Queue-it
Denmark · owned by GRO Fund II K/S (Denmark) · queue-it.com · 58 vendors
Queue-it provides virtual waiting room technology that helps organizations manage peak traffic and prevent website crashes during high-demand sales and registrations. The company's platform gives businesses real-time control over traffic flow while ensuring fair, reliable, and transparent online experiences for customers.
Resilience scores
- Digital Sovereignty: 16
- Digital Resilience: 9
- Financial Resilience: 7
Disruption prediction
Queue-it has an estimated 40% probability of disruption in the next 6 months.
29 of Queue-it's 58 vendors monitored for disruptions.
Technology vendors
- Adobe Inc. — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- Tealium — Technology — United States
- and 56 more
Services catalogue
2 services in catalogue across 2 categories; runs on 58 sub-vendors.
- Queue-it
- Virtual Waiting Room
Insights
Last updated 2026-09-13 · revision 53
58 direct vendors, 407 subvendors
Direct vendors by controlling owner country (sample)
- France: 1
- Sweden: 4
- Australia: 1
Subvendors by controlling owner country (sample)
- Unknown: 2
- India: 3
- Denmark: 12
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Queue-it exhibits a very high degree of migration readiness. Its architecture is inherently cloud-native, built on Amazon Web Services (AWS) and also utilizing Google Cloud Platform (GCP), indicating a flexible, multi-cloud approach. The tech stack is modern, API-driven (Queue-it Admin REST API), and modular, as evidenced by its extensive library of 25+ pre-built integration connectors (SDKs for edge/CDN, server-side, native mobile, and e-commerce platforms). This modularity and API-first design significantly reduce complexity for potential migrations. The company's robust regulatory compliance framework, including SOC 2 Type II, ISO certifications, GDPR, CCPA, HIPAA, PCI DSS, and NIS2 applicability, means it has established processes and controls that are crucial for managing compliance during any migration. Furthermore, Queue-it already handles complex data residency requirements, with infrastructure designed for data hosting in multiple AWS regions globally (US, EU, APAC), which simplifies the planning and execution of data migration and sovereignty needs. Financial stability, indicated by consistent growth, suggests the company has the resources to fund a significant migration effort. While the 'Total Vendors: 0' data point is confusing, the explicit use of multiple cloud providers (AWS, GCP) and multiple CDN/Edge providers (Akamai, Cloudflare, CloudFront, Fastly, Tencent) for core infrastructure demonstrates a strong multi-vendor strategy, which inherently minimizes vendor lock-in for critical components. The geographic diversity of vendor HQs across 9 countries also contributes to a flexible vendor ecosystem. The main area of unknown is the 'Vendor Lock-in Risk' for non-core services, but for its primary technology infrastructure, readiness is exceptionally high.
Compliance
8 in-scope frameworks identified; showing 3.
GDPR (source) — Compliant
Queue-it is headquartered in Copenhagen, Denmark — an EU member state — making GDPR universally and unconditionally applicable. As a SaaS provider, Queue-it acts as both a data controller (for its own employee, customer, and supplier data) and a data processor (processing visitor/end-user data on behalf of its 1,000+ enterprise clients globally). The company explicitly markets GDPR compliance on its homepage ('No sensitive data goes through Queue-it so you stay GDPR & CCPA compliant') and its Trust Center references GDPR compliance in customer testimonials. Risk is rated Medium rather than Low because: (1) Queue-it processes data from 172 countries including EU residents at massive scale (100M+ daily visitors); (2) as a data processor for enterprise clients, any breach or non-compliance could trigger joint liability; (3) Danish DPA (Datatilsynet) enforcement is active; (4) the company's global reach and multi-jurisdictional data flows require ongoing SCCs and transfer mechanism maintenance. However, the company's stated architecture of minimising personal data processing (HTTP redirects, no sensitive data transit) reduces inherent risk.
Evidence: https://queue-it.com/trust-center/, https://queue-it.com/trust-center/privacy/, https://queue-it.com/privacy-policy/, https://queue-it.com/cookie-statement/, https://queue-it.com/, https://queue-it.com/success-stories/generalitat-de-catalunya/, https://trust.queue-it.com/
Danish Data Protection Act — Compliant
As a Danish-headquartered company, Queue-it is subject to the Danish Data Protection Act (Act No. 502 of 23 May 2018), which supplements and implements GDPR in Denmark. The Danish Data Protection Authority (Datatilsynet) is Queue-it's lead supervisory authority under GDPR's one-stop-shop mechanism. Risk is Medium because: (1) Datatilsynet is an active enforcement authority with a track record of investigations and fines; (2) Queue-it's role as a data processor for 1,000+ clients creates ongoing compliance obligations; (3) Danish law includes specific provisions on employee data, sensitive data processing, and research that go beyond GDPR baseline; (4) however, Queue-it's stated data minimisation approach and active compliance posture reduce inherent risk.
