMTP with TLS.
- Encryption at rest. Secrets the Customer gives Calenzy (payment provider keys, webhook secrets) are encrypted with authenticated encryption; the key is held in a managed secrets service separate from the database. Passwords are stored as salted bcrypt hashes.
- Access control. Access to a Customer account is granted by membership; the Owner sets each user's permissions per module, which can only reduce what the plan allows; removal revokes access immediately. Billing is restricted to Owners. Calenzy staff access is limited to named staff accounts and used only for support and security.
- Authentication. Email and password with minimum length, or Google and Apple sign in verified server side. Sessions expire after 30 days of inactivity on the web and 90 days in the apps. Invitations use single use tokens stored hashed, with expiry and revocation.
- Infrastructure. Servers on Amazon Web Services in Singapore and Paris, in private networks with firewalls and a web application firewall; operating system and packages kept updated; administrative access over an authenticated private network with key based SSH; intrusion prevention on exposed services.
- Separation. Customer Data is separated by customer and project identifiers in the database and in storage; each Customer's email sending runs in its own sending tenant so that one Customer's reputation does not affect another's.
- Payments. Card data is collected and stored by Stripe only; Calenzy holds references, brand, last four digits and expiry.
- Backups and recovery. Daily backups kept 7 days in the region of the data.
- Logging and monitoring. Access and error logs kept 14 days; uptime and certificate monitoring with alerts; email bounce and complaint monitoring.
- Software practices. Code kept in version control with review; secrets kept out of code in a managed secrets service; secret scanning on the repositories; staging environments that refuse live payments.
- Data minimisation and deletion. Customers can delete records themselves; account deletion purges Customer Data from live systems and from backups within the rotation period; files of locked accounts remain readable only to the Customer.
- Organisation. A designated Data Protection Officer; a small team bound by confidentiality; a written breach procedure with the 48 hour customer notice in section 7; review of subprocessors before use.
Annex III: subprocessors
The current list of subprocessors, with the purpose and location of each, is published at calenzy.com/subprocessors and forms Annex III of this DPA. Changes are notified as described in section 5.
