Cal.com — Cal.com, Inc., USA
Your submission does not appear in the directory straight away. We look at the evidence and, if it holds, write a new assessment with a date and a record of the change. That separation is precisely what makes the entry worth something to your customers. It costs you nothing.
| Criterion | In the directory |
|---|---|
| Data processing agreement | Cal.com stellt den Auftragsverarbeitungsvertrag im Sicherheitsbereich zum Herunterladen bereit — neben den Prüfberichten und unter der Überschrift „Access compliance documents, certifications, and data protection agreements“: „Data Protection Agreement — Download“. Das Dokument ist damit einsehbar, ohne dass man den Vertrieb ansprechen muss. … h any personal data are, or are to be, processed. For the purpose of this Privacy Policy, we are a Data Controller of your data. DATA PROCESSORS (OR SERVICE PROVIDERS) means any natural or legal person wh … (Quelle: https://cal.com/privacy, abgerufen 2026-08-01 · maschinell gefunden, Regelwerk 3.0, Regel „Anhaltspunkt: Anbieter sieht sich als Verantwortlicher“) |
| Place of processing | Kein Speicherort und keine Übermittlungsgrundlage genannt. Für Cal.com ist das besonders bedauerlich: Der Dienst ist quelloffen und lässt sich selbst betreiben — womit sich die Frage nach dem Speicherort für den Betreiber vollständig anders stellt als für die gehostete Fassung. Die gelesenen Seiten unterscheiden die beiden Fälle nicht. |
| Training on customer data | Keine Aussage dazu gefunden, ob Termindaten zum Training verwendet werden. |
| Certifications | Cal.com weist im Sicherheitsbereich aus: „As a company that has achieved ISO 27001, SOC 2 Type II, CCPA, GDPR, and HIPAA certifications, we understand the critical importance of information security.“ Ungewöhnlich ist, dass die Nachweise nicht nur behauptet, sondern zum Herunterladen bereitgestellt werden: „Download SOC 2 Type II report“, „Download ISO 27001 Certification“ und ein Bericht über einen Eindringtest. Damit gehört Cal.com zu den wenigen Anbietern im Verzeichnis, bei denen sich die Angabe ohne Anmeldung am Original prüfen lässt. Als Zertifizierungen führen wir davon ISO 27001 und SOC 2 Typ II; DSGVO, CCPA und HIPAA sind Rechtsakte und keine Normen. |
| Subprocessors | Keine namentliche Liste. Die Datenschutzerklärung nennt nur Kategorien: „to our subsidiaries and affiliates; to contractors, service providers, and other third parties we use to support our business“. |
Would you like to maintain the entry and be heard before changes? A correction with evidence does not require that — it is covered by the vendor programme.
The interface is available in English. Directory entries, the AI register we produce, the quarterly record and the contract annexes remain in German — they are the authoritative documents.
Deutsch · English