Back to Tools
Twenty logo

Twenty

GDPR Compliant

Open-source CRM from France. Modern Salesforce alternative.

🇫🇷France🇪🇺EU Hosted🇪🇺 EuropeanOpen Sourcefrom Free (self-hosted)
Twenty website screenshot

GDPR Compliance Data

Verified from vendor documentation
GDPR Status
GDPR Compliant
HQ CountryFrance
OwnershipEuropean-owned
Foreign Disclosure ExposureNot yet verified
Data Hosting Location
European Union… the United States but data is currently hosted in Frankfurt (EU).
EU Servers Available
Data Processing AgreementNot verified
Sub-processor ListNot verified
Schrems II Risk
Low Risk
SCCs in Place
Last Verified5 August 2026
NotesOpen-source, self-hostable, French company

About Twenty

Open-Source CRM Built in France

Twenty is a French open-source CRM designed as a modern alternative to Salesforce. It offers a clean, customizable interface with full self-hosting capabilities, giving you complete control over your customer data within the EU.

Modern CRM, Open Source

Twenty reimagines what a CRM can be:

  • Clean interface. Modern, intuitive UI that doesn't feel like enterprise software from 2005
  • Fully customizable: Add custom objects, fields, and views to match your workflow
  • Self-hostable. Deploy on your own infrastructure for complete data sovereignty
  • API-first. Build integrations and automations with a developer-friendly API
  • Community-driven. Active open-source community contributing features and improvements

True Data Ownership

As a self-hostable open-source project, Twenty gives you complete control over where your data lives. The managed cloud version is hosted on EU infrastructure for teams that prefer not to self-host.

Key Features

Modern interface: Clean, intuitive CRM design
Custom objects: Flexible data modeling for any workflow
Self-hosting: Full control over your infrastructure
API-first: Developer-friendly REST and GraphQL APIs
Open source: Inspect, modify, and contribute to the codebase

Pros & Cons

Modern UI that's a joy to use
Fully open source with self-hosting option
No per-seat licensing fees
Younger project, fewer integrations than Salesforce
Self-hosting requires technical expertise

Pricing

Self-hosted

Popular
€0
  • Unlimited users
  • Full CRM
  • Open source
  • Complete data control

Cloud

Custom
  • Managed hosting
  • Automatic updates
  • Support
  • EU hosting available

Categories

Twenty on EuropeanMartech

Twenty GDPR & data protection: common questions

Is Twenty GDPR compliant?

Yes. On the evidence we checked, Twenty meets the requirements European businesses usually need. Twenty is a European company headquartered in France, data is hosted within the European Union. Every claim on this page links to the vendor's own documentation.

Where does Twenty store data?

Twenty states: "… the United States but data is currently hosted in Frankfurt (EU).". Data is hosted within the European Union.

Does Twenty offer a Data Processing Agreement (DPA)?

We could not locate a published DPA for Twenty. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.

What a DPA has to cover

Is Twenty a European company?

Yes. Twenty is headquartered in France and, as far as we can establish, European-owned.

Spot an error in the compliance data? Get in touch