Manchester-based UK CRM (Zestia Ltd) with a free tier, public DPA, and AWS hosting; post-Brexit jurisdiction.
- FROM
- —
- CLOUD ACT
- MATERIAL
A single roll-up of ownership and CLOUD Act exposure.
Twenty SAS (SIREN 914 989 041, Paris, France), subsidiary of Twenty.com PBC (public benefit corporation, Delaware / San Francisco, USA)
Paris-built open-source CRM (AGPL-3.0) from Twenty SAS, but the managed cloud is sold by a Delaware PBC and runs on AWS Frankfurt.
Twenty, in the CRM category, offers EU hosting with Germany as its hosting location, but a US parent or sub-processor leaves material CLOUD Act exposure.
Twenty is built in Paris by Twenty SAS (SIREN 914 989 041, registered 24 June 2022, 18 rue Soleillet, 75020 Paris), the French entity that employs the product team and holds the software IP, and EU workspaces are processed under a French-law DPA naming Twenty.com SAS as processor. But the managed cloud is sold under the terms of Twenty.com PBC, a Delaware public benefit corporation, governed by Delaware law, and the company's own privacy policy states that Twenty is based in the United States; that is a US parent, so eu_owned is off the table. All customer records sit on AWS eu-central-1 (Frankfurt), which keeps the data physically in the EU but under a US-owned hyperscaler, and the always-engaged sub-processor set adds ClickHouse (US-incorporated, processing in Germany), Cloudflare (edge, worldwide) and Sentry (processing in the United States). US parent plus AWS at rest is exactly the pattern the rubric calls material CLOUD Act exposure, and the score does not go above 3 for that reason. Positives that keep it at 3 rather than 2: EU-only data residency for the default region, an unusually granular public sub-processor register on the trust centre, SOC 2 Type 2, a self-serve DPA that any workspace admin can generate and sign in-app (which by itself caps the score at 4 under the DPA-accessibility rule since there is no public DPA URL), and an AGPL-3.0 codebase that lets a buyer leave the US contract entirely by self-hosting.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
Where ultimate control over the operating company sits.
Exposure depends on how you run this product.
Vendor-operated: the sub-processors below apply.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
Deploy on your own EU infrastructure and you control hosting and every sub-processor.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
Twenty is an open-source CRM built by a Paris product team and positioned as the open alternative to Salesforce. The code lives at github.com/twentyhq/twenty under AGPL-3.0 (with a small set of files marked @license Enterprise under a separate Twenty.com Commercial License, and the SDK packages under MIT) and has passed 54,000 GitHub stars. Founders Félix Malfait, Charles Bochet and Thomas des Francs went through Y Combinator S23 and raised a 5 million USD seed round in November 2024 led by Runa Capital, with angels from HubSpot, Front, Cal.com, Sentry and Photoroom. Functionally it is a developer-shaped CRM rather than a sales-suite: unlimited custom objects, fields and views, table / kanban / calendar views, workflows and AI agents, two-way email and calendar sync, REST and GraphQL APIs, webhooks and an MCP server.
The corporate structure is the thing a European buyer has to read carefully. Twenty SAS (SIREN 914 989 041, registered 24 June 2022 in the 20th arrondissement of Paris) employs the product team and holds the software IP, and the DPA configuration published in the source repository names Twenty.com SAS, 9 rue des Colonnes, 75002 Paris as the processor for the EU region under French law, with no SCC annex needed because nothing leaves the EEA by default. The commercial terms of the managed service, however, are those of Twenty.com PBC, a Delaware public benefit corporation with a San Francisco notice address, governed by Delaware law, and the privacy policy states plainly that Twenty is based in the United States. That is a US parent over a French subsidiary, which is why ownership is recorded as EU-headquartered with US funding rather than EU-owned, and why CLOUD Act exposure is Material. Data residency itself is clean: every customer record, backup and log sits on AWS eu-central-1 in Frankfurt, Germany, with audit logs in ClickHouse (also processed in Germany), Cloudflare in front for CDN and WAF, Sentry for error monitoring in the United States, and optional AI features routed to Anthropic, OpenAI or Mistral only when a workspace turns them on. AWS is the determining fact: it is a US-owned hyperscaler holding the data at rest, so an EU region does not remove the exposure. The trust centre at trust.twenty.com publishes SOC 2 Type 2 and GDPR status plus a per-vendor sub-processor register with processing locations, but the underlying policy documents are behind a request-access wall, and the DPA has no public URL: a workspace admin generates and signs it in-app under Settings > DPA, which under our DPA-accessibility rule caps the score at 4 before the CLOUD Act deduction.
