Skip to content

Twenty

Twenty.com PBC (Delaware public benefit corporation, San Francisco notice address), contracting party and DPA processor for the managed cloud; French operating subsidiary Twenty SAS (SIREN 914 989 041, Paris)

CRM · France
Founded 2022 · twenty.com

Paris-built open-source CRM (AGPL-3.0) from Twenty SAS; the managed cloud is contracted with US parent Twenty.com PBC, also the DPA processor, and runs on AWS Frankfurt.

Twenty is operated by a US-incorporated entity and remains directly subject to the CLOUD Act. It is listed under CRM.

Assessment notes

Twenty is built in Paris by Twenty SAS (SIREN 914 989 041, registered 24 June 2022, 18 rue Soleillet, 75020 Paris), the French entity that employs the product team and holds the software IP. The managed cloud, however, is contracted with Twenty.com PBC, a Delaware public benefit corporation, under Delaware law, and since a DPA revision merged on 12 August 2026 (pull request #24026 in the public repository) the PBC is also the processor and, under the Standard Contractual Clauses, the data importer for EU-hosted workspaces. The generated DPA states that Twenty PBC is the processor and Twenty SAS the EU affiliate for every hosting region, and that EU hosting does not by itself exclude a transfer where data is made available to Twenty PBC. With a US-incorporated company as the contracting processor, CLOUD Act exposure is recorded as direct; ownership stays EU HQ, US-funded, because the team, the IP and the operating company are French while control sits with the US parent. All customer records sit on AWS eu-central-1 (Frankfurt), and the always-engaged sub-processor set adds ClickHouse (US-incorporated, processing in Germany), Cloudflare (edge, worldwide) and Sentry (processing in the United States). An EU office under a US parent that is itself the processor is the 2/5 row of the rubric. In its favour: EU data residency by default, an unusually granular public sub-processor register on the trust centre, SOC 2 Type 2, a self-serve DPA that any workspace admin can generate and sign in-app (there is no public DPA URL), and an AGPL-3.0 codebase that lets a buyer leave the US contract entirely by self-hosting, which is scored separately and comes out clean.

Findings

CLOUD Act
Ownership
Sub-processors
9 · 8 US

Verified signals

Jurisdiction
  • EU / adequacy hosting: Yes
  • EU / adequacy operator: Yes
  • No US CLOUD Act exposure: No
Transparency
  • Public DPA: Not assessed
  • Sub-processors disclosed: Yes
  • Open-source clients: Yes
  • Third-party certification: Yes
CLOUD Act by deployment

Exposure depends on how you run this product.

Hosted SaaS (default)

Vendor-operated: the sub-processors below apply.

Self-hosted (open-source)

Deploy on your own EU infrastructure and you control hosting and every sub-processor.

Jump to

About Twenty

Twenty is an open-source CRM built by a Paris product team and positioned as the open alternative to Salesforce. The code lives at github.com/twentyhq/twenty under AGPL-3.0 (with a small set of files marked @license Enterprise under a separate Twenty.com Commercial License, and the SDK packages under MIT) and has passed 54,000 GitHub stars. Founders Félix Malfait, Charles Bochet and Thomas des Francs went through Y Combinator S23 and raised a 5 million USD seed round in November 2024 led by Runa Capital, with angels from HubSpot, Front, Cal.com, Sentry and Photoroom. Functionally it is a developer-shaped CRM rather than a sales-suite: unlimited custom objects, fields and views, table / kanban / calendar views, workflows and AI agents, two-way email and calendar sync, REST and GraphQL APIs, webhooks and an MCP server.

The corporate structure is the thing a European buyer has to read carefully. Twenty SAS (SIREN 914 989 041, registered 24 June 2022 in the 20th arrondissement of Paris) employs the product team and holds the software IP, but the managed service is contracted with Twenty.com PBC, a Delaware public benefit corporation with a San Francisco notice address, under Delaware law, and the privacy policy states plainly that Twenty is based in the United States. Since a DPA revision merged in August 2026, the PBC is also the processor and, under the Standard Contractual Clauses, the data importer for EU-hosted workspaces: the DPA generated in each workspace names Twenty PBC as processor and Twenty SAS as EU affiliate for every hosting region, keeps Delaware as the governing law, and notes that EU hosting does not by itself exclude a transfer where data is made available to Twenty PBC. An EU operating company under a US parent that is itself the contracting processor is why ownership is recorded as EU-headquartered with US funding and why CLOUD Act exposure is Direct. Data residency itself is clean: every customer record, backup and log sits on AWS eu-central-1 in Frankfurt, Germany, with audit logs in ClickHouse (also processed in Germany), Cloudflare in front for CDN and WAF, Sentry for error monitoring in the United States, and optional AI features routed to Anthropic, OpenAI or Mistral only when a workspace turns them on. Residency does not change the legal reach, though: the processor and the hyperscaler holding the data at rest are both US companies. The trust centre at trust.twenty.com publishes SOC 2 Type 2 and GDPR status plus a per-vendor sub-processor register with processing locations, but the underlying policy documents are behind a request-access wall, and the DPA has no public URL: a workspace admin generates and signs it in-app under Settings > DPA.

