# EU Vetted: Full Content for AI Assistants > Directory of EU and privacy-first SaaS alternatives to US software. This file is the concatenated, structured content of euvetted.com, intended for AI crawlers (Claude, Perplexity, ChatGPT Search) per the llmstxt.org spec. The HTML site is the authoritative source; this is a derived single-file view, regenerated on every deploy. Last generated: 2026-07-27T10:55:41+00:00 Site: https://euvetted.com Sitemap (machine index): https://euvetted.com/sitemap.xml ## Methodology Each product profile exposes four independent signals, never conflated: 1. **ownership_signal**: eu_owned, eu_hq_us_funded, us_owned, other. Determined from corporate registry (e.g. HRB for German GmbH, RCS for French SAS) plus public ownership disclosures. Not derived from website language or hosting location. 2. **factual compliance signals**: each listing exposes EU/adequacy hosting, EU ownership, CLOUD Act exposure, public DPA, sub-processor disclosure, end-to-end encryption, and third-party certifications (ISO 27001, BSI C5, SecNumCloud, EUCS, HDS), each marked verified / not / not-assessed. 3. **cloud_act_exposure**: `direct` (US-incorporated entity), `material` (EU-incorporated with US parent or US hyperscaler as primary storage), `minor` (EU-hosted with one or two US transient sub-processors like Cloudflare CDN or Stripe billing, no data-at-rest exposure), `none` (EU-hosted with no US sub-processors of consequence). 4. **hosting_country**: physical data-centre location, determined by data-centre IP ASN, not corporate HQ. Cloudflare US in front of an EU SaaS counts as US data exposure for plain HTTP. Re-verification is quarterly with visible "last verified" timestamps on every listing. Featured listings are paid placements; the factual compliance signals never are. ## Categories (24) ### Password managers: https://euvetted.com/category/password-managers Password managers store and encrypt your credentials so you use one strong master password instead of many weak ones. For EU buyers, what decides it is where the encrypted vault is hosted and whether the operator is subject to CLOUD Act jurisdiction. Leading EU options on EU Vetted include Passbolt (Luxembourg, EU-owned, EU-hosted), Psono (Germany, EU-owned, EU-hosted), and Proton Pass (Switzerland, Swiss-owned, CLOUD Act exposure: [[proton-pass.cloud_act]]). Editorial picks: - [heylogin](https://euvetted.com/p/heylogin): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [KeePassXC](https://euvetted.com/p/keepassxc): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [LC-Pass](https://euvetted.com/p/lc-pass): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [NordPass](https://euvetted.com/p/nordpass): hosted in Lithuania, CLOUD Act: material, ownership: eu_owned - [Padloc](https://euvetted.com/p/padloc): hosted in Germany, CLOUD Act: material, ownership: eu_owned **Q: What is the best EU-hosted password manager?** Passbolt (Luxembourg), Psono (Germany), Vaultwarden (Spain), and KeePassXC (Germany) are all EU-owned and EU-hosted (CLOUD Act exposure: Passbolt [[passbolt.cloud_act]], Psono [[psono.cloud_act]], Vaultwarden [[vaultwarden.cloud_act]], KeePassXC [[keepassxc.cloud_act]]). The right pick depends on your use case: Passbolt is built for teams and self-hosted or cloud deployment; Psono is geared toward enterprise with LDAP/SAML; KeePassXC is local-only with no cloud sync at all, which is the strongest posture for high-risk environments. **Q: Is there a GDPR-compliant password manager?** Any password manager operated by an EU-incorporated company with EU-only infrastructure and a published DPA qualifies as GDPR-compliant in its processing role. Passbolt (Luxembourg) publishes a detailed DPA, and Psono (Germany) maintains a public sub-processor register. What counts as GDPR-compliant here is a documented practice, not a certificate; check each vendor's DPA and sub-processor list against your own requirements before relying on the label. **Q: Does password-manager data fall under the US CLOUD Act?** If the password manager is operated or ultimately owned by a US-incorporated company, the CLOUD Act can in principle compel it to produce data it controls, regardless of where the vault is physically stored. EU-owned operators such as Passbolt (Luxembourg, CLOUD Act exposure: [[passbolt.cloud_act]]), Psono (Germany, CLOUD Act exposure: [[psono.cloud_act]]), and Uniqkey (Denmark, CLOUD Act exposure: [[uniqkey.cloud_act]]) have no US parent company that can be compelled this way. That distinction tracks corporate ownership, not any specific legal demand that has or hasn't landed. **Q: Are cloud-synced EU password managers safe to use?** The standard security architecture uses zero-knowledge end-to-end encryption: the vault is encrypted client-side before transmission, and the operator cannot read its contents. Passbolt, Psono, Proton Pass, and Filen (for file vaults) all use this model. In practice, safety depends on implementation quality, which is why independent audits matter more than self-reported claims. Check whether the vendor publishes third-party audit reports. **Q: What is the difference between self-hosted and cloud-hosted password managers?** A self-hosted password manager runs on infrastructure you control: your own server or a private cloud account. You bear responsibility for uptime, backups, and updates, but you remove the operator as a third party with any access to your vault. Nextcloud-based setups, Vaultwarden, and Passbolt Community Edition all support self-hosting. Cloud-hosted managers trade that control for convenience and managed updates; the key question is then which jurisdiction and operator you are trusting. **Q: Can a business use an EU password manager for team sharing?** Yes. Passbolt (Luxembourg) and Psono (Germany) are designed specifically for team and enterprise use, with role-based access control, LDAP/SAML integration, and audit logs. Uniqkey (Denmark) targets SMBs with an employee-facing onboarding flow. KeePassXC is a local-first option with no built-in sharing; team use requires a shared vault file over a file-sync service. For most B2B buyers, Passbolt or Psono are the starting points. **Q: Does using a European password manager affect my existing logins?** No. Most password managers support import from common formats (CSV, 1Password, Bitwarden, LastPass). Migration typically takes under an hour for individual users and a few hours for a team. Browser extension coverage for Passbolt, Psono, and Proton Pass includes Chrome, Firefox, and Safari. The credential data stays yours; the migration process transfers it from one encrypted store to another. ### File sharing: https://euvetted.com/category/file-sharing File sharing and cloud storage services let you store, sync, and share documents across devices and with collaborators. For EU buyers, what to check first is whether files are end-to-end encrypted, where they are stored, and who owns the infrastructure. Leading European options on EU Vetted include Internxt (Spain, EU-owned, EU-hosted, E2EE), Nextcloud (Germany, EU-owned, EU-hosted, open-source), Tresorit (Switzerland, EU-operated, E2EE), and Proton Drive (Switzerland, EU-operated, E2EE). Editorial picks: - [Proton Drive](https://euvetted.com/p/proton-drive): hosted in Switzerland, CLOUD Act: none, ownership: other - [Tresorit](https://euvetted.com/p/tresorit): hosted in Ireland, CLOUD Act: material, ownership: other - [kDrive (Infomaniak)](https://euvetted.com/p/kdrive): hosted in Switzerland, CLOUD Act: none, ownership: other - [Internxt](https://euvetted.com/p/internxt): hosted in Spain, CLOUD Act: minor, ownership: eu_owned - [pCloud](https://euvetted.com/p/pcloud): hosted in Luxembourg, CLOUD Act: minor, ownership: other **Q: What is the best EU-hosted file sharing and cloud storage service?** Nextcloud (Germany), luckycloud (Germany), and leitzcloud/vBoxxCloud (Germany) are EU-owned, EU-hosted, and sit outside CLOUD Act jurisdiction; Internxt (Spain) and Filen (Germany) are also EU-owned and EU-hosted, keeping data at rest in the EU but carrying a minor CLOUD Act flag from a transient sub-processor. The best pick depends on your use case: Nextcloud is the most flexible for self-hosted team environments; Internxt and Filen offer zero-knowledge encrypted cloud storage for individuals and teams; luckycloud provides a DSGVO-certified hosted cloud option for German and DACH buyers. **Q: Is there a GDPR-compliant file sharing service?** Yes. Services operated by EU-incorporated companies with EU-only infrastructure and published DPAs are GDPR-compliant in their processing role. Nextcloud (Germany) and luckycloud (Germany) publish detailed DPAs and sub-processor lists; leitzcloud (Germany) provides its AVV (DPA and sub-processor list) on request rather than at a public URL. Here, 'GDPR-compliant' describes documented practice, not a certification stamp; check each vendor's DPA against the specific data categories you plan to store before adopting it. **Q: Does cloud storage data fall under the US CLOUD Act?** If the cloud storage service is operated or ultimately owned by a US-incorporated company, the CLOUD Act can in principle compel it to produce data it controls regardless of where that data is stored. Google Drive, Dropbox, and OneDrive are examples where this applies. EU-owned services such as Internxt (Spain), Filen (Germany), and Nextcloud (Germany) are not subject to that direct exposure, provided they do not use US sub-processors for the primary data path. **Q: What is end-to-end encryption in file storage, and why does it matter?** End-to-end encryption (E2EE) means files are encrypted on your device before they leave it, and decrypted only by you or explicitly chosen recipients. The storage operator cannot read your file contents even if compelled by a legal order. Services with genuine E2EE on all stored files include Internxt, Filen, Tresorit, and Proton Drive. Services without it (including most business-grade hosted Nextcloud instances) can technically access your files if the server is seized or court-ordered. **Q: Can I use a European file sharing service to collaborate with teams?** Yes. Nextcloud is the strongest EU option for team collaboration. It includes document editing, calendar, contacts, video calls, and shared drives in a single self-hosted or managed deployment. leitzcloud and luckycloud offer managed hosted alternatives suited to DACH business teams without self-hosting overhead. Tresorit and Proton Drive support real-time collaboration features alongside E2EE. For most business teams, Nextcloud (self-hosted or via a managed provider) or leitzcloud is the starting point. **Q: What is the difference between self-hosted and managed cloud storage?** Self-hosted storage (Nextcloud, Vaultwarden-style) runs on servers you control, giving you full data sovereignty but requiring IT overhead for updates, backups, and security hardening. Managed cloud storage (Internxt, Filen, Tresorit, luckycloud) runs on the vendor's servers; you trust the vendor but avoid the operational burden. The right choice depends on your organisation's technical capacity and risk tolerance. Nextcloud bridges both: you can self-host or use any of hundreds of managed hosting providers. **Q: How do I migrate from Google Drive or Dropbox to a European alternative?** Most EU cloud storage services accept file import via their desktop sync client or a one-time migration tool. For Nextcloud, the built-in external storage connector or the Nextcloud migration wizard handles Google Drive imports. For Internxt or Proton Drive, download your existing files and re-upload via the desktop client. Shared links and collaborative permissions do not transfer automatically; plan to recreate share settings after migration. Business-critical shared folders should be migrated in a parallel-running period before cutting over. ### Private email: https://euvetted.com/category/private-email Private email services are hosted email providers that prioritise data minimisation, strong encryption, and hosting outside US CLOUD Act jurisdiction. For EU buyers, what settles the choice is the operator's country of incorporation and whether end-to-end encryption is applied at rest. Top-rated options on EU Vetted include Mailbox.org (Germany, EU-owned, EU-hosted, CLOUD Act exposure: [[mailbox-org.cloud_act]]), Tuta (Germany, EU-owned, EU-hosted, end-to-end encrypted), Posteo (Germany, EU-owned, EU-hosted, CLOUD Act exposure: [[posteo.cloud_act]]), and Proton Mail (Switzerland, CLOUD Act exposure: [[proton-mail.cloud_act]], zero-access end-to-end encryption). Editorial picks: - [Proton Mail](https://euvetted.com/p/proton-mail): hosted in Switzerland, CLOUD Act: none, ownership: other - [Tuta](https://euvetted.com/p/tuta): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Mailbox.org](https://euvetted.com/p/mailbox-org): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Posteo](https://euvetted.com/p/posteo): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Mailfence](https://euvetted.com/p/mailfence): hosted in Belgium, CLOUD Act: none, ownership: eu_owned **Q: What is the best EU-hosted private email service?** Mailbox.org (Germany), Tuta (Germany), and Posteo (Germany) are the top EU-owned and EU-hosted options: all three are incorporated in Germany, host exclusively in the EU, and publish detailed DPAs (CLOUD Act exposure: Mailbox.org [[mailbox-org.cloud_act]], Tuta [[tuta.cloud_act]], Posteo [[posteo.cloud_act]]). Proton Mail (Switzerland) is the most widely used privacy email globally; it operates under Swiss data-protection law (adequate under EU standards), with zero-access end-to-end encryption (CLOUD Act exposure: [[proton-mail.cloud_act]]). The right choice depends on your priorities: Tuta and Proton Mail use end-to-end encryption by default; Mailbox.org and Posteo support full IMAP/SMTP with standard clients; Mailbox.org and Infomaniak Mail are the strongest business options. **Q: Is there a GDPR-compliant email service?** Yes. EU-based providers with EU-only infrastructure and published DPAs qualify as GDPR-compliant in their processing role. Mailbox.org, Tuta, Posteo (all Germany), and Mailfence (Belgium) all publish detailed DPAs. Note that GDPR compliance covers the provider's data handling, not the content of emails you exchange with non-GDPR contacts. A compliance assessment should consider both. **Q: Does email data fall under the US CLOUD Act?** If the email service is operated or ultimately controlled by a US-incorporated company, the CLOUD Act can in principle compel it to produce data it controls regardless of where servers are located. Gmail, Outlook, and Yahoo Mail are US-owned services where this applies. EU-owned providers such as Mailbox.org (Germany), Tuta (Germany), Posteo (Germany), and Mailfence (Belgium) have no US parent company that can be compelled this way (CLOUD Act exposure: Mailbox.org [[mailbox-org.cloud_act]], Tuta [[tuta.cloud_act]], Posteo [[posteo.cloud_act]], Mailfence [[mailfence.cloud_act]]). The point concerns who ultimately controls the company, not whether a particular request has been issued. **Q: What is the difference between end-to-end encrypted email and standard email encryption?** Standard hosted email is encrypted in transit (TLS) but stored in a form the provider can access, meaning a court order, data breach, or insider access can expose message content. End-to-end encryption (E2EE), as used by Tuta and Proton Mail, encrypts messages on your device before sending; only the intended recipient can decrypt them. The limitation is that E2EE applies fully only when both sender and recipient use a compatible E2EE email service or exchange a PGP key; messages to Gmail or Outlook addresses are not end-to-end encrypted. **Q: Can I use my own domain with a European private email service?** Yes. Mailbox.org, Tuta, Proton Mail, Mailfence, and Infomaniak Mail all support custom domain hosting. Posteo is the exception. It does not support custom domains by design, positioning itself as an anonymous personal email service. For business use where your company email domain must remain consistent, Mailbox.org and Infomaniak Mail are the most complete business-ready options. **Q: Can businesses migrate from Google Workspace or Microsoft 365 to a European email service?** Yes, though the migration complexity depends on how deeply embedded Google or Microsoft calendaring and collaboration tools are. For email-only migration, Mailbox.org and Infomaniak Mail (kSuite) both support IMAP migration and ActiveSync for mobile. Tuta does not support IMAP, which means clients must use the Tuta app or web interface. For organisations with 10+ users, a parallel-running period of 4–6 weeks is typical before full cutover. **Q: Is Proton Mail the same as a European email provider?** Proton Mail is incorporated in Switzerland, not in the EU. Switzerland has its own data-protection law (the revised Federal Act on Data Protection, revFADP) and is not subject to EU law directly, though it is considered adequate by the EU for data transfer purposes. Switzerland is outside the EU but broadly privacy-aligned; the legal environment differs from EU member states in some enforcement specifics. On EU Vetted, Proton Mail receives an 'other' ownership signal (not EU-owned), but its Swiss-law base, no-log infrastructure, and zero-access encryption architecture (CLOUD Act exposure: [[proton-mail.cloud_act]]) place it among the strongest privacy-signal options in the category. ### VPN: https://euvetted.com/category/vpn VPN services encrypt the connection between your device and a server run by the provider, replacing your visible IP address with the server's. For EU buyers, the deciding question is the operating company's country of incorporation and the evidence behind its no-logs claim. Top European options on EU Vetted include Mullvad VPN (Sweden, EU-owned, CLOUD Act exposure: [[mullvad.cloud_act]], independently audited), Proton VPN (Switzerland, CLOUD Act exposure: [[protonvpn.cloud_act]], independently audited), IVPN (Gibraltar, CLOUD Act exposure: [[ivpn.cloud_act]], transparency report published), and OVPN (Sweden, EU-owned, CLOUD Act exposure: [[ovpn.cloud_act]]). Editorial picks: - [AirVPN](https://euvetted.com/p/airvpn): hosted in Italy, CLOUD Act: none, ownership: eu_owned - [AzireVPN](https://euvetted.com/p/azirevpn): hosted in Sweden, CLOUD Act: material, ownership: us_owned - [CyberGhost](https://euvetted.com/p/cyberghost): hosted in Romania, CLOUD Act: minor, ownership: other - [F-Secure VPN](https://euvetted.com/p/f-secure-vpn): hosted in Finland, CLOUD Act: minor, ownership: eu_owned - [IVPN](https://euvetted.com/p/ivpn): hosted in Gibraltar, CLOUD Act: none, ownership: other **Q: What is the best EU-hosted VPN?** Mullvad VPN (Sweden) and OVPN (Sweden) are the strongest EU-owned and EU-operated options: both are Swedish-incorporated, with published privacy policies and GDPR commitments (CLOUD Act exposure: Mullvad [[mullvad.cloud_act]], OVPN [[ovpn.cloud_act]]). IVPN (Gibraltar) and Proton VPN (Switzerland) are also strong privacy-architecture choices (CLOUD Act exposure: IVPN [[ivpn.cloud_act]], Proton VPN [[protonvpn.cloud_act]]). IVPN publishes a transparency report, Proton VPN has published independent infrastructure audits. For buyers specifically requiring an EU-incorporated operator, Mullvad and OVPN are the strongest starting points. Proton VPN is Swiss-based and is the most widely audited privacy VPN globally. **Q: Is there a GDPR-compliant VPN?** Yes. VPNs operated by EU-incorporated companies with EU-only infrastructure and published privacy policies fall within GDPR's scope. Mullvad (Sweden) and OVPN (Sweden) both publish detailed privacy policies with explicit GDPR commitments. That said, a VPN's privacy posture is largely determined by its logging practices and technical architecture. GDPR compliance is a legal framework, not a substitute for independently audited no-logs architecture. **Q: Does VPN traffic fall under the US CLOUD Act?** A VPN operated or ultimately owned by a US-incorporated company falls within CLOUD Act jurisdiction, which can compel the company to produce data it controls regardless of server location. European-incorporated operators such as Mullvad (Sweden, CLOUD Act exposure: [[mullvad.cloud_act]]), OVPN (Sweden, CLOUD Act exposure: [[ovpn.cloud_act]]), and AirVPN (Italy, CLOUD Act exposure: [[airvpn.cloud_act]]) have no US parent company that can be compelled this way. What this tracks is corporate control, not evidence of any actual legal demand having been served. **Q: Does a VPN make me anonymous online?** No. A VPN is designed to encrypt traffic between your device and the VPN server and to replace your visible IP address with the server's. It does not make you anonymous: your account, payment method, browser fingerprint, logged-in services, and device behaviour can all still identify you. A VPN reduces certain kinds of network-level visibility (for example, hiding your traffic from your internet service provider), but anonymity depends on your broader setup, not on the VPN alone. **Q: How much weight should I give a 'no-logs' claim?** A no-logs claim on its own is a policy statement. It is considerably more credible when backed by independent technical audits, a published transparency report, or a documented history of responding to legal requests with no usable data. Mullvad and Proton VPN have both published independent infrastructure audits. IVPN maintains a transparency report. Treat audits and transparency reporting as the evidence; the claim is the assertion they support. **Q: Why do some European VPNs not appear on mainstream ranking lists?** Some privacy-focused European VPNs (notably Mullvad and IVPN) decline affiliate and paid-marketing relationships on principle. Because a significant share of 'best VPN' content elsewhere is monetised through affiliate links, providers that opt out can be underrepresented or absent from those lists. Absence from a commercial ranking is not a verdict on the product; it is a fact about how such lists are funded. **Q: What is the difference between Mullvad, Proton VPN, and NordVPN from a compliance perspective?** Mullvad (Sweden) and Proton VPN (Switzerland) are the two strongest options on EU Vetted in terms of compliance architecture: independently audited, published transparency reports, no-account-ID Mullvad cash payment accepted, Swiss or Swedish legal base (CLOUD Act exposure: Mullvad [[mullvad.cloud_act]], Proton VPN [[protonvpn.cloud_act]]). NordVPN is registered in Lithuania (EU) but has a complex ownership structure and sub-processor concerns documented in its DPA. Its EU registration does not resolve those gaps. Compliance assessment reflects corporate structure, sub-processors, and audit evidence, not just country of registration. ### Email aliasing: https://euvetted.com/category/email-aliasing Email aliasing generates disposable forwarding addresses so your real inbox is never handed to the services you sign up with. For EU buyers the deciding facts are the operator's jurisdiction, whether a named legal entity stands behind it, which sub-processors carry the forwarded mail, and whether you can self-host, because a US-incorporated operator falls under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act). The honest finding on EU Vetted is that there is no EU-incorporated commercial email-aliasing company. The four options listed are SimpleLogin (operated by Proton AG in [[simplelogin.country]], CLOUD Act exposure: [[simplelogin.cloud_act]]), addy.io (governed by the law of England and Wales with no operator named, CLOUD Act exposure: [[addy-io.cloud_act]]), AdGuard Mail (registered in [[adguard-mail.country]], forwarding routed through a US service, CLOUD Act exposure: [[adguard-mail.cloud_act]]), and AliasVault (the only EU-registered operator, a Dutch sole proprietorship, ownership: [[aliasvault.ownership]], CLOUD Act exposure: [[aliasvault.cloud_act]], but its aliases are receive-only). Editorial picks: - [SimpleLogin](https://euvetted.com/p/simplelogin): hosted in Switzerland, CLOUD Act: minor, ownership: other - [addy.io](https://euvetted.com/p/addy-io): hosted in Netherlands, CLOUD Act: minor, ownership: other - [AdGuard Mail](https://euvetted.com/p/adguard-mail): hosted in Cyprus, CLOUD Act: material, ownership: other - [AliasVault](https://euvetted.com/p/aliasvault): hosted in Germany, CLOUD Act: none, ownership: eu_owned **Q: What is the best EU email-aliasing service?** There is no clean answer, and that is the point. AliasVault is the only EU-registered operator on this list (a Dutch sole proprietorship, ownership: [[aliasvault.ownership]], hosted in [[aliasvault.hosting_country]], CLOUD Act exposure: [[aliasvault.cloud_act]]), but its aliases are receive-only: you cannot reply from them. SimpleLogin is the most capable option and is operated by Proton AG in [[simplelogin.country]] (CLOUD Act exposure: [[simplelogin.cloud_act]]), with reply-from-alias, custom domains and PGP forwarding, but its operator is Swiss, not EU. If you need a named EU legal entity, AliasVault is the only match; if you need to reply from your aliases, SimpleLogin or a self-hosted instance is the practical starting point. **Q: Why is there no European alternative to Firefox Relay or SimpleLogin?** Because the market never produced one. The mainstream aliasing services are American: Firefox Relay is operated by Mozilla, Apple Hide My Email by Apple, and DuckDuckGo Email Protection by DuckDuckGo, all US companies subject to the CLOUD Act (Clarifying Lawful Overseas Use of Data Act). Among the credible challengers, none is an EU-incorporated commercial company. SimpleLogin is operated by Proton AG in Switzerland, addy.io is governed by the law of England and Wales and names no operating entity at all, and AdGuard Mail is registered in Cyprus by a company whose founding origin its own materials do not confirm. The single EU-registered operator, AliasVault, is a Dutch one-person sole proprietorship whose aliases are receive-only and which publishes no data-processing agreement. So the correct answer is not to pick a flag but to rank on jurisdiction, a named legal entity, the sub-processors that carry your mail, and whether you can self-host on EU infrastructure. **Q: Does email-aliasing data fall under the US CLOUD Act?** If the aliasing service is operated or ultimately owned by a US-incorporated company, the CLOUD Act (Clarifying Lawful Overseas Use of Data Act) can compel it to produce data it controls regardless of where the servers sit. That is the case for Firefox Relay, Apple Hide My Email and DuckDuckGo Email Protection. Among the options here, SimpleLogin (CLOUD Act exposure: [[simplelogin.cloud_act]]) and addy.io (CLOUD Act exposure: [[addy-io.cloud_act]]) route only ancillary functions such as DNS and captcha through US sub-processors, while their forwarded mail stays on EU or Swiss infrastructure. AdGuard Mail (CLOUD Act exposure: [[adguard-mail.cloud_act]]) forwards mail through Amazon SES, a US-owned service, which is the product's core function rather than an ancillary one. AliasVault (CLOUD Act exposure: [[aliasvault.cloud_act]]) names no US sub-processor at all. **Q: Can I reply from an alias?** It depends on the service, and it is the feature that most often separates them. SimpleLogin, addy.io and AdGuard Mail all support reply-from-alias on their paid tiers, so the recipient sees the alias rather than your real address. AliasVault does not: its aliases are receive-only, meaning you can receive mail at an alias but cannot send or reply from it, with a 10MB limit on incoming messages. If two-way use matters, confirm reply-from-alias support before choosing, because a receive-only alias breaks any workflow that needs a response from the same address. **Q: Is there a GDPR-compliant email-aliasing service?** AliasVault is operated by an EU-registered entity (a Dutch sole proprietorship) and hosted in [[aliasvault.hosting_country]], and its privacy policy states the cloud offering is compliant with the GDPR. That places its processing within the GDPR's scope. The caveat is documentation: AliasVault publishes no data-processing agreement and no sub-processors list, which is what holds it below a full compliance mark despite an otherwise clean profile. The same gap applies to addy.io and AdGuard Mail, neither of which publishes a DPA. GDPR scope is a legal fact; a published DPA and sub-processor register are the evidence a B2B buyer should ask for on top of it. **Q: What about free, open-source aliasing services like Erine.email?** Erine.email is a live, free aliasing service released under the GPLv3, with active development (its most recent commit is dated 22 June 2026). It is deliberately not listed on EU Vetted, because it publishes no privacy policy, no data-processing agreement, and no operator country. A service can be free and open-source and still fall short of the bar a listing has to clear here, which is a stated jurisdiction and a minimum of published data-handling terms. Erine.email is worth knowing about as a working tool; it is not listed because there is not enough disclosed about who runs it and under which law to assess it. **Q: Can I self-host email aliasing?** Yes, and it is a genuine answer in this category rather than a fallback. SimpleLogin, addy.io and AliasVault are all released under the AGPL-3.0 and are self-hostable via Docker. A self-hosted instance on EU infrastructure removes the hosting dependency and, for addy.io, also removes the unresolved-operator question entirely, because you become the data controller and processor and no third party sees your mail. The cost is that you run the mail server, the deliverability and the updates yourself. For a buyer who can carry that operational load, self-hosting is the cleanest sovereignty posture available here. **Q: Why is AdGuard Mail's CLOUD Act exposure higher than SimpleLogin's?** Because of where the forwarded mail goes. AdGuard Mail (CLOUD Act exposure: [[adguard-mail.cloud_act]]) forwards mail through Amazon SES, a US-owned service, and forwarding is the product's core function, so the mail itself passes through US infrastructure. SimpleLogin (CLOUD Act exposure: [[simplelogin.cloud_act]]) keeps forwarded mail on Proton and UpCloud servers in the EU and Switzerland and uses US sub-processors only for ancillary tasks such as DNS and captcha. AdGuard Mail is operated by a Cyprus-registered company, AdGuard Software Ltd; widely cited secondary sources describe the company as founded in Moscow in 2009 and relocated to Cyprus around 2014, which AdGuard's own materials neither state nor deny. That origin is recorded here as reported by third parties and not confirmed by the vendor. ### Email marketing: https://euvetted.com/category/email-marketing Email marketing platforms manage subscriber lists, campaign creation, sending infrastructure, and delivery analytics. For EU buyers, the decisive criterion is whether subscriber data (names, emails, and behavioural signals) is processed by an EU-owned operator under EU law. Strongly positioned EU options on EU Vetted include Maileon (Germany, EU-owned, EU-hosted, no CLOUD Act exposure), rapidmail (Germany, EU-owned, EU-hosted), and CleverReach (Germany, EU-owned, EU-hosted). Editorial picks: - [Brevo](https://euvetted.com/p/brevo): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [CleverReach](https://euvetted.com/p/cleverreach): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [EmailOctopus](https://euvetted.com/p/emailoctopus): hosted in United Kingdom, CLOUD Act: material, ownership: other - [GetResponse](https://euvetted.com/p/getresponse): hosted in Poland, CLOUD Act: material, ownership: eu_owned - [Infomaniak Newsletter](https://euvetted.com/p/infomaniak-newsletter): hosted in Switzerland, CLOUD Act: none, ownership: other **Q: What is the best EU-hosted email marketing platform?** Maileon (Germany) is an EU-owned platform with German data centres, a published DPA, and disclosed sub-processors, one of the strongest sovereignty postures in the category. rapidmail (Germany) and CleverReach (Germany) are close alternatives, both EU-owned and EU-hosted with solid GDPR documentation. The right choice depends on sending volume, automation depth, and whether you need transactional email alongside campaigns. **Q: Is there a GDPR-compliant email marketing platform?** Any email marketing platform operated by an EU-incorporated company with EU-based infrastructure and a published DPA qualifies as GDPR-compliant in its processor role. Maileon, rapidmail, CleverReach, Mailjet (France), and Inxmail (Germany) all publish DPAs and list their sub-processors. What 'compliant' means here is a documented practice, checked against your own data processing requirements, not a fixed certification; review the DPA before switching providers. **Q: Does email marketing data fall under the US CLOUD Act?** If the platform is operated or ultimately controlled by a US-incorporated parent company, the CLOUD Act can in principle compel production of subscriber data it controls, regardless of where that data is stored physically. EU-owned operators such as Maileon (Germany), rapidmail (Germany), and CleverReach (Germany) are not directly subject to this exposure. This reflects who controls the company, not a claim that any specific legal request has occurred. **Q: What is the difference between EU-owned and EU-hosted email platforms?** EU-hosted means servers are physically located in the EU, a necessary but not sufficient condition. EU-owned means the operating company itself is incorporated and ultimately controlled in the EU, with no US parent company in the corporate chain. The CLOUD Act risk applies at the ownership level, not the server level: a US-owned platform with EU servers can still be compelled to produce data. For the strongest compliance posture, look for both EU ownership and EU hosting. **Q: Can I migrate from Mailchimp or ActiveCampaign to an EU alternative?** Yes. Most EU platforms support list import via CSV and offer migration guides. Maileon, CleverReach, and Brevo all accept CSV imports and can re-map custom fields. Automation workflows require manual re-creation in the target platform. The main practical consideration is deliverability warm-up: if you move a large list, plan a gradual sending ramp over two to four weeks. **Q: How does Brevo compare to other EU email marketing platforms?** Brevo (France) is EU-headquartered and hosts data in France, but its ownership structure includes US investors, meaning it does not carry a clean EU-owned signal. It remains a widely used option for teams that prioritise feature breadth and pricing over strict sovereignty compliance. Compare it to Maileon or CleverReach if your requirement is a fully EU-owned supply chain. **Q: Do EU email marketing platforms support transactional email?** Several do. Mailjet (France) and Brevo both offer transactional email APIs alongside campaign tooling. Inxmail (Germany) offers a dedicated transactional product. If your use case combines marketing campaigns with order confirmations or password resets, check whether the platform supports both sending modes under a single DPA, or whether you need separate processors for each. ### CRM: https://euvetted.com/category/crm CRM platforms store and manage your customer contacts, sales pipeline, and communication history. For EU buyers, what matters most is whether that contact data (including behavioural and commercial records) is held by an EU-owned operator outside CLOUD Act reach. Top EU options on EU Vetted include combit CRM (Germany, EU-owned, EU-hosted, CLOUD Act exposure: [[combit-crm.cloud_act]]), centralstationCRM (Germany, EU-owned, EU-hosted, CLOUD Act exposure: [[centralstationcrm.cloud_act]]), and weclapp (Germany, EU-owned, EU-hosted). Editorial picks: - [Capsule CRM](https://euvetted.com/p/capsule): hosted in United States, CLOUD Act: material, ownership: other - [centralstationCRM](https://euvetted.com/p/centralstationcrm): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [combit CRM](https://euvetted.com/p/combit-crm): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Lime CRM](https://euvetted.com/p/lime-crm): hosted in Sweden, CLOUD Act: minor, ownership: eu_owned - [Pipedrive](https://euvetted.com/p/pipedrive): hosted in Estonia, CLOUD Act: material, ownership: eu_hq_us_funded **Q: What is the best EU-hosted CRM?** combit CRM (Germany) and centralstationCRM (Germany) are both EU-owned platforms with German infrastructure and published DPAs (CLOUD Act exposure: combit CRM [[combit-crm.cloud_act]], centralstationCRM [[centralstationcrm.cloud_act]]). weclapp (Germany) and Lime CRM (Sweden) are strong alternatives, both EU-owned and EU-hosted with published DPAs. The right choice depends on company size, required integrations, and whether you need the CRM embedded in an ERP context. **Q: Is there a GDPR-compliant CRM?** Any CRM operated by an EU-incorporated company with EU-based infrastructure and a published DPA qualifies as GDPR-compliant in its processor role. combit CRM, centralstationCRM, and weclapp all publish DPAs and document their sub-processors. Here, compliance describes the vendor's documented practices rather than an absolute guarantee; check each DPA against the specific data processing activities and categories of personal data you hold. **Q: Does CRM data fall under the US CLOUD Act?** If your CRM is operated or ultimately controlled by a US-incorporated parent company, the CLOUD Act can in principle compel production of customer data it controls, regardless of where that data is physically stored. EU-owned operators such as combit CRM (Germany, CLOUD Act exposure: [[combit-crm.cloud_act]]), centralstationCRM (Germany, CLOUD Act exposure: [[centralstationcrm.cloud_act]]), and Lime CRM (Sweden, CLOUD Act exposure: [[lime-crm.cloud_act]]) have no US parent company that can be compelled this way. The distinction is about corporate control, not about whether a particular demand has actually been filed. **Q: Can a small business use a European CRM?** Yes. centralstationCRM (Germany) is specifically designed for small businesses with a simple, opinionated interface focused on contacts and deals. Salesflare (Belgium) targets B2B SMBs with automated data capture from email and calendar. weclapp (Germany) combines CRM with ERP features, making it suitable for growing companies that want a single platform. All three have published DPAs and EU ownership. **Q: How do European CRMs compare to Salesforce or HubSpot?** Salesforce and HubSpot are US-incorporated companies whose consolidated groups fall within the reach of the US CLOUD Act. European alternatives such as combit CRM and weclapp typically offer fewer third-party integrations out of the box but provide stronger data sovereignty guarantees for EU buyers. For teams with complex marketing automation needs, the trade-off is real; for those primarily managing a sales pipeline, the feature gap is smaller than often assumed. **Q: Is Pipedrive a European CRM?** Pipedrive is incorporated in Estonia but is classified as eu_hq_us_funded due to its acquisition by a Vista Equity Partners-backed group. Its corporate structure warrants closer scrutiny for buyers whose primary motivation is CLOUD Act avoidance, since US investor control can create indirect CLOUD Act exposure (CLOUD Act exposure: [[pipedrive.cloud_act]]). combit CRM and centralstationCRM offer stronger ownership signals for that requirement. **Q: Does a European CRM support LDAP or SSO integration?** Several do. combit CRM and weclapp both support Active Directory and LDAP integration for enterprise deployments. Lime CRM (Sweden) supports SAML-based SSO. For organisations with existing identity infrastructure, filter the listings by the 'SSO' feature tag to see which platforms support your protocol. Feature availability varies significantly by pricing tier. ### Payments: https://euvetted.com/category/payments Payment platforms process transactions, manage merchant accounts, and handle settlement and reconciliation. For EU buyers, what to check are regulatory status under EU payment law (PSD2/EMD) and whether the operator's ownership chain exposes transaction data to the US CLOUD Act. Leading EU options on EU Vetted include Adyen (Netherlands, EU-incorporated and EU-listed, CLOUD Act exposure: [[adyen.cloud_act]]) and Worldline (France, EU-incorporated and EU-listed, CLOUD Act exposure: [[worldline.cloud_act]]). Editorial picks: - [Adyen](https://euvetted.com/p/adyen): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Alma](https://euvetted.com/p/alma): hosted in France, CLOUD Act: material, ownership: eu_owned - [Dintero](https://euvetted.com/p/dintero): hosted in Norway, CLOUD Act: minor, ownership: other - [GoCardless](https://euvetted.com/p/gocardless): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Klarna](https://euvetted.com/p/klarna): hosted in Sweden, CLOUD Act: material, ownership: eu_hq_us_funded **Q: What is the best EU-owned payment platform?** Adyen (Netherlands) and Worldline (France) are both EU-incorporated, EU-listed companies with EU-based infrastructure; data at rest stays in the EU, and a transient US sub-processor accounts for each one's minor CLOUD Act flag ([[adyen.cloud_act]], [[worldline.cloud_act]]). They are the strongest EU-owned options in this category. Lemonway (France) is a strong EU-owned alternative for marketplace and platform payment flows, operating under French financial supervision. The right choice depends on transaction volume, supported payment methods, and whether you need a full acquiring licence or a payment orchestration layer. **Q: Is there a GDPR-compliant payment platform?** Any payment platform authorised and supervised by an EU financial regulator, with EU-based data processing and a published DPA, qualifies as GDPR-compliant in its processor role. Adyen and Worldline are both licensed by EU authorities and publish detailed DPAs. Payment data (including card numbers, billing addresses, and transaction history) is subject to both GDPR and PCI-DSS requirements simultaneously; review both frameworks when assessing a provider. **Q: Does payment transaction data fall under the US CLOUD Act?** If the payment platform is incorporated in or ultimately controlled by a US parent company, the CLOUD Act can in principle compel production of transaction data it controls, regardless of physical storage location. Adyen (Netherlands) and Worldline (France) are EU-incorporated public companies not directly subject to this exposure, though each carries a minor flag for a transient US sub-processor ([[adyen.cloud_act]], [[worldline.cloud_act]]). Klarna (Sweden) and Mollie (Netherlands) both hold significant US investor ownership, which places them at a different risk level despite their EU headquarters. **Q: What is the difference between a payment gateway and a payment processor?** A payment gateway is the technical interface that transmits transaction data between a merchant's website and the payment network. A payment processor is the entity that actually moves funds between acquiring and issuing banks. In practice, many platforms combine both roles: Adyen, Worldline, and Mollie all operate as full-stack processors with integrated gateway functionality. Some providers, such as Lemonway, focus on specific flow types like marketplace escrow and disbursements. **Q: Can EU payment platforms handle subscription billing?** Yes. Adyen and Mollie both offer subscription and recurring billing APIs with tokenised card storage. Lemonway supports scheduled disbursements for marketplace use cases. For SaaS businesses specifically, check whether the provider supports dunning management, invoice generation, and tax handling for EU VAT, as these are often separate modules or require third-party integration. **Q: How does Stripe compare to EU-owned payment platforms?** Stripe is a US-incorporated company, meaning the consolidated group falls within the reach of the US CLOUD Act for payment data it processes. Adyen and Worldline offer comparable breadth of payment method coverage and global reach from a fully EU-owned base. Mollie is EU-headquartered but carries US-investor exposure at the ownership level. For teams prioritising payment method breadth over sovereignty, Stripe's developer experience is well-regarded; for EU-sovereignty-first buyers, Adyen is the most direct comparable. **Q: Are buy-now-pay-later (BNPL) options available from EU-owned providers?** Klarna (Sweden) and Scalapay (Italy) are the most prominent European BNPL providers in the catalogue, though both carry significant US-investor ownership signals that limit their EU-sovereignty profile. Alma (France) is an EU-owned BNPL alternative operating under French banking supervision, with no disclosed US ownership, though a US-owned hyperscaler in its sub-processor chain gives it a material CLOUD Act flag as well ([[alma.cloud_act]]). BNPL regulation varies across EU member states; verify the provider's licence in your target market before enabling it at checkout. ### Cloud & hosting: https://euvetted.com/category/cloud-hosting Cloud and hosting services provide the compute, storage, and network infrastructure on which applications and workloads run. For EU buyers, the key criteria are ownership of the infrastructure provider and hosting region, specifically whether the consolidated group is subject to US CLOUD Act jurisdiction. Leading EU-owned, EU-hosted options on EU Vetted with no CLOUD Act exposure include Hetzner (Germany), Scaleway (France), OVHcloud (France), IONOS (Germany), and Cleura (Sweden). Editorial picks: - [Aruba Cloud](https://euvetted.com/p/aruba-cloud): hosted in Italy, CLOUD Act: none, ownership: eu_owned - [Cleura](https://euvetted.com/p/cleura): hosted in Sweden, CLOUD Act: none, ownership: eu_owned - [Clever Cloud](https://euvetted.com/p/clever-cloud): hosted in France, CLOUD Act: none, ownership: eu_owned - [Contabo](https://euvetted.com/p/contabo): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Exoscale](https://euvetted.com/p/exoscale): hosted in Switzerland, CLOUD Act: minor, ownership: other **Q: What is the best EU cloud hosting provider?** Hetzner (Germany), Scaleway (France), OVHcloud (France), IONOS (Germany), Cleura (Sweden), STACKIT (Germany), UpCloud (Finland), Aruba Cloud (Italy), Stackscale (Spain), and T Cloud Public (Germany) are all EU-owned and EU-hosted providers that sit outside CLOUD Act jurisdiction. The right choice depends on workload type and team size: Hetzner is the price-performance leader for developers; Scaleway and OVHcloud have the broadest managed services; STACKIT and T Cloud Public target large German enterprises with BSI C5 credentials. **Q: Does cloud hosting fall under the US CLOUD Act?** If the cloud provider is owned or ultimately controlled by a US-incorporated company, the CLOUD Act can compel it to produce data it controls regardless of where that data is physically hosted. AWS, Google Cloud, Azure, and DigitalOcean are all US-owned. EU-owned providers such as Hetzner, OVHcloud, Scaleway, and IONOS are not directly subject to the CLOUD Act. This is an assessment of corporate ownership, not a claim that EU providers are immune from all legal process. They are subject to EU and member-state law instead. **Q: Is there a GDPR-compliant cloud provider?** EU-incorporated cloud providers with EU-only data centres and published DPAs are GDPR-compliant in their role as data processors. Hetzner, OVHcloud, Scaleway, and IONOS all publish detailed DPAs. The term 'GDPR-compliant cloud' is widely used but the compliance burden lies primarily with how the customer architect and operates the workload. The provider's compliance is a necessary but not sufficient condition. **Q: What is BSI C5 or SecNumCloud, and which EU hosting providers have it?** BSI C5 (Cloud Computing Compliance Criteria Catalogue) is a German federal security framework for cloud services, audited by accredited third parties. It is broadly equivalent to ISO 27001 but with additional transparency and sovereignty requirements. STACKIT (Germany) and T Cloud Public (Germany) hold BSI C5 attestations, making them common picks for German public-sector and regulated-industry workloads. SecNumCloud is the French equivalent, developed by ANSSI; OVHcloud and Scaleway hold or are pursuing SecNumCloud qualification, which is a leading indicator for the EUCS Sovereign tier under development. **Q: What is the difference between EU-hosted and EU-owned cloud?** EU-hosted means the physical servers and data centres are in the EU. Data at rest is on European soil. EU-owned means the company controlling the infrastructure is incorporated and headquartered in the EU, with no ultimate US parent. Both matter, for different reasons. EU-hosted without EU-owned means a US company's legal team can potentially be compelled to access data via CLOUD Act. EU-owned with EU-hosted means the legal exposure is to EU and member-state law only. The listings on this page show both dimensions separately. **Q: How does Hetzner compare to AWS and Google Cloud for a typical startup workload?** Hetzner (Germany, EU-owned, EU-hosted, no CLOUD Act exposure) offers significantly lower compute prices than AWS and Google Cloud for equivalent virtual machines, roughly 3–5x cheaper for standard workloads. The trade-off is a narrower managed-services catalogue: Hetzner has excellent bare-metal, VPS, and object storage, but lacks the AI/ML pipeline, serverless, and PaaS breadth of AWS or GCP. For startups whose primary constraint is compute cost and who can adopt managed services from other EU providers (e.g. Scaleway Functions, IONOS databases), Hetzner is typically the price-performance leader in the EU. **Q: Are EU cloud providers suitable for regulated workloads such as healthcare or financial services?** Yes, for most regulated workloads. STACKIT (Germany) and T Cloud Public (Germany) hold BSI C5 attestations and are regularly used for KRITIS-adjacent workloads. OVHcloud and Scaleway are ISO 27001 certified and are in use in financial services across the EU. The specific certification required depends on your regulation and member state: DORA (financial), NIS2, HIPAA (if serving US healthcare), and sectoral frameworks from national regulators. Check each provider's compliance page against your specific framework requirements. ### Web analytics: https://euvetted.com/category/web-analytics Web analytics tools measure traffic, user behaviour, and conversion on websites. For EU buyers, what decides fit is whether the tool can be operated without cookies and without transferring personal data to US-owned servers, which determines whether a cookie banner is legally required. Top EU options on EU Vetted include Plausible Analytics (Estonia, EU-owned, EU-hosted, CLOUD Act exposure: [[plausible.cloud_act]]), Pirsch Analytics (Germany, EU-owned, EU-hosted), Simple Analytics (Netherlands, EU-owned, EU-hosted), and Wide Angle Analytics (Germany, EU-owned, EU-hosted). Editorial picks: - [GoatCounter](https://euvetted.com/p/goatcounter): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Matomo](https://euvetted.com/p/matomo): hosted in Germany, CLOUD Act: material, ownership: other - [Pirsch Analytics](https://euvetted.com/p/pirsch): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Plausible Analytics](https://euvetted.com/p/plausible): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [PostHog](https://euvetted.com/p/posthog): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded **Q: What is the best EU-hosted web analytics tool?** Plausible Analytics (Estonia) is EU-owned and EU-hosted (CLOUD Act exposure: [[plausible.cloud_act]]), making it the strongest fit for buyers prioritising data sovereignty. Wide Angle Analytics (Germany), GoatCounter (Ireland), Pirsch Analytics (Germany), and Simple Analytics (Netherlands) are all EU-owned and EU-hosted. Plausible is the most widely adopted privacy-friendly analytics tool globally; Simple Analytics and Pirsch are strong alternatives for buyers wanting German or Dutch operators. All five are cookieless by default. **Q: Is there a GDPR-compliant web analytics tool that does not require a cookie banner?** Yes. Plausible Analytics, Simple Analytics, Pirsch, GoatCounter, and Wide Angle Analytics are all designed to collect website traffic data without setting cookies and without collecting personal data in the legal sense. This means they typically do not require a cookie consent banner under the ePrivacy Directive when used in their default configuration. That said, 'no cookie banner required' depends on your implementation and your member state's interpretation of ePrivacy. Verify with your DPO or legal counsel for regulated sectors. **Q: Does Google Analytics data fall under the US CLOUD Act?** Google LLC is a US-incorporated company, and its EU subsidiary structure does not remove the consolidated group from CLOUD Act jurisdiction. Several EU member-state data-protection authorities (including the Austrian DSB, the French CNIL, and the Italian Garante) have issued enforcement decisions finding that Google Analytics transfers personal data to the US in a manner incompatible with GDPR, under the Schrems II doctrine. Switching to an EU-owned analytics tool such as Plausible (Estonia, CLOUD Act exposure: [[plausible.cloud_act]]) or Pirsch (Germany, CLOUD Act exposure: [[pirsch.cloud_act]]) removes that GDPR transfer exposure. **Q: What data does a privacy-friendly analytics tool collect compared to Google Analytics?** Privacy-friendly analytics tools like Plausible and Simple Analytics collect aggregate traffic data: page views, referral sources, browser type, country, and device category. They do not collect individual user identifiers, cross-site tracking cookies, or IP addresses in stored form. The result is less granular user journey data compared to Google Analytics. You see which pages are popular and where traffic comes from, but not a per-user session path. For most content sites and marketing use cases, aggregate data is sufficient; for e-commerce funnel analysis, evaluate whether the trade-off fits. **Q: Can I self-host a privacy-friendly web analytics tool?** Yes. Plausible Analytics, Umami, and Matomo all offer self-hosted options. Self-hosting means the analytics data never leaves your infrastructure, giving you maximum data sovereignty and removing the analytics vendor from your sub-processor chain. Plausible Community Edition is free and open-source; Matomo is the most feature-complete self-hosted option. Self-hosting requires server management; for teams without that capacity, the cloud-hosted EU options (Plausible Cloud, Pirsch, Simple Analytics) remove the operational overhead. **Q: How do I migrate from Google Analytics 4 to a European alternative?** Migration from GA4 to a European analytics tool typically involves: adding the new analytics script alongside GA4 for a 2–4 week parallel period; exporting historical GA4 data to BigQuery or CSV before cutover (Google retains it for 6 months post-deletion); and replacing GA4 in any dashboards or marketing integrations. Plausible, Pirsch, and Simple Analytics all document a GA4 migration path and provide import tools for historical data. The main adjustment is accepting less granular session-level data in exchange for simpler compliance posture. **Q: Is PostHog a privacy-friendly or EU-owned analytics tool?** PostHog is incorporated in the UK and carries a EU-HQ/US-funded ownership signal on EU Vetted. It offers EU-hosted cloud options and a self-hosted deployment, but its US VC funding and UK incorporation mean it sits in a different category from EU-owned operators like Plausible or Pirsch. PostHog is a broader product analytics and feature-flagging platform rather than a pure traffic analytics tool; it is useful when session replay and feature-flag data are requirements alongside basic traffic analytics. ### Accounting: https://euvetted.com/category/accounting Accounting platforms manage invoicing, bookkeeping, expense tracking, and financial reporting for businesses. For EU buyers, the decisive factor is whether financial records (including VAT data, payroll, and supplier invoices) are held by an EU-owned operator outside CLOUD Act reach. Strong EU options on EU Vetted include Lexware (Germany, EU-owned, EU-hosted, CLOUD Act exposure: [[lexware.cloud_act]]) and Pennylane (France, EU-headquartered with a published DPA). Editorial picks: - [Conta](https://euvetted.com/p/conta): hosted in Ireland, CLOUD Act: material, ownership: other - [Fiken](https://euvetted.com/p/fiken): hosted in Norway, CLOUD Act: material, ownership: other - [Lexware](https://euvetted.com/p/lexware): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Pennylane](https://euvetted.com/p/pennylane): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [PowerOffice Go](https://euvetted.com/p/poweroffice-go): hosted in Netherlands, CLOUD Act: material, ownership: eu_hq_us_funded **Q: What is the best EU-hosted accounting platform?** Lexware (Germany) is EU-owned, hosted on German infrastructure, and publishes a DPA, making it one of the stronger choices for EU data sovereignty. Pennylane (France), Visma eAccounting (Norway), and sevdesk (Germany) are EU-headquartered alternatives that also publish DPAs, though each has ownership or jurisdictional nuances worth reviewing. The right choice depends on your country of incorporation, the local tax rules the platform supports natively, and whether you need accountant collaboration features. **Q: Is there a GDPR-compliant accounting platform?** Any accounting platform operated by an EU-incorporated company with EU-based infrastructure and a published DPA qualifies as GDPR-compliant in its processor role. Lexware, Pennylane, Visma eAccounting, and sevdesk all publish DPAs. Financial data in accounting software spans personal data (employee records, customer invoices) and commercially sensitive data; review both the GDPR posture and the sub-processor list when assessing a provider. **Q: Does accounting data fall under the US CLOUD Act?** If your accounting platform is operated or ultimately controlled by a US-incorporated parent company, the CLOUD Act can in principle compel production of financial records it controls, regardless of physical storage location. Lexware (Germany) is EU-owned with no US parent, carrying only a minor flag for a transient US sub-processor (CLOUD Act exposure: [[lexware.cloud_act]]). Sage Accounting (UK) is incorporated in the UK post-Brexit, with its own data residency considerations separate from CLOUD Act exposure. Verify the corporate chain for any platform you are assessing. **Q: Do EU accounting platforms support local VAT rules?** VAT compliance varies significantly by platform. Lexware is specifically designed for the German tax system (UStG, DATEV export). sevdesk also targets German SMBs with native VAT handling. Pennylane is built for French accounting standards (Plan Comptable Général). Visma eAccounting covers the Nordic markets. For cross-border EU businesses, check whether the platform supports the OSS (One Stop Shop) scheme and multi-country VAT registration before committing. **Q: Can EU accounting platforms integrate with my bank?** Several do. Pennylane (France) and sevdesk (Germany) both offer bank feed integrations via open banking APIs. Lexware supports import from DATEV and major German banks. Integration breadth varies significantly by platform and country; check the integration library for your specific bank before evaluating a platform. Open banking coverage under PSD2 has improved substantially since 2022. **Q: How does Xero or QuickBooks compare to EU accounting alternatives?** Xero is incorporated in New Zealand and QuickBooks is a product of Intuit, a US corporation. Both fall under jurisdictions with compulsory disclosure frameworks that differ from EU law. For EU buyers focused on data sovereignty, Lexware or Pennylane offer comparable SMB accounting functionality from an EU-owned base. The trade-off is that the US platforms have broader third-party integration ecosystems, which matters if you rely on specific CRM, payroll, or e-commerce integrations. **Q: Is Sage a good EU alternative for accounting?** Sage Accounting is incorporated in the UK (post-Brexit) under the 'other' ownership signal: it is not a US-owned platform, but as a UK company it is subject to UK data protection law (UK GDPR) rather than EU GDPR, and to UK court orders rather than the US CLOUD Act. For EU buyers whose primary concern is keeping financial data within EU-supervised jurisdiction, EU-incorporated platforms such as Lexware or Pennylane are the more consistent choice. ### Forms & surveys: https://euvetted.com/category/forms-surveys Form and survey platforms collect structured data from respondents via web forms, questionnaires, and feedback tools. For EU buyers, the critical question is whether collected responses (often personal data) are stored and processed by an EU-owned operator under EU law. Leading EU options on EU Vetted include Formdesk (Netherlands, EU-owned, EU-hosted, no CLOUD Act exposure) and LimeSurvey (Germany, EU-owned, EU-hosted, no CLOUD Act exposure). Editorial picks: - [Findmind](https://euvetted.com/p/findmind): hosted in Switzerland, CLOUD Act: minor, ownership: other - [Formbricks](https://euvetted.com/p/formbricks): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Formdesk](https://euvetted.com/p/formdesk): hosted in Netherlands, CLOUD Act: none, ownership: eu_owned - [Formspark](https://euvetted.com/p/formspark): hosted in Switzerland, CLOUD Act: minor, ownership: other - [LimeSurvey](https://euvetted.com/p/limesurvey): hosted in Germany, CLOUD Act: none, ownership: eu_owned **Q: What is the best EU-hosted form and survey platform?** Formdesk (Netherlands) and LimeSurvey (Germany) are both EU-owned platforms with EU-based infrastructure, published DPAs, and no CLOUD Act exposure. Tally (Belgium) is a strong alternative with a modern interface and EU ownership, though it has not yet published a full sub-processor list. The right choice depends on whether you need a self-hosted open-source option (LimeSurvey), a managed cloud form builder (Formdesk), or a lightweight no-code tool (Tally). **Q: Is there a GDPR-compliant form and survey platform?** Any form platform operated by an EU-incorporated company with EU-based infrastructure and a published DPA qualifies as GDPR-compliant in its processor role. Formdesk and LimeSurvey both publish detailed DPAs and document their sub-processors. Forms and surveys frequently collect consent, health data, or employee feedback (all regulated categories under GDPR); the legal basis for collection must be established by the controller (you), not the platform. **Q: Does form response data fall under the US CLOUD Act?** If the form platform is operated or ultimately controlled by a US-incorporated parent, the CLOUD Act can in principle compel production of submitted response data, regardless of where it is stored. EU-owned operators such as Formdesk (Netherlands), LimeSurvey (Germany), Tally (Belgium), Tripetto (Netherlands), and Survicate (Poland) are not directly subject to this exposure. Typeform (Spain) and Formbricks (Germany) carry US-investor ownership signals that place them at a different risk level despite EU headquarters. **Q: Can I self-host a form and survey platform in the EU?** Yes. LimeSurvey is an open-source platform that can be self-hosted on any EU infrastructure you control, giving you full data ownership with no third-party operator in the chain. Formbricks (Germany) also offers a self-hosted open-source version alongside its managed cloud offering. For organisations with strict data residency requirements, self-hosting LimeSurvey on a compliant EU server is typically the strongest posture available in this category. **Q: How does EU-hosted Typeform compare to alternatives?** Typeform is incorporated in Spain and hosts data in the EU, but it carries a US-investor ownership signal that places it at a different risk level than fully EU-owned alternatives. It remains a widely used tool for its conversational survey format. For buyers whose primary motivation is strict EU-ownership compliance, Tally (Belgium, EU-owned, EU-hosted) offers a comparable modern form interface with a cleaner ownership signal. **Q: Are there EU alternatives to Google Forms?** Yes. Formdesk (Netherlands, EU-owned, EU-hosted) and Tally (Belgium, EU-owned, EU-hosted) are the most direct functional alternatives. LimeSurvey (Germany, EU-owned, EU-hosted, open-source) is better suited to structured research surveys than ad-hoc data collection. Tripetto (Netherlands, EU-owned) offers a conversational format. All four are EU-owned; none have the same breadth of Google Workspace integration, but all can embed in websites and export responses to CSV or connect to Zapier or n8n for automation. **Q: Do EU form platforms support conditional logic and branching?** Most do. Formdesk, LimeSurvey, Typeform, and Tripetto all support conditional branching. Tally supports conditional logic on its paid plans. Survicate (Poland) specialises in product feedback with conditional flows built for NPS, CSAT, and CES use cases. Check the feature set at each pricing tier, as conditional logic is sometimes restricted to paid plans. ### Project management: https://euvetted.com/category/project-management Project management platforms organise tasks, timelines, team collaboration, and project documentation in one workspace. For EU buyers, what matters most is whether project data (including internal communications and commercially sensitive plans) is processed by an EU-owned operator outside CLOUD Act reach. Strong EU options on EU Vetted include Stackfield (Germany, EU-owned, EU-hosted, no CLOUD Act exposure), MeisterTask (Germany, EU-owned, EU-hosted), factro (Germany, EU-owned, EU-hosted), and SeaTable (Germany, EU-owned, EU-hosted). Editorial picks: - [Baserow](https://euvetted.com/p/baserow): hosted in Spain, CLOUD Act: minor, ownership: eu_owned - [factro](https://euvetted.com/p/factro): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [HansaChat](https://euvetted.com/p/hansachat): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Kantree](https://euvetted.com/p/kantree): hosted in France, CLOUD Act: none, ownership: eu_owned - [MeisterTask](https://euvetted.com/p/meistertask): hosted in Germany, CLOUD Act: none, ownership: eu_owned **Q: What is the best EU-hosted project management tool?** Stackfield (Germany), MeisterTask (Germany), factro (Germany), SeaTable (Germany), Taiga (Spain), Kantree (France), and YetiForce (Poland) are all EU-owned platforms with EU infrastructure and published DPAs. The right choice depends on your workflow style: Stackfield prioritises secure team communication alongside tasks; MeisterTask focuses on Kanban; factro is suited to project portfolio management; SeaTable combines project views with a spreadsheet-database hybrid. **Q: Is there a GDPR-compliant project management platform?** Any project management platform operated by an EU-incorporated company with EU-based infrastructure and a published DPA qualifies as GDPR-compliant in its processor role. Stackfield, MeisterTask, factro, SeaTable, and Taiga all publish DPAs. Project management data can include personal data (team member identities, HR-adjacent task assignments) alongside commercially sensitive information; a published DPA and EU ownership together are the minimum bar for compliance-conscious buyers. **Q: Does project management data fall under the US CLOUD Act?** If your project management tool is operated or ultimately controlled by a US-incorporated parent, the CLOUD Act can in principle compel production of project data it controls (including internal communications, task comments, and file attachments) regardless of where that data is physically stored. EU-owned operators such as Stackfield (Germany), MeisterTask (Germany), and Taiga (Spain) are not directly subject to this exposure. This tracks corporate ownership, not a claim about any particular legal request. **Q: Can I self-host a EU project management platform?** Yes. Taiga (Spain) is open source and fully self-hostable. YetiForce (Poland) is also open source and designed for self-hosted enterprise deployment. Baserow (Netherlands) supports self-hosting for its database-plus-project-view approach. For organisations that need full control over where project data lives (including file attachments and comment threads), self-hosted Taiga or YetiForce are the most complete options in this category. **Q: How do EU project management tools compare to Asana, Jira, or Monday.com?** Asana and Monday.com are US-incorporated companies; Jira is a product of Atlassian, an Australian company. All three have significant global footprints and extensive integration ecosystems. EU alternatives such as Stackfield and MeisterTask offer comparable task and workflow management from an EU-owned base. The main practical difference is integration breadth: US platforms connect to more third-party tools by default. For teams already in the Microsoft 365 or Google Workspace ecosystem, evaluate whether native integrations are a hard requirement before choosing. **Q: Is Teamwork.com a European project management platform?** Teamwork.com is incorporated in Ireland and is an EU-owned platform with EU infrastructure and a published DPA. It is a project management suite targeting agencies and client-facing teams. As an Irish-incorporated company it operates under EU law and GDPR jurisdiction, making it a compliant choice for teams that need Asana-level feature depth with stronger data sovereignty than a US-incorporated alternative. **Q: Do EU project management tools support agile and Scrum workflows?** Several do. Taiga (Spain, EU-owned, open-source) is purpose-built for agile teams with native Scrum and Kanban board support, backlog management, and sprint planning. MeisterTask (Germany, EU-owned, EU-hosted) is Kanban-first with customisable workflows. SeaTable (Germany, EU-owned, EU-hosted) can model agile workflows through its flexible database structure. YetiForce (Poland, EU-owned, open-source) is a broader CRM-plus-project platform that includes agile project views. For dedicated Scrum use, Taiga is the most purpose-built EU option in the catalogue. ### Helpdesk: https://euvetted.com/category/helpdesk Helpdesk and live-chat platforms handle customer support conversations and store interaction histories, contact details, and in some cases payment or health data. For EU buyers, the deciding question is whether the operator is EU-owned and EU-hosted, limiting CLOUD Act exposure. Strong EU options on EU Vetted include Crisp (France, EU-owned and EU-hosted, CLOUD Act exposure: [[crisp.cloud_act]]), Userlike (Germany, EU-owned and EU-hosted), and Customerly (Ireland, EU-owned and EU-hosted). Editorial picks: - [Crisp](https://euvetted.com/p/crisp): hosted in France, CLOUD Act: material, ownership: eu_owned - [Userlike (Lime Connect)](https://euvetted.com/p/userlike): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [LiveChat (Text)](https://euvetted.com/p/livechat): hosted in Poland, CLOUD Act: minor, ownership: eu_owned - [Customerly](https://euvetted.com/p/customerly): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [chatlyn](https://euvetted.com/p/chatlyn): hosted in Austria, CLOUD Act: minor, ownership: eu_owned **Q: What is the best EU-hosted helpdesk platform?