—
US-Linked
— Not assessed
— Not assessed
— Not assessed
Munich-based HR flagship for European SMBs (founded 2015); ISO 27001 + SOC 2 + TISAX; ~$770M US-VC-funded.
Public DPA: Yes
Sub-processors: No
Open source: No
Frankfurt · DE
Germany
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
ISO/IEC 27001
SOC 2
Paid
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
Spanish HR + payroll + finance SaaS (Barcelona, est. 2016); 16K+ customers, ISO 27001 + SOC 2 + AWS EU, US-VC-funded.
Public DPA: No
Sub-processors: Yes
Open source: No
DE
Germany
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
ISO/IEC 27001
SOC 2
Paid
€7/mo
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
Sage Group plc's HR cloud product (formerly CakeHR from Riga, acquired 2019); UK-public parent, modular SMB HR.
Public DPA: Yes
Sub-processors: Yes
Open source: No
IE
Ireland
EU-Based
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
This listing
EU-operated, with at most minor or transient US exposure.
EU-Hosted
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
ISO/IEC 27001
Paid
€7/mo
Minor
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
This listing
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
French HR platform (Nantes / Paris, est. 2002); EU-owned, hosted on OVH in France and Germany; ISO 27001; 1M+ users incl. AXA, Deezer.
Public DPA: Not assessed
Sub-processors: Yes
Open source: No
FR
France
EU-Based
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
This listing
EU-operated, with at most minor or transient US exposure.
EU-Hosted
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
ISO/IEC 27001
Paid
Minor
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
This listing
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
Israeli-founded modern HRIS for mid-market (Tel Aviv + London); 5,000+ customers, heavy US VC, mostly listed for completeness.
Public DPA: Not assessed
Sub-processors: Yes
Open source: No
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
ISO/IEC 27001
SOC 2
Paid
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.