Credit committees, trading floors, client meetings: in banking and insurance, a schedule names counterparties, transactions, deadlines. The sector lives under a permanent inventory of its providers — every SaaS added is one more line to document, audit and terminate cleanly.
Your sector's context
Since the Schrems II ruling (CJEU, 2020), the tension between the US Cloud Act and the GDPR remains unresolved: data held by a provider under US jurisdiction remains accessible to US authorities, even when hosted in Europe.
Regulatory framework
The obligations specific to your sector.
DORA: the register of ICT providers
Regulation (EU) 2022/2554 (DORA), applicable since 17 January 2025, requires financial entities to keep a register of their ICT providers and to manage third-party risk formally. A booking tool that hosts no booking data with the vendor lightens the analysis accordingly — the exact qualification is up to your compliance function.
Switzerland: FINMA outsourcing
FINMA Circular 2018/3 “Outsourcing” requires Swiss banks and insurers to inventory and govern their material outsourcing arrangements. Less data entrusted to third parties means a shorter outsourcing perimeter to defend in an audit.
Schrems II and the Cloud Act
Since the Schrems II ruling (CJEU, 16 July 2020), the tension between the American Cloud Act of 2018 and the GDPR persists: data held by a provider under US jurisdiction remains reachable by its authorities, even when hosted in Europe. Schedules that never leave your infrastructure are outside that field.
On the ground
Three typical use cases.
Committees and sensitive rooms
Credit committee, risk committee, data room: the subject, attendees and recurrence of your committees pass through no third party — bookings stay in your calendars.
Client booths and drop-in offices
Branches book booths and offices like any other calendar; requests go through your administrators, and every activated workstation is tracked and revocable.
Auditability
A lean client: no telemetry, no analytics, no CDN. What the application does can be verified technically — a concrete argument before an internal or external auditor.
For your compliance team: the scope held by the vendor is limited to the organisation's account (e-mail addresses, licence, seats, hashed device fingerprints) — exportable and documented in the customer area's compliance sheet, with dated purposes and retention periods.
One line fewer in the register
Outsourcing is managed through inventory: every provider that holds data enters the DORA register, the FINMA inventory, the audit plan. A schedule that never leaves your infrastructure creates no such line: the licence portal holds only the organisation's account, and the application talks only to your calendars. That is one less dependency to document, test and terminate.
By architecture, not by promise
What the architecture guarantees.
Your bookings stay with you
Schedules, attendees and bookings live in your Zimbra/CalDAV calendars and on your workstations — not with the vendor, not in a foreign cloud subject to extraterritorial laws.
The network goes down, your bookings don't
The licence is a signed certificate verified locally: the app keeps working without a connection, network outage included.
A lean, auditable client
No trackers, no embedded analytics, no CDN: what the app does can be verified — nothing has to be taken on faith.
These points describe the product's architecture, not a sector certification. They are not legal advice: have your compliance reviewed by a specialist. Content to be reviewed by a lawyer before publication.
Cookies: the bare minimum — and nothing without your consent.
This site only uses cookies that are strictly necessary for it to work (session, security). With your consent, we also enable anonymized, self-hosted audience measurement (Matomo). No advertising cookies, no third-party trackers.
Cookie policy