Cal.com
Zusammenfassung aus Eigentümerschaft und CLOUD-Act-Risiko.
-
EU-souverän In EU-/EWR-/Schweizer Eigentum und betrieben, ohne erkennbares CLOUD-Act-Risiko.
-
EU-ansässig EU-betrieben, mit höchstens geringfügigem oder vorübergehendem US-Bezug.
-
EU-gehostet EU-Hosting verfügbar, aber ein US-Mutterkonzern oder Hyperscaler-Unterauftragsverarbeiter erzeugt ein materielles Risiko.
-
US-verbunden Dieser Eintrag Von einem US-Unternehmen betrieben, direkt der US-Jurisdiktion unterworfen.
US-incorporated open-source Calendly alternative (Cal.com Inc, SF) founded by EU developers; production code moving closed-source in 2026.
Cal.com wird von einem US-Unternehmen betrieben und unterliegt damit direkt dem CLOUD Act. Gelistet unter Terminbuchung.
Bewertungsnotizen
Cal.com is US-incorporated as Cal.com, Inc. (San Francisco) despite its EU-founder origin (Peer Richelsen + Bailey Pumfleet, 2021): Delaware-style US corporation, US$32M VC-funded, and the privacy policy explicitly states data is transferred to and maintained in the US. Since the August 2026 privacy-policy rewrite the company runs a public Trust Center that names 19 sub-processors, every one of them US-located, including Amazon RDS Postgres and AWS S3 for the primary database and file storage, Vercel for hosting and CDN, Cloudflare R2, Stripe and Whop for payments, Twilio and SendGrid for SMS and transactional email, Daily.co for Cal Video, and OpenAI, Anthropic and Retell AI for meeting notes, in-product assistants and Cal.ai phone agents. Connected calendars and video tools (Google, Microsoft, Apple/CalDAV, Zoom) are explicitly framed as customer-authorised integrations, "your processors, not ours". ISO 27001 and SOC 2 Type 2 are now attested but the certificates and the DPA sit behind an NDA-gated access portal (trust.cal.com/access) rather than being publicly readable, which caps the score at 3. In 2026 Cal.com began moving its production codebase behind closed doors with only a stripped community edition (Cal.diy, MIT) remaining open-source, so the historical 'open-source Calendly alternative' positioning is degrading. The hosted SaaS carries direct CLOUD Act exposure as a US-incorporated entity (US-owned, US-hosted, no public DPA) and should not be the procurement-grade choice for strict EU buyers; the self-host path via Cal.diy on EU infrastructure (EU-hosted, no CLOUD Act exposure for that path) is the only structurally clean option. Alternatives in the category (SuperSaaS NL, Reservio CZ, Doodle CH, Cronofy UK) are all structurally cleaner from an EU-sovereignty perspective.
Befund
- CLOUD Act
- CLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
-
Keines EU-Betreiber, kein US-Mutterkonzern, keine relevanten US-Unterauftragsverarbeiter.
-
Gering Ein vorübergehender US-Unterauftragsverarbeiter (CDN, Karten); ruhende Daten bleiben in der EU.
-
Erheblich US-Mutterkonzern oder ein zentraler Unterauftragsverarbeiter ist ein US-Hyperscaler.
-
Direkt Dieser Eintrag Der Betreiber selbst ist US-ansässig.
-
- Eigentümer
- Eigentümerschaft
Wo die letztliche Kontrolle über das Betreiberunternehmen liegt.
-
EU-Eigentum In der EU ansässig und EU-kontrolliert; keine nennenswerte US-Beteiligung.
-
EU-Sitz, US-finanziert EU-Hauptsitz, aber von US-Risikokapital oder -Private-Equity kontrolliert.
-
EU-Tochter, US-Mutter Europäische Betriebsgesellschaft im Eigentum einer US-Muttergesellschaft.
-
US-Eigentum Dieser Eintrag Das Betreiberunternehmen selbst hat seinen Hauptsitz in den USA.
-
Sonstige Eine Nicht-EU-Jurisdiktion. Schweizer/EWR-Eigentum gilt hier als europäisch; UK und andere nicht.
-
- Unterauftragsverarbeiter
- 19 · 19 US
Geprüfte Signale
-
EU-/Angemessenheits-Hosting: Nein
-
EU-/Angemessenheits-Betreiber: Nein
-
Keine US-CLOUD-Act-Exposition: Nein
-
Öffentlicher AVV: Nein
-
Unterauftragsverarbeiter offengelegt: Ja
-
Open-Source-Clients: Ja
-
Zertifizierung durch Dritte: Ja
Die Exposition hängt davon ab, wie Sie dieses Produkt betreiben.
Anbieterbetrieben: die unten genannten Unterauftragsverarbeiter gelten.
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
-
Keines EU-Betreiber, kein US-Mutterkonzern, keine relevanten US-Unterauftragsverarbeiter.
-
Gering Ein vorübergehender US-Unterauftragsverarbeiter (CDN, Karten); ruhende Daten bleiben in der EU.
