VendorScore · Scheduling · Data-access posture
A plain-language answer from Calendly's security page, Help Center and DPA. Calendly reads your connected calendars to find conflicts; its exact OAuth scopes aren't published.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-07, public docs only, not legal advice.
Short answer
Yes, by design (with controls): Calendly reads connected calendars' busy times and stores booking data in plaintext with vendor-managed keys; AI and Notetaker send content to OpenAI and Recall.ai.
Scored configuration: Calendly Teams/Enterprise with domain control, SAML SSO/SCIM, audit log, Google or Microsoft 365 calendar via OAuth, Notetaker not auto-added to all meetings.
Default setup with Notetaker enabled (it auto-joins all future meetings) scores lower; the report estimates Overall ~52.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
Calendly uses OAuth for Google and Office 365 and says it accesses only the minimum calendar data needed; exact scopes aren't published.
Evidence: Calendly platform security & complianceNo training on customer data, but AI logs are stored to improve accuracy and authorized staff may access them to support or improve the product.
Evidence: AI at CalendlyNotetaker recordings are processed by Recall.ai and summaries by OpenAI; Notetaker auto-joins all future meetings once enabled.
Evidence: Calendly Notetaker FAQOur report flags these gaps in Calendly's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, by design (with controls): Calendly reads connected calendars' busy times and stores booking data in plaintext with vendor-managed keys; AI and Notetaker send content to OpenAI and Recall.ai. VendorScore rates Calendly 53/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Calendly Teams/Enterprise with domain control, SAML SSO/SCIM, audit log, Google or Microsoft 365 calendar via OAuth, Notetaker not auto-added to all meetings.
Calendly connects to Google and Office 365 calendars via OAuth and says it "is built to only access the minimum data needed from connected calendars": it checks the calendars you choose for conflicts and writes new meetings to one calendar. The exact OAuth scopes, and whether event titles or details are read or stored, aren't stated. Data is encrypted at rest with AES-256 and in transit with TLS 1.2+, with vendor-managed keys on Google Cloud (AWS for Notetaker data); there's no customer-managed key option and no E2EE claim.
Calendly says internal access is "on a need to know basis". AI-related logs are kept to improve accuracy, and access to them "is limited to authorized personnel who require it to support or improve the product". Support tools include Upscope screen sharing, Intercom and Zendesk. We found no customer-visible log of Calendly staff access.
No, per Calendly: "Calendly does not sell customer data or use customer data to train AI models. Third-party AI providers are prohibited from using customer data to train their models." But AI-related logs are stored "to improve accuracy", and authorized staff may access them. Calendly uses OpenAI models and doesn't offer an opt-out for AI features beyond not using them.
VendorScore doesn't certify compliance; Calendly publishes a DPA at https://calendly.com/legal/data-processing-addendum. Calendly's DPA gives at least 30 days' notice of new subprocessors only if you subscribe; otherwise you waive prior notice. You can object within 30 days.
Calendly's list (updated 2026-08-20) at https://calendly.com/help/calendly-sub-processors-gdpr-ccpa has 20 entries, including Google and AWS, OpenAI (AI features, Notetaker meeting summaries, SMS compliance), Hyperdoc/Recall.ai (audio/video recording for Notetaker), Intercom, Zendesk and Upscope. Data centres are mostly in the USA.
Not documented. Notetaker data is stored in U.S. data centres run by Google and AWS, and nearly all subprocessors are US-located.
Every URL cited on this page. Score, key findings and FAQ: VendorScore report (calendly.md), evidence dated 2026-10-07.