Data Processing Addendum

Last updated: July 1, 2026

Effective: August 1, 2026

Scope and incorporation

This Data Processing Addendum (“DPA”), including the Standard Contractual Clauses referenced below, forms part of the Terms and Conditions between the Remind1 account holder (“Customer”) and One System Software LLC (“Processor”). Together, the Terms and Conditions and this DPA form the “Agreement”. This DPA applies when the Processor processes Personal Data on the Customer’s behalf to provide Remind1. Updates affecting existing customers follow the change process in the Terms and Conditions, subject to applicable law and the Standard Contractual Clauses.

Defined Terms

  • Data Protection Laws: The EU GDPR and applicable EU/EEA member-state data protection laws, the UK GDPR and applicable UK data protection law, the Swiss Federal Act on Data Protection (FADP), and the CCPA/CPRA, in each case where applicable to processing under this DPA.
  • Personal Data: Any information relating to an identified or identifiable natural person that the Processor processes on the Customer’s behalf under this DPA.
  • CCPA / CPRA: The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, and any regulations or guidance promulgated thereunder, including amendments and successor legislation, applicable to Personal Information of California residents.
  • Standard Contractual Clauses (SCCs): Model clauses approved by the European Commission under Implementing Decision 2021/914.

Data Processing Description

Exhibit A – Data Categories & Technical/Organizational Measures

Appendix 1 – Data Processing Details (information for SCC Annex I.B)

Item Details
Data Subjects Customers and authorised calendar users whose data is processed to provide reminders, and clients, contacts and appointment participants whose personal data is included in connected calendars or reminder instructions.
Categories of Personal Data Names, email addresses and phone numbers included in reminder processing; calendar integration access and refresh tokens and related authorisation data; calendar and appointment data, including titles, dates, times, locations and video conference links; reminder content and delivery metadata; and support correspondence relating to this processing.
Special Category Data Special-category personal data is not required for ordinary use of Remind1, and the service is not designed to support it. Customers should use neutral descriptions and avoid including health or other special-category information in calendar titles, reminder messages or other fields shared with Remind1. If such information nevertheless appears, the Customer remains responsible for any required legal basis, applicable Article 9 condition and privacy notices. Remind1 processes it only on the Customer’s instructions to provide the service, applies the safeguards in Appendix 2, and deletes it under the retention schedule in Appendix 1.
Processing Purpose Providing the appointment reminder service on the Customer’s behalf, including authenticating access to connected calendars, retrieving relevant events, scheduling and delivering reminders, maintaining reminder history, adding reminder status to relevant events in connected calendars when the Customer enables calendar status updates, and providing related support.
Retention Sent-reminder history is deleted from active systems 12 months after sending. Calendar integration access and refresh tokens remain stored after a calendar is disconnected but are no longer used to access that calendar. They are deleted from active systems when the customer’s account is deleted. Following account termination, remaining personal data is deleted from active systems within 30 days, unless retention is required by law. Account termination does not extend an existing retention period. Cancelling a paid subscription does not constitute account termination and does not trigger account deletion. Existing retention periods continue to apply. Point-in-time database backups may contain personal data that has been removed from active systems. The database can be restored to an earlier state within a 14-day restore window.
Subject Matter Customer-connected calendar and appointment data, contact details, authorisation data and reminder data used to provide SMS appointment reminders, reminder history, related support and, where enabled, reminder status updates to events in connected calendars.
Nature of Processing With the Customer’s authorisation, accessing relevant events in connected calendars; retrieving and storing data needed to schedule and send reminders; scheduling and sending messages; recording reminder status, delivery metadata and sent-reminder history; where the Customer enables calendar status updates, adding reminder status to the relevant event in a connected calendar; providing related support; and deleting data under the retention schedule.
Duration of Processing Processing continues while the Customer’s Remind1 account is active. After account termination, remaining personal data is deleted from active systems within the period in the Retention row, while point-in-time database backups may remain restorable during the 14-day window described there. Any legally required retention is also governed by that row.
Transfer Frequency Transfers occur on a recurring basis while the Customer’s account and relevant calendar connection are active. This includes retrieving relevant events, processing reminders and, where the Customer enables calendar status updates, adding reminder status to those events.

