Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that Calendly acquires name, email address, phone number, job title, employer, employment seniority, social media usernames and avatars, and social media activity details from third-party lead-generation and marketing companies, and uses this data for sales and marketing purposes.
This analysis describes what Calendly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Calendly may hold detailed professional and social profile data about individuals who have not directly interacted with Calendly, sourced from third-party data brokers and lead-generation companies. This data flow may implicate CCPA and GDPR notice and transparency obligations, particularly regarding the requirement to inform data subjects about data obtained from third-party sources.
Under this clause, individuals may have Personal Data including employment details, social media usernames, and social media activity held by Calendly even if they have never used or signed up for the service. This data is stated to be used for Calendly's sales and marketing efforts.
Cross-platform context
See how other platforms handle Third-Party Employment and Social Profile Data Acquisition and similar clauses.
Compare across platforms →Monitoring
Calendly has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We may obtain Personal Data about you from third party sources. This Personal Data may include personal and employment information from lead-generation and marketing companies. For example, these third party sources may provide Calendly with name, email address, phone number, location of business, time zone, biographical details, job title, employer (and related company details), employment seniority, social media usernames and avatars, and social media activity details. Calendly uses this information to assist with its sales and marketing efforts.Excerpt from Calendly's Privacy Notice
1. REGULATORY LANDSCAPE: Third-party data acquisition for marketing purposes engages GDPR Article 14, which requires data controllers to provide transparency notices to individuals whose data is obtained from third parties rather than directly. Under CCPA and CPRA, data acquired from data brokers must be disclosed in the notice at collection and is subject to deletion and opt-out rights. The FTC Act applies to deceptive data practices including inadequate disclosure of third-party data sourcing. 2. GOVERNANCE EXPOSURE: Medium. The breadth of data categories acquired from third parties, including social media activity details and employment seniority, may exceed what is reasonably necessary for scheduling software marketing purposes, which is a consideration under GDPR data minimization requirements. The adequacy of the notice at collection in disclosing third-party sourced data categories to California residents should be assessed. 3. JURISDICTION FLAGS: EEA and UK residents have enforceable rights under GDPR Article 14 to receive transparency notices when their data is obtained from third parties, including the identity of the data source and the purposes for which the data will be used. California residents have the right to know the categories of third-party sources from which their data is collected and can exercise deletion rights. Individuals in other states with comprehensive privacy laws may have analogous rights. 4. CONTRACT AND VENDOR IMPLICATIONS: The specific third-party lead-generation and marketing companies from which data is sourced are not identified in the notice; the reference to Clearbit (with an opt-out link) suggests at least one such vendor. Procurement and privacy teams should verify that data acquisition agreements with lead-generation vendors include representations that the data was collected with appropriate notice and legal basis. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether the notice at collection for the Calendly website adequately discloses third-party sourced data categories consistent with CCPA regulatory requirements. GDPR Article 14 compliance should be reviewed to confirm whether individuals whose data is acquired from third parties receive the required transparency notices. Data mapping should confirm which specific lead-generation vendors supply which categories of data.
This provision establishes that Calendly may hold detailed professional and social profile data about individuals who have not directly interacted with Calendly, sourced from third-party data brokers and lead-generation companies. This data flow may implicate CCPA and GDPR notice and transparency obligations, particularly regarding the requirement to inform data subjects about data obtained from third-party sources.
Under this clause, individuals may have Personal Data including employment details, social media usernames, and social media activity held by Calendly even if they have never used or signed up for the service. This data is stated to be used for Calendly's sales and marketing efforts.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Calendly.