Calendly · Calendly Privacy Notice · View original document ↗

International Data Transfer and U.S. Storage Disclosure

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Calendly changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Calendly Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that Personal Data of individuals located in the EEA, UK, Canada, and other non-U.S. jurisdictions will be processed and stored in the United States or in countries where Calendly's service providers operate, and that those jurisdictions may not offer equivalent privacy protections.

This analysis describes what Calendly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision discloses that Personal Data from EEA, UK, and Canadian individuals is transferred to and stored in the United States, a jurisdiction that has historically been subject to adequacy assessments by European and UK data protection authorities. The policy states that transfer mechanisms including the DPF, Standard Contractual Clauses, and UK Addendum are relied upon to legitimize these transfers.

Consumer impact (what this means for users)

Under this clause, Personal Data submitted by EEA, UK, and Canadian users is stated to be transferred to and processed in the United States or in countries where Calendly's service providers are located. The policy acknowledges that these jurisdictions may not provide the same level of privacy protection as the user's home country.

Cross-platform context

See how other platforms handle International Data Transfer and U.S. Storage Disclosure and similar clauses.

Compare across platforms →

Monitoring

Calendly has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you are an individual located in the European Economic Area, the United Kingdom, Canada or another jurisdiction outside of the United States with laws and regulations governing Personal Data collection, use, and disclosure that differ from United States laws, please be aware that information we collect (including through the use of methods such as Cookies and other web technologies) will be processed and stored in the United States or in other countries where we or our Service Providers have operations. By submitting your Personal Data to Calendly and using Calendly, please be aware that your Personal Data may be transferred to, processed, and stored in the United States or another jurisdiction which may not offer the same level of privacy protection as those in the country where you reside.

Excerpt from Calendly's Privacy Notice

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: Cross-border data transfers from the EEA are governed by GDPR Chapter V, which requires a lawful transfer mechanism such as an adequacy decision, Standard Contractual Clauses, or binding corporate rules. The EU-U.S. DPF constitutes an adequacy decision for DPF-certified organizations. UK transfers are governed by UK GDPR and the UK International Data Transfer Agreement. Canadian transfers are governed by PIPEDA and provincial equivalents. 2. GOVERNANCE EXPOSURE: Medium. The policy's reliance on the DPF adequacy decision is subject to ongoing legal and political risk; organizations should maintain Standard Contractual Clauses as a supplementary mechanism in the event of DPF invalidation, consistent with the policy's statement that SCCs are also relied upon. The reference to service provider locations without specific enumeration creates some opacity for data mapping purposes, though a sub-processor list is referenced. 3. JURISDICTION FLAGS: EEA and UK individuals face the most structured regulatory framework governing their data transfers, with enforcement by national data protection authorities and the European Data Protection Board. Canadian users are subject to PIPEDA, which requires comparable protection for offshore transfers. The policy does not address transfers to or from other specific non-U.S. jurisdictions in detail. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations in the EEA and UK procuring Calendly should confirm that Standard Contractual Clauses are executed in addition to reliance on the DPF, given the historical pattern of DPF predecessor frameworks being invalidated. The sub-processor list referenced in the policy should be reviewed to identify the jurisdictions in which sub-processors operate and assess the adequacy of transfer mechanisms for each. 5. COMPLIANCE CONSIDERATIONS: Data protection officers in EEA and UK organizations should conduct transfer impact assessments for Calendly data flows, particularly for meeting recordings and transcripts that may contain sensitive personal data. The policy's reliance on SCCs and the UK Addendum should be confirmed against executed data processing agreements. Canadian compliance teams should assess whether Calendly's transfer arrangements satisfy PIPEDA accountability principles for offshore processing.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has enforcement authority over Calendly's DPF compliance, which is the stated adequacy mechanism for EEA and UK data transfers to the United States.
    File a complaint →

Provision details

Document information
Document
Calendly Privacy Notice
Entity
Calendly
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015887
Document ID
CA-D-00563
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
9c4f19c5c822aa52a1b2da5bb522c829f8cdb46c74a22604b9e46848c521cc8d
Analysis generated
July 9, 2026 09:03 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Calendly
Document: Calendly Privacy Notice
Record ID: CA-P-015887
Captured: 2026-07-09 09:03:25 UTC
SHA-256: 9c4f19c5c822aa52…
URL: https://conductatlas.com/platform/calendly/calendly-privacy-notice/provision/CA-P-015887/international-data-transfer-and-us-storage-disclosure/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Calendly's International Data Transfer and U.S. Storage Disclosure clause do?

This provision discloses that Personal Data from EEA, UK, and Canadian individuals is transferred to and stored in the United States, a jurisdiction that has historically been subject to adequacy assessments by European and UK data protection authorities. The policy states that transfer mechanisms including the DPF, Standard Contractual Clauses, and UK Addendum are relied upon to legitimize these transfers.

How does this clause affect you?

Under this clause, Personal Data submitted by EEA, UK, and Canadian users is stated to be transferred to and processed in the United States or in countries where Calendly's service providers are located. The policy acknowledges that these jurisdictions may not provide the same level of privacy protection as the user's home country.

Is ConductAtlas affiliated with Calendly?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Calendly.