Back to home

Legal

Data Processing Agreement

Last updated: 6 July 2026 · Version 1.1
This Data Processing Agreement ("DPA") is between SpaceStatus ("Processor") and the Customer ("Controller"). It forms part of the Terms of Service and takes effect automatically when you use SpaceStatus in a way that involves processing personal data on your behalf. This is required under GDPR Article 28 and the Swiss nFADP.

1. What this covers and how long it lasts

SpaceStatus processes personal data on the Customer's behalf only to provide the room display service described in the Terms of Service. Processing starts when you subscribe and stops when your account is terminated.

2. What we do with the data

SpaceStatus acts as a data processor when it reads and displays Microsoft 365 room calendar data on your behalf. More specifically, SpaceStatus:

  • Reads room resource calendar data via the Microsoft Graph API on your behalf
  • Renders room availability status, current meeting titles, and booking times on paired displays
  • Stores room list metadata (room names, building, floor) to build board configurations

SpaceStatus does not profile, build models from, or run analytics on personal data processed under this DPA.

3. What types of personal data are involved

The personal data processed under this DPA may include:

  • Calendar event subjects (meeting titles), which may contain names or other identifiers
  • Start and end times of calendar bookings
  • Room resource email addresses (these are typically system accounts, not personal emails)
  • Room metadata such as display names, building, floor, and capacity

We do not access attendee lists, meeting body text, attachments, personal mailboxes, or any calendar data outside of room resources.

4. Whose data is affected

The people whose data may be incidentally processed are employees or contractors of the Customer organisation whose names or identifiers happen to appear in meeting titles shown on room displays.

5. What SpaceStatus commits to as Processor

SpaceStatus undertakes to:

  • Process personal data only according to documented instructions from the Controller, as set out in the Terms of Service and this DPA, unless the law requires otherwise
  • Make sure anyone with access to the personal data is bound by confidentiality obligations
  • Put in place appropriate technical and organisational security measures, as described in Section 8
  • Not bring in any new sub-processor without prior written authorisation from the Controller (by accepting this DPA you give general authorisation for the sub-processors listed in Section 7)
  • Help the Controller respond to data subject rights requests, to the extent that is technically possible
  • Help the Controller with security obligations, breach notifications, data protection impact assessments, and prior consultation duties, where applicable
  • Delete or return all personal data at the end of the service relationship, at the Controller's choice
  • Make all information needed to demonstrate GDPR Article 28 compliance available and allow for audits

6. What the Customer commits to as Controller

The Customer, as data controller, undertakes to:

  • Make sure there is a lawful basis for processing under GDPR before using SpaceStatus
  • Make sure employees are appropriately informed that meeting titles may appear on shared room displays
  • Configure the Microsoft 365 tenant so that SpaceStatus can only access room resource calendars
  • Let SpaceStatus know about any changes to processing instructions that affect what is described in this DPA

7. Sub-processors

By accepting this DPA, the Customer gives general written authorisation for SpaceStatus to use the following sub-processors:

Sub-processorPurposeLocation
Microsoft CorporationMicrosoft Graph API, calendar data retrievalEU / Global
Stripe Payments Europe LtdPayment processing, invoicing, subscription billingEU / US (Standard Contractual Clauses)
SMTP2GOTransactional email deliveryEU
Hosting providerInfrastructure, servers, database storageEU / CH

If we intend to bring in a new sub-processor or replace an existing one, we will give the Controller reasonable advance notice. The Controller may object. If we cannot reach a resolution, the Controller may terminate the service.

8. Security

SpaceStatus maintains the following technical and organisational security measures:

  • TLS 1.2 or higher for all data in transit
  • Passwords hashed with PBKDF2 (SHA-256, 310,000 iterations) before storage
  • Role-based access controls on all API endpoints
  • Authentication tokens that expire automatically, stored using secure practices
  • Server access logs kept for 90 days for security monitoring
  • Calendar event data is not written to persistent storage. It is fetched in real time and discarded after rendering.

9. If there is a data breach

If a personal data breach occurs that involves data processed under this DPA, SpaceStatus will notify the Controller without undue delay and in any case within 72 hours of becoming aware of it. The notification will cover, to the extent known: what happened, which categories and approximate number of people are affected, which categories and approximate number of records are involved, the likely consequences, and the steps taken or planned to deal with it.

10. Helping with data subject requests

SpaceStatus will help the Controller handle requests from data subjects where possible. In practice, the data SpaceStatus holds on individual users is limited to account credentials and room board configurations. Customers can request deletion of their account and all related data at any time by writing to [email protected].

11. Deleting data when the service ends

When the service relationship ends, SpaceStatus will delete all personal data processed under this DPA within 30 days, unless keeping it is required by applicable law. The Controller can request written confirmation that deletion has taken place.

12. Audits

SpaceStatus will cooperate with audits and inspections by the Controller or a mandated auditor, with three conditions: reasonable advance notice is given, audits happen during normal business hours and no more than once per year, and the auditor has signed an appropriate non-disclosure agreement.

13. Governing law

This DPA is governed by Swiss law. Where the Customer is based in the EU or EEA, GDPR provisions take precedence over any conflicting Swiss law provisions, to the extent the GDPR requires it.

14. Questions

For anything related to this DPA, write to [email protected].


See also our Terms of Service, Privacy Policy, and Imprint.

© 2026 SpaceStatus. All rights reserved.

TermsPrivacyDPAImprintPricingSign in