Appendix 2 – Technical & Organizational Measures (Annex II)

  • Encryption: Website and app traffic is protected by HTTPS/TLS. The hosted database is encrypted at rest using AES-256.
  • Access Controls: Access to Remind1’s administration tools and customer data in the hosted database is limited by assigned roles. Administrator accounts require MFA, and authorised personnel receive only the permissions needed for service operation or customer support.
  • Data Minimization: With the Customer’s authorisation, Remind1 retrieves relevant events from connected calendars and stores only the authorisation, appointment, contact, reminder and delivery data needed to schedule and send reminders, maintain reminder history, add calendar status updates where enabled, and provide related support. Sent-reminder history is deleted according to the retention period in Appendix 1.
  • Monitoring: The hosting platform records server-side activity and errors in logs that can be reviewed when investigating incidents.
  • Backups: The hosted database is backed up automatically using point-in-time backups and can be restored to a point within the previous 14 days.
  • Incident Response: We investigate and mitigate personal-data breaches. If a breach affects data we process for a customer, we notify that customer without undue delay after becoming aware of it and provide relevant information as it becomes available.
  • Sub-processor oversight: Before a service provider processes customer reminder data, Remind1 requires a written agreement imposing data protection obligations corresponding to this DPA. Remind1 maintains the subprocessor list in Annex III, gives customers the advance notice described in “Addition of Sub-Processors,” and periodically reviews its subprocessor arrangements.

GDPR Contractual Terms

1. Sub-processor authorization:

The Processor may engage third-party service providers as subprocessors where necessary to provide the services, subject to the notification, objection, and data protection requirements in the “Addition of Sub-Processors” section of this DPA.

2. Customer obligations:

  • Establish and document a valid legal basis for collecting and processing Personal Data and sending appointment reminders.
  • Provide Data Subjects with all required privacy notices.
  • Obtain the Data Subject’s consent where required by applicable law.
  • Determine the purpose and essential means of the Processing of Personal Data in accordance with the Agreement.
  • Be responsible for the accuracy of Personal Data;
  • Comply with its obligations under applicable Data Protection Laws.

3. Processor obligations:

  • Process Personal Data only on documented instructions from the Customer, including instructions concerning international transfers, unless processing is required by EU or Member State law applicable to us. In that case, inform the Customer before processing unless that law prohibits notice on important public-interest grounds.
  • Ensure confidentiality of personnel processing data.
  • Implement security measures per Article 32 GDPR.
  • Assist Customer with data subject requests (Articles 15–22 GDPR).
  • Upon termination of the processing relationship, delete or return Personal Data at the Customer’s choice and delete existing copies, unless applicable law requires retention, in accordance with the retention provisions in Appendix 1. Cancelling a paid subscription alone does not terminate the processing relationship while the Customer’s Remind1 account remains active.
  • Make available to the Customer information needed to demonstrate compliance with Article 28 GDPR, and allow and contribute to audits or inspections by the Customer or an auditor appointed by the Customer. The parties will coordinate audits to protect security and other customers’ confidential information.
  • Immediately inform the Customer if, in our opinion, an instruction infringes applicable Data Protection Laws.
  • Assist the Customer with its security, personal-data breach, data protection impact assessment and prior-consultation obligations under Articles 32–36 GDPR, taking into account the nature of Remind1’s processing and the information available to us.

