Koofr
Synthèse de la propriété et de l’exposition au CLOUD Act.
-
Souverain UE Détenu et exploité dans l’UE/EEE/Suisse, sans exposition au CLOUD Act identifiée.
-
Basé UE Cette fiche Exploité dans l’UE, avec au plus une exposition américaine mineure ou transitoire.
-
Hébergé UE Hébergement UE disponible, mais une maison mère américaine ou un sous-traitant hyperscaler crée une exposition matérielle.
-
Lié aux US Exploité par une entité constituée aux États-Unis, directement soumise à la juridiction américaine.
Slovenian cloud storage (Koofr d.o.o., est. 2013), German ISO 27001 data centres, optional client-side encryption via the open-source Koofr Vault, 10 GB free.
Koofr est un service européen hébergé en Allemagne, avec tout au plus une exposition américaine mineure et transitoire au titre du CLOUD Act. Référencé dans la catégorie Partage de fichiers.
Notes d’évaluation
Koofr is operated by Koofr d.o.o. (Stegne 23A, Ljubljana, Slovenia; founded 2013, based in Technology Park Ljubljana), a fully EU-incorporated, EU-owned company that stores all data in ISO 27001-certified data centres in Germany, is GDPR-compliant by default, runs no file scanning or tracking, and offers optional client-side encryption via the Koofr Vault product; EU-owned and Germany-hosted with optional zero-knowledge encryption via Koofr Vault; CLOUD Act exposure was re-read down from none to minor in August 2026 once the privacy policy was read in full, because payments run through Braintree, part of PayPal, Inc. (US) — a single transient processor with no access to stored files, which is exactly the rubric's minor case rather than the clean none previously assumed; no Cloudflare and no US hyperscaler is named anywhere. The key documentation gap remains the absence of a public DPA, and the privacy policy that carries the processor disclosure has not been revised since 16 May 2018.
Constats
- CLOUD Act
- Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Cette fiche Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
-
- Actionnariat
- Propriété
Où se situe le contrôle ultime de la société exploitante.
-
Propriété UE Cette fiche Établie et contrôlée dans l'UE ; pas de participation américaine notable.
-
Siège UE, financement US Siège dans l'UE mais contrôlée par des capitaux américains (VC/PE).
-
Filiale UE, maison mère US Société d'exploitation européenne détenue par une société mère américaine.
-
Propriété US La société exploitante a elle-même son siège aux États-Unis.
-
Autre Une juridiction hors UE. La propriété suisse/EEE compte ici comme européenne ; le Royaume-Uni et d'autres non.
-
- Sous-traitants
- 0 aucun divulgué
Signaux vérifiés
-
Hébergement UE / adéquation: Oui
-
Opérateur UE / adéquation: Oui
-
Aucune exposition au CLOUD Act: Non évalué
-
DPA public: Non
-
Sous-traitants divulgués: Oui
-
Clients open source: Non
-
Certification tierce: Non
Aller à
À propos de Koofr
Koofr is a Slovenian cloud storage service operated by Koofr d.o.o., based at Stegne 23A in Ljubljana and a long-time member of Technology Park Ljubljana. Founded in 2013, it celebrated its tenth year of service in 2023 and is one of the cleaner small-vendor EU storage listings in this directory, fully Slovenian-incorporated, EU-owned, with no US parent, no US VC, and no PE on record.
The infrastructure story is solid: Koofr stores all customer data in ISO 27001-certified data centres in Germany, markets itself as "GDPR compliant by default," and explicitly commits to not scanning, indexing or tracking customer files. Standard transport encryption and encrypted storage apply to all accounts. For users who want true zero-knowledge encryption, Koofr offers Koofr Vault, a client-side-encrypted layer where files are encrypted in the browser/app before upload, so Koofr cannot read them. Koofr Vault is fully open-source, so its encryption can be independently audited. The apps and web UI are localised into more than 20 languages, including most major EU languages (German, French, Italian, Spanish, Dutch, Polish, Portuguese, Swedish, and others) alongside Slovenian and several global languages. A distinctive feature is that Koofr can connect and unify external clouds (Dropbox, Google Drive, OneDrive, Amazon) into a single interface, which is useful for migration but should be understood by privacy-focused buyers as an opt-in bridge to non-EU services.
For an EU-sovereignty audit the open question is documentation, not infrastructure. Koofr still publishes no DPA, and that is what caps this listing. It does name its processors, but only in prose inside a privacy policy that has not been revised since 16 May 2018, and only two of the four are named at all: Braintree Payments, described there as part of PayPal, Inc. (US), for card payments, and Headway for website services, alongside an unnamed accounting provider and a bank. No Cloudflare, no AWS, GCP or Azure and no US hyperscaler appears anywhere, and koofr.eu answers from plain Apache with no US CDN in front of it. That one transient US payment processor, which has no access to stored files, is why CLOUD Act exposure is recorded as Mineure rather than clear. The rest of the signal mix is strong: Slovenian entity, German ISO 27001 certified hosting, no file scanning, optional client-side encryption via Koofr Vault.
Pricing is freemium and unusually granular: 10 GB free forever; "Briefcase" tiers from €0.50/month (25 GB) and €1/month (100 GB); "Suitcase" tiers €4-10/month (250 GB to 1 TB); "Crate" tiers €20-35/month (2.5-5 TB) plus custom 10 TB+. Note that subscriptions are currently billed yearly and prices include 22% Slovenian VAT. Long-term subscribers can also join a Loyalty Program offering subscription discounts of up to 50%. The former free-storage referral scheme has been discontinued; there is no monetary affiliate programme. Best fit: privacy-conscious EU individuals and small teams who want German-hosted storage from an independent Slovenian vendor, especially those who will use Koofr Vault for sensitive files.
Carte des sous-traitants · aucun divulgué
Référentiels & certifications · aucune répertoriée
Matrice de fonctionnalités
Tableau 1Fonctionnalités de Koofr
Intégration & accès
Conformité & gouvernance
Tarifs & paliers
Documents publics
Alternatives dans cette catégorie
-
Suisse · 4 €/moisBasé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Cette fiche Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Non -
-
Suisse · 10 €/moisHébergé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Non -
-
Suisse · 4 €/moisSouverain UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Cette fiche Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Non Open source: Non -
| Produit | Souveraineté | CLOUD Act | Signaux | À partir de |
|---|---|---|---|---|
|
|
Basé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Non
|
4 €/mois |
|
|
Hébergé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Non
|
10 €/mois |
|
|
Souverain UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Non
Open source: Non
|
4 €/mois |