StackLégal

Tools and automation

GDPR Calendly

In an indie stack, Calendly is used for Appointment scheduling. Entity cited: Calendly, LLC. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Calendly

Yes. Public Data Processing Addendum.

Read the DPA

Stated role

Controller for personal data such as site visits and account creation. When customers use the services to collect and process personal data, Calendly acts as processor or service provider for those customers.

Personal data

Name, email, phone, identifier, password, billing address, card information held by the payment providers, last four digits, card type, expiration date, company, position, logs and device data including the IP address, cookies and local storage, guest data processed for the customers.

Sub-processors of Calendly

Help page listing the sub-processors.

List published by the vendor

Transfers outside the EU

Hosting / location

Calendly stores user and guest data in data centers in the United States operated by Google Cloud and Amazon Web Services.

EU–United States Data Privacy Framework

Calendly LLC is registered. EU-U.S. Data Privacy Framework status: Active.

Data Privacy Framework sheet

Cookies

Calendly and authorized third parties use cookies, pixels, web beacons, and local storage, including session and persistent cookies, subject to consent or another basis when required.

Typical use, written by StackLégal and not by the vendor: Appointment scheduling.

History

Last update: October 4, 2026.

  1. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is Calendly a processor within the meaning of the GDPR?

Controller for personal data such as site visits and account creation. When customers use the services to collect and process personal data, Calendly acts as processor or service provider for those customers.

What DPA does Calendly publish?

Yes. Public Data Processing Addendum. https://calendly.com/legal/data-processing-addendum

Which further sub-processors does Calendly publish?

Help page listing the sub-processors. https://calendly.com/help/calendly-sub-processors-gdpr-ccpa

Where does Calendly state that it processes data, including outside the EU?

Calendly stores user and guest data in data centers in the United States operated by Google Cloud and Amazon Web Services.

Is Calendly registered under the EU–United States Data Privacy Framework?

Calendly LLC is registered. EU-U.S. Data Privacy Framework status: Active. https://www.dataprivacyframework.gov/participant/6050

Which personal data does Calendly mention?

Name, email, phone, identifier, password, billing address, card information held by the payment providers, last four digits, card type, expiration date, company, position, logs and device data including the IP address, cookies and local storage, guest data processed for the customers.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets tools and automation

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.