Data Processing Agreement
Last updated: [DATE — to set]. This is a working draft pending legal review. For a signed DPA, or your organisation's own template, contact privacy@getscheduleit.app.
This Data Processing Agreement ("DPA") applies where you use Scheduleit to process personal data of your own users or contacts. It supplements our Terms of Service. In it, you are the controller and [Legal Entity] ("we") is the processor.
Scope and roles
We process personal data only to provide the Service — scheduling and delivering the webhooks and emails you configure. You determine the purposes and means; we act on your documented instructions (which include your configuration and use of the Service).
Personal data processed
- Recipient data — email addresses you verify for the email channel, and any personal data contained in the payloads you schedule.
- Delivery metadata — timestamps, endpoints, status, and attempt counts.
You must ensure you have a lawful basis and any necessary consent for this data, and you must not schedule special-category data unless appropriately safeguarded.
Our obligations
- Process personal data only on your instructions and as needed to provide the Service.
- Ensure personnel are bound by confidentiality.
- Apply appropriate technical and organisational security measures (encryption in transit, access controls, hashed credentials).
- Assist you, taking into account the nature of processing, with data-subject requests and with your security, breach-notification, and impact-assessment obligations.
- Notify you without undue delay after becoming aware of a personal-data breach affecting your data.
- Delete or return personal data at the end of the Service, subject to legal retention.
Sub-processors
You authorise us to engage the sub-processors listed on our Sub-processors page. We impose data-protection obligations on them equivalent to those in this DPA, and we give reasonable notice of changes so you can object.
International transfers
Where personal data is transferred across borders, we rely on appropriate safeguards such as the Standard Contractual Clauses.
Audits
On reasonable request we will make available information necessary to demonstrate compliance with this DPA, subject to confidentiality.