SuperSaaS
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Amsterdam-based Dutch appointment scheduling (SuperSaaS B.V., founded 2007 by Jan M. Faber), unfunded founder-owned, 205k+ businesses, 35 languages.
SuperSaaS offers EU hosting in the Netherlands, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Calendar booking.
Assessment notes
SuperSaaS B.V. (Strawinskylaan 6, 1077 XZ Amsterdam, Netherlands; founded 2007 by Jan M. Faber) is an unfunded, founder-owned Dutch appointment-scheduling platform with 205,000+ businesses on the platform across 35 UI languages and 60 countries, a structurally rare 19-year-old EU SaaS with no PE / VC / parent on record. The procurement-documentation gaps recorded in May 2026 are closed: the DPA is publicly readable at /info/data_processing_agreement (version 2.1, processor named as SuperSaaS B.V. at the Amsterdam address, no login or sales gate, and it restricts processing to "the EU or EEC"), and a public sub-processor list at /info/subprocessors names exactly two: Amazon Web Services, Inc. (Ireland) for infrastructure and storage, and Worldstream B.V. (Netherlands) for dedicated servers. The privacy policy, last updated March 2026, states processing happens "on servers in the Netherlands and elsewhere within the European Union or European Economic Area". So the shape is a Dutch, founder-owned vendor with an EU-only processing commitment and a very short chain — but the storage custodian named is AWS, a US-owned provider, which is data-at-rest exposure rather than the single transient processor the minor tier describes; the flag is therefore material. The score stays at 4 rather than dropping: only one US-owned sub-processor is involved, in an EU region, against a publicly readable DPA and a public sub-processor list. Two residual gaps: the sub-processor list is dated January 2021 and has not been refreshed, and neither document addresses Google Calendar / Outlook / Zoom connections or names the payment providers.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: No
Jump to
About SuperSaaS
SuperSaaS is an Amsterdam-headquartered Dutch online appointment-scheduling platform operated by SuperSaaS B.V. (Strawinskylaan 6, 1077 XZ Amsterdam) and founded in 2007 by Jan M. Faber. The company has reached 205,000+ businesses on the platform across 60 countries and 35 UI languages, and remains unfunded (no PE, no VC, no parent), making it one of the longest-running founder-controlled EU SaaS in the directory. The product covers self-service appointment booking for service businesses (yoga / fitness studios, salons, clinics, equipment rentals, classroom bookings, language-school timetables), reminders by email and SMS, payments through PayPal and Stripe, calendar sync, and integrations.
For an EU-sovereignty audit SuperSaaS is structurally clean at the ownership layer: Dutch B.V., founder-controlled, no outside capital. The procurement documentation is in better shape than a vendor this size usually manages: the DPA is publicly readable at version 2.1 without login and restricts processing to the EU or EEA, and a public sub-processor list names exactly two providers, Amazon Web Services, Inc. (Ireland) for infrastructure and storage and Worldstream B.V. (Netherlands) for dedicated servers. That very short chain also carries the one weakness: AWS is named for storage, so booking data is at rest with a US-owned provider even though the region is Irish: Material. Two residual gaps are worth raising in a procurement call: the sub-processor list is dated January 2021 and has not been refreshed, and neither document addresses Google Calendar, Outlook or Zoom connections. The product takes no transaction fees (PayPal / Stripe / other payment processors charge their fees directly), and the free tier covers up to 50 future appointments with SuperSaaS-branded advertising; paid tiers scale by appointment volume from €7/month and remove advertising.
Best fit: long-tail service-business segments (yoga studios, salons, dentists, driving instructors, equipment rentals, language schools, sports clubs) that need multilingual booking pages; SuperSaaS's 35-language coverage is unusually broad for the category and aligns with niche-language EU markets that Calendly and Acuity under-serve. Procurement-grade buyers get a publicly readable DPA, a named sub-processor list and an EU-only processing commitment here without having to ask. Buyers who must keep booking data off a US-owned provider entirely will not find a hosted option in this category that meets that bar, and should look at a self-hosted deployment on EU infrastructure instead.
Sub-processor map · not disclosed
Frameworks & certifications · none listed
Capability matrix
Table 1Capabilities of SuperSaaS
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
United States · $12/moUS-LinkedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct This listing The operator itself is US-incorporated.
Public DPA: No Sub-processors: Yes Open source: Yes -
-
United KingdomEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: No -
-
SwitzerlandEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
US-Linked | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: Yes
Open source: Yes
|
$12/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: No
|
— |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |