Skip to DPA
Calbraid
PrivacyTermsRefunds
Open Calbraid
Trust / 04
Privacy policyTerms of serviceRefund policyData processingSubprocessors

Business processing terms

Data
processing.

This addendum governs organization-controlled personal data processed through hosted Calbraid.

Version
1.0
Effective
3 August 2026

Parties and scope

This Data Processing Addendum (“DPA”) forms part of the Calbraid Terms of Service or another agreement (“Agreement”) between the customer controlling a Calbraid workspace (“Customer”) and Applifyer, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States (“Processor”). Processor uses affiliated operating company Applifyer SH.P.K., Rruga Vëllezërit Gërvalla, B2. 12, Prishtinë, Kosovo, NUI 811946089, VAT 330561995, as an affiliate subprocessor.

This DPA applies when Processor handles personal data in Customer-controlled calendars, event content, team configuration, or support material (“Customer Data”) on Customer’s behalf.

1. Roles and instructions

Customer is controller and Applifyer, LLC is processor for Customer Data unless law assigns different roles. Processor handles Customer Data only on documented instructions in the Agreement, workspace and provider configuration, authorized use, and support requests. Processor will notify Customer if an instruction appears unlawful unless prohibited by law.

2. Processing details

  • Duration: the Agreement plus export, deletion, legal-retention, and backup-expiry periods described in the Privacy Policy.
  • Nature and purpose: connect Customer-designated providers; retrieve, cache, organize, transform, synchronize, transmit, route, expose through CalDAV or private feeds, secure, support, back up, audit, and delete Customer Data.
  • Data subjects: Customer users, personnel, contractors, clients, invitees, event attendees and organizers, and other people represented in connected calendars.
  • Data types: identifiers, contact and professional data, availability, calendar and event content, locations, conference links, attendee responses, workspace roles, credentials and provider metadata, device synchronization data, and support/security records.
  • Sensitive data: not intentionally required. Calendar descriptions or locations may reveal sensitive information. Customer must assess suitability and minimize special-category or similarly regulated data.

3. Confidentiality and security

Processor restricts access to authorized people and providers bound by confidentiality. Measures include TLS, authenticated encryption of provider tokens, hashed member credentials, role-based access, private feeds, provider-bound OAuth state, signed billing webhooks, minimized and rotating logs, tested backups, and incident procedures. Customer remains responsible for its provider permissions, roles, client devices, app passwords, feed URLs, and lawful instructions.

4. Subprocessors

Customer authorizes Applifyer SH.P.K. and the providers listed on the Subprocessors page. Processor remains responsible for their data-protection obligations to the extent required by law. Material additions will be posted in advance where practical. Customer may object on reasonable data-protection grounds; the parties will seek an alternative, and either may terminate the affected paid service if none is feasible.

5. International transfers

For restricted EEA transfers, the 2021 EU Standard Contractual Clauses are incorporated by reference using Module Two where Customer is controller and Processor is processor. The optional docking clause applies. Supervisory authority and governing law follow Customer’s eligible EEA establishment or representative, otherwise Ireland. The UK Addendum or another lawful mechanism applies where required. Security measures in this DPA supplement those clauses.

6. Individual rights

Taking account of the processing, Processor provides reasonable assistance with access, correction, portability, restriction, objection, and erasure requests. If Processor receives a request about Customer Data, it will normally direct the requester to Customer. Customer decides the request unless law requires Processor to act independently.

7. Security incidents

Processor will notify Customer without undue delay after confirming a personal-data breach affecting Customer Data and provide available information reasonably needed for Customer’s legal duties. Notification is not an admission of fault. Customer must maintain a current owner contact.

8. Assistance and evidence

Processor will reasonably assist with data-protection impact assessments, regulator consultations, and information needed to demonstrate compliance. Requests must be proportionate and protect other customers, security, and confidential information. Audits should first use available documentation and remote evidence.

9. Return and deletion

Customer may request a portable copy during the Agreement. Following verified deletion or termination, Processor removes Customer Data from the live service except narrowly required legal records. Transactional Cloudflare R2 backups rotate after 14 days; separately encrypted disaster-recovery snapshots may persist for up to 12 months and are not restored to active use without reapplying verified deletions.

10. Priority and liability

If this DPA conflicts with the Agreement regarding Customer Data processing, this DPA controls. The Agreement’s liability terms apply except where applicable law requires otherwise.

DPA notices: info@applifyer.com
Applifyer, LLC · 131 Continental Dr, Suite 305 · Newark, DE 19713 · United States