1. Who We Are
Depending on the context, CalaHQ may act either as a data controller or a data processor. We act as controller for data relating to our website, marketing, account administration, billing, support, security, and product analytics. We generally act as processor for Customer Data that business customers upload into CalaHQ to manage their teams, leave policies, calendars, and related records.
2. Data We Collect
We collect the following categories of data when you use CalaHQ:
- Account Information: Name, email address, password, and organization details when you create an account.
- Subscription & Billing Data: Company name, billing address, tax number, and payment information (processed via third-party providers such as Stripe).
- Usage Data: Log data, device type, IP address, browser type, referral information, and actions within the app for security, diagnostics, analytics, and service improvement.
- Cookie and Similar Technology Data: We use essential cookies for core site and app functions, and may use non-essential technologies through tools such as Google Tag Manager, Google Analytics, Meta Pixel, and similar analytics or advertising tools we adopt in the future.
- Customer Data: Data entered by you or your organization (e.g., employee names, leave requests, and settings). This data belongs to the Customer.
- Support Data: Information you share when contacting our support team.
3. How We Use Data
We use collected data to:
- Provide, maintain, and improve the Services.
- Process payments and manage subscriptions.
- Authenticate users and secure accounts.
- Respond to support requests and communicate updates.
- Analyze aggregated usage for performance, reliability, product decisions, and troubleshooting.
- Measure website traffic, campaign performance, and product interest where we are permitted to do so.
- Store and respect cookie and tracking preferences where required by law.
- Comply with legal obligations and enforce our Terms.
4. Legal Basis for Processing
As an EU-based company, CalaHQ processes personal data under the following lawful bases under the GDPR:
- Contractual necessity: To provide and operate the Services you’ve subscribed to.
- Legitimate interest: To improve security, analyze performance, and prevent misuse.
- Consent: For non-essential cookies, analytics, advertising or retargeting technologies, and other optional features where consent is required.
- Legal obligation: When required by applicable law or authorities.
6. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy, including to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.
- Account and workspace administration data: retained while the relevant account or customer relationship remains active.
- Customer Data: retained for the duration of the subscription and then deleted from active systems within 30 days after deletion or termination, with residual backup retention for a limited period according to our backup cycles unless the law requires otherwise.
- Billing and tax records: retained for the period required by applicable accounting and tax laws.
- Support and security records: retained as long as reasonably necessary to investigate issues, prevent abuse, and maintain the Services.
- Cookie and analytics data: retained according to the settings of the relevant tools and our internal retention practices.
7. Data Security
We use industry-standard technical and organizational measures to protect your data against loss, misuse, and unauthorized access. These include encryption in transit (HTTPS), secure data centers, and access controls. However, no online service can guarantee absolute security.
8. International Data Transfers
Your data may be processed in the European Union or other countries where our service providers operate. When transferring data outside the EU/EEA, we rely on adequate safeguards such as Standard Contractual Clauses approved by the European Commission.
9. Your Rights
Under applicable law (including GDPR), you have the following rights regarding your personal data:
- Access the data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion (“right to be forgotten”) when legally permitted.
- Restrict or object to certain processing activities.
- Request data portability.
- Withdraw consent for processing (where applicable).
To exercise your rights, contact us at support@calahq.com. We will respond within 30 days as required by law.
If we process your data on behalf of one of our business customers, you may also need to contact that customer directly, since they control how your organization uses CalaHQ.
11. Children’s Privacy
The Services are not directed to individuals under 16. We do not knowingly collect data from children. If you believe a child has provided us personal data, please contact us for deletion.
12. Changes to This Policy
We may update this Privacy Policy periodically. The “Last updated” date indicates the latest revision. Significant changes will be communicated via email or in-app notice. Continued use after updates means you accept the revised Policy.
13. Contact Us
For privacy-related questions, requests, or complaints, contact:
If you are based in the EU and believe we have not resolved your concern, you may lodge a complaint with your local data protection authority. In Latvia, the supervisory authority is the Data State Inspectorate (Datu valsts inspekcija).