Cronofy
Synthèse de la propriété et de l’exposition au CLOUD Act.
-
Souverain UE Détenu et exploité dans l’UE/EEE/Suisse, sans exposition au CLOUD Act identifiée.
-
Basé UE Exploité dans l’UE, avec au plus une exposition américaine mineure ou transitoire.
-
Hébergé UE Cette fiche Hébergement UE disponible, mais une maison mère américaine ou un sous-traitant hyperscaler crée une exposition matérielle.
-
Lié aux US Exploité par une entité constituée aux États-Unis, directement soumise à la juridiction américaine.
Nottingham UK developer-API-first calendar / scheduling platform (Cronofy, founded 2013), ISO 27001 + SOC 2; Wise / GoCardless / Indeed customers.
Cronofy propose un hébergement européen au Royaume-Uni, mais une maison mère ou un sous-traitant américain laisse une exposition matérielle au CLOUD Act. Référencé dans la catégorie Réservation de créneaux.
Notes d’évaluation
Cronofy (Nottingham, UK; founded 2013 by Adam Bird and Garry Shutler) is a developer-API-first scheduling-automation platform with ISO 27001, ISO 27018, ISO 27701, SOC 2 Type II and a public SOC 3 attested plus GDPR and HIPAA alignment, and 180,000+ organisations on the platform handling 1B+ events; flagship customers Wise, GoCardless, Criteo, Teamtailor, Indeed, Squarespace. UK post-Brexit jurisdiction (other ownership tier) with an EU adequacy decision keeping transfers SCC-free. Ownership was clarified in August 2026: the earlier ''acquired, acquirer undisclosed'' reading was wrong — BGF invested £15M in May 2025 as a minority, non-controlling stake that gave Cronofy''s seed investors a partial exit; BGF is UK-domiciled, so there is no US-PE or US-VC control and the company remains independently operated. Two procurement-relevant gaps remain: (1) hosting runs entirely on Amazon Web Services, across six segregated single-region deployments (Germany, UK, US, Canada, Singapore, Australia) with no PII flowing between instances — a customer can pin data to Germany or the UK, but the at-rest custodian is a US-owned hyperscaler either way, which is what keeps the CLOUD Act flag at material; (2) Cronofy does not publish a publicly accessible DPA — it is available only on request via compliance@cronofy.com and only to direct customers, which caps the score at 3. Cronofy publishes no sub-processor list; it states it has no third-party sub-processors for meeting data and self-hosts its transcription models, and it treats connected Google, Microsoft, Zoom and Exchange accounts as end-user-authorised credentials rather than its own sub-processors.
Constats
- CLOUD Act
- Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
-
- Actionnariat
- Propriété
Où se situe le contrôle ultime de la société exploitante.
-
Propriété UE Établie et contrôlée dans l'UE ; pas de participation américaine notable.
-
Siège UE, financement US Siège dans l'UE mais contrôlée par des capitaux américains (VC/PE).
-
Filiale UE, maison mère US Société d'exploitation européenne détenue par une société mère américaine.
-
Propriété US La société exploitante a elle-même son siège aux États-Unis.
-
Autre Cette fiche Une juridiction hors UE. La propriété suisse/EEE compte ici comme européenne ; le Royaume-Uni et d'autres non.
-
- Sous-traitants
- — non divulgué
Signaux vérifiés
-
Hébergement UE / adéquation: Oui
-
Opérateur UE / adéquation: Oui
-
Aucune exposition au CLOUD Act: Non
-
DPA public: Non
-
Sous-traitants divulgués: Non
-
Clients open source: Non
-
Certification tierce: Oui
Aller à
À propos de Cronofy
Cronofy is a Nottingham-headquartered British developer-API-first calendar and scheduling-automation platform, founded in 2013 by Adam Bird (CEO) and Garry Shutler (CTO). The product is positioned for two audiences: SaaS product builders who need to integrate scheduling features (calendar availability, multi-person + multi-room coordination, video-conferencing integration) into their own applications via a unified API; and enterprise process-automation teams who need to coordinate scheduling across HR / sales / recruiting workflows. The flagship customer roster (Wise, GoCardless, Criteo, Teamtailor, Indeed, Squarespace) is unusually high-quality for a 29-employee API company, with 180,000+ end-companies on the platform handling 1B+ events.
Compliance posture is enterprise-grade: ISO 27001, ISO 27018, ISO 27701, SOC 2 Type II and a publicly available SOC 3, plus GDPR and HIPAA alignment, the standard stack required to serve the regulated-industry portion of the customer base. UK post-Brexit jurisdiction places Cronofy in the directory's other ownership tier; the UK holds an EU adequacy decision so cross-border EU↔GB transfers require no SCCs. Ownership is straightforward and there has been no acquisition: BGF invested £15M in May 2025 as a minority, non-controlling growth stake that also gave the seed investors a partial exit, and BGF is UK-domiciled, so no US private-equity or US-VC control sits over the company. Two procurement-relevant gaps do weaken the EU signal picture. Hosting runs entirely on Amazon Web Services, in six segregated single-region deployments (Germany, UK, US, Canada, Singapore, Australia) with no personally identifiable information flowing between instances, so a customer can pin data to Germany or the UK but the at-rest custodian is a US-owned hyperscaler in every region: Significative. The other is the DPA: there is none published, it is issued on request via compliance@cronofy.com and only to direct customers, so end users who reach Cronofy through a third-party integration get none. On the other side of the ledger, Cronofy publishes no sub-processor list because it states it has none for meeting data, and it self-hosts its own transcription models rather than routing recordings to a third-party AI vendor.
Pricing is usage-based on API volume plus dynamically assigned active seats ("pay for active users, not empty seats"), and the pricing page renders its figures client-side, so no tier price was captured at audit. Best fit: product builders integrating scheduling into B2B SaaS (HR-tech, recruiting, sales, customer-success), where Cronofy's certification stack and stable client roster reduce procurement friction. UK and EU customers should request the DPA directly and choose their deployment region explicitly before signing.
Carte des sous-traitants · non divulgué
Référentiels & certifications
Matrice de fonctionnalités
Tableau 1Fonctionnalités de Cronofy
Intégration & accès
Conformité & gouvernance
Tarifs & paliers
Documents publics
-
manquantContrat de sous-traitance (DPA)— manquant
-
manquantListe des sous-traitants— manquant
-
OuvrirConditions d'utilisationdocs.cronofy.com/policies…
Alternatives dans cette catégorie
-
États-Unis · 12 $/moisLié aux USExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe Cette fiche L'opérateur lui-même est établi aux États-Unis.
DPA public: Non Sous-traitants: Oui Open source: Oui -
-
SuisseHébergé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Non -
-
TchéquieHébergé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Non -
| Produit | Souveraineté | CLOUD Act | Signaux | À partir de |
|---|---|---|---|---|
|
|
Lié aux US | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Non
Sous-traitants: Oui
Open source: Oui
|
12 $/mois |
|
|
Hébergé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Non
|
— |
|
|
Hébergé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Non
|
— |