** Crisp (France) is EU-owned and EU-hosted (CLOUD Act exposure: [[crisp.cloud_act]]), with a published DPA and disclosed sub-processors. Userlike (Germany), Customerly (Ireland), chatlyn (Austria), and LiveChat by Text (Poland) are also EU-owned and EU-hosted. The right choice depends on your channel mix: Crisp covers live chat, email, and shared inbox; Userlike specialises in messaging-channel integrations; LiveChat is better known for high-volume e-commerce support. **Q: Is there a GDPR-compliant helpdesk software?** Any helpdesk operated by an EU-incorporated company with EU-only infrastructure and a published DPA qualifies as GDPR-compliant in its processing role. Crisp (France) and Userlike (Germany) both publish detailed DPAs and sub-processor lists. A published DPA reflects the operator's practices at a point in time, not a permanent guarantee; check it against your own requirements, particularly around any third-party chat or analytics integrations. **Q: Does helpdesk data fall under the US CLOUD Act?** If the helpdesk platform is operated or ultimately owned by a US-incorporated company, the CLOUD Act can in principle compel it to produce data it controls, regardless of where that data is stored. EU-owned operators such as Crisp (France, CLOUD Act exposure: [[crisp.cloud_act]]), Userlike (Germany, CLOUD Act exposure: [[userlike.cloud_act]]), and LiveChat (Poland, CLOUD Act exposure: [[livechat.cloud_act]]) have no US parent company that can be compelled this way. This is a read on corporate ownership only, not a prediction about any specific legal request. **Q: What customer data does a helpdesk platform typically process?** Helpdesk platforms typically process contact identity data (name, email, phone), full conversation transcripts, ticket metadata, and in some cases browser or device fingerprinting data used for proactive chat triggers. Enterprise deployments may also handle CRM data, order history, or identity-verified customer records. The breadth of data makes CLOUD Act exposure particularly significant for B2B buyers operating under sector-specific regulations such as financial services or healthcare. **Q: Can a helpdesk platform be self-hosted for maximum data control?** Several EU-adjacent open-source platforms support full self-hosting, though the products listed on EU Vetted are primarily SaaS. If self-hosting is a hard requirement, Chatwoot and Rocket.Chat are open-source options you can run on your own infrastructure. Among the SaaS products in this catalogue, Userlike and Crisp offer on-premises or private-cloud deployment options on their enterprise tiers. Check directly with the vendor for current availability. **Q: How does EU helpdesk software compare to Zendesk or Intercom for features?** Zendesk and Intercom have broad feature sets built over many years. EU alternatives such as Crisp and Userlike cover the core workflows (live chat, ticketing, shared inbox, canned responses, basic reporting) and are well-suited to SMB and mid-market buyers. Feature parity gaps tend to appear in advanced automation, AI-assisted triage, and enterprise integrations. Evaluate specific workflows against your current support volume before migrating. **Q: Is Tidio a safe choice for EU buyers?** Tidio is incorporated in Poland (EU) but carries an eu_hq_us_funded ownership signal, meaning it has EU headquarters but US investment or corporate linkage that introduces CLOUD Act exposure at the group level (CLOUD Act exposure: [[tidio.cloud_act]]). For buyers whose primary concern is GDPR compliance rather than strict EU sovereignty, Tidio may be sufficient; for stricter sovereign requirements, Crisp or Userlike are better starting points, both fully EU-owned (CLOUD Act exposure: Crisp [[crisp.cloud_act]], Userlike [[userlike.cloud_act]]). ### Calendar booking: https://euvetted.com/category/calendar-booking Calendar and booking platforms synchronise schedules, send automated reminders, and collect appointment data including personal contact details. For EU buyers, what decides it is operator jurisdiction: US-owned scheduling tools process calendar metadata and contact lists that fall within CLOUD Act reach. Strong EU options on EU Vetted include Doodle (Switzerland, non-US-owned, CLOUD Act exposure: [[doodle.cloud_act]]), Reservio (Czech Republic, EU-owned, EU-hosted, public DPA), and SuperSaaS (Netherlands, EU-owned, EU-hosted, public DPA). Editorial picks: - [Cal.com](https://euvetted.com/p/cal-com): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Cronofy](https://euvetted.com/p/cronofy): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Doodle](https://euvetted.com/p/doodle): hosted in Germany, CLOUD Act: minor, ownership: other - [Reservio](https://euvetted.com/p/reservio): hosted in Czechia, CLOUD Act: minor, ownership: eu_owned - [SuperSaaS](https://euvetted.com/p/supersaas): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned **Q: What is the best EU-hosted calendar and booking platform?** Doodle (Switzerland) is a non-US-owned platform with strong privacy practices operating under Swiss data-protection law, which the EU considers broadly adequate. Reservio (Czech Republic) and SuperSaaS (Netherlands) are both EU-owned and EU-hosted with published DPAs and disclosed sub-processors. Cronofy (UK) is based in the United Kingdom post-Brexit and operates under UK GDPR, which is currently considered adequate by the EU but represents a distinct legal framework. The right choice depends on whether you need group scheduling (Doodle), appointment booking for clients (Reservio, SuperSaaS), or a calendar API for developers (Cronofy). **Q: Is there a GDPR-compliant scheduling and booking tool?** Any scheduling platform operated by an EU-incorporated company with EU-only infrastructure and a published DPA qualifies as GDPR-compliant in its processing role. Reservio (Czech Republic) and SuperSaaS (Netherlands) both publish DPAs and are subject to EU data-protection authorities. A published DPA reflects the operator's current practices, not a permanent guarantee; check it alongside the vendor's list of calendar-provider integrations, since syncing with Google Calendar or Microsoft 365 introduces additional data flows. **Q: Does scheduling and calendar data fall under the US CLOUD Act?** Calendar metadata (meeting titles, participant lists, times, and locations) can be sensitive in business and legal contexts. If the scheduling tool is operated or ultimately owned by a US-incorporated company, the CLOUD Act can in principle compel it to produce this data. EU-incorporated operators such as Reservio (Czech Republic) and SuperSaaS (Netherlands) are not directly subject to the CLOUD Act. Swiss-based Doodle is not subject to the CLOUD Act through US corporate structure, though independent legal analysis should be applied to your specific situation. **Q: What data does a booking platform collect from end customers?** A typical appointment booking flow collects at minimum the customer's name, email address, and phone number, plus the selected service type, date, and time. Many platforms also store payment details if deposit or prepayment is enabled, and issue automated reminder sequences that include personal references. If your clients are consumers under GDPR, the booking platform is a data processor and its DPA terms govern the lawfulness of that collection. **Q: Can I use an EU booking platform if my customers are in multiple countries?** Yes. Doodle, Reservio, and SuperSaaS all support multi-language booking pages and timezone handling for international use. For businesses operating across EU member states, the advantage of an EU-incorporated operator is that a single DPA covers all EU countries without the complexity of adequacy decisions or Standard Contractual Clauses required for data transfers to non-adequate third countries. **Q: Is Cal.com a safe choice for EU buyers despite being US-based?** Cal.com is incorporated in the United States, which means its hosted service carries CLOUD Act exposure. It is open-source, which means you can self-host it entirely on EU infrastructure under your own data control. In that configuration the US corporate structure is less relevant. As a hosted SaaS service, however, data processed by Cal.com's own cloud infrastructure falls under US jurisdiction for CLOUD Act purposes. Buyers with strict sovereignty requirements should either use an EU-owned alternative or deploy Cal.com on their own infrastructure. **Q: How does EU calendar software integrate with Google Calendar and Microsoft 365?** Most EU booking platforms, including Doodle, Reservio, and SuperSaaS, support OAuth-based integration with Google Calendar and Microsoft Outlook for availability sync. The integration means calendar metadata flows through Google's or Microsoft's systems, which are US companies subject to the CLOUD Act. For buyers with strict data sovereignty requirements, this integration should be evaluated separately from the booking platform itself, and using an EU-hosted calendar backend such as a Nextcloud instance may be preferable. ### Docs & wikis: https://euvetted.com/category/docs-wikis Docs and wiki platforms store your organisation's internal knowledge, runbooks, and documentation, content that often contains strategic plans, technical architecture, and personnel information. For EU buyers, what settles the sovereignty question is operator jurisdiction and whether document content can be reached under the US CLOUD Act. Strong EU options on EU Vetted include Nuclino (Germany, EU-owned, EU-hosted), Anytype (Germany, EU-owned, EU-hosted), CryptPad (France, EU-owned, EU-hosted, end-to-end encrypted), and HumHub (Germany, EU-owned, EU-hosted). Editorial picks: - [Anytype](https://euvetted.com/p/anytype): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [BookStack](https://euvetted.com/p/bookstack): hosted in United Kingdom, CLOUD Act: none, ownership: other - [Collabora Online](https://euvetted.com/p/collabora-online): hosted in United Kingdom, CLOUD Act: minor, ownership: other - [CryptPad](https://euvetted.com/p/cryptpad): hosted in France, CLOUD Act: none, ownership: eu_owned - [HumHub](https://euvetted.com/p/humhub): hosted in Germany, CLOUD Act: none, ownership: eu_owned **Q: What is the best EU-hosted docs and wiki platform?** Anytype (Germany), CryptPad (France), and HumHub (Germany) are EU-owned, EU-hosted, and sit outside CLOUD Act jurisdiction; Nuclino (Germany) is EU-owned and EU-hosted but carries CLOUD Act exposure: [[nuclino.cloud_act]] through its sub-processor chain. Wiki.js (Canada) and BookStack (UK) are open-source self-hostable tools where the corporate structure is less relevant than your choice of hosting environment. Among SaaS products for teams, Nuclino is the most direct Notion or Confluence alternative; CryptPad is distinctive for end-to-end encrypted real-time collaboration. **Q: Is there a GDPR-compliant wiki or documentation platform?** Any wiki platform operated by an EU-incorporated company with EU-only infrastructure and a published DPA qualifies as GDPR-compliant in its processing role. Nuclino (Germany), CryptPad (France), HumHub (Germany), and Talkspirit (France) all publish DPAs. For self-hosted tools such as Wiki.js or BookStack, GDPR compliance depends on your own hosting choices and data-processing practices. A DPA documents what the vendor commits to, it is not a certification that execution is flawless; weigh it against your organisation's own data classification requirements. **Q: Does documentation platform data fall under the US CLOUD Act?** Internal documentation often contains the most sensitive organisational information: architecture decisions, HR records, financial models, and client data. If the platform is operated or ultimately owned by a US-incorporated company, the CLOUD Act can in principle compel production of that content regardless of where it is stored. EU-owned operators such as Nuclino (Germany), CryptPad (France), and HumHub (Germany) are not directly subject to the CLOUD Act. CryptPad's end-to-end encryption provides a technical layer of protection even if legal process were served on the operator. **Q: What is the difference between a docs tool, a wiki, and an intranet platform?** These categories overlap significantly. A docs tool (Nuclino, Joplin) is optimised for structured writing, linking, and versioning. A wiki (Wiki.js, BookStack) is built around community-editable, interlinked pages. An intranet platform (HumHub, Talkspirit) adds social features, news feeds, and team communication on top of document management. CryptPad covers document and spreadsheet collaboration with end-to-end encryption. The right choice depends on whether you need a developer-friendly knowledge base, a company-wide intranet, or a collaboration suite. **Q: Can documentation and wiki data be fully self-hosted?** Yes. Wiki.js (Canada) and BookStack (UK) are open-source tools designed specifically for self-hosting, and Anytype (Germany) supports a self-hosted sync server option. Nuclino and CryptPad offer cloud-hosted plans but also support on-premises enterprise deployments. Self-hosting removes the platform operator as a third-party processor, which is particularly relevant for documentation containing trade secrets, HR data, or client-confidential content. **Q: How does Nuclino compare to Notion or Confluence for EU buyers?** Nuclino (Germany, EU-owned and EU-hosted) offers a comparable experience to Notion for team wikis and linked documents with a simpler interface, though its hosted offering carries CLOUD Act exposure: [[nuclino.cloud_act]] through its sub-processor chain. Notion is US-incorporated and all data processed through its SaaS service falls under CLOUD Act jurisdiction. Confluence (Atlassian, US) carries the same jurisdictional concern. For EU buyers who need Notion-like functionality with the cleanest exposure signal, Anytype (Germany, local-first) is the most direct alternative currently in the EU Vetted catalogue. **Q: What is CryptPad and why is it recommended for EU buyers?** CryptPad is a French open-source collaborative document platform that uses end-to-end encryption: documents are encrypted in the browser before being stored on the server, meaning the server operator (including CryptPad's own cloud) cannot read the content. It is operated by XWiki SAS (France) and is EU-incorporated, EU-hosted, with no CLOUD Act exposure and the added protection of end-to-end encryption. It supports documents, spreadsheets, presentations, forms, and kanban boards. ### Video conferencing: https://euvetted.com/category/video-conferencing Video conferencing platforms process live audio, video, and chat communications, often storing recordings and transcripts. For EU buyers, what matters most is operator jurisdiction: US-owned platforms process meeting content and metadata that falls within CLOUD Act reach. Strong EU options on EU Vetted include Tixeo (France, EU-owned, ANSSI-qualified), Threema (Switzerland, CLOUD Act exposure: [[threema.cloud_act]]), Element/Matrix (UK, open federated protocol, self-hostable), and Wire (Switzerland, end-to-end encrypted; CLOUD Act exposure: [[wire.cloud_act]] via its sub-processor chain). Editorial picks: - [Element (Matrix)](https://euvetted.com/p/element-matrix): hosted in United Kingdom, CLOUD Act: material, ownership: other - [kMeet (Infomaniak)](https://euvetted.com/p/kmeet): hosted in Switzerland, CLOUD Act: none, ownership: other - [Olvid](https://euvetted.com/p/olvid): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Pexip](https://euvetted.com/p/pexip): hosted in Norway, CLOUD Act: material, ownership: other - [SimpleX Chat](https://euvetted.com/p/simplex-chat): hosted in United Kingdom, CLOUD Act: minor, ownership: other **Q: What is the best EU-hosted video conferencing platform?** Tixeo (France), Threema (Switzerland), and sipgate (Germany, VoIP and telephony) present the strongest signals: EU or Swiss ownership, no US corporate parent, and published DPA or security documentation, each sitting outside CLOUD Act reach. Element (UK/Matrix protocol) and Wire (Switzerland) have no US parent either, but their hosted offerings carry CLOUD Act exposure through their sub-processor chains ([[element-matrix.cloud_act]] and [[wire.cloud_act]] respectively); Element additionally supports full self-hosting that removes any third-party operator. For corporate video meetings specifically, Tixeo is the most focused option: EU-owned, ANSSI-qualified, and designed for sensitive environments. Pexip (Norway) and Whereby (Norway) are EEA-incorporated and GDPR-bound but not EU-owned; EU Vetted rates their exposure [[pexip.cloud_act]] and [[whereby.cloud_act]] respectively, once sub-processors are accounted for. **Q: Is there a GDPR-compliant video conferencing solution?** Any video platform operated by an EU-incorporated company with EU-only infrastructure and a published DPA qualifies as GDPR-compliant in its processing role. Tixeo (France) publishes detailed security and privacy documentation and holds ANSSI qualification. Meeting these criteria describes documented vendor practice, not a warranty against every failure mode; for meetings involving sensitive personal data (patient records, legal proceedings, HR conversations) the platform's recording and transcript handling policy is especially important to verify. **Q: Does video conferencing data fall under the US CLOUD Act?** Video conferencing platforms process some of the most sensitive business communications: board meetings, legal strategy discussions, M&A conversations, and HR interviews. If the platform is operated or ultimately owned by a US-incorporated company, the CLOUD Act can in principle compel it to produce recordings, transcripts, and meeting metadata regardless of storage location. EU-owned operators such as Tixeo (France, CLOUD Act exposure: [[tixeo.cloud_act]]) have no US parent company that can be compelled this way. Swiss-based operators Wire and Threema operate under Swiss law with no US corporate parent, though Wire's hosted offering still carries CLOUD Act exposure through its sub-processor chain (CLOUD Act exposure: Wire [[wire.cloud_act]], Threema [[threema.cloud_act]]). **Q: What is Matrix and why does Element appear in this category?** Matrix is an open, decentralised communication protocol; Element is the most widely used client application built on it. Element Matrix Services is incorporated in the UK and provides hosted Matrix servers, including video conferencing via the Jitsi integration. Because Matrix is an open federated protocol, organisations can also run their own Matrix homeserver and use Element as the client, removing any third-party operator entirely. EU Vetted lists Element for its open architecture, EU-adjacent incorporation, and the option of full self-hosted deployment that eliminates operator-side data exposure. **Q: What is Tixeo and what makes it suitable for sensitive environments?** Tixeo is a French video conferencing platform that holds qualification from ANSSI, the French national cybersecurity agency, and has been approved for use by French and EU government entities handling sensitive information. It uses end-to-end encryption for video calls, meaning that neither the Tixeo operator nor any intermediary can decrypt the video or audio stream. EU Vetted lists it as EU-owned and EU-hosted (CLOUD Act exposure: [[tixeo.cloud_act]]), with published security certifications. It offers both SaaS and on-premises deployment. **Q: Can EU video conferencing replace Zoom or Microsoft Teams for a business?** For most standard business meeting use cases (scheduled calls, screen sharing, file sharing, breakout rooms) European alternatives such as Tixeo, Wire, Whereby, and Pexip cover the core functionality. Feature parity gaps tend to appear in deep integrations with Microsoft 365 or Google Workspace, AI-assisted transcription, and large-scale webinar modes. Whereby and Pexip are designed for easy browser-based access without client installation, which reduces friction for external participants. **Q: Is Whereby or Pexip a safe choice despite not being EU-incorporated?** Whereby and Pexip are both incorporated in Norway, an EEA country that applies GDPR and is part of the European Economic Area but not an EU member state. EU Vetted lists both with EEA jurisdiction and no US corporate parent, while noting they are not EU-owned, the key gap relative to French or German alternatives. Their overall CLOUD Act exposure, once sub-processors are accounted for, is rated [[pexip.cloud_act]] (Pexip) and [[whereby.cloud_act]] (Whereby). Norway is not subject to the CLOUD Act through its corporate structure, making Norwegian-incorporated companies a lower-risk choice than US-incorporated ones. Adequacy for EU data transfers to Norway applies through the EEA Agreement. ### E-signature: https://euvetted.com/category/e-signature E-signature platforms process signed contracts, identity verification data, and in some cases qualified certificate credentials. For EU buyers, eIDAS compliance determines legal validity across the EU, and operator jurisdiction determines data sovereignty. On the sovereignty axis the cleanest option is Skribble (Switzerland, Swiss-law, non-US corporate structure, no US sub-processor in the data path). Universign (France) and Signaturit/Namirial (Spain) remain eIDAS-qualified QTSPs with strong track records, but both are now US private-equity owned and hosted on AWS at rest, so they carry material CLOUD Act exposure. Editorial picks: - [Eversign (Xodo Sign)](https://euvetted.com/p/eversign): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Signaturit (Namirial)](https://euvetted.com/p/signaturit): hosted in Spain, CLOUD Act: material, ownership: eu_hq_us_funded - [Signicat](https://euvetted.com/p/signicat): hosted in Norway, CLOUD Act: material, ownership: other - [Skribble](https://euvetted.com/p/skribble): hosted in Switzerland, CLOUD Act: none, ownership: other - [Tresorit eSign](https://euvetted.com/p/tresorit-esign): hosted in Ireland, CLOUD Act: material, ownership: other **Q: What is the best EU-hosted e-signature platform?** On the sovereignty axis, Skribble (Switzerland) is the cleanest option: it operates under Swiss law with a non-US corporate structure and keeps no US sub-processor in the signing data path, offering qualified electronic signatures under the Swiss ZertES standard with cross-recognition to eIDAS through bilateral arrangements. Universign (France) and Signaturit/Namirial (Spain) are eIDAS-qualified QTSPs with strong track records, but both are now US private-equity owned (Namirial by Bain Capital, Signaturit by PSG Equity, merged in 2025) and hosted on Amazon Web Services at rest, so they carry material CLOUD Act exposure rather than being sovereignty picks. Yousign (France) is a widely used EU-headquartered alternative with a strong track record in the SMB market, though it has received US investment which buyers with strict sovereignty requirements should evaluate. **Q: Is there a GDPR-compliant e-signature tool?** Any e-signature platform operated by an EU-incorporated company with EU-only infrastructure and a published DPA qualifies as GDPR-compliant in its processing role. Universign (France), Signaturit/Namirial (Spain), and Yousign (France) all publish DPAs. E-signature platforms process identity data and signed document content, making them a high-priority category for data-processing impact assessments. What a published DPA shows is process, not proof against every incident; check it against your own document types and signer data. **Q: Does e-signature data fall under the US CLOUD Act?** E-signature platforms retain signed contract documents, signer identity data (name, email, and sometimes biometric or ID-verification data), and audit trails. If the platform is operated or ultimately owned by a US-incorporated company, or hosts data on a US-owned cloud, the CLOUD Act can in principle compel production of those records. Exposure has to be assessed per operator: Skribble (Switzerland) has a non-US corporate structure with no US sub-processor in its data path and so avoids that direct exposure, whereas Universign (France) and Signaturit/Namirial (Spain) are now US private-equity owned and host on Amazon Web Services at rest, which brings them within material CLOUD Act reach despite their EU incorporation. This is particularly relevant for contracts involving trade secrets, M&A activity, or regulatory filings. **Q: What does eIDAS mean for e-signature platforms?** eIDAS (Electronic Identification, Authentication and Trust Services) is the EU regulation that defines three legally recognised signature levels: Simple Electronic Signature (SES), Advanced Electronic Signature (AdES), and Qualified Electronic Signature (QES). A QES has the same legal effect as a handwritten signature across all EU member states and is the standard required for land registry transactions, notarised documents, and certain regulated financial agreements. Universign and Signaturit/Namirial both offer QES. Skribble offers QES under the Swiss ZertES standard. **Q: What is the difference between a simple, advanced, and qualified electronic signature?** A Simple Electronic Signature (SES) is any electronic mark indicating consent: a typed name or an image of a signature. An Advanced Electronic Signature (AdES) is linked to the signer's identity through a certificate and detects post-signing tampering. A Qualified Electronic Signature (QES) requires a Qualified Trust Service Provider (QTSP) and a secure signing device; it has the highest legal standing under eIDAS and is equivalent to a handwritten signature in all EU countries. Most B2B contracts require AdES or QES for court-admissible evidence; some regulated industries require QES specifically. **Q: Is DocuSign or Adobe Sign safe to use for EU contracts?** DocuSign and Adobe Sign are both US-incorporated companies. Signed contracts and identity data processed through their platforms fall within CLOUD Act reach, regardless of where data is physically stored. Both offer EU data residency options as add-ons on enterprise plans, but data residency does not remove CLOUD Act exposure since it is the corporate structure, not the storage location, that matters for CLOUD Act purposes. EU buyers with strict sovereignty or sector-specific compliance requirements are better served by EU-incorporated alternatives. **Q: What about Yousign, is it fully EU-owned?** Yousign is a French company with strong EU market presence. Its ownership signal is eu_hq_us_funded, meaning it has received US investment, which can introduce potential CLOUD Act exposure at the parent-group level depending on corporate structure. Universign (France) and Signaturit/Namirial (Spain) share the same limitation and then some: both are now US private-equity owned and hosted on Amazon Web Services at rest, so they carry material CLOUD Act exposure and are not the sovereignty picks either. For buyers whose requirement is strict sovereignty without US ownership or US cloud dependency, Skribble (Switzerland), with its non-US corporate structure and no US sub-processor in the data path, is the stronger choice. For buyers whose primary concern is eIDAS compliance and GDPR-compliant processing rather than sovereign ownership, Yousign remains a solid and widely used option. ### HR & people: https://euvetted.com/category/hr HR and people platforms manage employee records, payroll, onboarding, and performance, processing some of the most sensitive personal data an organisation holds. For EU buyers, what to check first is CLOUD Act exposure and EU data-residency commitments. Strong EU options on EU Vetted include Lucca (France, EU-owned and EU-hosted with no CLOUD Act exposure) and Sage HR (UK, EU-hosted with a public DPA but UK-incorporated). Editorial picks: - [Factorial](https://euvetted.com/p/factorial): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [HiBob](https://euvetted.com/p/hibob): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [Lucca](https://euvetted.com/p/lucca): hosted in France, CLOUD Act: none, ownership: eu_owned - [Personio](https://euvetted.com/p/personio): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Sage HR](https://euvetted.com/p/sage-hr): hosted in Ireland, CLOUD Act: minor, ownership: other **Q: What is the best EU-hosted HR software?** Lucca (France) is an EU-owned and EU-hosted HR platform with no CLOUD Act exposure and published DPA and sub-processor documentation, the strongest sovereignty posture in the catalogue. Sage HR (UK) is EU-hosted and publishes a detailed DPA, though it is UK-incorporated following Brexit, which means it is not EU-owned. For organisations that require strictly EU ownership, Lucca is the clearest option currently. **Q: Is there a GDPR-compliant HR platform?** HR platforms that are incorporated in the EU, operate on EU-only infrastructure, and publish a detailed DPA with a full sub-processor list qualify as GDPR-compliant in their processing role. Lucca (France) meets these criteria and publishes detailed documentation. A DPA reflects what the operator states about its own practices, not a guarantee of outcome; review each vendor's DPA against your own requirements and data-transfer obligations. **Q: Does HR software data fall under the US CLOUD Act?** If an HR platform is operated or ultimately owned by a US-incorporated company, the CLOUD Act can in principle compel it to produce data it controls regardless of where that data is stored. HR data is particularly sensitive: it includes employment contracts, salary records, health information, and performance reviews. EU-owned operators such as Lucca (France), incorporated and hosted in France with no US parent, are not directly subject to that exposure. Personio, Factorial, and HiBob are listed as EU-headquartered but US-funded; their CLOUD Act exposure depends on the corporate structure of any US-incorporated parent. **Q: What HR data is covered by GDPR's special-category protections?** GDPR Article 9 defines special-category data to include health and medical information, which frequently appears in HR records (sick leave, disability accommodations, occupational health). Trade union membership, biometric data used for time-tracking, and certain performance data can also qualify. Processing this data requires a lawful basis under Article 9(2) (typically explicit employee consent or a legal obligation) and stricter technical and organisational measures. Verify that any HR platform you choose supports the access-control granularity needed to restrict special-category fields. **Q: Can payroll data be stored outside the EU?** Payroll data includes salary, bank details, and tax identification numbers, all personal data under GDPR. Transferring it outside the EU/EEA requires an adequate transfer mechanism: adequacy decision, Standard Contractual Clauses (SCCs), or Binding Corporate Rules. Transfers to the United States are permissible under SCCs, but the CLOUD Act means US-parent companies can in practice be compelled to access that data. If your compliance posture rules out CLOUD Act exposure, choose an HR platform with EU-only payroll data residency and an EU-owned operator. **Q: What is the difference between HR software and HCM (Human Capital Management)?** HR software typically covers core administrative functions: employee records, absence management, onboarding, and basic payroll. HCM platforms extend into workforce planning, talent acquisition, learning management, and people analytics, often integrated in a single suite. The GDPR obligations are the same regardless of label; what matters is which personal data each module processes and where it is stored. The listings on this page include both HR core tools and fuller HCM options; use the feature filter to narrow by the modules you need. **Q: Do EU HR platforms integrate with standard European payroll and accounting systems?** Most EU-built HR platforms offer direct or API-based integration with major European payroll providers and accounting software. Lucca, for example, integrates with widely used French payroll and accounting systems. Integration coverage varies by country, so verify that the platform supports the specific payroll engine and statutory reporting formats used in your jurisdiction before committing. ### Cookie consent: https://euvetted.com/category/cookie-consent Cookie consent platforms collect and store user consent signals for websites: the records that prove GDPR and ePrivacy compliance. For EU buyers, the critical criterion is where consent logs are hosted and whether the vendor itself is EU-owned. Leading EU options on EU Vetted include ConsentManager (Germany, EU-owned, EU-hosted, no CLOUD Act exposure), Didomi (France, EU-owned, EU-hosted, public DPA), and Iubenda (Italy, EU-owned, EU-hosted, public DPA). Editorial picks: - [ConsentManager](https://euvetted.com/p/consentmanager): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Cookiebot](https://euvetted.com/p/cookiebot): hosted in Denmark, CLOUD Act: material, ownership: eu_hq_us_funded - [Didomi](https://euvetted.com/p/didomi): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Iubenda](https://euvetted.com/p/iubenda): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [Usercentrics](https://euvetted.com/p/usercentrics): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded **Q: What is the best EU-hosted cookie consent platform?** ConsentManager (Germany) is EU-owned and EU-hosted with no CLOUD Act exposure, making it the strongest sovereignty signal among listed consent management platforms. Didomi (France) and Iubenda (Italy) are also EU-owned and publish detailed DPAs. The right choice depends on your use case: ConsentManager suits mid-market and enterprise with granular A/B testing; Didomi focuses on scalable enterprise consent orchestration; Iubenda targets smaller sites with an easy setup wizard. **Q: Is there a GDPR-compliant cookie consent tool?** Cookie consent tools incorporated in the EU, operating on EU-only infrastructure, and publishing a DPA that covers their own consent-log storage qualify as GDPR-compliant. ConsentManager, Didomi, and Iubenda all meet this bar. It is worth noting that the consent tool's own compliance is separate from your site's compliance: using a GDPR-compliant CMP does not automatically make your cookie implementation correct. You still need accurate cookie scanning and correctly scoped consent purposes. **Q: Does cookie consent data fall under the US CLOUD Act?** Consent logs are personal data under GDPR: they are timestamped records tied to a user's browsing session. If the consent platform is operated or ultimately owned by a US-incorporated company, the CLOUD Act can in principle reach those records. Cookiebot (Denmark) and Usercentrics (Germany) are EU-headquartered but US-funded; their CLOUD Act exposure depends on their US parent corporate structure. ConsentManager and Didomi are EU-owned and not directly subject to that exposure, based on public corporate filings. **Q: What is a Consent Management Platform (CMP) and do I need one?** A CMP is the technical layer that presents the cookie banner, records the user's consent choice, stores it in an auditable log, and communicates the signal to downstream scripts (analytics, advertising, personalisation). Under GDPR and the ePrivacy Directive, any site that places non-essential cookies must obtain and document prior consent. A CMP automates that process and maintains the audit trail. You need one if your site uses analytics tags (including privacy-friendly ones), social-media embeds, advertising pixels, or live-chat widgets that set cookies or access local storage. **Q: Does using a European CMP improve my GDPR compliance posture?** Choosing an EU-owned CMP removes one data processor from potential CLOUD Act exposure and aligns the vendor relationship with EU data-protection standards without needing a transfer mechanism. However, the CMP is one component of your compliance posture. The accuracy of your cookie scan, the legal basis you assign to each processing purpose, your data-retention settings, and your sub-processor disclosures all matter independently. An EU-owned CMP helps, but it does not substitute for a correct implementation. **Q: Can a CMP handle consent for multiple websites and jurisdictions?** Yes. Enterprise-grade CMPs such as ConsentManager and Didomi support multi-domain deployments and can serve jurisdiction-specific consent experiences. For example, a stricter opt-in flow for EU users and a different configuration for US visitors subject to CCPA/CPRA. Most platforms allow per-domain configuration from a single admin interface. If you operate sites across multiple EU member states, verify that the CMP supports the specific rules of each national data-protection authority, as some (notably France's CNIL) publish detailed technical requirements. **Q: How do I validate that my cookie consent implementation is correct?** Validation requires checking three things independently: that the banner fires before any non-essential scripts execute, that scripts are correctly blocked or unblocked based on the user's choice, and that consent logs are stored in a retrievable format. Browser developer tools and network-request monitors can verify script-firing order. Dedicated cookie audit tools can scan for unconsented cookies. If you handle significant EU user traffic, a periodic legal review of the consent purposes and legitimate-interest assessments is advisable. ### Headless CMS: https://euvetted.com/category/headless-cms Headless CMS platforms store and deliver structured content via API, decoupled from any specific frontend. For EU buyers, the deciding question is where content and editorial-session data are stored and whether the vendor is EU-owned. Strong EU options on EU Vetted include Hygraph (Germany, EU-owned and EU-hosted with a public DPA), Prismic (France, EU-owned with EU data residency), and DatoCMS (Italy, EU-owned with EU data residency). Editorial picks: - [DatoCMS](https://euvetted.com/p/datocms): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [Enonic](https://euvetted.com/p/enonic): hosted in Norway, CLOUD Act: material, ownership: other - [Hygraph](https://euvetted.com/p/hygraph): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Prismic](https://euvetted.com/p/prismic): hosted in United States, CLOUD Act: minor, ownership: eu_owned - [Storyblok](https://euvetted.com/p/storyblok): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded **Q: What is the best EU-hosted headless CMS?** Hygraph (Germany) is EU-owned, EU-hosted, and publishes a public DPA, making it the strongest compliance fit in the current catalogue. Prismic (France) and DatoCMS (Italy) are also EU-owned and offer EU data residency on their managed plans. Storyblok (Austria) and Strapi (France) are also in the catalogue; Storyblok is EU-headquartered but US-funded, while Strapi is an open-source platform that can be self-hosted on EU infrastructure, giving you full data-residency control regardless of the vendor's funding. **Q: Is there a GDPR-compliant headless CMS?** Headless CMS platforms that are incorporated in the EU, host content data in EU data centres, and publish a DPA covering their managed hosting service qualify as GDPR-compliant in their processing role. Hygraph (Germany), Prismic (France), and DatoCMS (Italy) all publish DPAs for their cloud offering. Self-hosted Strapi removes the vendor entirely from the processing chain. The data-protection obligations then sit solely with you as the data controller. **Q: Does headless CMS data fall under the US CLOUD Act?** A headless CMS stores structured content (product descriptions, articles, landing pages, configuration data) as well as editor accounts and potentially draft content. If the CMS is operated or ultimately owned by a US-incorporated company, the CLOUD Act can in principle compel it to produce that data. Hygraph, Prismic, and DatoCMS are EU-owned with no US parent, each carrying only a minor flag for transient sub-processors based on public corporate filings (CLOUD Act exposure: Hygraph [[hygraph.cloud_act]], Prismic [[prismic.cloud_act]], DatoCMS [[datocms.cloud_act]]). Strapi's cloud offering is managed by a US-incorporated entity; self-hosting Strapi avoids this entirely. **Q: What is the difference between a headless CMS and a traditional CMS?** A traditional CMS couples content storage with the frontend that displays it. WordPress, for example, stores content and renders pages in one system. A headless CMS stores only the content, exposing it via a structured API (REST or GraphQL) to any frontend: a Next.js app, a mobile app, a digital signage screen, or multiple channels simultaneously. The decoupled architecture gives frontend teams more flexibility and enables true omnichannel publishing. The tradeoff is that you need a separate frontend stack; there is no built-in page renderer. **Q: Can I self-host a headless CMS in the EU?** Yes. Strapi (France) is open-source and widely self-hosted on EU infrastructure such as Hetzner (Germany) or Scaleway (France). Self-hosting removes the vendor from the data-processing chain entirely. Your data never leaves your own infrastructure. Hygraph and DatoCMS are cloud-only products, but both offer EU data-residency on their managed plans. Prismic offers EU data-residency as well. When evaluating self-hosted options, factor in your team's capacity to manage updates, backups, and security patches. **Q: Which headless CMS is best for multi-language content?** Hygraph, Storyblok, Prismic, and DatoCMS all support multi-locale content fields as a native feature, making them suited for EU organisations that publish in multiple languages. The implementation model differs: some CMSs use a translation layer on top of a single content model; others offer fully independent locale-specific content trees. Verify that the CMS's localisation approach matches your editorial workflow: for example, whether translators can work in a parallel view, whether machine-translation integrations are available, and whether locale-specific publishing schedules are supported. **Q: How does a headless CMS handle media and image storage?** Most cloud headless CMS platforms include a managed digital-asset management (DAM) layer where images, videos, and documents are stored. For EU buyers, this is a second data-residency question: the content API might be EU-hosted while the media CDN routes through US infrastructure. Verify the specific CDN provider used by each platform and whether media can be restricted to EU points of presence. Self-hosted Strapi uses a configurable storage backend. S3-compatible EU providers such as Scaleway Object Storage or Hetzner Object Storage are straightforward integrations. ### E-commerce: https://euvetted.com/category/e-commerce E-commerce platforms power online stores, handling product catalogues, checkout flows, order management, and customer data. For EU buyers, the critical questions are where customer and transaction data are hosted and whether the vendor is subject to CLOUD Act jurisdiction. Notable EU options on EU Vetted include MyCashflow (Finland, EU-owned and EU-hosted), Shopware (Germany, EU-headquartered but US-funded), and Sylius (Poland, EU-owned and open-source). Editorial picks: - [Shopware](https://euvetted.com/p/shopware): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [PrestaShop](https://euvetted.com/p/prestashop): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [Sylius](https://euvetted.com/p/sylius): hosted in Poland, CLOUD Act: none, ownership: eu_owned - [MyCashflow](https://euvetted.com/p/mycashflow): hosted in Finland, CLOUD Act: none, ownership: eu_owned - [Saleor Commerce](https://euvetted.com/p/saleor): hosted in Ireland, CLOUD Act: material, ownership: eu_owned **Q: What is the best EU-hosted e-commerce platform?** MyCashflow (Finland) is EU-owned and EU-hosted, making it the most complete managed option for buyers who require no CLOUD Act exposure. Shopware (Germany), Sylius (Poland), Saleor Commerce (Poland), and PrestaShop (France) are also in the catalogue. Shopware, PrestaShop, and Saleor Commerce are EU-headquartered but carry US funding signals that affect their ownership signal. Sylius is EU-owned and open-source, making it self-hostable on any EU infrastructure. **Q: Is there a GDPR-compliant e-commerce platform?** E-commerce platforms that are EU-incorporated, store transaction and customer data in EU data centres, and publish a detailed DPA qualify as GDPR-compliant in their processing role. MyCashflow (Finland) meets these criteria as a fully managed platform. Open-source platforms such as Sylius and Saleor Commerce, when self-hosted on EU infrastructure, remove the vendor from the data-processing chain. Your obligations as data controller remain, but you choose the sub-processors entirely. A DPA is evidence of process, not a warranty that nothing goes wrong; verify each vendor's DPA and data-residency commitments. **Q: Does e-commerce data fall under the US CLOUD Act?** E-commerce platforms process some of the most commercially sensitive personal data: customer names and addresses, purchase history, payment method metadata, and browsing behaviour. If the platform is operated or ultimately owned by a US-incorporated company, the CLOUD Act can in principle compel it to produce that data. MyCashflow and Sylius are EU-owned and not directly subject to that exposure. Shopware and Saleor Commerce are EU-headquartered but US-funded; their CLOUD Act risk depends on their corporate structure with any US-incorporated parent entity. **Q: Can I self-host an EU e-commerce platform?** Yes. Sylius (Poland) and Saleor Commerce (Poland) are open-source platforms with active communities and can be deployed on EU infrastructure such as Hetzner (Germany), OVHcloud (France), or Scaleway (France). PrestaShop is also open-source and widely self-hosted. Self-hosting gives you complete data-residency control but requires your team to manage hosting, security updates, PCI-DSS scope for payment handling, and performance optimisation. MyCashflow and Shopware both offer managed cloud deployments with EU data residency. **Q: How does GDPR apply specifically to e-commerce?** E-commerce businesses process personal data at multiple touchpoints: account creation, checkout, order fulfilment, and post-purchase communications. GDPR requires a clear lawful basis for each processing activity: purchase fulfilment is typically contract performance; marketing emails require consent. Retention periods for transaction records must be defined and enforced. Cookie consent is mandatory for any tracking or analytics beyond what is strictly necessary. Additionally, if you use a third-party payment processor, you need a DPA or controller-to-controller agreement covering the transfer of payment-related personal data. **Q: What payment processors are available for EU e-commerce platforms?** Most EU e-commerce platforms integrate with major European payment service providers including Adyen (Netherlands), Mollie (Netherlands), Stripe (US-headquartered but EU-processing available), and regional providers. For buyers who want to keep the entire payment stack EU-owned, Adyen and Mollie are the most commonly cited options. Note that card-scheme data (Visa, Mastercard) always flows through US-incorporated card networks regardless of the payment processor; GDPR compliance here relies on Standard Contractual Clauses rather than data-residency. **Q: Is Shopware a good alternative to Shopify for EU buyers?** Shopware (Germany) is an EU-developed e-commerce platform with both a self-hostable open-source edition and a managed cloud offering. It is a frequently cited Shopify alternative in DACH and broader European markets, with a strong partner ecosystem and enterprise features. Shopware is EU-headquartered but has received US venture funding, which EU Vetted reflects in its ownership-signal rating. Shopify is US-incorporated and subject to the CLOUD Act directly. For organisations where US CLOUD Act exposure is a hard requirement, a fully EU-owned platform such as MyCashflow or a self-hosted Sylius deployment is the stronger option. ### Sovereign AI: https://euvetted.com/category/sovereign-ai Sovereign AI covers European AI models, inference APIs, and AI infrastructure designed to keep training data and inference workloads on EU soil, outside US CLOUD Act reach. For EU buyers, the question that matters is whether the AI provider is EU-owned and operates on EU-only infrastructure. Top EU options on EU Vetted include LightOn (France, EU-owned, no CLOUD Act exposure), Mistral AI (France, EU-HQ, EU-hosted, US-funded), and Aleph Alpha (Germany, EU-HQ, EU-hosted, US-funded). Editorial picks: - [Aleph Alpha](https://euvetted.com/p/aleph-alpha): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Black Forest Labs](https://euvetted.com/p/black-forest-labs): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Freepik](https://euvetted.com/p/freepik): hosted in Spain, CLOUD Act: minor, ownership: eu_owned - [Infomaniak AI Tools](https://euvetted.com/p/infomaniak-ai-tools): hosted in Switzerland, CLOUD Act: none, ownership: other - [LightOn](https://euvetted.com/p/lighton): hosted in France, CLOUD Act: none, ownership: eu_owned **Q: What is the best EU-owned AI model provider?** LightOn (France) is EU-owned and EU-hosted with no CLOUD Act exposure, making it the strictest-fit option in this catalogue for organisations requiring full sovereignty. Mistral AI (France) and Aleph Alpha (Germany) are also prominent EU-headquartered AI companies in the catalogue. Mistral AI and Aleph Alpha are listed with EU-headquartered but US-funded ownership signals, reflecting that both have received significant US venture capital, which affects their corporate-structure assessment. Black Forest Labs (Germany) focuses on image generation models and carries the same EU-HQ, US-funded ownership signal. **Q: Is there a GDPR-compliant alternative to OpenAI or Anthropic?** EU-incorporated AI providers that process inference workloads on EU-only infrastructure and publish a DPA covering their API service qualify as GDPR-compliant in their processing role. LightOn (France) meets this bar. Mistral AI (France) and Aleph Alpha (Germany) both offer EU-hosted API endpoints and publish DPAs. GDPR compliance for AI inference is an ongoing area of regulatory development, specifically around Article 22 obligations for automated decision-making and obligations under the EU AI Act (in force from 2025). Verify each provider's specific DPA against your use case. **Q: Does AI inference data fall under the US CLOUD Act?** When you send a prompt to an AI API, the inference request (which may contain proprietary business data, personal data, or confidential documents) is processed by the provider's infrastructure. If the AI provider is a US-incorporated company or has a US-incorporated parent, the CLOUD Act can in principle compel disclosure of data it processes or stores. EU-owned providers such as LightOn (France), which is EU-owned and EU-hosted with no CLOUD Act exposure, are not directly subject to that risk. Mistral AI and Aleph Alpha are EU-headquartered but have US investors; their CLOUD Act exposure depends on their corporate structure and any US parent entities. **Q: What is sovereign AI and why does it matter for European organisations?** Sovereign AI refers to AI infrastructure (models, inference APIs, training compute) that is controlled by domestic or European entities and operated on infrastructure outside the jurisdictional reach of foreign intelligence laws. For European organisations, it typically means using EU-incorporated and EU-hosted AI providers rather than US hyperscalers, so that prompts containing sensitive business data, personal data, or regulated information are not processed under US legal jurisdiction. The EU AI Act, SecNumCloud certification in France, and BSI guidance in Germany are all shaping the regulatory context for sovereign AI procurement. **Q: Can European AI models match the quality of US foundation models?** Model quality varies significantly by task, and direct benchmark comparisons are a moving target. Mistral AI's models have achieved competitive benchmark scores with US models of comparable parameter counts, particularly on European-language tasks. Aleph Alpha's Luminous models are designed for multilingual European contexts and enterprise document processing. LightOn focuses on retrieval-augmented generation infrastructure rather than foundation model development. For many enterprise use cases (document classification, summarisation, structured data extraction), EU models are a viable alternative; for advanced reasoning or multimodal tasks, the gap may be more pronounced. Evaluate against your specific use case rather than general benchmarks. **Q: What is the EU AI Act and how does it affect AI procurement?** The EU AI Act is a risk-based regulatory framework that classifies AI systems by risk level: from minimal risk (most applications) to high risk (medical devices, recruitment tools, critical infrastructure) to prohibited (social scoring, real-time biometric surveillance in public spaces). High-risk AI systems require conformity assessments, technical documentation, and human oversight mechanisms before deployment. As an AI buyer, you bear obligations as a deployer under the Act regardless of where the AI provider is based, but EU-based providers are typically better positioned to provide the required documentation and contractual commitments. The Act's high-risk provisions began applying in August 2026 for most categories. **Q: Is Mistral AI a private-data-safe alternative to OpenAI?** Mistral AI (France) offers EU-hosted API endpoints and publishes a DPA covering its La Plateforme service. Prompts sent to Mistral's API are processed on EU infrastructure, which avoids direct US CLOUD Act exposure, in principle. However, Mistral AI has received significant US and European venture funding, and EU Vetted rates its ownership signal as eu_hq_us_funded. For organisations where strict EU ownership is required, LightOn (France), which is EU-owned and EU-hosted with no CLOUD Act exposure, is the higher-sovereignty option in this catalogue. For organisations where EU-hosted processing is the primary requirement and US funding is acceptable, Mistral AI's enterprise API tier is a frequently cited option in EU markets. ### Git hosting: https://euvetted.com/category/git-hosting Git hosting platforms hold an organisation's source code, CI secrets, and issue history, some of its most sensitive engineering assets. For EU buyers the sovereignty question is who operates the forge and whether the code can be reached under the US CLOUD Act. The two market incumbents, GitHub (owned by Microsoft, US) and GitLab.com (GitLab Inc., US), both carry direct CLOUD Act exposure. The strongest European options on EU Vetted are Codeberg (Germany, non-profit, EU-hosted, free) and Codebahn (Swedish operator, France-hosted, paid and supported with a public DPA), both built on the open-source Forgejo engine. Editorial picks: - [Codebahn](https://euvetted.com/p/codebahn): hosted in France, CLOUD Act: none, ownership: eu_owned - [Codeberg](https://euvetted.com/p/codeberg): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [GitLab by Stackhero](https://euvetted.com/p/stackhero-gitlab): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Planio](https://euvetted.com/p/planio): hosted in Germany, CLOUD Act: none, ownership: eu_owned **Q: What is the best EU-hosted GitHub alternative?** Codeberg (Germany) and Codebahn (Swedish operator, France-hosted) are the two clearest picks in the EU Vetted catalogue. Both run the open-source Forgejo engine and keep all data inside the EU with no US legal entity in the path: Codeberg's CLOUD Act signal is [[codeberg.cloud_act]] and Codebahn's is [[codebahn.cloud_act]]. Codeberg is a free non-profit forge best suited to open-source projects; Codebahn is a paid, commercially supported service with a contractual DPA and hosted CI, better suited to businesses. **Q: Is GitLab a European alternative to GitHub?** No. GitLab Inc. is US-incorporated (Delaware, NASDAQ: GTLB), so GitLab.com carries the same direct CLOUD Act exposure as Microsoft-owned GitHub. GitLab is a second US incumbent, not an EU alternative. Self-hosting the open-source GitLab Community Edition on EU infrastructure is a different posture, because there the operator is you, not GitLab Inc. **Q: Does source code hosted on GitHub fall under the US CLOUD Act?** If the forge is operated by a US-incorporated company, yes: the CLOUD Act can in principle compel production of repository content, CI logs, and metadata regardless of where the servers sit. GitHub (Microsoft) and GitLab.com (GitLab Inc.) are both subject. EU-operated forges such as Codeberg (Germany) and Codebahn (Sweden) are not directly subject, and their exposure is recorded as [[codeberg.cloud_act]] and [[codebahn.cloud_act]] respectively. **Q: What is Forgejo, and why does it matter here?** Forgejo is open-source (GPL-3.0) Git forge software, a hard fork of Gitea created in 2022 and governed by Codeberg e.V. in Germany. It matters because both Codeberg and Codebahn run it: the same engine that powers the hosted services can be self-hosted on your own EU infrastructure, so there is always a zero-counterparty escape hatch and no proprietary lock-in. **Q: Should I pick a free or a paid EU git host?** Codeberg is free and donation-funded as a non-profit, which is ideal for open-source and personal projects, but it does not sign a commercial DPA or publish a formal sub-processors list. Codebahn is paid from [[codebahn.price_from]] per month, with a public DPA, a named all-EU sub-processor chain, hosted CI, and support, which is the better fit when you need contractual guarantees for a business. **Q: Can I self-host EU git hosting instead of using a SaaS?** Yes. Forgejo and Gitea (both open source) and GitLab Community Edition run on any EU infrastructure such as Hetzner, OVHcloud, Scaleway, IONOS, or STACKIT. Self-hosting removes the platform operator as a third-party processor entirely, which is the strongest posture for code that contains trade secrets or regulated data. The trade-off is that you take on operations, backups, and security patching yourself. ## Products (221 verified profiles) ### addy.io: https://euvetted.com/p/addy-io - Website: https://addy.io - Category: Email aliasing - Country of incorporation: United Kingdom - Hosting country: Netherlands - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: freemium (from €0.87/month) - Founded: 2019 - Sub-processors list: https://addy.io/privacy/ - Last verified: 2026-07-10 England-and-Wales-governed email-alias service (formerly AnonAddy), hosted in the Netherlands; unlimited aliases, PGP-encrypted forwarding and reply-from-alias on paid tiers, open-source and self-hostable. Its operating legal entity is not named in its own Terms or Privacy Policy. addy.io (renamed from AnonAddy in 2024) was created in 2019 by developer Will Browning and offers open-source email aliasing under AGPL-3.0, self-hostable via Docker (`github.com/anonaddy/anonaddy`) or usable as a hosted service. Neither the Terms of Use nor the Privacy Policy on addy.io names an operating legal entity, company number, or registered address; the Terms state only that they "shall be governed by and construed in accordance with the law of England and Wales". Public sources disagree on who operates the service: a public comparison repository lists the jurisdiction as "Netherlands", while other web results describe the operator as "Addy Pty Ltd" in Geelong, Australia; neither claim is corroborated by any addy.io primary source, so this listing records the legal entity and country_iso as not established. The Privacy Policy states servers are located in the Netherlands (UpCloud); named third parties are Stripe and NOWPayments for payments, Amazon SES for newsletter delivery, and Cloudflare Turnstile for captcha. Free, Lite ($1/month billed yearly) and Pro ($3/month billed annually, or $4/month billed monthly) tiers scale from 10 to unlimited aliases; Lite and Pro add custom domains, catch-all (enabled by default on custom domains), PGP-encrypted forwarding (bring-your-own GPG/OpenPGP key), and reply-from-alias, the last of which is deliberately withheld from the Free plan to curb spam and abuse. addy.io passed an independent security audit by Securitum in September 2023 with no significant vulnerabilities found, though this is a one-off audit rather than a recurring certification. **Compliance rationale:** addy.io's own Terms of Use state governing law as "the law of England and Wales", but neither the Terms nor the Privacy Policy name an operating legal entity, company number, or registered address anywhere on the site. Public sources disagree on who actually operates the service (a comparison repository says "Netherlands", other web results say "Addy Pty Ltd" in Geelong, Australia), and neither claim is corroborated by any addy.io primary source, so country_iso is left null and ownership_signal is other. Mailbox/alias data at rest sits on servers in the Netherlands (UpCloud); Stripe and NOWPayments handle payments, Amazon SES sends the newsletter, and Cloudflare Turnstile is a login captcha, none of which are the primary data-at-rest path, so CLOUD Act exposure is assessed as minor rather than material. The determining factor for compliance_score is that no DPA is published anywhere on the site, which caps this listing at 3/5 regardless of the otherwise reasonable EU hosting posture. **Sub-processors mapped:** 5 total, 3 US-owned - Amazon Simple Email Service (SES) (United States): Newsletter delivery [US-owned] - Cloudflare Turnstile (United States): Captcha / bot protection on login and registration [US-owned] - Stripe (United States): Card payment processing [US-owned] - NOWPayments (Netherlands): Cryptocurrency payment processing (yearly plans) - UpCloud (Finland): Hosting of alias and forwarded-email data at rest (servers located in the Netherlands) ### AdGuard Mail: https://euvetted.com/p/adguard-mail - Website: https://adguard-mail.com - Category: Email aliasing - Country of incorporation: Cyprus - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: freemium (from €2.99/month) - Founded: 2024 - Sub-processors list: https://adguard-mail.com/en/privacy.html - Last verified: 2026-07-10 Cyprus-registered (AdGuard Software Ltd) free/paid email-alias and temp-mail service that reached general availability (v1.0) in June 2025; core forwarding runs on Amazon SES (US), and no DPA is published. AdGuard Mail is a product of **AdGuard Software Limited**, a Cyprus-registered company (HE 332952, registered address Anexartesias and Athinon 79, Nora Court, Flat/Office 203-205, 3040 Limassol) whose own EULA sets Cyprus as the governing jurisdiction. AdGuard's own company pages state the company was "founded in 2009, with the HQ in Limassol and the team of experienced specialists working from all around the globe", without further origin detail. Widely cited secondary sources (Wikipedia and multiple company-profile aggregators) describe AdGuard as originally founded in Moscow, Russia in 2009, relocating its headquarters to Cyprus around 2014; AdGuard's own official pages do not mention this, and no primary source found by this review corroborates or refutes it beyond the secondary accounts, so the origin claim is recorded here as unconfirmed by AdGuard itself but not omitted. Current beneficial ownership beyond the Cyprus registration (third-party aggregators report one undisclosed institutional investor) was not established from any primary source. The product itself launched in beta in December 2024 and reached general availability at version 1.0 in June 2025, adding reply-from-alias and additional alias domains behind a paid subscription; it is no longer in beta. The Free plan offers 10 aliases, 1 recipient and 2,000 forwarded emails per month from a single shared alias domain; the paid Full plan (from €2.99/month, or €16.80/year) raises this to 1,000 aliases, 50 recipients, unlimited forwarding, reply-from-alias and a choice of 3 alias domains, none of which are user-owned custom domains. The Privacy Policy names Amazon SES as the service used for email forwarding, meaning the product's core function routes through US-owned infrastructure, alongside Paddle.com Market Ltd and PayPro Global, Inc. for payments. No DPA or sub-processors list beyond the general Privacy Policy is published. **Compliance rationale:** AdGuard Mail is operated by **AdGuard Software Limited**, a Cyprus-registered company (HE 332952, Limassol), whose own EULA sets Cyprus as the governing jurisdiction. AdGuard's own company pages state only a 2009 Cyprus founding; widely cited secondary sources (Wikipedia, company-profile aggregators) describe the company as originally founded in Moscow, Russia in 2009 before relocating headquarters to Cyprus around 2014, a detail AdGuard's own materials do not mention or corroborate, and current beneficial ownership beyond the Cyprus registration was not established from any primary source. Cyprus is an EU member state, but with the founding-control origin unresolved this listing takes ownership_signal: other rather than eu_owned. The determining factor for compliance_score is twofold: no DPA is published anywhere, and the Privacy Policy names **Amazon SES**, a US-owned service, as the mechanism used for email forwarding, i.e. the product's core function (not an ancillary one) routes through US infrastructure, which the rubric treats as material CLOUD Act exposure rather than minor. **Sub-processors mapped:** 3 total, 1 US-owned - Amazon Simple Email Service (SES) (United States): Email forwarding, the product's core function [US-owned] - Paddle.com Market Ltd (United Kingdom): Payment processing and merchant of record - PayPro Global, Inc. (Canada): Payment processing ### Adyen: https://euvetted.com/p/adyen - Website: https://www.adyen.com - Category: Payments - Country of incorporation: Netherlands - Hosting country: Netherlands (Amsterdam) - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid - Founded: 2006 - DPA: https://www.adyen.com/legal/data-processing-agreement - Sub-processors list: https://www.adyen.com/legal/list-of-adyen-subprocessors - Last verified: 2026-05-18 Dutch publicly-listed payments giant (Euronext Amsterdam), DNB-licensed credit institution + EU/UK/US banking licences; €1.4T processed/yr. Adyen is the Amsterdam-headquartered Dutch payments giant operated by Adyen N.V., publicly listed on **Euronext Amsterdam** since its June 2018 IPO and licensed by **De Nederlandsche Bank** (DNB) as a credit institution with passporting rights across the EEA, plus separate banking licences in the United Kingdom and the United States. Founded in 2006 by Pieter van der Does and Arnout Schuijff, the company processes more than **€1.4 trillion** in annual transaction volume across 200+ local payment methods, 150+ currencies, and 80+ countries from 29 global offices, supporting customer-base highlights such as Uber, eBay, Spotify, Microsoft, McDonald's, and H&M. As of April 2026 the market capitalisation stands at approximately €27B with €2.36B revenue in 2025 and 53% EBITDA margins: financial metrics that put it firmly in the strategic-EU-infrastructure tier alongside ASML and SAP. For an EU-sovereignty audit Adyen sits at the top of the payments category. The operating entity is a Dutch credit institution under direct DNB supervision; the public-listing structure on Euronext Amsterdam means ownership is broad institutional plus retail rather than concentrated in any US private-equity or sovereign-fund hands; there is no US-PE acquisition or majority on the cap table. The DPA / privacy statement was refreshed on 4 August 2025 with explicit references to Standard Contractual Clauses for cross-border intragroup transfers (Adyen runs subsidiaries in the US, UK, APAC, and LATAM to support local merchant acquisition, all operating under Dutch parent control). Sub-processors named include cloud providers, identity-verification firms, payment schemes (Visa, Mastercard, necessarily US-headquartered but governed by their own DPA and SCC framework), and CRM/marketing-tooling providers. The Dutch banking-law regime governs EU customer payment data with strong primary-jurisdiction Dutch oversight. Pricing is **Interchange++** per-transaction with no monthly, integration, or closure fees: US$0.13 base fee + variable component (e.g. Visa/Mastercard 0.60% + Interchange++ globally, Klarna 4.29% + US$0.30 in US/CA, Alipay 3%). Custom pricing is available for volume customers (the typical Adyen sales motion). Best fit: enterprise and large-mid-market merchants, marketplaces, platforms (Embedded Finance for SaaS), global e-commerce brands needing unified acquiring across continents, and any EU procurement-grade buyer that wants a publicly-listed Dutch credit institution rather than a venture-funded payment startup. Together with Mollie, Adyen is the canonical Dutch fintech anchor and a strategic-sovereignty pillar of EU payments. **Compliance rationale:** Adyen N.V. is an Amsterdam-headquartered Dutch credit institution, publicly listed on Euronext Amsterdam since 2018 (`ownership_signal: eu_owned`), holding a full **De Nederlandsche Bank** banking licence + EU + UK + US banking licences, processing €1.4T annually for the world's leading enterprises (29 global offices, 99.999% historical uptime); ownership is broad-public via Euronext Amsterdam (no US-PE controlling stake), the Dutch banking-law regime governs EU customer payment data, the privacy statement (updated August 2025) covers cross-Atlantic intragroup transfers under Standard Contractual Clauses, a public DPA (April 2025) and named sub-processors list are accessible. Only `cloud_act_exposure: minor` applies, from the parallel US banking subsidiary and unavoidable Visa/Mastercard scheme-side dependencies. **Sub-processors mapped:** 11 total, 0 US-owned - Adyen Australia Pty Ltd (Australia): Payment services (Australia subsidiary) - Adyen Canada Ltd. (Canada): Payment services (Canada subsidiary) - Adyen do Brasil Instituição de Pagamento Ltda. (Brazil): Payment services (Brazil subsidiary) - Adyen India Tech Hub Pvt. Ltd. (India): Technology services (India subsidiary) - Adyen India Technology Services