Is Calendly GDPR Compliant? DPA, Data Location and EU Transfers

Calendly publishes a Data Processing Addendum (DPA) and transfer safeguards for relevant international transfers, but no scheduling vendor can make every customer use automatically compliant. Calendly says user and invitee data is stored in US data centers. EU organizations should review the current DPA, data flows, integrations and their own use before choosing a scheduling platform.

Executive Summary (TL;DR)

Calendly’s current DPA says transfers of EU personal data to the United States use the EU-US Data Privacy Framework; if that framework is invalidated or no longer available, the DPA provides for Standard Contractual Clauses. Calendly’s data-storage documentation identifies US-based data centers managed by Google Cloud and AWS. Controllers still need to check purposes, data categories, subprocessors and enabled integrations. Kalendarius hosts its core application and database in the EU, while connected calendar providers should be assessed separately.

Scheduling Vendor Review: Data Location, Transfers and Contracts

Requirement / Capability Kalendarius (EU) Calendly
Core hosting location ✓ Core application and database hosted in the EU Calendly documents US data centers managed by Google Cloud and AWS
International transfers ✓ Assess calendar and other connected services separately The DPA specifies the Data Privacy Framework for relevant US transfers, with SCCs as a fallback
Data processing agreement ✓ Signed DPA available for Business and Enterprise customers Calendly publishes a DPA incorporated into its Customer Terms
Subprocessors and integrations ✓ Review the current provider list and the calendar services enabled by your team Review Calendly’s current subprocessor list and the integrations enabled by your team
Booking data and retention ✓ Configure appointment retention and limit the information requested on forms Check retention terms and restrict booking fields to what your process needs

What Calendly’s GDPR Documentation Says

Calendly publishes a Data Processing Addendum (DPA) that is incorporated into its Customer Terms when customer data includes personal data processed on the customer’s behalf. The DPA identifies Calendly LLC as processor for that service data and also describes limited situations in which Calendly acts as a controller.

For transfers of EU personal data to the United States, the current DPA specifies the EU-US Data Privacy Framework and says Standard Contractual Clauses apply if that framework is invalidated or ceases to be an available legal transfer mechanism. Check the current DPA and transfer documentation for your contract and configuration.

Understanding the Calendly DPA (Data Processing Addendum)

Organizations evaluating Calendly typically review its Data Processing Addendum to understand its technical and organizational security measures (TOMs), sub-processor structure, and breach notification commitments.

Use the DPA to check the processing scope, security terms, breach notices, subprocessors, assistance with data-subject requests, deletion and audit information. Compare those terms with the data that your organization actually sends and the services it connects. EU hosting can simplify review of a provider’s core hosting location, but it does not remove responsibilities for your own processing or connected services.

Calendly DPA vs Kalendarius EU DPA: The Article 28 Compliance Checklist

Article 28 of the GDPR sets out required processor-contract terms. A practical scheduling-vendor review can start with these questions:

1. Sub-processor Disclosures: Does the vendor identify sub-processors, give notice of changes, and explain where each processing activity occurs? Review calendar, email, payment and support integrations as well as the core host.

2. Technical & Organizational Measures (TOMs): Does the vendor document access controls, encryption in transit and at rest, backup protection, incident handling and data minimisation? Avoid treating any single control or certification as proof of GDPR compliance.

3. Breach Notification Commitments: Article 33(2) requires a processor to notify its controller without undue delay after becoming aware of a personal data breach; the contract should state the operational process.

4. Cross-Border Transfer Mechanisms: Identify actual transfers outside the EEA, the applicable adequacy decision or Article 46 safeguard, and whether supplementary measures are needed. EU core hosting can reduce this work but does not remove the need to assess enabled third-party integrations.

5. Retention and deletion: Can you set a retention period, respond to deletion requests, and understand what happens when the contract ends? Kalendarius lets organizations configure retention for completed appointments; available retention limits depend on the plan. Review the current contract for export and end-of-service deletion terms.

US Data Hosting and EU Data Transfer Review

Calendly’s documentation identifies US data centers for user and invitee data and describes the transfer safeguards in its DPA. For an EU organization, the practical review is to map which personal data is sent, the applicable transfer mechanism, the vendor’s subprocessor locations, and the measures relevant to the organization’s use case.

Kalendarius’s core application and database are hosted in the EU. That is a data-location fact, not a blanket compliance guarantee or immunity from legal process. Customers should include calendar providers and other enabled processors in their own assessment.

Key Considerations for European Data Protection Officers (DPOs)

The controller remains responsible for its purposes, lawful basis, transparency, data minimisation and retention. A provider’s DPA is one part of that review; it does not decide whether the customer’s particular use is appropriate.

Where personal data is transferred outside the EEA, organizations should identify the transfer mechanism and assess any additional safeguards that apply to their circumstances. Regulated teams may also have sector-specific duties. EU core hosting can simplify review of that hosting layer, while connected Google or Microsoft services should be assessed in the actual configuration.