Addition of Sub-Processors

  1. Right to Engage: The Processor may engage additional sub-processors to perform processing activities under this DPA, provided that the Processor ensures each sub-processor agrees to the same data protection obligations as set forth in this DPA.
  2. Notification: We will email the Customer’s account contact at least 30 days before adding or replacing a subprocessor and update the list in Annex III. The notice will identify the proposed subprocessor, its processing activity and location, and the planned start date, so the Customer has an opportunity to object during the notice period.
  3. Objection: The Customer may object in writing to a proposed subprocessor within the 30-day notice period if it has a reasonable basis to believe that the subprocessor will not comply with applicable Data Protection Laws or the obligations in this DPA. If the Customer objects, the parties will use reasonable efforts to resolve the objection.
  4. Liability: The Processor remains fully liable to the Customer for the performance of its subprocessors’ data protection obligations in accordance with Article 28(4) GDPR. Liability under the incorporated Standard Contractual Clauses remains unaffected.

California Consumer Privacy Act (CCPA / CPRA)

Where the CCPA/CPRA applies to personal information processed on a Customer’s behalf, One System Software LLC acts as the Customer’s service provider for that processing and agrees to:

  1. Process Personal Information to authenticate access to connected calendars, retrieve relevant appointment events, schedule and send reminders, maintain reminder history, add reminder status to relevant events when the Customer enables calendar status updates, and provide related support and security, or as otherwise permitted by the CCPA/CPRA.
  2. Do not sell or share the Personal Information. Do not retain, use, or disclose it for purposes outside those in item 1 or outside the direct business relationship with the Customer, except where the CCPA/CPRA permits.
  3. Assist the Customer with requests under the CCPA/CPRA concerning Personal Information processed under this DPA, including requests to know, delete, or correct, and follow the Customer’s lawful instructions for those requests.
  4. Where a subprocessor handles Personal Information covered by this section, require it under a written contract to provide the same level of privacy protection and comply with applicable CCPA/CPRA requirements.
  5. Provide the level of privacy protection required by the applicable CCPA/CPRA rules and notify the Customer if we determine that we can no longer meet these obligations. The Customer may take reasonable steps to check our handling of the Personal Information and, on notice, to stop and remedy any unauthorised use.

International Transfers

Personal Data may be transferred from the EEA, UK, or Switzerland to the United States or other countries outside the EEA/UK/CH that do not have an adequacy decision.

  1. Standard Contractual Clauses (SCCs): For transfers governed by the EU GDPR that require them, the European Commission-approved SCCs (Module 2 or Module 3, as applicable) are incorporated into this DPA by reference. The parties select German law for Clause 17 and German courts for Clause 18(b). Data subjects’ rights under Clause 18(c) remain unaffected. Transfers governed by UK or Swiss law also require the applicable local transfer terms; incorporating the EU SCCs alone does not complete those requirements. If this DPA conflicts with applicable SCCs, the SCCs prevail.
  2. Transfer Impact Assessment (TIA): The Processor has conducted a documented assessment of the transfers described in this section. It considers the recipient country’s laws and practices, potential access by public authorities, and the protection provided by the applicable transfer terms and technical, organisational and contractual measures. For UK restricted transfers relying on the UK Addendum, the assessment also considers whether protection for people’s information would be materially lower after the transfer. Residual risks and any needed additional safeguards are addressed as described below.
  3. Technical and Organisational Measures: Remind1 applies the measures in Appendix 2 to personal data it processes in its own systems, including HTTPS/TLS, encryption of the hosted database at rest, access controls, monitoring and breach response. Subprocessors use their own technical and organisational measures; we require protection appropriate to the data they process, as described in “Sub-Processor Oversight” below.
  4. Sub-Processor Oversight: We require subprocessors involved in international transfers to meet applicable data-protection obligations and use appropriate transfer safeguards. Their technical and organisational measures may differ from those described in Appendix 2, but must provide appropriate protection for the data they process. The subprocessors covered by this DPA are listed in Annex III.
  5. Residual Risks: We document any residual risks identified in the transfer impact assessment and assess whether additional safeguards are needed. If the required level of protection cannot be ensured, we will not begin the affected transfer or will suspend it until effective safeguards are available.

