Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Subscriber," "Controller") and Calisto ("Processor," "we," "us") for the provision of Calisto platform services. It governs the personal data that you, as a data controller, instruct Calisto to process on your behalf through the platform. This DPA supplements the Terms of Service and the Privacy Policy.
This DPA has two parts. Part 1 applies to every subscriber. Part 2 contains terms that apply only where a specific data protection law governs the Subscriber Data being processed. You receive the terms of Part 2 only to the extent that law applies to you.
PART 1 — BASE TERMS (ALL SUBSCRIBERS)
1. Parties
Subscriber (Controller): The entity or individual that has activated a Calisto account and subscribes to Calisto services that involve the processing of personal data belonging to the Subscriber's own customers, contacts, guests, employees, or other data subjects.
Calisto (Processor): North Coast Vacations, Inc., RNC 132-08055-6, Pedro Clisante 73, Sosúa, Puerto Plata, Dominican Republic.
2. Scope and Roles
2.1. When you use Calisto services to collect, store, or manage personal data about your own customers, contacts, guests, members, employees, or other individuals (collectively, "Subscriber Data"), you act as the data controller and Calisto acts as your data processor.
2.2. This DPA applies exclusively to Subscriber Data processed by Calisto on your behalf. It does not apply to personal data that Calisto collects and controls independently (such as your own account information), which is governed by the Privacy Policy.
2.3. Data that resides entirely on infrastructure you operate and is never transmitted to Calisto is outside the scope of this DPA. Calisto does not process data it never receives.
3. Subscriber-Operated Infrastructure (Bring Your Own Backend)
3.1. Calisto allows subscribers to connect their own backend infrastructure to the Calisto platform ("Subscriber Infrastructure"). When you do so, this section applies in addition to the rest of this DPA.
3.2. Responsibility. You are solely responsible for the security, availability, configuration, patching, access control, and regulatory compliance of your own infrastructure. Calisto's security measures described in §8 apply exclusively to infrastructure operated by Calisto. Calisto does not monitor, audit, or manage Subscriber Infrastructure.
3.3. Scope. When Subscriber Data is stored on or processed through your own infrastructure, you act as both data controller and infrastructure operator for that data. Calisto's obligations under this DPA apply only to Subscriber Data that transits through, is cached on, or is stored on Calisto-operated systems.
3.4. Data in transit. When data flows between Calisto-operated systems and Subscriber Infrastructure, Calisto secures the Calisto side of the connection (encryption in transit, authentication, access logging). You are responsible for securing your side. Both parties use TLS 1.2 or higher for data in transit between systems.
3.5. Breaches on your infrastructure. Any breach notification obligation of Calisto under Part 2 applies only to breaches on Calisto-operated infrastructure. For a breach on Subscriber Infrastructure, you are responsible for detection, notification to affected data subjects and authorities, and remediation.
3.6. Termination. Upon termination, Calisto deletes Subscriber Data held on Calisto-operated infrastructure per §9 and revokes all API credentials and access tokens connecting your infrastructure to the platform. Data stored on your own infrastructure is your responsibility to delete.
3.7. Compliance. If you operate infrastructure in a jurisdiction with specific data protection requirements, you are responsible for ensuring your infrastructure meets them. Calisto does not verify or warrant the compliance posture of Subscriber Infrastructure.
4. Categories of Data and Data Subjects
4.1. The categories of personal data processed depend on how you configure and use the platform. They include:
- Identification data: names, email addresses, phone numbers, postal addresses
- Transaction data: booking records, purchase history, payment references, invoices
- Communication data: messages, support tickets, call recordings, email correspondence
- Technical data: IP addresses, device identifiers, session logs, access timestamps
- Employment data: staff records, schedules, performance records (if you use workforce features)
- Property and asset data: unit details, ownership records, occupancy information
- Custom data: any additional personal data you choose to collect through Calisto forms, fields, or integrations
4.2. Data subjects include your customers, guests, tenants, members, patients, clients, employees, contractors, and any other individuals whose personal data you input, import, or collect through the platform.