Pricing is USD-denominated with no EUR list price: Pro at 9 USD per user per month (€8 equivalent), Organization at 19 USD per user per month for row-level permissions, SAML/OIDC SSO, custom domain and audit logs, and Enterprise from 50,000 USD per year for single-tenant isolation, IP allow-listing and SCIM. There is no free hosted tier, only a 30-day trial without a card. The product UI ships 33 locale catalogues including French, German, Spanish, Italian, Dutch, Polish and the Nordic languages. Best fit: technical teams that want a customisable CRM they can fork, extend and eventually take with them. Buyers whose procurement rules exclude a US parent or a US-owned hyperscaler should either self-host Twenty on Hetzner, OVHcloud or Scaleway, which removes the US contract and AWS entirely, or look at centralstationCRM (DE), weclapp (DE) or Teamleader (BE) elsewhere in this category.
Primary hosting: compute, managed databases, object storage and encrypted backups. Holds all customer CRM data at rest in eu-central-1 (Frankfurt). Always engaged.
Optional AI features (drafting, summarisation, enrichment). Engaged only when a workspace enables AI and runs an action; no training on customer data; SCCs in place.
Analytical database storing audit logs and powering in-product analytics and reporting; may contain customer personal data. Processed in Germany, always engaged.
CDN, DNS and web application firewall. Processes request/response content and connection metadata in transit only across the worldwide edge network, no long-term retention. Always engaged.
Google Maps look-ups and Google single sign-on only. Processed in Germany, engaged only for workspaces that use those features.
Optional AI features, depending on the model configured for the workspace. Processed in the United States and the EU; no training on customer data; SCCs in place.
Application error and performance monitoring; stack traces and request context, scrubbed but may incidentally contain customer data. Processed in the United States, always engaged.
Payment processing for the managed cloud subscription. Named in the privacy policy only; absent from the trust-centre register and from subprocessors.json as of 2026-08-10.
Optional AI features, depending on the model configured for the workspace. EU provider with EU hosting, so no transfer outside the EEA; no training on customer data.
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Amazon Web Services | Germany | Primary hosting: compute, managed databases, object storage and encrypted backups. Holds all customer CRM data at rest in eu-central-1 (Frankfurt). Always engaged. | US |
| Anthropic | United States | Optional AI features (drafting, summarisation, enrichment). Engaged only when a workspace enables AI and runs an action; no training on customer data; SCCs in place. | US |
| ClickHouse | Germany | Analytical database storing audit logs and powering in-product analytics and reporting; may contain customer personal data. Processed in Germany, always engaged. | US |
| Cloudflare | United States | CDN, DNS and web application firewall. Processes request/response content and connection metadata in transit only across the worldwide edge network, no long-term retention. Always engaged. | US |
| Google Cloud Platform | Germany | Google Maps look-ups and Google single sign-on only. Processed in Germany, engaged only for workspaces that use those features. | US |
| OpenAI | United States | Optional AI features, depending on the model configured for the workspace. Processed in the United States and the EU; no training on customer data; SCCs in place. | US |
| Sentry | United States | Application error and performance monitoring; stack traces and request context, scrubbed but may incidentally contain customer data. Processed in the United States, always engaged. | US |
| Stripe | United States | Payment processing for the managed cloud subscription. Named in the privacy policy only; absent from the trust-centre register and from subprocessors.json as of 2026-08-10. | US |
| Mistral AI | France | Optional AI features, depending on the model configured for the workspace. EU provider with EU hosting, so no transfer outside the EEA; no training on customer data. | EU |
Manchester-based UK CRM (Zestia Ltd) with a free tier, public DPA, and AWS hosting; post-Brexit jurisdiction.
Cologne-based German SMB CRM (42he GmbH), all-German hosting on Hetzner + Core-Backbone + Telekom, free tier for 3 users.
Konstanz-based German CRM (combit Software, since 1989), founder-owned, on-prem + cloud, German Mittelstand vendor.