Data Processing Agreement
Version 1.0 — 28 July 2026
This data processing agreement (DPA) forms part of the terms of service and applies automatically as soon as you use Calio — there is nothing to sign. If you need a signed copy for your records, email support@calio.nl.
1. Parties and roles
Controller: you, the customer with a Calio account. You decide which data you collect from your guests and why.
Processor: Calio (calio.nl), established in the Netherlands. Calio processes that data solely on your instructions.
For your own account data (your name, email address, billing details) Calio is the controller; that is covered by our privacy statement, not by this agreement.
2. Subject matter, nature and duration
- Subject matter and purpose: providing the scheduling service — showing availability, recording bookings and sending confirmations, reminders and changes.
- Nature of processing: storing, consulting, modifying, transmitting and deleting the data listed below.
- Duration: for as long as your Calio account exists. This agreement ends with your account.
3. Categories of data subjects and personal data
Data subjects: guests who book an appointment through your booking page, and any colleagues you add to your organisation.
Personal data:
- The guest's name and email address, and a phone number if you ask for one.
- Date, time, time zone, language and type of the appointment, plus its status.
- Answers to questions you add to your own booking form.
- If a guest uses the AI search help: the sentence in which they describe when they would like to meet.
- With a calendar connection: start and end times of your busy blocks — no titles, descriptions or attendees.
- Technical logs (IP address, timestamp) for security and debugging.
Calio is not intended for special categories of personal data (such as health data). Do not ask for those in your booking form; an appointment type like "intake" is enough.
4. Instructions
Calio processes the data only on your instructions and for the purposes in article 2, unless a legal obligation requires otherwise — in which case we inform you beforehand, unless that law prohibits it. We never use your guest data for our own purposes, do not sell it and do not train AI models with it.
5. Confidentiality
Everyone at Calio with access to personal data is bound by confidentiality. Access to production data is limited to those who need it for operations and support.
6. Security
Calio takes appropriate technical and organisational measures (Article 32 GDPR):
- All traffic is encrypted via TLS.
- Passwords are stored as Argon2 hashes, never in readable form.
- Calendar connection tokens are stored encrypted (AES-256-GCM).
- Customer data is separated at the database level (row level security): reading or writing another organisation's data is technically impossible, not merely blocked in the application.
- Daily backups, encrypted and kept at a second location.
- Security updates are applied periodically; server access is key-based.
7. Sub-processors
You give Calio general authorisation to engage the sub-processors below. They process only what is needed for their part and are contractually bound to the same obligations.
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean | Hosting of the application and the database | Amsterdam data centre (NL) |
| Resend | Delivery of confirmation, reminder and password reset emails | EU |
| Mistral AI | Language model for the AI search help; receives only the sentence the guest types | France |
| Microsoft (SharePoint) | Storage of encrypted backups | EU tenant |
If Calio replaces or adds a sub-processor, we announce it to account holders by email at least 30 days in advance. If you object and we cannot resolve it together, you may terminate your account with immediate effect.
If you connect your own Google Calendar or Microsoft 365 calendar, that is your choice and Calio acts on your instructions towards that provider; Google and Microsoft are not Calio sub-processors in that case.
8. Transfers outside the EEA
Data is stored and processed within the EU. Calio does not transfer personal data to countries outside the European Economic Area. Should that become necessary in the future, it will only happen with a valid transfer mechanism (such as standard contractual clauses) and we will announce it in advance under article 7.
9. Data subject rights
If a guest asks for access, correction or deletion, you handle that request — it is your data. Calio helps: in the app you can view and delete bookings, and on request we export all data belonging to your organisation. If Calio receives a request concerning your guests, we refer the person to you rather than answering it ourselves.
10. Data breaches
If Calio discovers a personal data breach, we notify you without undue delay and at the latest within 48 hours of discovery, with what we know at that point: what happened, which data and data subjects are affected, the likely consequences and the measures we are taking. Notifying the supervisory authority is your responsibility as controller; Calio provides all the information you need for it.
11. Assistance and audits
On request, Calio assists you with a data protection impact assessment (DPIA) and with questions from a supervisory authority, and makes available the information needed to demonstrate compliance with this article. You may have an audit carried out once a year at most, by an independent expert bound by confidentiality, provided it is announced at least four weeks in advance and reasonable costs are reimbursed. An audit must not disrupt the service to other customers.
12. Return and deletion
When your account ends, Calio deletes the personal data we process on your behalf within 30 days, including copies in backups as soon as those expire under the backup schedule. On request we provide an export before deletion. Data we are legally required to keep (such as billing records) is retained for that purpose only and no longer than necessary.
13. Liability and governing law
The liability provisions of the terms of service also apply to this agreement, to the extent permitted by the GDPR. This agreement is governed by Dutch law.
14. Changes
If Calio changes this agreement, we inform account holders by email at least 30 days in advance. The current version is always on this page, with the version number and date at the top.
See also our privacy statement and terms of service.