—
US-Linked
— Not assessed
— Not assessed
— Not assessed
French payment giant (Worldline SA, Paris-listed WLN), #4 PSP worldwide, 18k employees, free float ~73% anchored by Bpifrance and French banks.
Public DPA: Yes
Sub-processors: Yes
Open source: No
Paris · FR
France
EU-Based
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
This listing
EU-operated, with at most minor or transient US exposure.
EU-Hosted
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
ISO/IEC 27001
Paid
Minor
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
This listing
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
London-based mPOS fintech (originally Berlin), 4M+ SMBs, heavy US-VC funding (Goldman Sachs led €1.5B 2024); US$10-15B London listing in preparation.
Public DPA: Yes
Sub-processors: No
Open source: No
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
—
Paid
€0/mo
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
Swedish open-banking A2A payment innovator (Trustly Group AB, 2008), $10B annual volume, 33+ markets; Nordic Capital + BlackRock PE owned.
Public DPA: No
Sub-processors: No
Open source: No
Stockholm · SE
Sweden
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
ISO/IEC 27001
SOC 2
Paid
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
Amsterdam-based DNB-licensed payments platform: strong European payment methods (iDEAL, SEPA), 250k+ merchants; US-VC-funded cap table.
Public DPA: Yes
Sub-processors: No
Open source: No
Amsterdam · NL
Netherlands
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
—
Paid
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
Dutch publicly-listed payments giant (Euronext Amsterdam), DNB-licensed credit institution + EU/UK/US banking licences; €1.4T processed/yr.
Public DPA: Yes
Sub-processors: Yes
Open source: No
Amsterdam · NL
Netherlands
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
—
Paid
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
Oslo fintech (Dintero AS): Finanstilsynet-authorised PI and, since 2025, the only Norwegian-owned direct Visa/Mastercard acquirer; checkout for e-com, marketplaces and physical retail.
Public DPA: Yes
Sub-processors: Yes
Open source: No
Norway
EU-Based
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
This listing
EU-operated, with at most minor or transient US exposure.
EU-Hosted
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
—
Paid
Minor
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
This listing
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
London-based UK direct-debit and recurring-payments specialist (FCA-authorised); Mollie acquisition announced Dec 2025.
Public DPA: No
Sub-processors: Yes
Open source: No
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
—
Paid
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
London-based open-banking A2A real-time payments (Volt Technologies, 2019), FCA EMI, 2,500 banks across 31 territories; US-VC-led.
Public DPA: No
Sub-processors: No
Open source: No
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
—
Paid
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.