Calendly is a cloud service that simplifies meeting scheduling by securely connecting to calendar providers to check availability. We follow strict security practices.
With OAuth calendar integration, Calendly doesn't need access to your device. However, if you use the Calendly Outlook Plug-in, it must be installed to read calendar conflicts and schedule events.
Calendly’s commitment to trust
Customer trust is key to everything we do at Calendly. Our software asks for only the necessary access to provide smooth scheduling. We protect your privacy by limiting access to customer data internally. Employees receive security training, and access to internal systems is secured with multi-factor authentication.
Physical infrastructure
The Calendly application is hosted on Kubernetes / Google Cloud Services (GCS). GCS' data center operations have been accredited under:
- ISO 27001
- SOC 1 and SOC 2/SSAE 16/ISAE 3402 (Previously SAS 70 Type II)
- PCI Level 1
- FISMA Moderate
- Sarbanes-Oxley (SOX)
PCI compliance
Calendly uses Stripe, a PCI-compliant pay processor for encrypting and storing credit card details. More information on Stripe’s commitment to security and compliance can be found here. We utilize the direct Stripe javascript integration, so your credit card information never reaches Calendly’s servers.
Customer security best practices
We avoid collecting third-party passwords by utilizing OAuth authentication with Office365 and Google Calendar.
Data Encryption
- All connections from the browser to the Calendly platform are encrypted in transit using TLS SHA-256 with RSA Encryption.
- All data is encrypted when written to disk.
- User passwords are stored as salted password hashes and never accessible by any Calendly employee.
FAQs
Is Calendly GDPR compliant?
Calendly is fully committed to compliance with the General Data Protection Regulation (GDPR). We understand the importance of incorporating standards put forth by GDPR into our data practices and making sure our customers, whether citizens of the EU or businesses that use Calendly with European customers, feel secure and confident to continue using Calendly.
In response to GDPR, we have developed new features (including cookie management tools and data deletion processes), enhanced existing functionality (such as Terms of Use opt-ins), improved our documentation, and incorporated a Data Processing Addendum into our Terms of Use.
Calendly has designed its data privacy program to be compliant with GDPR, both now and as future developments come along.
Does Calendly have a Data Processing Addendum (DPA)?
We have incorporated a Data Processing Addendum into our Terms of Use. There is nothing additional for you to sign or execute, and by accepting the Terms of Use, the DPA is already in place for you.
Does Calendly’s Data Processing Addendum (DPA) include the UK Addendum to the Standard Contractual Clauses?
Yes. Calendly updated our DPA in September, 2022 to include the new UK Addendum. As one of the many data privacy law changes the UK is working through since Brexit, the UK’s Information Commissioner's office released in May, 2022 its own data transfer agreement, as well as an addendum it will allow entities to add to the 2021 EU Standard Contractual Clauses to allow for legal transfers of UK personal data to countries not deemed adequate with regard to their data protection laws, such as the United States. Parties are required to start using the transfer agreement or Standard Contractual Clauses addendum in new contracts on September 21, 2022, and are required to update existing contracts by March 21, 2024. More information regarding the UK addendum can be found on the ICO’s website. Calendly previously updated our DPA so that it includes the new version of EU Standard Contractual Clauses which came out last year. Since our DPA already incorporates the EU Standard Contractual Clauses, we have added the UK addendum to them to account for customers transferring personal data to us from the UK.
Can I get a signed version of Calendly’s Data Processing Addendum (DPA)?
Please contact us and we will be happy to process your request.