Data Processing Addendum

Last updated: 2026-01-19

This Data Processing Addendum (“DPA”) forms part of the agreement between Koalendar (“Processor”, “we”, “us”) and the customer entity that uses Koalendar (“Customer”, “Controller”, “you”) and applies to the extent Koalendar processes Personal Data on behalf of Customer in the course of providing the Koalendar service (the “Service”).

This DPA is incorporated by reference into our Terms of Service. By creating an account or using the Service, you agree to this DPA.

1. Definitions

Unless defined here, terms in this DPA have the meanings given in the GDPR or our Terms.

2. Roles and scope

This DPA does not apply to:

3. Details of processing (Article 28(3))

The details of processing are described in Annex 1 (subject matter, duration, nature and purpose of processing, types of Personal Data, and categories of data subjects).

4. Processor obligations

Koalendar will:

5. Subprocessors

5.1 Authorised Subprocessors

Customer authorises Koalendar to engage Subprocessors to process Personal Data on Customer’s behalf. A list of current Subprocessors is provided in Annex 2.

5.2 Subprocessor obligations

Koalendar will:

5.3 Changes to Subprocessors

Koalendar may update Subprocessors from time to time. If we add or replace a Subprocessor, we will update Annex 2. If Customer has a reasonable objection related to data protection, Customer may notify us promptly and, if the parties cannot resolve the issue, Customer may stop using the affected part of the Service or terminate the affected part of the Service or the Service in accordance with the Terms.

6. International data transfers

Customer acknowledges that some Subprocessors may process Personal Data outside the EEA, the UK, or Switzerland.

Where GDPR requires a transfer mechanism for such transfers, the parties agree that:

7. Assistance with data subject requests and GDPR obligations

Taking into account the nature of processing and the information available to Koalendar, we will provide reasonable assistance to Customer with:

Customer remains responsible for responding to data subject requests. Requests should be submitted to support@koalendar.com with sufficient details to identify the relevant account and booking page.

8. Personal Data Breach

Koalendar will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and will provide information reasonably available about:

9. Data retention, deletion, and return

Customer can delete data through the Service (where available) or by requesting deletion at support@koalendar.com.

Upon termination or expiry of the Service, Koalendar will delete or return Customer Personal Data in accordance with the Service’s standard retention and deletion practices, unless applicable law requires storage of the Personal Data.

10. Audits and compliance information

Koalendar will make available information reasonably necessary to demonstrate compliance with this DPA. If Customer requires an audit, Customer must provide reasonable advance notice and the audit must:

Where possible, Koalendar may satisfy audit requests by providing third-party certifications, audit reports, or summaries.

11. Miscellaneous


Annex 1: Processing details

A. Subject matter

Provision of the Service, including appointment scheduling workflows and communications.

B. Duration

The duration of Customer’s use of the Service, plus any limited retention periods required for security, backups, dispute resolution, or legal compliance.

C. Nature and purpose of processing

D. Categories of data subjects

E. Types of Personal Data

Depending on Customer configuration and how the Service is used:

Customer should not submit special categories of data (as defined by GDPR Article 9) unless strictly necessary and configured by Customer at its own responsibility.

F. Security measures (summary)

Koalendar maintains a security program designed to protect Personal Data, including measures such as:

Security measures may be updated from time to time in accordance with industry standards.


Annex 2: Subprocessors

Koalendar may use the following Subprocessors to provide the Service. Processing locations listed below are typical, and some vendors may process data in additional regions depending on configuration and operational needs.

SubprocessorPurposeTypical processing location
Google Cloud Platform (including Firebase)Application hosting, data storage, logs, and background processingUnited States and EEA
TwilioSMS delivery and messagingUnited States and other regions
Amazon Web Services (SES)Email deliveryUnited States and other regions
MixpanelProduct analyticsUnited States
Microsoft (Clarity)Session analytics and diagnosticsUnited States and EEA
Help ScoutCustomer support and help deskUnited States
HubSpotSales and contact managementUnited States and EEA
StripePayments and billing processingUnited States and EEA
OpenAIAutomated content moderation and AI-assisted features (where enabled)United States and other regions
SlackInternal notifications for support and operationsUnited States and other regions
TypeformOptional forms (onboarding, feedback)United States and EEA
Christine - Koalendar Testimonial

I absolutely LOVE this!! For someone who is very basically computer illiterate, this was one of the easiest tools to download and use.

Christine Cubillas
Owner of CommuniTAS
Dan Luthi - Koalendar Testimonial

Have really enjoyed the flexibility of Koalendar. It is simple to use, clean to present and very easy to setup for Google Meet or Zoom.

Dan Luthi
COO at Ignite Spot
Vanessa - Koalendar Testimonial

I've been using Koalendar for 4 months and I find it very helpful. Works perfectly with Google Calendar. It saves me a lot of time.

Vanessa DVJ
Founder of Jerez & Co

Ready to dive in?Start your free account today.

When you let clients self-book their appointments on your Koalendar scheduling page, you'll save hours of time spent on unnecessary emails.

Sign up for free
Koalendar booking page screenshot