Cronofy
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Nottingham UK developer-API-first calendar / scheduling platform (Cronofy, founded 2013), ISO 27001 + SOC 2; Wise / GoCardless / Indeed customers.
Cronofy offers EU hosting in the United Kingdom, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Calendar booking.
Assessment notes
Cronofy (Nottingham, UK; founded 2013 by Adam Bird and Garry Shutler) is a developer-API-first scheduling-automation platform with ISO 27001, ISO 27018, ISO 27701, SOC 2 Type II and a public SOC 3 attested plus GDPR and HIPAA alignment, and 180,000+ organisations on the platform handling 1B+ events; flagship customers Wise, GoCardless, Criteo, Teamtailor, Indeed, Squarespace. UK post-Brexit jurisdiction (other ownership tier) with an EU adequacy decision keeping transfers SCC-free. Ownership was clarified in August 2026: the earlier ''acquired, acquirer undisclosed'' reading was wrong — BGF invested £15M in May 2025 as a minority, non-controlling stake that gave Cronofy''s seed investors a partial exit; BGF is UK-domiciled, so there is no US-PE or US-VC control and the company remains independently operated. Two procurement-relevant gaps remain: (1) hosting runs entirely on Amazon Web Services, across six segregated single-region deployments (Germany, UK, US, Canada, Singapore, Australia) with no PII flowing between instances — a customer can pin data to Germany or the UK, but the at-rest custodian is a US-owned hyperscaler either way, which is what keeps the CLOUD Act flag at material; (2) Cronofy does not publish a publicly accessible DPA — it is available only on request via compliance@cronofy.com and only to direct customers, which caps the score at 3. Cronofy publishes no sub-processor list; it states it has no third-party sub-processors for meeting data and self-hosts its transcription models, and it treats connected Google, Microsoft, Zoom and Exchange accounts as end-user-authorised credentials rather than its own sub-processors.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other This listing A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: No
-
Sub-processors disclosed: No
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Cronofy
Cronofy is a Nottingham-headquartered British developer-API-first calendar and scheduling-automation platform, founded in 2013 by Adam Bird (CEO) and Garry Shutler (CTO). The product is positioned for two audiences: SaaS product builders who need to integrate scheduling features (calendar availability, multi-person + multi-room coordination, video-conferencing integration) into their own applications via a unified API; and enterprise process-automation teams who need to coordinate scheduling across HR / sales / recruiting workflows. The flagship customer roster (Wise, GoCardless, Criteo, Teamtailor, Indeed, Squarespace) is unusually high-quality for a 29-employee API company, with 180,000+ end-companies on the platform handling 1B+ events.
Compliance posture is enterprise-grade: ISO 27001, ISO 27018, ISO 27701, SOC 2 Type II and a publicly available SOC 3, plus GDPR and HIPAA alignment, the standard stack required to serve the regulated-industry portion of the customer base. UK post-Brexit jurisdiction places Cronofy in the directory's other ownership tier; the UK holds an EU adequacy decision so cross-border EU↔GB transfers require no SCCs. Ownership is straightforward and there has been no acquisition: BGF invested £15M in May 2025 as a minority, non-controlling growth stake that also gave the seed investors a partial exit, and BGF is UK-domiciled, so no US private-equity or US-VC control sits over the company. Two procurement-relevant gaps do weaken the EU signal picture. Hosting runs entirely on Amazon Web Services, in six segregated single-region deployments (Germany, UK, US, Canada, Singapore, Australia) with no personally identifiable information flowing between instances, so a customer can pin data to Germany or the UK but the at-rest custodian is a US-owned hyperscaler in every region: Material. The other is the DPA: there is none published, it is issued on request via compliance@cronofy.com and only to direct customers, so end users who reach Cronofy through a third-party integration get none. On the other side of the ledger, Cronofy publishes no sub-processor list because it states it has none for meeting data, and it self-hosts its own transcription models rather than routing recordings to a third-party AI vendor.
Pricing is usage-based on API volume plus dynamically assigned active seats ("pay for active users, not empty seats"), and the pricing page renders its figures client-side, so no tier price was captured at audit. Best fit: product builders integrating scheduling into B2B SaaS (HR-tech, recruiting, sales, customer-success), where Cronofy's certification stack and stable client roster reduce procurement friction. UK and EU customers should request the DPA directly and choose their deployment region explicitly before signing.
Sub-processor map · not disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of Cronofy
Integration & access
Compliance & governance
Pricing & tiers
Public documents
-
missingData Processing Addendum (DPA)— missing
-
missingSub-processors list— missing
-
OpenTerms of Servicedocs.cronofy.com/policies…
Alternatives in this category
-
United States · $12/moUS-LinkedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct This listing The operator itself is US-incorporated.
Public DPA: No Sub-processors: Yes Open source: Yes -
-
SwitzerlandEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
CzechiaEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
US-Linked | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: Yes
Open source: Yes
|
$12/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |