Data processing agreement

GDPR Article 28 · Updated 4 October 2026

Service provider
Salovuori Mikko Heikki
Business ID
2989730-9
Address
Länsisatamankatu 36, 00220 Helsinki
Email
mikko@calendo.fi

1. Parties and entry into force

This agreement is made between the business or person that has created a Calendo account (the "Customer", controller) and Salovuori Mikko Heikki (the "Provider", processor). It forms part of the terms of service and enters into force when the Customer accepts them. It applies whenever the Provider processes personal data on the Customer's behalf to provide the Calendo booking service.

If you need a signed copy of this agreement, ask for one at mikko@calendo.fi.

2. Subject matter, nature, purpose and duration

  • Purpose: receiving, confirming, reminding of, rescheduling and cancelling bookings, and the related messages, payments and reports.
  • Nature: collecting data through the booking page, storing, displaying it to the Customer, writing it to the Customer's calendar, sending messages, backing up and deleting.
  • Duration: while the Customer uses Calendo, and until the data is deleted under section 12.

3. Data subjects and personal data

  • Data subjects: people who book with the Customer, other attendees invited to bookings, the Customer's team members and the Customer's contacts imported into Calendo.
  • Personal data: name, email address and phone number; the booked time, meeting type, language and time zone; answers to booking questions, including image or PDF attachments if the Customer's form asks for them; notes; replies to text or WhatsApp reminders; marketing consent and its withdrawal; payment amount, status and Stripe reference numbers; team members' encrypted calendar access tokens; the audit log of the Pro plan.
  • Special categories (such as health data) are not processed unless the Customer asks for them in its own booking questions. The Customer is then responsible for the legal basis and must not collect unnecessary data.

4. The Customer's obligations

The Customer is responsible for having a lawful basis for the processing, for informing the people who book (its name is shown on the booking page, and the booking page links to Calendo's privacy policy), for the lawfulness of its instructions and settings, and for the services it connects itself, such as webhooks, Zapier or its own Stripe account.

5. The Provider's obligations

  • Processes personal data only on the Customer's documented instructions. These are this agreement, the terms of service and the settings the Customer makes in Calendo. The Provider informs the Customer if it considers an instruction unlawful.
  • Uses personal data for no purpose of its own. Anonymous, aggregated statistics may be used to develop the service.
  • Ensures that persons processing personal data are bound by confidentiality.
  • Implements the security measures in section 7.
  • Assists the Customer in responding to data subject requests and with the obligations of GDPR Articles 32–36.
  • Makes available the information needed to demonstrate compliance with this agreement.

6. Sub-processors

The Customer gives a general authorisation to use the following sub-processors. Services marked "if used" process data only when the Customer turns the feature on or connects the service.

  • Cloudflare, Inc.: hosting, database, file storage and backups.
  • Google LLC (if used): calendar events, Google Meet and messages through the Customer's own Google account.
  • Microsoft Ireland Operations Ltd / Microsoft Corporation (if used): calendar events, Microsoft Teams and messages through the Customer's own Microsoft account.
  • Twilio Inc. (if used): text message and WhatsApp reminders, payment links and replies to reminders. WhatsApp messages are also delivered by Meta Platforms Ireland Ltd.
  • Zoom Communications, Inc. (if used): Zoom meetings and their links (meeting topic, time and the name of the person who booked).
  • Anthropic, PBC (if used): the Pro plan's AI preparation summary. Booking answers and notes are sent only when the Customer requests a summary, and they are not used to train AI models.

Google and Microsoft are used through the Customer's own accounts under the Customer's own agreements with them. Payments the Customer collects go to the Customer's own Stripe account, and Stripe processes them under its agreement with the Customer.

The Provider announces new or replaced sub-processors at least 30 days in advance on this page and by email. The Customer may object on reasonable data protection grounds; if the matter cannot be resolved, the Customer may terminate the agreement before the change takes effect. The Provider binds its sub-processors to equivalent data protection obligations and is responsible for them as for itself.

7. Security

The measures in use are described at calendo.fi/tietoturva (in Finnish). They include encrypted traffic (HTTPS, HSTS), sign-in with Google, Microsoft or Apple without passwords and a signed session cookie, calendar access tokens encrypted with AES-GCM, account-level access checks on every request, abuse protection on the booking form, daily backups kept for 30 days with a weekly restore test, and automatic deletion of bookings after the retention period.

8. Personal data breaches

The Provider notifies the Customer of a personal data breach without undue delay and no later than 48 hours after becoming aware of it. The notice describes what is known: the nature of the breach, the categories and approximate number of data subjects, the likely consequences and the measures taken.

9. Data subject rights

The Customer responds to requests from the people who book. Calendo's export and deletion tools are available to it. The people who book can also download or delete their own booking data at calendo.fi/omat-tiedot, and the Customer is notified of a deletion. The Provider forwards any request addressed to it to the Customer without delay.

10. International transfers

Personal data may be transferred outside the EU/EEA only to the sub-processors in section 6 and on the grounds of Chapter V of the GDPR, such as the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.

11. Audits

The Customer may audit compliance with this agreement at its own cost, at most once a year and with 30 days' notice. Audits are primarily carried out through written information. Auditors must be bound by confidentiality.

12. Retention and deletion

  • Bookings and their attachments are deleted automatically after the retention period set by the Customer (by default 365 days after the meeting, adjustable from 30 to 3,650 days).
  • The Pro plan's audit log is kept for 365 days, and abuse-prevention hashes for 48 hours.
  • When the account is deleted, the Customer's personal data is deleted within 30 days, and backups within their retention period (30 days), unless the law requires otherwise. The Customer can export its data before deletion.

13. Liability and precedence

Liability is governed by Article 82 of the GDPR and, to the extent permitted by law, by the limitations in the terms of service. Finnish law applies. In matters of personal data processing, this agreement prevails over the terms of service.