ApexCal
Back to Home
GDPR / Privacy Compliance Schedule

Data Processing Agreement (DPA)

Effective Date: September 19, 2026 | Version 2.1

01.Scope & Controller-Processor Roles

This Data Processing Agreement ("DPA") supplements the Terms of Service between ApexCal SaaS ("Processor") and the customer entity subscribing to the platform ("Controller" or "Tenant Organization").

  • Tenant Organization (Controller): Determines the purposes and means of processing end-customer personal data submitted during appointment booking.
  • ApexCal SaaS (Processor): Processes personal data solely on documented instructions from the Controller to deliver appointment management, calendar sync, and AI receptionist services.

02.Categories of Personal Data Processed

The personal data processed under this agreement includes:

Customer IdentifiersFull name, telephone / WhatsApp number, email address, physical location.
Appointment MetadataBooking timestamps, assigned staff member, requested service, deposit status.
Staff Roster DetailsPractitioner names, business emails, working hours, shift assignments.
Communication RecordsWhatsApp AI receptionist booking conversation transcripts and reminder delivery logs.

03.Authorized Sub-Processors

The Controller provides general authorization for ApexCal to engage the following sub-processors:

Sub-ProcessorPurposeData Transferred
Stripe, Inc.Subscription billing and deposit processingBilling email, customer name, transaction totals
Twilio / Meta WhatsApp APIAutomated SMS & WhatsApp remindersCustomer phone number, appointment confirmation text
Hostinger Cloud InfrastructureServer hosting and database clusterEncrypted database storage and application hosting

04.Security Obligations & Breach Notification

ApexCal implements appropriate technical and organizational measures as detailed in our Security & Trust Center.

In the event of a confirmed personal data breach affecting Controller records, ApexCal will notify the Tenant Administrator without undue delay and within 72 hours of becoming aware of the incident.

05.Data Subject Rights & Deletion

ApexCal provides self-service tools inside the dashboard to assist Controllers in responding to data subject requests:

  • Export: Export client profiles and full appointment histories via CSV / JSON.
  • Correction: Edit customer phone numbers, names, and contact emails at any time.
  • Deletion Upon Termination: Following account closure and expiration of the 30-day grace period, all tenant records are permanently expunged from production databases.

06.DPA Execution & Inquiries

This DPA is incorporated into your online subscription agreement. Organizations requiring a customized countersigned DPA may contact our compliance team:

ApexCal Privacy & Data Protection Officer

Email: support@apexcal-saas.xilxil.com

Legal Inquiries: apexcal-saas.xilxil.com/contact