GDPR · Article 28
Data Processing Agreement
The customer is controller for personal data placed in CALAPPA for workforce operations and CALAPPA is processor, except for CALAPPA’s own account, security and billing processing. Data subjects may include administrators, employees, contractors and other people managed by the customer; data categories can include identity/contact data, organizational relationship, time records, schedules, leave, documents/evidence, tasks and expenses. CALAPPA Core does not require special-category data by design.
Last updated:
CALAPPA
- hi@calappaflow.com
- Privacy / DPO
- hi@calappaflow.com
Roles and instructions
The customer is controller for personal data placed in CALAPPA for workforce operations and CALAPPA is processor, except for CALAPPA’s own account, security and billing processing. Data subjects may include administrators, employees, contractors and other people managed by the customer; data categories can include identity/contact data, organizational relationship, time records, schedules, leave, documents/evidence, tasks and expenses. CALAPPA Core does not require special-category data by design.
CALAPPA processes customer data only on documented instructions and under confidentiality obligations.
Security and subprocessors
CALAPPA applies risk-based security measures and may use vetted subprocessors for infrastructure, payments and transactional communications under equivalent data-protection obligations.
Rights and incidents
CALAPPA assists the customer, within the nature of the service, with data-subject rights and personal-data breach obligations.
End of service
At the end of the service CALAPPA provides return/export mechanisms and then deletes or blocks processor data after the exit window, unless Union or Member State law requires retention.