Data Processing Addendum
Last updated: September 7, 2026
This Addendum covers what we do with personal data on your behalf. It applies to every Sync My Cal account — trials included, because a trial in the EEA needs it as much as a paid account does — and forms part of the Terms of Service, so there's nothing to sign to make it effective. If your process needs a countersigned PDF, ask and you'll get one.
1. The parties
You (“Customer”) are the controller. The calendars you connect hold personal data about you and about the people you meet, and you decide what gets synced where.
We are the processor: Ops Automators LLC, a Florida limited liability company, trading as Sync My Cal. Our registered address is on the countersigned copy, which you can request under section 14. Notices under this Addendum go to privacy@syncmycal.app.
Where a term is defined in the GDPR, it means the same here. “Data protection law” means the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and US state privacy laws where they apply to you.
2. What we process, and why
This is the Article 28(3) description. It's short because the service is narrow: it moves times between calendars, and it doesn't want the rest.
- Subject matter and purpose. Copying calendar events between accounts you connect, according to rules you configure.
- Duration. For as long as your account exists. Processing ends when you disconnect a calendar or delete the account.
- Categories of data subject. You, anyone else using your account, and the attendees of the events you sync.
- Personal data. Account email and name; an encrypted OAuth token per connected account; calendar names, colors and time zones; event start and end times; the identifier of a source event and of the copy we made from it; a sync activity log.
- What we never store. Event titles, descriptions, locations and attendee lists. In both modes these pass through memory — to decide what syncs, and in exact-copy mode to write the copy — and are never written to our database. A busy block carries only a time span and your chosen label, so no detail reaches the target calendar either.
- No special categories. We don't ask for and have no use for Article 9 data, and none of it is stored or copied onto another calendar by busy-block mode. It may still pass through memory transiently while a sync decides what to copy.
3. Processing only on your instructions
We process personal data only to provide the service, and only as your rules and settings instruct. We won't use it for our own purposes, we won't sell or share it, and we don't use it to train machine-learning models. If we ever think an instruction of yours breaks data protection law, we'll tell you rather than carry it out quietly.
Aggregate operational counts (how many syncs ran, how many failed) are ours and contain no personal data.
3a. US state privacy laws
Section 1 says US state privacy laws apply where they apply to you, so this says what that means in their own words rather than leaving a reviewer to infer it from section 3.
For the CCPA as amended by the CPRA, and for the comparable laws of Virginia, Colorado, Connecticut, Utah and Texas, we act as your service provider (or “processor” where that is the term used). We do not sell your personal information and we do not share it for cross-context behavioural advertising — those are the statutory terms, and both are the case. We will not retain, use or disclose it except to perform the service, for the limited purposes the statutes permit a service provider, and never to build a profile of anyone outside the service. We will not combine it with personal information from another source except as a service provider is permitted to.
We grant you the right to take reasonable steps to confirm we use it consistently with your obligations, we'll tell you if we determine we can no longer meet these terms, and we bind every subprocessor in section 6 to the same standard. Deidentified data, if we ever produce any, will not be re-identified.
4. Confidentiality and people
Access is limited to the people who need it to run and support the service, currently a very short list, each bound by confidentiality obligations that survive the end of their engagement. Nobody browses customer data for interest.
5. Security measures
The technical and organizational measures under Article 32:
- OAuth tokens encrypted at rest with AES-256-GCM; the key lives outside the database.
- Passwords stored only as bcrypt hashes. We never see the plaintext.
- TLS on every connection, HSTS enforced, plus CSP, frame-deny and no-sniff headers.
- Data minimization as the primary control: the event details worth stealing are never written down, so a database compromise can't leak them.
- Least-privilege OAuth scopes, one calendar scope per provider, revocable by you in one click.
- A daily logical database snapshot in a private Vercel Blob store, separate from the live database provider, with the newest 30 snapshots retained. The recovery-point objective is up to 24 hours; restore files are replay-tested before we rely on them.
- Managed infrastructure (Vercel, Supabase) with encryption at rest and TLS in transit.
- Self-serve export and deletion, so you can exercise rights without asking us.
More detail, kept current, on the security page.
6. Subprocessors
You give general authorization for the subprocessors listed at syncmycal.app/subprocessors, which is the current and complete list. Each is bound by a written contract with data protection terms at least as protective as these, and we stay responsible for their performance.
Ask to be notified and we'll email you before a new subprocessor starts processing your data. You have 30 days to object on reasonable data protection grounds; if we can't accommodate the objection, you can terminate the affected subscription and we'll refund any prepaid, unused fees.
