Legal
Data Processing Agreement (DPA)
Effective date: October 1, 2026
This Data Processing Agreement (“DPA”) supplements the Terms of Service (“Agreement”) entered into by and between ItGuysCan Mirosław Farajewicz, Zbożowa 3/14, Kraków, Poland, VAT ID: PL6842536537 (“Processor”, “we”, “us”) and the entity or individual subscribing to the Service (“Controller”, “you”).
1. Purpose and scope
- Roles. The Controller acts as the Data Controller and the Processor acts as the Data Processor pursuant to Article 28 of the General Data Protection Regulation (GDPR).
- Subject matter. The Processor provides an automated iCal feed monitoring and webhook delivery service as described in the Terms of Service.
- Categories of data. iCal feed URLs (which may contain embedded personal access tokens), calendar event metadata (summaries, timestamps, locations, UIDs), and target webhook callback URLs.
- Categories of data subjects. Individuals whose calendar events or personal data are contained within the monitored iCal feeds.
2. Obligations of the Processor
- Instructions. The Processor shall process personal data solely on documented instructions from the Controller, including with respect to transfers of personal data outside the EEA.
- Confidentiality. The Processor ensures that personnel authorized to process personal data are bound by strict obligations of confidentiality.
- Security measures. The Processor implements appropriate technical and organizational measures to ensure data security, including payload encryption in queue buffers, transient in-memory processing, and hash-based change detection at rest.
- Data minimization (
notify_onlymode). The Processor offers anotify_onlymode wherein only feed change alerts (without calendar event payload content) are processed and transmitted.
3. Sub-processors
- The Controller provides general authorization for the Processor to engage third-party sub-processors to support the execution of the Service.
- Authorized sub-processors:
- Hetzner Online GmbH — cloud infrastructure and server hosting, located in the EU.
- Stripe, Inc. — payment processing and billing services.
- The Processor shall inform the Controller of any intended changes or additions regarding sub-processors, giving the Controller the opportunity to object.
4. Data security and log retention
- Transient processing. Event diff payloads stored temporarily in queues during delivery retries or outage windows are encrypted and handled transitively.
- Retention. Webhook delivery logs, execution histories, and diagnostic data are automatically deleted after 30 days.
- SSRF and network protection. The Processor uses isolated outbound proxies and request validation to mitigate Server-Side Request Forgery (SSRF) and related security risks.
5. Data subject rights and breach notification
- Assistance. Taking into account the nature of processing, the Processor shall assist the Controller in responding to requests from data subjects exercising their rights under the GDPR.
- Breach notification. The Processor shall notify the Controller without undue delay upon becoming aware of a personal data breach affecting the Controller's data.
- Audits. The Processor shall provide the Controller with the necessary information to demonstrate compliance with Article 28 of the GDPR.
6. Termination and data deletion
Upon termination of the Agreement or deletion of the account, the Processor shall delete or return all personal data processed on behalf of the Controller, unless EU or Polish law requires continued storage.
See also: Terms of Service