These Terms govern Customer-enabled integrations and any developer access expressly authorized by Software Programming Group LLC (Provider). They supplement the Customer Agreement. They do not announce a public API, webhook service, application marketplace, or software development kit. Such access exists only when the Provider supplies it under written documentation or an accepted developer arrangement.
1. Supported native connections
A Customer may enable a supported connection only using an account it is authorized to connect. Available meeting integrations may include Google Meet, Microsoft Teams, Zoom, and Vitel Meet. The authorization screen and Documentation identify the permissions required for the selected functions. The Customer must review those permissions and obtain organizational or participant permissions where necessary.
The Customer may revoke a connection in CalendNow or the third party’s account controls, as available. Revocation may prevent new meeting links or updates but does not necessarily remove past events or independently stored records. The Customer is responsible for separate third-party licenses and its configuration. Provider-appointed subprocessors remain subject to the Provider’s DPA obligations.
2. Authorized developer access
If the Provider grants API or webhook access, the developer may use it only for the approved application, permitted endpoints, scopes, and purposes. Credentials must be kept confidential, separated by environment where supported, and rotated after suspected compromise. The developer must not bypass rate limits, scrape undocumented endpoints, share secrets publicly, or access data beyond a valid authorization.
An application must obtain and honor users’ permissions, provide accurate privacy information, use data only for the disclosed function, minimize collected fields, and offer a practical disconnection and deletion route. It must not sell obtained personal data, use it for undisclosed advertising or model training, or combine it with unrelated profiles without a lawful, specifically authorized basis and the Provider’s permission where required.
3. Security and incident cooperation
The developer must use reasonable safeguards appropriate to the data and maintain controls against injection, credential leakage, and unauthorized access. Webhook receivers, if provided, must use the documented verification method. The developer must promptly inform security@calendnow.ai of a compromise affecting CalendNow data or credentials and cooperate on containment and lawful notification.
No vulnerability test may disrupt users or access another customer’s information. Testing outside express authorization is prohibited. The Provider may revoke compromised credentials or suspend an unsafe integration to protect users, with notice when reasonably practicable.
4. Ownership and branding
The developer retains its application’s intellectual property. The Provider retains its interfaces, documentation, and trademarks. No license to impersonate the Provider, imply certification, use its logo, or represent an application as official is granted. Any branding permission must be separately documented.
5. Compatibility and termination
Third-party interfaces may change. The Provider will give reasonable notice of a material planned developer-interface change where practicable, but may act immediately for a serious security issue or legal requirement. No perpetual API compatibility or availability commitment is created without a signed agreement.
On termination or revocation, the developer must stop access and delete or return data obtained through that access as required by its permissions, the Agreement, and law. It must not continue collecting data using cached tokens. Confidentiality, privacy, ownership, and accrued obligations survive as appropriate.