Version: 2026-08-01
Effective date: 1 August 2026
This Data Processing Addendum (DPA) forms part of the Clearslot Business Terms of Service or another agreement governing the Customer's use of Clearslot (the Agreement). It is between the Customer identified in the Agreement (Customer) and CABALLUS LIMITED, an Irish company with company number 790078 and registered office at 2 Bridge Street, Athlone, Co. Westmeath, Ireland (Caballus).
It applies where Caballus processes Customer Personal Data on the Customer's behalf. It is intended to satisfy Article 28 of Regulation (EU) 2016/679 (GDPR) and equivalent processor-contract requirements under Applicable Data Protection Law.
1. Definitions and scope
Applicable Data Protection Law means the GDPR, the Irish Data Protection Acts 1988 to 2018, and any other privacy or data-protection law that applies to processing under this DPA.
Customer Personal Data means Personal Data contained in Customer Content that Caballus processes as processor on the Customer's behalf through the Service.
Personal Data, Controller, Processor, Data Subject, Process and Supervisory Authority have the meanings given by Applicable Data Protection Law.
Security Incident means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data processed by Caballus. It does not include unsuccessful attempts that do not compromise Customer Personal Data.
Subprocessor means another processor engaged by Caballus to process Customer Personal Data.
Caballus is a Processor and the Customer is the Controller, or a Processor appointing Caballus as a subprocessor, for Customer Personal Data. Each party remains responsible for its own compliance with Applicable Data Protection Law.
This DPA does not apply to personal data for which Caballus determines the purposes and means, such as account administration, Caballus subscription billing, security, legal compliance and business operations. The Clearslot Privacy Notice covers that processing.
2. Processing instructions
Caballus will process Customer Personal Data only:
- to provide, secure, maintain and support the Service in accordance with the Agreement;
- as configured or initiated by authorised Customer users;
- on other documented instructions from the Customer that Caballus has agreed to follow; or
- where law requires processing, in which case Caballus will inform the Customer before processing unless law prohibits that notice.
The Agreement, this DPA, the Customer's use and configuration of the Service, and supported requests from authorised users are the Customer's documented instructions.
Caballus will promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Caballus may suspend the affected processing until the parties resolve the issue. Caballus is not required to follow an instruction that is unlawful, technically unsupported, outside the Service, or would require material additional work unless the parties agree its scope and fees.
3. Customer responsibilities
The Customer warrants that:
- it has a lawful basis for the processing and has given all required notices;
- its instructions and use of the Service comply with Applicable Data Protection Law;
- Customer Personal Data is adequate, relevant and limited to what is necessary;
- it will respond to Data Subjects and authorities as Controller and use available Service controls before requesting additional assistance; and
- it will not submit payment-card numbers in free-text fields, passwords, authentication secrets, government identity numbers, special-category data, special care-required personal information, criminal-offence data or US consumer health data.
If the Customer is itself a Processor, it confirms that the relevant Controller has authorised the Customer to appoint Caballus and Caballus's Subprocessors.
4. Confidentiality and personnel
Caballus will ensure that people authorised to process Customer Personal Data:
- access it only where necessary for their responsibilities;
- are bound by contractual or statutory confidentiality duties; and
- receive appropriate privacy and security instructions.
Caballus remains responsible for its personnel's compliance with this DPA.
5. Security
Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risk to individuals, Caballus will maintain appropriate technical and organisational measures designed to protect Customer Personal Data. The current measures are described in Schedule 2.
The Customer is responsible for using the Service securely, including managing user access, protecting credentials, configuring booking forms and integrations appropriately, and keeping its devices and connected services secure.
Caballus may update the measures as technology and risks change, provided the overall level of protection does not materially decrease during a paid subscription.
6. Subprocessors
The Customer gives Caballus general written authorisation to use the Subprocessors in Schedule 3 and to appoint replacements or additional Subprocessors.
Caballus will:
- impose data-protection obligations on each Subprocessor that are no less protective in substance than the obligations applicable to Caballus under this DPA, to the extent relevant to the subcontracted processing;
- remain responsible to the Customer for the Subprocessor's performance of those obligations as required by Applicable Data Protection Law; and
- publish an updated schedule and give the account administrator at least 15 days' advance notice of a new Subprocessor where reasonably practicable.
The Customer may object in writing during the notice period on reasonable, documented data-protection grounds. The parties will try in good faith to resolve the objection, including a commercially reasonable configuration change where available. If they cannot resolve it, Caballus may choose not to use the Subprocessor for that Customer or either party may terminate the affected paid Service. Caballus will refund prepaid fees attributable to the unused terminated period. This is the Customer's sole remedy for a Subprocessor objection, to the extent permitted by law.
Advance notice is not required where an urgent replacement is reasonably necessary for security, legal compliance, provider failure or service continuity. Caballus will notify the Customer as soon as reasonably practicable afterward.
7. Assistance with Data Subject requests
Taking into account the nature of processing, Caballus will assist the Customer through Service functionality and reasonable additional measures to respond to requests to access, correct, erase, restrict, object to or port Customer Personal Data.
If Caballus receives a request relating to Customer Personal Data and can identify the Customer, Caballus will ordinarily direct the requester to the Customer and notify the Customer. Caballus will not respond on the Customer's behalf unless instructed or legally required.
If a request requires material work beyond standard Service functionality, Caballus may charge reasonable costs after giving an estimate, unless Applicable Data Protection Law requires assistance without charge.
8. Security Incidents
Caballus will notify the Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. The notice will include, as information becomes reasonably available:
- the nature of the incident;
- the categories and approximate numbers of affected Data Subjects and records;
- likely consequences;
- measures taken or proposed; and
- a contact for follow-up.
Caballus will take reasonable steps to contain, investigate and mitigate the Security Incident and will provide information reasonably needed for the Customer's notification and documentation duties. Notification is not an admission of fault or liability.
The Customer is responsible for notifying Supervisory Authorities, Data Subjects and others unless law assigns that duty to Caballus.
9. Compliance assistance
Taking into account the nature of processing and information available to it, Caballus will provide reasonable assistance with the Customer's obligations concerning processing security, breach notification, data-protection impact assessments and prior consultation with a Supervisory Authority.
Caballus may satisfy this obligation through documentation, security information, questionnaires, audit summaries and responses reasonably suited to the risk. Material bespoke assistance may be charged at reasonable rates agreed in advance, except where the need arises from Caballus's breach of this DPA.
10. Demonstrating compliance and audits
Caballus will make available information reasonably necessary to demonstrate compliance with this DPA.
The Customer must first use current third-party reports, certifications, summaries and written responses that Caballus makes available. If that information is not reasonably sufficient, the Customer may conduct one audit in any 12-month period, and an additional audit following a material Security Incident or where a Supervisory Authority requires it.
An audit must:
- be requested on at least 30 days' notice unless urgent circumstances require less;
- occur during normal business hours without disrupting operations;
- be limited to systems and records relevant to the Customer;
- be performed by the Customer or an independent auditor that is not a Caballus competitor and is bound by confidentiality; and
- avoid access to another customer's data, security-sensitive testing and production systems unless Caballus expressly agrees.
The Customer bears its audit costs and Caballus's reasonable costs, except where an audit identifies a material breach by Caballus. Caballus may propose a reasonable alternative method that provides equivalent assurance.
11. Government and third-party requests
Unless prohibited by law, Caballus will notify the Customer of a legally binding request for Customer Personal Data from a public authority. Caballus will assess the request, disclose only data it reasonably believes it must disclose, and challenge disproportionate or unlawful requests where there are reasonable grounds to do so.
12. International transfers
Caballus may process Customer Personal Data in the EEA and permit access from other countries only as described in this DPA and the subprocessor schedule.
For a transfer restricted by Applicable Data Protection Law, Caballus will use a valid transfer mechanism, such as an adequacy decision, the EU-US Data Privacy Framework for an eligible participating recipient, or the European Commission's Standard Contractual Clauses (SCCs), and will implement supplementary measures where required.
Where the Customer's use of the Service requires the parties to enter the SCCs or another mandatory transfer addendum, the applicable official clauses are incorporated by reference and completed using the processing details in this DPA unless the parties sign a more specific transfer agreement. The parties will reasonably cooperate to document the mechanism.
13. Return and deletion
During the subscription, the Customer can access, export and delete Customer Personal Data using supported Service functions.
After the Service ends, Caballus will, at the Customer's choice and subject to supported export functionality, return or delete Customer Personal Data, unless law requires retention. Unless the Customer gives a lawful contrary instruction:
- Caballus will delete or irreversibly anonymise remaining Customer Personal Data in active systems under its ordinary deletion process within 90 days after termination; and
- residual encrypted backup copies will be isolated from ordinary use and expire under the backup lifecycle, currently no later than 365 days for monthly backup generations.
Caballus may retain limited data required by law or reasonably necessary for security, fraud prevention, disputes or legal claims. This DPA continues to protect retained Customer Personal Data until deletion or anonymisation.
Return does not require Caballus to create a custom export, restore backup media, retain data beyond the ordinary schedule or provide data that would expose another person's information or Caballus security information.
14. Liability and order of precedence
The liability exclusions and caps in the Agreement apply in aggregate to the Agreement and this DPA, except to the extent Applicable Data Protection Law does not permit them.
If this DPA conflicts with the Agreement on processing Customer Personal Data, this DPA prevails. If valid SCCs conflict with this DPA, the SCCs prevail for the relevant transfer. Except as changed by this DPA, the Agreement remains in effect.
15. Duration and changes
This DPA starts when the Customer accepts the Agreement or when Caballus first processes Customer Personal Data, whichever is earlier. It ends when Caballus and its Subprocessors no longer process Customer Personal Data, subject to surviving confidentiality, deletion and legal obligations.
Caballus may update this DPA where reasonably necessary to reflect law, regulatory guidance, Service or Subprocessor changes, provided the update does not materially reduce mandatory data-protection rights. Notice will be given under the Agreement.
