Data Processing Addendum
Last updated August 24, 2026
This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Terms of Service and any other written or electronic agreement between UTC Labs ("we", "us") and the customer identified in the Account ("Customer", "you") under which we provide the Service (together, the "Agreement").
This DPA governs the processing of Personal Data by UTC Labs as Processor on behalf of Customer as Controller, in connection with Customer's use of the Service. It reflects the parties' agreement with respect to the Processing of Personal Data and applies to the extent that EU/UK/Swiss Data Protection Laws or other applicable Data Protection Laws apply to that Processing.
This DPA takes effect when you accept the Terms of Service. By using the Service, you accept this DPA on your own behalf and, where applicable, on behalf of the Customer entity you represent. No countersignature is required, but Customers that need a counter-signed copy may request one at contact@utclabs.com.
In the event of any conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA prevails. The Annexes form an integral part of this DPA.
1. Definitions
Capitalized terms not defined in this DPA have the meaning given to them in the Agreement. For the purposes of this DPA:
- "Customer Personal Data" means Personal Data that UTC Labs Processes on behalf of Customer in the course of providing the Service, as further described in Annex 1.
- "Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including (i) Regulation (EU) 2016/679 ("GDPR"), (ii) the UK Data Protection Act 2018 and the UK GDPR ("UK GDPR"), (iii) the Swiss Federal Act on Data Protection ("FADP"), (iv) the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and (v) any other applicable equivalent or successor laws.
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Special Categories of Personal Data" have the meanings given to them in the GDPR.
- "Sub-processor" means any third party engaged by UTC Labs that Processes Customer Personal Data on UTC Labs' behalf in connection with the Service.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data Processed by UTC Labs or its Sub-processors. Security Incident does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as unsuccessful log-in attempts, pings, port scans, denial-of-service attacks, or other network attacks on firewalls or networked systems.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries pursuant to GDPR, as set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, version B1.0, in force 21 March 2022.
- "End User" has the meaning given in the Terms of Service: a user of Customer's Application, or any person on whose behalf a calendar account is connected to the Service through Customer's Application.
2. Scope and Roles of the Parties
Customer is the Controller and UTC Labs is the Processor for the Personal Data Customer submits to or generates through the Service, including Personal Data of Customer's End Users whose calendar accounts are connected to the Service through Customer's Applications ("Customer Personal Data"). Where Customer is itself a Processor acting on behalf of a third-party Controller, UTC Labs acts as a Sub-processor and Customer warrants that it has the authority of the underlying Controller to enter into this DPA.
UTC Labs will Process Customer Personal Data only on documented instructions from Customer, including with regard to international transfers, except where required to do so by applicable law. The Agreement (including this DPA, the Service documentation, the Customer's configuration of the Service and its Applications, and the API requests issued by Customer's Applications) constitutes Customer's complete and final documented instructions to UTC Labs for the Processing of Customer Personal Data. Additional or alternate instructions must be agreed in writing.
UTC Labs will inform Customer if, in its opinion, an instruction infringes applicable Data Protection Laws, without obligation to monitor Customer's compliance with those laws.
This DPA applies only to UTC Labs' Processing of Customer Personal Data on Customer's behalf as Processor. UTC Labs separately Processes Personal Data as an independent Controller, including Customer's own Account, billing, and contact information; authentication, security, and fraud-prevention metadata used to operate and secure the Service; product analytics UTC Labs uses to operate and improve the Service; and UTC Labs' own marketing communications sent with the recipient's separate consent. That separate Processing is described in, and governed by, our Privacy Policy, not this DPA.
UTC Labs will not use Customer Personal Data to train or fine-tune artificial-intelligence or machine-learning models without Customer's express prior permission.
3. Customer Obligations
Customer is responsible for the lawfulness of Customer Personal Data and the means by which Customer acquired it. Customer warrants that it has all necessary rights, lawful bases, consents, and authorizations to Process Customer Personal Data and to instruct UTC Labs to Process Customer Personal Data on Customer's behalf as described in the Agreement and this DPA, including in connection with the calendar credentials and calendar data of End Users whose accounts are connected through Customer's Applications.
Customer is responsible for providing all required notices to, and obtaining all required consents from, Data Subjects (including End Users) in respect of Customer's Processing of their Personal Data through the Service.
Customer will not submit, and will use reasonable efforts to prevent its End Users from submitting, Special Categories of Personal Data or data subject to special legal regimes that the Service is not designed to handle, as described in the Terms of Service (including but not limited to data subject to HIPAA or GLBA). UTC Labs is not liable for the Processing of any such data submitted to the Service in breach of this restriction.
Customer acknowledges that the Service depends on third-party calendar providers and that the End Users' authorization of those providers, the data made available by them, and their continued availability are outside UTC Labs' control.