Relationship between DPA Appendices and SCC Annexes:

  • Appendix 1 → information for SCC Annex I.B (description of transfer). Customer-specific party details for Annex I.A and the competent supervisory authority for Annex I.C must be completed for the relevant Customer.
  • Appendix 2 → SCC Annex II (technical and organisational measures).
  • Subprocessor list → SCC Annex III (list of subprocessors).

Official texts and copies: The EU Standard Contractual Clauses and the UK Addendum are available from their issuing authorities. On request to [email protected], we will provide the applicable transfer terms as used for the relevant Customer, including the selected modules and options and completed customer-specific annex details, subject to permitted redactions.

Limitation of Liability

Any limitations or exclusions of liability in the Agreement apply only to the extent permitted by applicable law. They do not exclude or restrict the Processor’s responsibility under Article 28(4) GDPR or contradict or undermine the liability provisions of the incorporated Standard Contractual Clauses. In the event of a conflict, those mandatory requirements and the Standard Contractual Clauses prevail.

Modification

The parties will cooperate to amend this DPA or enter into further agreements as needed to comply with Data Protection Laws.

General

  • Governing law: This DPA is governed by the laws of Germany.
  • Jurisdiction: To the extent permitted by applicable law, the courts of Germany shall have exclusive jurisdiction over disputes arising out of or in connection with this DPA, subject to the jurisdiction provisions of the incorporated Standard Contractual Clauses and applicable UK and Swiss addenda.
  • Third-party rights: This DPA does not create third-party beneficiary rights except as provided by the incorporated Standard Contractual Clauses, applicable UK and Swiss addenda, or mandatory law.

Exhibit B - UK & Swiss Addenda

UK Addendum

For restricted transfers governed by the UK GDPR, the parties incorporate the ICO-approved International Data Transfer Addendum to the EU Standard Contractual Clauses (version B.1.0) into this DPA. Where the approved UK Addendum conflicts with this DPA, the UK Addendum prevails.

UK Addendum – Part 1, Table 1 (parties): The start date for a Customer is the date this DPA becomes binding on that Customer under the Terms and Conditions. The exporter is the Customer under those Terms. Its legal name, main address, registration number (if any), and contact details are identified by the Paddle billing record linked to its Remind1 account where the billed party is the Customer, supplemented by any details the Customer supplies directly to Remind1. Where there is no matching Paddle record, the exporter is identified by the details the Customer supplies directly to Remind1. The importer is One System Software LLC, trading as Remind1, 30 N Gould St, STE R, Sheridan, WY 82801, USA. The importer’s key contact is Alexander Reger at [email protected]. These customer-specific details and the start date form the party information for this Table 1 and SCC Annex I.A and must be identifiable before the UK Addendum is relied upon for a restricted transfer.

UK Addendum – Part 1, Table 2 (selected SCCs and clauses): The approved EU Standard Contractual Clauses under Commission Implementing Decision 2021/914 apply. Module 2 applies when the Customer is a controller; Module 3 applies when the Customer is a processor. Modules 1 and 4, the optional Clause 7 docking clause, and the optional Clause 11 dispute-resolution provision are not selected. For Clause 9(a), the parties select general authorisation of subprocessors with 30 days’ advance notice of additions or replacements, as set out in this DPA. For the Table 2 question about combining personal data received from the importer with personal data collected by the exporter, the answer is Yes for Modules 2 and 3: where the Customer enables calendar status updates, Remind1 may add reminder status to the Customer’s existing appointment event in a connected calendar, combining it with the Customer’s appointment data.

UK Addendum – Part 1, Table 3 (Appendix Information): Annex I.A (list of parties): the Customer as exporter and One System Software LLC as importer, with their details specified in Table 1 for the relevant Customer. Annex I.B (description of transfer): Appendix 1 of this DPA. Annex II (technical and organisational measures): Appendix 2 of this DPA. Annex III (list of subprocessors): Annex III in Exhibit C of this DPA.

UK Addendum – Part 1, Table 4 (ending the Addendum if it changes): Both the Customer (exporter) and One System Software LLC (importer) may end the UK Addendum only in the circumstances set out in Section 19 of the approved UK Addendum.

UK Addendum – Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.

Swiss Addendum

For transfers from Switzerland governed by the Swiss Federal Act on Data Protection (FADP), the EU Standard Contractual Clauses incorporated into this DPA apply with these Swiss adaptations:

  • References to the GDPR are read as references to the FADP where the transfer is governed by the FADP.
  • The Federal Data Protection and Information Commissioner (FDPIC) is the competent supervisory authority for transfers governed by the FADP. If the GDPR also applies, the competent EU supervisory authority remains responsible for the GDPR aspects.
  • The German law and courts selected in the SCCs remain applicable between the parties. A data subject habitually resident in Switzerland may also bring a claim in the Swiss courts under Clause 18(c).

Exhibit C – Standard Contractual Clauses and Transfer Details

Annex I – Description of Transfer

The EU Standard Contractual Clauses approved under Commission Implementing Decision 2021/914 are incorporated into this DPA for transfers that require them. Module 2 applies when the Customer is a controller; Module 3 applies when the Customer is a processor. The Customer is the data exporter and One System Software LLC is the data importer. Appendix 1 describes the data and processing, Appendix 2 describes the security measures, and Annex III lists the subprocessors. The parties’ customer-specific details and the competent supervisory authority must be completed for the relevant Customer before the SCCs are relied upon as a transfer safeguard.

Annex I.A – Parties, Activities, Roles and Agreement Date

Under Module 2, the Customer is the data exporter and acts as controller, and One System Software LLC is the data importer and acts as processor. Under Module 3, the Customer is the data exporter and acts as processor on behalf of its controller, and One System Software LLC is the data importer and acts as processor and, in relation to the Customer, as its subprocessor. The parties’ identities and contact details are the customer-specific details described in UK Addendum Table 1, and their activities relevant to the transfer are described in Appendix 1. The Customer agrees to the incorporated Standard Contractual Clauses by accepting the linked Terms and this DPA in the Remind1 pre-installation flow. One System Software LLC agrees to them by providing Remind1 under those Terms. For the signature and date fields in Annex I.A, the parties treat that binding agreement as their electronic execution of Annex I.A on the date this DPA becomes binding on the Customer under the Terms.

Annex I.C – Competent Supervisory Authority

For a Customer established in the EEA, the competent supervisory authority is the authority responsible for overseeing that Customer’s GDPR compliance concerning the transfer, including its lead supervisory authority where applicable. For a Customer outside the EEA but directly subject to the GDPR, the authority is determined under Clause 13 by the location of the Customer’s EU representative or, where no representative is required, the location of the relevant data subjects. The specific authority for the Customer must be identified in the Customer-specific transfer details before the EU Standard Contractual Clauses are relied upon for that transfer.

Annex II – Technical & Organizational Measures

  • See Appendix 2

Annex III – List of Sub-Processors

Sub-Processor Address Processing Activity Location
AC PM, LLC 1 N Dearborn Street, Suite 500, Chicago, IL 60602, USA Email delivery USA
Bird B.V. Keizersgracht 268, 1016 EV, Amsterdam, The Netherlands SMS delivery The Netherlands
Bubble Group, Inc. 22 West 21st Street, Floor 2, New York, NY 10010, USA Cloud hosting/infrastructure USA

Customer-connected calendar providers

Customers may connect calendars provided by Google or Microsoft. With the Customer’s authorisation, Remind1 retrieves relevant events from those calendar services to provide reminders and, where the Customer enables calendar status updates, adds reminder status to relevant events. Remind1 does not engage Google or Microsoft as subprocessors for the customer reminder-data processing covered by this DPA. The connected calendar services remain subject to their providers’ applicable terms and privacy notices.

Payment Providers Outside This DPA

Paddle.com Market Limited and Paddle.com Inc. provide payment services for Remind1 subscriptions. They are not engaged as subprocessors for the customer reminder-data processing covered by this DPA. Payment-related processing is described in our Privacy Policy and Paddle’s applicable privacy policy.