Data Storage and International Data Transfers
Having trouble understanding where your Calendly data is stored or how it’s protected? Use this guide to learn how Calendly manages and secures user data, and what to do if you need help with international data transfers.
Data Hosting Location
Calendly stores user and invitee data in U.S.-based data centers managed by Google Cloud Services (GCS) and Amazon Web Services (AWS).
Infrastructure Compliance
Calendly’s hosting providers meet several industry standards:
- ISO 27001
- SOC 1, SOC 2 / SSAE 16 / ISAE 3402
- PCI Level 1
- FISMA Moderate
- Sarbanes-Oxley (SOX)
Learn more:
Data Encryption
Calendly encrypts your data to protect it both in transit and at rest:
- All web traffic uses TLS SHA-256 with RSA Encryption
- Data at rest is encrypted using industry standards
- Passwords are stored as salted hashes
- iCloud Calendar passwords use salted encryption
Transferring Personal Data from the EEA or UK
If you collect data from individuals in the European Economic Area (EEA) or the UK, Calendly uses legal tools to ensure safe transfer.
Key Safeguards
- Standard Contractual Clauses (SCCs) are included in Calendly’s Data Processing Agreement (DPA)
- UK Addendum is also part of the DPA for UK-specific requirements
- All sub-processors that handle your data have signed DPAs