Calendly
Last Reviewed: 27 Jul 2026
At a Glance
Calendly's DPA addresses most GDPR requirements, but it is unclear whether Calendly's product-development and improvement processing extends to Processor/Customer data (e.g. meeting participant details) rather than being limited to Calendly's own account data. We recommend this contract is manually reviewed to ensure the terms are acceptable to you.
Company & Product Details
HQ
United States
Products
Scheduling Automation Platform
Product description
Online scheduling software for booking meetings, managing calendars, and automating meeting workflows.
What data is being processed?
Name, title, position, employer, contact information, connected calendar event details, approximate location/time zone, audio and visual meeting recording data, and materials presented on screen during meetings
Document Details
Date of DPA
01 Jun 2026
Additional date information
Document states "Effective Date: June 1, 2026" directly under the title.
What jurisdictions are covered?
EU, Swiss, and UK Data Protection Laws are explicitly addressed (Section 3), including GDPR, UK GDPR, and the Swiss FADP; US State Privacy Laws including the CCPA are addressed separately (Section 4). The competent supervisory authority is the Irish Data Protection Commission, and SCC governing law/jurisdiction is Ireland (Switzerland for Swiss-only transfers) (Annex I, Exhibit B).
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
United States Processing of Personal Data occurs in the United States and potentially other jurisdictions outside the Data Subject's residence; Customer must satisfy any notice/consent requirements for such transfers (clause 2.3).
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Calendly utilises commercially reasonable administrative, physical, and technical safeguards to protect the security, confidentiality and integrity of Personal Data, with details published at calendly.com/security (clause 6.1, Annex II).
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Upon becoming aware of a Security Breach, Calendly will notify Customer without undue delay, investigate, provide necessary details as required by applicable law, and take reasonable action to prevent recurrence; no specific fixed time limit (e.g. hours) is stated (clause 6.3).
What happens to the data on termination?
Calendly will return or securely destroy Personal Data in accordance with Customer's instructions upon request or termination of Customer's account(s), unless retention is required to comply with applicable law (clause 2.4).