Zum Inhalt springen

Cronofy

Terminbuchung · Vereinigtes Königreich
Gegründet 2013 · cronofy.com

Nottingham UK developer-API-first calendar / scheduling platform (Cronofy, founded 2013), ISO 27001 + SOC 2; Wise / GoCardless / Indeed customers.

Cronofy bietet EU-Hosting in dem Vereinigten Königreich, doch ein US-Mutterkonzern oder Unterauftragsverarbeiter hinterlässt ein materielles CLOUD-Act-Risiko. Gelistet unter Terminbuchung.

Bewertungsnotizen

Cronofy (Nottingham, UK; founded 2013 by Adam Bird and Garry Shutler) is a developer-API-first scheduling-automation platform with ISO 27001, ISO 27018, ISO 27701, SOC 2 Type II and a public SOC 3 attested plus GDPR and HIPAA alignment, and 180,000+ organisations on the platform handling 1B+ events; flagship customers Wise, GoCardless, Criteo, Teamtailor, Indeed, Squarespace. UK post-Brexit jurisdiction (other ownership tier) with an EU adequacy decision keeping transfers SCC-free. Ownership was clarified in August 2026: the earlier ''acquired, acquirer undisclosed'' reading was wrong — BGF invested £15M in May 2025 as a minority, non-controlling stake that gave Cronofy''s seed investors a partial exit; BGF is UK-domiciled, so there is no US-PE or US-VC control and the company remains independently operated. Two procurement-relevant gaps remain: (1) hosting runs entirely on Amazon Web Services, across six segregated single-region deployments (Germany, UK, US, Canada, Singapore, Australia) with no PII flowing between instances — a customer can pin data to Germany or the UK, but the at-rest custodian is a US-owned hyperscaler either way, which is what keeps the CLOUD Act flag at material; (2) Cronofy does not publish a publicly accessible DPA — it is available only on request via compliance@cronofy.com and only to direct customers, which caps the score at 3. Cronofy publishes no sub-processor list; it states it has no third-party sub-processors for meeting data and self-hosts its transcription models, and it treats connected Google, Microsoft, Zoom and Exchange accounts as end-user-authorised credentials rather than its own sub-processors.

Befund

CLOUD Act
Eigentümer
Unterauftragsverarbeiter
— nicht offengelegt

Geprüfte Signale

Jurisdiktion
  • EU-/Angemessenheits-Hosting: Ja
  • EU-/Angemessenheits-Betreiber: Ja
  • Keine US-CLOUD-Act-Exposition: Nein
Transparenz
  • Öffentlicher AVV: Nein
  • Unterauftragsverarbeiter offengelegt: Nein
  • Open-Source-Clients: Nein
  • Zertifizierung durch Dritte: Ja
Springen zu

Über Cronofy

Cronofy is a Nottingham-headquartered British developer-API-first calendar and scheduling-automation platform, founded in 2013 by Adam Bird (CEO) and Garry Shutler (CTO). The product is positioned for two audiences: SaaS product builders who need to integrate scheduling features (calendar availability, multi-person + multi-room coordination, video-conferencing integration) into their own applications via a unified API; and enterprise process-automation teams who need to coordinate scheduling across HR / sales / recruiting workflows. The flagship customer roster (Wise, GoCardless, Criteo, Teamtailor, Indeed, Squarespace) is unusually high-quality for a 29-employee API company, with 180,000+ end-companies on the platform handling 1B+ events.

Compliance posture is enterprise-grade: ISO 27001, ISO 27018, ISO 27701, SOC 2 Type II and a publicly available SOC 3, plus GDPR and HIPAA alignment, the standard stack required to serve the regulated-industry portion of the customer base. UK post-Brexit jurisdiction places Cronofy in the directory's other ownership tier; the UK holds an EU adequacy decision so cross-border EU↔GB transfers require no SCCs. Ownership is straightforward and there has been no acquisition: BGF invested £15M in May 2025 as a minority, non-controlling growth stake that also gave the seed investors a partial exit, and BGF is UK-domiciled, so no US private-equity or US-VC control sits over the company. Two procurement-relevant gaps do weaken the EU signal picture. Hosting runs entirely on Amazon Web Services, in six segregated single-region deployments (Germany, UK, US, Canada, Singapore, Australia) with no personally identifiable information flowing between instances, so a customer can pin data to Germany or the UK but the at-rest custodian is a US-owned hyperscaler in every region: Erheblich. The other is the DPA: there is none published, it is issued on request via compliance@cronofy.com and only to direct customers, so end users who reach Cronofy through a third-party integration get none. On the other side of the ledger, Cronofy publishes no sub-processor list because it states it has none for meeting data, and it self-hosts its own transcription models rather than routing recordings to a third-party AI vendor.

Pricing is usage-based on API volume plus dynamically assigned active seats ("pay for active users, not empty seats"), and the pricing page renders its figures client-side, so no tier price was captured at audit. Best fit: product builders integrating scheduling into B2B SaaS (HR-tech, recruiting, sales, customer-success), where Cronofy's certification stack and stable client roster reduce procurement friction. UK and EU customers should request the DPA directly and choose their deployment region explicitly before signing.

Unterauftragsverarbeiter-Karte · nicht offengelegt

Anbieter veröffentlicht keine Liste der Unterauftragsverarbeiter. Schrems-II-Konformität und CLOUD-Act-Risiko lassen sich ohne sie nicht unabhängig prüfen.

Rahmenwerke & Zertifizierungen

ISO/IEC 27001
Aktiv
ISO/IEC 27018
Aktiv
ISO/IEC 27701
Aktiv
SOC 2
Aktiv
Hinweis · US-Rahmenwerk

Funktionsmatrix

Tabelle 1Funktionen von Cronofy

White-Label Ja
Kalender-Sync Ja
Round-Robin / Team Ja
Gruppenbuchungen Ja
Video-Integration Ja
Automatische Erinnerungen Ja
Gratis-Tarif Nein

Integration & Zugriff

REST API Ja
SSO (SAML / OIDC) Ja

Compliance & Governance

Audit log Ja
Self-host / on-prem option Nein

Preise & Tarife

Individuelle Preise

Kontaktieren Sie den Anbieter für Staffel- oder Mengenpreise.

Preisseite ansehen

Öffentliche Dokumente

Anbieter veröffentlicht keinen öffentlichen AVV. Ohne öffentlich zugänglichen Auftragsverarbeitungsvertrag können kleine EU-Kunden den Verarbeitervertrag nicht selbst abschließen. Dies wird als fehlender öffentlicher AVV vermerkt (siehe So prüfen wir).
Anbieter veröffentlicht keine Liste der Unterauftragsverarbeiter. Schrems-II-Konformität und CLOUD-Act-Risiko lassen sich ohne sie nicht unabhängig prüfen.
  • Auftragsverarbeitungsvertrag (AVV)
    — fehlt
    fehlt
  • Liste der Unterauftragsverarbeiter
    — fehlt
    fehlt
  • Nutzungsbedingungen
    docs.cronofy.com/policies…
    Öffnen

Alternativen in dieser Kategorie

  • Vereinigte Staaten · 12 $/Mt.
    US-verbunden
    Öffentl. AVV: Nein Subprozessoren: Ja Open Source: Ja
  • Schweiz
    EU-gehostet
    Öffentl. AVV: Ja Subprozessoren: Ja Open Source: Nein
  • Tschechien
    EU-gehostet
    Öffentl. AVV: Ja Subprozessoren: Ja Open Source: Nein