Data Processing Agreement

Last updated: 10 October 2026

This Data Processing Agreement ("DPA") is part of the Opencals Terms between the merchant using Opencals ("you", the controller) and Stanislav Tyshchenko, trading as Opencals, a sole proprietorship registered in Poland ("Opencals", the processor). It applies whenever Opencals processes personal data on your behalf. It meets the requirements of Article 28 of the EU GDPR and of the UK GDPR.

You accept this DPA by accepting the Terms. If you need a signed copy for your records, email contact@opencals.com and we will countersign one.

1. What we process, and why

Subject matterProviding the Opencals booking, scheduling, payments and storefront service
DurationFor as long as you use Opencals, plus the deletion period in section 9
Nature and purposeStoring, organising, displaying, transmitting and deleting data so your customers can book, pay and receive notifications, and so you can manage your business
Data subjectsYour customers, clients or patients; your staff; anyone else whose data you put into Opencals
Types of dataNames, contact details, booking history, payment and invoice records, answers to your booking forms, notes, and any other data you choose to collect
Special categoriesOnly if you collect them, for example health information in a clinic's intake form. You are responsible for having a lawful basis and any consent needed

2. Your instructions

We process personal data only on your documented instructions. Your use of the service, its settings, and these Terms are your instructions. If we believe an instruction breaks data protection law, we will tell you. If the law requires us to process data in some other way, we will tell you first, unless the law forbids that.

3. Confidentiality

Everyone at Opencals who can access your data is bound by confidentiality. Today that is the founder only.

4. Security

We take appropriate technical and organisational measures to protect your data, taking into account the risk to the people it concerns. They are described on our Security page, which we keep up to date. We may change the measures as long as the overall level of protection does not go down.

5. Subprocessors

You authorise us to use the subprocessors listed on our Security page. Each one is bound by data protection terms that give at least the protection in this DPA. We remain responsible to you for their work.

We will tell you at least 14 days before adding or replacing a subprocessor, by email or by updating that list with an announcement in the dashboard. If you object on reasonable data protection grounds and we cannot resolve it, you can end your subscription and get a pro-rata refund of any prepaid fees.

6. International transfers

We host your data on Amazon Web Services in London, United Kingdom. Where a subprocessor handles data in a country without an adequacy decision, the transfer is covered by the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) or by the provider's certification under the EU–US Data Privacy Framework.

7. Helping you meet your obligations

We will help you, as far as we reasonably can:

  • answer requests from people exercising their rights (access, correction, deletion, portability, objection). Most of these you can handle yourself in the dashboard. If a request reaches us directly, we pass it on to you and do not answer it ourselves unless you ask us to;
  • carry out data protection impact assessments and any prior consultation with a supervisory authority;
  • meet your security obligations.

8. Personal data breaches

If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any case within 48 hours. We will include what we know about the nature of the breach, the data and people affected, the likely consequences, and what we are doing about it. We will send more information as we learn it.

9. Deletion and return

You can export your data from the dashboard at any time. When your subscription ends, we delete or anonymise your personal data within 90 days, including from active systems. Copies in backups are deleted as the backups expire, within 12 months. We keep invoices and records only where the law requires it.

10. Information and audits

We will give you the information you reasonably need to show that we meet this DPA. This includes answering security questionnaires and providing a summary of our latest security assessment under NDA.

If that is not enough, or a supervisory authority requires it, you may audit our compliance once a year, at your cost, with at least 30 days' written notice, during business hours, and under confidentiality. Audits must not disrupt the service or give access to other customers' data. Opencals has no third-party certification today. See the Security page for how we assess ourselves.

11. Liability and precedence

Each party's liability under this DPA follows the limits in the Terms, as far as data protection law allows. If this DPA and the Terms conflict on the processing of personal data, this DPA wins.

12. US health information (HIPAA)

This DPA is not a Business Associate Agreement (BAA). If you are a US covered entity or business associate, email security@opencals.com and we will sign a BAA with you. Do not store protected health information in Opencals until the BAA is signed.

13. Governing law

This DPA is governed by the law of Poland, and the courts of Warsaw have jurisdiction, unless data protection law requires otherwise.

Get started

Ready to transform your service business?

Join 150+ businesses already using Opencals. Start on a free development store with every feature unlocked, and only pay once you go live.

No credit card required
Setup in 10 minutes
Cancel anytime