4. Sub-processors
Customer provides UTC Labs with general written authorization to engage Sub-processors to Process Customer Personal Data in connection with providing the Service.
UTC Labs maintains a current list of its Sub-processors, including the name, role, and primary location of each Sub-processor, on the Sub-processors page. Customer may consult that list at any time. View the Sub-processors page.
UTC Labs will give Customer prior notice of the addition or replacement of any Sub-processor by updating the Sub-processors page at least 30 days before the change takes effect.
Customer may object to UTC Labs' appointment of a new Sub-processor on reasonable data-protection grounds by notifying UTC Labs in writing at contact@utclabs.com within 14 days of the notice. If Customer objects, the parties will work together in good faith to resolve the objection. If no resolution can be reached within a reasonable period, Customer may, as its sole remedy, terminate the affected subscription and receive a pro-rata refund of any Subscription Fees prepaid for the period after termination.
UTC Labs will enter into a written agreement with each Sub-processor that imposes data-protection obligations no less protective of Customer Personal Data than those imposed on UTC Labs under this DPA. UTC Labs remains liable to Customer for the performance of each Sub-processor's obligations under such agreement to the extent provided for in the Agreement.
5. International Data Transfers
UTC Labs' primary processing infrastructure for Customer Personal Data is located in the United States. UTC Labs may also need to Process Customer Personal Data anywhere else in the world where UTC Labs or its Sub-processors maintain operations.
Where UTC Labs Processes Customer Personal Data subject to the GDPR in a country that is not the subject of a European Commission adequacy decision, the parties incorporate the Standard Contractual Clauses (Module Two: Controller to Processor) into this DPA by reference, with the parties' details, the description of the transfer, and the technical and organizational measures completed as set out in Annex 3, with the following selections: (i) the optional docking clause (Clause 7) applies; (ii) for sub-processor changes, Option 2 (general written authorization) applies with the notice period set out in Section 4; (iii) Clause 17 (governing law) is governed by the law of Ireland; (iv) the forum and jurisdiction under Clause 18 are the courts of Ireland; and (v) Annex I.C identifies the Irish Data Protection Commission as the competent supervisory authority.
Where Customer Personal Data is subject to the UK GDPR, the parties incorporate the UK Addendum into this DPA, with the SCCs above as the "Approved EU SCCs" referenced in the UK Addendum, and with Tables 1 to 3 completed by reference to Annex 3. Either party may end the UK Addendum as set out in Section 19 of the UK Addendum.
Where Customer Personal Data is subject to the FADP, the SCCs apply with the following modifications: (a) references to the GDPR are read as references to the FADP where the FADP applies; (b) the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for transfers exclusively subject to the FADP; and (c) the term "Member State" is interpreted not to exclude Data Subjects in Switzerland from exercising rights in their place of habitual residence.
If a competent supervisory authority or court invalidates or limits the SCCs, UK Addendum, or any other transfer mechanism relied on under this DPA, UTC Labs and Customer will cooperate in good faith to adopt a replacement transfer mechanism that complies with applicable Data Protection Laws.
6. Security
UTC Labs will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the Processing, and the risk to Data Subjects. A current summary of those measures is set out in Annex 2.
UTC Labs will ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and have received training on their data-protection responsibilities, and will limit access to Customer Personal Data to personnel who need that access to perform their role.
UTC Labs may update its technical and organizational measures from time to time provided that the updated measures do not materially reduce the level of protection of Customer Personal Data.
7. Security Incident Notification
UTC Labs will notify Customer without undue delay and, where feasible, no later than seventy-two (72) hours after becoming aware of a Security Incident affecting Customer Personal Data.
Each notification will include, to the extent then known to UTC Labs: (a) a description of the nature of the Security Incident, including, where possible, the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences of the Security Incident; (c) the measures taken or proposed to address the Security Incident and to mitigate its possible adverse effects; and (d) a contact point at UTC Labs from which further information can be obtained. Where information cannot be provided at the same time, UTC Labs will provide it in stages without further undue delay.
UTC Labs will provide Customer with reasonable assistance to enable Customer to comply with its own notification obligations under applicable Data Protection Laws (including notifications to supervisory authorities and to affected Data Subjects).
UTC Labs' notification of, or response to, a Security Incident under this Section is not an acknowledgement by UTC Labs of any fault or liability with respect to the Security Incident.
8. Data Subject Requests and Cooperation
Taking into account the nature of the Processing, UTC Labs will provide reasonable assistance to Customer, through appropriate technical and organizational measures and insofar as possible, to enable Customer to fulfil its obligation to respond to requests from Data Subjects to exercise their rights under applicable Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, and objection).
If a Data Subject contacts UTC Labs directly with a request relating to Customer Personal Data, UTC Labs will, without undue delay, inform the Data Subject that the request should be addressed to Customer, or, where the Data Subject's identifying details allow UTC Labs to do so, forward the request to Customer. UTC Labs will not respond to such a request on Customer's behalf except on Customer's documented instructions.
