
folk
Partially CompliantLightweight relationship CRM built in Paris but incorporated in Delaware, with AWS servers stated to be in the United States.
Subject to the US CLOUD Act: a US parent company can be compelled to disclose data it holds, including data stored in the EU.
Paid
GDPR Compliance Data
Not independently verified| GDPR Status | Partially Compliant |
| HQ Country | United States |
| Ownership | Non-European |
| Foreign Disclosure Exposure | US CLOUD Act / FISA 702 |
| Data Hosting Location | United States"Personal Data are hosted by Amazon Web Services inside Aurora database that is fully-secured and not accessible outside our servers." and "Our AWS services are located in the US." Source: folk.app/privacy-policy (read 2026-08-24). |
| EU Servers Available | |
| Data Processing Agreement | Not verified |
| Sub-processor List | Not verified |
| Schrems II Risk | High Risk |
| SCCs in Place | |
| Last Verified | 24 August 2026 |
How we reached this
Commonly listed as a French tool, including by euromakers.org, and the team is in Paris, but the privacy policy names the controller as "Folk Inc., a Delaware corporation, whose registered office is located at 1209 North Orange Street, Wilmington, Delaware 19801". That is a US company, so ownershipOrigin is NON_EU. The same policy states "Our AWS services are located in the US", so contact data from EU users is stored in the United States by a US-owned host under a US controller: exposure US_CLOUD_ACT and Schrems II risk HIGH. No EU region is offered and no DPA was located at a public URL. PARTIAL rather than non-compliant because data subject rights, retention and a commitment not to sell data or train AI models on it are set out in the policy.
About folk
A Contact-First CRM
folk starts from the address book rather than the pipeline. Contacts are grouped, enriched and shared across a team, with a browser extension that captures people from LinkedIn and other web pages in a click, and email sequences layered on top.
It suits agencies, investors, recruiters and anyone whose work is relationship management rather than a repeatable sales process with stages. Pipelines exist, but they are not the centre of the product the way they are in Pipedrive or Teamleader.
Not a European Company
folk is routinely listed in European software directories as French, and the team is in Paris. The legal position is different, and folk states it plainly in its own privacy policy:
"We, Folk Inc., a Delaware corporation, whose registered office is located at 1209 North Orange Street, Wilmington, Delaware 19801, is the Data Controller, within the meaning of the GDPR, of Your personal data."
The hosting matches. "Personal Data are hosted by Amazon Web Services inside Aurora database", and "Our AWS services are located in the US".
So a European buyer using folk is handing contact data, which is personal data about named individuals and often quite a lot of it, to a US corporation storing it in the United States. That is a restricted transfer, and both the controller and the host are reachable under the CLOUD Act and FISA 702.
Why It Is Listed Here Anyway
Because being told this before signing is more useful than not finding folk at all. A directory that only lists the tools that pass is a directory that leaves buyers to discover the failures themselves, usually after procurement.
If the contact data in question is a personal network, this may be an acceptable trade. If it is an EU customer base, the transfer needs a legal basis, a record and a line in the privacy notice, and there are European alternatives that do not need any of that. They are listed under CRM.
Key Features
Pros & Cons
Categories
folk GDPR & data protection: common questions
Is folk GDPR compliant?
Partly. folk meets some of the requirements, with caveats worth reading before you commit. folk is based in United States, outside the EU/EEA, data is hosted in the United States.
Where does folk store data?
folk states: ""Personal Data are hosted by Amazon Web Services inside Aurora database that is fully-secured and not accessible outside our servers." and "Our AWS services are located in the US." Source: folk.app/privacy-policy (read 2026-08-24).". Data is hosted in the United States.
Does folk offer a Data Processing Agreement (DPA)?
We could not locate a published DPA for folk. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.
What a DPA has to cover βIs folk a European company?
No. folk is based in United States, outside the EU/EEA. It may still be a sound choice (EU hosting and a signed DPA matter more than a flag) but the ownership is not European.
Is folk subject to the US CLOUD Act?
Yes. US authorities can compel disclosure of data held by a US company or its subsidiaries, regardless of the country the servers sit in. EU hosting alone does not remove this, the question is who controls the data, not where the disk is.
Schrems II compliance checklist βRelated Tools

Brevo
All-in-one marketing platform with email, SMS, CRM, and automation. French company, EU data hosting.

Teamleader
Belgian CRM combining sales, project management, and invoicing. EU-hosted.

Pipedrive
Sales-focused CRM from Estonia with EU data hosting option.
Spotted something wrong?
Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.
If you work at folk and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.