Manchester-based UK CRM (Zestia Ltd) with a free tier, public DPA, and AWS hosting; post-Brexit jurisdiction.
- FROM
- —
- CLOUD ACT
- MATERIAL
Zusammenfassung aus Eigentümerschaft und CLOUD-Act-Risiko.
Twenty SAS (SIREN 914 989 041, Paris, France), subsidiary of Twenty.com PBC (public benefit corporation, Delaware / San Francisco, USA)
In Paris entwickeltes Open-Source-CRM (AGPL-3.0) der Twenty SAS; die verwaltete Cloud verkauft jedoch eine Delaware-PBC und läuft auf AWS Frankfurt.
Twenty aus der Kategorie CRM bietet EU-Hosting mit Germany als Hosting-Standort, doch ein US-Mutterkonzern oder Unterauftragsverarbeiter hinterlässt ein materielles CLOUD-Act-Risiko.
Twenty is built in Paris by Twenty SAS (SIREN 914 989 041, registered 24 June 2022, 18 rue Soleillet, 75020 Paris), the French entity that employs the product team and holds the software IP, and EU workspaces are processed under a French-law DPA naming Twenty.com SAS as processor. But the managed cloud is sold under the terms of Twenty.com PBC, a Delaware public benefit corporation, governed by Delaware law, and the company's own privacy policy states that Twenty is based in the United States; that is a US parent, so eu_owned is off the table. All customer records sit on AWS eu-central-1 (Frankfurt), which keeps the data physically in the EU but under a US-owned hyperscaler, and the always-engaged sub-processor set adds ClickHouse (US-incorporated, processing in Germany), Cloudflare (edge, worldwide) and Sentry (processing in the United States). US parent plus AWS at rest is exactly the pattern the rubric calls material CLOUD Act exposure, and the score does not go above 3 for that reason. Positives that keep it at 3 rather than 2: EU-only data residency for the default region, an unusually granular public sub-processor register on the trust centre, SOC 2 Type 2, a self-serve DPA that any workspace admin can generate and sign in-app (which by itself caps the score at 4 under the DPA-accessibility rule since there is no public DPA URL), and an AGPL-3.0 codebase that lets a buyer leave the US contract entirely by self-hosting.
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
Wo die letztliche Kontrolle über das Betreiberunternehmen liegt.
Die Exposition hängt davon ab, wie Sie dieses Produkt betreiben.
Anbieterbetrieben: die unten genannten Unterauftragsverarbeiter gelten.
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
Auf eigener EU-Infrastruktur betreiben: Sie kontrollieren Hosting und jeden Unterauftragsverarbeiter.
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
Twenty ist ein quelloffenes CRM, entwickelt von einem Pariser Produktteam und positioniert als die offene Alternative zu Salesforce. Der Code liegt unter github.com/twentyhq/twenty unter AGPL-3.0 (einzelne mit @license Enterprise markierte Dateien stehen unter einer separaten Twenty.com Commercial License, die SDK-Pakete unter MIT) und hat 54.000 GitHub-Sterne überschritten. Die Gründer Félix Malfait, Charles Bochet und Thomas des Francs durchliefen Y Combinator S23 und sammelten im November 2024 eine Seed-Runde über 5 Millionen USD unter Führung von Runa Capital ein, mit Angels von HubSpot, Front, Cal.com, Sentry und Photoroom. Funktional ist es ein entwicklernahes CRM statt einer Vertriebssuite: unbegrenzte eigene Objekte, Felder und Ansichten, Tabellen-, Kanban- und Kalenderansichten, Workflows und KI-Agenten, beidseitige E-Mail- und Kalendersynchronisation, REST- und GraphQL-APIs, Webhooks und ein MCP-Server.
Die Konzernstruktur muss ein europäischer Käufer genau lesen. Twenty SAS (SIREN 914 989 041, eingetragen am 24. Juni 2022 im 20. Pariser Arrondissement) beschäftigt das Produktteam und hält das Software-IP, und die im Quellcode veröffentlichte AVV-Konfiguration nennt Twenty.com SAS, 9 rue des Colonnes, 75002 Paris als Auftragsverarbeiter für die EU-Region nach französischem Recht, ohne SCC-Anhang, da standardmäßig nichts den EWR verlässt. Die kommerziellen Bedingungen des verwalteten Dienstes sind jedoch die der Twenty.com PBC, einer Public Benefit Corporation aus Delaware mit Zustellanschrift in San Francisco, nach dem Recht von Delaware, und die Datenschutzerklärung sagt ausdrücklich, dass Twenty in den Vereinigten Staaten ansässig ist. Das ist eine US-Muttergesellschaft über einer französischen Tochter, weshalb die Eigentümerschaft als EU-Sitz mit US-Finanzierung geführt wird und nicht als EU-eigen, und weshalb das CLOUD-Act-Risiko Erheblich ist. Die Datenhaltung selbst ist sauber: sämtliche Kundendatensätze, Backups und Logs liegen auf AWS eu-central-1 in Frankfurt, Audit-Logs in ClickHouse (ebenfalls in Deutschland verarbeitet), Cloudflare davor für CDN und WAF, Sentry für Fehlerüberwachung in den USA, und optionale KI-Funktionen gehen nur dann an Anthropic, OpenAI oder Mistral, wenn ein Workspace sie aktiviert. AWS ist der ausschlaggebende Punkt: ein US-eigener Hyperscaler hält die Daten im Ruhezustand, eine EU-Region beseitigt das Risiko also nicht. Das Trust Center unter trust.twenty.com weist SOC 2 Type 2 und GDPR-Status sowie ein Unterauftragsverarbeiter-Register mit Verarbeitungsorten aus, die zugrunde liegenden Richtliniendokumente stehen jedoch hinter einer Zugriffsanfrage, und der AVV hat keine öffentliche URL: eine Workspace-Administration erzeugt und unterzeichnet ihn direkt in der Anwendung unter Settings > DPA, was nach unserer AVV-Zugänglichkeitsregel die Bewertung bereits vor dem CLOUD-Act-Abzug auf 4 deckelt.
