Skip to content
Bookly
FeaturesPricingDocsChangelog
Get started
Bookly

The meeting is booked. Bookly handles the rest.

Open source under AGPL-3.0. Self-host it, or let us run it for you.

Product

  • Features
  • Why Bookly
  • Pricing
  • Changelog
  • Documentation

Self-host

  • GitHub
  • Install guide
  • API reference
  • Report an issue

Company

  • About
  • Contact
  • Security

Legal

  • Privacy policy
  • Terms of service
  • Data processing agreement
© 2026 Cloudeo Solutions, LLC. Built by Ahmad Hakroosh.support@bookly-app.io

Data processing agreement

This agreement applies whenever Bookly processes personal data of your guests and contacts on your behalf. It forms part of the terms of service; no signature is needed. A signed copy is available on request.

Last updated September 23, 2026

1. Parties and roles

The customer is the person or organisation that owns a workspace. The processor is Cloudeo Solutions, LLC, Cloudeo Solutions, LLC (“Bookly”). For the personal data of guests, contacts and meeting participants that the customer puts into Bookly or that arrives through bookings, the customer is the controller and Bookly the processor. For the customer's own account data Bookly is the controller, as described in the privacy policy.

2. What is processed

Names, email addresses, phone numbers, company names, booking details, answers to booking questions, notes the customer writes, meeting transcripts and recaps where the customer has turned transcription on, payment status, and the metadata that goes with all of it. Data subjects are the customer's guests, contacts and anyone else on a transcribed call. Processing lasts as long as the workspace exists and up to 30 days afterwards for backups.

3. Instructions

Bookly processes this data only to provide the service as documented, on the customer's instructions given through the product (creating event types, turning on integrations, sending emails, and so on), and as the law requires. Bookly will tell the customer if an instruction appears to break data-protection law.

4. Confidentiality and staff

Only named staff with a need can access customer data, under a duty of confidentiality, and every operator action on the hosted service is written to an audit log.

5. Security

The measures on the security page apply: encryption in transit and at rest, encrypted integration tokens, scoped API keys, rate limiting, signed webhooks, daily backups kept for 30 days, and dependency audits in CI. The software is open source, so the customer can inspect exactly how data is handled.

6. Sub-processors

The customer authorises the sub-processors below. Each is bound by a written agreement with obligations no weaker than this one. Bookly will publish changes to this list here at least 14 days before a new sub-processor handles customer data and email workspace owners; a customer who objects on reasonable grounds can end the service and export their data before the change.

Sub-processorPurposeLocation
VercelApplication hosting and edge networkUnited States (global edge)
NeonPostgreSQL database and backupsUnited States
UpstashJob queue, rate limitingUnited States
ResendTransactional and host email deliveryUnited States
Daily.coBookly video calls and their transcriptionUnited States
Recall.aiNotetaker for Google Meet, Teams and Zoom callsUnited States
StripeSubscriptions, paid bookings, payouts to hostsUnited States
AnthropicAI briefings, recaps and drafts (no training on your data)United States
SentryError reports (guest emails and phone numbers removed first)United States

Integrations the customer connects (Google, Microsoft, Zoom, HubSpot, Pipedrive) receive data under the customer's own agreements with those providers and are not sub-processors of Bookly.

7. International transfers

Data is processed in the United States. For data subjects in the EU, UK or Switzerland, transfers rely on the EU Standard Contractual Clauses (module two, controller to processor) and the UK addendum, which are incorporated here by reference, or on an adequacy decision such as the EU-US Data Privacy Framework where a sub-processor is certified under it.

8. Helping the customer

Bookly helps the customer answer data-subject requests: workspace export and deletion, per-contact editing and deletion, and transcript deletion are in the product, and guests can cancel bookings, unsubscribe from a host's emails and delete their transcript themselves. Requests that reach Bookly directly are forwarded to the customer without undue delay. Bookly will also help with data-protection impact assessments and consultations with a supervisory authority where the customer needs it.

9. Personal-data breaches

Bookly will notify the customer without undue delay, and at most 72 hours after becoming aware of a breach affecting their data, by email to the workspace owners, with what is known about the nature of the breach, the data and people affected, the likely consequences and the measures taken.

10. Deletion and return

The customer can export all workspace data at any time and delete the workspace from settings. On deletion Bookly removes the data and, within 30 days, the copies in backups, unless the law requires keeping some of it (billing records, for example).

11. Audit

Bookly will provide the information needed to show compliance with this agreement: this page, the security page, the public source code, and on request a summary of the sub-processors' own certifications. If that is not enough for a lawful audit request, the customer may audit once a year, on 30 days' notice, at reasonable times and cost.

12. Precedence

If this agreement conflicts with the terms of service, this agreement wins for data-protection matters. Liability is governed by the terms. Questions: support@bookly-app.io.

Sign in