Acuity Scheduling
benchmark · US
—
US-Linked
— Not assessed
— Not assessed
— Not assessed
US-incorporated open-source Calendly alternative (Cal.com Inc, SF) founded by EU developers; production code moving closed-source in 2026.
Public DPA: No
Sub-processors: Yes
Open source: Yes
US
United States
US-Linked
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
This listing
Operated by a US-incorporated entity, directly subject to US jurisdiction.
self-host
EU-Hosted
ISO/IEC 27001
SOC 2
Freemium
$12/mo
Direct
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
This listing
The operator itself is US-incorporated.
Nottingham UK developer-API-first calendar / scheduling platform (Cronofy, founded 2013), ISO 27001 + SOC 2; Wise / GoCardless / Indeed customers.
Public DPA: No
Sub-processors: No
Open source: No
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
ISO/IEC 27001
ISO/IEC 27018
+2 more
Paid
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
Brno-based Czech booking platform (Reservio s.r.o., ABUGO Group), 500k+ businesses, freemium with branded customer apps.
Public DPA: Yes
Sub-processors: Yes
Open source: No
CZ
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
—
Freemium
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
Amsterdam-based Dutch appointment scheduling (SuperSaaS B.V., founded 2007 by Jan M. Faber), unfunded founder-owned, 205k+ businesses, 35 languages.
Public DPA: Yes
Sub-processors: Yes
Open source: No
NL
Netherlands
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
—
Freemium
€7/mo
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
Swiss group-scheduling pioneer (Doodle AG, Zurich, 2007), owned by TX Group (SIX-listed Swiss media holding); SOC 2 + GDPR + HIPAA.
Public DPA: Yes
Sub-processors: Yes
Open source: No
DE
Germany
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
SOC 2
Freemium
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.