Pvt. Ltd. (India): Technology and payment services (India subsidiary) - Adyen Japan K.K. (Japan): Payment operations (Japan subsidiary) - Adyen MEA FZ-LLC (United Arab Emirates): Payment processing (Middle East / UAE subsidiary) - Adyen Mexico SA de CV (Mexico): Payment processing (Mexico subsidiary) - Adyen N.V. (San Francisco Branch) (United States): Payment operations (US branch of Adyen N.V.) - Adyen N.V. UK Branch (United Kingdom): Payment processing operations (intragroup branch of Adyen N.V.) - Adyen Singapore Pte. Ltd. (Singapore): Payment processing (Singapore subsidiary) ### AirVPN: https://euvetted.com/p/airvpn - Website: https://airvpn.org - Category: VPN - Country of incorporation: Italy - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €7/month) - Founded: 2010 - Last verified: 2026-05-11 Italian hacktivist-founded VPN (Perugia, 2010), no-logs, port forwarding, but no longer serves Italian residents (Piracy Shield). AirVPN is an Italian privacy-focused VPN founded in 2010 by a Perugia-based hacktivist collective and owned today by Paolo Brini. The service is intentionally small, unfunded, and operated outside the venture-backed VPN consolidator economy that has absorbed most of the brand-name competition (NordVPN, ExpressVPN, Surfshark, etc.). The product targets technically-fluent users who care about hard privacy guarantees: no activity logs, OpenVPN and WireGuard multi-protocol support, IPv6 support, port forwarding, custom DNS, multi-hop, gigabit servers, and detailed real-time server-status pages. For an EU-sovereignty audit AirVPN is structurally clean (Italian-incorporated, no US ties, no US-VC ownership, no US sub-processors on the customer-data path), and the no-logs claim is backed by an over-a-decade track record without security scandals. The catch, and the reason this listing carries a hard editorial caveat, is that **on 19 February 2024 AirVPN terminated service for residents of Italy** in direct response to Italy's "Piracy Shield" blocking regime. The Italian government mandates that ISPs, DNS resolvers, and intermediaries block flagged pirate-IP addresses within thirty minutes of alert without prior judicial review; AirVPN deemed the requirements an unacceptable risk for overblocking and human-rights violations, and new users must now declare that they are not Italian residents. So while the corporate posture is Italian and EU-controlled, the customer-availability story is unusual: AirVPN serves EU customers from every member state **except Italy**. Pricing is straightforward: a 3-day trial starts at €2; monthly plans around €7; 3-year heavily discounted (~€1.50/month equivalent). Bitcoin and other cryptocurrencies are accepted alongside cards. Best fit: privacy-maximalist users across the EU (excluding Italy), torrent-friendly use cases, and anyone wanting a small, founder-controlled provider with a documented activist posture. The Italian-resident blockade is itself a procurement signal: both as evidence of the vendor's willingness to walk away from a regime it disagrees with, and as a practical exclusion for any Italian buyer. **Compliance rationale:** AirVPN is an Italian-incorporated, founder-controlled (Paolo Brini), unfunded VPN service launched in 2010 by a hacktivist collective in Perugia with a more-than-decade record of no logging or security scandals: strong no-logs posture, transparency reports, port forwarding, multi-protocol. EU-owned, EU-incorporated, no US ties, no CLOUD Act exposure. Editorial flag: **AirVPN terminated service for residents of Italy on 19 February 2024** in protest of the Italian ''Piracy Shield'' blocking regime, which is a structural procurement flag worth surfacing. Signal gap: AirVPN does not publish a DPA. Only ToS and a privacy notice are available, with no processor agreement for EU buyers to self-serve. ### Aleph Alpha: https://euvetted.com/p/aleph-alpha - Website: https://aleph-alpha.com - Category: Sovereign AI - Country of incorporation: Germany - Hosting country: Germany (Heidelberg) - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2019 - Last verified: 2026-05-11 Heidelberg-based sovereign-AI lab (Pharia platform); merger with Canadian Cohere announced April 2026: Aleph Alpha shareholders to receive ~10% of combined ~$20B entity. Aleph Alpha is a Heidelberg-based German sovereign-AI company founded in 2019 to build "specialised LLMs (SLLMs) for European organisations", large language models that operate inside the customer's security perimeter and meet EU regulatory, defence, and public-sector procurement requirements. Co-founders include Samuel Weinbach (Co-Chief Research Officer); offices in Heidelberg (HQ), Berlin, Bayreuth, and Munich. Anchor investors pre-merger include **Schwarz Group** (Lidl / Kaufland parent, also the operator of STACKIT sovereign cloud), **Bosch Ventures**, **SAP**, and the **German Federal Ministry for Economic Affairs (BMWi)**, making Aleph Alpha until April 2026 the most-anchored German-sovereign-AI cap table. The strategic landscape changed on **24 April 2026**, when Toronto-based **Cohere announced a merger with Aleph Alpha** to form a transatlantic sovereign-AI group valued at approximately US$20B. The deal terms reported by Handelsblatt: Cohere shareholders receive ~90% of the combined entity, Aleph Alpha shareholders ~10% (Cohere's US$7B pre-deal valuation vs Aleph Alpha's US$3B book value); **Schwarz Group commits US$600M to Cohere's Series E**, the largest single cheque in Cohere's history, to backstop the sovereign-AI offering that will be delivered via STACKIT. The combined company will target regulated sectors (public sector, finance, defence, energy, manufacturing, telecommunications, healthcare) with Aleph Alpha's German anchor relationships intact through STACKIT delivery. The merger is subject to regulatory approval; closing date not publicly confirmed at audit time. For the directory's strict-ownership stance the implication is significant: pre-merger Aleph Alpha was `eu_owned` (German LLC with German + EU anchor investors); post-merger the entity is a subsidiary of Cohere, a Canadian-headquartered AI company with heavy US-VC funding history (Salesforce Ventures, NVIDIA, etc.), and **Aleph Alpha shareholders will hold only ~10% of the combined group**. The listing is therefore moved to `eu_hq_us_funded` with material CLOUD Act exposure pending the transaction close. The on-premise Pharia platform that runs inside the customer firewall continues to eliminate CLOUD Act exposure for self-hosting buyers regardless of the parent-entity change, and Schwarz Group's STACKIT partnership ensures continued sovereign-EU-cloud delivery for the on-premise-adjacent hybrid use case. Best fit: regulated DACH buyers, defence and public-sector procurement, and any organisation that wants to deploy LLM inference behind the customer firewall on sovereign infrastructure, but procurement-grade buyers signing multi-year commitments should monitor the merger close before committing to long-term contracts. **Compliance rationale:** Aleph Alpha (Heidelberg, Germany; founded 2019; offices in Berlin, Bayreuth, Munich) was structured as Germany's flagship sovereign AI vendor with anchor investors Schwarz Group, Bosch Ventures, SAP, and the German Federal Ministry for Economic Affairs. On **24 April 2026 Toronto-based Cohere announced a merger that gives Cohere shareholders ~90% of the combined ~US$20B entity, with Aleph Alpha shareholders receiving ~10%; Schwarz Group is committing US$600M to Cohere's Series E** to back the sovereign-AI delivery via STACKIT post-close. Pre-merger Aleph Alpha was structurally `eu_owned`; the imminent merger to a Canada-headquartered AI company with heavy US-VC funding shifts the listing to `eu_hq_us_funded` with material CLOUD Act exposure, pending re-verification after the merger closes. No public DPA or sub-processors list found at audit; certifications unconfirmed. ### AliasVault: https://euvetted.com/p/aliasvault - Website: https://www.aliasvault.com - Category: Email aliasing - Country of incorporation: Netherlands - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: free - Founded: 2024 - Sub-processors list: https://www.aliasvault.com/privacy-policy - Last verified: 2026-07-09 Dutch sole proprietorship (XIVISOFT / Leendert de Borst), open-source password manager with built-in receive-only email aliases; email aliases cannot send or reply, only receive. Free cloud tier hosted in Germany, AGPL-3.0 and fully self-hostable. AliasVault is a product of **XIVISOFT**, a Dutch sole proprietorship (eenmanszaak) operated by founder Leendert de Borst, KVK (Dutch Chamber of Commerce) number 51592193; the registered address is stated as "available upon request" rather than published, and no VAT number is stated. It combines a zero-knowledge password manager with built-in email-alias generation: every saved identity gets its own alias inbox inside the app. The official cloud offering (app.aliasvault.com) runs on the operator's own servers in Germany, within the EU; the Privacy Policy states this is "fully compliant with GDPR". The single most important buying fact is a structural limitation stated on AliasVault's own homepage: "Email aliases are receive-only, meaning you cannot send or reply to emails from your aliases", with a 10MB size limit on incoming mail. The core product is free and the vendor states it "will always remain that way"; Premium and Family tiers (higher limits, VIP alias domains, custom domains, automatic backups) are announced but not yet live as of this review. The client and server are open source under AGPL-3.0 (`github.com/aliasvault/aliasvault`, most recent release 0.30.0 on 2026-07-02) and fully self-hostable via Docker, which is also the only way to get a custom domain today, since none is available on the free cloud tier. No DPA or sub-processors list is published; the only named third party in the Privacy Policy is a self-hosted instance of Plausible.io analytics, run on AliasVault's own servers rather than Plausible's own hosted service. **Compliance rationale:** AliasVault is a product of **XIVISOFT**, a Dutch sole proprietorship (eenmanszaak) operated by founder Leendert de Borst, KVK 51592193 (vendor-stated, not independently cross-checked against the Dutch register); the registered address is stated only as "available upon request". The official cloud offering runs on the operator's own servers in Germany, within the EU, and the AGPL-3.0 source is fully self-hostable via Docker. No third-party trackers or US sub-processors are named in the Privacy Policy (a self-hosted Plausible.io instance is the only named service, run on AliasVault's own servers), so CLOUD Act exposure is assessed as none. The determining factor holding compliance_score at 3/5 despite the clean eu_owned and hosting profile is that **no DPA and no sub-processors list are published**, which this directory's rubric caps at 3/5 regardless of an otherwise clean sovereignty profile; AliasVault is also a young (2024-founded), single-founder operation without a formal customer-facing data-processing contract yet. ### Alma: https://euvetted.com/p/alma - Website: https://almapay.com - Category: Payments - Country of incorporation: France - Hosting country: France - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2019 - Last verified: 2026-05-21 Paris-area French BNPL for merchants: 2/3/4/10/12 installments + Pay Later; 21,800+ merchants across 8 EU countries; Alma SAS, EU-owned. Alma is a French BNPL (buy-now-pay-later) payment solution operated by **Alma SAS** (176 Avenue Charles de Gaulle, 92200 Neuilly-sur-Seine, France; RCS Nanterre 839 100 575), founded in 2019 by Louis Chatriot. The product enables merchants to offer customers payment in 2, 3, or 4 interest-free installments, medium-term financing in 10 or 12 installments, and deferred "Pay Later" options at 15 or 30 days, covering online, in-store (via payment terminal integrations including Adyen and Ingenico), and call-centre sales channels. As of 2026 Alma serves 21,800+ merchants across France, Germany, Belgium, Spain, Italy, Luxembourg, the Netherlands, and Portugal, with a notable customer list including Maisons du Monde, Nature & Découvertes, Maje, Promod, Etam, Lancel, and Alain Afflelou. For an EU-sovereignty audit Alma is the cleanest French corporate in the BNPL category, incorporated as a French SAS with a French registered address and no disclosed US parent or US-PE majority stake. The ownership-risk element is the investor base: the company raised €210M in 2022 (round led by Eurazeo Growth and Cathay Innovation, both French/Franco-Asian with EU-anchored management, alongside earlier backers including Idinvest Partners). The cap table is predominantly French/European VC, which keeps `ownership_signal: eu_owned` under the directory's taxonomy. The material CLOUD Act risk comes from infrastructure: the legal notice explicitly names **Google Cloud Platform** as the hosting provider (8 rue de Londres, 75009 Paris, the Paris GCP region address), and GCP is a US-owned service regardless of the EU region. No public DPA or sub-processors list was found on accessible pages at audit. Pricing is commission-based per transaction with no monthly fee; rates vary by installment type and market. PCI DSS Level 1 certification is confirmed for the payment-processing partner. Best fit: French and broader EU merchants wanting a BNPL-first checkout experience with a European legal entity: particularly retail, furniture, fashion, and opticians already represented in the customer base. **Compliance rationale:** Alma SAS (Neuilly-sur-Seine, France; RCS Nanterre 839 100 575) is an EU-incorporated French BNPL specialist serving 21,800+ merchants across 8 European countries (`ownership_signal: eu_owned`), but the legal notice confirms hosting on Google Cloud Platform (US-owned, Paris region): `cloud_act_exposure: material`; no public DPA or sub-processors list accessible at audit. ### Anytype: https://euvetted.com/p/anytype - Website: https://anytype.io - Category: Docs & wikis - Country of incorporation: Germany - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium - Founded: 2019 - Sub-processors list: https://anytype.io/app_privacy/ - Last verified: 2026-05-11 Berlin-based local-first peer-to-peer E2E-encrypted knowledge OS (Anytype, 2019); Any Source Available License; data lives on user device. Anytype is a Berlin-headquartered German knowledge-management platform built around an unusual architecture in the docs-and-wikis category: **local-first, peer-to-peer synchronization, end-to-end encryption**. Customer data lives on the user's device (macOS, Windows, Linux, plus mobile) with peer-to-peer sync between the user's own devices and any team / shared workspaces. The central Anytype servers never hold plaintext customer data; encryption is end-to-end with customer-controlled keys. The product positions itself as an offline-first, private alternative to Notion / Obsidian / Roam Research, marketed under the tagline "A safe haven for digital collaboration." Source code is published on GitHub under the **Any Source Available License 1.0**, a source-available licence with an anti-competitive-hosting clause that lets customers inspect, audit, and self-modify the codebase but prevents running a competing managed service. The company has opened repositories to its **100,000-strong community** and accumulated 7,000+ GitHub stars across the various repositories (anyproto/anytype-ts and others). Funding totals approximately **€13.4M** raised through the Berlin startup ecosystem; specific investor list not surfaced at audit time but the company is reported as Berlin-based. For an EU-sovereignty audit Anytype scores at the top of the docs-and-wikis category. The local-first architecture is structurally the strongest data-residency posture available: customer data is on the customer's device by default, never in plaintext on any cloud. Berlin legal entity, German jurisdiction, no US-VC control on record, source-available licence (with reasonable restrictions). The **MVP shortlist tagged Anytype as UK; corrected to DE based on the Berlin operation**, the sixth country mismatch in the directory's source shortlist. Best fit: privacy-maximalist knowledge workers, researchers, journalists, and EU SMBs / agencies wanting a Notion alternative with offline + E2E architecture; teams replacing Obsidian or Roam with a multi-device sync option that doesn't depend on a central cloud. **Compliance rationale:** Anytype is a **Berlin-based** local-first, peer-to-peer, end-to-end-encrypted knowledge OS for macOS / Windows / Linux. Source code published under **Any Source Available License 1.0** (source-available with anti-competitive-hosting clause; the company opened repositories to its 100,000-strong community); 7,000+ GitHub stars. **Local-first architecture means data lives on the user's device** with peer-to-peer sync; no central server holds plaintext customer data. Funded through €13.4M raise; Berlin German legal entity. Signals: EU-owned (German entity), end-to-end encrypted (local-first; central sync server cannot read user data), no CLOUD Act exposure, source-available codebase. Gap: no publicly accessible DPA. Only privacy policies and legal pages are available, with no processor agreement for EU buyers to self-serve; no formal sub-processors list. **MVP shortlist tagged Anytype as UK; corrected to DE based on the Berlin operation.** ### Aruba Cloud: https://euvetted.com/p/aruba-cloud - Website: https://www.arubacloud.com - Category: Cloud & hosting - Country of incorporation: Italy - Hosting country: Italy (Arezzo) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €1/month) - Founded: 1994 - Certifications: ISO27001, ISO27017, ISO27018 - DPA: https://www.arubacloud.com/terms-and-conditions/supply-services-aruba-cloud-and-data-center - Last verified: 2026-05-18 Italian sovereign cloud (Aruba S.p.A.), 4 Italian DCs (Arezzo/Bergamo/Rome), ACN-qualified up to AI3/QC3 for public administration. Aruba Cloud is the cloud division of Aruba S.p.A., Italy's largest privately-held cloud and web-services group, founded in 1994 and headquartered in Ponte San Pietro (BG), Italy (P.IVA 01573850516, C.F. 04552920482). The company operates proprietary infrastructure across four Italian data centres: IT1 and IT2 in Arezzo (the unique twin-DC configuration only a few kilometres apart that enables low-latency redundancy), IT3 in Bergamo (the flagship Global Cloud Data Centre campus), and IT4 in Rome. IT1 carries the highest Rating 4 ANSI/TIA-942-C-2024 data-centre certification. Compliance posture is among the strongest in Europe for Italian public-sector procurement. Aruba Cloud is qualified by Italy's **ACN** (Agenzia per la Cybersicurezza Nazionale / National Cybersecurity Agency) at the **AI3** level for infrastructure and **QC3** level for services, the qualifications required by the Italian Public Administration (PA) to host critical and strategic data. Certifications include ISO/IEC 27001, ISO 27017, ISO 27018, ISO 27035, and ISO 9001 at the management-system level. The company is a **CISPE** Code of Conduct signatory (the European cloud-infrastructure association founded explicitly around GDPR alignment), **DORA**-compliant for EU financial-services operational resilience, and **NIS 2**-compliant. The product is a VMware **Pinnacle Partner** (the highest VMware partnership tier) and offers data-sovereignty positioning under the explicit promise that "your data stays in Italy." Aruba S.p.A. also operates the .it domain registry, giving it deep ties to Italian internet infrastructure. The product surface covers bare metal, VPS, public cloud compute, VMware cloud, object storage, and managed services. Pricing is highly competitive: Cloud Server Pro starts from roughly €1/month for the smallest entry tier (the headline "Cloud Server PRO from €1/month" offer is a long-running positioning). Best fit: Italian SMBs, agencies, the entire Italian public-sector procurement chain (ACN-qualified workloads), VMware shops in Italy and Southern Europe, regulated industries (financial services post-DORA), and any EU buyer needing geographic diversity from DACH-clustered alternatives. Together with Hetzner (DE), OVHcloud (FR), Scaleway (FR), IONOS (DE), UpCloud (FI), STACKIT (DE), Cleura (SE), Exoscale (CH), T Cloud Public (DE), and Stackscale (ES), Aruba Cloud completes the 11-vendor procurement-grade EU hyperscaler-alternative shortlist. **Compliance rationale:** Aruba Cloud is the cloud division of Aruba S.p.A. (Ponte San Pietro, BG, Italy; P.IVA 01573850516), Italy''s largest privately-held cloud and hosting provider: proprietary infrastructure with four Italian data centres in Arezzo (IT1 + IT2), Bergamo (IT3), and Rome (IT4), Rating 4 ANSI/TIA-942-C at IT1 (the highest tier), ISO/IEC 27001 + 27017 + 27018 + 27035 certifications, qualified by Italy''s **ACN** (National Cybersecurity Agency) up to **AI3 / QC3** levels for IaaS / PaaS / SaaS, CISPE Code of Conduct, DORA and NIS 2 compliant; EU-owned and EU-hosted with no CLOUD Act exposure, and an exceptionally strong certification profile; however, Aruba does not publish a standalone DPA: data-processing terms are buried in the general T&Cs and a separate data-processing agreement is only obtainable by contacting dpo@aruba.it, which is a transparency gap relative to other directory entries. ### AzireVPN: https://euvetted.com/p/azirevpn - Website: https://www.azirevpn.com - Category: VPN - Country of incorporation: Sweden - Ownership signal: us_owned - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2012 - Last verified: 2026-05-15 Swedish privacy VPN (Stockholm, est. 2012): Blind Operator, RAM-only, audited no-logs; acquired by Malwarebytes (US) 7 Nov 2024. AzireVPN was founded in Stockholm, Sweden in 2012 and built a strong reputation in the privacy-VPN niche on three structural choices: it owned 100% of its server hardware, ran a diskless infrastructure with the OS in RAM, and developed the **"Blind Operator" security model**: a tool that disables both remote and local access to its servers, preventing any operator (including AzireVPN's own staff) from observing customer traffic. The no-logs policy was independently third-party-audited in 2026, the company published a monthly **warrant canary** (api.azirevpn.com/v3/warrantcanary), and maintained regular public transparency reports. By every structural measure that matters in the privacy-VPN category (EU-owned, EU-incorporated, owned hardware, diskless, audited no-logs, warrant canary), AzireVPN was a clean sovereignty pick before the acquisition. **The ownership story changed on 7 November 2024**, when Malwarebytes (a Santa Clara, California cybersecurity company) announced that it had acquired AzireVPN. Financial terms were not disclosed. Malwarebytes' stated plan is to integrate AzireVPN's VPN technologies and the Blind Operator IP into its own product lines, and the AzireVPN brand continues to operate. But the corporate facts have shifted: the **ultimate parent is now a US-incorporated company**, which under this directory's rubric puts CLOUD Act exposure at `material` regardless of where the Swedish operating entity sits or where the servers physically live. AzireVPN's homepage now describes itself as "part of Malwarebytes, a global leader in real-time cyber protection." AzireVPN remains in this directory because the underlying privacy engineering is genuinely strong and the user community values it, but it is listed as a **privacy-conscious option with an ownership-watch flag**, not as an EU-sovereignty pick. Buyers who specifically need a clean EU-or-Swiss ownership chain should now prefer Mullvad (founder-owned Swedish AB), OVPN (Swedish AB, owned hardware, court-proven no-logs), ProtonVPN (Swiss Foundation) or IVPN, all elsewhere in this directory. Pricing was not directly captured at audit; the AzireVPN /pricing page is the canonical source. UI is English-first. **Compliance rationale:** AzireVPN was a top-tier privacy-pick Swedish VPN: founded Stockholm 2012, fully-owned diskless RAM-only servers, 'Blind Operator' security model that disables both remote and local access, monthly warrant canary, third-party-audited no-logs, regular transparency reports. But on **7 November 2024 it was acquired by Malwarebytes (Santa Clara, California, USA)** and is now operated as part of a US-incorporated cybersecurity vendor; the Swedish operating entity and engineering team continue but the **ultimate parent is now US**, which puts CLOUD Act exposure at `material` and removes what had been an EU-ownership signal. Listed as a privacy-conscious option with a clear ownership-watch note rather than a sovereignty pick. ### Baserow: https://euvetted.com/p/baserow - Website: https://baserow.io - Category: Project management - Country of incorporation: Netherlands - Hosting country: Spain - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium - Founded: 2020 - Certifications: SOC2 - Last verified: 2026-05-21 Dutch open-source no-code database (Baserow B.V., Amsterdam, KvK 81129254, 2020), MIT-licensed, self-hostable, SOC 2 + HIPAA, Airtable replacement. Baserow is the open-source no-code database and application builder operated by **Baserow B.V.** (Keurenplein 4, Amsterdam, Netherlands; Chamber of Commerce 81129254), incorporated in 2020 and entirely governed by Dutch law with Amsterdam jurisdiction. The product is released under the **MIT Expat licence** with the full source code on GitHub (4.8k+ stars), positioning it as the open-source, EU-rooted alternative to Airtable for teams that want data portability and full control. Feature set: multi-type relational tables, grid/Kanban/calendar/gallery/survey views, workflow automations, a visual application builder, role-based permissions, audit logs, and API-first architecture with integrations across Jira, GitLab, GitHub, Zapier, Make, and n8n. The team of approximately 17 people is fully remote across the Netherlands, Germany, France, Belgium, Ireland, Austria, and other EU countries. Baserow is available in two deployment modes. **Self-hosted** on any EU infrastructure (Docker, Helm, Cloudron, or bare Hetzner/OVH server) makes the customer the sole data controller with no US-owned cloud in the picture. The **managed cloud** at baserow.io is the alternative for teams that prefer a hosted service; the cloud tier carries SOC 2 Type II and HIPAA attestations and commits to GDPR compliance, but the underlying hosting provider is not publicly named in accessible docs, holding the CLOUD Act flag at `minor` pending vendor disclosure. Pricing in USD (EUR conversion approximate): Free cloud tier covers 3,000 rows and 2 GB storage, permanent free, no credit card. Premium ~€9/user/month covers 50,000 rows, Kanban and calendar views, and XML/JSON/Excel export. Advanced ~€17/user/month adds 250,000 rows, role-based permissions, and audit logs. Self-hosted community edition is free; enterprise self-hosted licences available. Best fit: EU engineering teams, non-profits, and data-driven SMBs that want an open Airtable alternative with self-host optionality and Dutch/EU legal grounding. **Compliance rationale:** Baserow B.V. (Keurenplein 4, Amsterdam, Netherlands; KvK 81129254; incorporated 2020) is an MIT-licensed open-source no-code database under Dutch law with SOC 2 Type II and HIPAA attestations, self-hosted deployment as the primary sovereignty path, and a managed cloud tier with GDPR compliance. EU-owned, open-source, with the self-hosted path giving the customer full data control; main gap: the DPA is referenced in the ToS but not linked publicly, and the trust centre directs prospective buyers to contact sales rather than surfacing a self-serve document, alongside undisclosed hosting region for the managed cloud. ### Black Forest Labs: https://euvetted.com/p/black-forest-labs - Website: https://bfl.ai - Category: Sovereign AI - Country of incorporation: Germany - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2024 - Certifications: ISO27001 - Last verified: 2026-05-11 Freiburg-based German image-generation lab (FLUX models, Stable Diffusion creators), but heavily US-VC-funded; open-weight FLUX [schnell] under Apache 2.0. Black Forest Labs is the German image-generation research lab founded in 2024 by the **core team behind Stable Diffusion** (Robin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser, and Björn Ommer) whose 2022 paper "High-Resolution Image Synthesis with Latent Diffusion Models" (originating from Ludwig-Maximilians-Universität München and Heidelberg University) underpinned the entire current diffusion-models wave. The company is headquartered in **Freiburg, Germany** (with an additional research lab in San Francisco). The product surface is the FLUX family of image-generation models: the current generation includes FLUX.2 [max], [pro], [flex], and [klein]; previous-generation **FLUX [schnell] is published under Apache 2.0** and is freely usable commercially; **FLUX [dev]** is non-commercial-research-licensed; and **FLUX [pro/max]** are commercial-API-only. For an EU-sovereignty audit Black Forest Labs is structurally a Mistral-AI-like case: German legal-entity HQ + DE-origin founders + ISO 27001 certification + open-weight model strategy + a research-and-licence model that supports self-hosting on EU GPU infrastructure, versus a cap table that is dominated by US capital. The seed round in August 2024 raised US$31M led by **Andreessen Horowitz** with **General Catalyst**, Mätch.vc, Garry Tan, Brendan Iribe, Michael Ovitz, and NVIDIA's Timo Aila. The December 2025 Series B raised US$300M at a US$3.25B post-money valuation co-led by **Salesforce Ventures** and **Anjney Midha (AMP)**, with **a16z, NVIDIA, General Catalyst, and Temasek** participating; total raised US$450M. The single non-US-non-DE investor of any size is Temasek (Singapore sovereign wealth fund). Per the directory's strict-ownership stance this US-funded weighting is `eu_hq_us_funded` with material CLOUD Act exposure for the managed API; the underlying API hosting is not publicly disclosed but standard for an a16z portfolio is AWS / GCP. The procurement-grade answer is the self-host path. **FLUX [schnell] under Apache 2.0** runs on any EU GPU host (Hetzner H100, OVHcloud GPU, Scaleway B300, STACKIT GPU, IONOS Cloud) with no CLOUD Act exposure for buyers who can operate inference themselves. **FLUX [dev]** can be used for research and self-hosting subject to its non-commercial licence. ISO 27001 is attested on the Trust and Security page. Best fit: AI / ML engineering teams who want best-in-class diffusion models, EU regulated buyers who self-host on EU GPU infrastructure for sovereignty, and any procurement-grade buyer evaluating sovereign-AI image generation alongside Mistral AI for text. **Compliance rationale:** Black Forest Labs (Freiburg, Germany, with an additional SF lab) is the FLUX-model company founded in 2024 by the Stable Diffusion core team (Robin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser, Bjorn Ommer), ISO 27001 certified and produces open-weight image-generation models (FLUX.2 max/pro/flex/klein, plus historical FLUX [schnell] Apache 2.0 and FLUX [dev] non-commercial), but **the cap table is dominated by US capital** (Andreessen Horowitz, Salesforce Ventures, General Catalyst, NVIDIA, Anjney Midha AMP) after a US$31M seed (Aug 2024) and US$300M Series B at US$3.25B valuation (Dec 2025); Temasek (SG) is the only non-US institutional. EU-HQ, ISO 27001 certified, but `eu_hq_us_funded` with material CLOUD Act exposure for the managed API; no public DPA or sub-processors list found at audit. Self-hosted FLUX [schnell] on EU GPU infrastructure eliminates CLOUD Act exposure. ### BookStack: https://euvetted.com/p/bookstack - Website: https://www.bookstackapp.com - Category: Docs & wikis - Country of incorporation: United Kingdom - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: free (from €0/month) - Founded: 2015 - Last verified: 2026-05-18 UK solo-dev MIT-licensed self-hosted wiki + documentation platform (Dan Brown, 2015); no SaaS, no vendor counterparty risk. BookStack is a fully open-source, self-hosted wiki and documentation platform created in 2015 by **Dan Brown**, a UK-based full-stack web developer. The project was initially started under the working name "Oxbow" (first commit 12 July 2015) and has grown over the past decade into a category-defining "open-source Confluence alternative", particularly popular with IT teams, technical documentation sites, internal knowledge bases, and home-lab self-hosters. The codebase is **fully MIT-licensed** and source-available on Codeberg (mirror on GitHub), meaning buyers can fork, modify, redistribute, and use commercially with no licence restrictions or copyleft obligations. Technical stack: PHP with the Laravel framework + MySQL, standard LAMP-style deployment that runs on any Hetzner / OVHcloud / Scaleway / IONOS VPS with minimal resource requirements. Content organisation is structured into Books → Chapters → Pages with WYSIWYG and Markdown editing, full-text search, role-based access controls, **LDAP / SAML / OIDC SSO**, multi-language UI for 10+ locales, PDF and Markdown export, image management, and a clean RESTful API. The project explicitly does **not** operate a managed SaaS: third-party sponsor companies (Stellar Hosted, Cloudabove) offer BookStack hosting commercially but are explicitly not vetted or supported by Dan Brown's project team, so the "official" BookStack experience is self-host. For procurement-grade EU buyers BookStack is structurally one of the cleanest listings in this directory: no commercial entity to acquire or pressure, no VC investors, no parent company, fully MIT-licensed source code that can be forked at will, no managed cloud to worry about region selection on. Best fit: IT teams building internal knowledge bases, technical documentation projects, EU public-sector buyers who want MIT-licensed self-host as the procurement-grade default, home-lab and engineering-team self-hosters, organisations that want to escape Confluence's licensing complexity. The only minor caveats are the solo-developer maintenance model (some procurement teams require formal vendor SLA which BookStack doesn't offer directly; third-party hosting sponsors fill that gap) and the UK-post-Brexit `other` ownership tier (which is moot if you self-host since you control the deployment jurisdiction). **Compliance rationale:** BookStack is a **fully MIT-licensed open-source self-hosted wiki and documentation platform** created by UK-based developer **Dan Brown** in 2015 (first commit 12 July 2015, initially under the working name 'Oxbow') with no commercial entity controlling the project, no SaaS operated by the maintainer team, and no telemetry or vendor-counterparty risk. Built on PHP/Laravel + MySQL, supports 10+ UI languages, includes LDAP / SAML / OIDC SSO, role-based permissions, WYSIWYG editing, PDF/Markdown export. Pure self-host on customer-chosen EU infrastructure (Hetzner / OVHcloud / Scaleway / IONOS) delivers no CLOUD Act exposure and no vendor counterparty: gold-standard for procurement-grade self-host. ### Brevo: https://euvetted.com/p/brevo - Website: https://www.brevo.com - Category: Email marketing - Country of incorporation: France - Hosting country: France - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: freemium (from €8/month) - Founded: 2012 - Certifications: ISO27001 - DPA: https://www.brevo.com/legal/termsofuse/ - Sub-processors list: https://www.brevo.com/legal/termsofuse/ - Last verified: 2026-05-10 Paris-headquartered multi-channel customer-engagement platform with email, SMS, CRM, automation, ISO 27001 and a public DPA. Brevo (formerly Sendinblue) is a Paris-headquartered customer-engagement platform covering email marketing, transactional email, SMS, marketing automation, a built-in CRM, and chat. Founded in 2012 by Armand Thiberge as Sendinblue and rebranded as Brevo in May 2023, the company operates as a French SAS at 9–17 rue Salneuve, Paris, and reached unicorn status in December 2025 after a €500M round that brought General Atlantic (US) and Oakley Capital (UK) to a combined ~50% stake alongside Bpifrance, Bridgepoint, and management/employees. Infrastructure is split between EU on-premise data centers in France (primary) and Germany (additional capacity) and Google Cloud Platform with data stored exclusively in Belgium for cloud workloads, meaning customer data at rest sits with a US-owned cloud provider in an EU region. Brevo holds ISO 27001:2022 and publishes its DPA together with the sub-processors annex inside the General Terms of Use; this is a strong transparency signal but does not remove the GCP-borne CLOUD Act exposure or the use of Cloudflare and OpenAI as sub-processors. Pricing starts at roughly €8/month (Starter, 5,000 emails) with a free tier of 300 emails/day and unlimited contacts; the Brevo footer is shown on free and Starter plans. The affiliate program runs on PartnerStack with US$5 per free account and US$100 per paid account on a 90-day cookie. Best fit: SMBs and mid-market marketers in DACH and France who need a multi-channel platform with credible EU posture and a public DPA, and can accept GCP-EU as the cloud-hosting reality. Procurement teams with strict no-US-cloud requirements should look at Cleverreach, Inxmail, or rapidmail in this category. **Compliance rationale:** French SAS with ISO 27001:2022 and a publicly-attached DPA plus sub-processors annex inside the Terms of Use, but cloud workloads run on Google Cloud Platform in Belgium for primary at-rest storage plus Cloudflare and OpenAI sub-processors: EU-headquartered with a public DPA, but material CLOUD Act exposure via US-owned cloud infrastructure. **Sub-processors mapped:** 20 total, 10 US-owned - Anthropic (Ireland): AI provider (optional) [US-owned] - Cloudflare (United States): Content delivery network and WAF [US-owned] - Convrrt (United States): Customised landing pages (optional) [US-owned] - Google Cloud Platform (GCP) (United States): Hosting [US-owned] - Google Gemini (Ireland): AI provider (optional) [US-owned] - Integry (United States): Integration with third-party software (optional) [US-owned] - Omni (United States): Dashboards [US-owned] - OpenAI (Ireland): AI provider (optional) [US-owned] - Twilio SMS (United States): SMS routing to the NorAm zone (optional) [US-owned] - Zendesk (United States): Ticketing / support tool [US-owned] - Brevo CRM Solution (India): Customer experience and maintenance (Brevo Group) - Brevo GmbH (Germany): Customer experience and maintenance (Brevo Group) - iBasis (Liechtenstein): SMS routing except NorAm zone and France (optional) - Langfuse (Germany): AI provider (optional) - OVH (France): Hosting - Sendinblue Inc. (United States): Customer experience and maintenance (Brevo Group, EU-parented) - Sinch (United Kingdom): SMS routing to Portugal, India, Indonesia, Bahamas (optional) - Telnyx (Ireland): SMS routing (optional) - Vonage (United States): SMS routing (optional) - Yodel GmbH (Austria): Brevo Phone customer experience and maintenance (Brevo Group) ### Cal.com: https://euvetted.com/p/cal-com - Website: https://cal.com - Category: Calendar booking - Country of incorporation: United States - Hosting country: United States - Ownership signal: us_owned - CLOUD Act exposure: direct - Pricing tier: freemium - Founded: 2021 - Sub-processors list: https://cal.com/privacy - Last verified: 2026-05-11 US-incorporated open-source Calendly alternative (Cal.com Inc, SF) founded by EU developers; production code moving closed-source in 2026. Cal.com is one of the most-cited "open-source Calendly alternative" SaaS products of the past few years, founded in 2021 by Peer Richelsen (German) and Bailey Pumfleet (UK), with the commercial entity incorporated as **Cal.com, Inc.** in **San Francisco, California** despite the EU-founder origin. The company has raised approximately **US$32M** in venture funding and the GitHub repository (calcom/cal.com) has accumulated more than 41,000 stars since launch. The product replaces Calendly's hosted scheduling experience with a self-hostable, AGPLv3-licensed open-source codebase plus a managed SaaS (cal.com), a model that was the directory's reference "EU founders bringing US-style SaaS open-source pressure" story until 2026. The 2026 strategic shift complicates the listing. Per public reporting and direct corporate communication, Cal.com is **moving its production codebase behind closed doors** during 2026, leaving only a stripped community edition called **Cal.diy** under the more-permissive **MIT licence**, while rewritten authentication, data-handling, and commercial systems become proprietary. This narrows the structural "fork-if-anything-changes" guarantee that historically distinguished Cal.com from Calendly. For procurement-grade EU buyers the picture is now: (a) the hosted Cal.com SaaS is US-incorporated under Cal.com, Inc. and subject to US extraterritorial law by default, `direct` CLOUD Act exposure under our strict-ownership stance; (b) the privacy policy explicitly confirms data transfers to the United States, with US sub-processors Stripe, Twilio, and Daily.co alongside PostHog (UK); (c) the Cal.diy MIT community edition on EU infrastructure (Hetzner, OVHcloud, Scaleway) remains a legitimate self-host option but with reduced feature parity vs the proprietary hosted product. Pricing for the hosted SaaS is freemium with paid Team and Enterprise tiers; specific entry-tier EUR figures were not captured at audit. Best fit: developers and product builders who specifically want the Cal.com API surface and accept US-incorporation; teams comfortable with the new MIT/Cal.diy self-host path on EU infrastructure for sovereignty. Procurement-grade EU-only buyers needing a structurally EU-incorporated alternative should choose Doodle (CH, TX Group), SuperSaaS (NL, founder-owned), or Reservio (CZ, ABUGO Group) instead; all listed elsewhere in this category. **Compliance rationale:** Cal.com is **US-incorporated as Cal.com, Inc. (San Francisco)** despite its EU-founder origin (Peer Richelsen + Bailey Pumfleet, 2021): Delaware-style US corporation, US$32M VC-funded, and the privacy policy explicitly states data is transferred to and maintained in the US. Sub-processors are heavily US (Stripe, Twilio, Daily.co) plus PostHog (UK). No public DPA; no sub-processors list beyond general privacy-policy disclosure. **In 2026 Cal.com began moving its production codebase behind closed doors** with only a stripped community edition (Cal.diy, MIT) remaining open-source, so the historical 'open-source Calendly alternative' positioning is degrading. The hosted SaaS carries `direct` CLOUD Act exposure as a US-incorporated entity (US-owned, US-hosted, no public DPA) and should not be the procurement-grade choice for strict EU buyers; the self-host path via Cal.diy on EU infrastructure (EU-hosted, no CLOUD Act exposure for that path) is the only structurally clean option. Alternatives in the category (SuperSaaS NL, Reservio CZ, Doodle CH, Cronofy UK) are all structurally cleaner from an EU-sovereignty perspective. **Sub-processors mapped:** 8 total, 8 US-owned - Amazon Web Services (S3) (United States): Encrypted storage of video recordings [US-owned] - Daily.co (United States): Video conferencing and recording API [US-owned] - GitHub (United States): CI/CD: code hosting, review, build [US-owned] - Google Analytics (United States): Website performance and navigation analytics (non-EU visitors) [US-owned] - Intercom (United States): Customer support and communication [US-owned] - PostHog (United States): Product analytics; feature testing and observability [US-owned] - Stripe (United States): Payment processing [US-owned] - Twilio (United States): Email and SMS booking reminders/notifications [US-owned] ### Capsule CRM: https://euvetted.com/p/capsule - Website: https://capsulecrm.com - Category: CRM - Country of incorporation: United Kingdom - Hosting country: United States - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: freemium - Founded: 2009 - DPA: https://capsulecrm.com/dpa/ - Sub-processors list: https://capsulecrm.com/sub-processors/ - Last verified: 2026-05-10 Manchester-based UK CRM (Zestia Ltd) with a free tier, public DPA, and AWS hosting; post-Brexit jurisdiction. Capsule CRM is a Manchester-headquartered UK customer relationship management product operated by Zestia Limited (Companies House number 06418281, registered office 20 Dale St, Manchester, M1 1EZ). The platform is positioned for SMBs combining contact management, sales pipelines, project management, workflow automation, an AI-powered enrichment toolset, and 100+ integrations across Zapier, Slack, Google, Microsoft, QuickBooks, FreeAgent, Xero, Shopify, Typeform, and LinkedIn. The product reports a 4.7/5 G2 rating across 400+ reviews and is one of the longer-running independent UK CRMs. Compliance disclosures are unusually transparent for a vendor of this size: the DPA is publicly accessible at /dpa with a sub-processors annex maintained at a dedicated URL, sub-processor changes are notified at least 30 days in advance, the privacy policy was refreshed on 21 August 2025, and a sister legal entity (Capsulecrm, Inc.) carries EU-U.S. Data Privacy Framework certification along with the UK Extension and the Swiss-U.S. DPF for cross-Atlantic transfers. Where the listing weakens for a strict-CLOUD-Act buyer is in two places: (1) all customer data is hosted on Amazon Web Services, a US-owned hyperscaler, with no published commitment to a specific EU region only; (2) the existence of a US legal entity for non-EU customers means part of the customer base contracts with Capsulecrm Inc. directly. Per our strict-ownership stance these together produce material CLOUD Act exposure: UK post-Brexit jurisdiction, AWS hosting with no EU-only region commitment, and a US contracting entity are the three sovereignty gaps. Pricing is freemium and EU-buyer-friendly: a permanent Free plan covers 2 users, 250 contacts, 1 sales pipeline, and 5 custom fields; paid Starter / Growth / Advanced / Ultimate tiers scale by contact count, automation depth, and number of pipelines/project boards, with up to 15% discount on annual billing and a 14-day no-credit-card trial. Best fit: UK and EU SMBs that want a polished pipeline CRM with a free tier and a public DPA, and can accept a UK post-Brexit jurisdiction plus AWS hosting. Procurement-led EU-only buyers should prefer weclapp (DE, Frankfurt + Karlsruhe DC), Teamleader (BE/Visma), or Salesflare (BE) instead. **Compliance rationale:** Manchester-based UK CRM (Zestia Limited, company 06418281) with a publicly-accessible DPA and sub-processors page and a permanent free tier (2 users, 250 contacts), but customer data is hosted on Amazon Web Services and a separate US entity (Capsulecrm Inc.) is Data Privacy Framework certified for transatlantic transfers: UK post-Brexit jurisdiction, AWS hosting, and a US legal entity contracting with non-EU customers together produce material CLOUD Act exposure. **Sub-processors mapped:** 10 total, 10 US-owned - Amazon Web Services, Inc. (United States): Hosting (customer data, application logs) [US-owned] - APIHub Inc. (Clearbit) (United States): Business and contact data enrichment [US-owned] - CapsuleCRM Inc. (United States): Customer support services [US-owned] - Datadog Inc. (United States): Log aggregation and performance monitoring [US-owned] - Google Inc. (United States): Email (support communications and customer emails) [US-owned] - Help Scout PBC (United States): Support help desk for customer queries [US-owned] - OpenAI LLC (United States): AI processing (summarization, content generation, insights) [US-owned] - Pendo.io Inc. (United States): In-app guidance and product analytics [US-owned] - SolarWinds Worldwide LLC (United States): Log aggregation and performance monitoring [US-owned] - Twilio Inc. (SendGrid) (United States): Transactional / system emails [US-owned] ### CCV Shop: https://euvetted.com/p/ccv-shop - Website: https://www.ccvshop.nl - Category: E-commerce - Country of incorporation: Netherlands - Hosting country: Netherlands - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid (from €36/month) - Last verified: 2026-05-21 Dutch hosted e-commerce SaaS from €36/mo; 0% transaction fees; parent company CCV Group is Fiserv-owned (US). **CCV Shop** (Diamantstraat 3, Hengelo, Netherlands, KvK 08084328) is a Dutch hosted e-commerce platform offering plans from **€36/month (Basic, up to 50 products)** to **€129/month (Enterprise, unlimited products + B2B)**, all with 0% transaction fees and a 21-day free trial. The platform supports multi-language storefronts, API access (Professional+ plans), and multiple payment providers. CCV Shop is operated by the CCV Group, a Dutch payments + commerce company with 900 employees serving 150,000+ customers across Europe. However, **CCV Group B.V. is owned by Fiserv Inc.** (NYSE: FI, Milwaukee, Wisconsin), a major US financial technology company, so while the product team and operations are European, the ultimate beneficial owner is a US public company, creating material CLOUD Act exposure. Best fit for Dutch and Belgian SMBs who want a fully-managed, no-commission hosted shop with local Dutch-language support and local payment integrations. For buyers requiring clean EU ownership, Shopware Community Edition or PrestaShop self-hosted are stronger alternatives. **Compliance rationale:** CCV Shop is Dutch-operated (KvK 08084328, Hengelo NL), but its parent CCV Group B.V. is owned by Fiserv Inc. (NYSE: FI, US), making this a US-ultimate-owner situation with material CLOUD Act exposure. No public DPA or sub-processors list found; these must be requested via sales. ### centralstationCRM: https://euvetted.com/p/centralstationcrm - Website: https://centralstationcrm.de - Category: CRM - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €24/month) - Founded: 2010 - DPA: https://centralstationcrm.de/avv - Sub-processors list: https://centralstationcrm.de/datenschutz - Last verified: 2026-05-10 Cologne-based German SMB CRM (42he GmbH), all-German hosting on Hetzner + Core-Backbone + Telekom, free tier for 3 users. centralstationCRM is a Cologne-based German CRM for small teams operated by 42he GmbH (Herderstraße 70, 50931 Köln; HRB 70598 at AG Köln; VAT DE274568548; managing directors Axel von Leitner and Moritz Machner). The company is independent with no outside investors, focuses explicitly on small businesses and non-profits, and reports more than 10,000 users across consulting, marketing, coaching, and nonprofit segments. The product covers contact and customer management, task assignment, sales pipeline, KPI tracking, email archiving, and team collaboration with deliberate simplicity over enterprise depth. Compliance posture is best-in-class for the CRM category. Customer data is stored on servers across three German hosting providers (Hetzner Online GmbH, Core-Backbone GmbH, and Telekom Deutschland GmbH) all bound by GDPR-compliant data-processing agreements; newsletters use rapidmail (also Germany). No US-owned hyperscaler appears anywhere in the customer-data path, no US sub-processor handles customer business records, and no third-country transfer is required for normal operation. Banking-grade 256-bit TLS encryption is used in transit; daily off-site backups support recovery; data centres carry 24/7 surveillance and redundant power/network. The privacy policy openly names the hosting providers and the newsletter sub-processor; the imprint exposes the Handelsregister number, VAT, and managing directors, satisfying §5 TMG cleanly. Pricing is transparent: free Starter (3 users, 200 contacts, 100 MB storage), Team €24/month, Small Office €75/month (most popular), Business €149/month, Enterprise €289/month; all in EUR with monthly cancellation, no long-term contract, and a 30-day test phase that requires no credit card. Best fit: small German-speaking businesses, freelancers' teams, and EU non-profits that want a clean Cologne-rooted German CRM with explicit German data residency and zero US-cloud exposure. The trade-off is feature depth (no SSO, no audit log advertised) and German-only UI: buyers needing multi-locale UI or enterprise-grade SSO should look at weclapp (DE) or Teamleader (BE) instead. **Compliance rationale:** Cologne-based independent GmbH (42he GmbH, HRB 70598 AG Köln) with no outside investors, customer data stored exclusively across three German hosting providers (Hetzner, Core-Backbone, Telekom Deutschland), newsletter via rapidmail (DE): no US sub-processors anywhere on the customer-CRM-data path; sub-processors are openly named in the privacy policy and the imprint discloses managing directors and HRB number: EU-owned, EU-hosted (Germany only), with **minor CLOUD Act exposure** confined to website analytics/advertising trackers (Google, LinkedIn, Microsoft) that never touch the CRM data itself; among the strongest verified sovereignty postures in the CRM category, with the trackers being the only US-jurisdiction processors and easily removable. **Sub-processors mapped:** 3 total, 0 US-owned - Core-Backbone GmbH (Germany): Hosting infrastructure / decentralized backup storage - Hetzner Online GmbH (Germany): Hosting infrastructure / decentralized backup storage - Telekom Deutschland GmbH (Germany): Hosting infrastructure / decentralized backup storage ### chatlyn: https://euvetted.com/p/chatlyn - Website: https://chatlyn.com - Category: Helpdesk - Country of incorporation: Austria - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid - Founded: 2022 - Last verified: 2026-05-11 Vienna-based Austrian hospitality AI communications hub (founded 2022); 1,000+ properties, omnichannel inbox + WhatsApp; €8M Series A from Smedvig (NO). chatlyn is a Vienna-based Austrian AI communication hub built specifically for the hospitality vertical: hotels, hotel groups, and short-term-rental operators. Founded in late 2022 by **Nicolas Vorsteher** (CEO), **Michael Urbanek** (CTO), and **Matthias Haubner** (CPO), the platform unifies guest communications across email, WhatsApp, SMS, webchat, and social channels with intelligent automation, real-time translation in 35+ languages, and PMS (property-management-system) integration. The company has scaled rapidly to **1,000+ hotel properties across 30 countries** (customer references include **St. Regis Mauritius, Singer Palace Rome, and InterContinental** properties), establishing chatlyn as the European-rooted hospitality-AI brand of choice in 2025-2026. For an EU-sovereignty audit the ownership architecture is unusually clean for an AI-vertical SaaS. The **€8M Series A in June 2025 was led by Smedvig Ventures**, a Norwegian growth-equity firm. This means the lead investor is Nordic, not US-VC, which is structurally different from most AI-adjacent funding rounds in 2025-2026. Other Series A participants are Austrian and European: business angels include Andreas Burike (AnyDesk), Mathias Hiebeler (former owner of Grob Aircraft, recently acquired by German defence-tech Helsing), Austrian transport leader Blaguss, and strategic hospitality angels. No US-VC name appears on the cap table, keeping chatlyn firmly in the `eu_owned` ownership tier. Pricing is enterprise / hospitality-vertical sales-engaged; specific entry-tier EUR figures were not captured at audit. The main procurement documentation gaps for a 3-year-old startup: the underlying hosting provider, a unified DPA artefact, and a named sub-processors list are not publicly indexed at audit time, worth requesting before signing for any enterprise hotel-group buyer. Best fit: European hotel groups and hospitality businesses needing AI-driven guest communication with WhatsApp + email + SMS unification, multi-property operators with PMS integration needs, hospitality-tech procurement teams who specifically want an Austrian-rooted alternative to Intercom / Zendesk / Freshdesk. **Compliance rationale:** chatlyn is a Vienna-headquartered Austrian AI communication hub for hospitality, founded late 2022 by **Nicolas Vorsteher (CEO), Michael Urbanek (CTO), and Matthias Haubner (CPO)**; **€8M Series A in June 2025 led by Smedvig Ventures (Norwegian)** with Austrian angels (Blaguss, AnyDesk''s Andreas Burike, Helsing-related Mathias Hiebeler). Clean Nordic/Austrian cap table with no US-VC presence. Already serving 1,000+ hotel properties across 30 countries including St. Regis Mauritius, Singer Palace Rome, and InterContinental. EU-owned with a clean Nordic/Austrian investor structure. Key gap: chatlyn does not publish a publicly accessible DPA (the T&Cs state a DPA is concluded 'if necessary'; no public DPA page or PDF exists); no sub-processors list or hosting-provider disclosure is publicly indexed at audit. ### Cleura: https://euvetted.com/p/cleura - Website: https://cleura.com - Category: Cloud & hosting - Country of incorporation: Sweden - Hosting country: Sweden - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2005 - Certifications: ISO27001, ISO27017, ISO27018 - DPA: https://s3-kna1.citycloud.com/6a5aa55d8f094a13ae18199639aa72c2:cleura.files/Cleura_Data_Processing_Agreement_for_Public_Cloud-V24.03.25.pdf - Sub-processors list: https://cleura.com/resources/getting-started-with-cleura-cloud/regions-services-sub-processors/ - Last verified: 2026-05-18 Swedish OpenStack public + compliant cloud (Cleura, ex-City Network, Iver-owned), ISO 27001/27017/27018, EU-only residency. Cleura is a Swedish cloud-infrastructure provider operated by Cleura AB (formerly City Network), now part of Iver Sverige AB, the Swedish IT-services group that engages Iver as a sub-processor across all Cleura Public Cloud and Compliant Cloud regions (as confirmed in an April 2026 sub-processors update). With more than 20 years of operation, Cleura runs one of the largest OpenStack-based public cloud footprints in Europe and is an OpenInfra Foundation Gold Member; the company holds AAA credit rating and ships three deployment models: Public Cloud, Compliant Cloud (mission-critical workloads), and Private Cloud, all OpenStack-based with full API interoperability and an explicit anti-lock-in posture. Compliance and sovereignty are the entire pitch. Cleura's Public Cloud is deployed in multiple ISO 27001-certified Tier-III data centres in Europe; the Compliant Cloud tier additionally carries ISO 27017 and 27018 certifications and is positioned for regulated workloads. The company is ISO 9001 and 14001 certified at the management-system level, and emphatically markets itself as "not dependent on an unstable adequacy decision and not subject to US extraterritorial surveillance laws", a direct contrast positioning against AWS/Azure/GCP. Data residency is EU/EEA-only across regions in Sweden and Germany. As of the April 2026 update, all sub-processors are EU-based (Iver Sverige AB is the parent sub-processor reference). Pricing is per-second monitored, hourly calculated, monthly billed, with per-vCore-hour configurations for Generic CPU and High-Intensity CPU instance classes; specific entry-tier figures were not captured at audit. Best fit: Swedish and Nordic enterprises, regulated industries (financial services, healthcare, public sector), OpenStack-fluent engineering teams that want anti-lock-in infrastructure, and EU buyers needing Compliant Cloud-grade isolation. Together with Hetzner, OVHcloud, Scaleway, IONOS, UpCloud, and STACKIT, Cleura completes the European hyperscaler-alternative shortlist for procurement-grade EU buyers. **Compliance rationale:** Swedish OpenStack-based cloud (Cleura AB, formerly City Network, now part of Iver, a Swedish IT-services group) operating multiple ISO 27001 / 27017 / 27018-certified Tier-III EU data centres in Sweden and Germany, OpenInfra Foundation Gold member, and explicitly positioned as 'not subject to US extraterritorial surveillance laws' with EU-only data residency: EU-owned and EU-hosted with no CLOUD Act exposure. **Sub-processors mapped:** 4 total, 0 US-owned - 23 Technologies GmbH (Germany): Container platform deployment (only with Cleura Container Orchestration Engine) - Interxion GmbH (Germany): Remote hands (Public Cloud FRA1 datacenter; physical-only, no data access) - Interxion Sverige AB (Sweden): Remote hands (Public Cloud STO2 datacenter; physical-only, no data access) - Iver Sverige AB (Sweden): Infrastructure, managed services and support ### Clever Cloud: https://euvetted.com/p/clever-cloud - Website: https://www.clever-cloud.com - Category: Cloud & hosting - Country of incorporation: France - Hosting country: France (Paris) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €4.8/month) - Founded: 2010 - Certifications: ISO27001, HDS - DPA: https://www.clever-cloud.com/general-terms-and-conditions-of-use/clever-cloud-data-processing-agreement/ - Sub-processors list: https://cdn.clever-cloud.com/uploads/2026/02/clever-clouds-sub-processors.pdf - Last verified: 2026-06-15 French sovereign PaaS/IaaS: deploy apps and managed databases on EU infrastructure, billed per second. Clever Cloud is a French Platform-as-a-Service and Infrastructure-as-a-Service provider founded in Nantes in 2010. It automates the deployment, scaling and operation of web applications across most major languages and frameworks, with managed databases (PostgreSQL, MySQL, MongoDB, Redis), the S3-compatible Cellar object storage, and per-second pay-as-you-go billing that starts at roughly €4.80/month for the smallest runtime. Provisioning works through the console, a CLI, the API and an official Terraform provider, and organisations get SSO and activity logging. For sovereignty-conscious buyers, the decisive point is the operating model: Clever Cloud is a wholly French-owned, bootstrapped SAS, and its core regions run on European infrastructure: Paris, Roubaix and a dedicated Gravelines HDS region on OVHcloud, plus a London availability zone on IONOS. Keeping a deployment in the French regions means data and the sub-processor chain stay in the EU, with no CLOUD Act exposure. The platform holds ISO 27001:2022 and HDS (French health-data hosting) certification, publishes a DPA, and is pursuing SecNumCloud qualification on its own infrastructure. In April 2026 the consortium of DEEP (POST Luxembourg), OVHcloud and Clever Cloud was selected by the European Commission under the €180M Cloud III sovereign-cloud framework, with Clever Cloud supplying the PaaS, container and managed-services orchestration layer. That makes it a credible European answer to Heroku, Vercel and the application layers of AWS and Google Cloud for teams that want EU residency without operational overhead. **Compliance rationale:** French-owned SAS running on EU infrastructure with ISO 27001:2022 and HDS certification, an EU-only sub-processor chain, a published DPA and selection in the EU's €180M sovereign-cloud tender: no CLOUD Act exposure for FR-hosted deployments. ### CleverReach: https://euvetted.com/p/cleverreach - Website: https://www.cleverreach.com - Category: Email marketing - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: freemium (from €15/month) - Founded: 2007 - DPA: https://eu2.cleverreach.com/assets/dpa/5.2_en_example.pdf - Sub-processors list: https://www.cleverreach.com/en/privacy-policy/ - Last verified: 2026-05-10 German email marketing platform with EU-only customer data storage in Germany and a permanently free Lite tier. CleverReach is a Rastede-based German email marketing platform operating as CleverReach GmbH & Co. KG, founded in 2007. The company positions itself explicitly as "Email Marketing Made in Germany" and stores all customer subscriber data and email content exclusively on infrastructure within Germany and broader EU jurisdictions. With more than 400,000 customers worldwide, CleverReach is one of the largest German-owned ESPs and a strong DACH-focused alternative to Mailchimp and Constant Contact for buyers who want a clean German-hosting story without a US legal entity. The trust posture is solid: customer email data resides in Germany, the privacy policy lists Privacy-Framework and Standard Contractual Clauses for any cross-Atlantic transfers, and the company is a member of the Certified Senders Alliance with the CSA Trust Seal. The disclosed sub-processor inventory in the privacy policy includes US-owned tools: Google (Analytics/Ads/Meet/YouTube), Meta (Facebook/Instagram), Zendesk for support, Microsoft Ads, SurveyMonkey, Taboola, Reddit, LogMeIn. These touch the marketing site, advertising, and customer support rather than subscriber data at rest, which limits CLOUD Act exposure to the "minor" tier. Pricing is a clear strength for SMBs: a permanently free Lite tier covers 250 recipients and 1,000 emails/month; the Basic plan starts at €15/month for up to 5,000 recipients with paid plans climbing to a €499/month Enterprise tier. The product UI is available in six languages (DE, EN, ES, FR, IT, NL), making CleverReach unusually well-localized for a German vendor. Best fit: DACH-region SMBs and mid-market teams who need a credible German-hosting story, simple pricing, and broad language support, and don't require advanced SSO or audit-log features. **Compliance rationale:** German GmbH & Co. KG with 'Email Marketing Made in Germany' positioning and a CSA Trust Seal, but core recipient/subscriber data is processed and stored on Amazon Web Services (a US-owned hyperscaler) in EU regions (Ireland/Germany). So although the primary server location is German, customer mailing-list data at rest sits with a US-owned provider whose US parent is compellable regardless of EU region, giving material CLOUD Act exposure (SCC + Data Privacy Framework apply to the transfer). **Sub-processors mapped:** 3 total, 1 US-owned - Amazon Web Services, Inc. (United States): Data storage and processing, e-mail dispatch (processing in Ireland and Germany) [US-owned] - Hetzner Online GmbH (Germany): E-mail dispatch - PlusServer GmbH (Germany): E-mail dispatch ### Codebahn: https://euvetted.com/p/codebahn - Website: https://codebahn.net - Category: Git hosting - Country of incorporation: Sweden - Hosting country: France (Paris) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €9/month) - DPA: https://codebahn.net/dpa - Sub-processors list: https://codebahn.net/docs/reference/subprocessors/ - Last verified: 2026-07-21 Swedish-run (Hackerman AB) managed Forgejo forge with EU-only CI: flat-rate, bootstrapped, all-EU sub-processors, public DPA. Codebahn is a **managed, commercially supported Git hosting and CI platform** operated by **Hackerman AB** (org.nr 559079-1918), a bootstrapped Swedish company based in Gothenburg. It markets itself as a focused, independent GitHub alternative for European teams: unlimited users on every plan, flat-rate pricing, and hosted CI runners included on every paid organisation tier. The service is built on the open-source **Forgejo** engine (GPL-3.0), and Codebahn provides one-click export in an open format so customers can leave without lock-in. The infrastructure story is the differentiator. Primary compute, object storage, managed PostgreSQL, the container registry, transactional email and observability all run on **Scaleway fr-par (Paris, France)**, with encrypted daily backups (via Restic) stored separately on **Hetzner Falkenstein (Germany)**. Codebahn publishes a full sub-processors list naming exactly four vendors, all EU-incorporated: Scaleway (France), Hetzner (Germany), Mollie (Netherlands, payments) and Crisp (France, in-app support). There is no US entity in the data path, and the DPA is public at codebahn.net/dpa without a login. Feature coverage includes repositories, issues, pull requests with branch protection, webhooks, container registry, releases, a package registry, EU-based CI/CD, GitHub workflow compatibility, and migration import of up to 100 repositories with full history preserved. Pricing runs from Personal at 9 EUR/month (5 GiB, bring-your-own CI runners) through Starter (39 EUR, 25 GiB, 3,000 CI minutes), Team (119 EUR, 200 GiB, 10,000 minutes) and Scale (249 EUR, 500 GiB, 25,000 minutes), with annual billing saving two months and a 30-day money-back guarantee. As a bootstrapped company with no investors, Codebahn positions its terms as stable with no acquisition risk. Best fit: European teams and businesses that want a paid, supported managed forge with a contractual DPA and a verifiably all-EU sub-processor chain, rather than a free community service. **Compliance rationale:** Codebahn is a **managed, commercially supported Forgejo forge** operated by **Hackerman AB** (Gothenburg, Sweden), positioned as an independent European GitHub alternative for teams. It hits every 5/5 criterion: EU-owned Swedish operator, EU-only infrastructure (Scaleway fr-par in Paris for compute and storage, Hetzner Falkenstein in Germany for encrypted backups), a **publicly accessible DPA** at codebahn.net/dpa, a **public sub-processors list** where all four named sub-processors (Scaleway FR, Hetzner DE, Mollie NL, Crisp FR) are EU-incorporated, and no US legal entity anywhere in the data path: [[codebahn.cloud_act]]. The product is built on the open-source Forgejo engine with one-click open-format export, so there is no vendor lock-in. No third-party certification (ISO 27001 / SOC 2) is published yet, but the rubric does not require one for 5/5 given the fully transparent all-EU posture. **Sub-processors mapped:** 4 total, 0 US-owned - Crisp (France): In-app support chat - Hetzner (Germany): Encrypted backup storage (fsn1 / Falkenstein) - Mollie (Netherlands): Payment processing - Scaleway (France): Compute, object storage, managed PostgreSQL, container registry, transactional email, observability (primary, fr-par / Paris) ### Codeberg: https://euvetted.com/p/codeberg - Website: https://codeberg.org - Category: Git hosting - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: free - Founded: 2018 - Last verified: 2026-07-21 Berlin non-profit (Codeberg e.V.) running the open-source Forgejo forge: free, EU-hosted, community-governed GitHub alternative. Codeberg is a **free, non-profit Git hosting service** operated by **Codeberg e.V.**, a registered association based in Berlin, Germany. Established in September 2018 and launched publicly as codeberg.org in January 2019, it exists specifically to give open-source projects a European home that is not subject to US corporate ownership or US legal pressure. As of late 2025 it hosts over 300,000 repositories and more than 200,000 registered accounts, sustained by 1,100+ paying association members rather than any venture capital. The platform runs **Forgejo**, the open-source (GPL-3.0) forge software that Codeberg forked from Gitea in 2022 and now backs as its primary sponsor; Forgejo development itself happens on Codeberg's own infrastructure. Feature-wise it covers the full GitHub-style workflow: repositories, pull requests and code review, issue tracking, a package registry and container registry, webhooks, and hosted CI (Codeberg CI, based on Woodpecker), plus Codeberg Pages for static web hosting and one-click migration import from GitHub and GitLab. For an EU-sovereignty audit Codeberg's posture is among the cleanest in the directory: German non-profit operator, EU-only infrastructure chosen deliberately to avoid US DMCA and CLOUD Act reach: [[codeberg.cloud_act]], no US legal entity, and no US sub-processors. Because Forgejo is open source, organisations can also self-host the identical engine on their own EU infrastructure as a zero-counterparty escape hatch. The one procurement caveat is that, as a free community service, Codeberg does not sign a commercial DPA and publishes no formal sub-processors list. Best fit: open-source maintainers, privacy-conscious developers, and public-sector or education teams that want a European, non-commercial forge and are comfortable with a donation-funded governance model. **Compliance rationale:** Codeberg is the **community-governed non-profit Git forge** operated by **Codeberg e.V.