Cal.com
Synthèse de la propriété et de l’exposition au CLOUD Act.
-
Souverain UE Détenu et exploité dans l’UE/EEE/Suisse, sans exposition au CLOUD Act identifiée.
-
Basé UE Exploité dans l’UE, avec au plus une exposition américaine mineure ou transitoire.
-
Hébergé UE Hébergement UE disponible, mais une maison mère américaine ou un sous-traitant hyperscaler crée une exposition matérielle.
-
Lié aux US Cette fiche Exploité par une entité constituée aux États-Unis, directement soumise à la juridiction américaine.
US-incorporated open-source Calendly alternative (Cal.com Inc, SF) founded by EU developers; production code moving closed-source in 2026.
Cal.com est exploité par une entité immatriculée aux États-Unis et reste donc directement soumis au CLOUD Act. Référencé dans la catégorie Réservation de créneaux.
Notes d’évaluation
Cal.com is US-incorporated as Cal.com, Inc. (San Francisco) despite its EU-founder origin (Peer Richelsen + Bailey Pumfleet, 2021): Delaware-style US corporation, US$32M VC-funded, and the privacy policy explicitly states data is transferred to and maintained in the US. Since the August 2026 privacy-policy rewrite the company runs a public Trust Center that names 19 sub-processors, every one of them US-located, including Amazon RDS Postgres and AWS S3 for the primary database and file storage, Vercel for hosting and CDN, Cloudflare R2, Stripe and Whop for payments, Twilio and SendGrid for SMS and transactional email, Daily.co for Cal Video, and OpenAI, Anthropic and Retell AI for meeting notes, in-product assistants and Cal.ai phone agents. Connected calendars and video tools (Google, Microsoft, Apple/CalDAV, Zoom) are explicitly framed as customer-authorised integrations, "your processors, not ours". ISO 27001 and SOC 2 Type 2 are now attested but the certificates and the DPA sit behind an NDA-gated access portal (trust.cal.com/access) rather than being publicly readable, which caps the score at 3. In 2026 Cal.com began moving its production codebase behind closed doors with only a stripped community edition (Cal.diy, MIT) remaining open-source, so the historical 'open-source Calendly alternative' positioning is degrading. The hosted SaaS carries direct CLOUD Act exposure as a US-incorporated entity (US-owned, US-hosted, no public DPA) and should not be the procurement-grade choice for strict EU buyers; the self-host path via Cal.diy on EU infrastructure (EU-hosted, no CLOUD Act exposure for that path) is the only structurally clean option. Alternatives in the category (SuperSaaS NL, Reservio CZ, Doodle CH, Cronofy UK) are all structurally cleaner from an EU-sovereignty perspective.
Constats
- CLOUD Act
- Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe Cette fiche L'opérateur lui-même est établi aux États-Unis.
-
- Actionnariat
- Propriété
Où se situe le contrôle ultime de la société exploitante.
-
Propriété UE Établie et contrôlée dans l'UE ; pas de participation américaine notable.
-
Siège UE, financement US Siège dans l'UE mais contrôlée par des capitaux américains (VC/PE).
-
Filiale UE, maison mère US Société d'exploitation européenne détenue par une société mère américaine.
-
Propriété US Cette fiche La société exploitante a elle-même son siège aux États-Unis.
-
Autre Une juridiction hors UE. La propriété suisse/EEE compte ici comme européenne ; le Royaume-Uni et d'autres non.
-
- Sous-traitants
- 19 · 19 US
Signaux vérifiés
-
Hébergement UE / adéquation: Non
-
Opérateur UE / adéquation: Non
-
Aucune exposition au CLOUD Act: Non
-
DPA public: Non
-
Sous-traitants divulgués: Oui
-
Clients open source: Oui
-
Certification tierce: Oui
L'exposition dépend de votre mode d'exploitation.
Exploité par l'éditeur : les sous-traitants ci-dessous s'appliquent.
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe Cette fiche L'opérateur lui-même est établi aux États-Unis.
Déployez sur votre propre infrastructure UE et vous contrôlez l'hébergement et chaque sous-traitant.
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Cette fiche Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
Aller à
À propos de Cal.com
Cal.com is one of the most-cited "open-source Calendly alternative" SaaS products of the past few years, founded in 2021 by Peer Richelsen (German) and Bailey Pumfleet (UK), with the commercial entity incorporated as Cal.com, Inc. in San Francisco, California despite the EU-founder origin. The company has raised approximately US$32M in venture funding and the GitHub repository (calcom/cal.com) has accumulated more than 41,000 stars since launch. The product replaces Calendly's hosted scheduling experience with a self-hostable, AGPLv3-licensed open-source codebase plus a managed SaaS (cal.com), a model that was the directory's reference "EU founders bringing US-style SaaS open-source pressure" story until 2026.
The 2026 strategic shift complicates the listing. Per public reporting and direct corporate communication, Cal.com is moving its production codebase behind closed doors during 2026, leaving only a stripped community edition called Cal.diy under the more-permissive MIT licence, while rewritten authentication, data-handling, and commercial systems become proprietary. This narrows the structural "fork-if-anything-changes" guarantee that historically distinguished Cal.com from Calendly. For procurement-grade EU buyers the picture is now: (a) the hosted Cal.com SaaS is US-incorporated under Cal.com, Inc. and subject to US extraterritorial law by default, direct CLOUD Act exposure under our strict-ownership stance; (b) the privacy policy explicitly confirms data transfers to the United States, and the Trust Center now publishes 19 sub-processors, every one of them US-located, including Amazon RDS Postgres and AWS S3 for the primary database and file storage, Vercel for hosting and CDN, Cloudflare R2, Stripe and Whop for payments, Twilio and SendGrid for messaging, Daily.co for Cal Video, and OpenAI, Anthropic and Retell AI for meeting notes, in-product assistants and Cal.ai phone agents; PostHog is now listed as United States as well; (c) the Cal.diy MIT community edition on EU infrastructure (Hetzner, OVHcloud, Scaleway) remains a legitimate self-host option but with reduced feature parity vs the proprietary hosted product. ISO 27001 and SOC 2 Type 2 are now attested, but both certificates and the DPA sit behind an NDA acceptance flow at the Trust Center rather than being publicly readable, so a buyer cannot read them before signing.
