Tools and automation
GDPR Cal.com
In an indie stack, Cal.com is used for Appointment scheduling. Entity cited: Cal.com, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 5, 2026. Verified on October 5, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA Cal.com
The policy says it processes participants' data on instruction, under its DPA. The Trust Center marks the Data Processing Agreement as Restricted. Public URL of the text: not disclosed.
Stated role
The policy states that, for bookings made through the account, the customer is controller and Cal.com is processor. The public text of the DPA: not disclosed.
Personal data
The policy cites names, emails, phone numbers, and answers to booking questions, plus the IP address, the browser, and pages viewed. It states that recordings and transcripts are retained until deletion, and that AI features are optional.
Sub-processors of Cal.com
Public list on the Trust Center. It names in particular Amazon RDS Postgres, Vercel, SendGrid (Twilio), Stripe, PostHog, and Whop, location indicated: United States. The full table is not copied here.
Transfers outside the EU
Hosting / location
The policy states that Cal.com is a US company and that data is processed in the United States, with some sub-processors processing elsewhere. Data residency in the EU is indicated as possible on request at privacy@cal.com. A more precise default region: not disclosed.
EU–United States Data Privacy Framework
The policy asserts that Cal.com, Inc. has certified to the EU-U.S. Data Privacy Framework and the United Kingdom extension, and that transfers from Switzerland go through standard contractual clauses. Official search for “Cal.com” and “Cal.com, Inc.” on the list on 5 October 2026: no participant. Status on the list: not disclosed.
Cookies
The policy states that there are no third-party cookies in the product, and that the marketing site does analytics and advertising measurement. Names: not disclosed.
Typical use, written by StackLégal and not by the vendor: Appointment scheduling.
History
Last update: October 5, 2026.
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 5, 2026.
Frequently asked questions
Is Cal.com a processor within the meaning of the GDPR?
The policy states that, for bookings made through the account, the customer is controller and Cal.com is processor. The public text of the DPA: not disclosed.
What DPA does Cal.com publish?
The policy says it processes participants' data on instruction, under its DPA. The Trust Center marks the Data Processing Agreement as Restricted. Public URL of the text: not disclosed.
Which further sub-processors does Cal.com publish?
Public list on the Trust Center. It names in particular Amazon RDS Postgres, Vercel, SendGrid (Twilio), Stripe, PostHog, and Whop, location indicated: United States. The full table is not copied here. https://trust.cal.com/subprocessors
Where does Cal.com state that it processes data, including outside the EU?
The policy states that Cal.com is a US company and that data is processed in the United States, with some sub-processors processing elsewhere. Data residency in the EU is indicated as possible on request at privacy@cal.com. A more precise default region: not disclosed.
Is Cal.com registered under the EU–United States Data Privacy Framework?
The policy asserts that Cal.com, Inc. has certified to the EU-U.S. Data Privacy Framework and the United Kingdom extension, and that transfers from Switzerland go through standard contractual clauses. Official search for “Cal.com” and “Cal.com, Inc.” on the list on 5 October 2026: no participant. Status on the list: not disclosed.
Which personal data does Cal.com mention?
The policy cites names, emails, phone numbers, and answers to booking questions, plus the IP address, the browser, and pages viewed. It states that recordings and transcripts are retained until deletion, and that AI features are optional.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.