Data Processing Addendum

Last Updated: July 3, 2026

1. Introduction

This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer") and AddCal for your use of the AddCal Services (the "Agreement"). It applies whenever AddCal processes Personal Data on your behalf, and it sets out the terms on which we do so.

If you are an Organizer who uses AddCal to collect or process the Personal Data of others (for example, when you collect event registrations or RSVPs), you are the data controller for that data and AddCal is your data processor. This DPA governs that relationship.

This DPA supplements our Privacy Policy and Terms of Service. Where this DPA conflicts with those documents in respect of the processing of Personal Data covered here, this DPA prevails. Capitalised terms not defined here have the meaning given in the Agreement.

1.1 Who is Who

When we use the term "Organizer," we mean event creators using our Services to create events. "Consumers" are the individuals who register for, attend, or otherwise interact with those events. "Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and the California Consumer Privacy Act (CCPA/CPRA), in each case as amended or replaced from time to time.

The terms "Personal Data," "processing," "data controller," "data processor," "data subject," and "supervisory authority" have the meanings given to them in the GDPR.

2. Roles of the Parties

For Personal Data that AddCal processes on the Customer's behalf under the Agreement (such as Consumer registration data, attendee details, and custom form responses), the Customer is the data controller and AddCal is the data processor.

The Customer determines what Personal Data is collected and why, and is responsible for ensuring it has a lawful basis to collect that data and to instruct AddCal to process it, including providing any required notices to and obtaining any required consents from data subjects.

This DPA does not apply to Personal Data for which AddCal is itself the data controller (for example, your own account and billing information). Our handling of that data is described in our Privacy Policy.

3. Processing of Personal Data

3.1 Our Instructions

AddCal will process Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless we are required to do otherwise by applicable law. Your use of the Services, together with this DPA and the Agreement, constitutes your complete and final instructions to us regarding the processing of Personal Data. If we believe an instruction infringes Data Protection Laws, we will inform you.

3.2 Scope of Processing

The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of data subjects are described in Annex A to this DPA.

3.3 Confidentiality

We ensure that everyone we authorise to process Personal Data is bound by an appropriate duty of confidentiality, whether by contract or by statute, and processes that data only as needed to provide the Services.

4. Security

AddCal implements and maintains appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of the processing. A summary of these measures is set out in Annex B.

You are responsible for securing your own account credentials and for the security decisions you make when configuring the Services.

5. Sub-processors

You provide general authorisation for AddCal to engage sub-processors to help us provide the Services. The sub-processors we currently use are listed on our Sub-processors page (see also Annex C).

Where we engage a sub-processor, we only use sub-processors that are subject to a data processing agreement with data protection obligations consistent with those in this DPA, and we remain responsible for the sub-processor's performance.

We will give you reasonable notice (by updating the list in our Privacy Policy, or by email where you have asked to be notified) before adding or replacing a sub-processor. If you have a reasonable, data-protection-based objection to a new sub-processor, let us know at [email protected] within 30 days and we will work with you in good faith to address it. If we cannot, you may stop using the affected part of the Services.

6. Data Subject Rights

The Services give you tools to access, correct, export, and delete the Personal Data you process through AddCal, so that you can respond to data subject requests yourself.

Taking into account the nature of the processing, AddCal will provide reasonable assistance to help you respond to requests from data subjects to exercise their rights under Data Protection Laws. If we receive such a request directly from a data subject relating to your data, we will, where permitted, refer them to you rather than respond ourselves.

7. Assistance and Breach Notification

Taking into account the nature of the processing and the information available to us, AddCal will provide reasonable assistance to help you meet your obligations relating to the security of processing, data protection impact assessments, prior consultation with supervisory authorities, and the notification of personal data breaches.

If we become aware of a personal data breach affecting Personal Data we process on your behalf, we will notify you without undue delay. The notification will describe the nature of the breach and the measures we have taken or propose to take, to the extent then known. We will take reasonable steps to mitigate the effects of, and to minimise any damage resulting from, the breach. Our notification is not an acknowledgement of fault or liability, and you remain responsible for any notifications you are required to make to supervisory authorities or affected individuals.

8. Return and Deletion of Data

You can delete the Personal Data you process through AddCal at any time from within the Services. On termination or expiry of the Agreement, AddCal will, at your choice, delete or return the Personal Data we process on your behalf, and delete existing copies, unless applicable law requires us to retain it.

Personal Data held in routine backups is deleted in line with our standard backup retention cycle. If an account becomes inactive, we apply the retention and deletion practices described in our Privacy Policy.

9. Audits

AddCal will make available to you the information reasonably necessary to demonstrate compliance with this DPA. You agree that we may satisfy this obligation, and any right you have to audit or inspect our processing, by providing our security documentation, responses to a reasonable security questionnaire, and any third-party certifications or audit reports we hold from time to time. You agree that these are an adequate means of demonstrating our compliance.

An on-site inspection will only be available where the information described above is genuinely insufficient to demonstrate compliance, or where a supervisory authority specifically requires it. Any such inspection is limited to once in any twelve-month period, must be requested in writing on at least 30 days' prior notice, must be carried out during business hours and in a way that does not disrupt our operations or compromise the confidentiality or security of other customers' data, must not be conducted by a competitor of AddCal, and is carried out at your cost.

10. International Data Transfers

AddCal and its sub-processors may process Personal Data in countries other than the one in which you or your data subjects are located, including the United States.

