Data Processing Agreement (DPA)
A Data Processing Agreement (DPA) is a legally binding contract between an organization that controls personal data (the data controller) and an organization that processes it on the controller's behalf (the data processor). DPAs are required under GDPR when a controller engages a processor to handle EU personal data.
Who Needs a DPA for PrimeCal?
| Deployment model | Controller | Processor | DPA typically needed? |
|---|---|---|---|
| Cloud (hosted by a provider) | Your organization | PrimeCal hosting provider | Yes — obtain from your provider |
| Self-hosted (on your own infrastructure) | Your organization | (You are both controller and processor for your own data) | Depends on whether you engage a third party (e.g., your cloud host) |
| Enterprise deployment (operated for clients) | Your client organizations | Your organization | Yes — you are the processor; draft a DPA for your clients |
What a PrimeCal DPA Should Cover
A DPA for PrimeCal usage typically addresses:
- Subject matter and duration — calendar and user data processing, duration matching the subscription/service term
- Nature and purpose of processing — providing calendar management, scheduling, and collaboration services
- Type of personal data processed — user account data, calendar events, attendee information, OAuth tokens
- Categories of data subjects — employees, family members, or other end users depending on deployment context
- Sub-processors — any third-party services the PrimeCal deployment engages (e.g., database hosting provider, email delivery, OAuth providers like Google/Microsoft)
- Data subject rights — how requests for access, deletion, or portability are handled
- Security measures — technical and organizational measures (see Security Whitepaper)
- Data breach notification — notification timelines and process
- Return or deletion on termination — what happens to data when the service ends
Getting Your DPA
If you're using a hosted PrimeCal service, contact your provider to request their standard DPA.
If you're operating a self-hosted instance and need a DPA for your users or clients, you'll need to draft one with qualified legal counsel. The technical security measures in PrimeCal's Security Whitepaper can inform the "technical and organizational measures" section of your DPA.
This page provides structural guidance, not a binding legal document. A DPA must be drafted and reviewed by qualified legal counsel to be legally enforceable under your applicable jurisdiction.
Contact
For DPA requests related to a hosted PrimeCal service, contact your system administrator or provider. For self-hosted deployments, consult your legal team.