When a Calendly customer uses the platform to schedule or record a meeting with you, Calendly asserts it acts only as a data processor under that customer's instruction, and directs any data subject rights requests regarding that data to the originating customer rather than to Calendly.
This analysis describes what Calendly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that individuals whose data is collected by a Calendly customer during scheduling or meeting recording must direct rights requests to the customer entity, not to Calendly, which has direct implications for how data subject access, deletion, and correction rights are fulfilled in practice. Organizations deploying Calendly bear controller obligations under GDPR, CCPA, and comparable frameworks for data collected through Calendly's Services on their behalf.
Under this clause, if a business uses Calendly to schedule a meeting with you and records or processes your personal data in that context, your rights requests regarding that data are to be submitted to the business, not to Calendly. The agreement requires Calendly customers to comply with applicable laws requiring notice, disclosure, and consent prior to transferring Personal Data to Calendly.
Cross-platform context
See how other platforms handle Controller-Processor Distinction for Customer-Collected Data and similar clauses.
Compare across platforms →"Please note that when our customers use our Services to directly collect and process Personal Data, such as when our customers use our Services to schedule a meeting with you or record a meeting, Calendly acts as a processor (or service provider) on behalf of our customers (who are controllers of the Personal Data) under the Calendly Data Processing Addendum and Customer Terms and Conditions. If you have questions about how your data is processed by our customers or wish to exercise your rights with respect to that data, you should contact the customer which collected your information.Excerpt from Calendly's Privacy Notice
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that individuals whose data is collected by a Calendly customer during scheduling or meeting recording must direct rights requests to the customer entity, not to Calendly, which has direct implications for how data subject access, deletion, and correction rights are fulfilled in practice. Organizations deploying Calendly bear controller obligations under GDPR, CCPA, and comparable frameworks for data …
Under this clause, if a business uses Calendly to schedule a meeting with you and records or processes your personal data in that context, your rights requests regarding that data are to be submitted to the business, not to Calendly. The agreement requires Calendly customers to comply with applicable laws requiring notice, disclosure, and consent prior to transferring Personal Data …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Calendly.