Cal.com
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked This listing Operated by a US-incorporated entity, directly subject to US jurisdiction.
US-incorporated open-source Calendly alternative (Cal.com Inc, SF) founded by EU developers; production code moving closed-source in 2026.
Cal.com is operated by a US-incorporated entity and remains directly subject to the CLOUD Act. It is listed under Calendar booking.
Assessment notes
Cal.com is US-incorporated as Cal.com, Inc. (San Francisco) despite its EU-founder origin (Peer Richelsen + Bailey Pumfleet, 2021): Delaware-style US corporation, US$32M VC-funded, and the privacy policy explicitly states data is transferred to and maintained in the US. Since the August 2026 privacy-policy rewrite the company runs a public Trust Center that names 19 sub-processors, every one of them US-located, including Amazon RDS Postgres and AWS S3 for the primary database and file storage, Vercel for hosting and CDN, Cloudflare R2, Stripe and Whop for payments, Twilio and SendGrid for SMS and transactional email, Daily.co for Cal Video, and OpenAI, Anthropic and Retell AI for meeting notes, in-product assistants and Cal.ai phone agents. Connected calendars and video tools (Google, Microsoft, Apple/CalDAV, Zoom) are explicitly framed as customer-authorised integrations, "your processors, not ours". ISO 27001 and SOC 2 Type 2 are now attested but the certificates and the DPA sit behind an NDA-gated access portal (trust.cal.com/access) rather than being publicly readable, which caps the score at 3. In 2026 Cal.com began moving its production codebase behind closed doors with only a stripped community edition (Cal.diy, MIT) remaining open-source, so the historical 'open-source Calendly alternative' positioning is degrading. The hosted SaaS carries direct CLOUD Act exposure as a US-incorporated entity (US-owned, US-hosted, no public DPA) and should not be the procurement-grade choice for strict EU buyers; the self-host path via Cal.diy on EU infrastructure (EU-hosted, no CLOUD Act exposure for that path) is the only structurally clean option. Alternatives in the category (SuperSaaS NL, Reservio CZ, Doodle CH, Cronofy UK) are all structurally cleaner from an EU-sovereignty perspective.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct This listing The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned This listing The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 19 · 19 US
Verified signals
-
EU / adequacy hosting: No
-
EU / adequacy operator: No
-
No US CLOUD Act exposure: No
-
Public DPA: No
-
Sub-processors disclosed: Yes
-
Open-source clients: Yes
-
Third-party certification: Yes
Exposure depends on how you run this product.
Vendor-operated: the sub-processors below apply.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct This listing The operator itself is US-incorporated.
Deploy on your own EU infrastructure and you control hosting and every sub-processor.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Jump to
About Cal.com
Cal.com is one of the most-cited "open-source Calendly alternative" SaaS products of the past few years, founded in 2021 by Peer Richelsen (German) and Bailey Pumfleet (UK), with the commercial entity incorporated as Cal.com, Inc. in San Francisco, California despite the EU-founder origin. The company has raised approximately US$32M in venture funding and the GitHub repository (calcom/cal.com) has accumulated more than 41,000 stars since launch. The product replaces Calendly's hosted scheduling experience with a self-hostable, AGPLv3-licensed open-source codebase plus a managed SaaS (cal.com), a model that was the directory's reference "EU founders bringing US-style SaaS open-source pressure" story until 2026.
The 2026 strategic shift complicates the listing. Per public reporting and direct corporate communication, Cal.com is moving its production codebase behind closed doors during 2026, leaving only a stripped community edition called Cal.diy under the more-permissive MIT licence, while rewritten authentication, data-handling, and commercial systems become proprietary. This narrows the structural "fork-if-anything-changes" guarantee that historically distinguished Cal.com from Calendly. For procurement-grade EU buyers the picture is now: (a) the hosted Cal.com SaaS is US-incorporated under Cal.com, Inc. and subject to US extraterritorial law by default, direct CLOUD Act exposure under our strict-ownership stance; (b) the privacy policy explicitly confirms data transfers to the United States, and the Trust Center now publishes 19 sub-processors, every one of them US-located, including Amazon RDS Postgres and AWS S3 for the primary database and file storage, Vercel for hosting and CDN, Cloudflare R2, Stripe and Whop for payments, Twilio and SendGrid for messaging, Daily.co for Cal Video, and OpenAI, Anthropic and Retell AI for meeting notes, in-product assistants and Cal.ai phone agents; PostHog is now listed as United States as well; (c) the Cal.diy MIT community edition on EU infrastructure (Hetzner, OVHcloud, Scaleway) remains a legitimate self-host option but with reduced feature parity vs the proprietary hosted product. ISO 27001 and SOC 2 Type 2 are now attested, but both certificates and the DPA sit behind an NDA acceptance flow at the Trust Center rather than being publicly readable, so a buyer cannot read them before signing.
