Whereby
Synthèse de la propriété et de l’exposition au CLOUD Act.
-
Souverain UE Détenu et exploité dans l’UE/EEE/Suisse, sans exposition au CLOUD Act identifiée.
-
Basé UE Exploité dans l’UE, avec au plus une exposition américaine mineure ou transitoire.
-
Hébergé UE Cette fiche Hébergement UE disponible, mais une maison mère américaine ou un sous-traitant hyperscaler crée une exposition matérielle.
-
Lié aux US Exploité par une entité constituée aux États-Unis, directement soumise à la juridiction américaine.
Norwegian browser-based WebRTC video (ex-appear.in, Videonor-owned), no-install meetings + Embedded SDK; ISO 27001 + GDPR + HIPAA.
Whereby propose un hébergement européen en Irlande, mais une maison mère ou un sous-traitant américain laisse une exposition matérielle au CLOUD Act. Référencé dans la catégorie Visioconférence.
Notes d’évaluation
Whereby (originally appear.in, spun out of Norwegian telecom Telenor as a summer intern project and now owned by Videonor, a Norwegian entity) is a browser-based WebRTC video-calling platform without installs or accounts at the meeting-attendee level; ISO 27001 certified, GDPR and HIPAA compliant, sold as both consumer-style Whereby Meetings and Whereby Embedded (API/SDK for product builders). Norway holds an EU adequacy decision (SCC-free EU↔NO transfers). The DPA now names the hosting provider explicitly: Amazon Web Services EMEA SARL (Luxembourg / Ireland) stores user account information, and clause 7.5 commits DPA-covered data to Ireland or another EU/EEA location. CLOUD Act flag raised to material at the 2026-08 re-verify because that EU/EEA commitment covers only account data: the DPA explicitly carves out call content (voice, video, text, files) and traffic metadata, the privacy policy states usage information is stored in Ireland and the United States, and Whereby routes calls through a worldwide mesh of its own SFU media routers rather than an EU-confined media plane. EU-adequate jurisdiction, ISO 27001 certified, public DPA, but the video path itself is not contractually EU-bound and there is no confirmed EU ownership.
Constats
- CLOUD Act
- Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
-
- Actionnariat
- Propriété
Où se situe le contrôle ultime de la société exploitante.
-
Propriété UE Établie et contrôlée dans l'UE ; pas de participation américaine notable.
-
Européen Cette fiche Propriété suisse/EEE, sans participation américaine notable, considérée comme européenne.
-
Siège UE, financement US Siège dans l'UE mais contrôlée par des capitaux américains (VC/PE).
-
Filiale UE, maison mère US Société d'exploitation européenne détenue par une société mère américaine.
-
Propriété US La société exploitante a elle-même son siège aux États-Unis.
-
- Sous-traitants
- — non divulgué
Signaux vérifiés
-
Hébergement UE / adéquation: Oui
-
Opérateur UE / adéquation: Oui
-
Aucune exposition au CLOUD Act: Non
-
DPA public: Oui
-
Sous-traitants divulgués: Oui
-
Clients open source: Non
-
Certification tierce: Oui
Aller à
À propos de Whereby
Whereby is a Norwegian browser-based video-meeting platform originally launched as appear.in in 2013 as a summer-intern project inside the Norwegian telecom group Telenor. The product grew a strong user base internationally before being spun out and acquired by Videonor (a Norwegian holding entity) with the brand renamed to Whereby. The core proposition is unusual in the video-conferencing category: no installs, no accounts for meeting attendees, just a URL that opens in any modern browser via WebRTC. The product surface is two-tier: Whereby Meetings for individuals and teams (consumer + business plans), and Whereby Embedded, an API/SDK that lets product builders embed Whereby's WebRTC video into their own applications, competing directly with Twilio Video, Daily, Agora, and Zoom SDK.
Compliance posture is solid for a consumer-friendly video tool: ISO/IEC 27001 certified, GDPR-compliant by design, HIPAA-compliant for US-healthcare customers, and a privacy-first product philosophy carried over from the Telenor engineering culture. The legal entity sits in Norway (EEA member, EU adequacy decision under Art. 45 GDPR, SCC-free for EU↔NO transfers). The underlying infrastructure is now named: the DPA lists Amazon Web Services EMEA SARL (Luxembourg / Ireland) as the sub-processor storing user account information, and clause 7.5 commits DPA-covered data to Ireland or another EU/EEA location. That commitment does not reach the call itself. The DPA expressly carves out the content transmitted between users (voice, video, text, files) and traffic metadata, the privacy policy states usage information is stored in Ireland and the United States, and Whereby routes calls across its own worldwide mesh of Selective Forwarding Units rather than an EU-confined media plane, with no published EU-only media-residency option. The Session Transcription and Live Captions features add a speech-to-text vendor that is named in neither the documentation, the feature pages nor the DPA. CLOUD Act exposure is recorded as Significative on that basis.
Pricing is freemium with a long history of generous free tiers (free unlimited 1-on-1, free group meetings up to 45 minutes); paid plans add custom rooms, branding, longer meetings, advanced controls, recording, and analytics. Embedded pricing is usage-based per video-minute. Best fit: agencies and consultancies needing easy no-install client video calls, educational and healthcare workflows that benefit from no-account meetings, developers building video into their own products via Embedded, and Norwegian / Nordic / European buyers who specifically want a Norwegian-rooted EU-friendly alternative to Zoom and Google Meet.
Carte des sous-traitants · non divulgué
Référentiels & certifications
Matrice de fonctionnalités
Tableau 1Fonctionnalités de Whereby
Intégration & accès
Conformité & gouvernance
Tarifs & paliers
Documents publics
Alternatives dans cette catégorie
-
Royaume-UniHébergé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Oui -
-
SuisseSouverain UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Cette fiche Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Non -
-
France · 10 €/moisBasé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Cette fiche Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Non Sous-traitants: Non Open source: Oui -
| Produit | Souveraineté | CLOUD Act | Signaux | À partir de |
|---|---|---|---|---|
|
|
Hébergé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Oui
|
— |
|
|
Souverain UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Non
|
— |
|
|
Basé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Non
Sous-traitants: Non
Open source: Oui
|
10 €/mois |