Pricing for the hosted SaaS is freemium and quoted in USD only: Free at $0, Teams at $12 per user per month, Organizations at $28 per user per month, and a custom Enterprise tier; the page carries a yearly "Save 25%" label without stating whether the headline figures are the monthly or the annual-billing rate. Best fit: developers and product builders who specifically want the Cal.com API surface and accept US-incorporation; teams comfortable with the new MIT/Cal.diy self-host path on EU infrastructure for sovereignty. Procurement-grade EU-only buyers needing a structurally EU-incorporated counter-party should choose SuperSaaS (NL, founder-owned), Doodle (CH, TX Group) or Reservio (CZ, ABUGO Group) instead; all are listed elsewhere in this category, and all three carry US-owned providers of their own further down the chain.
Carte des sous-traitants · 19
-
Amazon RDS Postgres USÉtats-Unis
Primary Postgres database for the product
-
Amazon Web Services (S3) USÉtats-Unis
File and media storage
-
Anthropic USÉtats-Unis
In-product AI assistants (e.g. building routing forms)
-
Cloudflare USÉtats-Unis
File and media storage (R2); alternative email transport
-
Daily.co USÉtats-Unis
Cal Video: video calls, recordings, transcripts
-
Dub USÉtats-Unis
Website and signup attribution
-
Google Analytics / Google Tag Manager USÉtats-Unis
Marketing-site traffic measurement
-
Intercom USÉtats-Unis
Support chat and support tickets
-
Metabase Cloud USÉtats-Unis
Internal business intelligence and analytics
-
OpenAI USÉtats-Unis
AI meeting notes: summarizing Cal Video transcripts
-
PostHog USÉtats-Unis
Product analytics
-
Retell AI USÉtats-Unis
Cal.ai phone agents that place or take calls
-
SendGrid (Twilio) USÉtats-Unis
Transactional email delivery: confirmations, reminders, invites
-
Slack USÉtats-Unis
Internal and external communication
-
Stripe USÉtats-Unis
Subscriptions, checkout, invoices, and customer-collected booking payments
-
Twilio USÉtats-Unis
SMS and WhatsApp reminders, phone verification, phone number lookup
-
Vercel USÉtats-Unis
Hosting and CDN for the app and website; website analytics
-
Whop USÉtats-Unis
Global payment-processing platform powering Cal Pay
-
X (Twitter) Ads USÉtats-Unis
Ad measurement
| Prestataire | Pays | Finalité | Propriétaire |
|---|---|---|---|
| Amazon RDS Postgres | États-Unis | Primary Postgres database for the product | US |
| Amazon Web Services (S3) | États-Unis | File and media storage | US |
| Anthropic | États-Unis | In-product AI assistants (e.g. building routing forms) | US |
| Cloudflare | États-Unis | File and media storage (R2); alternative email transport | US |
| Daily.co | États-Unis | Cal Video: video calls, recordings, transcripts | US |
| Dub | États-Unis | Website and signup attribution | US |
| Google Analytics / Google Tag Manager | États-Unis | Marketing-site traffic measurement | US |
| Intercom | États-Unis | Support chat and support tickets | US |
| Metabase Cloud | États-Unis | Internal business intelligence and analytics | US |
| OpenAI | États-Unis | AI meeting notes: summarizing Cal Video transcripts | US |
| PostHog | États-Unis | Product analytics | US |
| Retell AI | États-Unis | Cal.ai phone agents that place or take calls | US |
| SendGrid (Twilio) | États-Unis | Transactional email delivery: confirmations, reminders, invites | US |
| Slack | États-Unis | Internal and external communication | US |
| Stripe | États-Unis | Subscriptions, checkout, invoices, and customer-collected booking payments | US |
| Twilio | États-Unis | SMS and WhatsApp reminders, phone verification, phone number lookup | US |
| Vercel | États-Unis | Hosting and CDN for the app and website; website analytics | US |
| Whop | États-Unis | Global payment-processing platform powering Cal Pay | US |
| X (Twitter) Ads | États-Unis | Ad measurement | US |
Source : liste publiée des sous-traitants de l’éditeur, lue le 26 août 2026.
Référentiels & certifications
Matrice de fonctionnalités
Tableau 2Fonctionnalités de Cal.com
Intégration & accès
Conformité & gouvernance
Tarifs & paliers
Documents publics
Alternatives dans cette catégorie
-
Royaume-UniHébergé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Non Sous-traitants: Non Open source: Non -
-
SuisseHébergé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Non -
-
TchéquieHébergé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Non -
| Produit | Souveraineté | CLOUD Act | Signaux | À partir de |
|---|---|---|---|---|
|
|
Hébergé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Non
Sous-traitants: Non
Open source: Non
|
— |
|
|
Hébergé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Non
|
— |
|
|
Hébergé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Non
|
— |