Security and Privacy
OneCal is built for people who connect their work and personal calendars to it, so protecting that data is a core part of the product. This page explains which standards OneCal is audited against, how we handle your calendar data, and where to find the documents your security team may ask for.
SOC 2 Type II
OneCal is SOC 2 Type II compliant. OneCal is the first calendar synchronization platform to complete a SOC 2 Type II audit.
SOC 2 is a widely recognized standard for how a company protects customer data. A Type II audit goes further than checking that security controls exist: an independent auditor also assesses whether those controls have operated effectively over an extended period of time. Our audit covered security, privacy, infrastructure, access controls, monitoring, incident response, and the internal processes behind how OneCal is built and run.
Privacy and security remain a long term commitment for us. We continue to invest in them as OneCal grows.
To review the SOC 2 Type II report and our latest penetration test report, open the OneCal Trust Center and request access. Both are shared under a non-disclosure agreement.
GDPR
OneCal is GDPR compliant. Our standard Data Processing Addendum, including the European Commission's Standard Contractual Clauses for international transfers, is available at onecal.io/dpa.
You can exercise your data protection rights, such as access, correction or deletion, by writing to contact@onecal.io. You can also delete your account yourself at any time from the Settings page.
How OneCal handles your calendar data
- OneCal connects to Google and Outlook over OAuth2, so we never see or store your passwords. iCloud uses an app-specific password that you can revoke at any time.
- OneCal requests only the calendar permissions it needs to read your events and write clone events and bookings.
- OneCal does not analyze or sell your calendar data.
- Your data is encrypted in transit and at rest, and hosted on Amazon Web Services.
- Your data is never used to train AI models. This applies to OneCal, and it applies to the AI provider that processes your AI Assistant messages.
Resources
- Trust Center: Our policies, security controls, and where to request the SOC 2 Type II and penetration test reports.
- Data security: An overview of how OneCal secures its infrastructure.
- Privacy Policy: What data OneCal collects, how it is used, and how long it is kept.
- Subprocessors: The companies that process data on OneCal's behalf.
- Data Processing Addendum: Our standard DPA for GDPR.
- SOC 2 announcement: The announcement on our blog.
Security settings you control
- Login Methods: Choose how you sign in, including SSO for teams.
- Support Access and Impersonation: Decide whether OneCal support or your team admins can sign in to your account to help you.
- Audit Logs: See who did what in your team.
- API Keys and MCP clients: Review and revoke programmatic access.
Good To Know
If your security team needs a completed security questionnaire, our policies, or the SOC 2 and penetration test reports, request them through the Trust Center or contact us.