Die Preise sind in USD ausgewiesen, eine EUR-Preisliste gibt es nicht: Pro für 9 USD pro Nutzer und Monat (entspricht €8), Organization für 19 USD pro Nutzer und Monat mit zeilenbasierten Berechtigungen, SAML/OIDC-SSO, eigener Domain und Audit-Logs, sowie Enterprise ab 50.000 USD pro Jahr mit Single-Tenant-Isolierung, IP-Freigabelisten und SCIM. Einen kostenlosen gehosteten Tarif gibt es nicht, nur eine 30-tägige Testphase ohne Karte. Die Produktoberfläche liefert 33 Sprachkataloge aus, darunter Französisch, Deutsch, Spanisch, Italienisch, Niederländisch, Polnisch und die nordischen Sprachen. Am besten geeignet für technische Teams, die ein anpassbares CRM wollen, das sie forken, erweitern und später mitnehmen können. Wer in der Beschaffung eine US-Muttergesellschaft oder einen US-eigenen Hyperscaler ausschließen muss, hostet Twenty besser selbst auf Hetzner, OVHcloud oder Scaleway, was den US-Vertrag und AWS vollständig entfernt, oder sieht sich centralstationCRM (DE), weclapp (DE) oder Teamleader (BE) in dieser Kategorie an.
Primary hosting: compute, managed databases, object storage and encrypted backups. Holds all customer CRM data at rest in eu-central-1 (Frankfurt). Always engaged.
Optional AI features (drafting, summarisation, enrichment). Engaged only when a workspace enables AI and runs an action; no training on customer data; SCCs in place.
Analytical database storing audit logs and powering in-product analytics and reporting; may contain customer personal data. Processed in Germany, always engaged.
CDN, DNS and web application firewall. Processes request/response content and connection metadata in transit only across the worldwide edge network, no long-term retention. Always engaged.
Google Maps look-ups and Google single sign-on only. Processed in Germany, engaged only for workspaces that use those features.
Optional AI features, depending on the model configured for the workspace. Processed in the United States and the EU; no training on customer data; SCCs in place.
Application error and performance monitoring; stack traces and request context, scrubbed but may incidentally contain customer data. Processed in the United States, always engaged.
Payment processing for the managed cloud subscription. Named in the privacy policy only; absent from the trust-centre register and from subprocessors.json as of 2026-08-10.
Optional AI features, depending on the model configured for the workspace. EU provider with EU hosting, so no transfer outside the EEA; no training on customer data.
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Amazon Web Services | Germany | Primary hosting: compute, managed databases, object storage and encrypted backups. Holds all customer CRM data at rest in eu-central-1 (Frankfurt). Always engaged. | US |
| Anthropic | United States | Optional AI features (drafting, summarisation, enrichment). Engaged only when a workspace enables AI and runs an action; no training on customer data; SCCs in place. | US |
| ClickHouse | Germany | Analytical database storing audit logs and powering in-product analytics and reporting; may contain customer personal data. Processed in Germany, always engaged. | US |
| Cloudflare | United States | CDN, DNS and web application firewall. Processes request/response content and connection metadata in transit only across the worldwide edge network, no long-term retention. Always engaged. | US |
| Google Cloud Platform | Germany | Google Maps look-ups and Google single sign-on only. Processed in Germany, engaged only for workspaces that use those features. | US |
| OpenAI | United States | Optional AI features, depending on the model configured for the workspace. Processed in the United States and the EU; no training on customer data; SCCs in place. | US |
| Sentry | United States | Application error and performance monitoring; stack traces and request context, scrubbed but may incidentally contain customer data. Processed in the United States, always engaged. | US |
| Stripe | United States | Payment processing for the managed cloud subscription. Named in the privacy policy only; absent from the trust-centre register and from subprocessors.json as of 2026-08-10. | US |
| Mistral AI | France | Optional AI features, depending on the model configured for the workspace. EU provider with EU hosting, so no transfer outside the EEA; no training on customer data. | EU |
Manchester-based UK CRM (Zestia Ltd) with a free tier, public DPA, and AWS hosting; post-Brexit jurisdiction.
Cologne-based German SMB CRM (42he GmbH), all-German hosting on Hetzner + Core-Backbone + Telekom, free tier for 3 users.
Konstanz-based German CRM (combit Software, since 1989), founder-owned, on-prem + cloud, German Mittelstand vendor.