oneVcard (oneVcard GmbH, WΓΆrth am Main, commercial register Aschaffenburg HRB 15617) is the only provider in this comparison with consistent Germany hosting: primary data center in Frankfurt, redundant in Nuremberg (subprocessors Hetzner and A1 Digital), and a DPA under Art. 28 GDPR is available. The offering includes NFC physicals, QR, Apple/Google Wallet, a central team console, SSO (SAML and OpenID Connect), CSV import, HR connectors (Entra ID, Personio, Google Workspace) as well as CRM integrations (HubSpot, Salesforce, Zoho). The Lite plan is permanently free, the Premium plan is paid; Teams and Enterprise terms are individual. As a weakness, it should be noted that oneVcard does not hold its own ISO 27001 or SOC 2 certification (the DPA document denies its own TOM certifications; the advertised ISO 27001 statement refers to the data center operator), that SCIM and MDM are not documented, and that hardly any independent user reviews are available.
Blinq (Blinq Technologies Pty Ltd, Melbourne) scores with a very mature product, enforced SSO, SCIM provisioning (Okta, Entra), more than 20 CRM integrations and top ratings (G2 4.8; Capterra 4.9 across several thousand reviews). It is hosted on Google Cloud; a guaranteed EU or Germany data residency is not documented, the controller is based in Australia, and a DPA can only be viewed on request via the Trust Center, the essential drawback for GDPR-sensitive procurement.
HiHello (HiHello, Inc., Palo Alto) offers the broadest identity set (SSO via OAuth 2.0/SAML, SCIM, directory sync with Okta, Entra ID, Google Workspace, Workday), is SOC 2 Type II certified and provides a DPA. However, all data resides on Google Cloud in Iowa (USA); there is no EU hosting and no German-language support, and prices are in USD.