Handling Sensitive Context in Appointment Bookings

Meeting booking forms often capture sensitive details, including custom question responses, attendee identities, and appointment titles (such as 'Medical Consultation' or 'M&A Advisory'). Depending on context, these details can trigger heightened obligations under Article 9 of the GDPR (special categories of personal data).

Before collecting appointment details, decide whether a service description, free-text field or calendar title could reveal sensitive information. Ask vendors how booking data appears in reminders and connected calendars, and avoid collecting details that are not needed to arrange the meeting.

Calendly Entity and VAT Details for EU Procurement

European procurement and accounting teams onboarding Calendly frequently search for official corporate registration details, tax status, and EU VAT information to complete their vendor diligence forms.

Calendly's legal terms identify Calendly LLC as the contracting entity. VAT treatment and the supplier details shown on an invoice can depend on the customer's location and purchasing arrangement, so procurement teams should verify the current order form or invoice instead of assuming that a US entity cannot hold an EU VAT registration.

Kalendarius is operated by Ugur Akcelik in Turin, Italy (VAT 12938420010). Paid subscriptions are billed by Paddle as merchant of record; Paddle collects payment, issues the invoice and applies the tax treatment shown at checkout. Customers should rely on the final invoice for accounting and VAT reporting.

The Value of an EU-Native Scheduling Solution

Kalendarius is an EU-focused alternative: its core application and database are hosted in the EU, public booking pages do not load third-party advertising or analytics trackers, and calendar synchronization with Google or Microsoft is optional. Business and Enterprise customers can request a signed DPA.

If you are comparing vendors, use the GDPR scheduling software buyer’s checklist to review hosting, subprocessors, booking fields, retention and connected calendars. EU hosting and tracker-free booking pages can simplify parts of a vendor review, but they do not by themselves make a customer’s processing GDPR compliant.

Primary sources and verification

Calendly details are based on its Data Processing Addendum, data storage and international transfers documentation, subprocessor list, and Customer Terms. Transfer guidance is based on the European Commission’s international-transfer guidance and the EDPB Recommendations 01/2020. Sources checked 25 September 2026.

Frequently Asked Questions

Is Calendly legally compliant under EU GDPR?

There is no blanket answer for every use case. Calendly publishes a DPA and describes transfer safeguards for relevant US transfers. Each controller should assess its own purposes, data, configuration, recipients and sector-specific obligations against the current documents.

What is Calendly's corporate address and VAT number for EU vendor setup?

Calendly's terms identify Calendly LLC as the contracting entity. Verify the supplier address, VAT identifier and tax treatment on the current order form or invoice; a vendor's US incorporation alone does not prove that it lacks an EU VAT registration. Kalendarius subscriptions are invoiced by Paddle as merchant of record.

How do I execute a GDPR Data Processing Agreement (DPA) with Calendly vs Kalendarius?

Calendly publishes a DPA incorporated into its Customer Terms, with transfer terms that include the Data Privacy Framework and SCC fallback. Kalendarius offers a signed Article 28 DPA to Business and Enterprise customers. In either case, review the current subprocessor list, enabled integrations and data flows for your configuration.

What is a Transfer Impact Assessment (TIA) and when is it required?

A transfer assessment depends on the transfer mechanism, destination, data and circumstances. Where an Article 46 tool is used, organizations should consider whether supplementary measures are needed. Kalendarius’s EU-hosted core service keeps its core hosting in the EU; customers should separately assess connected services that receive personal data.

Where does Kalendarius store meeting and booking data?

Kalendarius's core application and database are hosted with Hetzner in the European Union. Hetzner's hosting services and data centers are ISO/IEC 27001:2022 certified. Connected Google or Microsoft calendars remain subject to those providers' terms and the customer's configuration.

Can healthcare and legal organizations use Calendly?

That depends on the organization’s legal basis, the information collected, contract terms, configuration and sector requirements. If a booking can reveal health or other Article 9 data, minimize the details requested and review how they appear in booking records, email and connected calendars.

Where does Calendly host European appointment and guest data?

Calendly’s current data-storage documentation says user and invitee data is stored in US-based data centers managed by Google Cloud Services and Amazon Web Services. Its DPA specifies the EU-US Data Privacy Framework for relevant transfers to the United States and provides for SCCs if that framework is invalidated or ceases to be available. Check the current subprocessor list and your enabled integrations for other data flows.

What should be included in a scheduling vendor DPA checklist?

An Article 28 processor contract should cover documented instructions, confidentiality, security, sub-processors, assistance with data-subject rights and breach obligations, return or deletion, and audit information. The exact measures and retention terms should match the service and the controller's use case.

Reduce transfer complexity in your scheduling workflow

Use an EU-hosted core scheduling service with tracker-free public booking pages and optional calendar synchronization.

Get started with Kalendarius

Legal Disclaimer: Calendly is a registered trademark of Calendly, LLC. Kalendarius is an independent European software service developed by Kineto Soft and has no affiliation, partnership, sponsorship, or endorsement from Calendly, LLC. All product names, logos, and trademarks referenced on this page are property of their respective owners. Comparative information is compiled from publicly accessible documentation as of 2026 for general informational purposes to help European data controllers evaluate their data residency requirements, and does not constitute formal legal advice.