Taking into account the nature of the Processing and the information available to it, UTC Labs will provide Customer with reasonable assistance with the obligations under Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities), at Customer's expense for any out-of-pocket costs incurred by UTC Labs beyond those reasonably included in the Service.
9. Records and Audits
UTC Labs will maintain records of Processing activities carried out on Customer's behalf as required by Article 30(2) of the GDPR.
UTC Labs will make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and the obligations of a Processor under Article 28 of the GDPR. In the first instance, Customer's audit right is satisfied by UTC Labs providing: (a) this DPA and the description of technical and organizational measures set out in Annex 2; (b) copies of UTC Labs' then-current third-party certifications, attestations, penetration-test summaries, or audit reports, where available; and (c) reasonable written responses to a standard security questionnaire covering the matters set out in Annex 2, in each case subject to reasonable confidentiality obligations.
If the information provided under the preceding paragraph is not, in Customer's reasonable assessment, sufficient to demonstrate compliance with a specific obligation under this DPA, Customer may submit a written request to contact@utclabs.com identifying the matter to be addressed and the additional information required. UTC Labs will respond in writing within a reasonable period and in any event within thirty (30) days of receipt, providing further information, clarifications, or evidence reasonably available to it, subject to reasonable confidentiality obligations and to any restrictions arising from UTC Labs' obligations to third parties, the protection of other customers' data, or the protection of UTC Labs' trade secrets.
If, following completion of the steps in the preceding paragraphs, Customer reasonably believes that the information provided is still insufficient to demonstrate compliance with a specific obligation under this DPA, Customer may, at its expense, conduct an audit of UTC Labs' data-protection compliance limited to that specific matter, no more than once per twelve-month period (except where required by a supervisory authority or after a Security Incident), subject to: (a) at least sixty (60) days' prior written notice; (b) execution of a confidentiality agreement reasonably acceptable to UTC Labs; (c) the audit being conducted during regular business hours, in a manner that does not interfere with UTC Labs' operations, and not extending to data of any other customer, trade secrets, or any system to which access would breach UTC Labs' obligations to third parties; and (d) the auditor being a reputable independent third party that is not a competitor of UTC Labs and that has entered into the confidentiality agreement referenced above. The parties will share the audit results and discuss any findings in good faith.
10. Return and Deletion of Customer Personal Data
Customer may remove Customer Personal Data through the Service's functionality at any time during the term of the Agreement: removed End User calendar connections are no longer used and are permanently erased when the relevant Application or Organization is deleted, and Customer may delete Applications and Organizations at any time. For data export requests, Customer may contact UTC Labs at contact@utclabs.com.
On termination or expiry of the Agreement, UTC Labs will, at Customer's choice, delete or return all Customer Personal Data to Customer, and delete any existing copies, except to the extent that applicable law requires UTC Labs to retain the Personal Data, or where the Personal Data is retained in routine encrypted backups that are cycled out and deleted in the ordinary course of UTC Labs' backup-retention practices.
When the Agreement is terminated, including when Customer deletes their account through the Service, UTC Labs promptly deletes Customer Personal Data from active production systems. Backup copies are purged as those backups are cycled out in the ordinary course of UTC Labs' backup-retention practices (typically within seven (7) days). Financial records of record are held by UTC Labs' merchant of record under its own statutory retention periods, and are not retained by UTC Labs.
11. Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations of liability set out in the Agreement, and any reference in the Agreement to a party's liability means the aggregate liability of that party under the Agreement and this DPA together. Nothing in this DPA limits or excludes any liability that cannot be limited or excluded under applicable law, including liability under Article 82 of the GDPR.
Customer will not bring duplicative claims under both the Agreement and this DPA in respect of the same loss.
12. California Consumer Privacy Act
Where UTC Labs Processes Personal Data of California residents on Customer's behalf, UTC Labs acts as Customer's "service provider" within the meaning of the CCPA. UTC Labs will: (a) Process such Personal Data only for the limited and specified business purposes set out in this DPA and the Agreement; (b) not Sell or Share such Personal Data (as those terms are defined in the CCPA); (c) not retain, use, or disclose such Personal Data outside the direct business relationship between Customer and UTC Labs, or for any commercial purpose other than the business purposes set out in this DPA, except as permitted by the CCPA; and (d) not combine such Personal Data with Personal Data received from any other person, except as permitted by the CCPA.
UTC Labs certifies that it understands the restrictions set out in this Section and will comply with them.
13. General
This DPA takes effect on the date Customer accepts the Agreement and remains in force for as long as UTC Labs Processes Customer Personal Data, including after termination of the Agreement to the extent of any continued Processing necessary to give effect to Section 10 (Return and Deletion).