**, a registered association (eingetragener Verein) based in Berlin, Germany. It runs the open-source **Forgejo** engine (a hard fork of Gitea that Codeberg itself backs and develops), is funded by association membership and donations rather than venture capital, and deliberately keeps all infrastructure inside the EU to sit outside US DMCA and CLOUD Act reach. Signals: EU-owned (German e.V.), EU-hosted, no US legal entity, no US sub-processors, Forgejo engine open-source and self-hostable, no CLOUD Act exposure. Gap: as a free community service Codeberg does not offer a signed commercial DPA / AVV and publishes no formal sub-processors list, which is the single factor keeping this below 5/5 for procurement buyers who need a self-serve DPA. **Sub-processors mapped:** 2 total, 0 US-owned - Hetzner Online GmbH (Germany): Backups, redundancy, disaster recovery, DDoS protection, spare-resource efficiency - netcup GmbH (Germany): Backups, redundancy, disaster recovery, DDoS protection, spare-resource efficiency ### Collabora Online: https://euvetted.com/p/collabora-online - Website: https://www.collaboraonline.com - Category: Docs & wikis - Country of incorporation: United Kingdom - Hosting country: United Kingdom (Cambridge) - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: freemium - Founded: 2012 - Last verified: 2026-05-21 Cambridge-based LibreOffice Online (MPL-2.0/LGPL) by Collabora Productivity Ltd: free CODE dev edition + €3/user/mo Business; self-hostable on EU infra. Collabora Online is the commercial and managed-cloud edition of **LibreOffice Online** (the browser-based version of the ubiquitous open-source office suite) developed and supported by **Collabora Productivity Ltd**, a Cambridge, UK company founded around 2012 as a division of Collabora Ltd (the embedded Linux and open source consulting firm). The product delivers Writer, Calc, Impress, Draw, and Impress editing in the browser with real-time co-authoring and full compatibility with Microsoft Office formats (.docx, .xlsx, .pptx) and the Open Document Format (ODF). It integrates natively with **Nextcloud**, **ownCloud**, Seafile, Pydio, EGroupware, and other self-hosted platforms that need an in-browser document editor. Two product tiers exist: the **CODE (Collabora Online Development Edition)** is a freely downloadable rolling-release development build suitable for testing, home use, and small teams; the **Business subscription** starts at €3 per user per month and includes Long Term Support (LTS) releases, signed security updates, SLA-backed support, and enterprise deployment tools for large-scale Kubernetes rollouts. Educational institutions and non-profits receive custom pricing. For EU-sovereignty procurement Collabora Online sits in an interesting middle position. The core product is open source (MPL-2.0 / LGPL) and fully self-hostable: running the open-source server on **EU infrastructure (Hetzner, OVHcloud, Scaleway, IONOS, STACKIT)** delivers no CLOUD Act exposure and is the procurement-grade recommended path for EU public sector. The hosted cloud, operated by Collabora Productivity Ltd (Cambridge, UK, `other` post-Brexit), uses UK + Canada primary infrastructure and US sub-processors (Google Workspace for internal tooling, US invoicing processors) covered by Standard Contractual Clauses. No ISO 27001 or EU-specific certifications captured at audit. **200+ partner integrators globally** available for deployment support. Best fit: EU organisations already running Nextcloud or ownCloud wanting an integrated in-browser office editor; EU public sector buyers needing a libre-software alternative to Microsoft 365 Online; development and home-lab use cases via the free CODE edition. **Compliance rationale:** Collabora Productivity Ltd is a **UK-incorporated company** (Cambridge, registered as a division of Collabora Ltd). Post-Brexit `other` ownership signal. Product is MPL-2.0 / LGPL-licensed LibreOffice Online (CODE free edition; Business €3/user/month). Privacy notice acknowledges UK+Canada primary hosting and US sub-processors (Google Workspace, invoicing processors) covered by SCCs. No ISO 27001 or EU-specific certifications found. Signals: MPL-2.0 / LGPL open source, self-hostable on EU infrastructure with no CLOUD Act exposure. Gaps: UK (non-EU) incorporation, UK + Canada primary hosting for the managed cloud, US sub-processors under SCCs, no public DPA download link, no EU certifications. ### combit CRM: https://euvetted.com/p/combit-crm - Website: https://www.combit.net - Category: CRM - Country of incorporation: Germany - Hosting country: Germany (Konstanz) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 1989 - Sub-processors list: https://www.combit.net/datenschutz/ - Last verified: 2026-05-18 Konstanz-based German CRM (combit Software, since 1989), founder-owned, on-prem + cloud, German Mittelstand vendor. combit Software GmbH (Buecklestrasse 3-5, 78467 Konstanz, Germany) is a long-running independent German software vendor founded in 1989 by Peter Bertl with Christiane Bertl involved from the beginning. The company remains founder-owned and -led with current management by Björn Eggstein, Jochen Bartlau, and Brita Dannenmann. combit ships two flagship products: the **List & Label** reporting toolkit (widely embedded by other German software vendors) and **combit CRM Relationship Manager**, a flexible customer-relationship product with **on-premise installation as a first-class deployment option** alongside cloud. For procurement-grade EU buyers combit has the strongest verified sovereignty signals in the category: German GmbH, founder-controlled, no external VC/PE, on-prem deployment available (full customer-controlled data sovereignty by construction), multi-decade operating history, no CLOUD Act exposure, and the kununu Top Company 2025-2026 employee-satisfaction signal. Pricing tiered across product editions; specific EUR amounts not captured at audit. **Compliance rationale:** combit Software GmbH (Konstanz, Germany; founded 1989 by Peter and Christiane Bertl, still founder-owned and -led; current management Björn Eggstein + Jochen Bartlau + Brita Dannenmann) is a long-running independent German Mittelstand vendor with two products, **List & Label** (reporting tool) and **combit CRM Relationship Manager**, both offered as **on-premise installation** alongside cloud, no external VC/PE ownership, kununu Top Company 2025-2026; on-prem deployment delivers full customer-controlled sovereignty by construction. **Sub-processors mapped:** 10 total, 3 US-owned - Google Ireland Limited (Ireland): Analytics, Ads, Maps, reCAPTCHA; ancillary (marketing-site tracking, not core CRM data) [US-owned] - LinkedIn Ireland Unlimited Company (Ireland): Social analytics; ancillary (marketing-site tracking, not core CRM data) [US-owned] - Microsoft Corporation (United States): Advertising / UET tracking; ancillary (marketing-site tracking, not core CRM data) [US-owned] - communiteq.com (Netherlands): Web hosting - Inxmail GmbH (Germany): Newsletter services - OVH GmbH (Germany): Web hosting - Personio GmbH & Co. KG (Germany): HR / recruitment management - Smartsupp.com, s.r.o. (Czechia): Live chat services - TERRA Cloud GmbH (Germany): Web hosting - WORTMANN AG (Germany): Web hosting ### ConsentManager: https://euvetted.com/p/consentmanager - Website: https://www.consentmanager.net - Category: Cookie consent - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €23/month) - Founded: 2017 - Certifications: ISO27001 - DPA: https://app.consentmanager.net/tac.php - Sub-processors list: https://app.consentmanager.net/tac.php - Last verified: 2026-05-12 German-owned CMP with own EU data centres (not hyperscaler); ISO 27001, IAB TCF v2 ID 31, 100K+ websites, from €23/mo. **ConsentManager.net** is the cleanest cookie-consent pick in this catalogue from a sovereignty perspective: German-operated, **own European data centres rather than cloud-hyperscaler dependency**, **ISO 27001** certified, IAB TCF v2 certified CMP (ID 31), Google Certified Partner, IAB GPP standard. Usage-based pricing scales from **Free** (3,000 views/mo) to **Starter €23/mo** (100K views) to Professional €219/mo (10M views) to Enterprise. 30+ UI languages, support for 2,500+ tools (analytics, ads, social), built-in cookie crawler. 100K+ customer sites. Differentiated by A/B-tested designs that aim for higher acceptance rates and lower bounce. For procurement buyers wanting a non-US-PE, non-hyperscaler-dependent CMP this is the strongest pick. **Compliance rationale:** **ConsentManager.net** is German-operated with **own European data centres** (not hyperscaler-dependent), **ISO 27001** certified, IAB TCF v2 CMP (ID 31), Google Certified Partner, IAB GPP standard support, 30+ UI languages, 100K+ websites; EU-owned, EU-hosted, no CLOUD Act exposure, the cleanest cookie-consent pick in the catalogue. ### Conta: https://euvetted.com/p/conta - Website: https://conta.com - Category: Accounting - Country of incorporation: Norway - Hosting country: Ireland - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: freemium (from €9/month) - Founded: 2009 - DPA: https://hjelp.conta.no/databehandleravtale/ - Sub-processors list: https://hjelp.conta.no/personvernerklaering/oversikt-over-underleverandorer/ - Last verified: 2026-06-12 Norwegian free-invoicing-first accounting SaaS (founded 2009); 165K+ users, Norwegian-owned (founders + Must Invest), but runs entirely on AWS. **Conta** started in 2009 as a free invoicing program built by three founders (a journalist, a developer and an accountant) frustrated with how hard it was to run a small business in Norway. It is operated by **Conta AS** (org 998 807 867) under parent **Conta Group AS** (org 816 909 252, a ~13-company group), headquartered in Stavanger with offices in Ålesund, Oslo and a development office in Brazil, plus remote developers worldwide (~67 employees). The hook is genuinely free, unlimited invoicing (Premium ~$10.49/mo billed annually unlocks reminders, recurring invoices, branding removal); optional paid add-ons cover bookkeeping, VAT/MVA filing via Altinn, bank sync (ZTL), payroll and EHF e-invoicing. 165,000–260,000 business users across ~10 countries (NO, ES, IE, AU, NZ, IN, ID, PH, ZA, US). Ownership is clean and local, founders plus **Must Invest AS** (Erik Must) since 2020, with **no US venture or private-equity capital**, and Conta Group also co-owns Norwegian email-marketing tool **Mailmojo**. The catch for sovereignty buyers is the substrate: customer invoices, files and databases live on **Amazon AWS** (EC2/S3/RDS/DynamoDB/Lambda), with SendGrid, Google, Sentry, New Relic and Meta/LinkedIn trackers in the stack. Conta keeps everything inside EU/EEA regions and mirrors a backup to Norwegian **Jottacloud**, but the host and a long tail of sub-processors are US-owned, so CLOUD Act exposure is material despite the Norwegian cap table. **Compliance rationale:** **Conta** (Conta AS, org 998 807 867; parent **Conta Group AS**, org 816 909 252; Stavanger/Ålesund/Oslo, Norway, founded 2009) is a genuinely **Norwegian-owned** free-invoicing-led accounting SaaS: founders plus **Must Invest AS** (Erik Must, Norwegian family investor since 2020); **no US PE/VC**, ownership signal `other` (Norway = EEA, not EU). Its public DPA and sub-processor list are a transparency plus. BUT the entire data substrate runs on **Amazon AWS** (EC2, S3, RDS, DynamoDB, Lambda), US-owned, alongside **SendGrid, Cloudmailin, New Relic, Sentry, Google (Analytics/Ads/Firebase), Performission, Autopilot, Facebook, LinkedIn**. Conta states all infrastructure/data sits within EU/EEA, but AWS as host plus 10+ US sub-processors means CLOUD Act exposure is `material` and the score caps at 3; only the Norwegian **Jottacloud** holds the backup copy. ### Contabo: https://euvetted.com/p/contabo - Website: https://contabo.com - Category: Cloud & hosting - Country of incorporation: Germany - Hosting country: Germany (Munich) - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid (from €5/month) - Founded: 2003 - Last verified: 2026-05-18 Munich-based budget VPS / dedicated hosting (Contabo GmbH); KKR + Oakley-owned since 2022; 11 global DCs; VPS from <€5/month. Contabo is a Munich-based German cloud-and-hosting provider operated by Contabo GmbH (Welfenstrasse 22, 81541 Munich; HRB 180722 at Amtsgericht München; VAT DE267602842; managing directors Stephan Wolfram and Mario Wilhelm). Founded in 2003 and positioned in the budget VPS / dedicated-server tier, Contabo reports more than 225,000 customers across 190 countries running on 450,000+ servers in nine global regions and eleven data-centre locations: European Union, United Kingdom, three United States locations, Singapore, Japan, India, and Australia. Pricing is the headline feature: Cloud VPS 10 starts at less than €5/month on annual billing (4 vCPU, 8 GB RAM), and the product surface covers Cloud VPS, Virtual Dedicated Servers, bare-metal dedicated servers, object storage, domain registration, and managed application hosting for n8n, Nextcloud, GitLab, and similar. For an EU-sovereignty audit the listing is mixed. The German GmbH legal structure, Munich HQ, Frankfurt-area data centres, and EU footprint look natively European, but in June 2022 a consortium led by **KKR**, the US private-equity giant (Kohlberg Kravis Roberts, New York), together with Oakley Capital (UK) acquired the majority of Contabo alongside the management team. KKR's US-incorporation gives Contabo material CLOUD Act exposure at the parent-jurisdiction layer regardless of where the EU customer's specific VM runs. Additionally, three of Contabo's eleven data centres are in the United States, which means buyers who don't pin their workloads explicitly to EU regions may end up on US infrastructure. The DPA and security URLs returned 404 at audit; certifications are not advertised on accessible public pages. Best fit: indie developers, small SaaS builders, gamers, and prosumers who prioritise low VPS price over enterprise compliance. Contabo is one of the cheapest credible European VPS providers globally. Procurement-grade EU buyers needing a strict EU-controlled cloud should prefer Hetzner (DE, family-owned), Scaleway (FR, Iliad), OVHcloud (FR, public Euronext), or STACKIT (DE, Schwarz Group / Lidl), listed above in this category. Contabo serves a complementary, price-led use case rather than a compliance-led one. **Compliance rationale:** Munich-based German GmbH (Contabo GmbH, HRB 180722 AG München, VAT DE267602842, founded 2003 by Stephan Wolfram and Mario Wilhelm) running 450k+ servers across 11 global locations; in June 2022 KKR (US private equity) together with Oakley Capital (UK) acquired the majority of the company, and the data-centre footprint includes three US locations plus Singapore/Japan/India/Australia alongside the EU regions; the US-PE majority parent means material CLOUD Act exposure at the parent-jurisdiction layer, and ownership is classified as eu_hq_us_funded rather than eu_owned. ### Cookiebot: https://euvetted.com/p/cookiebot - Website: https://www.cookiebot.com - Category: Cookie consent - Country of incorporation: Denmark - Hosting country: Denmark (Copenhagen) - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: freemium (from €11/month) - Founded: 2012 - Certifications: ISO27001, ISO27701 - DPA: https://www.cookiebot.com/en/data-protection-agreement - Sub-processors list: https://www.cookiebot.com/en/privacy-policy/ - Last verified: 2026-05-12 Danish cookie consent (Cybot A/S, est. 2012); ISO 27001 + ISO 27701; acquired by Usercentrics 2022 (now Vista Equity-owned). **Cookiebot** (operated by **Cybot A/S**, Copenhagen, founded 2012) is one of the largest consent management platforms in Europe: 2.4M websites, 8.8B monthly consents, 600K+ customers, Google-certified Gold-tier CMP partner, **ISO 27001 + ISO 27701** certified, own Danish infrastructure. The procurement-grade caveat is the ownership chain: **Cybot was acquired by Usercentrics in 2022** for ~€100M+; **Usercentrics was then acquired by Vista Equity Partners** (US private equity) in 2024. So Cookiebot today is German-owned at the operating-group level but US-PE-controlled at the ultimate-beneficial-ownership level. For procurement teams evaluating DACH cookie-consent vendors this is a critical fact rarely surfaced in marketing material. **Compliance rationale:** **Cookiebot** by **Cybot A/S** (Copenhagen DK, founded 2012) is **ISO 27001 + ISO 27701** certified with own Danish infrastructure, 600K+ customers, 2.4M sites; **acquired by Usercentrics in 2022**, and Usercentrics in turn was acquired by **Vista Equity Partners** (US private equity) in 2024, flipping the ownership chain to `eu_hq_us_funded` with material CLOUD Act exposure via the US-PE ultimate parent. ### Crisp: https://euvetted.com/p/crisp - Website: https://crisp.chat - Category: Helpdesk - Country of incorporation: France - Hosting country: France (Nantes) - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: freemium - Founded: 2015 - Sub-processors list: https://help.crisp.chat/en/article/nhv54c/ - Last verified: 2026-05-18 Nantes-based French customer-messaging platform (Crisp IM SAS, founded 2015); fully bootstrapped, no VC, 200k+ customers, flat-rate pricing. Crisp is a Nantes-headquartered French customer-messaging platform operated by **Crisp IM SAS** and founded in 2015 by **Baptiste Jamin** (CEO) and **Valerian Saliou** (CTO). One of the structurally cleanest ownership stories in the directory: the company is **fully bootstrapped** (no venture capital, no private equity, no acquiring conglomerate, no US legal entity) and remains founder-controlled a decade after launch. The product reports 200,000+ customers and serves SMBs, e-commerce, and SaaS through a flat-rate pricing model that explicitly rejects the per-agent metering that dominates the Intercom / Drift / Freshdesk pricing pattern. The product surface is broader than the original Crisp live-chat origin suggests: **Hugo** (the recently-launched AI support agent), the embeddable chat widget, multi-channel inbox (email, WhatsApp, Messenger, Telegram, SMS, Twitter), AI chatbots and agents, support CRM, ticketing, knowledge base, status pages, video and voice calls, and analytics. Crisp markets the suite as "Built from France 🇫🇷 / Made in Europe", the same positioning that procurement-grade buyers value when assessing alternatives to US-controlled competitors. The G2 awards stack (High Performer, Momentum Leader, Loved Winter 2025) and 14-day no-credit-card free trial reflect a polished SMB go-to-market. For an EU-sovereignty audit Crisp has the cleanest ownership structure in the helpdesk category. French SAS legal entity, founder-controlled, bootstrapped: these are the structural fundamentals that even more-established competitors (Userlike acquired by Lime; LiveChat publicly listed but with US sales presence; Tidio US-VC-funded) can't quite match. One gap is disclosure: a unified DPA artefact is only accessible via workspace settings (login required), not via a public link. Procurement teams should request a signed DPA before onboarding. The decisive nuance, however, is on the infrastructure side: core chat and conversation data is hosted at rest on DigitalOcean (a US-owned cloud provider) in Amsterdam (plugin infrastructure in Frankfurt). Because the host has a US parent that is compellable regardless of the EU region, the CLOUD Act flag is `material` despite the clean French ownership. The AI feature stack (Hugo, chatbot/agent components) adds a further US LLM-API dependency (typically OpenAI or Anthropic at this product scale in 2026). Best fit: French and EU SMBs / e-commerce / SaaS that want bootstrapped-founder ownership; companies that value flat-rate pricing over per-agent metering; buyers replacing Intercom or Drift with a structurally EU-independent vendor. **Compliance rationale:** Crisp IM SAS (Nantes, France; founded 2015 by Baptiste Jamin (CEO) and Valerian Saliou (CTO)) is a **fully bootstrapped French customer-messaging platform with no venture capital, no PE, no parent company**. 200,000+ customers on a flat-rate pricing model that explicitly rejects per-agent metering, with a 'Made in Europe' positioning, a French SAS legal entity and founder control. The CLOUD Act exposure is nonetheless **material**: core chat and conversation data is hosted at rest on DigitalOcean (a US-owned cloud provider) in Amsterdam, Netherlands (plugin infrastructure runs in Frankfurt, Germany). Because the underlying hosting provider has a US parent, customer messaging data carries material CLOUD Act exposure despite the EU regions and the EU subsidiary; the DPA is also not publicly accessible (reachable only via workspace settings inside a customer account, login required), a gap relative to procurement-grade buyers who expect a self-service DPA link. **Sub-processors mapped:** 5 total, 3 US-owned - Cloudflare (United States): CDN / edge infrastructure / DDoS protection [US-owned] - DigitalOcean (United States): Server hosting (messaging in NL, plugins in DE; per Crisp via EU subsidiary subject to EU law) [US-owned] - Stripe (United States): Payment processing (credit card storage) [US-owned] - Enrich (France): Data enrichment (automatic user avatars); owned, developed and operated by Crisp - Mirage (France): AI features (LiveTranslate, MagicReply); owned, developed and operated by Crisp ### Cronofy: https://euvetted.com/p/cronofy - Website: https://www.cronofy.com - Category: Calendar booking - Country of incorporation: United Kingdom - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2013 - Certifications: ISO27001, SOC2 - Last verified: 2026-05-11 Nottingham UK developer-API-first calendar / scheduling platform (Cronofy, founded 2013), ISO 27001 + SOC 2; Wise / GoCardless / Indeed customers. Cronofy is a Nottingham-headquartered British developer-API-first calendar and scheduling-automation platform, founded in 2013 by **Adam Bird** (CEO) and **Garry Shutler** (CTO). The product is positioned for two audiences: SaaS product builders who need to integrate scheduling features (calendar availability, multi-person + multi-room coordination, video-conferencing integration) into their own applications via a unified API; and enterprise process-automation teams who need to coordinate scheduling across HR / sales / recruiting workflows. The flagship customer roster (**Wise, GoCardless, Criteo, Teamtailor, Indeed, Squarespace**) is unusually high-quality for a 29-employee API company, with 180,000+ end-companies on the platform handling 1B+ events. Compliance posture is enterprise-grade: **ISO 27001, SOC 2, GDPR-aligned, HIPAA-aligned**, the standard stack required to serve the regulated-industry portion of the customer base. UK post-Brexit jurisdiction places Cronofy in the directory's `other` ownership tier; the UK holds an EU adequacy decision so cross-border EU↔GB transfers require no SCCs. Two procurement-relevant gaps weaken the EU signal picture: public reporting indicates Cronofy has been **acquired** (the acquirer is not directly disclosed at audit and the operating brand persists in the market), and approximately **60% of Cronofy's revenue is US-based**, which strongly suggests an AWS-EU + AWS-US dual-region backend that the directory's strict-ownership CLOUD Act stance treats as material exposure for at-rest customer data. A public DPA is not available; the data-processing agreement must be requested directly. Pricing is API-tier-based with per-event usage scaling; specific EUR tier figures were not captured at audit. Best fit: product builders integrating scheduling into B2B SaaS (HR-tech, recruiting, sales, customer-success), where Cronofy's ISO 27001 + SOC 2 + HIPAA stack and stable client roster reduce procurement friction. UK + EU customers should request the DPA, the underlying hosting region map, and post-acquisition ownership disclosure directly before signing. **Compliance rationale:** Cronofy (Nottingham, UK; founded 2013 by Adam Bird and Garry Shutler) is a developer-API-first scheduling-automation platform with **ISO 27001 + SOC 2 + GDPR + HIPAA** attested and 180,000+ companies on the platform handling 1B+ events; flagship customers Wise, GoCardless, Criteo, Teamtailor, Indeed, Squarespace. UK post-Brexit jurisdiction (`other` ownership tier) with an EU adequacy decision keeping transfers SCC-free. Three procurement-relevant gaps: (1) public reporting indicates the company has been acquired (acquirer not directly disclosed at audit); (2) **~60% of revenue is US-based**, suggesting an AWS-EU + AWS-US dual-region backend that the directory''s strict CLOUD Act stance flags as `material` exposure for at-rest customer data; (3) Cronofy does not publish a publicly accessible DPA; a data-processing agreement is available only on request via compliance@cronofy.com. Signal mix: ISO 27001 + SOC 2 + GDPR + HIPAA certified, EU adequacy for cross-border transfers, but no public DPA, undisclosed post-acquisition ownership, and material CLOUD Act flag. ### Cryptee: https://euvetted.com/p/cryptee - Website: https://crypt.ee - Category: File sharing - Country of incorporation: Estonia - Hosting country: Estonia (Tallinn) - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: freemium (from €3/month) - Founded: 2018 - Sub-processors list: https://crypt.ee/help/privacy - Last verified: 2026-05-18 Estonian-incorporated zero-knowledge encrypted photos / notes / docs PWA (Cryptee, 2018, John Ozbay), bootstrapped, open source. Cryptee is an Estonian-incorporated privacy-first Progressive Web App for encrypted photos, documents, notes, journal entries, files, and personal media, founded on 1 June 2018 by **John Ozbay** (a cybersecurity researcher, designer, and privacy activist based in Tallinn) and 100% bootstrapped with no outside investment. The product is engineered as a Google Photos / Google Docs / iCloud Photos / Evernote replacement for users who specifically want their cloud data to be unreadable to anyone except themselves: every document, note, photo, and file is encrypted client-side with AES-256 before it leaves the device, and Cryptee mathematically cannot read the content. The source code is open and publicly available for independent audit. Cryptee positions itself as particularly relevant for victims and survivors of domestic abuse, journalists and reporters, and activists: users whose threat model assumes the cloud provider could be coerced. For an EU-sovereignty audit Cryptee is structurally exemplary. Estonia is an EU member with a long-standing reputation for digital infrastructure and e-Residency, and crucially **Estonia is outside the Five-Eyes / Nine-Eyes / Fourteen-Eyes intelligence-sharing arrangements**, a positioning argument the vendor makes explicitly. Combined with zero-knowledge encryption, AGPL-style code openness, and a bootstrapped cap table with no US capital, Cryptee delivers an exceptionally clean EU-owned, EU-hosted, no CLOUD Act exposure posture. Privacy advocacy partnerships include the Electronic Frontier Foundation (EFF) and Privacy International. As a small solo-led operation, Cryptee does not pursue formal ISO 27001 / SOC 2 attestations. Pricing in EUR: Free tier (limited storage); €3/month (Plus); €9/month (Pro); €27/month (Studio); annual discounts available. No SSO, audit log, or on-prem options at this scale. Best fit: individual privacy-conscious users, journalists, activists, NGOs, and small teams whose threat model demands true zero-knowledge encryption and minimal regulatory surface area. Procurement-grade enterprise buyers with SSO/audit/compliance documentation needs should choose Proton Drive or Tresorit instead. **Compliance rationale:** Cryptee (Tallinn, Estonia; founded June 2018 by John Ozbay) is a 100% bootstrapped Progressive-Web-App for zero-knowledge encrypted notes, documents, journals, photos, and files: **AES-256 client-side encryption before data leaves the device**, **fully open source for public audit**, Estonia is **outside the 14-Eyes intelligence-sharing arrangement**, and no VC/PE involvement on the cap table; however the verified sub-processor list (2026-06) shows the primary host is Google Cloud (a US-owned hyperscaler), with Cloudflare, Stripe and Sentry also US, so CLOUD Act exposure is material on a structural reading, though client-side AES-256 encryption means Google stores only ciphertext and Cryptee holds no keys; EU-owned with open-source clients, but no public DPA (the /help/privacy and /help/terms paths return 404; no DPA document exists on the public site), the key documentation gap for procurement buyers. **Sub-processors mapped:** 5 total, 4 US-owned - Cloudflare Portugal, Unipessoal Lda. (Portugal): CDN and security services [US-owned] - Google Ireland Ltd. (Google Cloud Platform) (Ireland): Cloud infrastructure / data storage and hosting (primary host) [US-owned] - Sentry Software Netherlands B.V. (Sentry.io) (Netherlands): Error collection and reporting [US-owned] - Stripe.com (United States): Payment processing (subscriptions after 2021-02-21) [US-owned] - Paddle.com Market Ltd (United Kingdom): Payment processing (subscriptions before 2021-02-21) ### CryptPad: https://euvetted.com/p/cryptpad - Website: https://cryptpad.org - Category: Docs & wikis - Country of incorporation: France - Hosting country: France (Paris) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium - Founded: 2014 - Last verified: 2026-05-18 Paris-based E2E-encrypted open-source collaboration suite (CryptPad by XWiki SAS), NLnet/NGI-EU-funded; zero-knowledge architecture. CryptPad is the canonical end-to-end-encrypted open-source collaboration suite, actively developed by a team at **XWiki SAS**, a Paris-based French company that has been building open-source software since 2004. The platform delivers a Google Docs / Notion / Microsoft Office Online alternative built around zero-knowledge encryption: documents are encrypted on the user's device before any data leaves it, and XWiki itself has no ability to read customer documents. The product surface covers rich text, code, slides, forms, kanban, calendar, polls, whiteboard, sheet, and team drives: a complete office-suite-grade feature set running entirely E2E. Funding architecture is the structurally interesting story. **CryptPad is funded by NLnet PET, NGI TRUST, NGI DAPSI, and the NGI Zero Commons Fund**, the European Commission's Next Generation Internet (NGI) programme that channels EU public-research money into European-sovereign open-source infrastructure. Additional funding comes from **CryptPad.fr subscribers and Open Collective donations**. This combination (**EU public funding + community subscriptions**) gives CryptPad a structurally different cap table from any US-VC-funded competitor: no exit pressure, no dilution risk, no acquisition rumours, and explicit alignment with the European Commission's sovereign-tech agenda. Pricing for CryptPad.fr (the managed cloud) is freemium with paid storage tiers; the entire codebase is open source on GitHub (cryptpad/cryptpad) and self-hostable for organisations wanting full control. Best fit: privacy-maximalist EU teams, journalists and activists, EU public-sector and education buyers (where NLnet / NGI funding lineage is itself a procurement signal), and any organisation that wants a full office suite where the vendor structurally cannot read the documents. **Compliance rationale:** CryptPad is the **end-to-end encrypted open-source collaboration suite** developed by **XWiki SAS** (Paris, France; making open-source software since 2004). Funded by **NLnet PET, NGI TRUST, NGI DAPSI, NGI Zero Commons Fund** (European Commission's Next Generation Internet programme) plus CryptPad.fr subscribers and Open Collective donations, making this one of the most clearly **EU-publicly-funded sovereign-tech projects in the directory**. Zero-knowledge encryption means even XWiki cannot read customer documents; full source on GitHub; self-hostable on EU infrastructure. Signals: EU-owned (French SAS), EU-hosted, EU public funding lineage, end-to-end encrypted (zero-knowledge), no CLOUD Act exposure, no US-VC, no US legal entity. Gap: no publicly accessible DPA. The DPA is reachable only inside a customer account for paid Organisation-Plan holders; no public sub-processors list. ### Customerly: https://euvetted.com/p/customerly - Website: https://www.customerly.io - Category: Helpdesk - Country of incorporation: Ireland - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid - Founded: 2017 - DPA: https://drive.google.com/file/d/176QjkP1zx9BmrASmpHQNygOJwkjlty-Q/view?usp=sharing - Last verified: 2026-05-11 Dublin-based Italian-founded customer messaging + AI CRM (Customerly Ltd, 2017); EU-only data storage; Aura AI Assistant solves 71% of support volume. Customerly is a Dublin-headquartered customer-messaging + AI CRM platform operated by **Customerly Limited** (71 Lower Baggot Street, Dublin D02 P593, Ireland; incorporated on 5 October 2017). The company was founded by Italian entrepreneurs **Luca and Daniele**, who met in 2012 while completing MBAs in entrepreneurship at MIP Politecnico di Milano and later chose to incorporate in Ireland following mentorship advice that an Irish Limited or US INC structure is the standard scalable SaaS vehicle. The product is built around **Aura AI Assistant** (the company reports Aura solves 71% of support ticket volume and saves agents ~19 hours per month), AI Live Chat, Help Center, NPS + surveys, Chatflows, Knowledge Base, and workflow automation, positioned for B2C SaaS businesses as an Intercom / Drift / Freshdesk alternative. For an EU-sovereignty audit the listing is structurally clean on the ownership side: Irish Limited Company, no PE or VC ownership chain visible at audit, Italian founder team, no US legal entity disclosed. The corporate page commits explicitly that "all data is stored in EU only", the most procurement-relevant signal in the category. The product carries Software Advice / Capterra / GetApp "Leader" badges. Where the listing weakens for the strictest procurement-grade buyers is in the formal disclosure layer: a DPA is available only on email request (not a public self-service link), no named sub-processors list is publicly indexed, and the underlying hosting provider for the EU-only data is not disclosed. AI components (Aura) imply at least one US-cloud or US-API dependency (likely OpenAI or Anthropic for the LLM backbone), which is the standard pattern for AI-augmented SaaS in 2026 and the reason the CLOUD Act flag sits at `minor`. Pricing is per-feature / per-volume tiered; specific entry-tier EUR figures were not captured at audit. Best fit: B2C SaaS businesses needing AI-augmented customer support with native EU data-residency commitments, Italian / Irish / European SMB and mid-market SaaS teams, and any organisation that prefers a Dublin-incorporated counterparty over a US-incorporated competitor (Intercom, Drift) for category-equivalent features. **Compliance rationale:** Customerly Limited (Dublin, Ireland; 71 Lower Baggot Street, D02 P593; incorporated 5 October 2017 by Italian entrepreneurs Luca and Daniele after MBA studies at MIP Politecnico di Milano) is a B2C SaaS-focused AI customer-service + CRM product with Aura AI Assistant, live chat, knowledge base, NPS, and chatflows. The corporate page commits explicitly that 'all data is stored in EU only'. Clean Irish ownership with no PE / VC chain visible, EU-only data residency claim, multiple G2 / Capterra / GetApp 'Leader' designations. EU-owned and EU-only data residency verified. Key gap: Customerly does not publish a publicly accessible DPA (available only via email request to legal@; no public self-service link exists); no sub-processors list is publicly indexed either. ### CyberGhost: https://euvetted.com/p/cyberghost - Website: https://www.cyberghostvpn.com - Category: VPN - Country of incorporation: Romania - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: paid (from €2/month) - Founded: 2011 - Sub-processors list: https://www.cyberghostvpn.com/privacypolicy - Last verified: 2026-05-15 Romanian-operated VPN (CyberGhost S.R.L., 2011) under Kape Technologies (UK; ex-Crossrider) → Unikmind/Teddy Sagi (IM) since 2023; listed as a warning. CyberGhost is operated by CyberGhost S.R.L., headquartered in Bucharest, Romania, with the product itself dating to 2011. It is included in this directory primarily because of its Romanian operations and historical brand recognition in the privacy-VPN category, but the ownership chain is the editorial story, and it is the reason this listing carries an ownership-watch warning. The chain runs as follows. In 2017 CyberGhost was acquired for €9.1M by **Kape Technologies plc**, an AIM-listed UK holding company that has since become the largest VPN consolidator in the consumer market. Kape's portfolio also includes **ExpressVPN, Private Internet Access (PIA), Zenmate, and the VPN review site VPN Mentor**, the last of which is a structural conflict of interest, since a holding company that owns multiple VPN services should arguably not also own the most-trafficked review/comparison site for that same category. Kape Technologies began life as **Crossrider**, an Israeli ad-tech and browser-extension business with a well-documented adware history; the rebranding to "Kape Technologies" was a deliberate distancing move. On **19 May 2023 Unikmind Holdings Limited** (an Isle of Man-registered vehicle controlled by Israeli businessman **Teddy Sagi**) secured ~98.5% of Kape's shares in a take-private deal valuing the company at approximately £1.25-1.51bn, and Kape **delisted from AIM on 31 May 2023**. Against that backdrop, the product-level signals look reasonable in isolation: an **independent Deloitte audit** confirmed no user-data storage; AES-256 encryption with kill-switch and DNS-leak protection; NextGen 10-Gbps servers across 100+ countries; 24+ supported platforms; 20+ UI languages; Bitcoin payment via BitPay; a 45-day money-back guarantee. Pricing on the 26-month plan reaches €1.75/month, among the cheapest in the category, which is itself a Kape-pricing pattern. None of those product strengths offset the structural concerns of the ownership chain for a directory whose value proposition is sovereignty + auditable corporate trust. CyberGhost is therefore listed as **a warning rather than a recommendation**, with the full Crossrider-Kape-Unikmind-Sagi history surfaced in the rationale, which is exactly the kind of editorial scoop no other EU directory currently makes visible. EU buyers wanting a clean Romanian VPN should look outside the Kape stable; sovereignty buyers should prefer Mullvad, OVPN, ProtonVPN, IVPN or AirVPN. **Compliance rationale:** CyberGhost is operated by **CyberGhost S.R.L.** in Bucharest, Romania (founded 2011). But the entire ownership chain sits well outside the EU: parent **Kape Technologies plc** (UK, AIM-listed until May 2023) acquired CyberGhost for €9.1M in 2017, and **on 19 May 2023 Kape was taken private by Unikmind Holdings Limited** (an Isle of Man vehicle controlled by **Israeli businessman Teddy Sagi**) at a ~£1.25-1.51bn valuation, delisting from AIM on 31 May 2023; Kape was originally **Crossrider**, an Israeli ad-tech / browser-extension business with a documented adware history, and the same Kape group also owns **VPN Mentor, a VPN review site (a structural conflict of interest)** alongside ExpressVPN, PIA and Zenmate; the product itself has a Deloitte no-logs audit and accepts Bitcoin, but the combination of Romanian-operations + UK Kape parent + Isle-of-Man Unikmind + Crossrider history + review-site conflict means CyberGhost carries no EU-ownership or no-CLOUD-Act-exposure signals: it is listed as a warning rather than a recommendation. ### DatoCMS: https://euvetted.com/p/datocms - Website: https://www.datocms.com - Category: Headless CMS - Country of incorporation: Italy - Hosting country: Ireland (Milan) - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium (from €39/month) - Founded: 2015 - Sub-processors list: https://www.datocms.com/legal/gdpr - Last verified: 2026-05-12 Italian developer-friendly headless CMS (Milan); 25K+ businesses; bootstrapped feel, no US PE. **DatoCMS** (operated by **Dato srl**, Milan, Italy) is a developer-friendly headless CMS positioned as "the most complete, user-friendly and performant Headless CMS": 25,000+ businesses, scaling from small teams to enterprises with 250+ editors managing global content operations. Paid plans from **€39/mo** (Agency Partner tier; regular tier from similar entry point); free tier available for hobby projects. Mostly self-funded / bootstrapped feel, no identified US-PE majority involvement, placing DatoCMS in `ownership_signal: eu_owned`. The procurement-grade caveat is verification depth: no public ISO 27001 / SOC 2 attestation surfaced on marketing site at time of research, review trust/security pages directly with the vendor before promoting. **Compliance rationale:** **DatoCMS** (Dato srl, Milan IT) is a smaller bootstrapped-feel Italian headless CMS serving 25,000+ businesses; no US-PE involvement identified; `ownership_signal: eu_owned`; ISO 27001 / SOC 2 attestation not surfaced publicly and sub-processor list not disclosed; for procurement-grade buyers verify trust / security pages directly with the vendor before promoting. ### Didomi: https://euvetted.com/p/didomi - Website: https://www.didomi.io - Category: Cookie consent - Country of incorporation: France - Hosting country: France (Paris) - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid (from €19/month) - Founded: 2017 - Certifications: ISO27001 - Sub-processors list: https://trust.didomi.io/subprocessors - Last verified: 2026-05-12 Paris-based enterprise CMP (founded 2017); ISO 27001, Google-certified CMP; clients include Volvo, Michelin, Yahoo. **Didomi** (Paris, France, founded 2017) is an enterprise-grade Consent Management Platform with a strong roster of European brands: **Volvo, Yahoo, Michelin, Lacoste, Rakuten**. ISO 27001 certified, Google Certified CMP partner, IAPP Bronze Member. The platform covers consent collection, **Preference Management**, **Privacy Request automation**, **Compliance Monitoring**, and **server-side tagging**, broader than pure cookie-banner vendors. Cap table is mostly European (Breega, Elaia, BPI France, Smartfin), no US PE majority identified at time of research. For French / European procurement buyers wanting an alternative to the Vista-controlled Usercentrics / Cookiebot stack, Didomi is the strongest enterprise CMP option in the catalogue. **Compliance rationale:** **Didomi** (Paris FR, founded 2017) is **ISO 27001** certified, Google-certified CMP, IAPP Bronze Member, enterprise customer base (Volvo / Yahoo / Michelin / Lacoste / Rakuten); funded primarily by EU + FR investors (Breega, Elaia, BPI France, Smartfin) with no identified US-PE majority, `ownership_signal: eu_owned`, minor CLOUD Act exposure; DPA and sub-processor list not publicly surfaced. ### Dintero: https://euvetted.com/p/dintero - Website: https://www.dintero.com - Category: Payments - Country of incorporation: Norway - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: paid - Founded: 2017 - DPA: https://www.dintero.com/legal/dpa - Sub-processors list: https://www.dintero.com/legal/dpa - Last verified: 2026-06-12 Oslo fintech (Dintero AS): Finanstilsynet-authorised PI and, since 2025, the only Norwegian-owned direct Visa/Mastercard acquirer; checkout for e-com, marketplaces and physical retail. Dintero is an Oslo-headquartered Norwegian fintech operated by **Dintero AS** (Nydalsveien 36A, 0484 Oslo; org.nr 919 656 395), founded in 2017 by Daro Navaratnam and team (ex-dSAFE, which was acquired by Bambora). It delivers a unified checkout and payment platform (Dintero Checkout) for online stores, platforms, marketplaces and physical retail, bundling cards, Vipps, Swish, invoice and financing (BNPL), payment links, recurring billing, in-person/POS and marketplace split-payment flows, plus adjacent CRM/loyalty tooling. The company is authorised as a **payment institution under the Norwegian Financial Supervisory Authority (Finanstilsynet)** with EEA passporting across the EU/EEA, and in April 2025 went live as a **principal Visa acquiring member**, completing a ~three-year process to become a direct Visa/Mastercard acquirer, which the company markets as the only Norwegian-owned direct acquirer and Norway's first new acquirer in over 20 years. Going direct means Dintero controls the chain from point-of-sale to the card networks without an intermediary acquirer. For an EU/EEA-sovereignty audit Dintero is one of the cleanest ownership stories in the payments category. Total external funding is small (~US$5-7M over a handful of rounds) and the cap table is overwhelmingly Nordic: **Schibsted Ventures** (Norwegian media group's venture arm), **Bring Ventures** (the venture arm tied to Posten Bring, the Norwegian state postal group), **CoFounder** and **Harding Invest** (both Norwegian), with **Mastercard Lighthouse** (Mastercard's Nordic startup-engagement programme) as a minor US-linked participant. There is no US private-equity or US-VC controlling stake, no US parent, and no Delaware operating entity. Because Norway is EEA but not EU, ownership is flagged `other` (a sovereignty positive, not the US-funded caveat that weighs on Mollie/Trustly/Klarna/SumUp). The honest caveat is infrastructure transparency: Dintero does not publicly name its hosting/cloud provider or data-residency region, publishes no standalone self-serve DPA (data-processing terms sit as Annex 1 to the merchant agreement) and no named sub-processors list (the privacy policy references an unnamed "infrastructure provider"). The Visa/Mastercard scheme connectivity is unavoidable US-headquartered payment rails and is distinct from where customer/transaction data is stored; the data-at-rest substrate here is simply unverified, so the CLOUD Act flag is set to `minor` defensively rather than `none`. Pricing is sales-led / volume-negotiated (no public per-transaction rate card), with merchant onboarding via Dintero's own back-office and plugins for WooCommerce, Magento, NopCommerce and Optimizely. Best fit: Norwegian and broader Nordic e-commerce, marketplaces/platforms and omnichannel retailers who want native Vipps/Swish + cards through a single Finanstilsynet-regulated, Norwegian-owned counter-party, and EEA buyers who prioritise a clean non-US ownership chain over published-DPA self-service. Procurement teams that require a public DPA, named sub-processors and disclosed hosting region should request these in writing before onboarding. **Compliance rationale:** **Dintero AS** (Oslo, org.nr 919 656 395, founded 2017 by Daro Navaratnam) is a Finanstilsynet-authorised payment institution with EEA passporting and, since April 2025, a full principal **Visa/Mastercard acquiring licence**, making it, on its own framing, the only Norwegian-owned direct Visa/Mastercard acquirer (Norway's first new acquirer in 20+ years). It is a PCI DSS Level 1 Service Provider and a GDPR data controller. Ownership is genuinely clean-Nordic: Schibsted Ventures (NO), Bring Ventures (NO, Posten/Bring), CoFounder (NO) and Harding Invest (NO), with Mastercard Lighthouse (US accelerator) as a minor program investor. No US PE/VC control, so `ownership_signal: other` (Norway, EEA but non-EU) is a sovereignty positive. The drag on the compliance score is transparency: no self-serve standalone DPA (it lives as Annex 1 to the merchant agreement), no public named sub-processors list, and the cloud substrate is not publicly disclosed, so `cloud_act_exposure: minor` is set defensively (card-scheme Visa/Mastercard connectivity is payment rails, not data-at-rest exposure; the data-at-rest hosting provider is simply unverified). Caps at 4/5 pending a public DPA + named-hosting disclosure. ### Doodle: https://euvetted.com/p/doodle - Website: https://doodle.com - Category: Calendar booking - Country of incorporation: Switzerland - Hosting country: Germany - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: freemium - Founded: 2007 - Certifications: SOC2 - DPA: https://doodle.com/en/data-processing-addendum - Sub-processors list: https://help.doodle.com/en/articles/9457241-list-of-data-subprocessors - Last verified: 2026-05-18 Swiss group-scheduling pioneer (Doodle AG, Zurich, 2007), owned by TX Group (SIX-listed Swiss media holding); SOC 2 + GDPR + HIPAA. Doodle is the Swiss group-scheduling pioneer headquartered in Zurich, operated by **Doodle AG** and founded in 2007 as a no-account meeting-scheduling poll (the "Doodle poll" that became a generic verb in many European business contexts during the 2010s). The product has since expanded into a full meeting-scheduling + time-management platform (Doodle Time OS) competing directly with Calendly and Acuity but with a heritage of group-availability scheduling that the US incumbents historically lacked. Ownership is unusually clean for a 19-year-old SaaS: in January 2014, **Tamedia** (the Swiss publishing giant since renamed and reorganised into the publicly-listed **TX Group**, SIX Swiss Exchange ticker CH0011178255) completed a 100% acquisition of Doodle, and the company has remained a fully-owned subsidiary inside the TX Group's portfolio. TX Group is widely-held on the Swiss public market with no US-PE controlling stake on the cap table; this gives Doodle a Swiss-publicly-listed corporate parent without the Cohere / Vista / KKR-style US-PE risk seen elsewhere on this directory. Compliance posture is enterprise-ready: **SOC 2 compliant**, **GDPR** + **CCPA** + **HIPAA** aligned, and **Cyber Verify Level III** attested. Headcount stood at **127 employees** as of March 2026. Pricing is freemium with paid Pro, Team, and Enterprise tiers; specific entry-tier EUR figures were not captured at audit (pricing page was JS-rendered and showed placeholders). Best fit: EU and Swiss SMBs and enterprises who want a group-scheduling tool with a Swiss-publicly-listed corporate counterparty, regulated industries needing HIPAA / SOC 2 attestation, and any procurement-grade buyer preferring the TX Group / Swiss-public-listed ownership architecture over US-VC-funded competitors (Calendly, Acuity). The underlying hosting provider is not publicly disclosed at audit, which is the procurement-question gap to close before signing. **Compliance rationale:** Doodle AG (Zurich, Switzerland; founded 2007 as the original group-scheduling polling tool) is **wholly owned by the TX Group**, the Swiss publicly-listed media holding (SIX Swiss Exchange: CH0011178255, formerly Tamedia, completed 100% acquisition in January 2014). Compliance posture covers **SOC 2**, GDPR, CCPA, HIPAA, and Cyber Verify Level III; 127 employees (March 2026); 19-year operating history. Signal mix: Swiss legal entity under a Swiss-publicly-listed parent with no US-PE control, EU/CH adequacy for cross-border transfers, multi-framework compliance attestation (SOC 2, GDPR, CCPA, HIPAA, Cyber Verify Level III), and a public DPA at doodle.com/en/data-processing-addendum; CLOUD Act flag at `minor` pending vendor disclosure of the underlying hosting provider. No public sub-processors list found at audit. ### Element (Matrix): https://euvetted.com/p/element-matrix - Website: https://element.io - Category: Video conferencing - Country of incorporation: United Kingdom - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2017 - Certifications: ISO27001 - DPA: https://element.io/data-processing-agreement - Sub-processors list: https://element.io/data-processing-agreement - Last verified: 2026-05-18 UK-headquartered open-source Matrix protocol commercialisation; powers Bundeswehr BwMessenger + French Tchap + NATO + UN. Element is the commercial entity behind the open-source **Matrix** decentralised messaging-and-collaboration protocol, a Slack / Microsoft Teams / WhatsApp / Signal alternative engineered specifically for digital sovereignty and federation. The protocol was created in 2014 by **Matthew Hodgson (CEO/CTO)** and **Amandine Le Pape (COO)** while they were working at Amdocs; the commercial entity **New Vector Ltd** was spun out in 2017, rebranded to Element in 2020, and renamed **Element Creations Limited** in 2025. The Matrix protocol itself is custodied by the independent **Matrix.org Foundation** (established 2018), separate from Element the company, which gives the protocol the same kind of structural independence that the Linux Foundation provides for Linux. Element's procurement-grade positioning is unmatched in the EU-sovereignty conversation. **The German Bundeswehr's BwMessenger** (the official secure messenger used daily by the entirety of Germany's Armed Forces) is a fork of Element built by BWI GmbH (Bundeswehr's IT supplier) and Element together; BwMessenger is described in Bundeswehr / BWI communications as "the cornerstone of the Bundeswehr's communication infrastructure". The **French government's Tchap and Visio** (the chat and video-conferencing components of La Suite numérique, the French government workspace suite) are both built on Matrix. Other reference customers include **NATO, UN, HM Government, US Space Force, US Marines, and Swedish agencies**. Certifications: **ISO/IEC 27001:2022, Cyber Essentials Plus, OpenChain ISO/IEC 5230** (open-source supply-chain compliance). Deployment is sovereign-friendly by design. Element Server Suite is sold as software that customers run on their own infrastructure, including air-gapped deployments for defence and government use, and the Matrix protocol itself is fully open source (Apache 2.0). Element's regional structure includes **Element Software GmbH (Germany)** and **Element Software SARL (France)** for EU-customer contracting, alongside the UK parent (Element Creations Ltd) and a US subsidiary (Element Software Inc). Element Cloud is the managed SaaS option. Investors include Automattic, Notion, First Minute Capital, Status, Protocol Labs, and Metaplanet. Best fit: governments, defence ministries, regulated industries, and any organisation that wants federated cross-organisation communication on a sovereign-deployable open-source protocol. The UK post-Brexit jurisdiction (`other` ownership tier) is the only nuance for the strictest procurement criteria. The German + French subsidiaries are available for buyers who need an EU-incorporated counterparty. **Compliance rationale:** Element Creations Limited (UK, formerly New Vector Ltd, founded 2017; renamed 2025) is the commercial entity behind the open-source **Matrix decentralised messaging protocol** created by Matthew Hodgson and Amandine Le Pape. Independent custody of the protocol sits with the **Matrix.org Foundation** (2018). The company holds **ISO/IEC 27001:2022, Cyber Essentials Plus, and OpenChain ISO/IEC 5230**, runs regional subsidiaries in Germany (Element Software GmbH) and France (Element Software SARL) for EU-customer contracting, and powers the German Bundeswehr's BwMessenger (Bundeswehr-wide secure messaging) and the French government's Tchap + Visio inside La Suite numérique. Other customers: NATO, UN, HM Government, US Space Force, US Marines, Swedish agencies. Open-source Matrix protocol + self-host as the default deployment pattern + multi-entity EU contracting: ISO 27001 certified, public DPA with disclosed sub-processors, open-source clients. The **managed Element Cloud** carries `material` CLOUD Act exposure: it runs on AWS (US hyperscaler) with US-incorporated sub-processors for CRM (HubSpot), analytics (PostHog) and comms (Twilio). Message content is E2EE, but account/operational data sits with US-jurisdiction processors, the same managed-vs-self-host duality as other sovereign messengers. **Self-hosting on EU infrastructure removes the exposure entirely** (`effective_cloud_act_if_self_hosted: none`), which is the procurement-default path for the Bundeswehr BwMessenger and French Tchap deployments. **Sub-processors mapped:** 6 total, 5 US-owned - Amazon Web Services (AWS) (United States): Cloud infrastructure / hosting [US-owned] - HubSpot (United States): CRM / customer management [US-owned] - PostHog (United States): Product analytics [US-owned] - Stripe (United Kingdom): Payment processing (UK entity, US parent) [US-owned] - Twilio (United States): Communications / SMS services [US-owned] - Zammad (Germany): Customer support / ticketing ### EmailOctopus: https://euvetted.com/p/emailoctopus - Website: https://emailoctopus.com - Category: Email marketing - Country of incorporation: United Kingdom - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: freemium (from €0/month) - Founded: 2014 - DPA: https://wordpress-media.emailoctopus.com/blog/uploads/2022/07/EmailOctopus-DPA-Final-4-July-22.pdf - Sub-processors list: https://docs.google.com/spreadsheets/d/e/2PACX-1vSjAnGYQME6C5_-sLM2e6L3dhVXXJWM17P7QfXzcmaMnRu2zwirJ7vG1kkGbgvfTF0-mAwWWl20ZYK8/pubhtml - Last verified: 2026-05-11 London-based low-cost email marketing (Three Hearts Digital, 2014), generous free tier, indie-friendly, Amazon SES-backbone. EmailOctopus is the low-cost email-marketing service operated by **Three Hearts Digital Ltd** at 86-90 Paul Street, London EC2A 4NE, United Kingdom. The product targets indie creators, bloggers, small SMBs, and price-sensitive marketers who want a Mailchimp / MailerLite / ConvertKit alternative with a particularly generous free tier (free up to a meaningful subscriber count) and competitive paid pricing, for example approximately $480/year at 100,000 subscribers. The brand is well-known in the indie-hacker and content-creator community. For an EU-sovereignty audit the listing has structural caveats. The operating entity is UK-incorporated post-Brexit (UK adequacy decision under Art. 45 GDPR keeps transfers EU↔UK legally clean), but EmailOctopus historically built its product as a thin layer on top of **Amazon Simple Email Service (Amazon SES)** for the actual mail delivery, a US-owned hyperscaler dependency for the core product workload. No public ISO 27001 / SOC 2 certifications, no named sub-processors page, and the hosting region for application data is not publicly disclosed. The brand is GDPR-compliant per the homepage, but procurement-grade buyers needing detailed transfer documentation should request the DPA directly. Pricing in EUR / USD: free tier with no credit card required; paid tiers scale by subscriber count with monthly or annual billing (10% discount for annual). Best fit: indie creators, low-volume bloggers, small SMBs, and price-sensitive marketers who want a serviceable Mailchimp alternative and accept the UK + Amazon SES dependency. Procurement-grade EU buyers should choose CleverReach (DE) or rapidmail (DE) at SMB tier, or Maileon / Inxmail at enterprise. **Compliance rationale:** **Three Hearts Digital Ltd** (London, 86-90 Paul Street, EC2A 4NE) operates EmailOctopus as a low-cost subscriber-based email marketing service with a generous free tier: GDPR-compliant, indie-friendly, and **competitively priced** ($480/year at 100k subscribers); but UK post-Brexit jurisdiction + no public certifications (ISO 27001 / SOC 2) + hosting provider not disclosed (AWS likely at this low-cost scale, given EmailOctopus's historical relationship with Amazon SES as the underlying delivery backbone). UK-incorporated (adequacy-covered) with material CLOUD Act exposure via presumed Amazon SES delivery dependency and no public sub-processors or DPA disclosure. ### Enonic: https://euvetted.com/p/enonic - Website: https://www.enonic.com - Category: Headless CMS - Country of incorporation: Norway - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: freemium - Founded: 2000 - Certifications: ISO27001, ISO9001 - DPA: https://www.enonic.com/platform/security - Sub-processors list: https://enonic.com/cloud/third-party-suppliers - Last verified: 2026-06-12 Norwegian headless/hybrid CMS (Oslo, est. 2000); founder-owned, ISO 27001 + 9001 certified; but managed Enonic Cloud runs on Google Cloud + Azure + Fastly. **Enonic** (Enonic AS, Oslo, founded 2000) is Norway's largest Norwegian-owned CMS vendor, a hybrid headless / visual-editing content platform built on its open-source **Enonic XP** runtime, positioned directly against Optimizely, Contentful and Sanity. Founder-owned by Morten Øien Eriksen and Thomas Sigdestad with no identified VC or PE capital, it is one of the cleaner ownership stories in the category. Compliance posture is genuinely strong: **ISO 27001:2022** (annually externally audited against all 93 controls) and **ISO 9001:2015** certified, GDPR-compliant with a designated Data Privacy Officer, DORA-aligned, a publicly downloadable DPA, and a public sub-processor list. The important nuance for sovereignty buyers is the **managed Enonic Cloud** infrastructure: Enonic's own third-party-suppliers page lists the production IaaS as **Google Cloud Platform** (US-owned, EU region), **Microsoft Azure** for encrypted off-site backups (Sweden), **Fastly** (US) for CDN, plus Mailgun (DE), Auth0 and Zendesk (EU), and Slack (US) for community support. So while the *company* is Norwegian and bootstrapped, the *hosted data at rest* sits on US-owned hyperscalers within the EEA: material CLOUD Act exposure. Buyers who need true sovereignty can instead self-host the open-source XP runtime (GPL-3.0 with a linking exception) on Hetzner / OVH / Scaleway, which removes the US sub-processors from the data path. Pricing: a free tier (5 GB), with Professional and Enterprise tiers quoted on request (no public EUR price). **Compliance rationale:** **Enonic** (Enonic AS, Oslo, founded 2000) is **ISO 27001:2022 + ISO 9001:2015 certified** (annual external audit of the 93 InfoSec controls), GDPR-compliant with a named Data Privacy Officer, DORA-aligned, and publishes both a downloadable DPA and a public sub-processor list, a strong governance posture. **Norway is EEA/EFTA but not EU**, and ownership is founder-led (Morten Øien Eriksen + Thomas Sigdestad) with no identified VC/PE/US capital, hence `ownership_signal: other` (clean Norwegian local-hero on paper). The procurement caveat is the **managed Enonic Cloud stack itself**: per its own third-party-suppliers page the production IaaS is **Google Cloud Platform** (US-owned, EU region) with **Microsoft Azure** for encrypted off-site backups (Sweden) and **Fastly** (US) as CDN; data-at-rest lives on US-owned hyperscaler infrastructure inside the EEA, which is textbook **material CLOUD Act exposure** despite the Norwegian cap table. The escape hatch is self-hosting the open-source Enonic XP runtime on EU-sovereign infra, which removes Google/Azure/Fastly entirely. ### Eversign (Xodo Sign): https://euvetted.com/p/eversign - Website: https://eversign.com - Category: E-signature - Country of incorporation: Austria - Hosting country: United States - Ownership signal: us_owned - CLOUD Act exposure: direct - Pricing tier: paid - Founded: 2017 - Certifications: SOC2 - DPA: https://eversign.com/legal/dpa - Sub-processors list: https://eversign.com/legal/subprocessors - Last verified: 2026-05-11 Vienna-launched e-signature platform (eversign GmbH, 2017), acquired by Apryse (US/PDFTron) in 2022, rebranded as Xodo Sign. Eversign was originally founded in 2017 as a Vienna-headquartered e-signature platform operating as **eversign GmbH** (Austrian Firmenbuch FN572452t, with offices also in London), at launch one of the more promising EU-based DocuSign alternatives, with SOC II + GDPR + eIDAS + UETA compliance and a flat developer-API-friendly pricing model. In **2022 the company was acquired by Apryse** (formerly PDFTron Systems Inc.), a US-Canadian document-processing technology group headquartered in Denver, Colorado with operations in Vancouver, Canada (the same Apryse that runs the **Xodo** consumer PDF tools). Post-acquisition, the Eversign product was integrated into the Apryse portfolio and rebranded as **Xodo Sign**; the eversign.com URL persists primarily for SEO continuity and existing customer accounts. For an EU-sovereignty audit the listing now sits firmly outside the procurement-grade tier despite the Austrian engineering heritage. The controlling entity is a US-incorporated parent (Apryse / PDFTron Systems Inc.), which under our strict-ownership stance is `us_owned` with `direct` CLOUD Act exposure. The product retains its eIDAS-compliant signature workflow and Austrian/UK operating presence, but contracts are now with the Apryse-controlled entity rather than with an EU-controlled vendor. Compliance attestations carry through: SOC II / GDPR / eIDAS / UETA. Pricing follows the Apryse-portfolio strategy with transparent per-user / per-document tiers; specific entry-tier EUR figures were not captured at audit. Best fit: existing eversign customers who already have contracts, US-headquartered enterprise buyers using the wider Apryse stack (Xodo / PDFTron). Procurement-grade EU-only buyers should choose **Yousign (France, eIDAS-qualified)**, **Skribble (Switzerland, ZertES + eIDAS)**, **Universign (France, qualified trust service provider)**, or **Signaturit (Spain, eIDAS-qualified Barcelona)** instead; all listed in this category and structurally cleaner under the strict-ownership stance. **Compliance rationale:** Eversign GmbH (Vienna + London, founded 2017) launched as an EU-based e-signature platform with SOC II + GDPR + eIDAS + UETA attestation, but in 2022 it was **acquired by Apryse (formerly PDFTron Systems Inc., headquartered in Denver, Colorado, USA with operations in Vancouver, Canada)** and subsequently rebranded as **Xodo Sign**. The resulting product is `us_owned` with `direct` CLOUD Act exposure under a US parent; it retains a legacy Vienna engineering operation, eIDAS-compliant signature workflow, and a continuing EU-customer base, but procurement-grade EU buyers should choose Yousign (FR, EU-headquartered, eIDAS-qualified), Skribble (CH, no CLOUD Act exposure, ZertES + eIDAS), Universign (FR) or Signaturit (ES) instead; all structurally cleaner than a US-owned parent, with Skribble the cleanest on CLOUD Act exposure (Universign and Signaturit are US-private-equity-owned and AWS-hosted, so `material` rather than `none`). ### Exoscale: https://euvetted.com/p/exoscale - Website: https://www.exoscale.com - Category: Cloud & hosting - Country of incorporation: Switzerland - Hosting country: Switzerland (Geneva) - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: paid (from €9/month) - Founded: 2011 - Certifications: ISO27001, ISO27017, ISO27018 - DPA: https://www.exoscale.com/dpa/ - Sub-processors list: https://www.exoscale.com/privacy/ - Last verified: 2026-05-18 Swiss public cloud (Akenes SA, A1 Digital member), 6 EU/CH zones, ISO 27001 + FINMA + TISAX, Swiss-data-residency guarantee. Exoscale is a Swiss public cloud operated by Akenes SA (Boulevard de Grancy 19A, 1006 Lausanne; CHE-423.524.322), founded in 2011 and a member of A1 Digital, the digital subsidiary of A1 Telekom Austria Group, the largest telecoms group in Central and Eastern Europe. The product covers compute, storage, AI/GPU instances, Kubernetes (SKS), DBaaS (PostgreSQL, MySQL, Redis, OpenSearch, Kafka, Valkey), and object storage across six European data-centre zones: Switzerland (Geneva CH-GVA-2 and Zurich CH-DK-2), Austria (Vienna AT-VIE-1 and AT-VIE-2), Germany (Frankfurt DE-FRA-1), and Croatia (Zagreb HR-ZAG-1). Pricing is billed by the second at a flat rate across all zones, with no upfront commitment. Compliance is enterprise-grade and built specifically for regulated workloads. Exoscale carries ISO/IEC 27001:2022, ISO 27017, ISO 27018, the **Swiss FINMA Circular 2018/3** outsourcing framework (essential for Swiss financial-services customers), TISAX (German automotive supply-chain security), DORA-readiness for EU financial-services operational resilience, and the full Cloud Security Alliance 100-control-point framework. Operating under Swiss law and the Swiss Federal Data Protection Act, the company explicitly guarantees that "data uploaded in one of our Swiss zones is stored in Switzerland only": no cross-border transfers. The Swiss zones are housed in Equinix-managed facilities with strict physical-access controls; decommissioned drives are destroyed or cryptographically locked. Switzerland's EU adequacy decision (Art. 45 GDPR) keeps transfers between CH and EU jurisdictions legally clean without SCCs. Sub-processors are deliberately minimal: Aiven Oy (Helsinki, FI) handles DBaaS orchestration; Adyen (NL) and PostFinance / PayPal cover payments; Matomo (NZ-incorporated, EU-self-hostable) handles portal analytics; Mailchimp is used for newsletters but no permanent email storage; AWS appears solely as an **archival** sub-processor, the only US-owned dependency, holding the CLOUD Act flag at `minor` rather than `none`. Compute, Storage, and SKS currently have **no third-party processors listed**. The EU GDPR representative is A1 Digital International GmbH (Lassallestrasse 9, Vienna, AT). Best fit: Swiss financial-services (FINMA-regulated), DACH automotive supply-chain (TISAX), regulated public-sector buyers, and EU companies that want Swiss data residency with EU/CH adequacy clarity. **Compliance rationale:** Lausanne-based Swiss public cloud (Akenes SA, member of Austrian Telekom A1 Group's A1 Digital), founded 2011, with ISO/IEC 27001:2022 + ISO 27017 + ISO 27018 + FINMA Circular 2018/3 + TISAX + DORA-ready, six EU/EEA + CH data-centre zones in Geneva, Zurich, Vienna ×2, Frankfurt, and Zagreb, and a Swiss-data-residency guarantee for workloads placed in Swiss zones; AWS appears as an archival sub-processor on the customer-data path, which is the sole reason a minor CLOUD Act flag applies. Compute, object storage and SKS workloads stay on the EU/CH stack with no US dependency. **Sub-processors mapped:** 7 total, 3 US-owned - Amazon Web Services, Inc. (United States): Archival sub-processor; customer-data backups/archives at rest (US-owned); sole reason for the minor CLOUD Act flag, kept off the live customer workloads [US-owned] - Mailchimp (Intuit Inc.) (United States): Newsletter delivery with no permanent email storage; ancillary, off the customer-data path [US-owned] - PayPal (United States): Payment processing; ancillary, off