7. Data subject requests
Requests come to you, not us, and the product is built so you can answer most of them yourself. Settings › Your data downloads one JSON file containing every category listed in section 5 — profile, billing, connected accounts and calendars, sync rules and their filters, the copies we made, preferences, sign-in history, migration requests and support notes, and team membership. Credentials are excluded from it by design: password hash, two-factor secret, recovery codes, and the OAuth tokens for your calendars. You can also delete an account from Billing and disconnect a calendar at any time. If a request needs us, email privacy@syncmycal.app and we'll help within the statutory deadline at no charge. If a data subject contacts us directly, we'll refer them to you rather than act on it.
8. Personal data breaches
If we become aware of a breach affecting your personal data, we'll notify you without undue delay and in any event within 72 hours of becoming aware, with what we know: what happened, which data, likely consequences, and what we're doing about it. Article 33(2) asks a processor for “without undue delay” and gives you, as controller, 72 hours to reach your regulator; this commitment is written to sit inside that rather than to sound impressive and then be missed at 3am on a Sunday by a company this size. Follow-up detail comes as the investigation progresses. We'll help you meet your own notification duties.
9. International transfers
Our infrastructure runs in the United States, so if you're in the EEA, UK or Switzerland, your data is transferred there. For those transfers the EU Standard Contractual Clauses (Commission Decision 2021/914, Module Two, controller to processor) are incorporated into this Addendum by reference, with the UK International Data Transfer Addendum and the Swiss equivalent applying where relevant. Where the SCCs and this Addendum disagree, the SCCs win.
The clause options, stated rather than left to be argued about. The optional docking clause (Clause 7) applies. For the purposes of Clause 17 the SCCs are governed by the law of Ireland, and under Clause 18(b) the courts of Ireland resolve disputes arising from them — an EU member state law and forum, as Clause 17 requires, and deliberately not the Florida law that governs the rest of this Addendum under section 13. Under Clause 9(a) you give general written authorization for the subprocessors in section 6, with fourteen days' notice of changes. The Annexes are this document: section 2 is Annex I.B (description of the transfer), section 5 is Annex II (technical and organizational measures), and section 6 is Annex III (subprocessors). The supervisory authority under Annex I.C is the one for your own place of establishment.
For the UK Addendum: Tables 1 to 3 are populated by sections 1, 2, 5 and 6 of this document, and in Table 4 neither party may end the Addendum as set out in its Section 19.
Google and Microsoft process the calendar data on their own global infrastructure under their own transfer mechanisms, because it's their calendar and you already have an agreement with them.
10. Audits and information
Ask and we'll answer reasonable questions about this Addendum in writing, including a security questionnaire, once per twelve months and more often if a regulator or a breach requires it. Sync My Cal is a small operation without a SOC 2 report; if you need one from the infrastructure underneath, Vercel, Supabase and Stripe publish theirs. On-site audits are available where data protection law entitles you to one, at your cost and on 30 days' notice.
11. Deletion and return
Return first, because SCC Clause 8.5 gives you the choice of return or deletion and this document only ever offered deletion. Settings › Your data downloads everything we hold in one machine-readable file, at any time, without asking us — so a return is something you take rather than request. If you need it in another shape, ask.
Delete your account and your tokens, calendars, rules, event mappings, migration requests and sync log go with it. Ask us instead and it's done within 30 days. Deletion from the live database is immediate. For disaster recovery we keep the newest 30 daily logical snapshots in a private store separate from the live database. A deleted record can therefore remain in a snapshot until that snapshot leaves the retention cycle. We do not selectively restore deleted accounts. If a full-service recovery uses an older snapshot, deletion requests made after that snapshot are reapplied before normal service resumes. Events already written into your calendars stay where they are: they're in your accounts, not ours, and deleting them is your call. Nothing is retained beyond these operational retention windows or what law requires.
12. Liability and precedence
The limitation of liability in the Terms of Service applies to this Addendum, and to the SCCs between the parties, as one aggregate cap. On personal data, this Addendum takes precedence over anything in the Terms or the Privacy Policy that conflicts with it.
13. Governing law
The law and forum that govern the Terms of Service govern this Addendum, except where data protection law or the SCCs require otherwise.
14. Signed copies and questions
Email privacy@syncmycal.app with your legal entity name and address for a countersigned copy, or with whatever your review needs. A person answers, usually the one who wrote the sync engine.