-
Erheblich US-Mutterkonzern oder ein zentraler Unterauftragsverarbeiter ist ein US-Hyperscaler.
-
Direkt Dieser Eintrag Der Betreiber selbst ist US-ansässig.
Auf eigener EU-Infrastruktur betreiben: Sie kontrollieren Hosting und jeden Unterauftragsverarbeiter.
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
-
Keines Dieser Eintrag EU-Betreiber, kein US-Mutterkonzern, keine relevanten US-Unterauftragsverarbeiter.
-
Gering Ein vorübergehender US-Unterauftragsverarbeiter (CDN, Karten); ruhende Daten bleiben in der EU.
-
Erheblich US-Mutterkonzern oder ein zentraler Unterauftragsverarbeiter ist ein US-Hyperscaler.
-
Direkt Der Betreiber selbst ist US-ansässig.
Springen zu
Über Cal.com
Cal.com is one of the most-cited "open-source Calendly alternative" SaaS products of the past few years, founded in 2021 by Peer Richelsen (German) and Bailey Pumfleet (UK), with the commercial entity incorporated as Cal.com, Inc. in San Francisco, California despite the EU-founder origin. The company has raised approximately US$32M in venture funding and the GitHub repository (calcom/cal.com) has accumulated more than 41,000 stars since launch. The product replaces Calendly's hosted scheduling experience with a self-hostable, AGPLv3-licensed open-source codebase plus a managed SaaS (cal.com), a model that was the directory's reference "EU founders bringing US-style SaaS open-source pressure" story until 2026.
The 2026 strategic shift complicates the listing. Per public reporting and direct corporate communication, Cal.com is moving its production codebase behind closed doors during 2026, leaving only a stripped community edition called Cal.diy under the more-permissive MIT licence, while rewritten authentication, data-handling, and commercial systems become proprietary. This narrows the structural "fork-if-anything-changes" guarantee that historically distinguished Cal.com from Calendly. For procurement-grade EU buyers the picture is now: (a) the hosted Cal.com SaaS is US-incorporated under Cal.com, Inc. and subject to US extraterritorial law by default, direct CLOUD Act exposure under our strict-ownership stance; (b) the privacy policy explicitly confirms data transfers to the United States, and the Trust Center now publishes 19 sub-processors, every one of them US-located, including Amazon RDS Postgres and AWS S3 for the primary database and file storage, Vercel for hosting and CDN, Cloudflare R2, Stripe and Whop for payments, Twilio and SendGrid for messaging, Daily.co for Cal Video, and OpenAI, Anthropic and Retell AI for meeting notes, in-product assistants and Cal.ai phone agents; PostHog is now listed as United States as well; (c) the Cal.diy MIT community edition on EU infrastructure (Hetzner, OVHcloud, Scaleway) remains a legitimate self-host option but with reduced feature parity vs the proprietary hosted product. ISO 27001 and SOC 2 Type 2 are now attested, but both certificates and the DPA sit behind an NDA acceptance flow at the Trust Center rather than being publicly readable, so a buyer cannot read them before signing.
Pricing for the hosted SaaS is freemium and quoted in USD only: Free at $0, Teams at $12 per user per month, Organizations at $28 per user per month, and a custom Enterprise tier; the page carries a yearly "Save 25%" label without stating whether the headline figures are the monthly or the annual-billing rate. Best fit: developers and product builders who specifically want the Cal.com API surface and accept US-incorporation; teams comfortable with the new MIT/Cal.diy self-host path on EU infrastructure for sovereignty. Procurement-grade EU-only buyers needing a structurally EU-incorporated counter-party should choose SuperSaaS (NL, founder-owned), Doodle (CH, TX Group) or Reservio (CZ, ABUGO Group) instead; all are listed elsewhere in this category, and all three carry US-owned providers of their own further down the chain.