Pricing is USD-denominated with no EUR list price: Pro at $9 per user per month, Organization at 19 USD per user per month for row-level permissions, SAML/OIDC SSO, custom domain and audit logs, and Enterprise from 50,000 USD per year for single-tenant isolation, IP allow-listing and SCIM. There is no free hosted tier, only a 30-day trial without a card. The product UI ships 33 locale catalogues including French, German, Spanish, Italian, Dutch, Polish and the Nordic languages. Best fit: technical teams that want a customisable CRM they can fork, extend and eventually take with them. Buyers whose procurement rules exclude a US parent or a US-owned hyperscaler should either self-host Twenty on Hetzner, OVHcloud or Scaleway, which removes the US contract and AWS entirely, or look at centralstationCRM (DE) or combit CRM (DE) elsewhere in this category, since weclapp and Teamleader both run customer data on Amazon Web Services.

Sub-processor map · 9

Source
  • Amazon Web Services US
    Germany

    Primary hosting: compute, managed databases, object storage and encrypted backups. Holds all customer CRM data at rest in eu-central-1 (Frankfurt). Always engaged.

  • Anthropic US
    United States

    Optional AI features (drafting, summarisation, enrichment). Engaged only when a workspace enables AI and runs an action; no training on customer data; SCCs in place.

  • ClickHouse US
    Germany

    Analytical database storing audit logs and powering in-product analytics and reporting; may contain customer personal data. Processed in Germany, always engaged.

  • Cloudflare US
    United States

    CDN, DNS and web application firewall. Processes request/response content and connection metadata in transit only across the worldwide edge network, no long-term retention. Always engaged.

  • Google Cloud Platform US
    Germany

    Google Maps look-ups and Google single sign-on only. Processed in Germany, engaged only for workspaces that use those features.

  • OpenAI US
    United States

    Optional AI features, depending on the model configured for the workspace. Processed in the United States and the EU; no training on customer data; SCCs in place.

  • Sentry US
    United States

    Application error and performance monitoring; stack traces and request context, scrubbed but may incidentally contain customer data. Processed in the United States, always engaged.

  • Stripe US
    United States

    Payment processing for the managed cloud subscription. Named in the privacy policy only; absent from the trust-centre register and from subprocessors.json as of 2026-08-10.

  • Mistral AI EU
    France

    Optional AI features, depending on the model configured for the workspace. EU provider with EU hosting, so no transfer outside the EEA; no training on customer data.

Source: the vendor’s published sub-processor list, read 2 Oct 2026.

8 of 9 sub-processors are US-owned or US-based. CLOUD Act exposure applies.

Frameworks & certifications

SOC 2
Active
Informational · US framework

Capability matrix

Table 2Capabilities of Twenty

Sales pipeline Yes
Email sync Yes
Workflow automation Yes
Lead capture No
Email campaigns No
Quotes / invoicing No
Telephony No
Mobile app No
Free tier No

Integration & access

REST API Yes
SSO (SAML / OIDC) Yes

Compliance & governance

Audit log Yes
Self-host / on-prem option Yes

Pricing & tiers

from $9/mo
Paid
View pricing page

Public documents

DPA provided on request. The vendor provides its Data Processing Addendum to customers on request (by email or inside the account portal) rather than publishing it at a public URL, so it is not counted as a public DPA (see How we assess).
  • Data Processing Addendum (DPA)
    — on request
    on request
  • Sub-processors list
    trust.twenty.com
    Open
  • Terms of Service
    twenty.com/legal…
    Open

Alternatives in this category

  • United Kingdom
    EU-Hosted
    Public DPA: Yes Sub-processors: Yes Open source: No
  • Germany · €24/mo
    EU-Sovereign
    Public DPA: Yes Sub-processors: Yes Open source: No
  • Germany
    EU-Sovereign
    Public DPA: Not assessed Sub-processors: Yes Open source: No