Doodle
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Swiss group-scheduling pioneer (Doodle AG, Zurich, 2007), owned by TX Group (SIX-listed Swiss media holding); SOC 2 + GDPR + HIPAA.
Doodle offers EU hosting in Germany, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Calendar booking.
Assessment notes
Doodle AG (Zurich, Switzerland; founded 2007 as the original group-scheduling polling tool) is wholly owned by the TX Group, the Swiss publicly-listed media holding (SIX Swiss Exchange: CH0011178255, formerly Tamedia, completed 100% acquisition in January 2014). Ownership remains the strongest signal here: a Swiss legal entity under a Swiss-publicly-listed parent, no US-PE control, EU/CH adequacy for cross-border transfers, a publicly readable DPA at doodle.com/en/data-processing-addendum, and SOC 2 Type II plus Cyber Verify Level III and GDPR alignment; 127 employees (March 2026); 19-year operating history. The processor chain is the weak half, and it was mis-read in May 2026 as minor because the sub-processor list was not found. Doodle publishes one at doodle.com/en/data-subprocessors/ (last updated 9 September 2025) and it names nine sub-processors, seven of them US-owned: core customer data sits on Amazon Web Services (Germany, Ireland) with MongoDB Atlas (Germany, Ireland) as the cloud database, so the at-rest custodians are US-owned providers even though the regions are European; billing runs through Chargebee (USA); Mailgun (USA) and Intercom (Ireland) deliver email; Google Analytics (USA), Growthbook (Germany/Ireland/USA), Microsoft behaviour analytics (Germany, Ireland) and Zapier (USA) complete the list. That is data-at-rest exposure on a US-owned hyperscaler plus a US payment rail, which is material rather than minor, and ≥3 US sub-processors, which caps the score at 3 under the rubric. Connected calendars and video tools (Google, Microsoft, Zoom) do not appear on the sub-processor list and the DPA does not address them either way, so their status is undocumented rather than confirmed as customer-authorised.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
European This listing Swiss/EEA-owned, with no significant US ownership; treated as European.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Doodle
Doodle is the Swiss group-scheduling pioneer headquartered in Zurich, operated by Doodle AG and founded in 2007 as a no-account meeting-scheduling poll (the "Doodle poll" that became a generic verb in many European business contexts during the 2010s). The product has since expanded into a full meeting-scheduling + time-management platform (Doodle Time OS) competing directly with Calendly and Acuity but with a heritage of group-availability scheduling that the US incumbents historically lacked.
Ownership is unusually clean for a 19-year-old SaaS: in January 2014, Tamedia (the Swiss publishing giant since renamed and reorganised into the publicly-listed TX Group, SIX Swiss Exchange ticker CH0011178255) completed a 100% acquisition of Doodle, and the company has remained a fully-owned subsidiary inside the TX Group's portfolio. TX Group is widely-held on the Swiss public market with no US-PE controlling stake on the cap table; this gives Doodle a Swiss-publicly-listed corporate parent without the Cohere / Vista / KKR-style US-PE risk seen elsewhere on this directory. Compliance posture is enterprise-ready: a completed SOC 2 Type II examination, Cyber Verify Level III, and GDPR alignment with a named DPO; a HIPAA business associate agreement is still offered, though the CCPA and HIPAA claims are no longer restated on the security page. Headcount stood at 127 employees as of March 2026.
Pricing is freemium with paid Pro, Team and Enterprise tiers, quoted in USD per seat and billed annually: Team shows US$11 per seat on annual billing against US$16 on monthly, and Enterprise starts at US$15,000; the Pro figure is still rendered client-side, so no entry-tier EUR figure was captured. Best fit: EU and Swiss SMBs and enterprises who want a group-scheduling tool with a Swiss-publicly-listed corporate counterparty, regulated industries needing HIPAA / SOC 2 attestation, and any procurement-grade buyer preferring the TX Group / Swiss-public-listed ownership architecture over US-VC-funded competitors (Calendly, Acuity). The gap to close before signing is no longer disclosure but the chain itself: the security page and the sub-processor list name Amazon Web Services and MongoDB Atlas (Germany, Ireland) as the custodians of booking data at rest and Chargebee (USA) as the billing rail, with Mailgun, Zapier, Google Analytics and Growthbook alongside, so seven of the nine listed sub-processors are US-owned: Material.
Sub-processor map · not disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of Doodle
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
United States · $12/moUS-LinkedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct This listing The operator itself is US-incorporated.
Public DPA: No Sub-processors: Yes Open source: Yes -
-
United KingdomEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: No -
-
CzechiaEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
US-Linked | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: Yes
Open source: Yes
|
$12/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: No
|
— |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |