English
consentglass · GDPR scanner for websites

HomeGuides › Service

Embedding Calendly in compliance with data protection law

The Calendly widget (assets.calendly.com) loads scripts and can set identifiers as soon as the page is opened. Appointment data, email address and visitors’ IP flow to Calendly in the USA.

Is this a risk?

If the widget loads before consent and sets non-necessary identifiers, the basis under § 25 (1) TDDDG is missing. Processing the booking data needs a legal basis (for appointment requests usually Art. 6 (1)(b)) as well as a data processing agreement and a transfer basis for the USA.

What you can do

How consentglass helps

The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.

Read on

This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.