the customer-data path [US-owned] - Adyen N.V. (Netherlands): Payment processing; ancillary, off the customer-data path - Aiven Oy (Finland): Orchestration of data infrastructure services instances (DBaaS) running on Exoscale Compute - InnoCraft Ltd (Matomo) (New Zealand): Portal/website analytics; ancillary, EU-self-hostable, off the customer-data path - PostFinance AG (Switzerland): Payment processing; ancillary, off the customer-data path ### Factorial: https://euvetted.com/p/factorial - Website: https://factorialhr.com - Category: HR & people - Country of incorporation: Spain - Hosting country: Germany - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid (from €7/month) - Founded: 2016 - Certifications: ISO27001, SOC2 - Last verified: 2026-05-12 Spanish HR + payroll + finance SaaS (Barcelona, est. 2016); 16K+ customers, ISO 27001 + SOC 2 + AWS EU, US-VC-funded. **Factorial** (Barcelona, Spain, founded 2016 by Jordi Romero, Pau Ramon, and Bernat Farrero) is a fast-growing Iberian HR-and-business-management SaaS: 16,000+ customers across HR, payroll, time tracking, talent, finance, and IT modules. Compliance: **ISO 27001 (ENAC), SOC 2 Type II (AICPA)**, AWS EU hosting. The product is genuinely Spanish-built, but the cap table is heavily US: **Tiger Global**, **CRV**, **General Catalyst**, **GGV** lead recent rounds, with Atomico (UK) and Creandum (EU) as European voices. For procurement evaluation Factorial is "Spanish-operating, US-VC-controlled", similar to Personio's posture. **Compliance rationale:** **Factorial** (Barcelona ES, founded 2016) is **ISO 27001 + SOC 2 Type II** certified with AWS EU hosting and 16,000+ customers; cap table includes **Tiger Global**, **CRV**, **General Catalyst**, **GGV** (all US VCs) plus Atomico (UK) and Creandum (EU). Material US-VC funding flips signal to `eu_hq_us_funded` and creates CLOUD Act influence. ### factro: https://euvetted.com/p/factro - Website: https://www.factro.de - Category: Project management - Country of incorporation: Germany - Hosting country: Germany (Bochum) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium - Last verified: 2026-05-18 German PM software (factro by Schuchert Managementberatung, Bochum), 100% Made in Germany, free tier for up to 10 users. factro is a German project-management product operated by **Schuchert Managementberatung GmbH & Co. KG** in Bochum, Germany. The brand positions itself explicitly around "100% Made in Germany": all customer data is stored on German servers, the product is **DSGVO and BDSG-neu compliant**, and the operating entity is a founder-led management-consulting firm with no external venture-capital or private-equity involvement on the cap table. The product covers projects, tasks, time tracking, document management, and reporting with particular adoption in the German public administration sector and across 30+ industries. factro serves more than **5,000 organisations and 100,000 users** and offers a free tier covering up to 10 users with no credit card required and no subscription obligation, an unusually generous freemium for the German PM market. Paid tiers add advanced reporting, automation, and unlimited project depth. The German-only hosting, DSGVO compliance, EU ownership, and no CLOUD Act exposure are strong signals; the main gap is that the DPA is not publicly downloadable: it is provided on request to paid-plan customers only. Best fit: German and DACH SMBs, public administration, and mid-market teams that want a German-rooted PM alternative to Asana / Monday / Trello with explicit DSGVO posture and free-tier evaluation path. Together with Stackfield and MeisterTask, factro forms a three-pillar German-rooted PM shortlist. **Compliance rationale:** factro is operated by **Schuchert Managementberatung GmbH & Co. KG** in Bochum, Germany with explicit **'100% Made in Germany'** positioning: all customer data stored in German data centres, **DSGVO + BDSG-neu compliant**, EU-owned, no CLOUD Act exposure; serves 5,000+ organisations and 100,000+ users across 30+ industries with particular strength in German public-administration sectors. The DPA gap is the main caveat: factro does not publish a publicly accessible DPA; a data-processing agreement is available on request for paid-plan customers only rather than as a self-serve download. No formal ISO 27001 certification is publicly advertised. ### Fiken: https://euvetted.com/p/fiken - Website: https://fiken.no - Category: Accounting - Country of incorporation: Norway - Hosting country: Norway - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: paid (from €20/month) - Founded: 2014 - DPA: https://fiken.no/sluttbrukeravtale - Sub-processors list: https://fiken.no/sluttbrukeravtale/datautveksling - Last verified: 2026-06-12 Norwegian cloud accounting for sole traders and small companies; founder-owned, Norway-hosted, flat monthly pricing. **Fiken** (Fiken AS, Oslo, founded 2014) is Norway's most popular do-it-yourself cloud accounting tool for sole proprietorships (enkeltpersonforetak) and small limited companies (aksjeselskap). It bundles bookkeeping, invoicing, bank reconciliation, VAT/MVA reporting, payroll with a-melding, annual accounts and the tax return into one flat monthly fee: from ~229 NOK/mo (~€20) for sole traders and ~349 NOK/mo for an AS, after a 30-day free trial. There is no permanent free tier. The product is praised for radical simplicity and a strong public REST API (api.fiken.no) widely used by Norwegian fintech integrations, banks and accountants. Crucially for a sovereignty audit, Fiken is one of the rare profitable, fully founder-owned European SaaS companies: the three founders, Bendik Gill Bakken (CEO), Joakim Blomskøld and Aleksander Blomskøld, still hold ~33.33% each, with no PE, VC or US capital on the cap table (Finansavisen reported in April 2025 that the trio had each become NOK-billionaires on the business; ~87 employees, ~375M NOK 2024 revenue). Primary data is hosted in Norway, partly to satisfy the Norwegian Bookkeeping Act, in a datacenter the company says is ISO 27001:2013 / ISO 9001:2015 certified. The caveat is the sub-processor stack: the published databehandler list names AWS, Microsoft and Google for backup, OpenAI for AI assistance, plus a long tail of US SaaS (Intercom, Freshdesk, Mailchimp, Twilio, Sentry, New Relic, Slack, Notion, Meta), all under SCCs. The UI is Norwegian-only, so practical reach is the Norwegian market rather than pan-EU. **Compliance rationale:** **Fiken AS** (Oslo, founder-owned, primary data hosted in Norway in an ISO 27001/9001 datacenter with a publicly accessible DPA) nonetheless lists 20+ US-owned sub-processors (including AWS, Microsoft and Google for *backup of stored data* plus OpenAI for AI features), so despite a clean Norwegian core the data-at-rest backup chain creates material CLOUD Act exposure, capping the score at 3/5. ### Filen: https://euvetted.com/p/filen - Website: https://filen.io - Category: File sharing - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium (from €2/month) - Founded: 2021 - Sub-processors list: https://filen.io/privacy - Last verified: 2026-05-18 German zero-knowledge E2E cloud (Filen Cloud Dienste UG, Recklinghausen, 2021), Tier IV ISO 27001 DCs, no US data, open source apps. Filen is a German-headquartered zero-knowledge end-to-end encrypted cloud-storage product operated by **Filen Cloud Dienste UG (haftungsbeschränkt)**, founded in mid-2021 in **Recklinghausen, Germany** by Jan Lenczyk (CEO + CTO), Jan Kulartz (COO + CMO), and Phil Hedrich (CDO + Customer Care). The product is structurally similar to Mega and Internxt (every file is encrypted on the user's device with AES-256 before it leaves the client, the encryption keys never reach Filen's servers, and the company mathematically cannot read uploaded content) and ships as Filen Drive, Filen Notes, Filen Chats, Filen Sync, and a network-drive client across Windows, macOS, Linux, iOS, Android, and the web. The applications are open source on GitHub for independent audit. For an EU-sovereignty audit Filen is among the cleanest listings in the file-sharing category. **All servers are located in Germany** in **Tier IV ISO 27001-certified high-security data centres** across multiple regions for disaster-recovery redundancy. The vendor states explicitly that **no data is stored in the United States**, an unusually strong commitment for a product at this price point. German data-protection law (Bundesdatenschutzgesetz) applies on top of GDPR, and the UG legal structure is a German limited-liability format. The ownership chain is clean: founder-led with no VC/PE investors on record. Customer keys, file content, file names, and metadata are all encrypted client-side: zero-knowledge end-to-end. Among the strong EU-owned file-sharing alternatives (Proton Drive, Tresorit, Internxt, Filen, Cryptee), Filen wins on price-to-performance for users who want German jurisdiction specifically. Pricing is the most aggressive in the directory's encrypted-cloud category: free tier available with limited storage; **Pro I starts at €1.99/month for 200 GiB**; Pro II / III / IV scale up with more storage and higher upload caps; unlimited bandwidth, uploads, client-side encryption, syncing, and file sharing across all paid tiers. No lifetime plans (vendor explicitly opts out). Best fit: privacy-conscious individuals and small teams who want German jurisdiction, zero-knowledge encryption by default, open-source apps, and aggressive pricing; particularly relevant for journalists, NGOs, and SMBs in DACH. **Compliance rationale:** Filen Cloud Dienste UG (Recklinghausen, Germany; founded mid-2021 by Jan Lenczyk, Jan Kulartz, and Phil Hedrich) runs an explicit ''next-generation zero-knowledge end-to-end encrypted cloud'' from **Tier IV ISO 27001-certified German data centres** with **no data stored in the United States**, AES-256 client-side encryption, **open-source applications on GitHub**, and a founder-led cap table with no external venture capital; sub-processors are disclosed on the /privacy page (Stripe IE, PayPal US, Cloudflare US, Sentry US); EU-owned and EU-hosted with only **minor CLOUD Act exposure**: the US-jurisdiction sub-processors are all transient (payments, error telemetry, bot protection) and, because storage is zero-knowledge end-to-end encrypted, none of them can read file content; zero-knowledge E2E encryption, open-source clients, and disclosed sub-processors; the key documentation gap is no standalone public DPA URL. **Sub-processors mapped:** 7 total, 5 US-owned - Cloudflare, Inc. (United States): Bot protection via Turnstile (Standard Contractual Clauses) [US-owned] - Coinbase Inc. (United States): Cryptocurrency payment processing (Standard Contractual Clauses) [US-owned] - PayPal Inc. (United States): Payment processing (Standard Contractual Clauses) [US-owned] - Sentry Inc. (United States): Error management / telemetry (Standard Contractual Clauses) [US-owned] - Stripe Payments Europe Ltd. (Ireland): Payment processing [US-owned] - Fider (Germany): Feature-suggestion tool (open source, self-hosted by Filen on its German infrastructure) - Plausible Analytics (Estonia): Web analytics (self-hosted by Filen in Germany) ### Findmind: https://euvetted.com/p/findmind - Website: https://findmind.ch - Category: Forms & surveys - Country of incorporation: Switzerland - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: freemium - Founded: 2009 - Last verified: 2026-05-11 Swiss research-focused online survey tool operated by Fabian Keller since 2009; used by University of Zurich researchers. Findmind is a Swiss online survey tool operated by Fabian Keller as a single-operator service since 2009. The product is positioned for academic and market research workflows (multilingual surveys, multiple question types, graphical reports, Excel/Word export, custom banners and images) and is referenced inside the University of Zurich's Banking & Finance research-tools catalogue, which is a strong (if niche) credibility signal for procurement teams in higher education. The footer copyright reads "© Fabian Keller 2009–2023", suggesting a minimally-maintained but stable product surface. For an EU-sovereignty audit the listing sits in the "other (Switzerland)" tier. Switzerland is not an EU member but holds an EU adequacy decision under Art. 45 GDPR (renewed by the European Commission), so cross-border transfers between EU and CH do not require SCCs, a legally clean position. What is not exposed on the public website at audit time is the rest of the procurement-grade chain: there is no resolvable DPA URL, no public sub-processors page, no explicit hosting-provider disclosure, no security overview, and no imprint with a CHE Handelsregister number; the legal-entity structure looks like a sole proprietorship rather than an AG or GmbH. With no positive evidence of US-owned hyperscaler use we set CLOUD Act exposure defensively to `minor`, but procurement-led buyers should request the underlying hosting provider and a written DPA before signing. Pricing was not captured at audit (the public landing page rendered only a browser-compatibility notice to WebFetch); the product positions itself as "free/cheap" with a freemium model in CHF and EUR. Best fit: Swiss academic researchers, German-speaking market-research teams, and SMBs that want a simple Swiss-incorporated survey tool with multilingual question support. Procurement-grade buyers requiring named hosting + DPA should prefer Tally (BE) or Tripetto (NL) in this category, both audited below. **Compliance rationale:** Swiss research-focused survey tool operated by Fabian Keller as a sole proprietor since 2009. Switzerland holds an EU adequacy decision and the customer base is heavily academic (used by the University of Zurich), but the public site does not expose a formal DPA, sub-processors list, hosting disclosure, or imprint with CHE registration number; with no positive evidence of US-cloud at rest the CLOUD Act flag is set defensively to minor, pending vendor disclosure of hosting provider and written DPA. ### Formbricks: https://euvetted.com/p/formbricks - Website: https://formbricks.com - Category: Forms & surveys - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: freemium (from €82/month) - Founded: 2022 - Certifications: SOC2 - DPA: https://formbricks.com/dpa - Sub-processors list: https://formbricks.com/dpa - Last verified: 2026-05-21 German open-source experience-management platform (Formbricks GmbH, Kiel) for link, website and in-product surveys; AGPLv3, self-hostable. Formbricks is a German open-source experience-management platform operated by Formbricks GmbH (Kuhnkestr. 6, 24118 Kiel), founded in 2022 by Johannes Dancker and Matti Nannt. It positions itself as the open-source Qualtrics alternative and covers link surveys, website and in-product (in-app) surveys, and email-embedded feedback forms, with event-triggered targeting, user segmentation, conditional logic, multi-language surveys, file uploads, webhooks, and SDKs. The full core application is licensed under AGPLv3 on GitHub and is fully self-hostable. For an EU-sovereignty audit the ownership tier is eu_hq_us_funded: Formbricks is a German GmbH but is backed by OSS Capital (a US open-source-focused VC), Flex Capital, and the GitHub Accelerator, with angels including Tom Preston-Werner (GitHub) and Peer Richelsen (Cal.com). The managed Formbricks Cloud (app.formbricks.com) is hosted in Germany on Amazon Web Services, which handles the database and email at rest. The DPA is publicly downloadable without signup and lists its Annex IV sub-processors: AWS (DE region), PostHog (DE region), Stripe (US), Sentry (DE region), Brevo (FR), Google Cloud (EU), and Chatwoot (US). The company holds SOC 2 Type II and states ISO 27001 is in progress. Per the directory's strict CLOUD Act stance (provider parent jurisdiction matters more than data-centre region), AWS at rest plus the US sub-processors plus US-VC ownership make this material CLOUD Act exposure for the managed cloud. Self-hosting the AGPLv3 build on EU-incorporated infrastructure (Hetzner, OVHcloud, Scaleway) removes the AWS and US sub-processor exposure entirely, making the customer the sole data controller. Pricing: a free Hobby tier (250 responses/month, 1 workspace); Pro at US$89/month (~€82); Scale at US$390/month. Note "USA hosting" is an opt-in add-on, so the default cloud is Germany. Self-hosting is free under AGPLv3. Best fit: privacy-conscious product teams and EU developers replacing Qualtrics or Qualaroo for in-product surveys, or wanting a GDPR-compliant, self-hostable feedback layer. The self-host path is the procurement-grade option. **Compliance rationale:** German GmbH (Kiel) shipping an AGPLv3 open-source survey/forms platform with a publicly-downloadable DPA (sub-processors in Annex IV) and SOC 2 Type II, but the managed Formbricks Cloud runs on AWS in Germany for database + email at rest, with Stripe/Google Cloud/Sentry/PostHog/Chatwoot alongside it and US VC (OSS Capital) on the cap table, EU-headquartered but US-VC-funded with material CLOUD Act exposure for the managed cloud; self-hosting the AGPLv3 build on EU infrastructure removes the AWS and US sub-processor exposure entirely. **Sub-processors mapped:** 7 total, 6 US-owned - AWS (United States): Database and email delivery (data storage) [US-owned] - Chatwoot (United States): Customer support [US-owned] - Google Cloud (United States): Smart functionality (opt-in; does not touch respondent data) [US-owned] - PostHog (United States): Product analytics (anonymized IP and device information; EU region) [US-owned] - Sentry (United States): Error tracking and diagnostics [US-owned] - Stripe (United States): Payment processing [US-owned] - Brevo (France): Marketing/communication and admin notifications ### Formdesk: https://euvetted.com/p/formdesk - Website: https://www.formdesk.com - Category: Forms & surveys - Country of incorporation: Netherlands - Hosting country: Netherlands (Wassenaar) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2004 - DPA: https://formdesk.com/en/processor-agreement-avg/ - Last verified: 2026-05-18 Dutch enterprise forms platform (Innovero Software Solutions B.V., Wassenaar, 20+ years), NL-only hosting. Formdesk is a Dutch enterprise online-forms platform operated by **Innovero Software Solutions B.V.** at Rijksstraatweg 713, 2245 CC Wassenaar, Netherlands. The product specialises in online form creation with workflow automation, targeting Dutch enterprise customers (corporates, public administration, education, healthcare) and the broader European market with over 20 years of operating history. Hosting is exclusively Netherlands-based; certifications are listed at /en/certifications/ (specifics not captured at audit). **Compliance rationale:** **Innovero Software Solutions B.V.** (Wassenaar, Rijksstraatweg 713, Netherlands) operates Formdesk as a Dutch enterprise forms platform with **Netherlands-based hosting** and 20+ years of operating history, targeting Dutch and broader European markets; full Dutch B.V. legal entity, founder-controlled, EU-owned and EU-hosted with no CLOUD Act exposure, and a public DPA at /en/processor-agreement-avg/. ### Formspark: https://euvetted.com/p/formspark - Website: https://formspark.io - Category: Forms & surveys - Country of incorporation: Switzerland - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: freemium (from €23/month) - Founded: 2018 - Sub-processors list: https://formspark.io/legal/subprocessors/ - Last verified: 2026-05-11 Developer form-backend (form-to-email API) flagged as Swiss; 20k+ customers, one-time-payment bundles, no UI. Formspark is a developer-focused form backend that handles servers, databases, and analytics so the developer keeps full control over markup and styling. Founded in 2018 and trusted by more than 20,000 customers across React, Vue, Next.js, WordPress, Webflow, and static-site setups, the service is positioned as a Formspree alternative for solo developers, agencies, and freelancers. The MVP shortlist flags Formspark as Switzerland-based; the public marketing surface does not directly confirm a CH legal entity, so this listing is provisional and depends on vendor outreach for an accurate Imprint / Mentions légales. Compliance disclosures are thin at audit. The homepage footer references Terms, Privacy, and a GDPR section; the dedicated /privacy, /dpa, /security, and /imprint URLs all returned 404 to WebFetch, and the underlying hosting provider for form submissions is not publicly named. Without a published DPA artefact, a named sub-processors list, or an explicit hosting-region commitment, procurement-grade buyers cannot independently verify the EU/CH residency claim today. The CLOUD Act flag is set defensively to `minor` (no positive evidence of US-cloud at rest, but also no positive disclosure of EU-only stack). Pricing is unusual and EU-buyer-friendly: a free tier exists, and the paid bundle is US$25 (currently 50% off from US$50) for 50,000 submissions, 100 forms, and unlimited team members on a one-time payment basis; data bundles do not expire, and there is no recurring subscription. Best fit: indie developers and small agencies who need a no-frills form-to-email backend with one-time-payment economics. Procurement-grade buyers needing a self-served DPA, named sub-processors, and a confirmed EU hosting region should look at Tally (BE) or Tripetto FormBuilder SDK (NL self-host) in this category instead. **Compliance rationale:** Small Swiss-flagged developer form-backend service (Formspark, founded 2018, ~20k customers) sold as a no-UI form-to-email API with a one-time-payment bundle model; footer links to Privacy and GDPR docs but DPA, sub-processors, security, and imprint URLs were not resolvable at audit and the underlying hosting / data-residency story is not publicly disclosed. Switzerland adequacy decision keeps transfers legally clean, but the CLOUD Act flag is set defensively to minor pending vendor disclosure of hosting provider and a written DPA. ### Freepik: https://euvetted.com/p/freepik - Website: https://www.freepik.com - Category: Sovereign AI - Country of incorporation: Spain - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium - Founded: 2010 - Last verified: 2026-05-21 Spanish AI image generation platform (Pikaso, F Lite model) by the Freepik Group; majority-owned by Swedish PE firm EQT; 200M+ users. Freepik is a Málaga-based Spanish technology platform founded in 2010 by Alejandro Sánchez, Pablo Blanes, and Joaquín Cuenca. Originally a search engine for stock design resources, the company has evolved into a full-stack generative AI image platform. The AI offering centres on **Pikaso**, Freepik's own text-to-image generator, and **F Lite** (an open text-to-image model released in April 2025, trained on commercially licensed "safe-for-work" images) alongside **Freepik Enterprise** (launched May 2025) for organisation-level AI image generation with centralised management, brand safeguards, and legal indemnification for generated content. The company has grown aggressively through acquisitions: Videvo (stock video/audio, June 2022), Iconfinder (icon platform, October 2022), EyeEm (photography marketplace, October 2023), and most notably **Magnific** (Spanish AI image upscaling startup, May 2024), whose technology now powers AI enhancement and upscaling inside the Freepik platform; the parent group later renamed itself to reflect this transformation. The company is **majority-owned by EQT AB**, a Swedish private equity firm listed on Nasdaq Stockholm, which acquired a majority stake in 2020. EQT is EU-headquartered (Stockholm), making Freepik's beneficial ownership EU-controlled with no US PE or US parent exposure in the primary ownership chain. From an EU-sovereignty stance, Freepik presents a straightforward `eu_owned` case on the ownership axis: Spanish incorporation, Swedish (EU) PE majority-shareholder, founders still involved. The compliance picture is weaker: no public DPA URL, no sub-processors list, and no EU-specific certifications (C5, EUCS, SecNumCloud, ISO 27001) were found at audit. The US-cloud exposure for the hosted API and image-generation service is also unclear; the company's hosting infrastructure is not publicly detailed. The F Lite model is Apache 2.0–licensed open weights, enabling EU buyers to run self-hosted image generation on EU GPU infrastructure if they need full data sovereignty. Best fit: creative professionals and marketing teams wanting EU-incorporated AI image generation with a broad asset library; procurement-grade buyers requiring DPA should negotiate directly with Freepik Enterprise. **Compliance rationale:** Freepik (Málaga, Spain; founded 2010; majority-owned by Swedish PE EQT, Nasdaq Stockholm, which is EU-owned) operates Pikaso, a text-to-image generator powered by their own F Lite open model (April 2025) and Stable Diffusion, with 200M+ users. EU-owned with no US-PE majority, but no public DPA, no public sub-processors list, and no EU-specific certifications found at audit; hosting infrastructure undisclosed. ### F-Secure VPN: https://euvetted.com/p/f-secure-vpn - Website: https://www.f-secure.com/en/vpn - Category: VPN - Country of incorporation: Finland - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid (from €4/month) - Founded: 1988 - Certifications: ISO27001 - Sub-processors list: https://www.f-secure.com/en/legal/privacy/consumer/vpn - Last verified: 2026-07-10 Finnish publicly listed VPN (F-Secure Corporation, Helsinki; Nasdaq Helsinki: FSECURE), formerly FREEDOME VPN, ISO 27001-certified company-wide but with no independently audited no-logs claim. F-Secure VPN, formerly branded FREEDOME VPN, is operated by F-Secure Corporation, a Finnish company headquartered at Tammasaarenkatu 7, Helsinki (Business ID 3269349-7). F-Secure traces back to Data Fellows, founded on 16 May 1988 by Petri Allas and Risto Siilasmaa. The company as it exists today is the product of a 1 July 2022 partial demerger: WithSecure Corporation (the pre-2022 combined entity) split its consumer-security business into a newly listed F-Secure Corporation on **Nasdaq Helsinki (ticker FSECURE)**, while the corporate/enterprise-security business kept the WithSecure name. Co-founder **Risto Siilasmaa** remains F-Secure's largest shareholder, reported at roughly 40% of shares outstanding, with no foreign or US corporate parent identified in the ownership chain. F-Secure holds a company-wide **ISO/IEC 27001:2022** certification (KPMG IT Certification Ltd, certificate FI241106-169) covering its Helsinki, Oulu, Bratislava, Kuala Lumpur, Bengaluru and Hilversum offices. The product itself is a consumer VPN sold standalone or bundled inside F-Secure Total. It offers virtual server locations in "over 20 countries" per F-Secure's own marketing copy, which does not give an exact server or country count, so both are recorded as null here rather than guessed. Plans cap at 5 simultaneous devices. Two VPN protocol generations are in circulation: the older version runs OpenVPN and IPSec/IKEv2, and the newer version (rolled out via app updates) runs **WireGuard, the proprietary Hydra protocol, and IPSec**. Kill switch is available on Windows, macOS and Android (not documented for iOS). Port forwarding is not offered or mentioned anywhere in F-Secure's own documentation. The no-logs picture is the reason this listing scores low despite clean ownership. F-Secure's own VPN privacy notice states plainly that it does **not** log which destination addresses a customer connects to, but it separately discloses that it **does** retain VPN service-provisioning logs, source public IP address, a randomly generated device ID, GeoIP-derived country, and access timestamps, for **one year**, plus VPN service-log events for provisioned devices for **three months**, and temporary abuse-detection logs for 90 days. This is exactly the kind of connection metadata that, in January 2019, Finland's National Bureau of Investigation formally requested from F-Secure in connection with a serious-crime investigation led by German prosecutors; F-Secure handed the logs over, then went to court arguing the seizure was overbroad and coercive. In May 2019 a Finnish district court agreed, and after the NBI's appeal, the **Helsinki Court of Appeal ruled the seizure of the FREEDOME VPN logs unlawful and ordered the data destroyed**. The logs at issue reportedly contained customer IP addresses, device IDs, and VPN session start/end times, not visited-site records, so the "no logging of destination traffic" claim survives narrowly, but the case is direct, real-world proof that F-Secure's VPN retains and can be compelled to hand over identifying connection metadata. No independent third-party audit (Cure53, Deloitte, PwC or otherwise) of any F-Secure no-logs claim was found on F-Secure's own site or in its press materials, which puts F-Secure behind every audited competitor in this directory (Mullvad, IVPN, ProtonVPN, NordVPN, Surfshark, CyberGhost, Opera VPN) on the one axis this category is built around. F-Secure's own VPN privacy notice additionally discloses that the newer WireGuard/Hydra VPN version is provided with the help of an **unnamed third-party infrastructure provider** that also processes customer data; its identity and jurisdiction are not published. Separately, an F-Secure staff reply in the company's own community forum states that F-Secure uses roughly 10-20 different third-party hosting providers worldwide for its physical servers, legally owned by F-Secure with exclusive physical access, but does not name them. Neither disclosure confirms a US-owned sub-processor, so `cloud_act_exposure` is recorded as `minor` rather than `material`, but the lack of a named, auditable sub-processor list is itself a transparency gap. **Finland is a member of the 14 Eyes intelligence-sharing alliance**, the same jurisdictional caveat this directory applies to Sweden (Mullvad, OVPN) and Norway (Opera VPN); it does not by itself lower the ownership signal, but it is a fact EU/EEA buyers evaluating jurisdictional exposure should weigh alongside the no-logs gap above. Pricing is subscription-only with no persistent free tier: a 5-day free trial is offered, and F-Secure's own site advertises annual plans at **EUR 49.99/year for 1 device** (the true entry price, equivalent to about EUR 4.17/month, billed annually), EUR 69.99/year for 3 devices, and EUR 79.99/year for 5 devices, alongside pricier 2-year commitments. A 30-day money-back guarantee applies. F-Secure runs its own affiliate programme (hosted via Cleverbridge/Partnerize) covering F-Secure Total, Internet Security, Scam Protection and VPN, advertising "up to 30% commission" with no minimum payout on F-Secure's own affiliate page; third-party affiliate aggregators report figures up to 40% and a 60-day cookie, neither of which is confirmed on F-Secure's own site, so those numbers are not used here. Best fit: mainstream buyers who already want an antivirus/identity-protection bundle from a recognisable, publicly listed Nordic vendor and are not specifically shopping for an independently audited no-logs guarantee. EU/EEA buyers whose priority is a proven, audited no-logs architecture should prefer Mullvad, OVPN, ProtonVPN or IVPN, all elsewhere in this directory. **Compliance rationale:** F-Secure VPN (formerly branded FREEDOME VPN) is operated by **F-Secure Corporation** (Business ID 3269349-7), a Finnish publicly listed company headquartered in Helsinki and traded on **Nasdaq Helsinki (FSECURE)** since the 1 July 2022 partial demerger that split F-Secure's consumer-security business from the corporate-security business now called WithSecure; co-founder Risto Siilasmaa remains the largest shareholder at roughly 40%, with no foreign or US parent identified, and the company holds a company-wide **ISO/IEC 27001:2022 certification** (KPMG IT Certification, certificate FI241106-169). On the axis that matters most for a VPN listing, independently audited no-logs evidence, F-Secure has none: its own VPN privacy notice discloses that it retains VPN service-provisioning logs (source IP address, random device ID, GeoIP country, access timestamp) for one year and VPN service-log events for three months, and this retained connection metadata is exactly what let Finland's National Bureau of Investigation obtain and hand over FREEDOME VPN logs to German prosecutors in a January 2019 criminal case; the seizure was later ruled unlawful by the Helsinki Court of Appeal and the data ordered destroyed, but the episode proves connection-identifying logs existed to seize in the first place. No Cure53/Deloitte/PwC-style independent no-logs audit has ever been published for F-Secure VPN. `cloud_act_exposure` is set to `minor` rather than `none` because F-Secure's own privacy notice states it engages an unnamed third-party infrastructure provider to help operate the newer WireGuard/Hydra VPN version, whose corporate jurisdiction is not disclosed; there is no evidence of a US parent or that F-Secure Corporation itself is US-incorporated, so exposure is not rated `material`. **Finland is a member of the 14 Eyes intelligence-sharing alliance**, a jurisdictional caveat that applies on top of the no-logs gap regardless of F-Secure's otherwise clean Nordic ownership. No public DPA was found. Net: solid EU/Nordic public-company ownership and a real company-wide ISO 27001 certification, offset by the weakest no-logs evidence base and the only confirmed real-world logs-were-seized precedent of any VPN in this directory. ### GetResponse: https://euvetted.com/p/getresponse - Website: https://www.getresponse.com - Category: Email marketing - Country of incorporation: Poland - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: freemium (from €16/month) - Founded: 1998 - DPA: https://www.getresponse.com/legal/data-processing-agreement - Sub-processors list: https://www.getresponse.com/legal/max-dpa-list-of-subprocessors - Last verified: 2026-05-10 Gdańsk-headquartered Polish email marketing and automation platform with webinars, landing pages, and a 350k+ customer base. GetResponse is a Polish email marketing and automation platform headquartered in Gdańsk, founded in 1998 and operating as the joint-stock company GetResponse S.A. (KRS 0000942075, ul. Grunwaldzka 413, 80-309 Gdańsk) with VAT ID 9581468984. The company converted to a joint-stock structure in 2022 and is held by founders, employees (via ESOP), and earlier investors rather than publicly traded on the Warsaw Stock Exchange. With more than 350,000 customers worldwide, GetResponse is one of the largest EU-headquartered email marketing platforms. The product spans email marketing, marketing automation, landing pages, conversion funnels, paid ads, push notifications, and webinars, making it a broader Mailchimp/ConvertKit alternative for SMB and mid-market customers who also want webinar functionality. Security disclosures on the trust page cite PCI-DSS certification, GDPR compliance, TLS 1.2+ in transit, AES-256 at rest, role-based access control, MFA enforcement, and 24/7 SOC monitoring; ISO 27001, SOC 2, EUCS, and C5 are not advertised on the public security page. The privacy policy (effective 17 Mar 2026) refers to processing "mainly in the European Economic Area" but does not name the underlying hosting provider or list individual sub-processors: only categories such as Google services for analytics/advertising (DPF-covered), webinar support, customer support, and payment processors. Pricing in EUR is straightforward: Starter at €16/month (€13.12 with annual billing), with a free tier available after a 14-day premium trial that is heavily restricted (1,000 landing-page visitors/month, 10-person webinar cap, GetResponse branding on outbound mail). The product UI supports nine languages including PL, EN, DE, FR, ES, IT, PT, plus VN and RU. Best fit: SMB and mid-market marketers in Central and Eastern Europe wanting a Polish-headquartered all-in-one platform with strong language coverage. Procurement-grade buyers should request the DPA and a named sub-processors list directly, since neither is publicly indexed at audit time; the absence of both is the main transparency gap at this assessment. **Compliance rationale:** Polish S.A. headquartered in Gdańsk with privacy policy referencing EEA-primary processing and SCC + DPF for US transfers, but no publicly accessible DPA or named sub-processors list (privacy policy describes only sub-processor categories: Google services, webinar support, payment processors). EU-owned with EEA-primary processing but no public DPA and no named sub-processors disclosure. ### GitLab by Stackhero: https://euvetted.com/p/stackhero-gitlab - Website: https://www.stackhero.io - Category: Git hosting - Country of incorporation: France - Hosting country: France - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid (from €49/month) - Certifications: ISO27001 - DPA: https://www.stackhero.io/en-US/stackhero/gdpr - Sub-processors list: https://www.stackhero.io/Stackhero-DPA.pdf - Last verified: 2026-07-21 French-operated managed GitLab CE (Stackhero) on a dedicated EU-region VM; ISO 27001:2022, public DPA; hosting region is customer-selected. GitLab by Stackhero is a managed **GitLab Community Edition** offering from **Stackhero**, a French company that provisions and maintains open-source software on dedicated cloud instances. Rather than sharing a multi-tenant platform, each customer gets a private, isolated VM running a full GitLab CE, with CI/CD pipelines, a container registry and package registry, one-click updates, and automatic daily backups retained for up to three months. Because the software is GitLab CE, teams get the complete GitLab workflow (merge requests, issues, CI/CD, registries) with Stackhero handling the infrastructure, security, and upgrades. For an EU-sovereignty audit the operator profile is strong: Stackhero is a French company holding its own **ISO 27001:2022** certification (British Assessment Bureau, certificate #254338), and it publishes a downloadable **DPA** without a login. When a European region is selected, the repository content stays in the EU, but Stackhero's DPA names two US-incorporated sub-processors, **Stripe** for payments and **Intercom** for support, that handle account and billing personal data, so the exposure is minor rather than none: [[stackhero-gitlab.cloud_act]]. Two further caveats keep this a 4/5 rather than a clean 5/5: hosting location is a customer choice made at service creation and Stackhero also offers a USA region, so European residency is opt-in rather than a contractual guarantee; and the DPA does not name the underlying cloud host, so the specific EU provider behind the European region cannot be confirmed. Buyers should select a European region explicitly and record that choice. Pricing starts at [[stackhero-gitlab.price_from]] per month with unlimited users, repositories, and CI/CD time, billed per hour on a single monthly invoice. The underlying engine is GitLab CE (US-origin open source, with no phone-home for the Community Edition), so it is the operator and infrastructure, not the software vendor, that determine the sovereignty posture. Best fit: teams that specifically want GitLab's full feature set but need it run by an EU operator on a private EU-region instance, with a certificate and a public DPA they can hand to procurement. **Compliance rationale:** GitLab by Stackhero is a **managed GitLab Community Edition instance** operated by **Stackhero**, a French company, on a dedicated, isolated VM with automatic daily backups. Signals: EU-owned French operator, its own **ISO 27001:2022 certification** (British Assessment Bureau, certificate #254338), and a **publicly downloadable DPA (PDF)**. When a European region is chosen the repository content stays in the EU, but Stackhero's DPA (section 5.2) names two US-incorporated sub-processors, **Stripe** (payments) and **Intercom** (support), that process account and billing personal data, giving minor CLOUD Act exposure: [[stackhero-gitlab.cloud_act]]. That, together with the hosting region being customer-selected at service creation (a USA region is also offered) and the DPA not naming the underlying cloud host, holds the score at 4/5. This listing reflects the EU-region deployment. **Sub-processors mapped:** 2 total, 2 US-owned - Intercom (United States): Customer support communication (first name, last name, email, company name) [US-owned] - Stripe (United States): Payment processing (credit card numbers) [US-owned] ### GoatCounter: https://euvetted.com/p/goatcounter - Website: https://www.goatcounter.com - Category: Web analytics - Country of incorporation: Ireland - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium - Founded: 2019 - Sub-processors list: https://www.goatcounter.com/help/privacy - Last verified: 2026-05-10 Solo-developer open-source web analytics on Hetzner DE/FI; no IP storage, no trackers, free for personal use, MIT-style source on GitHub. GoatCounter is a minimalist open-source web analytics tool developed and operated by solo developer Martin Tournoij (GitHub: arp242). The hosted service goatcounter.com runs on Hetzner Online GmbH servers in Finland and Germany; the operator is currently based in Ireland. The project is fully open source on GitHub and self-hostable, making it a credible "no SaaS lock-in, no CLOUD Act exposure" answer for indie publishers, NGO sites, and small EU teams. The privacy posture is exceptionally clean: GoatCounter does not store IP addresses, does not store the full User-Agent header, does not use cookies for visitor tracking, and stores only aggregate-table data per hour rather than individual pageviews (with the option to opt into pageview-level data collection if the customer enables it). Site owners are advised that a GDPR consent banner is generally not required because no personally identifiable data is collected and the service rests on legitimate interest analogous to in-store foot-traffic counting. Account login uses cookies for session persistence; no third-party sharing of account data; backups retained up to 30 days after account deletion. Pricing is freemium and pragmatic: the hosted service is free for personal and non-commercial use, with paid tiers for commercial and high-traffic use; specific tier prices were not captured at audit and are listed in /help/billing. Best fit: indie devs, bloggers, small e-commerce shops, and EU NGOs who want a no-cookie analytics stack on Hetzner with the option to self-host the open-source build. Procurement-grade enterprise buyers who require a formal DPA, named sub-processors annex, and a corporate legal entity should look at Plausible (also Hetzner DE) or Pirsch (also Hetzner DE) instead. GoatCounter is structurally a one-person shop and does not produce those artefacts today. **Compliance rationale:** Solo-developer open-source web analytics (Martin Tournoij, Ireland-based) running on Hetzner servers in Germany and Finland with no third-party sharing, no IP storage, no User-Agent storage, no trackers, and no US sub-processors anywhere on the customer-data path; EU-hosted with no CLOUD Act exposure, but no formal DPA artefact or unified named sub-processors annex, adequate for indie/SMB buyers but not for procurement-grade buyers requiring contract-level transparency. ### GoCardless: https://euvetted.com/p/gocardless - Website: https://gocardless.com - Category: Payments - Country of incorporation: United Kingdom - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2011 - Sub-processors list: https://gocardless.com/privacy/ - Last verified: 2026-05-11 London-based UK direct-debit and recurring-payments specialist (FCA-authorised); Mollie acquisition announced Dec 2025. GoCardless is a London-headquartered UK payments platform specialising in **direct debit** and **recurring** payments, operated by GoCardless Ltd (Sutton Yard, 65 Goswell Road, London EC1V 7EN; Companies House 07495895). Founded in 2011 by Hiroki Takeuchi, Tom Blomfield, and Matt Robinson, the company is authorised by the UK's Financial Conduct Authority under the Payment Services Regulations 2017 (registration 597190) and supports a uniquely broad set of bank-to-bank schemes: **Bacs** (UK), **SEPA Direct Debit** (Eurozone), **ACH** (US), **BECS** (Australia and New Zealand), **PAD** (Canada), **Autogiro** (Sweden), and **Betalingsservice** (Denmark). The product is positioned as the direct-debit-and-recurring-payments alternative to Stripe/PayPal, particularly strong for subscription SaaS, B2B invoicing, charities, and any business with predictable recurring billing. Two ownership signals matter for an EU-sovereignty audit at this time. First, the historical cap table includes Permira (UK), BlackRock (US), Accel (US), and Balderton (UK) alongside other backers: mixed-jurisdiction with material US-VC exposure that, on its own, would place GoCardless in the `eu_hq_us_funded`-equivalent UK band. Second, and more importantly, in **December 2025 Dutch Mollie announced an agreement to acquire GoCardless** for approximately **US$1.1B**, with regulatory approvals expected to complete the deal by mid-2026. If the acquisition closes as announced, GoCardless will become a subsidiary of Mollie B.V. (Amsterdam, DNB-licensed EMI), shifting the primary regulatory anchor from FCA to a Dutch parent, though Mollie itself carries a US-funded cap table (TCV, General Atlantic, Blackstone, Alkeon; see Mollie's listing). Ownership signals remain in transition pending acquisition close: `cloud_act_exposure: material`, no public DPA, and no public sub-processors list until the Mollie-owned entity publishes updated disclosures. Pricing in GBP is volume-tiered: Standard 1% + £0.20 (capped at £4 domestic UK), Advanced 1.25% + £0.20 (capped £5, with auto failed-payment recovery), Pro 1.4% + £0.20 (capped £5.60, with fraud protection), and Custom for >£1M annual volume. International payments via the Wise mid-market FX engine cost ~1% more. Branding add-ons: £50/month for bank-statement branding, £150/month for fully customised checkout. Best fit: UK and EU subscription SaaS, mid-market B2B invoicing, NGOs and membership organisations collecting recurring direct debits across multiple jurisdictions. EU procurement-grade buyers needing strict EU-controlled ownership should re-evaluate after the Mollie acquisition closes or use Mollie directly for cards/iDEAL/SEPA workflows. **Compliance rationale:** GoCardless Ltd (Sutton Yard, 65 Goswell Road, London EC1V 7EN; Companies House 07495895) is the UK direct-debit-and-recurring-payments specialist, FCA-authorised under the Payment Services Regulations 2017 (597190), but in December 2025 Dutch Mollie announced an acquisition agreement valuing the company at ~US$1.1B, the deal subject to regulatory approval and expected to close by mid-2026, so the immediate ownership state is in transition; UK post-Brexit jurisdiction plus a historical cap-table mix (Permira UK + BlackRock US + Accel US + Balderton UK) results in `cloud_act_exposure: material` and `ownership_signal: other` (transition pending Mollie acquisition close); no public DPA or sub-processors list accessible at audit. **Sub-processors mapped:** 25 total, 18 US-owned - Amazon Web Services (United States): File storage and scale computing [US-owned] - Celigo (United States): Partner integration platform [US-owned] - Cloudflare (United States): Website and API optimisation and protection [US-owned] - DataVisor (United States): AML and fraud checks [US-owned] - Dun & Bradstreet (United States): Company credit scoring and identity verification [US-owned] - Finastra Limited (United Kingdom): Direct debit scheme provider software (BACS) [US-owned] - GitHub (United States): Software development [US-owned] - Google (United States): Hosting on Google Cloud Platform and other cloud services [US-owned] - LexisNexis Risk Solutions (United States): Background and AML checks, fraud prevention [US-owned] - Looker (United States): Data platform and analytics [US-owned] - Mastercard Payment Services (Denmark): Payment scheme operator, chargeback processing (Betalingsservice) [US-owned] - Okta (United States): Employee access management [US-owned] - Pardot (United States): Sending transactional emails [US-owned] - Provenir (United States): Credit decisioning [US-owned] - Segment (United States): Anonymous online event tracking and analytics [US-owned] - SendGrid (United States): Sending transactional emails [US-owned] - ThreatMetrix (United States): Fraud identification [US-owned] - Zendesk (United States): Support ticketing software [US-owned] - Creditsafe (United Kingdom): Background and AML checks - Onfido (United Kingdom): Identity verification - PayGate (United Kingdom): Direct debit scheme provider software (BACS) - Pure JAM (United Kingdom): Support telephony service - Trulioo (Canada): Identity verification - Vonage (United States): Support telephony service - Wise (United Kingdom): FX services ### HansaChat: https://euvetted.com/p/hansachat - Website: https://hansa.chat - Category: Project management - Country of incorporation: Germany - Hosting country: Germany (Falkenstein/Nuremberg) - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid (from €99/month) - Sub-processors list: https://hansa.chat/privacy - Last verified: 2026-06-16 Lübeck-based company chat with flat per-workspace pricing (not per-seat); Hetzner DE hosting only, all-EU sub-processors, SSO on all plans, a Slack alternative. HansaChat is a German internal-communication platform, a company chat positioned as a fixed-price alternative to Slack and Microsoft Teams. It is operated as a sole proprietorship by Igor Tverdokhleb from Lübeck (Barkentinenstr. 20, 23558 Lübeck); the imprint lists no GmbH/UG legal form, Handelsregister (HRB) number, or VAT ID, so it is an early-stage, founder-run product rather than an incorporated company. Its core differentiator is pricing: HansaChat charges per workspace, not per user. Paid plans run €99/month (Starter: unlimited users and messages, 25 GB), €199/month (Company: 100 GB, webhooks/integrations, audio-video calls) and €299/month (Business: admin controls, advanced search), plus storage add-ons and a limited free Demo (2,000 messages, 1 GB, deleted after 30 days of inactivity). For teams that have outgrown Slack's per-seat math the flat model can be dramatically cheaper at scale; the founder's own framing, which readers can keep in mind, is "a company chat without per-user pricing plans." SSO is included on every plan. On sovereignty the stack is deliberately tight and all-European. Core application data, databases and file storage run exclusively on Hetzner Cloud in Germany (Falkenstein and Nuremberg) on a private Kubernetes cluster, with TLS in transit and encryption at rest (encrypted Longhorn volumes for MySQL, encrypted MinIO for files). Sub-processors are publicly enumerated in the privacy policy and are all EU: Hetzner (DE, hosting), EmailLabs / Vercom S.A. (PL, transactional email) and Creem / Armitage Labs OÜ (EE, merchant-of-record billing). The only US touch-point is Sentry for error monitoring (stated to carry no PII and being migrated to self-hosted Loki/Grafana), giving minor CLOUD Act exposure. There is no end-to-end encryption (operators retain technical access to workspace content) and as of February 2026 the vendor's security page states backups and disaster recovery are not yet in place, a real maturity caveat for procurement. Best fit: small DACH teams that want a transparent, EU-hosted Slack replacement at a predictable flat price and don't need certifications or a signable DPA today. No public ISO 27001 / BSI C5 certification and no separate customer-signable DPA exist yet, which caps the compliance score; both would be the obvious additions as the product matures. **Compliance rationale:** **HansaChat** (sole proprietorship of Igor Tverdokhleb, Lübeck, Germany, no GmbH/HRB/VAT in the imprint) is a flat-priced company chat hosted **exclusively on Hetzner in Germany (Falkenstein/Nuremberg)** with a fully EU sub-processor set **publicly listed in its privacy policy** (Hetzner DE hosting, EmailLabs/Vercom S.A. PL email, Creem/Armitage Labs OÜ EE merchant-of-record billing); the score is capped at **3/5** because there is **no separate customer-signable DPA/AVV** and **no third-party certification (ISO 27001 / BSI C5)**, with **minor CLOUD Act exposure** via Sentry (US) error monitoring (stated no PII, migration to self-hosted planned) and an early-stage maturity caveat. The vendor's own security page states there are **no backups or disaster recovery as of Feb 2026**; not end-to-end encrypted. **Sub-processors mapped:** 4 total, 1 US-owned - Sentry (Functional Software, Inc.) (United States): Error monitoring; per security page, stated no PII; migration to self-hosted Loki/Grafana planned. Not in the privacy-policy §6 register. [US-owned] - Creem (Armitage Labs OÜ) (Estonia): Payment processing / merchant-of-record billing, invoices, subscriptions - EmailLabs (Vercom S.A.) (Poland): Transactional & service email delivery - Hetzner Online GmbH (Germany): Hosting; core application data, databases, file storage (Falkenstein + Nuremberg) ### Hetzner: https://euvetted.com/p/hetzner - Website: https://www.hetzner.com - Category: Cloud & hosting - Country of incorporation: Germany - Hosting country: Germany (Gunzenhausen) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €4/month) - Founded: 1997 - Certifications: ISO27001, C5 - DPA: https://www.hetzner.com/legal/data-processing/ - Sub-processors list: https://www.hetzner.com/legal/privacy-policy/ - Last verified: 2026-05-11 Family-founded German hyperscaler alternative (1997), EU DCs in Falkenstein, Nuremberg, Helsinki; ISO 27001 + BSI C5 Type 2; from €4/month. Hetzner Online GmbH is the reference EU hyperscaler alternative on this directory and the most-cited "EU-incorporated EU-controlled" hosting provider in the broader sovereignty conversation. Founded in 1997 by Martin Hetzner and still family-controlled, the company operates from Industriestr. 25, 91710 Gunzenhausen, Germany, with a Data Protection Officer reachable at data-protection@hetzner.com. The product surface covers dedicated servers (EX/AX/RX/SX/GPU lines), cloud servers, web hosting, managed servers, object storage, storage boxes, Storage Share (Nextcloud), DNS, SSL, load balancers, and domain registration. Pricing from approximately €4/month for small cloud VMs, with cloud-cost benchmarks claimed at 10–12× cheaper than AWS / Azure / GCP for comparable configurations. For procurement-grade EU buyers the compliance posture is the strongest in this directory. Hetzner is ISO 27001 certified (annual TÜV Rheinland audits) and holds BSI C5 Type 2 (the German government's cloud-security catalogue) alongside the "Bayerns Best 50" and ECO Awards. The privacy policy (last updated 16 Apr 2025) commits that customer data for non-cloud products is processed and stored "exclusively within the EU," that EU-region cloud customers' data stays in Europe, and (most importantly for CLOUD Act analysis) that Hetzner only accepts authority requests for the Falkenstein and Nuremberg facilities from German authorities and courts, and for the Helsinki facility from Finnish authorities and courts. US and Singapore data centres exist (Oregon, Virginia, Singapore) and require international legal cooperation before EU-stored customer data can be accessed; customers fully control which region their workload runs in. The only US-resident sub-processors that appear on Hetzner's privacy policy, Kapa.ai (US, AI chatbot on the corporate website) and Google Analytics (US, marketing-site analytics), touch the hetzner.com marketing surface, not customer workloads. Other named sub-processors are EU (Brevo DE, Computop Paygate DE, Rexx Systems DE, iDenfy LT, Intrum DE). The DPA / AVV can be concluded directly inside the customer account with a checkbox, no handwritten signature required, and Hetzner explicitly states that customer master data (payment details, etc.) is not shared with overseas subsidiaries. Best fit: every EU procurement-grade buyer in this directory who controls their own hosting choice; Hetzner is also the named hosting provider for Plausible, Pirsch, GoatCounter, and the recommended self-host target for Matomo, Plausible, Tripetto SDK, and others. **Compliance rationale:** Hetzner Online GmbH (Gunzenhausen, family-founded by Martin Hetzner in 1997, fully private and German-controlled) is the directory's reference EU hyperscaler alternative: ISO 27001 + BSI C5 Type 2 certified, customer infrastructure can be pinned to EU-only data centres in Falkenstein, Nuremberg, or Helsinki, the company explicitly accepts authority access only from German or Finnish courts for those facilities, and the on-account DPA is freely available with sub-processors named publicly: EU-owned, EU-hosted, with no CLOUD Act exposure for EU-region customers. **Sub-processors mapped:** 1 total, 0 US-owned - Hetzner Finland Oy (Finland): Building rental and technical support for the Finland (Helsinki) region (Hetzner group entity) ### Hetzner Storage Share: https://euvetted.com/p/hetzner-storage-share - Website: https://www.hetzner.com/storage/storage-share/ - Category: File sharing - Country of incorporation: Germany - Hosting country: Germany (Falkenstein) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €4.29/month) - Founded: 1997 - Certifications: ISO27001, C5 - DPA: https://www.hetzner.com/AV/DPA_en.pdf - Sub-processors list: https://www.hetzner.com/legal/privacy-policy/ - Last verified: 2026-07-10 Hetzner Online GmbH's managed Nextcloud, single data centre in Falkenstein, Germany; ISO 27001 + BSI C5 Type 2 certified, from €4.29/month for 1 TB, no annual contract. Storage Share is Hetzner Online GmbH's managed Nextcloud offering, sold alongside the company's dedicated servers, cloud VMs, Storage Boxes, and web hosting from the same Gunzenhausen-headquartered, family-controlled entity that operates the rest of the directory's reference EU hyperscaler listing. The product is, in Hetzner's own words, "a standard community version of the third-party software application Nextcloud" with only minor Hetzner-side compatibility and security patches (documented publicly: a patch to the bundled Monitoring app, and blocking the public user-profile URL route by default). Three fixed plans are sold: NX11 (1 TB, 3 subdomains, 50 simultaneous connections), NX21 (5 TB, 7 subdomains, 100 connections), and NX31 (10 TB, 10 subdomains, 200 connections), each with unlimited user accounts and unlimited traffic, billed strictly monthly with no minimum contract period and no cancellation period (no free tier). As a full Nextcloud Community instance, it ships with Contacts, Calendar, and Tasks pre-installed, is extensible via the Nextcloud Appstore (an admin can add Talk, Mail, Collabora/OnlyOffice integration, and more), supports WebDAV, and syncs through the official Nextcloud desktop clients (Windows, macOS, Linux) and mobile apps (iOS, Android). For an EU-sovereignty audit, Storage Share inherits Hetzner's strongest-in-directory compliance posture but with one product-specific difference worth flagging. It runs in a single data centre, Falkenstein, Germany, with Hetzner stating no other Storage Share location is currently offered (an internal FAQ update on additional locations is pending). The your-storageshare.de product domain resolves directly to Hetzner's own IP space with no Cloudflare or other third-party CDN in front of it, so there is no plain-HTTP US exposure the way there is for SaaS fronted by Cloudflare US. Hetzner's ISO/IEC 27001:2022 certificate (SOCOTEC-audited, valid 27.09.2025-26.09.2028) states its scope covers "all hosting services and the data centers" at Nuremberg, Falkenstein, and Helsinki; separately, Hetzner's BSI C5:2020 Type 2 attestation (WP Koehler GmbH, audit report dated 17 Nov 2025) explicitly lists "Storage (Share, Box, Object Storage)" among the certified product lines, alongside dedicated server, managed server, web hosting, and cloud server. The generic Art. 28 GDPR Data Processing Agreement is a publicly downloadable PDF (no account or login required), and Hetzner's privacy policy names its sub-processors; the only US-touching entries on that list (Kapa.ai and Google Analytics) sit on the hetzner.com marketing site, not on the storageshare.de product domain, and Storage Share itself introduces no additional sub-processor beyond Hetzner (Nextcloud GmbH is not involved; Hetzner runs the open-source Community Edition itself). The one caveat that differentiates Storage Share from the directory's zero-knowledge-by-default storage picks: data is not encrypted at rest by default. Hetzner's own documentation offers an optional server-side encryption module but actively recommends against enabling it, since the encryption keys and the encrypted files sit on the same device, and states that this mode cannot run in parallel with Nextcloud's separate end-to-end encryption option. Buyers who need default-on client-side encryption should look at Proton Drive, Tresorit, or Internxt instead; buyers who mainly want a cheap, certified, single-country-hosted Nextcloud instance with no vendor lock-in beyond the standard Nextcloud export path get Hetzner's compliance profile at €4.29-27.39/month. Best fit: EU teams and privacy-conscious individuals who already trust Hetzner for hosting and want the identical legal entity, data centre, and certification scope for file sync and sharing, and who are comfortable that encryption is opt-in rather than default. **Compliance rationale:** Storage Share is Hetzner Online GmbH's own managed Nextcloud (Gunzenhausen HQ, family-controlled, no PE/VC), run exclusively in Hetzner's own Falkenstein, Germany data centre (no other location currently offered) with no Cloudflare or other US intermediary in front of the product domain (your-storageshare.de resolves directly to Hetzner IP space), and the same ISO/IEC 27001:2022 and BSI C5:2020 Type 2 attestations that cover Hetzner's cloud and dedicated servers explicitly name "Storage (Share, Box, Object Storage)" in their certified scope; the generic Art. 28 DPA is publicly downloadable without login or account signup at hetzner.com/AV/DPA_en.pdf; the one caveat this directory records is that Storage Share data is not encrypted at rest by default (Hetzner's own docs recommend against enabling the optional server-side encryption, since the keys sit next to the encrypted files on the same device, and true end-to-end/zero-knowledge encryption is not the default the way it is for Proton Drive, Tresorit, or Internxt), so buyers who need default-on zero-knowledge encryption should pick one of those instead; on jurisdiction and hosting the posture is EU-owned, single-region EU-hosted, with no CLOUD Act exposure for this product. ### heylogin: https://euvetted.com/p/heylogin - Website: https://www.heylogin.com - Category: Password managers - Country of incorporation: Germany - Hosting country: Germany (Nuremberg) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €4/month) - Founded: 2021 - Certifications: ISO27001 - DPA: https://www.heylogin.com/en/dpa - Sub-processors list: https://www.heylogin.com/en/subprocessors - Last verified: 2026-06-29 German passwordless zero-knowledge password manager (heylogin GmbH, Braunschweig), all-German sub-processor stack, ISO 27001:2022, no CLOUD Act exposure. heylogin is a passwordless, zero-knowledge password manager built by heylogin GmbH in Braunschweig, Germany, a company spun out of IT-security research at TU Braunschweig by Dr. Dominik Schürmann (CEO) and Vincent Breitmoser (CTO), and originally incorporated as Confidential Technologies GmbH in 2018 before relaunching under the heylogin brand with the product's 2021 release. Its distinguishing idea is that there is no master password: the vault is unlocked and synced using the security chip in the user's smartphone (and FIDO2 keys, Touch ID, Windows Hello), with a "swipe to login" confirmation and a 1-click browser overlay that automates the actual website sign-in. The second factor is built into the vault encryption itself rather than bolted on as a separate login step. For an EU-sovereignty audit heylogin is best-in-class. The vault is end-to-end encrypted on the device before it ever reaches the cloud (Curve25519, XSalsa20-Poly1305, Argon2 key-stretching, age for at-rest backups, aligned to BSI TR-02102-1), so the heylogin cloud is a pure transport-and-storage layer with no ability to decrypt customer data. Every sub-processor is German with no third-country transfer: Hetzner Online (production in Nuremberg, standby in Falkenstein), IONOS (S3 backups in Frankfurt), Myra Security (Munich) for DDoS protection and CDN (a German CDN rather than Cloudflare US), and Heinlein Hosting / mailbox.org (Berlin) for transactional email. The ISMS is ISO 27001:2022 certified, the DPA and a detailed sub-processor annex are publicly downloadable without a login, and all data centres are ISO 27001-certified Hetzner facilities running on renewable electricity. The only US touchpoints are non-data: a minority Mozilla Ventures pre-seed stake (2022), the Webflow-hosted marketing site that is explicitly separated from the product on heylogin.app, and user-side recovery-seed backups to the user's own Google/Apple account. Pricing is freemium: a free Private tier for individuals; Business at €3.99/user/month billed yearly (€4.99 monthly) adding user/team management plus Entra ID, Google Workspace and CSV provisioning; and a yearly Enterprise tier (50+ seats) adding audit logs, Pwnitoring breach monitoring, optional on-premises backup and phone support. A separate Enterprise-for-MSPs tier and an EVB-IT cloud contract for European public-sector buyers are available. Best fit: German and EU SMBs, MSPs and public-sector buyers that want a passwordless, ISO 27001-certified vault with a genuinely all-German processing stack and zero CLOUD Act exposure. Buyers wanting open-source instead should compare Passbolt or Psono. **Compliance rationale:** heylogin GmbH (Sophienstr. 