Reservio
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Brno-based Czech booking platform (Reservio s.r.o., ABUGO Group), 500k+ businesses, freemium with branded customer apps.
Reservio offers EU hosting in Czechia, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Calendar booking.
Assessment notes
Reservio s.r.o. (Brno, Czech Republic; incorporated 6 November 2012; member of the ABUGO Group) is a Czech online booking platform serving 500,000+ businesses and 21M+ clients annually with a freemium model: scheduling calendar, POS, client and team management, branded customer apps, and SMS / email reminders. Ownership is clean: a Czech s.r.o. inside a Czech SaaS holding group, no PE or VC chain visible, and the payment rail is Adyen N.V. in Amsterdam rather than a US processor. Data residency is committed in writing — "all data are located only on servers in the European Union or in countries that ensure protection of personal data in a manner equivalent to" Czech law — and CDN delivery runs through CDN77 (Czech-incorporated, ultimately Datacamp Limited in Cyprus), so the asset layer is EU-domiciled too. The processor chain is where the score falls. The privacy policy names, as recipients, Twilio Inc. / SendGrid (USA) for the booking confirmations and reminders that carry client names and appointment detail, OpenAI, L.L.C. (USA), New Relic, Inc. (USA) for monitoring and Intercom, Inc. (USA) for support, alongside Microsoft Clarity, Google Analytics / Tag Manager / Ads, Facebook and Seznam.cz on the marketing side. Four US-owned processors touching product data, one of them an AI vendor, is material exposure and ≥3 US sub-processors, which caps the score at 3. The DPA itself is fine — it is publicly readable as Article 21.3 of the terms and conditions, no login and no sales gate — but the hosting provider is still unnamed, and Google Calendar / Microsoft 365 / Zoom connections are not addressed anywhere in the policy set.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: No
Jump to
About Reservio
Reservio is a Brno-headquartered Czech online appointment-scheduling platform operated by Reservio s.r.o. and a member of the ABUGO Group. Incorporated on 6 November 2012, the company has scaled to 500,000+ businesses on the platform with 21M+ clients and 20M+ bookings per year, large enough to be a serious B2C booking marketplace in Central and Eastern Europe alongside being a B2B scheduling tool. The product surface covers scheduling calendar, online booking website, POS, client management, team management, mobile apps (iOS/Android), SMS and email reminders, online payments, and an optional branded customer app (white-label mobile app) for businesses on higher tiers. The freemium model unlocks the scheduling calendar, booking website, client management, team coordination, and integrated POS without payment.
For an EU-sovereignty audit Reservio is a clean Czech ownership story: no PE / VC chain visible, member of the ABUGO Group (Czech corporate holding), 23 employees. CDN delivery is via CDN77 (a Czech-incorporated CDN provider, ultimately part of Datacamp Limited in Cyprus); Czech and Cypriot incorporations are both inside the EU so the asset layer is EU-domiciled. Where the listing weakens is the processor chain rather than the paperwork. The DPA is publicly readable as Article 21.3 of the terms and conditions, with no login and no sales gate, and the privacy policy enumerates the recipients. Payments run through Adyen N.V. in Amsterdam, an EU rail in a category where the US default is Stripe, but the same list names Twilio Inc. / SendGrid (USA) for the booking confirmations and reminders that carry client names and appointment detail, OpenAI, L.L.C. (USA) with no stated purpose, New Relic (USA) for monitoring and Intercom (USA) for support: Material. The customer-data hosting provider is still not publicly named; the privacy policy commits to residency in the EU or an equivalent country instead of naming a provider.
Best fit: Czech, Slovak, Polish, Hungarian, and broader CEE small and medium service businesses (beauty salons, fitness clubs, language schools, medical practices, equipment rentals); EU SMBs that benefit from Reservio's white-label customer-app option; multilingual booking pages across the CEE language belt. Procurement-grade EU-only buyers should ask Reservio to name its hosting provider, and to state what booking data, if any, reaches OpenAI, before signing.
Sub-processor map · not disclosed
Frameworks & certifications · none listed
Capability matrix
Table 1Capabilities of Reservio
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
United States · $12/moUS-LinkedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct This listing The operator itself is US-incorporated.
Public DPA: No Sub-processors: Yes Open source: Yes -
-
United KingdomEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: No -
-
SwitzerlandEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
US-Linked | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: Yes
Open source: Yes
|
$12/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: No
|
— |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |