Data Processing Addendum
Last updated: August 12, 2026
This Addendum covers what we do with personal data on your behalf. It applies to every paid Sync My Cal account and forms part of the Terms of Service, so there's nothing to sign to make it effective. If your process needs a countersigned PDF, ask and you'll get one.
1. The parties
You(“Customer”) are the controller. The calendars you connect hold personal data about you and about the people you meet, and you decide what gets synced where.
We are the processor: Ops Automators LLC, a Florida limited liability company, trading as Sync My Cal. Our registered address is on the countersigned copy, which you can request under section 14. Notices under this Addendum go to privacy@syncmycal.app.
Where a term is defined in the GDPR, it means the same here. “Data protection law” means the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and US state privacy laws where they apply to you.
2. What we process, and why
This is the Article 28(3) description. It's short because the service is narrow: it moves times between calendars, and it doesn't want the rest.
- Subject matter and purpose. Copying calendar events between accounts you connect, according to rules you configure.
- Duration. For as long as your account exists. Processing ends when you disconnect a calendar or delete the account.
- Categories of data subject. You, anyone else using your account, and the attendees of the events you sync.
- Personal data. Account email and name; an encrypted OAuth token per connected account; calendar names, colors and time zones; event start and end times; the identifier of a source event and of the copy we made from it; a sync activity log.
- What we never store. Event titles, descriptions, locations and attendee lists. In busy-block mode we never read them at all. In exact-copy mode they pass through memory to write the copy and are never written to our database.
- No special categories.We don't ask for and have no use for Article 9 data. If your event titles contain it, busy-block mode means we never see it.
3. Processing only on your instructions
We process personal data only to provide the service, and only as your rules and settings instruct. We won't use it for our own purposes, we won't sell or share it, and we don't use it to train machine-learning models. If we ever think an instruction of yours breaks data protection law, we'll tell you rather than carry it out quietly.
Aggregate operational counts (how many syncs ran, how many failed) are ours and contain no personal data.
4. Confidentiality and people
Access is limited to the people who need it to run and support the service, currently a very short list, each bound by confidentiality obligations that survive the end of their engagement. Nobody browses customer data for interest.
5. Security measures
The technical and organizational measures under Article 32:
- OAuth tokens encrypted at rest with AES-256-GCM; the key lives outside the database.
- Passwords stored only as bcrypt hashes. We never see the plaintext.
- TLS on every connection, HSTS enforced, plus CSP, frame-deny and no-sniff headers.
- Data minimization as the primary control: the event details worth stealing are never written down, so a database compromise can't leak them.
- Least-privilege OAuth scopes, one calendar scope per provider, revocable by you in one click.
- Managed infrastructure (Vercel, Neon) with encryption at rest, automated backups and point-in-time restore.
- Self-serve export and deletion, so you can exercise rights without asking us.
More detail, kept current, on the security page.
6. Subprocessors
You give general authorization for the subprocessors listed at syncmycal.app/subprocessors, which is the current and complete list. Each is bound by a written contract with data protection terms at least as protective as these, and we stay responsible for their performance.
Ask to be notified and we'll email you before a new subprocessor starts processing your data. You have 30 days to object on reasonable data protection grounds; if we can't accommodate the objection, you can terminate the affected subscription and we'll refund any prepaid, unused fees.
7. Data subject requests
Requests come to you, not us, and the product is built so you can answer most of them yourself: export from Settings, delete an account from Billing, disconnect a calendar at any time. If a request needs us, email privacy@syncmycal.app and we'll help within the statutory deadline at no charge. If a data subject contacts us directly, we'll refer them to you rather than act on it.
8. Personal data breaches
If we become aware of a breach affecting your personal data, we'll notify you without undue delay and within 48 hours, with what we know: what happened, which data, likely consequences, and what we're doing about it. Follow-up detail comes as the investigation progresses. We'll help you meet your own notification duties.
9. International transfers
Our infrastructure runs in the United States, so if you're in the EEA, UK or Switzerland, your data is transferred there. For those transfers the EU Standard Contractual Clauses (Commission Decision 2021/914, Module Two, controller to processor) are incorporated into this Addendum by reference, with the UK International Data Transfer Addendum and the Swiss equivalent applying where relevant. Clause options: docking is available, and the governing law and forum are those named in section 13. Where the SCCs and this Addendum disagree, the SCCs win.
Google and Microsoft process the calendar data on their own global infrastructure under their own transfer mechanisms, because it's their calendar and you already have an agreement with them.
10. Audits and information
Ask and we'll answer reasonable questions about this Addendum in writing, including a security questionnaire, once per twelve months and more often if a regulator or a breach requires it. Sync My Cal is a small operation without a SOC 2 report; if you need one from the infrastructure underneath, Vercel, Neon and Stripe publish theirs. On-site audits are available where data protection law entitles you to one, at your cost and on 30 days' notice.
11. Deletion and return
Delete your account and your tokens, calendars, rules, event mappings and sync log go with it. Ask us instead and it's done within 30 days. Backups age out on their own rolling schedule. Events already written into your calendars stay where they are: they're in your accounts, not ours, and deleting them is your call. Nothing is retained beyond what law requires.
12. Liability and precedence
The limitation of liability in the Terms of Service applies to this Addendum, and to the SCCs between the parties, as one aggregate cap. On personal data, this Addendum takes precedence over anything in the Terms or the Privacy Policy that conflicts with it.
13. Governing law
The law and forum that govern the Terms of Service govern this Addendum, except where data protection law or the SCCs require otherwise.
14. Signed copies and questions
Email privacy@syncmycal.app with your legal entity name and address for a countersigned copy, or with whatever your review needs. A person answers, usually the one who wrote the sync engine.