5. Processing Instructions
5.1. Your instructions to Calisto are defined by your use of the platform: the applications you activate, the integrations you enable, the automation rules you configure, and the data you input.
5.2. Calisto processes Subscriber Data only to provide the platform services you have activated, unless the law requires otherwise.
6. Confidentiality
Calisto ensures that all personnel authorised to process Subscriber Data are bound by obligations of confidentiality, whether contractual or statutory.
7. Sub-Processors
7.1. You authorise Calisto to engage sub-processors to process Subscriber Data.
7.2. Calisto engages the following categories of sub-processors:
- Intra-group processors: Calisto Philippines for back-office and help-desk services
- Infrastructure providers: hosting, cloud computing, content delivery, and database services
- Payment processors: for the processing of financial transactions initiated through the platform
- Identity verification providers: for KYC, document verification, and compliance screening
- Communication providers: for email delivery, SMS, telephony, and messaging services
- Analytics and monitoring: for platform performance, error tracking, and security monitoring
7.3. Calisto imposes data protection obligations on each sub-processor by written contract.
8. Security Measures
8.1. Calisto implements and maintains the following technical and organizational security measures for the protection of Subscriber Data:
- Encryption: TLS 1.2+ in transit; AES-256 or equivalent at rest for stored Subscriber Data
- Access control: role-based access, least-privilege principles, multi-factor authentication for all staff and contractor access to systems containing Subscriber Data
- Network security: firewalls, intrusion detection, DDoS mitigation, and network segmentation
- Infrastructure: self-hosted infrastructure with data residency controls; no default reliance on third-party public cloud for primary Subscriber Data storage. These measures apply to Calisto-operated infrastructure only; Subscriber Infrastructure under §3 is outside the scope of these controls
- Personnel: staff and contractor confidentiality agreements
- Vulnerability management: regular vulnerability scanning and patching
- Business continuity: automated backups, disaster recovery procedures, and redundancy across data centres
- Logging and monitoring: audit logs of access to Subscriber Data, security event monitoring, and anomaly detection
8.2. Calisto reviews and updates its security measures to reflect changes in technology, threats, and regulatory requirements.
9. Return and Deletion
9.1. You can export your Subscriber Data at any time through the platform's data export tools before account closure.
9.2. Upon termination, Calisto deletes Subscriber Data held on Calisto-operated infrastructure, unless the law requires retention. This obligation is not conditional on payment status. Calisto retains only anonymised or aggregated metadata necessary for legal compliance and platform operations, as described in the Privacy Policy.
10. Data Location
Subscriber Data is stored in the European Union, primarily in Germany, France, and Sweden, and is accessed from the Dominican Republic and the Philippines.
11. Term
This DPA takes effect when you activate Calisto services that involve the processing of Subscriber Data and remains in effect for the duration of your use of those services.
12. Liability
12.1. Liability under this DPA is subject to the limitations set out in the Terms of Service.
12.2. Nothing in this DPA limits either party's liability to the extent such liability cannot be limited by contract under applicable law.
13. Governing Law and Jurisdiction
13.1. This DPA is concluded in the Dominican Republic and is governed by the laws of the Dominican Republic, except where a law listed in Part 2 requires the application of a different law, and then only to the extent required.
13.2. Any dispute arising under this DPA is resolved in the courts of Santo Domingo, Dominican Republic, except where a law listed in Part 2 requires otherwise.
14. Conflict
If this DPA conflicts with the Terms of Service or any other agreement between you and Calisto, this DPA prevails with respect to the processing of Subscriber Data. Within this DPA, a section of Part 2 prevails over Part 1 where that section applies.
PART 2 — JURISDICTION-SPECIFIC TERMS
15. European Union, European Economic Area, and Switzerland
This section applies where Regulation (EU) 2016/679 ("GDPR") or the Swiss Federal Act on Data Protection applies to the processing of Subscriber Data.