Pricing for the hosted SaaS is freemium and quoted in USD only: Free at $0, Teams at $12 per user per month, Organizations at $28 per user per month, and a custom Enterprise tier; the page carries a yearly "Save 25%" label without stating whether the headline figures are the monthly or the annual-billing rate. Best fit: developers and product builders who specifically want the Cal.com API surface and accept US-incorporation; teams comfortable with the new MIT/Cal.diy self-host path on EU infrastructure for sovereignty. Procurement-grade EU-only buyers needing a structurally EU-incorporated counter-party should choose SuperSaaS (NL, founder-owned), Doodle (CH, TX Group) or Reservio (CZ, ABUGO Group) instead; all are listed elsewhere in this category, and all three carry US-owned providers of their own further down the chain.
Sub-processor map · 19
-
Amazon RDS Postgres USUnited States
Primary Postgres database for the product
-
Amazon Web Services (S3) USUnited States
File and media storage
-
Anthropic USUnited States
In-product AI assistants (e.g. building routing forms)
-
Cloudflare USUnited States
File and media storage (R2); alternative email transport
-
Daily.co USUnited States
Cal Video: video calls, recordings, transcripts
-
Dub USUnited States
Website and signup attribution
-
Google Analytics / Google Tag Manager USUnited States
Marketing-site traffic measurement
-
Intercom USUnited States
Support chat and support tickets
-
Metabase Cloud USUnited States
Internal business intelligence and analytics
-
OpenAI USUnited States
AI meeting notes: summarizing Cal Video transcripts
-
PostHog USUnited States
Product analytics
-
Retell AI USUnited States
Cal.ai phone agents that place or take calls
-
SendGrid (Twilio) USUnited States
Transactional email delivery: confirmations, reminders, invites
-
Slack USUnited States
Internal and external communication
-
Stripe USUnited States
Subscriptions, checkout, invoices, and customer-collected booking payments
-
Twilio USUnited States
SMS and WhatsApp reminders, phone verification, phone number lookup
-
Vercel USUnited States
Hosting and CDN for the app and website; website analytics
-
Whop USUnited States
Global payment-processing platform powering Cal Pay
-
X (Twitter) Ads USUnited States
Ad measurement
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Amazon RDS Postgres | United States | Primary Postgres database for the product | US |
| Amazon Web Services (S3) | United States | File and media storage | US |
| Anthropic | United States | In-product AI assistants (e.g. building routing forms) | US |
| Cloudflare | United States | File and media storage (R2); alternative email transport | US |
| Daily.co | United States | Cal Video: video calls, recordings, transcripts | US |
| Dub | United States | Website and signup attribution | US |
| Google Analytics / Google Tag Manager | United States | Marketing-site traffic measurement | US |
| Intercom | United States | Support chat and support tickets | US |
| Metabase Cloud | United States | Internal business intelligence and analytics | US |
| OpenAI | United States | AI meeting notes: summarizing Cal Video transcripts | US |
| PostHog | United States | Product analytics | US |
| Retell AI | United States | Cal.ai phone agents that place or take calls | US |
| SendGrid (Twilio) | United States | Transactional email delivery: confirmations, reminders, invites | US |
| Slack | United States | Internal and external communication | US |
| Stripe | United States | Subscriptions, checkout, invoices, and customer-collected booking payments | US |
| Twilio | United States | SMS and WhatsApp reminders, phone verification, phone number lookup | US |
| Vercel | United States | Hosting and CDN for the app and website; website analytics | US |
| Whop | United States | Global payment-processing platform powering Cal Pay | US |
| X (Twitter) Ads | United States | Ad measurement | US |
Source: the vendor’s published sub-processor list, read 26 Aug 2026.
Frameworks & certifications
Capability matrix
Table 2Capabilities of Cal.com
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
United KingdomEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: No -
-
SwitzerlandEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
CzechiaEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: No
|
— |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |