Calendly

Last Reviewed: 27 Jul 2026

Data Use Review

At a Glance

Calendly's DPA addresses most GDPR requirements, but it is unclear whether Calendly's product-development and improvement processing extends to Processor/Customer data (e.g. meeting participant details) rather than being limited to Calendly's own account data. We recommend this contract is manually reviewed to ensure the terms are acceptable to you.

Company & Product Details

HQ

United States

Products

Scheduling Automation Platform

Product description

Online scheduling software for booking meetings, managing calendars, and automating meeting workflows.

What data is being processed?

Name, title, position, employer, contact information, connected calendar event details, approximate location/time zone, audio and visual meeting recording data, and materials presented on screen during meetings

Document Details

Date of DPA

01 Jun 2026

Additional date information

Document states "Effective Date: June 1, 2026" directly under the title.

What jurisdictions are covered?

EU, Swiss, and UK Data Protection Laws are explicitly addressed (Section 3), including GDPR, UK GDPR, and the Swiss FADP; US State Privacy Laws including the CCPA are addressed separately (Section 4). The competent supervisory authority is the Irish Data Protection Commission, and SCC governing law/jurisdiction is Ireland (Switzerland for Swiss-only transfers) (Annex I, Exhibit B).

Is the DPA incorporated into service or customer agreements?

Yes
The DPA is automatically incorporated into Calendly's Customer Terms (the Agreement) and applies without any separate signature or execution required (Preamble).

Location & Transfers

Where is data held or processed?

United States Processing of Personal Data occurs in the United States and potentially other jurisdictions outside the Data Subject's residence; Customer must satisfy any notice/consent requirements for such transfers (clause 2.3).

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
Calendly is self-certified under the EU-US, UK, and Swiss Data Privacy Frameworks, which are the primary transfer mechanism relied on. If a Data Privacy Framework is invalidated, transfers default to the SCCs (Module 2, Controller to Processor) plus a UK Addendum, with governing law of Ireland (Switzerland for Swiss-only data) (clause 3.1, Exhibits B & C).

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Calendly utilises commercially reasonable administrative, physical, and technical safeguards to protect the security, confidentiality and integrity of Personal Data, with details published at calendly.com/security (clause 6.1, Annex II).

Non Processor Data Use

Does the company process data solely as a processor?

Unclear
Annex I (Nature of the Processing) states that Calendly's processing of Personal Data as Processor may include internal purposes such as "product development and improvement," framed as necessary to provide the Services under Customer's instructions. Separately, clause 9 confirms Calendly also processes "certain personal data" as an independent Controller for account management, billing, and to "develop, improve, and understand usage of its products and services" under its own Privacy Notice. It is unclear whether the product-development use described in Annex I is limited to service-delivery optimisation, or overlaps with the broader product-improvement purpose Calendly pursues as Controller, potentially extending Calendly's own-purpose use to Processor/Customer Data such as meeting participant details (Annex I §5; clause 9(vi)).

Subprocessing

General authorization

General
Customer consents in advance to Calendly's published sub-processor list (Annex III) under general authorization (SCC Option 2). Calendly must notify subscribed customers of new sub-processors at least 30 days in advance; customers who do not subscribe to notifications waive the right to prior notice. Objections must be raised within 30 days and are resolved through good-faith discussion, with termination of the affected service as the fallback remedy (clauses 5.1–5.3, Exhibit B Clause 9).

Do all the DPA terms flow down to sub-processors?

Yes
Calendly must enter into a written agreement with each sub-processor containing data protection obligations at least as restrictive as its own obligations under this DPA (clause 5.3).

Is data only processed on the instruction of the controller?

Yes
Calendly processes Personal Data only on Customer's documented instructions; the Agreement, this DPA, and Customer's compliant use of the Services together constitute Customer's complete and final instructions (clause 2.2).

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Calendly provides functionality within the Services to help Customer fulfil Data Subject Requests, and will reasonably assist Customer with such requests where Customer cannot act on them itself using the Services (clause 7.2).

Does the contract include staff confidentiality clauses?

Yes
Calendly ensures employees, contractors, agents and auditors who access Personal Data are under a duty of confidentiality (clause 6.2).

Are there audit rights for the data?

Structured
Within 30 days of Customer's written request, and no more than once annually, Calendly will make available its most recent third-party audit/certification reports (e.g. SOC 2 or ISO 27001) to demonstrate compliance. If further information is needed, the parties negotiate in good faith on what additional information Calendly will provide (clause 8).

Is there assistance with DPIA requests?

Yes
Calendly will assist Customer with obligations under GDPR Articles 32–36 (or UK equivalents), maintain records of processing activities under Article 30(2), cooperate with supervisory authorities on request, and provide reasonable assistance with data protection assessments (clauses 3.2, 7.1).

How much notice is provided for data breaches?

Upon becoming aware of a Security Breach, Calendly will notify Customer without undue delay, investigate, provide necessary details as required by applicable law, and take reasonable action to prevent recurrence; no specific fixed time limit (e.g. hours) is stated (clause 6.3).

What happens to the data on termination?

Calendly will return or securely destroy Personal Data in accordance with Customer's instructions upon request or termination of Customer's account(s), unless retention is required to comply with applicable law (clause 2.4).