40, 38118 Braunschweig; HRB 207299 Amtsgericht Braunschweig; founders Dr. Dominik Schürmann & Vincent Breitmoser, ex-TU Braunschweig) is a passwordless, zero-knowledge password manager whose vault is end-to-end encrypted (Curve25519 / XSalsa20-Poly1305 / Argon2 / age, BSI TR-02102-1 aligned) so the cloud is a pure transport/storage layer that cannot decrypt customer data. Every sub-processor is German with no third-country transfer: Hetzner (Nuremberg production + Falkenstein standby), IONOS (Frankfurt S3 backups), Myra Security (Munich, DDoS + CDN, a German CDN, not Cloudflare US), and Heinlein/mailbox.org (Berlin, transactional email); and the ISMS is ISO 27001:2022 certified with a publicly downloadable DPA and detailed sub-processor annex. The only US touchpoints are non-data: Mozilla Ventures' minority 2022 pre-seed stake, the Webflow-hosted marketing site (explicitly separated from the product on heylogin.app, holds no customer data), and user-side phone backups of the recovery seed to the user's own Google/Apple platform account. EU-owned, EU-hosted (Germany only), DPA + sub-processors public, no Cloudflare US, no CLOUD Act exposure → 5/5. ### HiBob: https://euvetted.com/p/hibob - Website: https://www.hibob.com - Category: HR & people - Country of incorporation: United Kingdom - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2015 - Certifications: ISO27001, SOC2 - Sub-processors list: https://www.hibob.com/privacy/hibob-subsidiaries-and-sub-processors/ - Last verified: 2026-05-12 Israeli-founded modern HRIS for mid-market (Tel Aviv + London); 5,000+ customers, heavy US VC, mostly listed for completeness. **HiBob** (the "bob" platform) was founded in **Tel Aviv** in 2015 and operates a significant London office, with additional presence in New York, Amsterdam, Berlin, Lisbon, Sydney, and Zagreb. Targets mid-market (50-2,000 employees) with a modern HRIS UX. Compliance: **ISO 27001 + SOC 2** certified. But the sovereignty / procurement story is weak: **Israeli HQ + heavy US VC funding** (General Atlantic, Bain Capital Ventures, Insight Partners, Battery Ventures) means HiBob is the least "European" entry in this HR set. Listed for completeness and to flag the misperception that "London office" implies "European company". For compliance-driven EU procurement HiBob fits the alternative-to-BambooHR slot but with material caveats. **Compliance rationale:** **HiBob** is **Israeli-headquartered** (Tel Aviv) with London as a major secondary office and offices in NYC, Amsterdam, Berlin, Lisbon, Sydney, Zagreb. `country_iso` set to GB reflects EU-buyer-facing brand but `ownership_signal` is `eu_hq_us_funded` due to Israeli HQ + heavy US VC funding (General Atlantic, Bain Capital Ventures, Insight Partners, Battery Ventures); CLOUD Act exposure material; non-EU HQ, US-VC-controlled, and no public DPA or sub-processor disclosure identified, the weakest sovereignty profile in the HR set. ### HumHub: https://euvetted.com/p/humhub - Website: https://www.humhub.com - Category: Docs & wikis - Country of incorporation: Germany - Hosting country: Germany (Munich) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium - Founded: 2015 - Sub-processors list: https://www.humhub.com/en/privacy/ - Last verified: 2026-05-18 Munich-based AGPLv3 open-source enterprise social network + intranet (HumHub GmbH & Co. KG, 2015), 4,500+ organisations, self-hostable on EU infra. HumHub is a Munich-headquartered German open-source enterprise social-network and intranet platform operated by **HumHub GmbH & Co. KG** and originally spun off from the Munich web agency **zeros+ones** in early 2015 as an independent company. The codebase is built on the Yii PHP framework and licensed under **GNU Affero General Public License v3** with an optional commercial licence for buyers who need exemption from the AGPL copyleft. The product reports **4,500+ organisations** on the platform across 30+ UI languages: a customer base that spans corporations and SMEs, cities and municipalities, social and charitable institutions, foundations and clubs, political parties, and educational institutions (schools, universities). Two product editions ship: **Community Edition** is fully open-source, free to self-host on any infrastructure (Hetzner, OVHcloud, Scaleway, IONOS, STACKIT, on-bare-metal); **Professional Edition** is commercially licensed with enterprise features, formal support, and managed SaaS hosting. The **80+ optional modules** are distributed via the HumHub marketplace and cover use-cases like LDAP / SAML SSO, calendar, tasks, polls, custom pages, Mattermost-style chat, file storage, and dozens of integrations. The combination of a permissive baseline + paid-tier monetisation gives HumHub structural sustainability without requiring VC dilution: the company is HumHub GmbH & Co. KG with no PE / VC / parent on record. For procurement-grade EU buyers HumHub sits at the top of the docs / wikis / knowledge category by ownership architecture: German GmbH & Co. KG legal structure, AGPLv3 source-availability, self-host as the recommended default for sovereignty, "Open Source Software made in Germany" branded positioning, and a cross-sector public-sector + non-profit customer base that signals procurement-friendliness. Pricing for the Professional Edition is enterprise / sales-engaged; specific EUR tier figures were not captured at audit. Best fit: German and EU corporates building internal intranets and social networks, EU public-sector and educational buyers needing AGPLv3 source-availability for forking flexibility, non-profits and clubs that benefit from the free Community Edition, and any procurement-grade buyer who wants a structurally clean German open-source vendor. **Compliance rationale:** HumHub GmbH & Co. KG (Munich, Germany; spun off as an independent company in early 2015 from the Munich-based web agency zeros+ones) is an **AGPLv3 open-source enterprise social network and intranet platform** with optional commercial licence, 4,500+ organisations on the platform across 30+ languages, both Community (free open source) and Professional (commercial) editions, and an 80+ module marketplace. Used by corporations, municipalities, charities, foundations, clubs, political parties, schools, and universities: strong cross-sector EU adoption pattern. Signals: EU-owned (German GmbH & Co. KG), EU-hosted, AGPLv3 open source, no PE / VC / parent on record, no CLOUD Act exposure on self-hosted deployments. Gap: no publicly accessible DPA download link and no formal sub-processors list for the hosted Professional Edition. ### Hygraph: https://euvetted.com/p/hygraph - Website: https://hygraph.com - Category: Headless CMS - Country of incorporation: Germany - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium (from €39/month) - Founded: 2017 - Certifications: ISO27001, SOC2 - Last verified: 2026-05-12 Berlin GraphQL-native headless CMS (formerly GraphCMS, founded 2017); enterprise clients incl. Samsung, LEGO; mostly EU-funded. **Hygraph** (Berlin, Germany, founded 2017; previously **GraphCMS** until 2021 rebrand) is a GraphQL-native, API-first headless CMS positioned for enterprise teams managing complex multi-brand, multi-region, multi-platform content. Enterprise customers include **Samsung, Dr. Oetker, LEGO, Paramount, TED**. Compliance: **ISO + SOC** referenced in marketing (no explicit certificate URL on public homepage at time of research). $30M Series B 2023 led by **One Peak** (UK private equity) with participation from **OpenOcean** (Finland) and **SquareOne** (Germany). Its mostly-European cap table makes Hygraph one of the cleanest non-US-funded headless CMS picks in the catalogue. From €39/mo for paid tier; free tier available. **Compliance rationale:** **Hygraph** (formerly **GraphCMS**, Berlin DE, founded 2017) is **ISO 27001 + SOC 2 referenced**, GraphQL-native federated content platform, enterprise customer base (Samsung, Dr. Oetker, LEGO, Paramount, TED); $30M Series B 2023 led by **One Peak** (UK PE) with OpenOcean (FI) and SquareOne (DE); mostly European cap table, no US-PE majority, so `ownership_signal: eu_owned`. Gap: Hygraph does not publish a publicly accessible DPA; data-processing terms and sub-processors are not surfaced in public documentation and access appears to require enterprise contact; verification of DPA and sub-processor disclosure is pending despite the largely EU-aligned ownership and certification posture. ### Icedrive: https://euvetted.com/p/icedrive - Website: https://icedrive.net - Category: File sharing - Country of incorporation: United Kingdom - Hosting country: United Kingdom - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: freemium (from €6/month) - Founded: 2019 - Last verified: 2026-05-18 UK/Gibraltar cloud storage (ID Cloud Services Ltd), opt-in Twofish client-side encryption, lifetime plans; UK/DE/US data centres, no region pinning. Icedrive is a consumer-and-prosumer cloud storage service operated by ID Cloud Services Ltd, a UK micro-company based in Swansea, Wales (one secondary source additionally cites a Gibraltar company registration; the discrepancy is unresolved and flagged below). Founded in 2019, it is effectively a one-person operation led by CEO James Bressington, which is unusual for a directory of procurement-grade vendors and is itself a risk signal: there is no team depth, no funding disclosed, and no public corporate filings surfaced at audit. The product's headline differentiator is encryption. Icedrive is the only mainstream cloud storage service to use the Twofish algorithm, and it offers true zero-knowledge client-side encryption: files and even file/folder names are encrypted on the device with a 256-bit key that never reaches Icedrive's servers. The important caveat for buyers: this applies **only to files placed in a dedicated encrypted folder**, not to the whole account. Anything stored outside that folder is not zero-knowledge. For an EU-sovereignty audit Icedrive is weak. Storage is distributed across data centres in the UK, Germany and the United States with N+2 redundancy, and **customers cannot choose their storage region**, so EU data can and does land on US infrastructure, which is material CLOUD Act exposure regardless of the client-side encryption available on the opt-in folder. There is no public DPA, no sub-processors list, and no certifications. The vendor's own site (icedrive.net) returned HTTP 403 to automated fetching at audit, so several fields rely on secondary sources. Pricing is competitive and lifetime-friendly: a 10 GB free tier, Pro plans from ~$5.99/month for 2 TB, and one-time lifetime plans starting around $389 for 2 TB with $199/1 TB and $449/5 TB add-on "stacks"; the lifetime model is the main reason Icedrive appears on best-of lists. Best fit: privacy-curious individuals who will discipline themselves to use the encrypted folder and who value lifetime pricing over EU data residency. Procurement-grade EU buyers should prefer Koofr (SI/DE), Internxt (ES), Tresorit (CH/HU) or Proton Drive (CH), all covered elsewhere on this directory. **Compliance rationale:** Icedrive is operated by **ID Cloud Services Ltd**, a UK micro-company (HQ Unit 12 J-Shed, Kings Road, Swansea, Wales; one source also cites a Gibraltar registration) founded in 2019 and effectively a one-person operation led by James Bressington; the product offers genuine client-side Twofish encryption but **only on an opt-in dedicated encrypted folder**, not the whole account, and runs a distributed storage architecture across data centres in the **UK, Germany AND the USA with no customer region selection**, meaning EU buyers cannot keep data out of US infrastructure; combined with UK-post-Brexit ownership, material CLOUD Act exposure, no public DPA or sub-processors list, and no certifications, the signal mix is the weakest in this category. ### Infomaniak AI Tools: https://euvetted.com/p/infomaniak-ai-tools - Website: https://www.infomaniak.com/en/hosting/ai-services - Category: Sovereign AI - Country of incorporation: Switzerland - Hosting country: Switzerland (Geneva) - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: freemium - Founded: 1994 - Certifications: ISO27001, ISO9001, ISO14001, ISO50001 - DPA: https://www.infomaniak.com/documents/privacy/DPA/Data_Processing_Agreement_(DPA).pdf - Sub-processors list: https://www.infomaniak.com/en/legal/confidentiality-policy - Last verified: 2026-06-18 Swiss sovereign-AI API + Euria assistant (Infomaniak, Geneva, since 1994); open-source LLMs served on own Swiss DCs, no training on user data, no CLOUD Act. Infomaniak AI Tools is the artificial-intelligence offering of **Infomaniak Group SA**, the independent Swiss technology company founded in Geneva in 1994 by **Boris Siegenthaler** and **Fabian Lucchi**, privately held, founder-led, with no venture-capital or private-equity investors on the cap table (the kdrive listing documents the same vendor in full). The product is a **developer API that serves open-source large language models, image-generation models, and speech-to-text transcription**, exposed through an OpenAI-compatible interface so existing tooling and SDKs can be re-pointed with minimal changes. Alongside the API, Infomaniak ships **Euria**, a free, sovereign ChatGPT-style assistant for end users, and integrates the same AI across kSuite (kChat, Mail, kDrive). What makes this on-thesis for an EU-sovereignty directory is where the inference actually runs. Unlike the European frontier labs in this category (Mistral, Aleph Alpha, LightOn) whose managed APIs frequently sit on US-cloud partnership infrastructure (Azure, AWS, GCP), Infomaniak runs its AI workloads **on its own Swiss data centres** in Geneva, on hardware it owns and operates. The vendor states explicitly that **customer prompts and data are not used to train models** and are processed under Swiss law. The compliance footprint mirrors the rest of the Infomaniak estate: **ISO/IEC 27001** (since June 2018), **ISO 9001**, **ISO 14001**, **ISO 50001**, and **B Corp (2025)**; Switzerland's Art. 45 GDPR adequacy decision keeps EU↔CH transfers SCC-free. Pricing is consumption-based and positioned to undercut the US incumbents: new users get a large block of free credits to evaluate the API (roughly a million tokens' worth), after which usage is billed pay-per-use with no subscription commitment; Euria is free. The trade-off versus the frontier labs is model frontier capability: Infomaniak serves strong open-source models (Mistral, Llama, DeepSeek and Granite for text, plus Whisper for transcription) rather than proprietary frontier models, so buyers needing absolute top-end reasoning may still prefer a frontier provider. Best fit: Swiss and EU developers and organisations that want GDPR-clean, Swiss-hosted inference for chat, RAG back-ends, transcription, and image generation without sending prompts to a US-owned cloud; public-sector and regulated buyers; and privacy-conscious teams wanting a drop-in OpenAI-compatible endpoint on sovereign infrastructure. **Compliance rationale:** Infomaniak AI Tools is the sovereign-AI offering of **Infomaniak Group SA** (Geneva, Switzerland; founded 1994 by Boris Siegenthaler and Fabian Lucchi; independent, privately held, founder-led; full ownership cross-reference in the kdrive listing). It is an **OpenAI-compatible API serving open-source LLMs plus image generation and speech-to-text**, and **Euria**, a free sovereign ChatGPT-style assistant, with inference running **entirely on Infomaniak's own Swiss data centres**, customer data explicitly **not used for model training**, ISO 27001 + ISO 9001 + ISO 14001 + ISO 50001 + B Corp 2025, and Switzerland's EU adequacy decision keeping EU↔CH transfers SCC-free; Swiss-owned, Swiss-hosted inference with no US cloud dependency and no CLOUD Act exposure, a managed-API peer to Mistral / Aleph Alpha / LightOn that, unlike them, runs on first-party Swiss infrastructure rather than US-cloud partnerships. **Sub-processors mapped:** 1 total, 1 US-owned - PayPal (United States): Payment processing; ancillary, off the inference/data path [US-owned] ### Infomaniak Mail (kSuite): https://euvetted.com/p/infomaniak-mail - Website: https://www.infomaniak.com/en/ksuite - Category: Private email - Country of incorporation: Switzerland - Hosting country: Switzerland (Geneva) - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: freemium (from €6/month) - Founded: 1994 - Certifications: ISO27001, ISO9001, ISO14001, ISO50001 - DPA: https://www.infomaniak.com/documents/privacy/DPA/Data_Processing_Agreement_(DPA).pdf - Last verified: 2026-05-15 Swiss email + groupware (Infomaniak Group SA, Geneva, since 1994), own Swiss DCs, ISO 27001 + B Corp 2025, free tier with @ik.me address. Infomaniak Mail is the email and groupware product within **kSuite**: Infomaniak Group SA's integrated Workspace-style bundle that pairs email with Drive, Calendar, Contacts, kMeet (video conferencing), kPaste (encrypted notes/snippets), kChat (team messaging) and an Office Suite. The vendor is **Infomaniak Group SA** in Geneva, founded in 1994 by Boris Siegenthaler and Fabian Lucchi (growing out of a 1990 user group), one of the longest-running independent European hosting companies, privately held, founder-led, with no venture-capital or private-equity investors anywhere on the cap table. The kDrive listing in this directory documents the same vendor in full; this entry mirrors that ownership and infrastructure context. For an EU-sovereignty audit Infomaniak is among the strongest Swiss listings in this directory. The compliance footprint is unusually broad: **ISO/IEC 27001** since June 2018, plus **ISO 9001** (quality), **ISO 14001** (environmental), **ISO 50001** (energy), and **B Corp certification in 2025**. Switzerland holds an EU adequacy decision under Art. 45 GDPR, so transfers EU↔CH are SCC-free. All customer data is stored exclusively on Swiss-located infrastructure operated by Infomaniak itself; the latest data centre is built into the basement of a participatory housing cooperative and recycles 100% of consumed electricity as heat into a local district-heating network warming approximately 6,000 homes per year, among the most genuinely sustainable hosting operations in Europe. Pricing is freemium and notably generous at the entry tier. **My kSuite** is a free tier offering 20 GB of email + Drive storage at an @ik.me or @etik.com address, with kMeet, kChat, kPaste and Office included, one of the most complete free privacy-email-and-collaboration offers in the European market. **Paid kSuite** tiers add custom-domain support, larger storage, admin controls, and SLA, scaling by user count and storage; Standard is in the rough region of €5-6/user/month and Pro around €11/user/month (per the public pricing page; pricing page rendered partially to automated fetching at audit, so EUR figures are approximate). Best fit: every Swiss-jurisdiction-aware EU user who wants email + a full collaboration stack from a single founder-led independent provider, and any procurement-grade buyer wanting an integrated Workspace alternative to Google/Microsoft. Together with Proton Mail, kSuite completes the directory's two-pillar Swiss-sovereignty email shortlist. **Compliance rationale:** Infomaniak Mail is the email pillar of **kSuite**, the Google-Workspace-style bundle (Mail, Drive, Calendar, Contacts, kMeet, kPaste, kChat, Office) operated by **Infomaniak Group SA** (Geneva, Switzerland; founded 1994 by Boris Siegenthaler and Fabian Lucchi; still independent, privately held, founder-led with no VC/PE on record), built on **Infomaniak's own Swiss data centres** (which kDrive runs on too, full ownership cross-reference in the kdrive listing), **ISO 27001 + ISO 9001 + ISO 14001 + ISO 50001 + B Corp 2025** certified, with a **free 'My kSuite' tier** offering 20 GB at @ik.me / @etik.com addresses; founder-owned, own Swiss data centres, no CLOUD Act exposure, public DPA available, the strongest broad-stack Swiss collaboration pick alongside Proton Mail. ### Infomaniak Newsletter: https://euvetted.com/p/infomaniak-newsletter - Website: https://www.infomaniak.com/en/marketing-events/newsletter-tool - Category: Email marketing - Country of incorporation: Switzerland - Hosting country: Switzerland (Geneva) - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: freemium - Founded: 1994 - Certifications: ISO27001, ISO9001, ISO14001, ISO50001 - DPA: https://www.infomaniak.com/documents/privacy/DPA/Data_Processing_Agreement_(DPA).pdf - Sub-processors list: https://www.infomaniak.com/en/legal/confidentiality-policy - Last verified: 2026-06-18 Swiss credit-based newsletter tool (Infomaniak, Geneva, since 1994); unlimited contacts, own Swiss DCs, ISO 27001, no CLOUD Act. Infomaniak Newsletter is the email-marketing product of **Infomaniak Group SA**, the independent Swiss technology company founded in Geneva in 1994 by **Boris Siegenthaler** and **Fabian Lucchi**, privately held, founder-led, with no venture-capital or private-equity investors on the cap table (the kdrive listing documents the same vendor in full). The tool covers the core newsletter workflow: a drag-and-drop / template-based campaign editor, **unlimited contacts and contact lists**, list import and segmentation, scheduled sends, and real-time open / click statistics. It integrates with the rest of the Infomaniak estate (Mail, kSuite, the website/site-creator products), and uses Infomaniak's own sending infrastructure for deliverability. For an EU-sovereignty audit, the differentiator is the hosting. The competitive set in this category (Brevo, Mailjet and similar) are EU-headquartered but typically run customer data on US-owned cloud (Google Cloud, AWS) with Cloudflare in front, which puts them at material CLOUD Act exposure. Infomaniak Newsletter instead runs on **Infomaniak's own Swiss data centres** in Geneva, with software developed in-house and all customer data on Swiss-located infrastructure under Infomaniak's direct control. The compliance footprint mirrors the rest of the estate: **ISO/IEC 27001** (since June 2018), **ISO 9001**, **ISO 14001**, **ISO 50001**, and **B Corp (2025)**; Switzerland's Art. 45 GDPR adequacy decision keeps EU↔CH transfers SCC-free. Pricing is unusual: there is **no subscription**. The tool uses a **credit model** (one credit sends one email) with a block of free credits for new users and recurring free monthly credits granted by other Infomaniak products (for example mail hosting or a VPS), then additional credits purchased on a sliding scale. This suits senders with irregular or seasonal volume better than a fixed monthly contact-tier plan. The trade-off is feature depth: Infomaniak Newsletter is a focused campaign tool, not a full marketing-automation suite: there is no built-in CRM, multi-step automation journeys, landing-page builder, or SMS channel of the kind Brevo or GetResponse offer. Best fit: Swiss and EU businesses, associations, and public-sector senders that want GDPR-clean, Swiss-hosted newsletters on a pay-as-you-go basis (especially existing Infomaniak Mail / kSuite customers) and anyone who prioritises data residency over advanced automation. **Compliance rationale:** Infomaniak Newsletter is the email-campaign product of **Infomaniak Group SA** (Geneva, Switzerland; founded 1994 by Boris Siegenthaler and Fabian Lucchi; independent, privately held, founder-led; full ownership cross-reference in the kdrive listing), a **credit-based newsletter tool** (templates, unlimited contacts, real-time stats) run on **Infomaniak's own Swiss data centres** with ISO 27001 + ISO 9001 + ISO 14001 + ISO 50001 + B Corp 2025, GDPR-compliant under Swiss law and the EU adequacy decision keeping EU↔CH transfers SCC-free; Swiss-owned, Swiss-hosted, in-house software, no CLOUD Act exposure; a clean Swiss alternative to Mailchimp where peers in this category (Brevo, Mailjet) run on US-owned cloud, though its feature surface is lighter than full marketing-automation suites. **Sub-processors mapped:** 1 total, 1 US-owned - PayPal (United States): Payment processing for credit purchases; ancillary, off the subscriber-data path [US-owned] ### Infomaniak Public Cloud: https://euvetted.com/p/infomaniak-public-cloud - Website: https://www.infomaniak.com/en/hosting/public-cloud - Category: Cloud & hosting - Country of incorporation: Switzerland - Hosting country: Switzerland (Geneva) - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: paid (from €3/month) - Founded: 1994 - Certifications: ISO27001, ISO9001, ISO14001, ISO50001 - DPA: https://www.infomaniak.com/documents/privacy/DPA/Data_Processing_Agreement_(DPA).pdf - Sub-processors list: https://www.infomaniak.com/en/legal/confidentiality-policy - Last verified: 2026-06-18 Swiss OpenStack public cloud + VPS + hosting (Infomaniak Group SA, Geneva, since 1994); own Swiss DCs, ISO 27001 + B Corp 2025, no CLOUD Act. Infomaniak Public Cloud is the infrastructure-as-a-service offering of **Infomaniak Group SA**, the independent Swiss technology company founded in Geneva in 1994 by **Boris Siegenthaler** and **Fabian Lucchi**, one of the longest-running independent European hosting companies, privately held and founder-led with no venture-capital or private-equity investors on the cap table (the kdrive listing documents the same vendor in full). The cloud product is a **standards-based OpenStack public cloud**: compute instances billed by the hour, block and object storage, managed Kubernetes, managed databases, and GPU instances for AI/ML workloads, accessible via the OpenStack API and Terraform. Alongside it Infomaniak sells VPS (from roughly €3/month), shared and managed web hosting, and managed cloud servers: a full ladder from a single small VPS up to OpenStack-orchestrated production estates. For an EU-sovereignty audit this is among the most defensible Swiss IaaS listings in the directory. Infomaniak designs, builds, and fully operates **its own Swiss data centres** in Geneva: there is no hyperscaler underneath, the software stack is developed in-house, and all customer data stays on Swiss-located infrastructure under Infomaniak's direct control. The compliance footprint is broad: **ISO/IEC 27001** (since June 2018), **ISO 9001** (quality), **ISO 14001** (environmental), **ISO 50001** (energy), and **B Corp certification (2025)**. Switzerland holds an EU adequacy decision under Art. 45 GDPR, so transfers EU↔CH are SCC-free, and the latest data centre recycles 100% of its consumed electricity as heat into a local district-heating network warming roughly 6,000 homes a year, among the most genuinely sustainable hosting operations in Europe. Because OpenStack is an open standard, there is no proprietary lock-in at the orchestration layer: workloads are portable to any other OpenStack cloud (OVHcloud, Cleura, and others in this category). Pricing is transparent and usage-based: compute billed by the second/hour, object storage per GB, VPS on flat monthly tiers from ~€4. Best fit: Swiss and EU organisations that want a genuine Swiss-jurisdiction public cloud rather than a US hyperscaler's EU region; regulated and public-sector buyers needing data-residency and adequacy clarity; and teams that value an independent founder-led vendor running its own sustainable infrastructure. Together with Exoscale, Infomaniak completes the directory's Swiss-sovereignty IaaS shortlist. **Compliance rationale:** Infomaniak Public Cloud is the IaaS layer of **Infomaniak Group SA** (Geneva, Switzerland; founded 1994 by Boris Siegenthaler and Fabian Lucchi; independent, privately held, founder-led with no VC/PE on record; full ownership cross-reference in the kdrive listing), a **standards-based OpenStack public cloud** (compute, block + object storage, managed Kubernetes, managed databases, GPU instances) plus VPS and web hosting, run entirely on **Infomaniak's own Swiss data centres** (Geneva) with ISO 27001 + ISO 9001 + ISO 14001 + ISO 50001 + B Corp 2025; Swiss-owned, own Swiss infrastructure, in-house software, public DPA, and Switzerland's EU adequacy decision keeping EU↔CH transfers SCC-free: no CLOUD Act exposure, making it a direct Swiss-sovereignty peer to Exoscale and the EU IaaS set (Hetzner / OVHcloud / Scaleway). **Sub-processors mapped:** 1 total, 1 US-owned - PayPal (United States): Payment processing; ancillary, off the customer-workload path [US-owned] ### Internxt: https://euvetted.com/p/internxt - Website: https://internxt.com - Category: File sharing - Country of incorporation: Spain - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium (from €10/month) - Founded: 2020 - Certifications: ISO27001 - DPA: https://internxt.com/DPA.pdf - Sub-processors list: https://internxt.com/legal - Last verified: 2026-05-18 Valencia-based open-source zero-knowledge encrypted cloud (Internxt, 2020), post-quantum crypto, lifetime plans, 1 GB free, 1M+ users. Internxt is a Valencia-based zero-knowledge encrypted cloud-storage product operated by **Internxt Universal Technologies S.L.** (VAT B98936354), founded in 2020 by Fran Villalba Segarra (CEO), currently with a team of approximately 30 and more than 1 million active users. The product covers Drive, Send (file transfer), VPN, Antivirus, Cleaner, Mail, and Meet across a single privacy-focused account, positioning itself as a European Mega / Tresorit / Proton Drive challenger with two structural differentiators: **fully open-source code** (publicly auditable on GitHub) and **post-quantum cryptography** (Kyber-512 alongside AES-256 at rest and TLS 1.3 in transit). Internxt was the first cloud-storage vendor to ship post-quantum protection across consumer tiers, and the codebase has been independently audited by Securitum (2024). For an EU-sovereignty audit Internxt stands out for two reasons. First, ownership: Spanish founder-controlled with no venture-capital or private-equity investors on the cap table, financially stable, 100% YoY growth. Second, compliance: **ISO/IEC 27001:2022** certified, HIPAA-aligned, GDPR-compliant, Spanish DPO via Egida (legal@egida.es), terms last updated January 2026. The infrastructure side is a distributed-node architecture with servers in multiple countries rather than a single EU-locked region, a choice driven by encryption philosophy: because every file is encrypted on the device before upload and the encryption keys never leave the user, plaintext customer content cannot be read by any node operator anywhere in the world. This makes the multi-region distribution a `minor` CLOUD Act flag rather than `material` (the threat model assumes the encryption stands). Pricing in EUR is a hybrid of subscription and lifetime: 1 GB encrypted free; Essential 1 TB at a regular ~€9.99/month billed annually (~€120/year). Internxt bills annually or as a one-time lifetime purchase. There is no month-to-month plan, so the per-month figure is the annual price divided over twelve months. The headline rates advertised on the site (often ~€1-4/month) are first-year promotional prices that renew at the full ~€9.99/month after the first term; Premium and Ultimate tiers scale to multi-TB; **lifetime plans** are a signature offering: one-time payment for permanent access up to 5 TB per plan, stackable across multiple plans with the same email up to 100 TB total. 30-day money-back guarantee. Best fit: privacy-first individuals and SMBs that want a Spanish-founded open-source alternative to Dropbox / iCloud / Google Drive with the option to escape subscriptions via lifetime plans, post-quantum protection, and verifiable code. **Compliance rationale:** **Internxt Universal Technologies S.L.** (Valencia, Spain; VAT B98936354) is a founder-controlled zero-knowledge encrypted cloud-storage product founded in 2020 by Fran Villalba Segarra: **fully open-source code on GitHub**, **post-quantum cryptography (Kyber-512)** in addition to AES-256 / TLS 1.3, ISO/IEC 27001:2022 certified, independently audited by Securitum (2024), HIPAA-aligned, no VC/PE investors on the cap table, with a public DPA at internxt.com/DPA.pdf; the distributed-node infrastructure is global rather than EU-only but zero-knowledge encryption means plaintext customer data never leaves the device; EU-owned with public DPA and open-source clients, with only a `minor` CLOUD Act flag reflecting the multi-region node distribution. ### Intility: https://euvetted.com/p/intility - Website: https://intility.com - Category: Cloud & hosting - Country of incorporation: Norway - Hosting country: Norway (Oslo) - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2000 - Certifications: ISO27001 - Sub-processors list: https://intility.com/privacy-policy - Last verified: 2026-06-12 Norwegian managed enterprise-cloud platform (est. 2000), own platform colocated in Oslo, NO/SE data residency, ISO 27001 + ISAE 3402/3000; enterprise quote-based, no public pricing. Intility AS is a Norwegian managed enterprise-cloud and digital-workplace provider founded in 2000, headquartered at Schweigaards gate 39, 0191 Oslo (org. nr 981 967 070), serving roughly 700 companies across 3,000+ locations in Norway and the wider Nordics. Unlike a self-service IaaS, Intility sells a fully-managed "complete platform for multicloud IT environments": it operates its own platform on colocated infrastructure (Bulk Data Centers' OS-IX facility in Oslo, with Swedish presence), wrapping compute, networking, managed Kubernetes, managed databases, identity/SSO, security and an end-user digital workplace into one operated service. This is a real local operator running its own stack, not a thin reseller of a US hyperscaler. For sovereignty-minded buyers the key distinction is between Intility's dedicated Sovereign Cloud SKU and its default multicloud platform. The Sovereign Cloud keeps all data stored and processed strictly within Norwegian and Swedish jurisdiction, operated and supported exclusively by NO/SE personnel, and can be locked to a single country, a genuinely clean posture for finance, healthcare, energy and public-sector workloads. The mainstream Intility platform, by contrast, is explicitly multicloud and commonly integrates Microsoft 365 / Azure and other public cloud at the customer's election, which carries material US CLOUD Act exposure for any data that lands there. Buyers must therefore specify the sovereign offering to get the local-only guarantees. Compliance evidence is solid on attestation but weak on self-serviceability: Intility holds ISO 27001 (certified April 2025 by Scandinavian Certification AS, scope = all service deliveries, only "outsourced development" excluded) and publishes ISAE 3402 Type 2 (information security) and ISAE 3000 Type 2 (GDPR) reports. However, the DPA is not publicly available (processing is governed by separate per-customer data-processing agreements), and the only public sub-processor list covers the corporate marketing website (Fathom Analytics, Hotjar, Questback, Teamtailor, WhistleB), not the customer platform. Ownership is Norwegian-led with minority Nordic/UK venture backing (Northzone, Melesio; linked via the Amphytron vehicle of Bjørn Stray and Arild Engh); no US private-equity or US controlling stake is evident. Pricing is enterprise and quote-based with no public EUR list. Best fit: Nordic enterprises and public bodies that want a single managed sovereign platform and will contract the Sovereign Cloud SKU explicitly. **Compliance rationale:** Intility AS (org. nr 981 967 070, Schweigaards gate 39, Oslo) is a Norwegian-controlled managed enterprise-cloud platform that runs its OWN platform on colocated hardware (Bulk Data Centers, OS-IX Oslo) with all platform data stored and processed within Norwegian and Swedish borders and operated by NO/SE staff, a genuine local operator, not a US-hyperscaler reseller. It is ISO 27001 certified (audited April 2025 by Scandinavian Certification AS, covering all service deliveries) and additionally publishes ISAE 3402 Type 2 (security) and ISAE 3000 Type 2 (GDPR) reports. It is capped at 3/5 because: (1) the flagship product is a multicloud managed platform that routinely integrates Microsoft 365 / Azure and other public cloud for customers, introducing material US CLOUD Act exposure outside the dedicated 'Sovereign Cloud' SKU; (2) there is no publicly self-servable DPA: processing is governed by per-customer agreements available only on contract, and the public sub-processor list (Fathom, Hotjar, Questback, Teamtailor, WhistleB) covers only the corporate website, not the customer platform; (3) Norway is EEA but outside the EU, and no EUCS / C5 / SecNumCloud attestation exists. The clean local-hero posture applies to the Sovereign Cloud offering specifically; the default platform is multicloud. ### Inxmail: https://euvetted.com/p/inxmail - Website: https://www.inxmail.de - Category: Email marketing - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid - Founded: 1999 - Certifications: ISO27001 - Last verified: 2026-05-10 Freiburg-based premium German enterprise email marketing platform with ISO 27001 (TÜV Rheinland) and EU-only hosting. Inxmail is a Freiburg-headquartered German email marketing platform operated by Inxmail GmbH (Wentzingerstr. 17, 79106 Freiburg im Breisgau), founded in 1999 and one of the longest-running independent ESPs in DACH. The product is positioned as a premium enterprise solution for media and publishing, energy utilities, banking and insurance, and retail/e-commerce, with a modular platform covering newsletter campaigns, marketing automation, transactional / trigger-based emails, and an SMTP Mail Relay. Inxmail reports more than 2,000 corporate customers. The compliance posture is strong on the technical side: customer data is hosted exclusively on EU servers, the company is ISO 27001-certified by TÜV Rheinland (first issued 2020) for development and operation of its email marketing applications, and it carries the "Software Made in Germany" industry seal. The privacy policy notes that any transatlantic transfers (e.g. for Google Analytics or LinkedIn marketing pixels on the corporate website) are covered by Standard Contractual Clauses; the external Data Protection Officer is DDSK GmbH. Where Inxmail is weaker for a procurement-grade assessment is transparency: the dedicated DPA (AVV), security, and sub-processor pages were not publicly resolvable at audit time, and pricing is enterprise-only on a sales-contact basis, so small EU buyers cannot self-serve a copy of the DPA; the absence of a public DPA and sub-processors disclosure is the primary gap in an otherwise solid EU-hosted, EU-owned, ISO 27001-certified profile. Pricing is custom: per the public prices page, fees cover hosting, administration, deliverability team, and monthly user support, scaling with email volume; no public price tier or freemium is advertised. Best fit: mid-market and enterprise marketers in DACH (publishers, utilities, financial services) who want a long-running independent German vendor, ISO 27001 attestation, and white-glove deliverability support, and are comfortable with sales-mediated procurement. Buyers who need a freemium entry tier or self-serve DPA download should look at CleverReach or rapidmail in this category. **Compliance rationale:** Freiburg-based GmbH with EU-only hosting, ISO 27001 certified by TÜV Rheinland, SCC for the small US sub-processor footprint that exists for marketing-site analytics, and 'Software Made in Germany' designation: EU-owned and EU-hosted with minor CLOUD Act exposure, but no publicly-linked DPA or sub-processors document (enterprise sales model gates these documents to the contracting flow). ### IONOS: https://euvetted.com/p/ionos - Website: https://www.ionos.com - Category: Cloud & hosting - Country of incorporation: Germany - Hosting country: Germany (Frankfurt) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €2/month) - Founded: 1988 - Certifications: ISO27001, C5 - DPA: https://www.ionos.de/terms-gtc/AVV/ - Sub-processors list: https://www.ionos.de/terms-gtc/fileadmin/pdf/terms-gtc/DE/AVV/AVV_Liste_Subunternehmen_v4_5_DE.pdf - Last verified: 2026-05-18 German publicly-listed cloud (IONOS Group SE, Frankfurt + Berlin DCs), first DE provider with both BSI C5 + IT-Grundschutz, Gaia-X member. IONOS is the cloud and hosting arm of IONOS Group SE, a publicly-listed German company (Frankfurt Stock Exchange) descended from the 1&1 Internet / United Internet group, founded in 1988. The company operates from Karlsruhe and is one of the larger European hosting players, with millions of domains under management and a full product surface across web hosting, managed servers, cloud compute, cloud object storage (S3-compatible), Cloud Cubes, managed Kubernetes, and email. The cloud workload story is split between IONOS Inc. (Philadelphia, USA) for US customers and IONOS Group SE / IONOS SE (Germany) for EU customers. Buyers contracting through ionos.de / EU pricing pages contract with the German entity, which is what places EU-region workloads under German jurisdiction with no CLOUD Act exposure. Compliance posture is among the strongest in the directory. IONOS Cloud was the first German cloud provider to demonstrate both the German government's BSI **C5** attestation (Cloud Computing Compliance Criteria Catalogue) for Compute Engine, Cloud Cubes, and S3 Object Storage (received November 2023) and the BSI **IT-Grundschutz** certification, the underlying baseline for the ISO/IEC 27001 attestation IONOS Cloud holds for its Frankfurt and Berlin data centres and co-located capacity. The company is an active **Gaia-X** member (the European data-sovereignty initiative), is available to the German public sector through the **govdigital** sovereign-cloud framework, and announced a January 2026 cooperation agreement with the BSI focused on building a sovereign-cloud platform for the federal administration and post-quantum protection. Pricing for IONOS Cloud Compute starts at approximately €2/month for the smallest VPS-class instances, with hourly + monthly billing. The product surface, sales-locale, and EUR pricing on ionos.de make it a natural fit for German and broader-EU SMBs and public-sector buyers. Best fit: German public-sector procurement (govdigital path), regulated industries that need BSI C5 + IT-Grundschutz dual coverage, and any EU buyer wanting a Frankfurt-rooted hyperscaler-alternative with a public-listed German parent and a documented BSI cooperation roadmap. Note: customers who specifically use US-region services or sign up via ionos.com US pricing contract with IONOS Inc. (Philadelphia) and are subject to international data transfers under the IONOS Inc. privacy policy. **Compliance rationale:** IONOS Group SE (German parent, publicly listed on Frankfurt Stock Exchange, originally the 1&1 / United Internet group) operates IONOS Cloud from Frankfurt and Berlin data centres and is the first German cloud provider to hold **both** BSI C5 attestation **and** BSI IT-Grundschutz certification (the latter underpins its ISO/IEC 27001), plus active Gaia-X membership and a January 2026 cooperation with BSI for federal sovereign cloud; for EU customers contracting with the German entity, EU-owned and EU-hosted with no CLOUD Act exposure. ### Iubenda: https://euvetted.com/p/iubenda - Website: https://www.iubenda.com - Category: Cookie consent - Country of incorporation: Italy - Hosting country: Ireland (Milan) - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium (from €2/month) - Founded: 2010 - Certifications: ISO27001 - DPA: https://www.iubenda.com/terms-and-conditions/39701710 - Last verified: 2026-05-12 Italian privacy-compliance toolkit (Milan, est. 2010); 150K+ customers; subject to direction of Team.blue NV (Belgium). **Iubenda** (Milan, Italy, founded 2010) is a 15-year-old privacy-compliance toolkit covering **cookie consent, privacy policy generator, terms generator, accessibility widget, and advanced compliance solutions**. It has 150,000+ customers across 400,000+ sites and apps. **In-house legal team monitors regulations** and updates the templates accordingly. Google-certified CMP partner, IAB TCF 2.2 validated, ISO 27001 aligned. Parent company is **Team.blue NV** (Belgium), a European hosting / SaaS consolidator backed by **Hg Capital** (UK PE) and **CPP Investments** (Canada Pension), no material US private-equity majority. For procurement buyers Iubenda is one of the cleanest cookie-consent picks remaining outside the Vista-controlled Usercentrics / Cookiebot consolidation. **Compliance rationale:** **Iubenda** (Milan IT, founded 2010, 15+ years operational) is **ISO 27001 aligned**, IAB TCF 2.2 validated, Google-certified CMP, 150K+ customers, supports 27 human-translated languages with in-house legal team monitoring regulations, and crucially its parent **Team.blue NV** (Belgium) is European-controlled (Hg Capital UK + CPP Investments Canada, no US PE majority); ownership_signal `eu_owned`, minor CLOUD Act exposure; note: explicit sub-processor list and DPA URL not surfaced publicly. ### IVPN: https://euvetted.com/p/ivpn - Website: https://www.ivpn.net - Category: VPN - Country of incorporation: Gibraltar - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: paid (from €6/month) - Founded: 2009 - Sub-processors list: https://www.ivpn.net/en/privacy/ - Last verified: 2026-05-11 Gibraltar-incorporated VPN (IVPN Limited / ex-Privatus, founded 2009), Cure53-audited no-logs, open-source apps, independent ownership. IVPN is a Gibraltar-incorporated privacy-focused VPN operated by **IVPN Limited** (formerly Privatus Limited), founded in 2009 by Nicholas Pestell. The company is independent: no parent company, no private-equity or venture-capital ownership, no other VPN brands operated, a structural rarity in a category dominated by conglomerated VPN consolidators (Kape Technologies, NordVPN parent group, etc.). Gibraltar is a British Overseas Territory that maintains GDPR alignment with the EU framework but explicitly sits **outside the 5/9/14 Eyes** intelligence-sharing alliance, which is the headline jurisdictional advantage IVPN markets to its target audience. Compliance and privacy posture are gold-standard. The no-logs policy has been independently audited by **Cure53** (the German cybersecurity firm) three separate times, alongside a comprehensive pentest of apps and infrastructure. IVPN publishes transparency reports on law-enforcement requests, runs all apps as open-source, and is one of only two VPN providers (alongside Proton VPN) on most "best for privacy" 2026 shortlists with both open-source apps AND annual third-party audits. The privacy policy is straightforward: no activity logs, no connection logs, no DNS query logs, no IP-address logs, no timestamp logs. Tor-over-IVPN and multi-hop modes are supported. Pricing is direct and trial-friendly: Standard plan around US$6/month (€5–6 equivalent); a 7-day trial is available; cards plus Bitcoin and Monero accepted. No free tier. Best fit: privacy-maximalist EU and worldwide users who want a Cure53-audited no-logs guarantee under a Gibraltar-Outside-Eyes jurisdiction, journalists, researchers, and anyone valuing independent ownership over feature-bloated marketing. The smaller server fleet vs Proton VPN means slightly lower geo-coverage and streaming-unblock breadth, which is the trade-off for the structurally cleaner posture. **Compliance rationale:** IVPN Limited (formerly Privatus Limited) is a Gibraltar-incorporated VPN provider founded in 2009 by Nicholas Pestell (independent, no parent company, no PE/VC funding, no other VPN brands owned) with a Cure53-audited no-logs policy (three independent audits + a comprehensive pentest), open-source apps, public transparency reports, and Gibraltar jurisdiction explicitly outside the 5/9/14 Eyes intelligence-sharing alliance. No CLOUD Act exposure; independent ownership with no US ties. The one gap in the signal set: IVPN does not publish a publicly accessible DPA. Only a privacy policy is available, with no processor agreement for EU buyers to self-serve. ### Joplin: https://euvetted.com/p/joplin - Website: https://joplinapp.org - Category: Docs & wikis - Country of incorporation: France - Hosting country: France - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €3/month) - Founded: 2016 - Last verified: 2026-05-21 Open-source E2EE note-taking app by French developer Laurent Cozic (2016); Joplin Cloud hosted in France; €2.99/mo; self-sync to any EU storage. Joplin is a fully open-source, cross-platform note-taking and task-management application created in 2016 by **Laurent Cozic**, a French developer. The application runs on Windows, macOS, Linux, Android, iOS, and as a terminal app, with notes saved in Markdown to an open format on the user's chosen storage backend. Joplin Cloud, the optional managed sync service, is hosted in France under EU privacy laws and charged from **€2.99/month** (Basic) through €5.99/month (Pro) and €7.99/user/month (Teams). All Joplin Cloud tiers support **end-to-end encryption** (the same E2EE available for self-sync scenarios) meaning Laurent Cozic's servers cannot read user notes even when syncing through Joplin Cloud. The product positions itself as a privacy-first Evernote / Obsidian / Roam Research alternative. The core differentiators for EU-sovereignty buyers are the French operator (EU member state, GDPR-default), the E2EE architecture on the cloud tier, and the fully open-source codebase (MIT-licensed; GitHub: laurent22/joplin). Synchronisation works with Joplin Cloud (France-hosted), Dropbox, OneDrive, Nextcloud, WebDAV, or any S3-compatible storage, giving EU buyers the flexibility to sync through purely EU infrastructure (e.g. Hetzner S3 / OVHcloud Object Storage / Infomaniak kDrive) if preferred. For EU-sovereignty procurement Joplin is the cleanest note-taking listing in the docs-and-wikis category by operator origin: French developer, France-hosted cloud, E2EE, MIT open source. The remaining gap is the absence of a formal DPA document (typical for a micro-ISV solo project) and the lack of an explicit sub-processors page. In practice the E2EE architecture means this gap is structurally less significant than for non-encrypted services. Best fit: individual privacy-conscious knowledge workers, journalists, researchers, and freelancers wanting a self-hostable open-source Obsidian / Evernote alternative with EU data residency; teams using the Teams tier with shared notebook access. **Compliance rationale:** Joplin is an **open-source, end-to-end encrypted note-taking application** created by French developer **Laurent Cozic** (copyright 2016-2026). Joplin Cloud is hosted in France, protected by EU privacy laws, with E2EE meaning even the operator cannot read user notes. Signals: EU developer (France), EU-hosted cloud (France), end-to-end encrypted, no CLOUD Act exposure, MIT open-source codebase. Gaps: no publicly accessible DPA (typical gap for a micro-ISV solo project); no formal sub-processors list. ### Jottacloud: https://euvetted.com/p/jottacloud - Website: https://www.jottacloud.com - Category: File sharing - Country of incorporation: Norway - Hosting country: Norway - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: freemium (from €7/month) - Founded: 2008 - DPA: https://jottacloud.com/en/data-processing-agreement - Sub-processors list: https://docs.jottacloud.com/en/articles/1937299-general-data-protection-regulation-gdpr-at-jottacloud - Last verified: 2026-05-14 Norwegian cloud storage & backup (Jotta Group AS, est. 2008), 100% Norway-hosted on renewable power, server-side AES-256, public DPA, no CLOUD Act reach. Jottacloud is a Norwegian cloud storage and online-backup service operated by Jotta Group AS, headquartered at Øvre Slottsgate 5, Oslo (organisation number 992 603 615). It was founded in 2008 by Roland Rabben (reportedly motivated by wanting to keep his family's photos safe) and the name is a deliberate misspelling of "Yottabyte." Over more than fifteen years it has grown into one of the larger independent European storage providers, with reported double-digit average annual revenue growth. The core sovereignty story is strong and simple: **all of Jottacloud's server infrastructure is physically in Norway**, powered by renewable hydropower and seawater-cooled, and the company explicitly markets that as a Norwegian operator it is outside the reach of the US CLOUD Act. Data is protected under Norwegian and EEA privacy law, a Data Processing Agreement is publicly linked (not gated behind enterprise sales), and the company maintains a transparency page. The main caveat for an encryption-focused buyer: Jottacloud uses **server-side AES-256 encryption with company-managed keys**, not zero-knowledge / client-side encryption: Jotta can technically access stored data, unlike Proton Drive, Internxt or Tresorit. No ISO 27001 certification or sub-processors list was surfaced at audit. An ownership change is in progress and worth watching: in March 2025 Jotta AS and Telenor Software Lab announced a merger to create a larger Norwegian cloud-storage challenger, with founder Roland Rabben as CEO. Telenor is a large, partly Norwegian-state-owned telco; this does not introduce US exposure, but it does change the cap-table and should be re-verified on the next audit pass. Pricing is freemium: 5 GB free; Home 1 TB at €6.90/month (€69/year); Unlimited at €11.90/month (€119/year); Pro 10 TB at €29.90/month. Best fit: Norwegian and EEA individuals and SMBs who want straightforward backup-and-sync with genuine in-country hosting and a clean CLOUD Act story, and who do not require zero-knowledge encryption. Buyers who need client-side encryption should prefer Proton Drive, Internxt, Filen or Tresorit. **Compliance rationale:** Jottacloud is operated by **Jotta Group AS** (Øvre Slottsgate 5, Oslo, Norway; org. no. 992 603 615), founded 2008 by Roland Rabben, a Norwegian company with **all server infrastructure in Norway**, powered by renewable hydropower, with a publicly linked DPA and an explicit statement that the US CLOUD Act does not reach a Norwegian operator; EEA-incorporated (Norway, not EU) with Norwegian-only hosting, public DPA, and no CLOUD Act exposure; key gaps are server-side (not zero-knowledge) encryption and no ISO 27001 or sub-processors list surfaced at audit. ### Kantree: https://euvetted.com/p/kantree - Website: https://kantree.io - Category: Project management - Country of incorporation: France - Hosting country: France - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Certifications: ISO27001 - DPA: https://kantree.io/privacy/dpa - Sub-processors list: https://kantree.io/privacy - Last verified: 2026-05-18 Flexible French work management platform (Kantree by Digicoop), 100% employee-owned cooperative, EU hosting, ISO 27001. Kantree is the work-management platform built by **Digicoop**, a French workers' cooperative (SCOP: Société Coopérative et Participative) that is 100% employee-owned. The legal structure is a fundamental procurement-grade signal: there are no external shareholders, no VC / PE on the cap table, and the cooperative model permanently prevents acquisition or hostile takeover, a governance posture matched in this directory only by Proton's non-profit foundation structure and Cryptee's solo bootstrap. The product covers Kanban boards, Gantt timelines, custom forms, dashboards, and workflow automations across project management, engineering, IT, HR, and marketing use cases. Compliance posture: **ISO/IEC 27001 certified**, GDPR compliant, **EU-only hosting with daily backups**, French jurisdiction throughout. The combination of cooperative ownership, ISO 27001, EU hosting, and no CLOUD Act exposure makes Kantree one of the strongest sovereignty signals in this category. The product is also available as a self-hosted on-premise deployment for organisations that want to keep the entire stack on their own infrastructure. Pricing details were not directly captured at audit (the /pricing path requires deeper crawl); the model is paid SMB / mid-market without a public freemium. Best fit: EU SMBs and agencies that value the cooperative ownership story alongside the flexibility of an Airtable / Monday-class platform, and any organisation requiring an on-premise PM option without losing managed-cloud feature parity. **Compliance rationale:** Kantree is operated by **Digicoop**, a French **workers' cooperative** (SCOP) that is **100% employee-owned**, a structurally rare governance model that permanently prevents external takeover, paired with **ISO/IEC 27001** certification and explicit **EU-only hosting** with daily backups; the product is a flexible Kanban/Gantt/timeline work-management platform covering project, engineering, IT, HR, and marketing use cases. EU-owned by cooperative structure, EU-hosted, ISO 27001 certified, with no CLOUD Act exposure. ### kDrive (Infomaniak): https://euvetted.com/p/kdrive - Website: https://www.infomaniak.com/en/kdrive - Category: File sharing - Country of incorporation: Switzerland - Hosting country: Switzerland (Geneva) - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: paid (from €4/month) - Founded: 1994 - Certifications: ISO27001 - DPA: https://www.infomaniak.com/documents/privacy/DPA/Data_Processing_Agreement_(DPA).pdf - Last verified: 2026-05-18 Swiss kDrive cloud (Infomaniak, Geneva, since 1994), own Swiss DCs, ISO 27001 + B Corp 2025, district-heating heat recycling. kDrive is the cloud-storage and collaboration product of **Infomaniak Group SA**, the independent Swiss technology company founded in Geneva in 1994 by **Boris Siegenthaler** and **Fabian Lucchi** (growing out of a 1990 user group). Infomaniak is one of the longest-running independent European hosting companies, privately held, founder-led, with no venture-capital or private-equity investors anywhere on the cap table. The company designs, builds, and fully operates **its own Swiss data centres** with all customer infrastructure and servers under its direct control, and ships an integrated ecosystem of products: kDrive (cloud storage and sync), kMail / Mail, kSuite (office and collaboration), Public Cloud (compute), Web Hosting, Streaming, Newsletter, kMeet (video conferencing), and more. For an EU-sovereignty audit Infomaniak is among the most defensible Swiss listings in this directory. The compliance footprint is unusually broad: **ISO/IEC 27001** since June 2018, **ISO 9001** (quality), **ISO 14001** (environmental), **ISO 50001** (energy), plus **B Corp certification in 2025**, the international label that recognises strong social, environmental, governance, and transparency standards. Switzerland holds an EU adequacy decision under Art. 45 GDPR, so transfers EU↔CH are SCC-free. All customer data is stored exclusively on Swiss-located infrastructure operated by Infomaniak itself; the latest data centre is built into the basement of a participatory housing cooperative and recycles 100% of consumed electricity as heat into the local district-heating network warming approximately 6,000 homes per year, among the most genuinely sustainable hosting operations in Europe. kDrive pricing in EUR: Solo kDrive ~€4.42/month for 3 TB; my kSuite tiers bundle Drive with Mail / Documents / Meet / Spreadsheets / Presentation for from ~€7/month; business and Pro tiers above scale by users and storage. Best fit: every Swiss-jurisdiction-aware EU procurement-grade buyer; particularly compelling for environmentally-conscious organisations, public-sector procurement, and any team wanting an independent founder-led Swiss vendor with broad-stack collaboration (Drive + Mail + Docs + Meet) under a single provider. Together with Proton Drive and Tresorit, kDrive completes the directory's three-pillar Swiss-sovereignty file-sharing shortlist. **Compliance rationale:** **Infomaniak Group SA** (Geneva, Switzerland; founded 1994 by Boris Siegenthaler and Fabian Lucchi, growing out of a 1990 user group; still independent, privately held, founder-led) operates kDrive on **its own Swiss-built and Swiss-operated data centres**: ISO 27001 certified since June 2018 plus ISO 9001 + ISO 14001 + ISO 50001 + **B Corp certified (2025)**, all customer data stays in Switzerland, and the latest DC recycles 100% of its electricity into the local district heating network (enough to warm ~6,000 homes annually); Swiss-headquartered and founder-led, own Swiss data centres, public DPA, ISO 27001 + multi-ISO certifications, B Corp, and no CLOUD Act exposure. ### KeePassXC: https://euvetted.com/p/keepassxc - Website: https://keepassxc.org - Category: Password managers - Country of incorporation: Germany - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: free - Founded: 2016 - Last verified: 2026-05-18 GPLv3 fully-offline desktop password manager (KeePassXC Team, Weimar DE, est. 2016): no cloud, no servers, no telemetry; structurally zero CLOUD Act exposure. KeePassXC is a modern, secure, open-source password manager for Windows, macOS and Linux, maintained by the KeePassXC Team, an unfunded, international volunteer group with core members based in Weimar, Germany. The project began in 2016 as a community-driven fork of KeePassX (itself a cross-platform port of the original Windows-only KeePass), and is licensed under **GPLv3** with the full source openly available on GitHub. KeePassXC is the structurally cleanest listing in the password-manager category, for one simple reason: it is **entirely offline**. There is no cloud service, no servers, no online account, no subscription, no ads, and no telemetry. Passwords are stored in a locally encrypted .kdbx database file that the user controls completely. KeePassXC explicitly states "no data is stored on remote servers." Because there is no service-side data processing at all, there is no DPA, no sub-processors list, and no hosting country to audit, and CLOUD Act exposure is not merely "none" but structurally impossible. Sync, if the user wants it, is the user's own choice: they can place the .kdbx file on any storage they trust (a EU cloud-storage provider from this directory, a USB key, a self-hosted server), but that is a decision the user makes and controls, not something KeePassXC does. The trade-off is that KeePassXC is a desktop application, not a service: there is no built-in cross-device sync, no team-sharing infrastructure, and no web client, features that hosted competitors (Proton Pass, NordPass, Uniqkey) provide out of the box. KeePassXC itself ships only desktop builds (Windows, macOS, Linux) and has no official mobile client, but its encrypted .kdbx database uses the open KeePass file format, which compatible third-party mobile apps can open (KeePassDX on Android, Strongbox and KeePassium on iOS), so the offline approach is not confined to the desktop. It does offer a robust feature set within its offline scope: strong AES/ChaCha20 encryption, a password generator, browser integration via the official browser extension, TOTP storage, SSH-agent integration, and Secret Service API support on Linux. The project is funded entirely by donations. Best fit: privacy-maximalist individuals and technically confident users who want absolute local control of their credentials with zero service dependency, and any procurement-grade buyer for whom "there is no vendor and no server" is the strongest possible answer to a sovereignty question. **Compliance rationale:** KeePassXC is a **GPLv3 open-source, fully offline desktop password manager** maintained by an unfunded international volunteer team (the KeePassXC Team, with core members based in Weimar, Germany; the project began in 2016 as a community fork of KeePassX). There is **no cloud, no servers, no account, no telemetry, no data processing of any kind**: the encrypted .kdbx database file lives entirely on the user's own devices, which makes CLOUD Act exposure structurally impossible; EU-maintained, open-source, with the strongest data-minimisation posture in the directory alongside Mullvad. ### Keila: https://euvetted.com/p/keila - Website: https://www.keila.io - Category: Email marketing - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid (from €8/month) - DPA: https://www.keila.io/dpa/dpa.en.pdf - Sub-processors list: https://www.keila.io/dpa/subcontractors.en.pdf - Last verified: 2026-06-16 German open-source (AGPLv3) newsletter platform; public DPA + sub-processors, EU-only data (Hetzner DE + Scaleway FR), self-hostable. A privacy-first Mailchimp alternative. Keila is the open-source email-newsletter platform built and operated by Keila GmbH, a small bootstrapped company based in Seybothenreuth, Germany (managing director Philipp Schmieder; HRB 8676, Amtsgericht Bayreuth). Licensed under AGPLv3 with source on GitHub (pentacent/keila) and an official Docker image, it can be self-hosted for free or used as a managed EU-hosted cloud service, positioned as a privacy-first alternative to Mailchimp, ConvertKit and other proprietary newsletter tools. Functionally it covers the newsletter workflow end to end: a visual block editor plus Markdown and MJML/custom HTML layouts, signup forms with custom fields, double opt-in, bot protection (Friendly Captcha or hCaptcha), list segmentation with both a visual editor and a query language, Liquid-based personalization, marketing automations, A/B testing, and open/click analytics that are privacy-conscious and can be switched off entirely. A comprehensive API is available (Zapier integration in private beta). Sending is flexible: either "Send with Keila" (managed) or bring-your-own SMTP/ESP such as AWS SES, Mailgun, Postmark or SendGrid. The sovereignty story is among the cleanest in the category. Keila GmbH is 100% European-owned with no foreign capital, all customer data is stored exclusively on EU servers (Hetzner in Germany, Scaleway in France), and both the DPA and the sub-processor list are public PDFs downloadable without a login. The approved sub-processor list (as of April 2026) names only Hetzner (DE), Scaleway (FR), AWS EMEA SARL (Luxembourg/Germany, used only for the optional managed SMTP relay) and Intuition Machines (US, only if hCaptcha is chosen over the EU Friendly Captcha). Both US-linked services are optional and transient with no customer data at rest in the US, so CLOUD Act exposure is minor. A self-hoster using bring-your-own SMTP and Friendly Captcha removes it entirely. Cloud pricing is transparent and scales by monthly email volume, with unlimited contacts and projects on every plan: €8 (XS, 2,000 emails/mo), €16 (S, 5,000), €32 (M, 15,000), €64 (L, 50,000), €128 (XL, 100,000) and €256 (XXL, 250,000). There is deliberately no free cloud tier (the company is bootstrapped and declines to monetize user data), though self-hosting is free. Best fit: privacy-conscious creators, NGOs and SMBs who want a GDPR-clean, EU-hosted or self-hostable newsletter tool and don't need a free plan. **Compliance rationale:** **Keila GmbH** (Seybothenreuth, Germany; HRB 8676 Amtsgericht Bayreuth; managing director Philipp Schmieder) is a 100% European-owned, bootstrapped **open-source (AGPLv3)** newsletter platform with a **publicly downloadable DPA and sub-processor list**; all customer data is stored exclusively on **EU servers (Hetzner DE + Scaleway FR)**, and the only US-linked sub-processors are **optional and transient**: Intuition Machines (hCaptcha; Friendly Captcha is the EU alternative) and AWS EMEA SARL (EU-region SMTP relay, used only with the 'Send with Keila' option), so CLOUD Act exposure is **minor**, holding the cloud score at **4/5** (5/5 requires no US sub-processors; self-hosted with bring-your-own SMTP + Friendly Captcha is effectively 5/5 / none). **Sub-processors mapped:** 4 total, 2 US-owned - Amazon Web Services EMEA SARL (Luxembourg): SMTP relay; used only if the optional "Send with Keila" managed-sending option is enabled (EU region, Luxembourg/Germany). US-owned (Amazon parent). [US-owned] - Intuition Machines, Inc. (United States): hCaptcha bot protection; optional; Friendly Captcha (EU) is the alternative. No customer data at rest. [US-owned] - Hetzner Online GmbH (Germany): Server infrastructure (application data, databases, file storage) - Scaleway SAS (France): Server infrastructure ### Klarna: https://euvetted.com/p/klarna - Website: https://www.klarna.com - Category: Payments - Country of incorporation: Sweden - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid (from €0/month) - Founded: 2005 - Last verified: 2026-05-11 Stockholm-based Klarna Bank AB (Finansinspektionen-licensed Swedish bank): BNPL + checkout giant, 150M+ consumers, US IPO pending. Klarna is the Stockholm-headquartered BNPL (buy-now-pay-later) and checkout giant operated by **Klarna Bank AB (publ)** (Sveavägen 46, 111 34 Stockholm; Org. nr 556737-0431). Founded in 2005, Klarna received a **full Swedish banking licence from Finansinspektionen** in June 2017, making it one of the few BNPL providers with bank-grade regulatory anchoring rather than just a payment-institution licence. The company partners with 200,000+ merchants across 17+ countries, serves 150M+ active consumers globally, and offers Pay-in-3 / Pay-Later / Pay-Now / Klarna One-time-card / Klarna Card products plus a Klarna Plus subscription tier. For an EU-sovereignty audit Klarna is in the awkward middle ground: legally a Swedish bank under Finansinspektionen supervision (strong EU anchor) but with a cap table that is heavily US-VC-funded (Sequoia Capital, Silver Lake, and others alongside Bestseller and other Nordic backers) and an active intention to **list on the New York Stock Exchange**: the company filed S-1 paperwork with the SEC in 2024 and has been preparing the IPO in 2025 (the first attempt was postponed due to market turmoil related to US trade-war volatility). Post-IPO ownership will be predominantly US-public-market, which under our strict-ownership stance changes the directory's tier assignment. As of the audit date the company is still privately held with the Swedish bank entity unchanged, so this listing reflects the **pre-IPO snapshot**; the entry should be re-verified after listing. Pricing for merchants is bundled into transaction fees that vary by payment method and country (BNPL ranges roughly 2.99% to 4.99% + fixed components per the Adyen comparison reference); Klarna does not charge merchant monthly fees on standard plans and offers volume-negotiated enterprise contracts. Best fit: EU retailers and marketplaces needing strong BNPL / Pay-in-3 conversion lift, especially in DACH and Nordic markets where Klarna has the strongest consumer adoption. Procurement-grade EU-only buyers concerned about post-IPO US ownership should weigh Adyen (Euronext-listed Dutch credit institution) or Worldline (Euronext-listed French acquirer) instead. **Compliance rationale:** **Klarna Bank AB (publ)** (Stockholm, Sveavägen 46; Org. nr 556737-0431) holds a full Swedish **Finansinspektionen** banking licence since 2017 and processes for 200,000+ merchants across 17+ countries with 150M+ consumers, but the cap table is heavily US-VC-funded (Sequoia, Silver Lake, Bestseller, others) and the company has been actively preparing a **US IPO on the New York Stock Exchange** (delayed earlier in 2025 due to market turmoil; relaunch in progress), meaning post-IPO ownership will be predominantly US-public-market; `ownership_signal: eu_hq_us_funded`, `cloud_act_exposure: material`, no public DPA or sub-processors list accessible at audit, pending re-verification post-listing. ### kMeet (Infomaniak): https://euvetted.com/p/kmeet - Website: https://www.infomaniak.com/en/ksuite/kmeet - Category: Video conferencing - Country of incorporation: Switzerland - Hosting country: Switzerland (Geneva) - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: free - Founded: 1994 - Certifications: ISO27001, ISO9001, ISO14001, ISO50001 - DPA: https://www.infomaniak.com/documents/privacy/DPA/Data_Processing_Agreement_(DPA).pdf - Sub-processors list: https://www.infomaniak.com/en/legal/confidentiality-policy - Last verified: 2026-06-18 Free Swiss browser-based video meetings (Infomaniak, Geneva, since 1994); no guest account, own Swiss DCs, ISO 27001, no CLOUD Act. kMeet is the video-conferencing product of **Infomaniak Group SA**, the independent Swiss technology company founded in Geneva in 1994 by **Boris Siegenthaler** and **Fabian Lucchi**, privately held, founder-led, with no venture-capital or private-equity investors on the cap table (the kdrive listing documents the same vendor in full). The proposition is simple and consumer-friendly: **browser-based video meetings with no software install and no account required for guests**: a host shares a link and participants join from any modern browser. It is available **free and standalone**, and is also bundled inside kSuite alongside Mail, kDrive, kChat and the Office suite, with integrations into Infomaniak Calendar for one-click scheduled meetings. For an EU-sovereignty audit kMeet is a clean Swiss pick. It runs on **Infomaniak's own Swiss data centres** in Geneva (no hyperscaler underneath, software developed in-house), so meeting media and metadata stay on Swiss-located infrastructure under Infomaniak's direct control. The compliance footprint mirrors the rest of the estate: **ISO/IEC 27001** (since June 2018), **ISO 9001**, **ISO 14001**, **ISO 50001**, and **B Corp (2025)**; Switzerland's Art. 45 GDPR adequacy decision keeps EU↔CH transfers SCC-free. On encryption, kMeet is built on the open-source **Jitsi Meet / WebRTC** stack: sessions are TLS-secured by default, and **opt-in end-to-end encryption** is available on up-to-date Chromium browsers and the desktop app (not currently on mobile). For always-on, cross-platform zero-access E2E, Tixeo or Wire remain stronger picks; for everyday GDPR-clean Swiss video with optional E2E, kMeet is an excellent free option. Pricing is the standout: kMeet is **free**, with no per-meeting time limit and no participant account requirement, recording available to kDrive on paid kSuite tiers. Best fit: Swiss and EU teams, freelancers, educators, and public-sector users who want a no-friction, no-install, GDPR-clean Swiss alternative to Zoom, Google Meet, and Microsoft Teams, especially those already using kSuite or Infomaniak Mail/Calendar, and anyone who wants meetings hosted on first-party Swiss infrastructure rather than a US provider's cloud. **Compliance rationale:** kMeet is the video-conferencing product of **Infomaniak Group SA** (Geneva, Switzerland; founded 1994 by Boris Siegenthaler and Fabian Lucchi; independent, privately held, founder-led, full ownership cross-reference in the kdrive listing), a **free, browser-based video tool requiring no account for guests**, run on **Infomaniak's own Swiss data centres** with ISO 27001 + ISO 9001 + ISO 14001 + ISO 50001 + B Corp 2025, GDPR-compliant under Swiss law with the EU adequacy decision keeping EU↔CH transfers SCC-free; Swiss-owned, Swiss-hosted, no CLOUD Act exposure. A strong free Swiss alternative to Zoom / Google Meet / Teams, available standalone or inside kSuite, built on open-source Jitsi Meet with **opt-in end-to-end encryption** (desktop Chromium / app; default TLS in transit). **Sub-processors mapped:** 1 total, 1 US-owned - PayPal (United States): Payment processing for paid kSuite upgrades; ancillary, off the meeting-media path [US-owned] ### Kolab Now: https://euvetted.com/p/kolab-now - Website: https://kolabnow.com - Category: Private email - Country of incorporation: Switzerland - Hosting country: Switzerland - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: paid (from €5/month) - Founded: 2013 - Last verified: 2026-05-15 Swiss open-source Kolab groupware SaaS (Apheleia IT AG, Bern; Kolab Systems since 2010, Kolab Now since 2013), board incl. FSF Europe founder Georg Greve. Kolab Now is operated by Apheleia IT AG, a Swiss software-freedom company headquartered in Bern. The legal entity was originally founded as **Kolab Systems** in Zürich in 2010 and was later renamed Apheleia IT AG. The Kolab Now consumer/SMB SaaS launched as a public beta in January 2013 and became a paid generally-available service on 1 August 2013. The product is a managed hosting of the **fully open-source Kolab groupware platform** that the same company develops and maintains, covering email, calendars, contacts, tasks, files, and notes via standard open protocols (IMAP, SMTP, CalDAV, CardDAV) so that any standard mail/calendar client can connect. The governance and pedigree are unusually strong for the privacy-email category. The Apheleia IT AG board includes **Georg Greve** (CEO; founding president of the **Free Software Foundation Europe**), CTO Jeroen van Meeuwen, **Michael Moser** (CCO; co-founder of **Adfinis**, Switzerland's leading open-source integrator), and **Philipp Koch** (co-founder of Swiss hosting company **Nine.ch**). That combination (a free-software figurehead plus a Swiss open-source integrator plus a Swiss hosting operator on the same board) is uncommon and translates into a structurally transparent posture: the product is open-source software run by people whose careers are documented free-software / open-infrastructure work. For an EU-sovereignty audit Kolab Now is a clean Swiss pick. The legal entity is Swiss-incorporated, the data is hosted in Switzerland, Switzerland holds an EU adequacy decision under Art. 45 GDPR (so EU↔CH transfers need no SCCs), and there is no US parent and no US-VC participation. The only documentation gaps are: no public DPA or sub-processors URLs and no formal ISO 27001 attestation were surfaced at audit, a documentation gap rather than a structural concern. Pricing in CHF (per the public site / blog): the standard groupware individual account is **CHF 8.99/month**, the email-only individual account is **CHF 4.55/month**, and the on-site (self-host) Apheleia "Kolab on-site Email & Groupware" subscription starts at **CHF 2.25 per user/month** for fewer than 50 users. EUR equivalents recorded approximately. Best fit: privacy-conscious EU users who want Swiss-jurisdiction email/groupware on top of a transparent, fully-open-source software stack, and any procurement-grade buyer who specifically values FSF-Europe / Adfinis / Nine.ch governance over a brand-name marketing pitch. **Compliance rationale:** Kolab Now is operated by **Apheleia IT AG** in Bern, Switzerland (formerly **Kolab Systems**, founded 2010 in Zürich; Kolab Now launched as public beta in January 2013 and as a paid GA service on 1 August 2013), built on the **fully open-source Kolab groupware** that Apheleia maintains, with a board of directors that includes **Georg Greve** (founding president of Free Software Foundation Europe), **Michael Moser** (co-founder of Adfinis, Switzerland''s leading open-source integrator) and **Philipp Koch** (co-founder of Swiss hosting company Nine.ch); exceptionally strong open-source-Swiss governance and pedigree, Swiss data centres, no US ties, no CLOUD Act exposure. Gap: Kolab Now does not publish a publicly accessible DPA (customers are directed to a DPO contact rather than a self-serve document); no public sub-processors list and no formal ISO 27001 attestation surfaced at audit. ### Koofr: https://euvetted.com/p/koofr - Website: https://koofr.eu - Category: File sharing - Country of incorporation: Slovenia - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €1/month) - Founded: 2013 - Last verified: 2026-05-14 Slovenian cloud storage (Koofr d.o.o., est. 2013), German ISO 27001 data centres, optional client-side encryption via the open-source Koofr Vault, 10 GB free. Koofr is a Slovenian cloud storage service operated by Koofr d.o.o., based at Stegne 23A in Ljubljana and a long-time member of Technology Park Ljubljana. Founded in 2013, it celebrated its tenth year of service in 2023 and is one of the cleaner small-vendor EU storage listings in this directory, fully Slovenian-incorporated, EU-owned, with no US parent, no US VC, and no PE on record. The infrastructure story is solid: Koofr stores all customer data in **ISO 27001-certified data centres in Germany**, markets itself as "GDPR compliant by default," and explicitly commits to not scanning, indexing or tracking customer files. Standard transport encryption and encrypted storage apply to all accounts. For users who want true zero-knowledge encryption, Koofr offers **Koofr Vault**, a client-side-encrypted layer where files are encrypted in the browser/app before upload, so Koofr cannot read them. Koofr Vault is fully open-source, so its encryption can be independently audited. The apps and web UI are localised into more than 20 languages, including most major EU languages (German, French, Italian, Spanish, Dutch, Polish, Portuguese, Swedish, and others) alongside Slovenian and several global languages. A distinctive feature is that Koofr can connect and unify external clouds (Dropbox, Google Drive, OneDrive, Amazon) into a single interface, which is useful for migration but should be understood by privacy-focused buyers as an opt-in bridge to non-EU services. For an EU-sovereignty audit the open question is documentation, not infrastructure. At audit no public DPA and no sub-processors list could be surfaced on koofr.eu. The underlying signal mix is otherwise strong (Slovenian entity, German ISO 27001 hosting, no file scanning, optional client-side encryption via Koofr Vault, no CLOUD Act exposure); the missing documentation is the gap to resolve on the next pass rather than a structural weakness. Pricing is freemium and unusually granular: 10 GB free forever; "Briefcase" tiers from €0.50/month (25 GB) and €1/month (100 GB); "Suitcase" tiers €4-10/month (250 GB to 1 TB); "Crate" tiers €20-35/month (2.5-5 TB) plus custom 10 TB+. Note that subscriptions are currently billed yearly and prices include 22% Slovenian VAT. Long-term subscribers can also join a Loyalty Program offering subscription discounts of up to 50%. The former free-storage referral scheme has been discontinued; there is no monetary affiliate programme. Best fit: privacy-conscious EU individuals and small teams who want German-hosted storage from an independent Slovenian vendor, especially those who will use Koofr Vault for sensitive files. **Compliance rationale:** Koofr is operated by **Koofr d.o.o.