When you use Calendly to collect information from people who book time with you, you are legally responsible for that data collection, including getting any required permissions from those individuals.
This analysis describes what Calendly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Business users who share booking pages publicly are treated as the data controller for all information submitted by meeting invitees, meaning GDPR, CCPA, and other privacy obligations fall on the customer, not Calendly.
Interpretive note: The precise scope of customer controller obligations may vary by jurisdiction and the nature of data collected; GDPR and CCPA apply different standards for lawful basis and notice requirements.
Removal of explicit data processing limitation (processing only on behalf of customer and per instructions) eliminates restrictions on how Calendly can use invitee data, paired with new provisions allowing third-party AI sharing and expanded internal uses.
View full change record →This clause places full legal responsibility on the Calendly customer for any personal information collected from meeting invitees through their booking pages, including the obligation to have a lawful basis for collection and to obtain required consent under applicable privacy law.
How other platforms handle this
Where ZipRecruiter processes your Personal Data in the capacity of a service provider (data processor), and you seek access, or want to correct, amend, or delete your Personal Data...we will provide you with the data controller's contact information, so you can contact them directly.
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
"Customers may use the Services to collect information from Invitees. Customer is solely responsible for ensuring that any such collection, use, and disclosure of Invitee information complies with all applicable laws and regulations, including obtaining any required consents from Invitees. Calendly processes Invitee information on behalf of the Customer and in accordance with Customer's instructions.Excerpt from Calendly's Terms of Use
(1) REGULATORY LANDSCAPE: This provision directly engages GDPR Articles 4, 24, and 28, which define controller and processor roles and obligations.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Business users who share booking pages publicly are treated as the data controller for all information submitted by meeting invitees, meaning GDPR, CCPA, and other privacy obligations fall on the customer, not Calendly.
This clause places full legal responsibility on the Calendly customer for any personal information collected from meeting invitees through their booking pages, including the obligation to have a lawful basis for collection and to obtain required consent under applicable privacy law.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Calendly.