Data Processing Agreement
Last updated: 10 October 2026
This Data Processing Agreement ("DPA") is part of the Opencals Terms between the merchant using Opencals ("you", the controller) and Stanislav Tyshchenko, trading as Opencals, a sole proprietorship registered in Poland ("Opencals", the processor). It applies whenever Opencals processes personal data on your behalf. It meets the requirements of Article 28 of the EU GDPR and of the UK GDPR.
You accept this DPA by accepting the Terms. If you need a signed copy for your records, email contact@opencals.com and we will countersign one.
1. What we process, and why
| Subject matter | Providing the Opencals booking, scheduling, payments and storefront service |
| Duration | For as long as you use Opencals, plus the deletion period in section 9 |
| Nature and purpose | Storing, organising, displaying, transmitting and deleting data so your customers can book, pay and receive notifications, and so you can manage your business |
| Data subjects | Your customers, clients or patients; your staff; anyone else whose data you put into Opencals |
| Types of data | Names, contact details, booking history, payment and invoice records, answers to your booking forms, notes, and any other data you choose to collect |
| Special categories | Only if you collect them, for example health information in a clinic's intake form. You are responsible for having a lawful basis and any consent needed |
2. Your instructions
We process personal data only on your documented instructions. Your use of the service, its settings, and these Terms are your instructions. If we believe an instruction breaks data protection law, we will tell you. If the law requires us to process data in some other way, we will tell you first, unless the law forbids that.
3. Confidentiality
Everyone at Opencals who can access your data is bound by confidentiality. Today that is the founder only.
4. Security
We take appropriate technical and organisational measures to protect your data, taking into account the risk to the people it concerns. They are described on our Security page, which we keep up to date. We may change the measures as long as the overall level of protection does not go down.
5. Subprocessors
You authorise us to use the subprocessors listed on our Security page. Each one is bound by data protection terms that give at least the protection in this DPA. We remain responsible to you for their work.
We will tell you at least 14 days before adding or replacing a subprocessor, by email or by updating that list with an announcement in the dashboard. If you object on reasonable data protection grounds and we cannot resolve it, you can end your subscription and get a pro-rata refund of any prepaid fees.
6. International transfers
We host your data on Amazon Web Services in London, United Kingdom. Where a subprocessor handles data in a country without an adequacy decision, the transfer is covered by the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) or by the provider's certification under the EU–US Data Privacy Framework.
7. Helping you meet your obligations
We will help you, as far as we reasonably can:
- answer requests from people exercising their rights (access, correction, deletion, portability, objection). Most of these you can handle yourself in the dashboard. If a request reaches us directly, we pass it on to you and do not answer it ourselves unless you ask us to;
- carry out data protection impact assessments and any prior consultation with a supervisory authority;
- meet your security obligations.
8. Personal data breaches
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any case within 48 hours. We will include what we know about the nature of the breach, the data and people affected, the likely consequences, and what we are doing about it. We will send more information as we learn it.
9. Deletion and return
You can export your data from the dashboard at any time. When your subscription ends, we delete or anonymise your personal data within 90 days, including from active systems. Copies in backups are deleted as the backups expire, within 12 months. We keep invoices and records only where the law requires it.
10. Information and audits
We will give you the information you reasonably need to show that we meet this DPA. This includes answering security questionnaires and providing a summary of our latest security assessment under NDA.
If that is not enough, or a supervisory authority requires it, you may audit our compliance once a year, at your cost, with at least 30 days' written notice, during business hours, and under confidentiality. Audits must not disrupt the service or give access to other customers' data. Opencals has no third-party certification today. See the Security page for how we assess ourselves.
11. Liability and precedence
Each party's liability under this DPA follows the limits in the Terms, as far as data protection law allows. If this DPA and the Terms conflict on the processing of personal data, this DPA wins.
12. US health information (HIPAA)
This DPA is not a Business Associate Agreement (BAA). If you are a US covered entity or business associate, email security@opencals.com and we will sign a BAA with you. Do not store protected health information in Opencals until the BAA is signed.
13. Governing law
This DPA is governed by the law of Poland, and the courts of Warsaw have jurisdiction, unless data protection law requires otherwise.
Get started
Ready to transform your service business?
Join 150+ businesses already using Opencals. Start on a free development store with every feature unlocked, and only pay once you go live.