15.1. EU representative. Calisto's representative under Article 27 GDPR is LUNA LIMPIEZAS NORTH COAST SL, registration number B72574890, C/ Zurbano 45 1º, 28010 Madrid, Spain.
15.2. Standard contractual clauses (controller to processor). The standard contractual clauses between controllers and processors adopted by Commission Implementing Decision (EU) 2021/915 are incorporated into this DPA by reference and completed as follows:
- Annex I (parties): Section 1 of this DPA and §15.1
- Annex II (description of processing): nature and purpose — hosting and processing Subscriber Data to provide the platform services you activate; categories of data and data subjects — Section 4; duration — Section 11; location — Section 10
- Annex III (technical and organisational measures): Section 8
- Clause 7.7 (sub-processors): Option 2, general written authorisation, with notice of intended changes given at least thirty (30) days in advance
Where these clauses conflict with any other part of this DPA, these clauses prevail.
15.3. Sub-processor objection. You can object to a new sub-processor by notifying Calisto in writing within fourteen (14) days of receiving notice. If Calisto cannot accommodate the objection, either party can terminate the affected services without penalty upon thirty (30) days' notice.
15.4. Breach notification. Calisto notifies you of a personal data breach affecting Subscriber Data without undue delay after becoming aware of it.
15.5. International transfers. Where Subscriber Data is transferred to a country without an adequacy decision, the transfer is governed by the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 (Module Two, controller to processor), incorporated by reference. For transfers subject to Swiss law, those clauses apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner.
15.6. Data subject requests. If Calisto receives a request directly from one of your data subjects, Calisto redirects it to you.
16. United Kingdom
This section applies where the UK GDPR applies to the processing of Subscriber Data.
16.1. Section 15 applies, with references to the GDPR read as references to the UK GDPR.
16.2. International transfers are governed by the International Data Transfer Addendum to the EU standard contractual clauses issued by the UK Information Commissioner, incorporated by reference.
17. Brazil
This section applies where Law No. 13,709/2018 ("LGPD") applies to the processing of Subscriber Data.
17.1. Calisto processes Subscriber Data according to your instructions and the LGPD.
17.2. International transfers of Subscriber Data are governed by the standard contractual clauses approved by the Autoridade Nacional de Proteção de Dados (ANPD), incorporated by reference.
17.3. Calisto notifies you of a security incident affecting Subscriber Data without undue delay after becoming aware of it.
17.4. Section 15.3 (sub-processor objection) applies.
18. United States
This section applies where the California Consumer Privacy Act (as amended by the California Privacy Rights Act) or another US state consumer privacy law applies to the processing of Subscriber Data.
18.1. Service provider terms. Calisto acts as your service provider or processor. Calisto:
- processes Subscriber Data only for the business purpose of providing the platform services you activate
- does not sell or share Subscriber Data
- does not retain, use, or disclose Subscriber Data outside the direct business relationship with you
- does not combine Subscriber Data with personal data it receives from other sources, except as the law permits
- provides the level of privacy protection the applicable law requires
- notifies you if it determines it can no longer meet its obligations under the applicable law
18.2. You can take reasonable steps to stop and remediate any unauthorized use of Subscriber Data by Calisto.
18.3. Where a state law requires it, Calisto makes available the information necessary to demonstrate compliance, allows reasonable assessments, and gives you notice of new sub-processors and an opportunity to object.
18.4. Breach notification. Where a state breach notification law applies to a breach of personal information as that law defines it, Calisto notifies you as that law requires.
19. All Other Countries
Where the data protection law of a country not listed in this Part 2 applies to Subscriber Data and requires processor terms that this DPA does not contain, Calisto complies with those mandatory terms, and only to the extent that law requires.
CONTACT
Support: https://pro.calistoco.com/support/tickets
Mail: North Coast Vacations, Inc., Pedro Clisante 73, Sosúa, Puerto Plata, Dominican Republic