Evidence: https://queue-it.com/privacy-policy/, https://queue-it.com/trust-center/privacy/, https://queue-it.com/about/
NIS2 (source) — Assessment Required
NIS2 (EU Directive 2022/2555, transposed into Danish law by December 2024) potentially applies to Queue-it under the 'Digital Providers' category, specifically as a 'managed service provider' or 'cloud computing service provider' — both listed as Important Entities under NIS2 Annex II. Queue-it is a SaaS company providing critical digital infrastructure services (virtual waiting rooms) to 1,000+ organisations including public sector, financial services, healthcare-adjacent, and government entities across the EU. The company was founded in 2010, has 4 global offices, and serves 100M+ daily visitors — strongly suggesting it exceeds the NIS2 medium enterprise threshold (50+ employees or €10M+ turnover). Risk is Medium because: (1) if applicable as an Important Entity, non-compliance could result in fines up to €7M or 1.4% of global annual turnover; (2) Danish NIS2 transposition (Lov om sikkerhed i net- og informationssystemer) is in force; (3) Queue-it's role as critical digital infrastructure for government and financial sector clients increases regulatory scrutiny; (4) however, Queue-it may not be directly classified as a 'digital infrastructure' provider under NIS2 Annex I (Essential Entities) but rather Annex II (Important Entities) as a digital provider/managed service.
Evidence: https://queue-it.com/about/, https://queue-it.com/trust-center/, https://queue-it.com/public-sector/, https://queue-it.com/financial-services/, https://trust.queue-it.com/
Financials
Three-year financials
- 2025: gross profit DKK 122M, EBIT DKK -6.64M, equity DKK 525K
- 2024: gross profit DKK 112M, EBIT DKK 168K, equity DKK 8.65M
- 2002: gross profit DKK 84.0M, EBIT DKK -19.1M, equity DKK 8.16M
Financial Resilience Score: 7/10
Queue-it demonstrates strong qualitative financial resilience characteristics typical of a mature, category-leading SaaS business. The company operates a recurring revenue model with 1,000+ enterprise customers across diversified industries (ecommerce, ticketing, public sector, education, financial services, telecom, travel) and geographies (offices on 4 continents, users from 172 countries). Blue-chip customers including Ticketmaster, IKEA, Sky, and multiple government agencies provide sticky, often multi-year contracts that enhance revenue visibility. The company's 15-year operating history, founder-led leadership, and position as category leader in virtual waiting rooms provide competitive moats. Strong partner network (AWS, Google Cloud, Akamai, Salesforce) and capital-light SaaS model with proprietary IP support scalability. The pandemic period (2020-2021) demonstrated demand resilience through government vaccine registration and unemployment portal use cases. Key risks include competition from CDN and bot-management vendors (Cloudflare, Akamai, Fastly, Imperva), concentration in cyclical peak-event verticals sensitive to discretionary spending, FX exposure across multiple currencies, and disruption risk from agentic AI/evolving bot traffic patterns. The growth-stage cost base from 4 international offices implies significant SG&A that depends on continued ARR growth for profitability. As a private Danish ApS, financial transparency is limited to statutory annual report disclosures.
Key strengths: Recurring SaaS revenue model with 1,000+ enterprise customers, Diversified customer base across industries and geographies, Blue-chip sticky customers (Ticketmaster, IKEA, Sky, government agencies), Category leader position in virtual waiting rooms, 15-year operating history with founder-led leadership, Strong partner network (AWS, Google Cloud, Akamai, Salesforce), Capital-light SaaS model with proprietary IP, Users from 172 countries; 38B+ annual visitors processed
Risk factors: Competition from CDN/bot-management vendors (Cloudflare, Akamai, Fastly, Imperva), Concentration in cyclical peak-event verticals (ticketing, sneaker drops), FX exposure across DKK/EUR/USD/AUD/KRW/JPY, Agentic AI and evolving bot traffic patterns could disrupt positioning, Growth-stage cost base from 4 international offices requires continued ARR growth, Limited financial transparency as private Danish ApS, Cloud-native autoscaling as potential substitute technology
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.