UTC Labs may update this DPA from time to time, including to reflect changes in applicable Data Protection Laws, transfer mechanisms, or UTC Labs' operations. We will give notice of material changes as described in the Terms of Service. Updates that are required by applicable law, by a supervisory authority, or to reflect a replacement transfer mechanism take effect on the date specified in the notice without requiring further action by Customer.
If any provision of this DPA is found by a court of competent jurisdiction to be invalid or unenforceable, the remaining provisions remain in full force and effect.
Questions about this DPA, requests for a counter-signed copy, requests for an executed copy of the SCCs, or notices required under this DPA may be sent to UTC Labs at contact@utclabs.com.
Annex 1: Description of the Processing
Subject matter
UTC Labs Processes Customer Personal Data as necessary to provide the Service in accordance with the Agreement and Customer's documented instructions, including any features and functionality made available to Customer from time to time.
Duration
For the term of the Agreement, plus the post-termination retention period set out in Section 10.
Nature and purpose
Processing activities include hosting, storing, transmitting, backing up, securing, and otherwise handling Customer Personal Data as reasonably necessary to serve the API requests issued by Customer's Applications, deliver outbound webhooks, and otherwise deliver, support, and improve the Service in accordance with the Agreement and Customer's instructions. Calendar event content is read from and written to the connected calendar providers on a per-operation basis and is not persistently stored by the Service.
Categories of Data Subjects
- Customer's authorized users: account holders and members of Customer's Organization who use the Service.
- Customer's End Users: users of Customer's Applications whose calendar accounts are connected to the Service, and other persons whose Personal Data appears in the calendar data processed through the API (such as event attendees).
Categories of Personal Data
- Identification and contact data: such as name and email address of authorized users, and the email address of End Users' connected calendar accounts.
- Account and Organization data: account and membership information for authorized users, such as role assignments and invitation status.
- Calendar connection credentials: OAuth access and refresh tokens, application-specific passwords, provider account identifiers, granted scopes, and connection status for End Users' connected calendar accounts, together with any external identifier Customer's Application assigns to an End User.
- Calendar data: Personal Data contained in calendar and event details as exposed by the connected calendar providers, processed on a per-operation basis to serve Customer's API requests and not persistently stored.
- Integration data: identifiers and event types contained in outbound webhook messages delivered to Customer-provided endpoints, and other Personal Data transmitted through Customer's use of the API.
- Support communications: messages and attachments exchanged with UTC Labs' support channels.
Special categories of Personal Data
The Service is not intended for, and Customer warrants that it will not submit, Special Categories of Personal Data (Article 9 GDPR) or data subject to HIPAA or GLBA. To the extent any such data is submitted in breach of that restriction, it is not part of the Processing contemplated by this DPA.
Frequency of the Processing
Continuous, for the duration of the Agreement.
Retention
As set out in Section 10 of this DPA and in our Privacy Policy.
Annex 2: Technical and Organizational Measures
UTC Labs implements technical and organizational measures designed to protect Customer Personal Data in line with Article 32 of the GDPR, including: encryption of Personal Data in transit (TLS) and at rest; application-layer encryption of End User calendar passwords in addition to encryption at rest; private, network-isolated production databases hosted on AWS; role-based access controls and the principle of least privilege for personnel; storage of API keys in hashed form only; rate limiting on the API; automated encrypted backups; automated dependency vulnerability scanning; a documented incident-response procedure; and the execution of data-processing agreements with each Sub-processor. UTC Labs may update these controls from time to time provided that any update does not materially reduce the overall level of protection of Customer Personal Data.
Annex 3: Annexes to the Standard Contractual Clauses
This Annex 3 completes the annexes to the Standard Contractual Clauses where they are incorporated under Section 5 of this DPA.
A. List of Parties
Data exporter: Customer, identified in its Apiroc Account, acting as Controller, with the contact details Customer provides in its Account.
Data importer: UTC Labs, Durana Tech Park, Rruga Ahmet Zogu, nr. pasurisë 336, ZK 3852, njësia administrative Xhafzotaj, Bashkia Shijak, kodi postar 2013, Albania, acting as Processor. Contact: contact@utclabs.com.
B. Description of Transfer
The categories of Data Subjects, categories of Personal Data, special categories of data (none, as set out in Annex 1), nature and purpose of the Processing, frequency, duration, and retention are set out in Annex 1.
C. Competent Supervisory Authority
For transfers subject to the GDPR: the Irish Data Protection Commission (21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland). For transfers subject to the UK GDPR: the UK Information Commissioner's Office. For transfers subject only to the FADP: the Swiss Federal Data Protection and Information Commissioner.
II. Technical and Organisational Measures
The technical and organizational measures applied by the data importer are set out in Annex 2.
III. List of Sub-processors
The current list of authorized Sub-processors is published on our Sub-processors page.
