Correction

Cal.com — Cal.com, Inc., USA

What happens to your submission

Your submission does not appear in the directory straight away. We look at the evidence and, if it holds, write a new assessment with a date and a record of the change. That separation is precisely what makes the entry worth something to your customers. It costs you nothing.

Current state
CriterionIn the directory
Data processing agreementCal.com stellt den Auftragsverarbeitungsvertrag im Sicherheitsbereich zum Herunterladen bereit — neben den Prüfberichten und unter der Überschrift „Access compliance documents, certifications, and data protection agreements“: „Data Protection Agreement — Download“. Das Dokument ist damit einsehbar, ohne dass man den Vertrieb ansprechen muss. … h any personal data are, or are to be, processed. For the purpose of this Privacy Policy, we are a Data Controller of your data. DATA PROCESSORS (OR SERVICE PROVIDERS) means any natural or legal person wh … (Quelle: https://cal.com/privacy, abgerufen 2026-08-01 · maschinell gefunden, Regelwerk 3.0, Regel „Anhaltspunkt: Anbieter sieht sich als Verantwortlicher“)
Place of processingKein Speicherort und keine Übermittlungsgrundlage genannt. Für Cal.com ist das besonders bedauerlich: Der Dienst ist quelloffen und lässt sich selbst betreiben — womit sich die Frage nach dem Speicherort für den Betreiber vollständig anders stellt als für die gehostete Fassung. Die gelesenen Seiten unterscheiden die beiden Fälle nicht.
Training on customer dataKeine Aussage dazu gefunden, ob Termindaten zum Training verwendet werden.
CertificationsCal.com weist im Sicherheitsbereich aus: „As a company that has achieved ISO 27001, SOC 2 Type II, CCPA, GDPR, and HIPAA certifications, we understand the critical importance of information security.“ Ungewöhnlich ist, dass die Nachweise nicht nur behauptet, sondern zum Herunterladen bereitgestellt werden: „Download SOC 2 Type II report“, „Download ISO 27001 Certification“ und ein Bericht über einen Eindringtest. Damit gehört Cal.com zu den wenigen Anbietern im Verzeichnis, bei denen sich die Angabe ohne Anmeldung am Original prüfen lässt. Als Zertifizierungen führen wir davon ISO 27001 und SOC 2 Typ II; DSGVO, CCPA und HIPAA sind Rechtsakte und keine Normen.
SubprocessorsKeine namentliche Liste. Die Datenschutzerklärung nennt nur Kategorien: „to our subsidiaries and affiliates; to contractors, service providers, and other third parties we use to support our business“.
A publicly retrievable page carrying the statement. Best on your own domain — what we can read there, your customers can read too.
For queries about this submission only. No mailing list, no sharing.

Would you like to maintain the entry and be heard before changes? A correction with evidence does not require that — it is covered by the vendor programme.

The interface is available in English. Directory entries, the AI register we produce, the quarterly record and the contract annexes remain in German — they are the authoritative documents.

Deutsch · English