cal.com privacy policy — score 55/100 (medium risk)

Viimati analüüsitud

Aruande sisu (kokkuvõte, leitud asjaolud, tsitaadid) on genereeritud inglise keeles ja seda pole lokaliseeritud.

Käivita uus analüüs teise poliitika kohta

Cal.com, Inc. · cal.com

Aruande üksikasjad

medium risk

Cal.com provides standard GDPR rights and a subprocessor list, but fails to specify the legal basis for EU-to-US data transfers and remains silent on AI training data usage.

The privacy policy demonstrates some compliance awareness by listing GDPR rights, appointing a DPO, and naming an EU Representative. However, it suffers from significant gaps typical of US-centric policies, such as relying on vague 'adequate controls' for international data transfers without naming the legal mechanism. Furthermore, the policy is completely silent on AI model training despite the company actively marketing an AI product (Cal.ai), and it uses overly broad language regarding the personal data it collects.

Viimati analüüsitud
AllikasURL
Pikkus27,243 märki

Kategooriate kaupa hinnang

Poliitika jaotus peamistele vastavusaladele. Hea = tugev, keskmine = segane, nõrk = muret tekitav.

Data Minimizationfair

Collects standard scheduling data but uses advertising cookies and shares emails for ad matching, which goes beyond strict necessity.

Transparencyfair

Lists subprocessors and rights clearly, but the categories of personal data collected are vaguely defined.

Third-party Sharingfair

Subprocessors are well-documented, but sharing data with ad platforms like Google and Meta for audience matching raises consent questions.

International Transferspoor

Explicitly transfers EU data to the US but fails to name the legal transfer mechanism required by GDPR Chapter V.

AI/Model Trainingpoor

The policy is completely silent on whether user data is used for AI training, despite the company marketing an AI product.

User Rightsgood

Clearly lists all standard GDPR rights, provides a DPO contact, and has appointed an EU Representative under Article 27.

Peamised leitud asjaolud

Märkimisväärsed klauslid, probleemid või head tavad (kriitilised esimesena)

Kriitiline

Missing Legal Basis for International Transfers

The policy admits transferring data to the US but does not cite Standard Contractual Clauses, Binding Corporate Rules, or the EU-US Data Privacy Framework, relying instead on vague language about 'adequate controls'.

Kriitiline

Silence on AI Training Practices

Despite prominently advertising 'Cal.ai' and AI-powered calls, the privacy policy contains absolutely no disclosure regarding whether user data, meeting content, or transcripts are used to train AI models.

Hoiatus

Vague Definition of Personal Data Categories

The policy states personal data 'may include, but is not limited to: Cookies and Usage Data', failing to explicitly list the specific categories of personal data collected (e.g., name, email address) in the definitions section, violating GDPR Article 13(2)(a) specificity requirements.

Hoiatus

Ambiguous Advertising Tracking and Consent

The policy admits to using advertising cookies and sharing emails with ad platforms (Google, Meta, LinkedIn) for audience matching, framing it as a U.S.-only feature with an email opt-out, but fails to clarify how explicit GDPR-standard consent is obtained for any EU users who might fall into these tracking nets.

Kokkuvõte kasutajale

Your data will likely be shipped to the US under unspecified legal protections, and while basic GDPR rights are offered, the policy leaves dangerous gray areas around advertising tracking and AI usage.

Vastavusseisund

Mixed compliance posture; structural GDPR elements exist but substantive safeguards for international transfers and AI processing are missing.

EL-i ülekanded

Inadequate. The policy explicitly transfers data to the US but fails to name a valid GDPR transfer mechanism like Standard Contractual Clauses or the EU-US Data Privacy Framework.

Tuvastatud signaalid

Tekstis tuvastatud konkreetsed andmed ja tavad

Kogutud andmed
Email addressIP addressBrowser type and versionPages visited and time spentMobile device unique IDMobile operating systemPhone numberSMS contents
Töötlemise eesmärgid
Service provision and maintenanceCustomer supportUsage monitoring and analysisMarketing and promotional communicationsAdvertising and audience matchingSecurity and fraud prevention
Jagamine kolmandate osapooltega
Google AdsMeta (Facebook and Instagram)LinkedInPosthogGitHubTwilioDaily.coIntercomStripe
Rahvusvahelised ülekanded
Data transferred to the United StatesNo specific GDPR transfer mechanism named
Tehisintellekt / Mudeli koolitus
No mention of AI trainingNo opt-out for AI training

Tõendite väljavõtted

Otsesed tsitaadid poliitikast nende leidude toetuseks

If you are located outside United States and choose to provide information to us, please note that we transfer the data, including Personal Data, to United States and process it there.

Personally identifiable information may include, but is not limited to: Cookies and Usage Data

For users located in the United States, we may share limited information—such as your email address—with advertising platforms including Google Ads, Meta (Facebook and Instagram), and LinkedIn.

Puudub või ebaselge

  • Legal mechanism for EU-US data transfers
  • Specific categories of personal data collected
  • AI model training disclosures
  • Data retention timeframes
  • Lawful basis for processing under GDPR Article 6

Küsimused, mida küsida

  • What is the specific legal mechanism (e.g., Standard Contractual Clauses, EU-US Data Privacy Framework) used to authorize the transfer of EU personal data to the United States?
  • Is any user data, including booking content, video transcripts, or call recordings, used to train or improve the Cal.ai models or any other machine learning algorithms?
  • How is explicit consent obtained from EU users before placing advertising cookies or sharing their data with ad networks for audience matching?
  • What are the specific retention periods for the different categories of personal data you collect?
Selle analüüsi genereerib tehisintellekt ja see ei ole õigusnõuanne. Vastavusotsuste puhul konsulteeri alati kvalifitseeritud juristiga.

Jaga seda analüüsi

Igaüks, kellel on see link, saab ülalolevat tulemust vaadata.

DentroChati loodud

100% Euroopa tehisintellektivestlus kõigile

Vestle tehisintellektiga, tööta failidega, loo pilte ja otsi veebist. Andmed jäävad Euroopasse.

EL-is majutatud infrastruktuurTekst, failid, pildid ja veebiotsingKiire, Mõtlemise ja Loova režiimidPrivaatsus vaikimisi esikohalÜkski andme ei lahku Euroopast
Proovi tasuta →