16. Contact
Data-protection contact: clearslot-support@caballus.ie
Postal address: CABALLUS LIMITED, 2 Bridge Street, Athlone, Co. Westmeath, Ireland
Subject matter
Provision of Clearslot's scheduling, booking-page, availability, contact, messaging, reporting, integration and related support functionality as configured by the Customer.
Duration
For the term of the Agreement and the deletion/retention period described in section 13.
Nature and purpose
Collection, recording, organisation, storage, retrieval, consultation, use, transmission, display, synchronisation, restriction, deletion and other processing necessary to provide, secure and support the Service on the Customer's documented instructions.
Categories of Data Subjects
- Customer employees, contractors, users, administrators and representatives;
- Bookers, invitees, attendees, prospects, clients and contacts;
- people represented in connected calendars, contact lists or routing-form responses;
- providers or staff whose availability and services are managed; and
- people who communicate with the Customer through Clearslot.
Types of Personal Data
- identifiers, names, contact details, organisation and role;
- account association and access/permission data;
- booking, availability, calendar, meeting, attendance and cancellation data;
- form questions and answers, notes, messages and Customer Content;
- service descriptions, preferences, language and time zone;
- payment amount, currency, status and provider identifiers, but not full card numbers held by Stripe;
- connected-service identifiers, permissions and tokens;
- IP address, device/browser data, timestamps, logs and security events; and
- other Personal Data the Customer chooses to submit consistently with the Agreement.
Sensitive data
The launch Service is not intended or approved for special-category data, special care-required personal information, criminal-offence data, authentication secrets, full payment-card data or US consumer health data. The Customer must not submit or solicit such data.
Frequency
Continuous or as initiated by the Customer and its users during the term.
Customer instructions for deletion
Service controls, a verified written request, and the default process in section 13.
Caballus maintains measures appropriate to the launch Service and risk, including:
Governance and people
- defined operational responsibility for security and privacy;
- confidentiality duties and need-to-know access;
- review of material provider and system changes; and
- documented incident, backup and restoration procedures.
Identity and access
- unique user accounts and authenticated sessions;
- role- and organisation-based application access controls;
- restricted production and administrative access;
- multi-factor authentication for privileged provider accounts where supported; and
- revocation of sessions and access when an account or role is removed.
Infrastructure and network security
- Cloudflare edge protection, TLS termination, traffic filtering, rate limiting and anti-abuse controls where configured;
- default-restricted origin and database network exposure;
- host firewalls and separation of production services;
- security updates and vulnerability remediation according to risk; and
- secrets kept outside source code and encrypted or access-controlled in operational storage.
Data protection
- TLS for data in transit over public networks;
- client-side encryption of PostgreSQL backups before upload to Scaleway Object Storage;
- logical separation of Customer data through organisation and access identifiers;
- restricted handling of integration tokens and credentials; and
- data minimisation and supported deletion/export functions.
Monitoring and resilience
- application, authentication and security logging;
- monitoring and investigation of material operational and security events;
- nightly encrypted database backups with daily, weekly and monthly lifecycle rules;
- documented restoration procedures and periodic restore testing; and
- incident containment, recovery and communication procedures.
These measures do not represent a certification or a promise that every control applies identically to every component.
A. Core Subprocessors
| Provider and location | Service and processing | Typical processing location / transfer safeguard |
|---|---|---|
| Hetzner Online GmbH (Germany) | Compute, networking and PostgreSQL infrastructure; hosting Customer Personal Data | Selected EEA region; no restricted transfer intended for ordinary hosting |
| Cloudflare, Inc. and relevant affiliates (United States and other locations) | DNS, CDN, web application security, traffic delivery, Pages/edge functions, R2 object storage, Email Routing and Turnstile anti-abuse processing | EEA and global edge processing; applicable adequacy mechanism, Data Privacy Framework and/or SCCs under Cloudflare's DPA |
| Scaleway S.A.S. (France) | Storage of client-side encrypted database backups | France (EEA) |
| Plus Five Five, Inc. (Resend) (United States) | Transactional email transmission, delivery events and related support | United States/global; SCCs and other applicable mechanism under Resend's DPA |
| Google Cloud EMEA Limited and relevant Google affiliates | Google Workspace mailbox where Customer Personal Data is included in a support request | EEA and global processing; Google Cloud DPA and applicable adequacy mechanism and/or SCCs |
B. Customer-authorised integrations and other recipients
These providers receive data only for the relevant billing/payment function or when the Customer enables the integration. Depending on the feature and provider terms, they may act as the Customer's processor, Caballus's processor, an independent controller or a joint controller. They are not core Clearslot hosting providers.
| Provider | Function |
|---|---|
| Stripe Payments Europe, Limited and Stripe affiliates | Caballus subscription billing; optional Customer connected account, booking payments, refunds, disputes and fraud/compliance processing |
| Google LLC and relevant Google affiliates | Google Calendar synchronisation and Google Meet creation enabled by the Customer |
| Zoom Communications, Inc. and relevant affiliates | Zoom meeting creation and updates enabled by the Customer |
The Customer authorises Caballus to transmit the data and instructions necessary for an integration it enables. Data already received by an integration provider remains subject to that provider's terms and the Customer's relationship with it after disconnection.