Where we transfer Personal Data out of the European Economic Area, the United Kingdom, or Switzerland to a country that is not subject to an adequacy decision, we put in place an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses (Module Two: controller to processor), together with the UK International Data Transfer Addendum for transfers subject to the UK GDPR. Those clauses are incorporated into this DPA by reference and apply to the relevant transfers.

Where Personal Data subject to the Australian Privacy Act 1988 is disclosed to an overseas recipient, including a sub-processor located outside Australia, we take reasonable steps to ensure that recipient handles the Personal Data in a way consistent with the Australian Privacy Principles, as described in Section 12.

11. California (CCPA/CPRA)

This section applies where AddCal processes Personal Data that is subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"). For the purposes of the CCPA, the Customer is the "business" and AddCal is a "service provider." Terms such as "sell," "share," "personal information," and "commercial purpose" have the meanings given to them in the CCPA.

When acting as a service provider, AddCal:

  • Will not sell or share Personal Data that it processes on the Customer's behalf
  • Will not retain, use, or disclose that Personal Data for any purpose other than to provide the Services specified in the Agreement, or as otherwise permitted by the CCPA
  • Will not retain, use, or disclose that Personal Data outside the direct business relationship between AddCal and the Customer
  • Will not combine that Personal Data with personal information it receives from other sources, except as permitted by the CCPA
  • Will comply with the obligations applicable to service providers under the CCPA and provide the same level of privacy protection it requires

We will notify the Customer if we determine that we can no longer meet our obligations as a service provider under the CCPA. The Customer may take reasonable and appropriate steps to stop and remediate any unauthorised use of Personal Data. AddCal will assist the Customer, taking into account the nature of the processing, in responding to verifiable consumer requests to exercise their rights under the CCPA.

12. Australia (Privacy Act 1988)

AddCal is operated from Australia and is subject to the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"). This section applies where AddCal processes Personal Data that is subject to Australian privacy law.

In handling Personal Data on the Customer's behalf, AddCal will:

  • Handle that Personal Data in a manner consistent with the APPs, to the extent they apply to the processing
  • Take reasonable steps to protect that Personal Data from misuse, interference, loss, and unauthorised access, modification, or disclosure, as described in Section 4 and Annex B
  • Only use or disclose that Personal Data for the purposes of providing the Services or as otherwise permitted under this DPA and the Agreement
  • Where it discloses Personal Data to an overseas recipient (including a sub-processor), take reasonable steps to ensure that recipient handles the data consistently with the APPs

The Customer remains responsible for ensuring that its own collection, use, and disclosure of Personal Data through the Services complies with the Privacy Act 1988 and the APPs, including providing any required collection notices and obtaining any required consents.

If AddCal becomes aware of an eligible data breach affecting Personal Data it processes on the Customer's behalf, it will notify and assist the Customer as set out in Section 7 so that the Customer can meet its obligations under the Notifiable Data Breaches scheme.

13. Order of Precedence and Liability

In the event of a conflict, the order of precedence is: (1) any applicable Standard Contractual Clauses, (2) this DPA, and (3) the rest of the Agreement. Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

14. Changes to This DPA

We may update this DPA from time to time to reflect changes in our Services or in Data Protection Laws. The updated version will be indicated by an updated "Last Updated" date and will be effective as soon as it is accessible. Material changes that reduce your rights under this DPA will not apply retroactively.

15. Contact

If you have any questions about this DPA, or if you require a countersigned copy for your records, please contact us at [email protected].


Annex A — Details of Processing

Subject matter: AddCal's provision of the Services to the Customer under the Agreement, namely a platform for creating, sharing, and managing calendar events and collecting event registrations and RSVPs.

Duration: For the term of the Agreement, and until Personal Data is deleted or returned in accordance with Section 8.

Nature and purpose of processing: Collecting, recording, organising, structuring, storing, retrieving, using, and transmitting Personal Data as needed to operate the Services, including hosting and storing event and registration data, sending event-related communications, measuring performance, supporting users, and enabling the Customer to configure and use the Services.

Types of Personal Data:

  • Identification and contact details (such as name and email address)
  • Event registration and RSVP information
  • Responses to custom registration forms created by the Organizer
  • Calendar and event information associated with a data subject
  • Technical data collected automatically, such as IP address and device or usage information

The Customer must not use the Services to process special categories of Personal Data (such as health, racial or ethnic origin, or biometric data) unless it has put in place the additional protections required by Data Protection Laws.

Categories of data subjects:

  • Consumers who register for, RSVP to, or interact with the Customer's events
  • The Customer's own team members and other individuals whose data the Customer chooses to process through the Services

Annex B — Security Measures

AddCal maintains technical and organisational measures appropriate to the risk, including:

  • Encryption of Personal Data in transit using TLS, and encryption of data at rest
  • Access controls that limit access to Personal Data to authorised personnel on a need-to-know basis
  • Hosting with reputable cloud infrastructure providers operating recognised security and availability controls
  • Logging, monitoring, and error tracking to help detect and respond to security events
  • Regular backups and tested restoration procedures
  • Internal policies and confidentiality obligations for personnel who handle Personal Data

These measures may be updated over time to keep pace with technology and evolving risks, provided that the level of protection is not reduced.

Annex C — Sub-processors

The current list of AddCal's sub-processors is maintained on our Sub-processors page, which forms part of this Annex. We may update that list from time to time as our Services evolve.