Calendly Subprocessors List (September 2026): Changes and History

Calendly names 20 subprocessors on its published list. Read from the vendor's own page and re-checked daily.

Last checked September 26, 2026 Official source ↗

Calendly subprocessors (September 2026)

# Subprocessor Purpose Location
1 Aiven Infrastructure USA
2 Amazon Web Services Infrastructure USA
3 Assembled User support management USA
4 Cloudflare Content Delivery Network (CDN) and Distributed Denial of Service (DDoS) mitigation USA
5 Datadog Infrastructure performance monitoring and business Analytics USA
6 E-HAWK Malicious actor detection and prevention USA, Netherlands
7 Elasticsearch In-app search services USA
8 Google Infrastructure and analytics USA
9 Hex Product related data analysis and visualization USA
10 Hyperdoc (a.k.a. Recall.ai) Processes audio/video recording for Calendly Notetaker USA
11 Intercom Customer support enablement USA
12 Loris.ai Customer support tool USA
13 Monte Carlo Data quality observability USA
14 OpenAI AI features, Notetaker meeting summaries, SMS compliance USA
15 Redis Manages in-memory data storage and caching services USA, Israel
16 Sprig Customer feedback tool USA
17 Temporal Technologies Supports background workflows to sync Gmail metadata for contact email threads USA
18 Twilio SMS provider and domain-based message authentication, reporting and conformance USA
19 Upscope Interactive screen sharing for customer support assistance USA, UK
20 Zendesk Customer service communication tool USA

Get an email when Calendly changes its subprocessors

ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.

Track Calendly free

Key DPA terms at Calendly

What Calendly's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?

Breach notification

Without undue delay, with no set deadline

“notify Customer of the Security Breach without undue delay”
DPA, calendly.com ↗
Notice of a new subprocessor

30 days ahead

“Calendly will notify Customer via such mechanism if Customer has signed up to receive notification of any such additions at least thirty (30) days prior to any such additions taking effect.”
DPA, calendly.com ↗
Transfers outside the EU

Standard contractual clauses and the EU–US Data Privacy Framework

“Calendly is self-certified under the Data Privacy Frameworks and will adhere to its obligations under the Data Privacy Frameworks.”
“Module 2 of the SCCs for Controller to Processor transfers, together with the options and amendments set out in Exhibit B to this DPA, shall apply and are incorporated into this DPA.”
DPA, calendly.com ↗
Customer data after the contract ends

Deleted or returned when the contract ends

“Calendly shall return or securely destroy Personal Data, in accordance with Customer's Instructions, upon Customer's request or upon termination of Customer's account(s), unless Personal Data must be retained to comply with Applicable Laws.”
DPA, calendly.com ↗
Audit rights

Through certifications and audit reports only

“Within thirty (30) days of Customer's written request, and no more than once annually, Calendly shall make available to Customer (or a mutually agreed upon third-party auditor) information reasonably necessary to demonstrate Calendly's compliance with the obligations set forth in this DPA in the form of its most recent third party audit or certification report(s) (such as SOC 2 or ISO 27001).”
DPA, calendly.com ↗

Documents we track for Calendly

DPA
checked September 26, 2026 calendly.com ↗
Privacy policy
checked September 26, 2026 calendly.com ↗
Subprocessor list
checked September 26, 2026 calendly.com ↗
Terms of service
checked September 26, 2026 calendly.com ↗

Change history

Tracking since September 26, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.

Calendly subprocessors FAQ

How many subprocessors does Calendly use?
Calendly lists 20 subprocessors on its published list, including Aiven, Amazon Web Services, Assembled, Cloudflare, and Datadog and 15 more.
Where does Calendly process customer data?
The subprocessors named by Calendly are located in USA, Israel, Netherlands, and UK, as stated on its list.
How quickly does Calendly report a personal data breach to customers?
According to its DPA, Calendly reports a personal data breach to customers without undue delay, with no set deadline: “notify Customer of the Security Breach without undue delay”
How much notice does Calendly give before adding a subprocessor?
Calendly's DPA gives 30 days' notice of a new subprocessor, the time customers have to object: “Calendly will notify Customer via such mechanism if Customer has signed up to receive notification of any such additions at least thirty (30) days prior to any such additions taking effect.”
How does Calendly transfer personal data outside the EU?
Calendly's DPA relies on standard contractual clauses and the EU–US Data Privacy Framework: “Calendly is self-certified under the Data Privacy Frameworks and will adhere to its obligations under the Data Privacy Frameworks.”
When was Calendly's subprocessor list last checked?
ClauseTrail last checked Calendly's subprocessor list on September 26, 2026. Lists are re-checked daily.
How do I find out when Calendly adds or removes a subprocessor?
ClauseTrail monitors Calendly's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.