Unterauftragsverarbeiter-Karte · 19
-
Amazon RDS Postgres USVereinigte Staaten
Primary Postgres database for the product
-
Amazon Web Services (S3) USVereinigte Staaten
File and media storage
-
Anthropic USVereinigte Staaten
In-product AI assistants (e.g. building routing forms)
-
Cloudflare USVereinigte Staaten
File and media storage (R2); alternative email transport
-
Daily.co USVereinigte Staaten
Cal Video: video calls, recordings, transcripts
-
Dub USVereinigte Staaten
Website and signup attribution
-
Google Analytics / Google Tag Manager USVereinigte Staaten
Marketing-site traffic measurement
-
Intercom USVereinigte Staaten
Support chat and support tickets
-
Metabase Cloud USVereinigte Staaten
Internal business intelligence and analytics
-
OpenAI USVereinigte Staaten
AI meeting notes: summarizing Cal Video transcripts
-
PostHog USVereinigte Staaten
Product analytics
-
Retell AI USVereinigte Staaten
Cal.ai phone agents that place or take calls
-
SendGrid (Twilio) USVereinigte Staaten
Transactional email delivery: confirmations, reminders, invites
-
Slack USVereinigte Staaten
Internal and external communication
-
Stripe USVereinigte Staaten
Subscriptions, checkout, invoices, and customer-collected booking payments
-
Twilio USVereinigte Staaten
SMS and WhatsApp reminders, phone verification, phone number lookup
-
Vercel USVereinigte Staaten
Hosting and CDN for the app and website; website analytics
-
Whop USVereinigte Staaten
Global payment-processing platform powering Cal Pay
-
X (Twitter) Ads USVereinigte Staaten
Ad measurement
| Anbieter | Land | Zweck | Eigentümer |
|---|---|---|---|
| Amazon RDS Postgres | Vereinigte Staaten | Primary Postgres database for the product | US |
| Amazon Web Services (S3) | Vereinigte Staaten | File and media storage | US |
| Anthropic | Vereinigte Staaten | In-product AI assistants (e.g. building routing forms) | US |
| Cloudflare | Vereinigte Staaten | File and media storage (R2); alternative email transport | US |
| Daily.co | Vereinigte Staaten | Cal Video: video calls, recordings, transcripts | US |
| Dub | Vereinigte Staaten | Website and signup attribution | US |
| Google Analytics / Google Tag Manager | Vereinigte Staaten | Marketing-site traffic measurement | US |
| Intercom | Vereinigte Staaten | Support chat and support tickets | US |
| Metabase Cloud | Vereinigte Staaten | Internal business intelligence and analytics | US |
| OpenAI | Vereinigte Staaten | AI meeting notes: summarizing Cal Video transcripts | US |
| PostHog | Vereinigte Staaten | Product analytics | US |
| Retell AI | Vereinigte Staaten | Cal.ai phone agents that place or take calls | US |
| SendGrid (Twilio) | Vereinigte Staaten | Transactional email delivery: confirmations, reminders, invites | US |
| Slack | Vereinigte Staaten | Internal and external communication | US |
| Stripe | Vereinigte Staaten | Subscriptions, checkout, invoices, and customer-collected booking payments | US |
| Twilio | Vereinigte Staaten | SMS and WhatsApp reminders, phone verification, phone number lookup | US |
| Vercel | Vereinigte Staaten | Hosting and CDN for the app and website; website analytics | US |
| Whop | Vereinigte Staaten | Global payment-processing platform powering Cal Pay | US |
| X (Twitter) Ads | Vereinigte Staaten | Ad measurement | US |
Quelle: veröffentlichte Unterauftragsverarbeiter-Liste des Anbieters, gelesen am 26 Aug 2026.
Rahmenwerke & Zertifizierungen
Funktionsmatrix
Tabelle 2Funktionen von Cal.com
Integration & Zugriff
Compliance & Governance
Preise & Tarife
Öffentliche Dokumente
Alternativen in dieser Kategorie
-
Vereinigtes KönigreichEU-gehostetCLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
-
Keines EU-Betreiber, kein US-Mutterkonzern, keine relevanten US-Unterauftragsverarbeiter.
-
Gering Ein vorübergehender US-Unterauftragsverarbeiter (CDN, Karten); ruhende Daten bleiben in der EU.
-
Erheblich Dieser Eintrag US-Mutterkonzern oder ein zentraler Unterauftragsverarbeiter ist ein US-Hyperscaler.
-
Direkt Der Betreiber selbst ist US-ansässig.
Öffentl. AVV: Nein Subprozessoren: Nein Open Source: Nein -
-
SchweizEU-gehostetCLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
-
Keines EU-Betreiber, kein US-Mutterkonzern, keine relevanten US-Unterauftragsverarbeiter.
-
Gering Ein vorübergehender US-Unterauftragsverarbeiter (CDN, Karten); ruhende Daten bleiben in der EU.
-
Erheblich Dieser Eintrag US-Mutterkonzern oder ein zentraler Unterauftragsverarbeiter ist ein US-Hyperscaler.
-
Direkt Der Betreiber selbst ist US-ansässig.
Öffentl. AVV: Ja Subprozessoren: Ja Open Source: Nein -
-
TschechienEU-gehostetCLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
-
Keines EU-Betreiber, kein US-Mutterkonzern, keine relevanten US-Unterauftragsverarbeiter.
-
Gering Ein vorübergehender US-Unterauftragsverarbeiter (CDN, Karten); ruhende Daten bleiben in der EU.
-
Erheblich Dieser Eintrag US-Mutterkonzern oder ein zentraler Unterauftragsverarbeiter ist ein US-Hyperscaler.
-
Direkt Der Betreiber selbst ist US-ansässig.
Öffentl. AVV: Ja Subprozessoren: Ja Open Source: Nein -
| Produkt | Souveränität | CLOUD Act | Signale | Ab |
|---|---|---|---|---|
|
|
EU-gehostet | CLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
|
Öffentl. AVV: Nein
Subprozessoren: Nein
Open Source: Nein
|
— |
|
|
EU-gehostet | CLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
|
Öffentl. AVV: Ja
Subprozessoren: Ja
Open Source: Nein
|
— |
|
|
EU-gehostet | CLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
|
Öffentl. AVV: Ja
Subprozessoren: Ja
Open Source: Nein
|
— |