Calendly · Calendly Privacy Notice · View original document ↗

Controller-Processor Distinction for Customer-Collected Data

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Calendly changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Calendly Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

When a Calendly customer uses the platform to schedule or record a meeting with you, Calendly asserts it acts only as a data processor under that customer's instruction, and directs any data subject rights requests regarding that data to the originating customer rather than to Calendly.

This analysis describes what Calendly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that individuals whose data is collected by a Calendly customer during scheduling or meeting recording must direct rights requests to the customer entity, not to Calendly, which has direct implications for how data subject access, deletion, and correction rights are fulfilled in practice. Organizations deploying Calendly bear controller obligations under GDPR, CCPA, and comparable frameworks for data collected through Calendly's Services on their behalf.

Consumer impact (what this means for users)

Under this clause, if a business uses Calendly to schedule a meeting with you and records or processes your personal data in that context, your rights requests regarding that data are to be submitted to the business, not to Calendly. The agreement requires Calendly customers to comply with applicable laws requiring notice, disclosure, and consent prior to transferring Personal Data to Calendly.

Cross-platform context

See how other platforms handle Controller-Processor Distinction for Customer-Collected Data and similar clauses.

Compare across platforms →

Monitoring

Calendly has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Please note that when our customers use our Services to directly collect and process Personal Data, such as when our customers use our Services to schedule a meeting with you or record a meeting, Calendly acts as a processor (or service provider) on behalf of our customers (who are controllers of the Personal Data) under the Calendly Data Processing Addendum and Customer Terms and Conditions. If you have questions about how your data is processed by our customers or wish to exercise your rights with respect to that data, you should contact the customer which collected your information.

Excerpt from Calendly's Privacy Notice

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly engages GDPR Articles 4, 28, and 82 regarding the controller-processor distinction, as well as CCPA and CPRA provisions governing service provider relationships. Under GDPR, the allocation of controller obligations to Calendly customers is consistent with standard practice where a customer determines the purposes and means of processing. However, the adequacy of the referenced Data Processing Addendum in meeting Article 28 requirements warrants review, particularly for customers in the EEA and UK. 2. GOVERNANCE EXPOSURE: High. This provision places direct controller obligations on organizations using Calendly for meeting scheduling, recording, and customer relationship management. Failure to maintain compliant privacy notices, consent mechanisms, and data subject rights procedures as the controller could expose those organizations to regulatory action under GDPR, CCPA, and equivalent frameworks, independently of Calendly's own compliance posture. 3. JURISDICTION FLAGS: EEA and UK-based organizations face heightened exposure under GDPR and UK GDPR, where controller obligations are prescriptive and enforceable by data protection authorities. California-based organizations must assess whether their use of Calendly as a service provider is properly documented and whether their own privacy notices disclose the use of Calendly for data processing. Educational institutions must additionally assess FERPA applicability when student data is involved. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations procuring Calendly should review the Data Processing Addendum referenced in this provision to confirm it addresses Article 28 requirements including data security, sub-processor management, audit rights, and data breach notification obligations. The provision asserts that Calendly customers are responsible for obtaining necessary consents and providing required disclosures before transferring Personal Data to Calendly, which may constitute a contractual liability allocation that procurement teams should evaluate. 5. COMPLIANCE CONSIDERATIONS: Compliance teams at organizations using Calendly should audit their own privacy notices and consent flows to confirm they adequately disclose Calendly's role as a processor. Data mapping exercises should document what Personal Data flows to Calendly through scheduling, recording, and transcript functions, and assess whether appropriate data processing agreements are in place. Rights fulfillment procedures should be updated to address data subject requests concerning data processed through Calendly.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive data practices and DPF compliance, relevant where the controller-processor allocation may affect individual rights fulfillment in a U.S. consumer context.
    File a complaint →
  • State AG
    State attorneys general in California and other states with comprehensive privacy laws may have jurisdiction where the controller-processor distinction affects how data subject rights are fulfilled under state law.
    File a complaint →

Provision details

Document information
Document
Calendly Privacy Notice
Entity
Calendly
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015882
Document ID
CA-D-00563
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
9c4f19c5c822aa52a1b2da5bb522c829f8cdb46c74a22604b9e46848c521cc8d
Analysis generated
July 9, 2026 09:03 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Calendly
Document: Calendly Privacy Notice
Record ID: CA-P-015882
Captured: 2026-07-09 09:03:25 UTC
SHA-256: 9c4f19c5c822aa52…
URL: https://conductatlas.com/platform/calendly/calendly-privacy-notice/provision/CA-P-015882/controller-processor-distinction-for-customer-collected-data/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Calendly's Controller-Processor Distinction for Customer-Collected Data clause do?

This provision establishes that individuals whose data is collected by a Calendly customer during scheduling or meeting recording must direct rights requests to the customer entity, not to Calendly, which has direct implications for how data subject access, deletion, and correction rights are fulfilled in practice. Organizations deploying Calendly bear controller obligations under GDPR, CCPA, and comparable frameworks for data …

How does this clause affect you?

Under this clause, if a business uses Calendly to schedule a meeting with you and records or processes your personal data in that context, your rights requests regarding that data are to be submitted to the business, not to Calendly. The agreement requires Calendly customers to comply with applicable laws requiring notice, disclosure, and consent prior to transferring Personal Data …

Is ConductAtlas affiliated with Calendly?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Calendly.