Skip to content

Cronofy

Calendar booking · United Kingdom
Founded 2013 · cronofy.com

Nottingham UK developer-API-first calendar / scheduling platform (Cronofy, founded 2013), ISO 27001 + SOC 2; Wise / GoCardless / Indeed customers.

Cronofy offers EU hosting in the United Kingdom, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Calendar booking.

Assessment notes

Cronofy (Nottingham, UK; founded 2013 by Adam Bird and Garry Shutler) is a developer-API-first scheduling-automation platform with ISO 27001, ISO 27018, ISO 27701, SOC 2 Type II and a public SOC 3 attested plus GDPR and HIPAA alignment, and 180,000+ organisations on the platform handling 1B+ events; flagship customers Wise, GoCardless, Criteo, Teamtailor, Indeed, Squarespace. UK post-Brexit jurisdiction (other ownership tier) with an EU adequacy decision keeping transfers SCC-free. Ownership was clarified in August 2026: the earlier ''acquired, acquirer undisclosed'' reading was wrong — BGF invested £15M in May 2025 as a minority, non-controlling stake that gave Cronofy''s seed investors a partial exit; BGF is UK-domiciled, so there is no US-PE or US-VC control and the company remains independently operated. Two procurement-relevant gaps remain: (1) hosting runs entirely on Amazon Web Services, across six segregated single-region deployments (Germany, UK, US, Canada, Singapore, Australia) with no PII flowing between instances — a customer can pin data to Germany or the UK, but the at-rest custodian is a US-owned hyperscaler either way, which is what keeps the CLOUD Act flag at material; (2) Cronofy does not publish a publicly accessible DPA — it is available only on request via compliance@cronofy.com and only to direct customers, which caps the score at 3. Cronofy publishes no sub-processor list; it states it has no third-party sub-processors for meeting data and self-hosts its transcription models, and it treats connected Google, Microsoft, Zoom and Exchange accounts as end-user-authorised credentials rather than its own sub-processors.

Findings

CLOUD Act
Ownership
Sub-processors
— not disclosed

Verified signals

Jurisdiction
  • EU / adequacy hosting: Yes
  • EU / adequacy operator: Yes
  • No US CLOUD Act exposure: No
Transparency
  • Public DPA: No
  • Sub-processors disclosed: No
  • Open-source clients: No
  • Third-party certification: Yes
Jump to

About Cronofy

Cronofy is a Nottingham-headquartered British developer-API-first calendar and scheduling-automation platform, founded in 2013 by Adam Bird (CEO) and Garry Shutler (CTO). The product is positioned for two audiences: SaaS product builders who need to integrate scheduling features (calendar availability, multi-person + multi-room coordination, video-conferencing integration) into their own applications via a unified API; and enterprise process-automation teams who need to coordinate scheduling across HR / sales / recruiting workflows. The flagship customer roster (Wise, GoCardless, Criteo, Teamtailor, Indeed, Squarespace) is unusually high-quality for a 29-employee API company, with 180,000+ end-companies on the platform handling 1B+ events.

Compliance posture is enterprise-grade: ISO 27001, ISO 27018, ISO 27701, SOC 2 Type II and a publicly available SOC 3, plus GDPR and HIPAA alignment, the standard stack required to serve the regulated-industry portion of the customer base. UK post-Brexit jurisdiction places Cronofy in the directory's other ownership tier; the UK holds an EU adequacy decision so cross-border EU↔GB transfers require no SCCs. Ownership is straightforward and there has been no acquisition: BGF invested £15M in May 2025 as a minority, non-controlling growth stake that also gave the seed investors a partial exit, and BGF is UK-domiciled, so no US private-equity or US-VC control sits over the company. Two procurement-relevant gaps do weaken the EU signal picture. Hosting runs entirely on Amazon Web Services, in six segregated single-region deployments (Germany, UK, US, Canada, Singapore, Australia) with no personally identifiable information flowing between instances, so a customer can pin data to Germany or the UK but the at-rest custodian is a US-owned hyperscaler in every region: Material. The other is the DPA: there is none published, it is issued on request via compliance@cronofy.com and only to direct customers, so end users who reach Cronofy through a third-party integration get none. On the other side of the ledger, Cronofy publishes no sub-processor list because it states it has none for meeting data, and it self-hosts its own transcription models rather than routing recordings to a third-party AI vendor.

Pricing is usage-based on API volume plus dynamically assigned active seats ("pay for active users, not empty seats"), and the pricing page renders its figures client-side, so no tier price was captured at audit. Best fit: product builders integrating scheduling into B2B SaaS (HR-tech, recruiting, sales, customer-success), where Cronofy's certification stack and stable client roster reduce procurement friction. UK and EU customers should request the DPA directly and choose their deployment region explicitly before signing.

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.

Frameworks & certifications

ISO/IEC 27001
Active
ISO/IEC 27018
Active
ISO/IEC 27701
Active
SOC 2
Active
Informational · US framework

Capability matrix

Table 1Capabilities of Cronofy

White-label Yes
Calendar sync Yes
Round-robin / team Yes
Group bookings Yes
Video integration Yes
Automated reminders Yes
Free tier No

Integration & access

REST API Yes
SSO (SAML / OIDC) Yes

Compliance & governance

Audit log Yes
Self-host / on-prem option No

Pricing & tiers

Custom pricing

Contact vendor for tier or volume pricing.

View pricing page

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement. This is recorded as no public DPA (see How we assess).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
  • Terms of Service
    docs.cronofy.com/policies…
    Open

Alternatives in this category

  • United States · $12/mo
    US-Linked
    Public DPA: No Sub-processors: Yes Open source: Yes
  • Switzerland
    EU-Hosted
    Public DPA: Yes Sub-processors: Yes Open source: No
  • Czechia
    EU-Hosted
    Public DPA: Yes Sub-processors: Yes Open source: No