** (Stegne 23A, Ljubljana, Slovenia; founded 2013, based in Technology Park Ljubljana), a fully EU-incorporated, EU-owned company that stores all data in **ISO 27001-certified data centres in Germany**, is GDPR-compliant by default, runs no file scanning or tracking, and offers optional client-side encryption via the Koofr Vault product; EU-owned and Germany-hosted with no CLOUD Act exposure and optional zero-knowledge encryption via Koofr Vault; the key documentation gaps are no public DPA and no sub-processors list surfaced at audit. ### LC-Connect: https://euvetted.com/p/lc-connect - Website: https://leitzcloud.eu/lc-connect/ - Category: Private email - Country of incorporation: Germany - Hosting country: Germany (Frankfurt) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Certifications: ISO27001 - Last verified: 2026-06-16 German-hosted business email + calendar, contacts, tasks, notes and video meetings from LC by vBoxx GmbH; an integrated Microsoft 365 / Outlook alternative (TLS, not E2E). LC-Connect is the communication and collaboration component of the leitzcloud suite, operated by **LC by vBoxx GmbH** (Frankfurt am Main; part of the Dutch vBoxx group). It bundles business email, calendar, contacts, tasks, notes, and online video meetings into a single platform, with integration into leitzcloud storage so attachments can be sent as links or files from the user's cloud. The positioning is an integrated, German-hosted alternative to Microsoft 365 / Outlook (and Google Workspace) for businesses that want their communications and organisational data kept inside EU infrastructure. Data is hosted exclusively in **Germany** on the group's own georedundant infrastructure, with **ISO/IEC 27001 (TÜV Nord)** certification, giving an EU-owned, EU-hosted, no-CLOUD-Act-exposure posture. Encryption is TLS in transit and server-side at rest. This is business groupware, **not** a zero-access end-to-end-encrypted mailbox like Proton Mail or Tuta, which is the right distinction for readers comparing on encryption model. The vendor provided an AVV (DPA, sub-processor list, data-residency statement) on request in June 2026; it is not yet published at a public URL. Best fit: DACH SMBs and public-sector-adjacent teams that want one EU-hosted environment for mail, calendar, and meetings rather than stitching together separate tools. **Compliance rationale:** **LC-Connect** is the email-and-groupware component of the leitzcloud suite, operated by **LC by vBoxx GmbH** (Frankfurt am Main, HRB 117087; part of the Dutch vBoxx group). It combines business email, calendar, contacts, tasks, notes, and online video meetings in a single DSGVO-oriented platform hosted exclusively in **Germany** on the operator's own georedundant infrastructure, with **ISO/IEC 27001 (TÜV Nord)** certification; EU-owned, EU-hosted, no CLOUD Act exposure. Encryption is TLS in transit plus server-side at rest; it is **not** zero-access end-to-end encrypted, so it is positioned as a German-hosted Microsoft 365 / Outlook alternative for organisations that want integrated collaboration inside EU infrastructure rather than a zero-knowledge mailbox. The vendor supplied an AVV (DPA + sub-processors + data-residency) on request; no public DPA URL is the documentation gap. ### LC-Pass: https://euvetted.com/p/lc-pass - Website: https://leitzcloud.eu/lc-pass/ - Category: Password managers - Country of incorporation: Germany - Hosting country: Germany (Frankfurt) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €3.99/month) - Certifications: ISO27001 - Last verified: 2026-06-16 German-hosted business password manager from LC by vBoxx GmbH; collections, group sharing, central management, unlimited devices; an EU-hosted 1Password / LastPass alternative. LC-Pass is the credential-management component of the leitzcloud suite, operated by **LC by vBoxx GmbH** (Frankfurt am Main; part of the Dutch vBoxx group). It lets organisations securely store, manage, and share passwords, credit-card details, and other sensitive data, organised into collections with group-based sharing and per-item rights, plus central management and reporting for administrators and unlimited items, devices, and synchronisation. The positioning is a German-hosted alternative to 1Password and LastPass for teams that want their secrets held inside EU infrastructure rather than with a US-based provider. Data is stored across **two georedundant German locations** on the group's own infrastructure, ISO/TÜV-certified and DSGVO-oriented, with zero-knowledge encryption stated by the vendor, an EU-owned, EU-hosted, no-CLOUD-Act-exposure posture. The vendor provided an AVV (DPA, sub-processor list, data-residency statement) on request in June 2026; it is not yet published at a public URL, which is the remaining transparency gap. Best fit: DACH SMBs and public-sector-adjacent teams already using or considering leitzcloud who want team credential management under the same German operator and data residency. **Compliance rationale:** **LC-Pass** is the business password manager in the leitzcloud suite, operated by **LC by vBoxx GmbH** (Frankfurt am Main, HRB 117087; part of the Dutch vBoxx group). It stores and shares credentials, credit-card data, and other secrets for teams, with collections, group sharing and per-item rights, central management and reporting, and unlimited items, devices, and synchronisation. Data is stored in **two georedundant German locations** on the operator's own infrastructure, ISO/TÜV-certified and DSGVO-oriented, with zero-knowledge encryption per the vendor, EU-owned, EU-hosted, no CLOUD Act exposure. It is positioned as a German-hosted alternative to 1Password / LastPass for organisations that want credential management inside EU infrastructure. The vendor supplied an AVV (DPA + sub-processors + data-residency) on request; no public DPA URL is the documentation gap. ### leitzcloud: https://euvetted.com/p/leitzcloud - Website: https://leitzcloud.eu - Category: File sharing - Country of incorporation: Germany - Hosting country: Germany (Frankfurt) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €8.8/month) - Certifications: ISO27001 - Last verified: 2026-06-16 German-operated (LC by vBoxx GmbH, Frankfurt) Leitz-branded business cloud on its own German data centres (Frankfurt + Mannheim), ISO 27001 (TÜV Nord), AVV available on request. leitzcloud is a business cloud-storage and file-collaboration product operated by **LC by vBoxx GmbH**, a German company registered in Frankfurt am Main (HRB 117087), part of the Dutch **vBoxx** group and marketed under licence from the Leitz office-supplies brand as "leitzcloud by vBoxx". It targets SMB, mid-market, enterprise, freelance, non-profit, public-sector, and startup customers across DACH and Benelux, pairing secure storage, sync, and sharing with real-time online document editing (Word, Excel, presentations), role-based corporate-governance controls, and guest access. The product UI is available in five languages: German, English, French, Dutch, and Brazilian Portuguese. Compliance posture is enterprise-grade and German-centric. Customer data is stored **exclusively in Germany**, georedundant across two high-security data centres (**maincubes FRA01** in Frankfurt and **PFALZKOM DATACENTER Rhein-Neckar II (DCRN II)** near Mannheim) on leitzcloud's **own infrastructure** rather than rented hyperscaler capacity, powered by 100% renewable electricity. The platform holds **ISO/IEC 27001** certification (TÜV Nord) and undergoes TÜV audits; the vendor also cites ISO 9001 and ISAE 3402 controls. Combined with the German operating entity and EU-only data residency, this gives an EU-owned, EU-hosted, no-CLOUD-Act-exposure posture suited to procurement-grade and public-sector-adjacent buyers. On documentation: leitzcloud supplied an AVV on request (June 2026) covering its Data Processing Agreement, sub-processor list, and hosting / data-residency details; it is not published at a stable public URL, which is the remaining transparency gap relative to vendors that post their DPA openly. Best fit: German and DACH SMBs and public-sector adjacencies that want German-only data residency on the operator's own infrastructure plus a multilingual UI, and Dutch / Benelux businesses via the vBoxx group. leitzcloud is the file-storage component of a broader suite that also includes LC-Connect (mail / calendar / meetings) and LC-Pass (password manager). **Compliance rationale:** **leitzcloud** is operated by **LC by vBoxx GmbH** (Friedrich-Ebert-Anlage 36, 60325 Frankfurt am Main; Registergericht Frankfurt am Main HRB 117087, USt DE326895475), a German operating entity within the Dutch vBoxx group, running business file storage exclusively from **two georedundant German data centres** (maincubes FRA01 in Frankfurt and PFALZKOM DATACENTER Rhein-Neckar II near Mannheim) on its **own infrastructure**, powered by 100% renewable electricity, with **ISO/IEC 27001 (TÜV Nord)** certification and TÜV audits; EU-owned, EU-hosted in Germany, no CLOUD Act exposure. The vendor supplied an AVV (DPA + sub-processor list + data-residency statement) on request; it is not published at a public URL, which remains the one documentation gap. ### Lemonway: https://euvetted.com/p/lemonway - Website: https://www.lemonway.com - Category: Payments - Country of incorporation: France - Hosting country: France (Paris) - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid - Founded: 2007 - Last verified: 2026-05-11 Paris-based ACPR-licensed pan-European marketplace payment institution (since 2007), €12.4B 2025 volume, 400+ marketplaces. Lemonway is a Paris-headquartered marketplace-payments specialist founded in 2007 by Sébastien Burlet and Damien Guermonprez. Operating as a French **ACPR-licensed Payment Institution** (approval number 16568, since 2012) with European passporting across **29 countries**, Lemonway directly competes with Mangopay and Stripe Connect for marketplace-payment infrastructure. The company processes €12.4B annually across 1.4M open wallets and reports 400+ marketplace clients including SNCF Connect & Tech, Decathlon, Eiffage, and ArcelorMittal: a customer list that skews heavily toward large French enterprises and B2B marketplaces. Offices in Paris (HQ) and Hamburg with approximately 145 employees. For an EU-sovereignty audit Lemonway is the cleanest marketplace-payments listing alongside its competitor Mangopay. The cap table is entirely European: €50M total raised across **Breega Capital** (Paris VC, lead 2018 €35M), **Speedinvest** (Vienna VC, 2018 co-lead), and **Toscafund** (UK asset manager, €25M in 2019), with no US private-equity or venture-capital involvement on record. The ACPR licence anchors the legal jurisdiction firmly in France with all the supervisory teeth of European banking law. A 2024 partnership with **Société Générale** to support large-corporate B2B marketplaces in Europe adds an EU-bank co-distribution channel. PCI-DSS certified; 99.9%+ API availability. The 2024 acquisition of PayGreen's operations extended Lemonway from pure marketplace payments into broader e-commerce. Pricing is enterprise / volume-negotiated and marketplace-specific; no public per-transaction tier applies, and `starts_from_eur` is left null. Best fit: EU marketplaces and B2B platforms requiring ACPR-licensed multi-party payment infrastructure with full EU jurisdiction and no US PE/VC involvement in the ownership chain: particularly French and DACH marketplaces. Two transparency gaps remain: the underlying hosting provider is not publicly disclosed on accessible pages (vendor outreach can confirm whether it's OVHcloud, Scaleway, or similar French infrastructure, typical for ACPR-licensed PIs), and the DPA is embedded in the general T&Cs rather than published as a standalone document. **Compliance rationale:** Lemonway (Paris, founded 2007) is an **ACPR-licensed Payment Institution** (approval number 16568, licensed since 2012) with European passporting in 29 countries, processing €12.4B annually across 1.4M wallets for 400+ marketplaces (SNCF Connect, Decathlon, Eiffage, ArcelorMittal); the cap table is fully European (Breega FR + Speedinvest AT + Toscafund UK) and the partnership with Société Générale for B2B marketplaces adds further EU banking anchoring: `ownership_signal: eu_owned`, `cloud_act_exposure: minor`; however Lemonway does not publish a standalone DPA (data-processing obligations are embedded within the general T&Cs) meaning EU buyers cannot self-serve the DPA artefact, and the hosting provider is not publicly disclosed. ### Leviia: https://euvetted.com/p/leviia - Website: https://www.leviia.com - Category: File sharing - Country of incorporation: France - Hosting country: France (Roubaix) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €2.4/month) - Founded: 2020 - Certifications: ISO27001, HDS - Last verified: 2026-06-15 French sovereign cloud storage and Nextcloud-based drive, hosted only in France, ISO 27001 and HDS certified. Leviia is a French sovereign cloud company founded in 2020 by brothers Arnaud and William Meauzoone, headquartered in Montevrain (Seine-et-Marne). It positions itself as a French alternative to US storage giants, with data hosted exclusively in France. Two products anchor the catalogue: Leviia Drive, a Nextcloud-based collaborative file-sync-and-share suite for individuals, families and SMBs, and Storag3, an S3-compatible object-storage service for backup and archiving from €9.99/TB/month with no egress or request fees. Storage is built on French infrastructure (OVHcloud data centres at Roubaix, Gravelines and Strasbourg, plus Free Pro private servers), with triple replication across three distant data centres, daily backups, in-transit and server-side encryption, plus anti-ransomware and anti-DDoS protection. Leviia is ISO 27001 and HDS certified, the latter implying GDPR-aligned data-security and audit obligations. Ownership is French: the founders retain control and a 2022 round was led by Xavier Niel's personal holding, so there is no US parent and no material US sub-processor handling data at rest. Drive plans start at €2.40/user/month for 1 TB, with a 15-day free trial; an S3 API is available, but a public DPA and a sub-processors list were not located at the time of review. **Compliance rationale:** French-owned and France-hosted (OVHcloud + Free Pro) with ISO 27001 + HDS, but capped at 3 because no public DPA or sub-processors list was found. ### Lexware: https://euvetted.com/p/lexware - Website: https://www.lexware.de - Category: Accounting - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid - Founded: 1989 - DPA: https://datenschutz.lexware.de/ - Sub-processors list: https://office.lexware.de/app/uploads/20240326_Auftragsverarbeitung_lexoffice.pdf - Last verified: 2026-05-12 Lexware Office: cloud accounting from Haufe Group (German family-owned), DSGVO + GoBD + TÜV, 400K+ DACH customers. **Lexware** is a brand of **Haufe Group**, one of the few large German B2B-software groups still **family-owned** (the Haufe family, Freiburg) and not subject to US-PE rollup pressure. The cloud product **Lexware Office** covers accounting, invoicing, payroll, and tax preparation for German freelancers and SMBs (Gründer, Unternehmer, Freiberufler), with 400,000+ customers across DACH. Data is hosted in Germany ("Made in Germany"), the product is **DSGVO-konform, GoBD-konform, TÜV-tested**, and pricing is promotional-led (50% Rabatt für 3 Monate at time of research). UI is German-only. For procurement buyers prioritising "no US ownership chain at all" this is one of the cleanest accounting picks in the catalogue. **Compliance rationale:** **Lexware** (a brand of **Haufe Group**, family-owned German publishing + B2B-software group, Freiburg) is German-hosted, DSGVO + GoBD-konform, **TÜV-tested**, 400,000+ DACH customers, and crucially **not US-PE-controlled**: Haufe is one of the few large remaining German family-owned software groups; EU-owned, EU-hosted, minor CLOUD Act exposure, with a public DPA (datenschutz.lexware.de); no ISO 27001 or C5 attestation surfaced on the public marketing site. ### LightOn: https://euvetted.com/p/lighton - Website: https://www.lighton.ai - Category: Sovereign AI - Country of incorporation: France - Hosting country: France (Paris) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2016 - Certifications: SOC2 - Last verified: 2026-05-11 Paris-based enterprise GenAI (Paradigm platform), Europe's first publicly-listed GenAI company on Euronext Growth Paris, on-premise-first. LightOn is a Paris-headquartered enterprise generative-AI company founded in 2016 by Igor Carron, Laurent Daudet, Florent Krzakala, and Sylvain Gigan, all French engineers and academics, with the original ambition "to push the boundaries of extreme-scale AI." The current product surface is centred on **Paradigm**, an on-premise-first generative-AI platform for enterprise business units that runs entirely within the customer's security perimeter, with hybrid (sovereign European cloud GPU) and managed-SaaS deployment options. Historical research output includes more than 12 large language models, including 100+ billion parameter open-source foundation models and the flagship Alfred line. For an EU-sovereignty audit LightOn is a structurally clean listing. In **November 2024 LightOn became Europe's first publicly-traded GenAI company**, listing on Euronext Growth Paris at €10.35 per share with a €62M market cap on day one and raising €11.9M. The founder team remains active and there is no US-PE or US-VC controlling stake; the company is structurally French-owned and EU-public-market accountable. The product architecture itself eliminates the standard EU-vendor sovereignty trade-off: with on-premise as the default deployment model, customer data never leaves the buyer's firewall, and even the hybrid option uses **sovereign European cloud GPUs** rather than US hyperscalers. GDPR-compliant and SOC 2 Type 1 certified. Customer references read like a who's-who of French regulated / public-sector / defence procurement: **Safran**, **Groupama**, **Région Île-de-France**, **Direction Générale des Finances Publiques**, **CNES** (French space agency), **Verlingue**, **French Space Command**, plus indirect-channel partnerships with **Orange Business** and **Hewlett Packard Enterprise**. LightOn targets positive EBITDA by 2026 per its IPO prospectus. Best fit: French and EU regulated buyers (defence, public sector, finance, healthcare) needing on-premise sovereign GenAI without any US-cloud dependency; enterprise teams replacing OpenAI / Anthropic / Cohere with a Paradigm-class platform that runs inside the firewall. Pricing is enterprise-only via sales engagement. **Compliance rationale:** LightOn (Paris, founded 2016 by Igor Carron, Laurent Daudet, Florent Krzakala, Sylvain Gigan, all French engineers and academics) is **Europe's first publicly-traded GenAI company**, listed on Euronext Growth Paris since November 2024 (IPO €10.35/share, €62M market cap day 1). Founder-team still active, no US-VC majority, no PE concentration. The Paradigm platform is sold **on-premise-first** so customer data never leaves the buyer's firewall, with hybrid (sovereign European cloud GPU) and SaaS as secondary options; GDPR + SOC 2 Type 1 certified; flagship customers include Safran, Groupama, Région Île-de-France, Direction Générale des Finances Publiques, CNES, and French Space Command. EU-owned, EU-hosted, no CLOUD Act exposure, but LightOn does not publish a publicly accessible DPA (one exists per the privacy policy but is available on request only, via rgpd_rssi@); no public sub-processors list found at audit. ### Lime CRM: https://euvetted.com/p/lime-crm - Website: https://www.lime-technologies.com - Category: CRM - Country of incorporation: Sweden - Hosting country: Sweden - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid - Founded: 1990 - DPA: https://www.lime-technologies.com/en/legal/terms-conditions/dpa/ - Sub-processors list: https://www.lime-technologies.com/en/legal/subprocessors/ - Last verified: 2026-05-11 Swedish public-listed Nordic + DACH CRM (Lime Technologies, since 1990), 1M+ users, vertical-tailored, agnostic to single-vendor lock-in. Lime CRM is the flagship product of **Lime Technologies Sweden AB** (Org. nr 556397-0465), a publicly-listed Swedish enterprise software company that traces back to 1990 (originally as a Lund University spin-off) and now operates across Sweden, Denmark, Germany, Finland, Netherlands, and Norway with more than 1 million users. The product portfolio is unusually broad for a Nordic CRM vendor: **Lime CRM** (enterprise CRM tailored by vertical), **Lime Go** (plug-and-play B2B sales CRM), **Lime Connect** (customer messaging + AI), and **Lime Intenz** (change-management services). Industry verticals include real estate, manufacturing, energy, retail / wholesale, NGO, services, and consultancy. For an EU-sovereignty audit the key positive signals are strong: the operating entity is publicly listed on Nasdaq Stockholm (per the investor-relations page at investors.lime-technologies.com), Swedish-incorporated, and no controlling US shareholder is on record; the cap table is a Swedish public free-float with institutional investors and founder/insider holdings. Operations are confined to Nordic and DACH/Benelux markets with explicit EU jurisdiction. What remains unverified at audit: the Trust Center at trust.lime-technologies.com exists but specific ISO 27001 / SOC 2 certifications were not confirmed, and the underlying hosting provider for Lime CRM cloud was not publicly named; vendor outreach would fill those gaps (CLOUD Act flag set to minor as a result). Pricing is enterprise / volume-negotiated; trial signups offered for both Lime CRM and Lime Go. Best fit: Nordic and DACH SMBs and mid-market companies in real estate, manufacturing, energy, retail, NGO, or consulting verticals that want a publicly-listed Swedish vendor with deep industry templates and multi-product breadth across CRM + customer messaging + change management. Procurement-grade EU-only buyers needing verified Swedish hosting + ISO 27001 should request the trust-center documentation directly. **Compliance rationale:** **Lime Technologies Sweden AB** (Org. nr 556397-0465) is a publicly-listed Swedish enterprise software company operating Lime CRM, Lime Go, Lime Connect, and Lime Intenz with **1M+ users across 6 European markets (SE, DK, DE, FI, NL, NO)** and a multi-vertical industry-tailored product approach; Swedish public-market ownership with no controlling US shareholder, EU-only operations: EU-owned (Nasdaq Stockholm listed, no controlling US shareholder), EU-operated; hosting region and specific certifications not captured at audit (Trust Center exists at trust.lime-technologies.com); CLOUD Act flag set to minor pending hosting provider disclosure. ### LimeSurvey: https://euvetted.com/p/limesurvey - Website: https://www.limesurvey.org - Category: Forms & surveys - Country of incorporation: Germany - Hosting country: Germany (Hamburg) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium - Founded: 2003 - Last verified: 2026-05-18 German GPL-licensed open-source survey platform (LimeSurvey GmbH Hamburg, project since 2003), self-host first. LimeSurvey is one of the longest-running open-source survey platforms in Europe. The project was started by **Carsten Schmitz** in 2003, and the commercial entity **LimeSurvey GmbH** (Hamburg, Germany) was founded in August 2015 to better coordinate development and provide commercial services around the open-source codebase. Schmitz remains Founder + CTO. The platform is licensed under **GPL v2 (or later)** with source on GitHub, runs on PHP with MySQL / PostgreSQL / SQLite / MSSQL backends, and is widely deployed in EU universities, public administrations, and research institutions. The LimeSurvey Cloud managed tier is the commercial alternative to self-host. **Compliance rationale:** **LimeSurvey GmbH** (Hamburg, Germany; founded August 2015, but the open-source LimeSurvey project itself dates to 2003 by **Carsten Schmitz** who remains Founder + CTO) is one of the longest-running open-source survey platforms in Europe, **GPL-2.0+** licensed with source on GitHub, deployable on customer infrastructure (PHP + MySQL/PostgreSQL/SQLite/MSSQL) for full sovereignty; also offered as managed LimeSurvey Cloud, EU-owned and Hamburg-hosted with no CLOUD Act exposure, but the DPA for the managed cloud tier is not publicly accessible without an account; the self-host path on EU infrastructure removes this gap entirely. ### LiveChat (Text): https://euvetted.com/p/livechat - Website: https://www.livechat.com - Category: Helpdesk - Country of incorporation: Poland - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid - Founded: 2002 - DPA: https://www.livechat.com/legal/data-processing-addendum/ - Sub-processors list: https://www.livechat.com/help/livechat-list-of-subprocessors/ - Last verified: 2026-05-11 Wrocław-based Polish customer-service suite (Text S.A., WSE-listed since 2014), 28k+ customers in 150+ countries; LiveChat + ChatBot + HelpDesk. LiveChat is the original product of **Text S.A.**, a Polish customer-service software company headquartered in **Wrocław, Poland** since its founding in **2002**, now publicly listed on the **Warsaw Stock Exchange** under the ticker **TXT** (originally listed as LVC in April 2014; rebranded from LiveChat Software S.A. to Text S.A. in September 2023). The company has built an unusually long-running EU customer-service brand: 28,000+ paid customers across 150+ countries, including reference deployments at **Adobe, AirAsia, Best Buy, Better Business Bureau, ING, Huawei, Orange, and PayPal**. The current product surface is **LiveChat** (the original live-chat platform), **ChatBot** (no-code chatbot builder), **HelpDesk** (ticketing and support workflow), and **Copilot** (AI assistant layered across the suite). For an EU-sovereignty audit the listing is structurally clean at the ownership layer: **Polish public-listed company on WSE**, widely-held stock, **no US-PE or US-VC controlling interest** on the cap table, EU-rooted founder culture, 20+-year operating history through multiple AI-cycle inflexions. A public DPA is available at livechat.com/legal/data-processing-addendum/. The company also operates a US office in Boston, Massachusetts to serve its substantial North American customer base. This is a sales-and-operations presence rather than a controlling-entity restructure, so the ownership tier remains `eu_owned`. The main procurement caveat: the broader Text platform's AI features (Copilot, ChatBot) and the US-heavy enterprise customer base imply a multi-region hosting architecture with at least US-region availability. EU customers should explicitly request EU-region placement and may need to opt out of AI features that route through US LLM APIs. Pricing is enterprise / per-agent / per-volume; specific entry-tier EUR figures were not captured at audit. Best fit: Polish, EU, and US-EU mid-market enterprises needing a long-running publicly-accountable customer-service vendor; e-commerce + financial services + telecoms customers (the existing reference base); buyers who specifically want the Warsaw-Stock-Exchange counterparty as a sovereignty signal. Procurement-grade EU-only buyers requiring zero US-cloud should look at Crisp (FR, EU-owned and EU-hosted) or Userlike (DE, Swedish-public-listed parent) instead. **Compliance rationale:** LiveChat is now operated by **Text S.A.** (Wrocław, Poland; founded 2002 as LiveChat Software, rebranded to Text S.A. in September 2023), **publicly listed on the Warsaw Stock Exchange since April 2014** (WSE ticker TXT). Widely-held public stock with no US-PE or US-VC controlling interest on record; 28,000+ paid customers across 150+ countries including Adobe, ING, Orange, PayPal; broader Text platform includes LiveChat, ChatBot, HelpDesk, and Copilot AI. EU-owned via the Polish WSE-listed parent with no US controlling interest. A public DPA is available (livechat.com/legal/data-processing-addendum/). Gaps: no public sub-processors list captured at audit; the US Boston sales office and AI feature stack imply minor US-cloud dependency at the product layer; EU customers should explicitly confirm EU-region data placement. ### Lucca: https://euvetted.com/p/lucca - Website: https://www.lucca.fr - Category: HR & people - Country of incorporation: France - Hosting country: France - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2002 - Certifications: ISO27001, SECNUMCLOUD - Sub-processors list: https://www.lucca.fr/rgpd/ - Last verified: 2026-05-12 French sovereign-cloud HR platform (Nantes / Paris, est. 2002); SecNumCloud + ISO 27001; 1M+ users incl. AXA, Deezer. **Lucca** (Nantes and Paris, France, founded 2002) is a 20-year-old French HR-tech vendor with arguably the cleanest sovereignty profile in this catalogue's HR set: **SecNumCloud** (ANSSI France's sovereign-cloud certification, required for French government and OIV/OSE contracts) + **ISO 27001** + **Qualiopi**. The modular product covers payroll (Pagga), time and absences (Timmi), talent and performance (Poplee), compensation, and expenses (Cleemy). 1M+ users including enterprise clients like AXA, Deezer, and Pernod Ricard. **No US VC ownership** identified; mostly profitable-and-bootstrapped trajectory. For French and European procurement audiences with a strict CLOUD-Act preference, this is a flagship pick. **Compliance rationale:** **Lucca** (Nantes / Paris FR, founded 2002, 20+ years operational) is one of the very few procurement-grade HR platforms in this catalogue holding **SecNumCloud (ANSSI France) certification** alongside ISO 27001 and Qualiopi; 1M+ users including Deezer / AXA / Pernod Ricard; **no US-VC ownership** identified; EU-owned and FR-hosted with no CLOUD Act exposure, the cleanest French sovereign-cloud story in the HR set. ### luckycloud: https://euvetted.com/p/luckycloud - Website: https://luckycloud.de - Category: File sharing - Country of incorporation: Germany - Hosting country: Germany (Berlin) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2015 - Certifications: ISO27001 - DPA: https://luckycloud.de/de/rechtliches/dokumente/download/dpa/current/status - Last verified: 2026-05-11 Berlin-based German zero-knowledge cloud (luckycloud GmbH, 2015), own DCs in Berlin/Nuremberg/Frankfurt, ISO 27001 BSI. luckycloud is a Berlin-based zero-knowledge encrypted cloud-storage product operated by **luckycloud GmbH** at Solmsstraße 26, registered with the Charlottenburg Local Court under HRB 169276 B (VAT DE301776461; managing director Luc Mader). The product traces back to 2007 when Mader built an online platform at his Berlin university to share study materials with friends; the commercial company was founded in 2015 and serves SMBs and consumers across DACH. The product line covers luckycloud One (consumer), Teams, Business, and Enterprise tiers with client-side encryption as a default feature across all plans. For an EU-sovereignty audit luckycloud is one of the cleanest pure-German listings in the directory. The infrastructure is **fully owned and operated** by the company itself (luckycloud GmbH creates, manages, and maintains the IT stack independently) across three ISO 27001 / BSI-certified German data centres in **Berlin, Nuremberg, and Frankfurt**. The product is built on open-source software (the file-sync stack uses luckycloud's own in-house Sync Client which replaced an earlier Seafile-based stack; OnlyOffice powers document editing) and follows a strict **zero-knowledge principle with triple-encryption layering**: vendor cannot access plaintext customer data. Trust signals include TÜV Süd certification, NETZSIEGER recognition, "Deep Tech" certification, eco Award 2019, and Alliance for Cyber Security membership. Founder-led, no VC/PE investors. Pricing was not directly captured at audit (the /en/pricing path returned 404; main pricing surface is on /pricing or /preise on the German site); the model is paid SMB-and-up with no consumer freemium tier observable. Best fit: German and DACH SMBs and consumers wanting a fully-German alternative to Dropbox / OneDrive / Google Drive with own-DC infrastructure, zero-knowledge encryption, and a small founder-led counterparty. Together with Filen, Cryptee, Internxt, Proton Drive, Tresorit, Nextcloud (self-host), and kDrive, luckycloud is part of the directory's top-tier EU-owned file-sharing shortlist. **Compliance rationale:** luckycloud GmbH (Berlin, Solmsstr. 26; HRB 169276 B Charlottenburg; founded 2015 by Luc Mader who built the precursor in 2007 at a Berlin university) operates **its own server infrastructure** across three ISO 27001 / BSI-certified German data centres (Berlin, Nuremberg, Frankfurt), with **zero-knowledge encryption + triple-encryption layering + open-source code**; no VC/PE investors, founder-led, multiple TÜV Süd / eco / Alliance for Cyber Security trust signals; EU-owned, own German data centres, ISO 27001 + BSI, public DPA, zero-knowledge E2E encryption, no CLOUD Act exposure. ### Mailbox.org: https://euvetted.com/p/mailbox-org - Website: https://mailbox.org - Category: Private email - Country of incorporation: Germany - Hosting country: Germany (Berlin) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €1/month) - Founded: 2014 - Certifications: ISO27001, C5 - Sub-processors list: https://mailbox.org/de/datenschutz/ - Last verified: 2026-05-12 Berlin-based private email + drive + meet + office bundle (Heinlein Support GmbH); ISO 27001 + BSI C5, €1/mo entry. **Mailbox.org** (operated by **Heinlein Support GmbH**, Berlin) is a procurement-grade German private-email-plus-productivity suite (**Mail + Drive + Meet + Office** in a single bundled offering), entry tier from **€1/mo** (Light), business plans from €1/user/mo. The compliance posture is rare: **ISO/IEC 27001:2022 + BSI C5 Type 1** (Bundesamt für Sicherheit in der Informationstechnik Type-1 Cloud Computing Compliance certification, the BSI's standard for trusted cloud services in Germany), plus full **PGP** support for end-to-end-encrypted mail. Servers in own German data centres on 100% renewable energy. Slogan "Ihre Daten. Ihre Kontrolle." For DACH compliance buyers this is one of the cleanest picks across the entire directory. **Compliance rationale:** **Mailbox.org** is operated by **Heinlein Support GmbH** (Berlin, founded 2014) on **own German data centres**, holds **ISO/IEC 27001:2022 + BSI C5 Type 1** (rare full BSI-standard certification for an SMB email vendor), GDPR-compliant, PGP-supported, 100% renewable energy; entry tier **€1/mo**; EU-owned, EU-hosted, with no CLOUD Act exposure. ### Maileon: https://euvetted.com/p/maileon - Website: https://www.maileon.com - Category: Email marketing - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2002 - Certifications: ISO27001 - DPA: https://learn.zohopublic.eu/external/manual/data-privacy-templates/article/data-processing-agreement-pursuant-to-art-28-gdpr?p=b8207eab5b198d87395456bb3d46939ce7d6bd5d760affacf1338e7d55a8efaca8bf0fc3e06c12b7d6822c99888e60b7 - Last verified: 2026-05-18 German enterprise email marketing (XQueue GmbH, Offenbach, 2002), ISO 27001, EU data centres, 3k+ customers, 10 offices worldwide. Maileon is the enterprise email-marketing and marketing-automation platform operated by **XQueue GmbH**, a German company headquartered in **Offenbach am Main** with additional offices in **Freiburg im Breisgau**. Founded in 2002, XQueue has more than 20 years of operating history and serves 3,000+ corporate customers across 10 international offices, with multi-channel capability covering email, SMS, and triggered transactional flows. The platform targets enterprise B2B customers with high-deliverability requirements and explicit DACH / EU public-administration adjacency. For an EU-sovereignty audit Maileon presents a strong signal profile. The operating entity is a German GmbH; customer email-data is stored in EU (German) data centres only; there is no CLOUD Act exposure. The company holds **ISO/IEC 27001** certification plus GDPR alignment, ECO Award membership, ISPA (Internet Service Providers Austria) membership, and CSA (Certified Senders Alliance) trust-seal certification, the standard mid-tier German Mittelstand compliance stack for ESP procurement. Founder-led / privately-controlled with no external VC/PE involvement on record. Pricing is enterprise / volume-negotiated; specific EUR tiers were not directly captured at audit. Best fit: enterprise B2B marketers in DACH and broader EU markets that want a German-rooted Mailchimp / SendGrid alternative with ISO 27001 + CSA evidence and a 20-year vendor track record. Procurement-grade buyers preferring SMB pricing tiers should look at MailerLite, CleverReach, or rapidmail in the same category. **Compliance rationale:** Maileon is operated by **XQueue GmbH** (Offenbach am Main, Germany; founded 2002, additional office in Freiburg), an enterprise-focused email-marketing and marketing-automation platform with **ISO/IEC 27001** certification, GDPR / SSL / ECO / ISPA / CSA membership badges, **EU (German) data centres**, 3,000+ customers, 10 offices worldwide and over 20 years of operating history: EU-owned, EU-hosted (Germany), ISO 27001-certified, no CLOUD Act exposure. ### MailerLite: https://euvetted.com/p/mailerlite - Website: https://www.mailerlite.com - Category: Email marketing - Country of incorporation: Lithuania - Hosting country: Netherlands - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: freemium (from €9/month) - Founded: 2010 - Certifications: ISO27001 - DPA: https://www.mailerlite.com/legal/data-processing-agreement - Sub-processors list: https://www.mailerlite.com/legal/data-processing-agreement - Last verified: 2026-05-18 Lithuanian-founded email marketing platform with EU data storage, a generous free tier, and broad automation plus transactional features. MailerLite is a Vilnius-founded email marketing and automation platform offering newsletters, automation flows, landing pages, signup forms, and transactional email through its sister product MailerSend. Founded in 2010 by Ignas Rubezius, the company was acquired by Polish e-mail communications group Vercom in April 2022 for around €84M, and public reporting indicates a further 2025 transition under Polish-listed cyber_Folks; both moves keep MailerLite under EU ownership. The legal structure splits by region: MailerLite Limited (Dublin, Ireland) is the data controller for EEA, UK, and Swiss customers, while MailerLite, Inc. (San Francisco, California) handles other regions. Primary subscriber storage runs from an EU data center carrying ISO 27001 certification (Bureau Veritas), but the US legal entity together with several US sub-processors (Intercom for support, Stripe/Braintree/PayPal for payments, OpenAI and Google Vertex AI for AI-assistant features, Zoom for events, Oracle NetSuite for accounting) introduce material CLOUD Act exposure, especially for customers handled by the US Inc. MailerLite competes on price and UX against Mailchimp: a free tier covers up to 500 subscribers and 12,000 monthly emails, paid plans start at roughly €9/month, and a long-running 30%-recurring affiliate program with a 45-day cookie remains a strong distribution lever. Marketing-site internationalization covers EN, ES, and PL; in-product UI localization in those languages was not directly verified during this audit. Best fit: SMBs and creators who want a credible EU primary-hosting story and low-cost entry, and can accept a US legal entity for non-EEA accounts plus US sub-processors for support and AI features. Procurement teams with strict no-CLOUD-Act requirements should pair this with legal review or look at higher-scoring alternatives in the category. **Compliance rationale:** EU-owned (Polish parent cyber_Folks via Vercom) with EU primary email storage and ISO 27001, but a US legal entity (MailerLite Inc., San Francisco) for non-EEA customers plus multiple US sub-processors (Intercom, Stripe, OpenAI, Google Vertex AI, Zoom, NetSuite) and no public DPA or dedicated sub-processors page: material CLOUD Act exposure, no public sub-processors disclosure. **Sub-processors mapped:** 2 total, 1 US-owned - Google Ireland Limited (Ireland): Data center operations (DE for Legacy MailerLite, NL for new MailerLite) [US-owned] - Vercom S.A. (Poland): Shareholder; managing and improving MailerLite services ### Mailfence: https://euvetted.com/p/mailfence - Website: https://mailfence.com - Category: Private email - Country of incorporation: Belgium - Hosting country: Belgium (Brussels) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €3/month) - Founded: 1999 - DPA: https://mailfence.com/c/mailfence/website/GDPR_Data_Processing_Agreement.docx - Sub-processors list: https://mailfence.com/en/privacy.jsp - Last verified: 2026-05-12 Belgian secure email + calendar + docs (ContactOffice, est. 1999); browser-side PGP, donates 15% to EFF + EDRi. **Mailfence** (operated by **ContactOffice Group**, Belgium, founded 1999) is one of the longest-running European secure-email services: **OpenPGP end-to-end encryption** done in-browser, integrated calendar, docs, contact groups, **no ads, no trackers, no government backdoors**, EU jurisdiction (Belgium). Pricing tiers from Free (500MB) to Ultra ($225/mo billed monthly for 60GB). Notable ethical commitment: **15% of Ultra-tier revenue donated to the Electronic Frontier Foundation and European Digital Rights**. Available in 12 languages; iOS, Android, and PWA apps. No formal ISO 27001 attestation was surfaced on the public site. **Compliance rationale:** **Mailfence** is operated by **ContactOffice Group** (Belgium, founded 1999): 25+ years operational, European data centres, **OpenPGP end-to-end encryption** in-browser, no ads / no trackers / no backdoors, donates **15% of Ultra-tier revenue to EFF + EDRi**; under Belgian / EU jurisdiction with strong privacy laws, EU-owned, no CLOUD Act exposure; no formal ISO 27001 attestation surfaced on the public site, and a public DPA URL is available. ### Mailjet: https://euvetted.com/p/mailjet - Website: https://www.mailjet.com - Category: Email marketing - Country of incorporation: France - Hosting country: France - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: freemium (from €8/month) - Founded: 2010 - Certifications: ISO27001, SOC2 - DPA: https://sinch.com/legal/terms-and-conditions/other-sinch-terms-conditions/data-protection-agreement/ - Sub-processors list: https://sinch.com/legal/data-protection-agreement-sub-processors/ - Last verified: 2026-05-10 Paris-founded transactional and marketing email API, ISO 27001-certified, EU-only data centres, owned by Sweden-listed Sinch. Mailjet is a Paris-founded email-delivery platform offering transactional and marketing email APIs, drag-and-drop newsletter design, segmentation, and a real-time collaboration editor. Founded in 2010 and acquired by Pathwire in 2019, Mailjet has been part of Sinch AB (publicly listed on Nasdaq Stockholm, Sweden) since 2021 and is now branded "Sinch Mailjet", though it retains its Paris team and product identity. Mailjet was the first email service provider to obtain ISO 27001 certification (BSI, 2017) and AFAQ certification from AFNOR for GDPR adherence. The trust page states that customer data is stored in secure data centres "exclusively within the European Union" with daily encrypted backups in geographically separated EU environments. Additional certifications/attestations referenced include SOC 2, PCI DSS, CSA STAR Level 1, HIPAA, and Certified Senders Alliance (CSA member since 2014). The Data Processing Agreement is published publicly on the parent Sinch domain and uses Standard Contractual Clauses for transatlantic transfers; the dedicated sub-processors page is also hosted on Sinch but did not resolve at audit time, leaving a verification gap. Pricing starts at US$9/month (Starter, 8,000 emails), roughly €8, with a free tier of 6,000 emails/month capped at 200/day. The affiliate program pays a relatively modest 15% per lead with a 30-day cookie, paid monthly via PayPal or bank transfer. Best fit: developer teams and marketers wanting a credible French email-API with ISO 27001 and an EU-only data-residency story, who can accept a Swedish-listed parent with global operations. Procurement decisions in regulated industries should confirm the underlying cloud provider and sub-processors list before signing. **Compliance rationale:** French SAS with EU-only data-centre claim, ISO 27001 (BSI), public DPA via parent Sinch (Sweden) and SCC-based transfers; the Sinch sub-processor list (verified 2026-06) shows Mailjet hosts on Google Cloud (a US-owned hyperscaler) alongside Atlassian, Zendesk, Stripe and Mailgun; a US-owned hyperscaler as the core host raises CLOUD Act exposure to material despite the EU data region and a public DPA. **Sub-processors mapped:** 6 total, 5 US-owned - Atlassian Corporation (United States): Support ticket tracking, incident management [US-owned] - Google Cloud France SARL (France): Cloud datacenters (hosting/infrastructure) [US-owned] - Mailgun Technologies, Inc. (United States): Intra-Sinch email support / managed services [US-owned] - Stripe Payments Europe, Limited (Ireland): Billing and payment systems [US-owned] - Zendesk, Inc. (United States): Customer support platform [US-owned] - Mailjet SAS (France): Customer support, deployment, managed services (Sinch group) ### Mailo: https://euvetted.com/p/mailo - Website: https://www.mailo.com - Category: Private email - Country of incorporation: France - Hosting country: France - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €1/month) - Founded: 1998 - Last verified: 2026-05-15 French family-owned email since 1998 (Mail Object; founders Voyat & Lenoir, reacquired from Lagardère 2007), French-hosted, Free tier €0 + Premium from €1/mo. Mailo is one of the older independent European email services, with an unusual 25-year corporate history. It was launched in **1998 as Francemail** by Pascal Voyat and Philippe Lenoir, renamed **FranceMel in 1999**, then acquired by the French media conglomerate **Lagardère Group** and rebranded **NetCourrier**. Crucially, in **2007 the founders reacquired the service from Lagardère** through their company **Mail Object**, returning it to independent French family ownership. The service was renamed **Net-C in 2012** and finally **Mailo in 2019**, and across all those rebrands the underlying vendor and family-ownership structure has remained unchanged. For an EU-sovereignty audit Mailo's positioning is appealingly simple: a "100% European" email service with **secure servers physically located in France**, operated by a small French family-owned company under French and EU law. It is a member of the **PrivacyTech** ecosystem and the **French Tech** initiative, soft positive signals that don't replace formal certifications but indicate participation in the French privacy-and-startup community. The offering is feature-rich for a small vendor: web mail, calendar, contacts, file sharing, IMAP/POP/SMTP, mobile apps, anti-spam, anti-virus, custom domains on paid tiers, and unlimited disposable aliases. The company has been operating continuously for over 25 years, longer than nearly every competitor in the privacy-email space. The signal gaps reflect what is missing rather than what is wrong: no formal ISO 27001 / SOC 2 attestation was surfaced, no public DPA or sub-processors URLs were captured at audit, and the encryption architecture (specifically whether messages are stored at rest with server-managed keys or with any client-side encryption layer) was not detailed on the homepage or who-are-we page. None of those gaps suggest poor practice, but a procurement-grade buyer will need to request those documents. Pricing is freemium and one of the most affordable in the category: **Mailo Free** at €0/month; **Mailo Premium from €1/month** (the cheapest paid tier in the directory's private-email category); **Premium+** with capacity expandable to 500 GB. Best fit: French and Francophone-EU users who want a long-established, family-owned French email service at the lowest possible price, and who don't need formal ISO 27001 documentation or in-house PGP key management. **Compliance rationale:** Mailo is operated by **Mail Object**, a small French family-owned company run by founders **Pascal Voyat and Philippe Lenoir**. The service has unusually deep heritage: launched as **Francemail in 1998**, renamed FranceMel and acquired by Lagardère Group, rebranded NetCourrier, **reacquired by its founders in 2007** through Mail Object, renamed Net-C in 2012, and finally Mailo in 2019; a '**100% European**' email service hosted on **secure servers in France**, free tier exists, member of PrivacyTech and French Tech ecosystems; EU-owned, EU-hosted, no CLOUD Act exposure. Gap: Mailo publishes no DPA and no public sub-processors list (only standard privacy terms and T&C are available on the public site); no formal ISO 27001 attestation. ### Make: https://euvetted.com/p/make-newsletter - Website: https://make.as - Category: Email marketing - Country of incorporation: Norway - Hosting country: Norway - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: paid (from €73/month) - Founded: 2009 - Sub-processors list: https://make.as/personvern - Last verified: 2026-06-12 Oslo-based Norwegian email and SMS marketing platform storing customer data on Norwegian servers, with an official 'Made in Norway' label. Make is a Norwegian email-marketing, SMS-marketing, and automation platform operated by Make AS (Sandakerveien 116, 0484 Oslo; org. NO 993555002), founded on 4 February 2009 and a newsletter partner to Norwegian businesses ever since. It serves around 1,700 private and public-sector customers (including names like NRK) and positions its Norwegian identity as its core differentiator: personal Norwegian-language support, local presence, and the official "Made in Norway" label. Note this is the Norwegian ESP Make AS, not the US automation tool make.com (Celonis). For an EU/EEA-sovereignty audit Make presents a clean nominal hosting story: the company states that all customer personal data is stored and transmitted from Norwegian servers and IP addresses, fully within EEA jurisdiction where GDPR applies directly. The named sub-processors in the privacy statement are a mix: Pipedrive (EE) for CRM, 24Seven Office (NO) for accounting, Posten/Bring (NO) for digital signing, StatusCake (UK) for monitoring, and two US-owned tools, Intercom (support/chat) and Google Workspace (internal document management). These US tools are scoped to support and internal operations rather than to subscriber data at rest, which keeps CLOUD Act exposure in the minor tier. The weak points for procurement-grade buyers are transparency: there is no publicly downloadable DPA (databehandleravtale) and no publicly attested security certification such as ISO 27001; the "Made in Norway" mark is a country-of-origin trust label, not an information-security audit. Pricing is in NOK and aimed at the Norwegian SMB/enterprise market: Standard at 850 NOK/month (~€73, 1,000 contacts, 4,000 emails, 3 users, one training hour), Pro at 1,150 NOK/month (~€98, 10,000 emails, 10 users, unlimited segmentation/automation), and a custom Enterprise tier; SMS is billed separately, plans are billed annually in advance, and there is a 30-day demo but no permanent free tier. Distribution is via a reseller partner programme rather than a public affiliate scheme with a tracking cookie. Best fit: Norwegian and EEA buyers who want a Norway-resident newsletter and SMS tool with Norwegian-language support and an unambiguous "data stays in Norway" answer, and who don't require a self-serve DPA, ISO 27001 evidence, or English product localization. Buyers needing a public DPA or ISO 27001 should look at rapidmail, CleverReach, or Maileon in this category. **Compliance rationale:** Norwegian AS (Make AS, Oslo; org NO 993555002, founded 2009) that stores customer subscriber and email data on Norwegian servers and markets an official 'Made in Norway' label. Norway is in the EEA so GDPR applies directly and there is no EU↔NO transfer problem. But the privacy policy names US-owned operational sub-processors (Intercom for support/chat, Google Workspace for internal documents) alongside EU ones (Pipedrive EE, 24Seven Office NO, Posten Bring NO, StatusCake UK); these touch support and internal ops rather than subscriber data at rest, holding CLOUD Act exposure to the minor tier. No public Data Processing Agreement (provided only inside the contracting flow) and no public security certification (ISO 27001 etc.) cap the editorial score at 3/5 despite a clean Norwegian-hosting and Norwegian-ownership story. ### Mangopay: https://euvetted.com/p/mangopay - Website: https://mangopay.com - Category: Payments - Country of incorporation: Luxembourg - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2013 - Last verified: 2026-05-11 Luxembourg CSSF + UK FCA-EMI-licensed marketplace payments (2013), 2,500+ platforms (Vinted, Malt, Wallapop), Advent International-owned since 2022. Mangopay is a Luxembourg-headquartered marketplace-payments specialist operated by **Mangopay S.A.** and founded in 2013. The product is purpose-built for two-sided marketplaces and platforms: multi-party wallet infrastructure, multi-currency accounts, FX, KYC / KYB across 16+ countries, payouts to merchants, and the regulated end-to-end flow that Stripe Connect and Braintree compete on. The customer base includes Vinted (EU's largest second-hand fashion marketplace), Malt (freelance marketplace), Wallapop (Spanish C2C), Debenhams, and Chrono24; 2,500+ platforms in total, processing €68B across 207M wallets to date. Regulatory posture is strong on paper: **Mangopay S.A. holds a CSSF (Commission de Surveillance du Secteur Financier) Electronic Money Institution licence in Luxembourg** for EU/EEA passporting, plus a UK Electronic Money Institution licence from the **FCA** for post-Brexit UK operations. Luxembourg's CSSF-EMI framework is among the most demanding in Europe and is widely used by Fortune-500-grade fintech. Where the EU-sovereignty audit complicates things is ownership: in 2015 Mangopay (alongside Leetchi.com, the consumer-side sister product) was acquired by **Crédit Mutuel Arkéa**, the French cooperative bank, a clean EU-owned chapter. In April 2022 Crédit Mutuel exited and **Advent International** (a US private-equity firm headquartered in Boston, Massachusetts) acquired Mangopay with €75M of primary capital. The US-PE controlling shareholder results in `ownership_signal: eu_hq_us_funded` and `cloud_act_exposure: material` even though the licensed entity remains Luxembourgish. Pricing is enterprise / volume-negotiated for marketplaces; no public per-transaction pricing applies, and `starts_from_eur` is left null. Best fit: marketplace and platform operators in the EU who need multi-party regulated payments and KYC at scale and accept a US-PE-owned counter-party. Procurement-grade EU-only marketplaces should consider Lemonway (FR, also marketplace-focused, listed later in this category) or build on top of Adyen / Worldline (NL/FR public-listed) instead. **Compliance rationale:** Mangopay S.A. (Luxembourg, founded 2013, marketplace-payments specialist for Vinted / Malt / Wallapop / Chrono24 / 2,500+ platforms) holds an **EMI licence from the CSSF (Luxembourg) plus a UK EMI from the FCA** (strong EU regulatory anchoring) but was acquired in April 2022 by **Advent International** (US private equity, Boston) with €75M primary capital injection; `ownership_signal: eu_hq_us_funded`, `cloud_act_exposure: material` (US-PE controlling shareholder) despite the Luxembourg licence; no public DPA or sub-processors list accessible at audit. ### Matomo: https://euvetted.com/p/matomo - Website: https://matomo.org - Category: Web analytics - Country of incorporation: New Zealand - Hosting country: Germany - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: freemium (from €29/month) - Founded: 2007 - Certifications: ISO27001 - DPA: https://matomo.org/matomo-cloud-dpa/ - Sub-processors list: https://matomo.org/privacy-policy/ - Last verified: 2026-05-10 Open-source web analytics (NZ-incorporated InnoCraft) with EU-hosted Matomo Cloud on AWS and full self-hosted option. Matomo (formerly Piwik, renamed in 2018) is a long-running open-source web analytics platform operated by InnoCraft Limited, a New Zealand company at 7 Waterloo Quay, Wellington (NZBN 6106769). It is one of the only Schrems-friendly Google Analytics alternatives that ships in two clearly separated forms: Matomo On-Premise (fully free and self-hostable on the customer's own infrastructure with unlimited hits, websites, and team members) and Matomo Cloud, the managed SaaS offering. The product reports more than one million tracked websites across 190+ countries, including the European Commission and the United Nations. For EU buyers the operational story has two sides. On the positive side: the company is ISO 27001:2022 certified, the privacy policy is public, the GDPR Manager built into Matomo helps with Art. 30 records and consent capture, and Matomo Cloud commits that 100% of customer Cloud data and backups are stored in Europe rather than in the US. On the strict-CLOUD-Act side: InnoCraft is New Zealand-incorporated (NZ has an EU adequacy decision, so transfers are legally clean), and Matomo Cloud is operated on Amazon Web Services, meaning customer analytics data at rest sits with a US-owned hyperscaler even when the AWS region is European. Per our parent-jurisdiction stance (Schrems II, Microsoft Ireland v US), this counts as material CLOUD Act exposure regardless of region for the Cloud product. Buyers who self-host the on-premise edition on EU infrastructure (e.g. Hetzner) sidestep this entirely. Pricing for Matomo Cloud Business starts at €29/month (€348/year, 50,000 hits/month, 30 sites, 30 users) with a 21-day free trial. Anthropic Claude and OpenAI are used to analyse aggregated, non-PII Matomo data for product features; Cognism is used for B2B marketing data enrichment on the matomo.org site. Best fit: organisations who want a long-running open-source GA alternative with a credible European-data-residency Cloud offering, or who can run the open-source build on their own EU-hosted infrastructure for a fully sovereign posture with no CLOUD Act exposure. **Compliance rationale:** Open-source veteran with ISO 27001:2022 and customer Cloud data 100% stored in Europe, but the controlling legal entity is InnoCraft Limited in New Zealand and Matomo Cloud runs on AWS, meaning customer data at rest sits with a US-owned hyperscaler in the EU region; NZ holds an EU adequacy decision so transfers are legally clean, but the AWS dependency is material CLOUD Act exposure for procurement-grade buyers despite the strong open-source / on-premise alternative. **Sub-processors mapped:** 3 total, 1 US-owned - Amazon Web Services EMEA SARL (Luxembourg): Hosting (servers, databases, logs; Frankfurt with Dublin backups) and CDN for JavaScript files [US-owned] - Oblivion Cloud Control B.V. (Xebia Group B.V.) (Netherlands): AWS solution provider: infrastructure management, IT consulting and support - Tideways GmbH (Germany): Application performance monitoring (APM) ### MeisterTask: https://euvetted.com/p/meistertask - Website: https://www.meistertask.com - Category: Project management - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €14/month) - Founded: 2015 - Certifications: ISO27001 - DPA: https://a.storyblok.com/f/289344/x/e3557c833d/dpa-meisterlabs_en_may-2025.pdf - Last verified: 2026-05-18 German Kanban + tasks + docs (MeisterLabs, Munich-area, since 2006), DE hosting, ISO 27001, 10k+ companies including Allianz / LBBW. MeisterTask is the Kanban-and-task-management platform built by **MeisterLabs GmbH**, the long-running German productivity-software company founded in 2006 by **Michael Hollauf** and **Till Vollmer**. The MeisterLabs portfolio began with MindMeister (the visual mind-mapping product launched in 2009) and expanded to MeisterTask in 2015, followed by MeisterNote and MeisterAI; the company operates from the Munich area (Vaterstetten) with additional offices in Vienna and Seattle. MeisterTask serves more than 10,000 companies and ranks 4.6/5 on G2; notable reference customers include LBBW, Allianz, Ritter Sport, Fischer, and Sana Regio Kliniken, a customer mix that skews to regulated German enterprises (banking, manufacturing, healthcare). For an EU-sovereignty audit MeisterTask presents a strong signal set. The product is "made in the EU, hosted in Germany" (all customer data stored exclusively on German infrastructure) and the operating entity (MeisterLabs GmbH) holds **ISO/IEC 27001** certification with full GDPR compliance, a public DPA, and EU security/privacy alignment. The company is EU-owned with no CLOUD Act exposure; the founders remain at the company and no major US-VC / US-PE acquisition is on record. The Seattle office is a sales operation rather than a customer-data jurisdiction. Pricing in EUR: Free tier covers up to 3 projects (unlimited tasks), up to 5 notes, 20 MeisterAI prompts/month, 5 Content Manager seats, and unlimited team members; **Pro €13.50/user/month** (annual billing) adds unlimited projects/notes, 75 AI prompts, external sharing, integrations, private projects, recurring tasks; **Business €24/user/month** adds timeline view, subtasks, custom reports, role-based permissions; Enterprise tier with SSO. Best fit: German and DACH SMBs and mid-market teams that want a Kanban / project-management product with German hosting, ISO 27001 evidence, and a long-running EU vendor without the data-residency negotiations required for Asana / Monday / Trello. **Compliance rationale:** MeisterTask is operated by **MeisterLabs GmbH** (founded 2006 by Michael Hollauf and Till Vollmer; the older MindMeister mind-mapping tool launched 2009, MeisterTask launched 2015) with operations near Munich (Vaterstetten); the task-and-Kanban platform is **made in the EU and hosted in Germany**, holds **ISO/IEC 27001** certification, is fully GDPR-compliant, and serves 10,000+ companies including LBBW, Allianz, Ritter Sport, Fischer, Sana Kliniken. EU-owned, EU-hosted, with a public DPA (https://a.storyblok.com/f/289344/x/e3557c833d/dpa-meisterlabs_en_may-2025.pdf) and no CLOUD Act exposure; ISO 27001 certificate verified 2026-05-18. ### Mistral AI: https://euvetted.com/p/mistral-ai - Website: https://mistral.ai - Category: Sovereign AI - Country of incorporation: France - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2023 - DPA: https://legal.mistral.ai/terms/data-processing-addendum - Last verified: 2026-05-11 Paris-based frontier LLM lab (Mistral 7B, Mixtral, Le Chat, La Plateforme); €11.7B valuation post-ASML Series C; open-weight + commercial models. Mistral AI is the Paris-headquartered frontier LLM lab founded in **April 2023** by Arthur Mensch (CEO), Guillaume Lample, and Timothée Lacroix, three former DeepMind and Meta AI researchers who built the company on a strategy of open-weight foundational models plus commercial frontier offerings. The product surface spans **Le Chat** (consumer conversational AI hub), **La Plateforme** (developer API), **Studio** (agentic-workflow application platform), **Vibe** (codebase-aware coding models), **Forge** (custom model development), and Applied AI Services for tailored R&D. Customer references include **Stellantis** (automotive), **ASML** (semiconductors), and **CMA CGM** (logistics). Model line-up: Mistral 7B, Mixtral 8x7B / 8x22B, Mistral Small / Medium / Large, Codestral, and specialised vision and embedding models. The open-weight versions (7B, Mixtral 8x7B, Mistral Small) are released under Apache 2.0 and are the de-facto standard for European on-premise LLM deployment. Funding trajectory: seed €105M (June 2023) at €240M led by Lightspeed; Series A US$415M (Dec 2023) at US$2B led by Andreessen Horowitz; Series B US$640M (June 2024) at US$6B; **Series C €1.7B (September 2025) at €11.7B valuation led by Dutch chip giant ASML with a €1.3B cheque for an 11% anchor stake**; March 2026 US$830M debt financing from a consortium of seven banks. Other investors include **NVIDIA** (US), Andreessen Horowitz (US), DST Global (UK-registered with Russian-origin roots), Bpifrance (French state), General Catalyst (US), Index Ventures (UK/US), Lightspeed (US). ASML at 11% makes a European company the largest single shareholder, and Bpifrance provides additional French state alignment, but the US-VC stack collectively still constitutes meaningful US-weighted ownership, which is why the strict-ownership listing sits at `eu_hq_us_funded` rather than `eu_owned`. Procurement-grade picture: the **API product (La Plateforme + Le Chat)** is hosted on cloud-partnership infrastructure that includes Microsoft Azure for European-region deployment, so the at-rest exposure for managed-API customers is material under the strict CLOUD Act stance; no public DPA or sub-processors list was found at audit. The **open-weight self-host path** is the cleanest sovereign answer: Mistral 7B + Mixtral 8x7B + Mistral Small running on Hetzner H100, OVHcloud GPU, Scaleway B300, STACKIT GPU, or IONOS sovereign cloud eliminates CLOUD Act exposure entirely. Best fit: French and EU regulated buyers, defence and public-sector procurement, large enterprises in automotive / semiconductors / logistics, and any organisation evaluating sovereign frontier LLMs, but procurement-led EU-only buyers should choose the self-host path on EU GPU infrastructure rather than the managed API. **Compliance rationale:** Mistral AI (Paris, founded April 2023 by Arthur Mensch, Guillaume Lample, Timothée Lacroix, former DeepMind / Meta researchers; founders still actively running the company) is the leading European frontier-LLM lab (open-weight Mistral 7B / Mixtral / Mistral Small under Apache 2.0 plus commercial Mistral Large / Codestral / Le Chat / La Plateforme) and following its **September 2025 €1.7B Series C at €11.7B valuation led by Dutch ASML (€1.3B for an 11% anchor stake)**, the largest single shareholder is now European; the cap table also includes Bpifrance (French state). Per strict-ownership stance the listing is `eu_hq_us_funded` despite the EU anchors because Andreessen Horowitz, NVIDIA, General Catalyst, Index Ventures, Lightspeed, and DST Global collectively hold material US-weighted positions, and the La Plateforme API hosts on US-cloud infrastructure partnerships: material CLOUD Act exposure for the managed API product; no public DPA or sub-processors list found at audit. Self-hosted open-weights on EU GPU infrastructure eliminate CLOUD Act exposure entirely. ### Mollie: https://euvetted.com/p/mollie - Website: https://www.mollie.com - Category: Payments - Country of incorporation: Netherlands - Hosting country: Netherlands (Amsterdam) - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2004 - DPA: https://www.mollie.com/legal/data-processing-agreement - Last verified: 2026-05-18 Amsterdam-based DNB-licensed payments platform: strong European payment methods (iDEAL, SEPA), 250k+ merchants; US-VC-funded cap table. Mollie is the Amsterdam-headquartered European payments platform operated by Mollie B.V., authorised by **De Nederlandsche Bank** (the Dutch central bank) as an **electronic-money institution** (EMI) under PSD2. Founded in 2004 by Adriaan Mol, the company serves more than 250,000 businesses with a product surface covering online payments (cards, PayPal, SEPA Direct Debit, iDEAL, Bancontact, Klarna, etc.), in-person payments (terminals, Tap to Pay on iPhone), payment links, recurring/subscription billing, invoicing, and a business account. The developer experience is considered one of the strongest in the European Stripe-alternative space, with ready libraries for JavaScript, PHP, .NET, and Python and a long list of e-commerce-platform integrations. For an EU-sovereignty audit, the listing's structural tension is the cap table. Mollie is genuinely Dutch-incorporated, DNB-regulated, GDPR-aligned, PCI DSS Level 1 certified, and commits to processing and storing payment data within European data centres under EU privacy law: all strong procurement-grade signals. But in June 2021 the company closed a US$800M growth round at a ~US$6.5B valuation, with **TCV**, **General Atlantic**, **Blackstone**, and **Alkeon Capital** (all US private-equity / late-stage growth funds) joining alongside existing European backers. The resulting cap table is heavily US-funded (`ownership_signal: eu_hq_us_funded`, `cloud_act_exposure: material`), meaning ownership-jurisdiction exposure under a strict CLOUD Act stance even though the operating entity, DNB licence, and customer-data infrastructure sit firmly in the Netherlands. Mollie remains a strong technical and regulatory choice, but procurement teams with strict ownership-chain requirements should know that the controlling capital is largely US. Pricing is transaction-based and EU-buyer-friendly: Visa/Mastercard EEA Consumer at 1.80% + €0.25, American Express at 2.90% + €0.25, SEPA Direct Debit at €0.35 per transaction, PayPal pass-through plus €0.10, free up to 5 payouts/month, no monthly fee on the standard tier (Pay as you go), and a Pro tier at €20/month with lower variable rates. Volume customers (>€100k/month) get tailored rates. Best fit: Dutch and broader Benelux + DACH SMBs and mid-market merchants who need iDEAL and Bancontact natively, e-commerce platforms wanting a Stripe alternative with European payment-method depth, and SaaS billing teams comfortable with a US-funded but EU-regulated counter-party. **Compliance rationale:** Amsterdam-headquartered Mollie B.V. is a De Nederlandsche Bank-licensed electronic-money institution (EMI) regulated under PSD2 with PCI DSS Level 1, EU data-residency commitment, and one of the strongest European Stripe-alternative product surfaces (iDEAL, SEPA, cards, PayPal, in-person Tap to Pay, recurring); however the 2021 US$800M growth round brought TCV, General Atlantic, Blackstone, and Alkeon (all US PE/VC) onto the cap table: material US-funded ownership exposure (`ownership_signal: eu_hq_us_funded`, `cloud_act_exposure: material`) despite the strong regulatory and technical posture; no public DPA URL accessible at audit. ### Mullvad VPN: https://euvetted.com/p/mullvad - Website: https://mullvad.net - Category: VPN - Country of incorporation: Sweden - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €5/month) - Founded: 2009 - Sub-processors list: https://mullvad.net/en/help/privacy-policy - Last verified: 2026-05-18 Swedish founder-owned VPN (Mullvad VPN AB / Amagicom AB, Gothenburg, 2009), anonymous numbered accounts, Cure53-audited, flat €5/month. Mullvad VPN is one of the most-cited privacy-maximalist VPN providers in the world, operated by Mullvad VPN AB and parent **Amagicom AB** in Gothenburg, Sweden (Box 53049, 400 14 Gothenburg). Launched in March 2009 by Fredrik Strömberg and Daniel Berntsson, the company remains **100% founder-owned**. There is no private equity, no venture-capital backing, no parent conglomerate, and no acquisition pressure. Mullvad's product philosophy is built on a single radical idea: a VPN can be useful without ever collecting customer identity. The account system reflects this: accounts are random numbered tokens; there is no email address, no username, no password recovery, no personal-data field at signup. Users can generate as many accounts as they wish on the website at any time. The no-logs commitment is more rigorous than most competitors and externally verified. Mullvad does not log activity, traffic, DNS queries, connection events, IP addresses, bandwidth, or timestamps. **Cure53 (the German cybersecurity firm) has audited Mullvad multiple times**: a 2018 penetration test of the macOS / Windows / Linux apps; a 2020 infrastructure audit; a 2024 desktop-application audit that rated security "high"; and a 2024 audit of the WireGuard and OpenVPN relay-code that found no PII retention or privacy leaks (only two low- and medium-severity issues, both unrelated to logging). Nginx access logs on web infrastructure are deleted after 5 minutes without IPs; support emails are auto-deleted after 70 days; cash-payment envelopes are shredded after processing; cryptocurrency transaction records are deleted after 20 days. All apps are open-source on GitHub. Pricing is famously simple and never-changing: **€5/month flat, regardless of commitment length** (1 month, 1 year, or 1 decade, all the same monthly rate). The company explicitly does not run sales, holiday promotions, "Black Friday" discounts, or affiliate programmes. These are excluded as a matter of principle to avoid marketing-influence bias. Payment methods include cash (mail), cryptocurrencies (Bitcoin, Bitcoin Cash, Monero with a 10% discount), credit cards, PayPal, and regional bank transfers. 14-day money-back guarantee (except cash payments). 5 simultaneous devices. No port forwarding. Best fit: privacy-maximalist users worldwide who specifically want anonymous-account architecture and a Swedish-EU-jurisdiction founder-owned provider, and any procurement-grade buyer for whom "ownership simplicity + audited no-logs" beats feature breadth. **Compliance rationale:** Mullvad VPN, operated by Mullvad VPN AB (parent Amagicom AB) in Gothenburg, Sweden, founded March 2009 by Fredrik Strömberg and Daniel Berntsson and **100% founder-owned with no PE/VC/parent-company on record**. Anonymous numbered accounts (no email, no username, no personal data), Cure53-audited no-logs policy (2018 apps, 2020 infrastructure, 2024 apps + WireGuard/OpenVPN relay code), flat €5/month price unchanged since 2009, open-source apps, cash/Monero accepted. EU-owned and EU-hosted under Swedish jurisdiction with **no CLOUD Act exposure**. The only US-jurisdiction sub-processors are the optional card-payment processors (Stripe, PayPal), which are ancillary and never touch the no-logs service data, and the anonymous-account/no-logs architecture means no user identity or activity is ever linked to a payment (cash and Monero are accepted specifically to avoid them), so under a customer-data-at-rest definition CLOUD Act exposure is none. A gold-standard privacy profile on ownership, jurisdiction, and no-logs architecture. The one gap in the signal set: Mullvad does not publish a publicly accessible DPA. The anonymous-account architecture means no traditional controller-to-processor relationship is established, and only a privacy policy and no-logging data policy are available; no processor agreement exists for EU buyers to self-serve. **Sub-processors mapped:** 3 total, 2 US-owned - PayPal (United States): PayPal payment processing; ancillary [US-owned] - Stripe (United States): Credit-card payment processing; ancillary [US-owned] - SEB (Skandinaviska Enskilda Banken) (Sweden): Bank wire and Swish payment processing ### MyCashflow: https://euvetted.com/p/mycashflow - Website: https://www.mycashflow.com - Category: E-commerce - Country of incorporation: Finland - Hosting country: Finland (Helsinki) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €49/month) - Founded: 2007 - DPA: https://www.mycashflow.com/data-processing-agreement - Last verified: 2026-05-12 Finnish all-in-one e-commerce SaaS with own Helsinki hosting and 0% commission across plans. **MyCashflow**, operated by **Pulse247 Oy** (Helsinki, founded 2007), is a Finnish hosted e-commerce platform powering **7,000+ online stores** with €1.6B+ in cumulative processed sales. Plans run €49/mo (Basic, 200 products) to €165/mo (Pro, 20,000 products) with **0% commission** on online sales across tiers. **Servers are physically located in Helsinki** on Pulse247-operated infrastructure, with no AWS / Azure / hyperscaler dependency disclosed publicly, which is a procurement differentiator over both Shopify (Google Cloud, US) and PlentyONE (AWS Frankfurt). Native UI is English + Finnish; storefronts handle 17 order languages. Best fit for Finnish / Nordic merchants and EU SMBs prioritising a genuine EU hosting story over Shopify's app marketplace depth. **Compliance rationale:** **MyCashflow** (operated by **Pulse247 Oy**, Helsinki, founded 2007) runs on **own infrastructure in Helsinki** (no AWS / Azure / hyperscaler dependency disclosed) with 7,000+ live stores and €1.6B cumulative GMV; pricing starts at **€49/mo** (Basic) with 0% commission across plans. Signals: EU-owned ✓, EU-hosted ✓, no CLOUD Act exposure ✓. **No public DPA or sub-processors list**: these must be requested via sales before promoting. ### netcup: https://euvetted.com/p/netcup - Website: https://www.netcup.com - Category: Cloud & hosting - Country of incorporation: Germany - Hosting country: Germany (Nuremberg) - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid (from €1.84/month) - Founded: 2008 - Certifications: ISO27001, ISO27701, ISO9001, ISO14001 - DPA: https://www.netcup.com/en/helpcenter/documentation/general/dpa - Last verified: 2026-07-10 German budget VPS and dedicated-server host (netcup GmbH, Karlsruhe; part of Austria's founder-owned Anexia group since 2016); ISO 27001/27701; from €1.84/month. netcup is a German VPS, dedicated-server, and web-hosting provider operated by netcup GmbH (Emmy-Noether-Straße 10, 76131 Karlsruhe; HRB 705547 at Amtsgericht Mannheim; VAT DE262851304; managing directors Oliver Werner and Alexander Windbichler). The company traces back to a sole proprietorship run by Felix Preuß, was incorporated as netcup GmbH in 2008, and has been part of the Austrian Anexia group since November 2016. Anexia Holding GmbH (Klagenfurt, Austria) is wholly owned by its founder, Alexander Windbichler, with no private-equity or venture-capital investor identified on the cap table; both companies stated at the time of the acquisition that netcup would keep operating its own German infrastructure as a distinct brand. netcup reports more than 200,000 customers. The product line covers vServer (Lite, x86, ARM64), Root Server dedicated hardware on AMD EPYC, a vGPU line, server-attached block and backup storage, Managed Server and Managed Cloud Cluster (netcup's own in-house virtualization platform, not a managed Kubernetes offering), web hosting, and domain registration and reselling. For an EU-sovereignty audit the picture is mixed but net-positive. netcup holds ISO/IEC 27001 (information security), ISO/IEC 27701 (privacy information management), ISO 9001, and ISO 14001, all audited by TÜV Nord since 2023, and covering the netcup, Anexia, and DATASIX group entities together. The company operates five customer-selectable data-centre locations: Nuremberg (Germany, the flagship, marketed as fully GDPR-compliant) and Vienna (Austria) are EU; Amsterdam (Netherlands) is EU; Manassas, Virginia (USA) and Singapore are not. Customers who don't pin their order to an EU location can end up on US or Singaporean infrastructure under netcup's own brand, not through a third-party reseller. netcup's own "Digital Sovereignty" marketing page states that customer data "is not subject to laws such as the CLOUD Act or the Patriot Act," a blanket claim that sits awkwardly next to the company's own Manassas facility and is less specific than the explicit per-facility court-jurisdiction commitments some EU competitors publish; this directory records the exposure as `minor` rather than `none` on that basis. The privacy policy also names OpenAI Ireland Ltd, with an explicit transfer to the USA, as a processor for AI-assisted support chat, alongside Stripe (Ireland, with its own sub-processors in third countries) for identity checks and PayPal (Luxembourg) for payments; these touch the support and billing layer, not customer VM workloads. A Data Processing Agreement under Art. 28 GDPR is offered at no extra charge but is generated per customer inside the login-gated Customer Control Panel rather than published as a static, publicly readable document, and no standalone public sub-processor registry was found. Pricing is the headline differentiator: the cheapest vServer Lite tier (piko) starts at €1.84/month including 19% VAT on standard monthly billing with no minimum term advertised; the standard VPS 500 line starts at roughly €5.91/month (or €0.010/hour on pure hourly billing), and Root Server dedicated hardware and vGPU instances are priced separately. Infrastructure-as-code support exists only through unofficial, community-maintained Terraform providers (not a netcup-published provider), so `iac_terraform` is recorded as false. Best fit: indie developers, small SaaS builders, and prosumers who want low-cost, German-branded infrastructure with EU location pinning and don't need enterprise-grade compliance certifications such as BSI C5 or SecNumCloud. Procurement-grade buyers needing a stricter EU-only compliance posture should prefer Hetzner, OVHcloud, Scaleway, or STACKIT, listed above in this category. **Compliance rationale:** netcup GmbH (Karlsruhe, HRB 705547 Amtsgericht Mannheim, part of the Austrian founder-owned Anexia group since 2016, no US-PE or VC in the ownership chain) is ISO 27001 / 27701 / 9001 / 14001 certified with EU-primary hosting in Nuremberg, but the DPA is only generated per-customer inside the login-gated Customer Control Panel rather than published as a standalone public document, and the privacy policy names OpenAI Ireland Ltd (support chat, with an explicit USA transfer) among its sub-processors: the account-gated DPA caps the score at 4/5 per the directory's DPA-accessibility rule. ### Nextcloud: https://euvetted.com/p/nextcloud - Website: https://nextcloud.com - Category: File sharing - Country of incorporation: Germany - Hosting country: Germany (Stuttgart) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €6/month) - Founded: 2016 - Sub-processors list: https://nextcloud.com/privacy/ - Last verified: 2026-05-18 German open-source content-collaboration platform (Nextcloud GmbH, Stuttgart, 2016); fully self-hostable + managed Nextcloud One hosted in DE. Nextcloud is the directory's flagship self-hostable content-collaboration platform, operated by **Nextcloud GmbH** at Hauptmannsreute 44a, 70192 Stuttgart, Germany. Founded in June 2016 by Frank Karlitschek (founder and CEO; previously creator of ownCloud) together with Niels Mache and approximately a dozen open-source entrepreneurs, the company is privately held and founder-led with no external venture capital. Nextcloud reports **400,000+ deployments** and tens of millions of users at thousands of organisations, and ships as an integrated suite: Files (Dropbox-class storage), Talk (Slack/Zoom-class messaging and video), Groupware (mail/calendar/contacts), Office (with Collabora / OnlyOffice integrations), Assistant (sovereign AI), and Flow (no-code automation), positioning itself as "the better Microsoft 365 for private clouds." The compliance story is structurally different from every other vendor in this category. **Nextcloud is open source under AGPL-3.0 and designed to be self-hosted by default**, which means the customer becomes the data controller and operator of their own instance: there is no Nextcloud-managed cloud sitting between customer data and the customer (except for **Nextcloud One**, an optional managed offering for organisations under 100 users that is hosted in Germany with 24/7 support). The privacy policy makes this explicit: "Nextcloud software is designed to ensure no user data is transferred to us." For procurement-grade EU buyers this gives complete control over hosting region, encryption keys, and sub-processor footprint: running Nextcloud on Hetzner / OVHcloud / Scaleway / STACKIT or on the customer's own data centre delivers EU-owned, EU-hosted, no CLOUD Act exposure by construction. The reference customer list reflects this positioning: Deutsche Telekom, Amnesty International, German federal agencies, BWI (the Bundeswehr's IT subsidiary), and a long list of European universities. In 2026 Nextcloud partnered with IONOS to launch **Euro-Office** as an open-source Microsoft Office alternative (stable release summer 2026) and pledged **€250M of digital-sovereignty investment by 2030**. Pricing reflects the self-host-first model. The **Community Edition is free** under AGPL-3.0; commercial Enterprise subscriptions start at €71.29 per user per year (Standard, 100-user tier) ≈ €6/user/month, scaling to €105 (Premium, with consulting and clustering support) and €205 (Ultimate, with AI Assistant, Flow, and 24/7 support) at 100-user volumes. **Nextcloud One** is the managed German-hosted tier for <100 users. Best fit: every EU procurement-grade buyer in the directory; particularly compelling for public-sector procurement, regulated industries, and any organisation that wants a Microsoft 365 alternative under its own control. Together with Hetzner/OVHcloud/STACKIT (hosting), this is the canonical EU-sovereign-cloud productivity stack. **Compliance rationale:** **Nextcloud GmbH** (Stuttgart, founded June 2016 by Frank Karlitschek and Niels Mache with ~12 open-source founders, privately held, founder-CEO still in place) is the reference EU-sovereignty content-collaboration platform: **400,000+ deployments**, tens of millions of users, fully open source (AGPL-3.0) and self-hostable by default with explicit 'keep your data on servers you own' positioning; reference customers include Deutsche Telekom, Amnesty International, German federal agencies, BWI (Bundeswehr IT), and EU public administrations; EU-owned, open-source under AGPL-3.0, no CLOUD Act exposure because the customer typically operates the infrastructure itself. ### NordPass: https://euvetted.com/p/nordpass - Website: https://nordpass.com - Category: Password managers - Country of incorporation: Lithuania - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: freemium (from €2/month) - Founded: 2019 - Certifications: ISO27001, SOC2 - DPA: https://business.nordsec.com/legal/data-processing-agreement - Last verified: 2026-05-14 Lithuanian password manager by Nord Security, zero-knowledge XChaCha20, ISO 27001 + SOC 2, but hosted on AWS (US): material CLOUD Act exposure. NordPass is the password-manager product of Nord Security, the Lithuanian cybersecurity company headquartered in Vilnius and best known for NordVPN. NordPass launched in 2019 and sits alongside NordVPN, NordLayer, NordLocker and NordStellar in the Nord Security portfolio. As a product it is well-built: zero-knowledge architecture with **XChaCha20** end-to-end encryption (data encrypted on-device before it leaves), passkey support, integrated 2FA, secure sharing, data-breach scanning, and a business tier with SSO, activity logging and admin controls. The company voluntarily undergoes independent security audits and holds **ISO/IEC 27001 and SOC 2** attestations, plus HIPAA alignment and FIDO Alliance compliance. For an EU-sovereignty audit, however, NordPass is mid-table rather than top-tier, and the reason is infrastructure, not product quality. NordPass states plainly that it is **"hosted on AWS"**: Amazon Web Services is a US-owned hyperscaler, so even with EU-region placement the data-at-rest sits with a US-incorporated processor subject to the CLOUD Act. That structural exposure is classified as **material** CLOUD Act exposure. The zero-knowledge encryption is a genuine and important mitigation (AWS holds only encrypted blobs Nord cannot decrypt and AWS cannot read), but it does not change the ownership classification of the infrastructure. Separately, the Nord Security ownership chain includes US venture capital: the 2022 $100M round was co-led by General Catalyst (US) alongside Novator (Iceland) and Burda (Germany); the group uses multiple legal entities across jurisdictions, so the precise NordPass operating entity should be confirmed against the Lithuanian register before the listing goes live. Pricing is freemium: a free tier limited to one active device; Premium at roughly €1.50-2/month on longer plans; Family and Business tiers above. The NordPass pricing page did not render concrete figures to automated fetching at audit, so the EUR entry is approximate. Best fit: individuals and businesses already inside the Nord ecosystem, and buyers who prioritise audited product security and prize zero-knowledge encryption over strict hosting sovereignty. EU buyers who need a clean no-US-infrastructure posture should prefer Proton Pass (CH), Passbolt (LU, self-hostable) or Psono (DE, self-hostable). **Compliance rationale:** NordPass is the password manager of **Nord Security**, the Lithuanian cybersecurity group (Vilnius; founded 2019, also behind NordVPN, NordLayer, NordLocker, NordStellar). The product itself is genuinely strong (zero-knowledge XChaCha20 end-to-end encryption, voluntary independent audits, **ISO/IEC 27001 + SOC 2** attested), but the infrastructure is **hosted on AWS** (a US-owned hyperscaler), which is material CLOUD Act exposure even with zero-knowledge encryption mitigating the practical risk, and the Nord Security cap-table includes US VC (General Catalyst co-led the 2022 round). Key gaps: AWS-hosted (US-owned sub-processor), US venture capital on the cap table, sub-processor list not confirmed at audit. ### NordVPN: https://euvetted.com/p/nordvpn - Website: https://nordvpn.com - Category: VPN - Country of incorporation: Lithuania - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: paid (from €4/month) - Founded: 2012 - Certifications: ISO27001 - DPA: https://business.nordsec.com/legal/data-processing-agreement - Last verified: 2026-05-15 Panama-incorporated VPN (NordVPN S.A.) under NL holding Nord Security, LT operations; Deloitte + PwC no-logs audits, RAM-only diskless servers, ISO 27001. NordVPN is the flagship product of Nord Security, the Lithuanian cybersecurity group that also operates NordPass, NordLayer, NordLocker, NordStellar and, since the 2022 merger, Surfshark. It is one of the largest consumer VPN services in the world (Nord Security reports more than 20M users across its products with NordVPN accounting for around 15M). It is included in this directory as a **privacy-pick rather than an EU-sovereignty pick**. The distinction matters, because the ownership chain is unusually layered. The legal entity that operates the VPN service is **NordVPN S.A.**, registered in **Panama**. Historically named Tefincom S.A., this entity was deliberately set up in Panama for its absence of mandatory data-retention laws, which is itself a privacy positioning. The group **holding company** is Nord Security in **Amsterdam, Netherlands**. Day-to-day operations and the bulk of the engineering team are in **Vilnius, Lithuania**. And the cap-table includes US venture capital: the 2022 $100M round was co-led by **General Catalyst** (US) alongside Novator (Iceland) and Burda (Germany). None of those layers makes NordVPN US-incorporated (the CLOUD Act does not apply directly to a Panamanian entity), but the company is also clearly not EU-owned in the way Mullvad (founder-owned Swedish AB) or ProtonVPN (Swiss non-profit Foundation) are. Where NordVPN is genuinely strong is product security and audit history. Independent **no-logs audits by Deloitte (December 2023) and PwC** validated the no-retention claim; the entire server fleet has been transitioned to **colocated, diskless RAM-only servers** so configuration is loaded fresh on every boot and nothing persists; Nord Security holds **ISO/IEC 27001**; and the product offers WireGuard (NordLynx), kill-switch, multi-hop, Tor-over-VPN, and threat-protection extras. cloud_act_exposure is set to `minor` rather than `material` to reflect the Panama incorporation + RAM-only architecture (no data-at-rest exposure). The US-VC stake and likely US payment / CDN sub-processors keep it above `none`. Pricing is paid-only (no free tier; 30-day money-back): Basic from around €3.99/month on a 2-year plan, Plus and Complete tiers above. The affiliate programme is one of the most lucrative in the entire VPN category (see affiliate block). Best fit: mainstream privacy-conscious buyers who want a heavily audited, RAM-only no-logs VPN with broad device coverage and aggressive pricing on long commitments. EU buyers who specifically want sovereignty rather than just privacy should prefer Mullvad (SE), ProtonVPN (CH), IVPN, or AirVPN (IT), all elsewhere in this directory. **Compliance rationale:** NordVPN's ownership chain is genuinely complex and **not EU-owned in the strict sense**: the VPN service is operated by **NordVPN S.A. (Panama)**, historically Tefincom S.A., a Panamanian entity chosen for its no-data-retention jurisdiction, under the Nord Security holding company in **Amsterdam, Netherlands**, with operations and staff in **Vilnius, Lithuania**, and the 2022 $100M funding round was co-led by US VC General Catalyst alongside Novator (IS) and Burda (DE); the product itself is one of the most rigorously audited consumer VPNs (Deloitte 2023 + PwC no-logs audits, full transition to colocated diskless RAM-only servers, ISO 27001), so it is included as a **privacy-pick rather than a sovereignty-pick**. Ownership signals: Panama operating entity (not EU-owned), US-VC minority stake (General Catalyst), CLOUD Act exposure rated `minor` due to Panama incorporation + RAM-only architecture eliminating data-at-rest exposure. No public DPA at the NordVPN S.A. level for individual consumers; a business DPA is available at business.nordsec.com. ### Nuclino: https://euvetted.com/p/nuclino - Website: https://www.nuclino.com - Category: Docs & wikis - Country of incorporation: Germany - Hosting country: Germany (Munich) - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: freemium - Founded: 2015 - Certifications: SOC2 - Sub-processors list: https://www.nuclino.com/legal/subprocessors - Last verified: 2026-05-18 Munich-based founder-owned lightweight team wiki (Nuclino GmbH, 2015), all-German hosting, SOC 2 Type II, 12,000+ teams incl. NASA, MIT. Nuclino is a Munich-headquartered lightweight team-knowledge-base operated by **Nuclino GmbH** and founded in 2015 by **Björn Michelsen** (CEO, co-founder), and one of the structurally cleanest listings in the docs-and-wikis category. The company is **profitable, fully founder-owned, no venture capital and no private equity** on the cap table, no parent conglomerate, and explicitly positions this independence as a customer benefit ("we focus on customers instead of pleasing investors or chasing another funding round"). The product is differentiated from Notion / Confluence / Coda by its lightweight design philosophy (speed and simplicity over feature bloat) and its **visual knowledge graph** view that lets teams see their documentation as a connected network rather than a folder tree. For procurement-grade EU buyers Nuclino ticks every box on the rubric. The legal entity is **Nuclino GmbH** in Munich, Germany: German Handelsregister-registered, GDPR-aligned, with **all customer data hosted in Germany**. **SOC 2 Type II attested**. The customer base reaches 12,000+ teams across NASA, Ubisoft, MIT, Paddle, Psyon Games, Invoice Simple, Vistaprint, and many others: strong cross-sector enterprise reference set including US federal-civil + Hollywood AAA studio + university + B2B-SaaS adoption. Pricing is freemium with paid Standard, Premium, and Enterprise tiers; specific entry-tier EUR figures were not captured at audit. The product line now includes the Sidekick AI assistant for AI-augmented note-taking and document workflows; Canvas as a new visual editor. Best fit: German and EU SMBs and mid-market teams wanting a Notion alternative with explicit German data residency, lightweight UX, and a knowledge-graph view; procurement-grade buyers prioritising bootstrapped + founder-owned + SOC 2-attested vendors over US-VC-funded competitors (Notion, Coda, Confluence). Together with HumHub (DE, AGPLv3) and BookStack (UK, MIT) Nuclino completes the directory's top-tier sovereignty trio for the docs-and-wikis category. **Compliance rationale:** Nuclino GmbH (Munich, Germany; founded 2015 by Björn Michelsen et al.) is a **profitable, fully founder-owned** lightweight team-knowledge-base (explicitly no venture capital, no PE, no parent) that hosts **all customer data in Germany** with **SOC 2 Type II** attestation and GDPR compliance. Customer base of 12,000+ teams including NASA, Ubisoft, MIT, Paddle, Vistaprint. Real-time collaborative editing, visual knowledge graph (the differentiator vs Notion), Sidekick AI assistant. Signals: EU-owned (German GmbH), EU-hosted (Germany) but **material CLOUD Act exposure**: primary hosting runs on AWS and Heroku (US hyperscalers) with FrontApp (US) for support, so customer documents sit with US-jurisdiction infrastructure providers; SOC 2 Type II certified, sub-processors publicly disclosed. Gap: no publicly accessible DPA. The privacy policy directs procurement buyers to contact@nuclino.com rather than offering a self-serve download. **Sub-processors mapped:** 7 total, 3 US-owned - Amazon Web Services EMEA SARL (Luxembourg): Cloud infrastructure / hosting (primary) [US-owned] - FrontApp, Inc. (United States): Customer support system [US-owned] - Heroku, Inc. (United States): Cloud platform service [US-owned] - BunnyWay d.o.o. (Slovenia): Content delivery network (Bunny.net) - Mailjet SAS (France): Transactional email delivery - Paddle.com Market Ltd (United Kingdom): Payment processing / merchant of record - Stability AI Ltd. (United Kingdom): AI image generation service ### Olvid: https://euvetted.com/p/olvid - Website: https://olvid.io - Category: Video conferencing - Country of incorporation: France - Hosting country: France - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium (from €10/month) - Founded: 2019 - Last verified: 2026-06-05 French E2EE messenger (Olvid SAS, Paris, founded 2019), ANSSI CSPN certified, mandated for French government ministers; no phone number/identifier, content + metadata encrypted. Olvid is a French end-to-end encrypted messaging application developed by **Olvid SAS** (26 rue Vignon, 75009 Paris; SIREN 850 667 171), founded in 2019 by a four-person team including two PhD cryptographers, Thomas Baignères (CEO) and Matthieu Finiasz (CTO). It is best known as the only messenger to hold France's **ANSSI CSPN** (Certification de Sécurité de Premier Niveau), obtained for iOS in 2020 and Android in 2021 following technical audits by Synacktiv, whose evaluation reports are published openly, and as the messenger **mandated by the French Prime Minister** in a November 2023 circular for ministers and ministerial cabinets, replacing WhatsApp, Signal and Telegram from December 2023. The architecture is unusual even among privacy messengers. Olvid requires **no phone number, no email, and no identifier of any kind**: users connect by exchanging cryptographic identities (typically a QR-code scan or invitation link), and Olvid maintains no central directory of users. Both the **content and the metadata** of every message are end-to-end encrypted, using a custom protocol with forward secrecy via single-use ephemeral keys (formally validated academically by Michel Abdalla, ENS/CNRS). Because the server holds no decryptable data and plays no role in the security model, it cannot determine who is communicating with whom, closing the metadata gap that even Signal leaves partially open. The clients and the message-distribution server are open source on GitHub under AGPL-3.0. The product is freemium and three-tier. **Free** covers all core consumer messaging (unlimited messages, attachments, groups, ephemeral messages, multi-profile, Olvid Web, inbound calls) on iOS, Android, Windows and Linux. **Business** (€9.90/user/month, billed annually) adds outbound calls, multi-device and license management. **Enterprise** (€9.90/user/month plus a flat annual platform fee) adds a Management Console, SSO, central user/group management, instant revocation, MDM deployment and Olvid Bots. There is no self-hosted/on-prem edition. The principal sovereignty caveat for a strict procurement reviewer is that the backend runs on **AWS** (a US provider), so US CLOUD Act jurisdiction reaches the infrastructure layer even though the zero-knowledge design means the host never sees message content or metadata. Best fit: French and EU public-sector buyers and regulated organisations that want a government-grade, ANSSI-certified WhatsApp/Signal replacement with the strongest available metadata privacy; privacy-conscious individuals who want a messenger with no identifier at all. **Compliance rationale:** Olvid SAS (26 rue Vignon, 75009 Paris; SIREN 850 667 171; founded 2019 by four founders incl. two cryptography PhDs) is the only messaging app certified **ANSSI CSPN** (iOS 2020, Android 2021, audited by Synacktiv with public reports) and was **mandated by the French Prime Minister's Nov 2023 circular** for government ministers and cabinets, replacing WhatsApp/Signal/Telegram from Dec 2023. Both message content **and metadata** are end-to-end encrypted; no phone number, email or identifier is required, and Olvid's servers cannot determine who talks to whom, a stronger metadata posture than Signal or WhatsApp. EU-owned French SAS, founder-controlled, no US capital on record; open source (AGPL-3.0) including the server. The one gap that holds this below a 5: core infrastructure runs on **AWS** (a US provider), so `cloud_act_exposure: minor` applies at the host level even though the zero-knowledge design means the host never sees plaintext or metadata; there is also no standalone published DPA/sub-processor page. No SecNumCloud: Olvid argues it is less relevant for a zero-knowledge service. ### Omnivery: https://euvetted.com/p/omnivery - Website: https://omnivery.com - Category: Email marketing - Country of incorporation: Czechia - Hosting country: Czechia - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid - Founded: 2006 - Certifications: ISO27001, ISO27017, ISO27018, ISO27701 - DPA: https://omnivery.com/legal/dpa - Sub-processors list: https://omnivery.com/legal/gdpr - Last verified: 2026-07-17 Czech transactional email platform (SMTP relay and API) on its own physical infrastructure, no hyperscaler cloud for core sending. Omnivery is a transactional email platform (SMTP relay plus REST API) operated by Omnivery s.r.o. in Chrášťany near Prague, Czech Republic. The product is the 2021 relaunch of Mailkit, a Czech email-delivery vendor founded in 2006 by Jakub Olexa (still CEO), and it targets developers and businesses sending transactional and notification email who want an alternative to US-hosted senders such as SendGrid, Mailgun, Postmark, SparkPost and Bird. Its central differentiator is genuine: unlike most of the category, Omnivery runs its core sending stack on its own physical infrastructure rather than AWS, Azure or Google Cloud, and states it never stores email content. The company holds a stack of ISO certifications issued by the Czech body TAYLLORCOX, including ISO 27001, 27017, 27018 and 27701 (a 7-certificate PDF is published on the site), plus HIPAA readiness and CSA / M3AAWG / Signal Spam memberships. The Data Processing Agreement, privacy policy and sub-processor list are all public and readable without a sales gate, which is a strong transparency signal for the category. On sovereignty the picture largely holds up, with caveats worth knowing. The vendor confirms (July 2026) that the EU is currently its only data location, that data residency is customer-selectable per sending domain, and that storage can also be on-premise or dedicated to a single customer or domain. The US subsidiary, Omnivery US Inc. (Austin, Texas), is sales-only with no technical access to customer data, and the Google LLC entry in the privacy policy covers Google Analytics on the marketing site rather than the customer data path. The three US-owned sub-processors on the GDPR page (Amazon Web Services, Filestack and Kickbox) serve an optional email-validation feature that is disabled by default and warns before it is enabled, and the vendor says it will move to an EU validation provider. Two things to watch: a US data location is being set up, and the specific EU data-centre country is still not named publicly. Pricing is quote-based with no free tier and no self-serve signup, an intentional anti-abuse measure. Best fit: EU teams that want a non-hyperscaler transactional sender with public compliance docs and can accept enterprise, contact-sales onboarding. **Compliance rationale:** Czech s.r.o. running its core sending stack on its own physical infrastructure with EU-only data at rest (vendor-confirmed 2026-07-17, customer-selectable per-domain residency), a publicly readable Art. 28-compliant DPA with immediate message-content deletion, a public sub-processor list and TAYLLORCOX-issued ISO 27001/27017/27018/27701; the only US touchpoints are a sales-only subsidiary with no data access, marketing-site Google Analytics and an optional email-validation feature that is disabled by default, so exposure is minor rather than material, but the score is held at 4 rather than 5 because the specific EU data-centre country is not publicly named, a US data location is being set up, and the EU-only/opt-in facts rest on vendor statements not yet reflected in public documentation. **Sub-processors mapped:** 4 total, 3 US-owned - Amazon Web Services, Inc. (United States): E-mail validation (optional feature, disabled by default; processing in Ireland/EU region) [US-owned] - Filestack, Inc. (United States): E-mail validation (optional feature, disabled by default) [US-owned] - J2 Martech Corp DBA Kickbox (United States): E-mail validation (optional feature, disabled by default) [US-owned] - ProfiSMS s.r.o. (Czechia): SMS delivery ### OnlyOffice: https://euvetted.com/p/onlyoffice - Website: https://www.onlyoffice.com - Category: Docs & wikis - Country of incorporation: Latvia - Hosting country: Latvia (Riga) - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: freemium - Founded: 2009 - Last verified: 2026-05-11 Riga-based Latvian office suite (Ascensio System SIA), AGPLv3 self-hostable + DocSpace cloud; complex post-2023 Singapore+UK+Russian-origin ownership chain. ONLYOFFICE is a Microsoft 365 / Google Docs alternative office suite (documents, spreadsheets, presentations, PDF editing, fillable forms, real-time co-authoring) operated by **Ascensio System SIA**, headquartered in Riga, Latvia and founded in 2009 by **Lev Bannov**. The product ships as a fully open-source AGPLv3 codebase plus a managed DocSpace cloud, with desktop apps (Windows, Linux, macOS), mobile apps (iOS, Android), and 40+ third-party connectors for embedding into platforms like Nextcloud, ownCloud, Confluence, and many others. Real-world EU adoption is significant: the city of **Lyon, France** publicly migrated to OnlyOffice in 2025 as part of its sovereign-IT strategy. For an EU-sovereignty audit ONLYOFFICE is the most structurally complex listing in the docs-and-wikis category. The operating-and-contracting entity is **Ascensio System SIA** in Riga, Latvia, an EU member state company. But the corporate ownership chain has multiple non-EU layers that procurement teams must understand before signing material multi-year deals: Ascensio System SIA was originally established in 2009 as a subsidiary of the **Russian-based New Communication Technologies**; in **August 2023 the ownership restructure** transferred control to **Ascensio System Limited (UK)**, which is in turn owned by **OnlyOffice Capital Group Pte. Ltd. (Singapore)**; the founder and **ultimate beneficial owner Lev Bannov** holds Russian and Turkish dual citizenship and has resided in **Istanbul, Turkey** since 2023. The August 2023 restructure was specifically designed to distance the operating entity from Russian ownership and align with EU procurement norms, but the structure is still non-trivial: EU-operating, UK-holding, Singapore-master-holding, Russian-Turkish UBO. AGPLv3 open-source means the entire codebase is auditable and self-hostable: this is the procurement-grade escape hatch. **Running the open-source ONLYOFFICE Community / Document Server on EU infrastructure (Hetzner, OVHcloud, Scaleway, IONOS, STACKIT)** keeps everything inside the customer's chosen jurisdiction and effectively neutralises the ownership-chain complexity for the deployment data flows. Pricing: open-source self-host free; DocSpace Cloud free Startup tier with paid Business / Enterprise tiers. Best fit: EU public-sector and government buyers (Lyon model) that self-host on EU infrastructure under AGPLv3, organisations needing Microsoft Office format compatibility with sovereign-deployment options, and any procurement-grade buyer comfortable with the complex but EU-operating ownership chain (or who self-hosts to neutralise it). **Compliance rationale:** ONLYOFFICE has a **complex ownership chain procurement-grade buyers must understand**: operating entity is **Ascensio System SIA in Riga, Latvia** (so Latvian + EU jurisdiction at the contracting layer); founder and CEO **Lev Bannov** is a Russian national with Russian + Turkish dual citizenship who has been residing in Istanbul since 2023; the company was originally a 2009 subsidiary of **Russian-based New Communication Technologies** until an August 2023 ownership restructure transferred control to **Ascensio System Limited (UK), in turn owned by OnlyOffice Capital Group Pte. Ltd. (Singapore)**, with Bannov as the ultimate beneficial owner across the group. AGPLv3-licensed and self-hostable, so EU buyers can fully escape the ownership chain by running their own instance. The operating entity is EU-incorporated (Latvia) but the ownership chain spans UK–Singapore–Russian-Turkish UBO; no public DPA or sub-processors list is available. Self-host on EU infrastructure (Hetzner / OVHcloud / Scaleway) is the procurement-grade recommended path. It neutralises the ownership-chain complexity by keeping all data flows under the customer's chosen EU jurisdiction. ### Oodrive: https://euvetted.com/p/oodrive - Website: https://www.oodrive.com - Category: File sharing - Country of incorporation: France - Hosting country: France (Paris) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2000 - Certifications: SECNUMCLOUD, HDS, ISO27001 - Last verified: 2026-06-15 French SecNumCloud-qualified secure file sharing, collaboration and e-signature, hosted entirely in France beyond CLOUD Act reach. Oodrive is a French trusted-cloud vendor (founded 2000, based in Paris) offering secure file sharing, data collaboration, backup and electronic signature through its Oodrive Work suite (sharing, storage, co-editing, chat, the Oodrive Meet video tool) and Oodrive Sign e-signature solution. It positions itself as Europe's leading sovereign collaboration platform and a direct alternative to Dropbox, Box, Google Drive and DocuSign for organisations handling sensitive data and critical infrastructure. Its core differentiator is data sovereignty: solutions are hosted exclusively in France across two sites on hardware owned by Oodrive, under French jurisdiction and explicitly described as outside the reach of extraterritorial laws such as the US CLOUD Act and FISA. Oodrive was the first provider to receive the ANSSI Security Visa via SecNumCloud (2019) and holds SecNumCloud 3.2 qualification for its Oodrive Work and Oodrive Meet collaborative suite, renewed by ANSSI in February 2025 for three years. It also holds HDS 2.0 (health-data hosting), ISO 27001 and ISO 27701 certifications. Pricing is enterprise and quote-based; there is no public free tier. Oodrive targets regulated sectors (public sector, finance, healthcare, defence) where SecNumCloud qualification is a procurement requirement rather than a marketing badge. **Compliance rationale:** SecNumCloud 3.2-qualified end-to-end (infrastructure to software) plus HDS 2.0 and ISO 27001/27701, with data hosted exclusively in France under French jurisdiction and explicitly outside CLOUD Act/FISA reach. ### Opera VPN: https://euvetted.com/p/opera-vpn - Website: https://www.opera.com/features/free-vpn - Category: VPN - Country of incorporation: Norway - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: freemium (from €4/month) - Founded: 1995 - Sub-processors list: https://www.opera.com/legal/privacy - Last verified: 2026-06-12 Oslo-heritage browser VPN (Opera Norway AS): Deloitte-audited free browser proxy + paid VPN Pro, but ultimately Chinese-controlled via Kunlun Tech (Opera Limited, Cayman/NASDAQ). Listed as a warning. Opera VPN is two products under one brand, both carrying the Opera name and its Oslo heritage. The **free browser VPN** is a no-registration, unlimited, browser-only TLS/HTTPS proxy built into the Opera browser, offering three broad regions (Americas, Europe, Asia) rather than country-level choice; it is a proxy for Opera browser traffic, not a full-device VPN tunnel, and lacks a kill switch. The paid **Opera VPN Pro** is a full-device VPN (Windows, macOS, Android; no native iOS/Linux app at audit) priced around €4/month with annual plans roughly 50% cheaper, 6 simultaneous devices, and a 30-day money-back guarantee. Crucially, VPN Pro does **not** run on infrastructure Opera owns: it is a white-labelled third-party network, originally NordVPN's servers, more recently reported (TechRadar) to be powered by ExpressVPN's technology, so the underlying fleet belongs to non-EU VPN consolidators. On product privacy, Opera has a genuine credential: the free browser VPN completed an **independent Deloitte no-log audit** (engagement 18 June–10 August 2024) which verified that the infrastructure contains no logging functionality and collects no data about browsing activity or originating network address. Opera Norway AS is the named data controller, and the privacy statement describes both free VPN and VPN Pro as no-log services, with only a random subscriber ID shared with the third-party VPN Pro provider. The reason this listing exists as a **warning rather than a recommendation** is the ownership chain: the cleanest 'Norwegian outside, foreign inside' example in the directory. Opera Norway AS (Oslo) is wholly owned through Opera Services AS and Opera Holdings AS by **Opera Limited**, a holding company **incorporated in the Cayman Islands** and listed on **NASDAQ under OPRA**. Opera Limited is in turn **majority-controlled by Kunlun Tech Co. Ltd.** (a Beijing-based, Shenzhen-listed Chinese technology group holding roughly 69%) whose controlling shareholder **Zhou Yahui** also serves as Opera's executive chairman. The 2016 acquisition by a Kunlun-led Chinese consortium is the moment the heritage Norwegian browser became a Chinese-controlled asset. For an EU/EEA sovereignty audit, none of the Norwegian heritage signal survives this: the ultimate decision-making and beneficial control sit under Chinese jurisdiction, the listed parent under Cayman/US-securities jurisdiction, and Norway itself is a member of the 'Nine Eyes' extended intelligence alliance. Best read: a usable free browser proxy with a real Deloitte audit, but the structural antithesis of a sovereignty pick. EU/EEA buyers wanting an actual sovereignty profile should prefer Mullvad (SE, founder-owned), OVPN (SE), ProtonVPN (CH, non-profit Foundation), or IVPN. **Compliance rationale:** Opera VPN is the 'Norwegian outside, foreign inside' case in this category. The data controller and heritage entity is **Opera Norway AS** in Oslo (a 30-year-old Norwegian browser maker; the free browser VPN dates to 2016 via the SurfEasy acquisition), and the free in-browser VPN passed an **independent Deloitte no-log audit** (18 Jun–10 Aug 2024) confirming no logging of browsing activity or originating network address, so on a pure product-privacy axis it is defensible. But the ownership reality is the opposite of a sovereignty win: Opera Norway AS rolls up via Opera Services AS → Opera Holdings AS to **Opera Limited, incorporated in the Cayman Islands and listed on NASDAQ (OPRA)**, which is in turn **majority-owned and controlled by Kunlun Tech Co. Ltd.** (Beijing-based, Shenzhen-listed; ~69% stake), whose controlling shareholder **Zhou Yahui is also Opera's executive chairman**. The structural exposure is therefore dual and non-EEA: a minor US-nexus from the Cayman/NASDAQ listing, but **material exposure to Chinese-law / non-EEA control of the ultimate parent**, captured here as `cloud_act_exposure: material` (closest tier; the controlling jurisdiction is China, not the US). country_iso is kept as NO to reflect the Oslo operating entity / buyer-facing brand, with the Chinese control captured in ownership_signal + this rationale. The paid **Opera VPN Pro** (~€4/mo, 6 devices) does not run on Opera's own fleet: it is a white-labelled third-party network (originally NordVPN, more recently reported to be ExpressVPN/Kape technology), neither EU-owned. Listed as a **warning**, not a recommendation: no EU/Norwegian sovereignty signal survives the Kunlun Tech control. ### Orbifs: https://euvetted.com/p/orbifs - Website: https://orbifs.eu - Category: File sharing - Country of incorporation: Norway - Hosting country: France (Paris) - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: paid (from €69/month) - Founded: 2016 - DPA: https://orbifs.eu/legal/dpa - Sub-processors list: https://orbifs.eu/legal/subprocessors - Last verified: 2026-06-23 Norwegian-run virtual project drive (Archi Systems AS, EEA) for large CAD/BIM/point-cloud files, hosted on EU-owned OVHcloud in France with single-writer file locking and immutable versions. Orbifs is a virtual project drive for large professional files (CAD, BIM, point-cloud and media) built and operated by **Archi Systems AS**, a company incorporated in Oslo, Norway (org. no. 916 683 332, registered 2016, originally an architectural-services firm) and therefore within the EEA and bound by the GDPR. Files appear as ordinary files in Windows Explorer and macOS Finder and open on demand: there are no full local copies, no VPN, and no sync conflicts, because the drive streams object bytes from the cloud as they are needed. Concurrency is handled with single-writer file locking (one writer at a time on a CAD/BIM file) and every change is kept as an immutable version, implemented with S3 versioning plus Object Lock (write-once-read-many), SHA-256 content addressing and FastCDC content-defined chunking, so stored bytes cannot be overwritten or deleted before their lock expires. The desktop clients cover Windows and macOS. For an EU-sovereignty audit the hosting story is the strong part. Orbifs runs on **OVHcloud**, a European-owned (French) provider, with file content (object bytes) in Paris, file metadata in Frankfurt, and off-region backups in Paris with point-in-time recovery: "hosted in Europe, end to end." Connections are TLS-terminated at the edge (Caddy) and object storage uses server-side AES-256 encryption; keys are currently managed by the storage provider, with a customer-managed-key (BYOK) option still being finalised, and there is **no end-to-end / zero-knowledge encryption today**. The sub-processor list is deliberately short and EU-based: OVHcloud (FR) for hosting, Stripe Payments Europe (IE) for billing, and optional Google Ireland / Microsoft Ireland sign-in for tenants who choose SSO, all EU subsidiaries of US-headquartered parents, but ancillary and never in the path of project file content at rest; support and transactional email run on Archi Systems' own EEA mail server, so no third party handles correspondence. This is why the directory records `minor` rather than `none` CLOUD Act exposure: the at-rest data sits on an EU-owned provider, but the lack of E2E plus the US-parented billing/optional-sign-in processors keep it just short of a clean `none`. On certifications the vendor is candid: a CSA STAR Level 1 (CAIQ) **self-assessment** is published, while ISO/IEC 27001 and SOC 2 are stated as in progress and Cyber Essentials / ENS as candidate; no third-party certification is claimed yet, so the directory lists none. Pricing is paid with no free tier; annual billing is the headline price and all figures exclude VAT (monthly billing carries a ~15–20% premium): Studio at €69/month (1 TB, 5 seats), Practice at €249/month (5 TB, 20 seats), Business at €699/month (15 TB, 50 seats), and Enterprise from €1,990/month (50 TB+, with a dedicated region available). SSO/SAML and audit-log export are included on the Business plan and above. Best fit: architecture, engineering, construction and media teams that move very large CAD, BIM, point-cloud and video files and want a mounted, EU-hosted project drive with file locking and immutable history as a replacement for a NAS+VPN setup or a US cloud drive (Dropbox, OneDrive, SharePoint, Google Drive), with the caveat that this is a young, single-product vendor whose certifications and BYOK custody model are still maturing. **Compliance rationale:** **Archi Systems AS** (Oslo, Norway, EEA, GDPR-bound; org. no. 916 683 332) runs Orbifs, a virtual project drive for very large CAD/BIM/point-cloud/media files, entirely on **OVHcloud** (EU-owned, French) with file bytes in Paris, metadata in Frankfurt and off-region backups in Paris, a public DPA, a public and deliberately short EU-based sub-processor list, and its own EEA mail server so no third party handles support correspondence; EEA-incorporated and EU-hosted at rest, which is why CLOUD Act exposure is `minor` rather than `none`: there is no end-to-end encryption (object storage uses provider-managed AES-256 SSE, BYOK still being finalised) and the only US-parented sub-processors are ancillary (Stripe Payments Europe (IE) for billing and optional Google/Microsoft Ireland sign-in), none of which touch project file content at rest; held at 4/5 (not 5) by those US-parented ancillary processors and the absence of any third-party certification, with only a self-published CSA STAR Level 1 (CAIQ) self-assessment and ISO 27001 / SOC 2 stated as in progress. **Sub-processors mapped:** 4 total, 3 US-owned - Google Ireland Ltd. (Ireland): Optional sign-in authentication (SSO); ancillary, only if tenant enables it (EU subsidiary of US-headquartered Alphabet/Google) [US-owned] - Microsoft Ireland Operations Ltd. (Ireland): Optional sign-in authentication (SSO); ancillary, only if tenant enables it (EU subsidiary of US-headquartered Microsoft) [US-owned] - Stripe Payments Europe, Ltd. (Ireland): Billing and payment processing; ancillary (EU subsidiary of US-headquartered Stripe) [US-owned] - OVHcloud (OVH SAS) (France): Hosting, object storage, backups and logs; file content (Paris), metadata (Frankfurt), off-region backups (Paris) ### Outline: https://euvetted.com/p/outline - Website: https://www.getoutline.com - Category: Docs & wikis - Country of incorporation: United States - Hosting country: United States - Ownership signal: us_owned - CLOUD Act exposure: direct - Pricing tier: paid - Founded: 2016 - DPA: https://docs.getoutline.com/s/dpa - Sub-processors list: https://docs.getoutline.com/s/dpa - Last verified: 2026-05-11 US-incorporated open-source-style wiki (Outline, NYC) under BSL licence; self-hostable for EU sovereignty, but hosted cloud is US. Outline is a US-incorporated open-source-style knowledge-base and wiki product, operated by **General Outline, Inc.** in **New York City** and originally founded by **Tom Moor**. The product positions itself as a fast, beautiful, real-time-collaborative knowledge base for teams, feature-comparable to Notion and Confluence but with a leaner UX and an open-source codebase on GitHub (outline/outline). The product targets fast-growing software teams, has built a strong following in the developer-tools community, and supports 20+ languages with RTL support, dark mode, Slack and Figma integrations. For an EU-sovereignty audit Outline is the canonical "open-source license ≠ EU-controlled" case alongside Cal.com. The licence is the **Business Source License (BSL)**: open-source in spirit but with a competitor-hosting prohibition that excludes Outline from the OSI-approved open-source definition. The BSL contract specifies that the codebase reverts to **Apache 2.0** four years after publication date, so v0.62.0 (and earlier) became Apache 2.0 in March 2026. This means **buyers can fully self-host the licence-converted Apache 2.0 versions on EU infrastructure** (Hetzner, OVHcloud, Scaleway, IONOS, STACKIT) with no licence-restriction concerns and no CLOUD Act exposure for that path. The **hosted Outline cloud, by contrast, is operated from the US by General Outline, Inc., which is `us_owned` and subject to US extraterritorial law by default: `direct` CLOUD Act exposure**. The self-host path on EU infrastructure is procurement-grade-friendly, but the managed cloud should not be the first choice for EU buyers when category alternatives like **HumHub (DE, AGPLv3, German GmbH)**, **Nuclino (DE)**, **Cryptpad (FR, E2E-encrypted)**, **OnlyOffice (LV)**, **BookStack (UK, MIT-licensed self-host)**, or **Wiki.js (open source self-host)** offer structurally cleaner EU-controlled ownership. Best fit: EU developer teams who specifically want Outline's UX and are willing to self-host on EU infrastructure under the converted Apache 2.0 versions. **Compliance rationale:** Outline is **US-incorporated as General Outline, Inc.** (New York City; founder Tom Moor) despite the open-source-style positioning. Source code is published under the **Business Source License (BSL)** which permits self-hosting but explicitly forbids competing hosted services; older versions (v0.62.0 and earlier) revert to **Apache 2.0** four years after publication (March 2026 onwards). Hosted cloud is US-region; the company itself is `us_owned` with `direct` CLOUD Act exposure. Signals: self-hostable codebase (BSL / Apache-2.0 on older versions); EU-hosted self-deploy achieves no CLOUD Act exposure. Gaps: US ownership, US-hosted managed cloud, direct CLOUD Act exposure, no public DPA or sub-processors list. **The hosted cloud should not be the first choice for EU buyers**: procurement-grade alternatives in this category include HumHub (DE, AGPLv3), Nuclino (DE), Cryptpad (FR), OnlyOffice (LV), or BookStack (UK MIT). ### OVHcloud: https://euvetted.com/p/ovhcloud - Website: https://www.ovhcloud.com - Category: Cloud & hosting - Country of incorporation: France - Hosting country: France (Roubaix) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €5/month) - Founded: 1999 - Certifications: ISO27001, SECNUMCLOUD, C5, SOC2 - DPA: https://storage.gra.cloud.ovh.net/v1/AUTH_325716a587c64897acbef9a4a4726e38/contracts/5cec77c-OVH_Data_Protection_Agreement-IE-6.2.pdf - Sub-processors list: https://us.ovhcloud.com/legal/data-processing-agreement/ - Last verified: 2026-05-18 French sovereign cloud (OVH Groupe, Roubaix, 1999), ANSSI SecNumCloud 3.2-qualified Bare Metal Pod; 46 DCs, public on Euronext Paris. OVHcloud (legal entity OVH Groupe SAS, Roubaix, France) is the largest European hyperscaler alternative and the directory's reference choice for French and EU public-sector sovereign workloads. Founded in 1999 by Octave Klaba, the company is publicly listed on Euronext Paris and remains under founding-family control: as of 20 October 2025, Octave Klaba returned as combined Chairman of the Board and Chief Executive Officer after Benjamin Revcolevschi's one-year tenure. The group reported €1.08B revenue for fiscal year 2025 (+9.3%) at a 40.4% adjusted-EBITDA margin, serves 1.6M customers, and operates 46 data centres across four continents. Flagship customers include Société Générale, Louis Vuitton, Capgemini, and Sopra Steria. Compliance is the differentiator. OVHcloud carries ISO/IEC 27001:2013, ISO/IEC 27701:2019, SOC 1/2/3, PCI DSS 3.2 Level 1, and GDPR alignment as the baseline. On top of that it holds the French government's **ANSSI SecNumCloud 3.2** qualification (March 2025, applied to the Bare Metal Pod platform), the most stringent French sovereign-cloud certification, designed to provide protection from the U.S. CLOUD Act and FISA Section 702 by guaranteeing that cloud operations are immune from non-EU jurisdiction. It also carries French **HDS** (healthcare data hosting), German **BSI C5** (cloud-security catalogue), Spanish **ENS**, UK G-Cloud public-sector framework, and HIPAA / HITECH for US healthcare workloads. The corporate position is explicit: "We do not sell, use or transfer your data; choose where to store your data and the jurisdiction that protects it." For procurement, this matters because OVHcloud is one of the four winners of the €180M April 2026 EU sovereign-cloud tender (alongside Scaleway, Clever Cloud, and STACKIT). AWS was deliberately excluded. The Public Cloud product starts at roughly €5/month for small compute instances; first-time customers get US$200 in free credit. Data-centre regions across Frankfurt, Paris, London, Strasbourg, Roubaix, Gravelines, plus North America (Toronto, US), Asia-Pacific (Singapore, Sydney), and others, all customer-elected. Network capacity is 100 Tbit/s globally. Best fit: any EU procurement-grade buyer needing a strict CLOUD-Act-clean hyperscaler alternative, regulated industries (healthcare, finance, public sector), and customers who want SecNumCloud-grade isolation for the most sensitive workloads. **Compliance rationale:** OVH Groupe SAS (Roubaix, founded 1999 by Octave Klaba, publicly listed on Euronext Paris with the founding family still in control as Chairman + CEO) is one of two recommended EU-sovereign hyperscaler alternatives in this directory: ISO 27001 + ISO 27701 + SOC 2 + PCI DSS + GDPR baseline plus the French government's **ANSSI SecNumCloud 3.2** qualification (March 2025, awarded for Bare Metal Pod), the German BSI **C5** catalogue, French **HDS** for healthcare, Spanish **ENS**, and UK G-Cloud: EU-owned and EU-hosted with no CLOUD Act exposure for customer workloads placed in EU regions. ### OVPN: https://euvetted.com/p/ovpn - Website: https://www.ovpn.com - Category: VPN - Country of incorporation: Sweden - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €4/month) - Founded: 2014 - Sub-processors list: https://www.ovpn.com/en/privacy-policy - Last verified: 2026-05-15 Swedish founder-owned VPN (OVPN Integrität AB, est. 2014), fully owns hardware, diskless RAM-only, court-proven no-logs, legal-fees insurance. OVPN is operated by OVPN Integrität AB, a Swedish company that has been publishing transparency reports continuously since 2014. It is one of the cleanest small-vendor listings in the consumer-VPN category, and the structural details are what set it apart from larger competitors. **OVPN fully owns its server hardware**: there are no rented servers and no virtual machines anywhere in the fleet, which removes a class of supply-chain and shared-tenancy risk that almost every other VPN provider accepts. All VPN servers are **diskless and run their operating system from RAM**, so there is no persistent storage on the hardware that could be seized. The no-logs claim is unusually well-evidenced. Where most VPN providers point at an annual third-party audit, OVPN has the policy **legally tested**: in an information-injunction case the company was able to demonstrate it had no data to hand over, and OVPN now carries **insurance to cover legal fees** for future similar cases, a level of structural commitment to non-retention that mirrors Mullvad's culture in the same Swedish jurisdiction. Encryption is modern across the board: AES-256-GCM with OpenVPN, Curve25519 + ChaCha20 with WireGuard. The fleet covers 32 cities globally with full IPv6 support, multihop, port forwarding (up to 7 ports in the 49152-65535 range), and an optional public IPv4 add-on. For an EU-sovereignty audit OVPN is a top-tier pick alongside Mullvad in the same Swedish jurisdiction. It is founder-owned, EU-incorporated, has no US parent, no US VC, no PE, and the owned-hardware + diskless + court-proven posture is structurally as strong as anything in the category. It is genuinely under-known compared to NordVPN/Surfshark/CyberGhost, which is precisely the kind of listing this directory exists to surface. Pricing is paid-only with a 10-day money-back guarantee: 1-month €12, 1-year €4.99/month, 3-year €4.22/month (the long-commitment best-value tier). UI languages: English, Swedish, German, Norwegian. Best fit: privacy-maximalist EU buyers who want a small, owner-operated, structurally-sound Swedish provider with court-tested no-logs, and who prefer "we own everything and it's all in RAM" over a marketing-heavy mainstream brand. **Compliance rationale:** OVPN is operated by **OVPN Integrität AB**, a Swedish company publishing transparency reports continuously since 2014. One of the cleanest sovereignty stories in the consumer-VPN category: **fully owns its server hardware (no rented servers, no virtual machines)**, all VPN servers are **diskless with the operating system in RAM**, the no-logs policy is **court-proven** (an information-injunction case where OVPN simply had nothing to hand over, with legal-fees insurance to underwrite future cases), supports modern crypto (AES-256-GCM / Curve25519 / ChaCha20 / WireGuard), and runs 32 locations with IPv6. EU-owned and EU-incorporated under Swedish jurisdiction, no CLOUD Act exposure, no PE / VC / parent on record. An exemplary sovereignty profile on ownership, jurisdiction, and no-logs architecture. Signal gap: OVPN does not publish a DPA on the site; only a privacy policy is available, with no processor agreement for EU buyers to self-serve. ### Padloc: https://euvetted.com/p/padloc - Website: https://padloc.app - Category: Password managers - Country of incorporation: Germany - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: freemium (from €3/month) - Founded: 2019 - Last verified: 2026-05-18 German AGPLv3 open-source password manager (MaKleSoft, Bavaria), audited 3×, self-hostable, but hosted cloud uses Stripe + defunct Privacy Shield ref. Padloc is an open-source, end-to-end encrypted password manager developed by MaKleSoft, a German micro-company based at Meisenstr. 5 in Ansbach, Bavaria, with Martin Kleinschrodt as the contact person. It is the successor to the earlier "Padlock" project (which dates to around 2015) and was rebranded to Padloc around 2019. The product is published under the **GNU Affero General Public License (AGPLv3)**, with a commercial licence available for commercial use; self-hosting is free for personal use and non-profit organisations. Padloc states its data is end-to-end encrypted so neither MaKleSoft nor anyone else can read it, and the project advertises that it has been **audited by three independent groups of security experts**. For an EU-sovereignty audit, Padloc splits sharply into two products. The **self-hosted** path is excellent: AGPLv3 source on GitHub, a published security whitepaper, a German developer bound by GDPR, and full control of where the data lives. Run on Hetzner, OVHcloud or Scaleway and it is EU-owned, self-hosted, with no CLOUD Act exposure. The **hosted cloud** path is where the concerns sit. Padloc's public privacy policy still states that its third-party data processors "conform to the U.S.-E.U. Privacy Shield Framework", a framework that the Court of Justice of the EU invalidated in the Schrems II ruling in July 2020. A privacy policy that has not been updated to reflect five-year-old case law is itself a red flag. The policy also names **Stripe** (US) as the payment processor and does not disclose the cloud hosting location or a full sub-processors list. On that basis the hosted product carries material CLOUD Act exposure and an unresolved DPA / sub-processor gap. Pricing is freemium: a Free $0 tier; Premium at $3.49/month ($34.90/year); Family at $5.95/month; Team at $3.49/user/month; Business at $6.99/user/month; Enterprise custom. Best fit: privacy-conscious individuals and teams who will **self-host** Padloc on EU infrastructure. That is the configuration that earns the listing. Buyers considering the hosted cloud version should weigh the outdated privacy policy and prefer Proton Pass, Passbolt or Psono until MaKleSoft updates its sub-processor and hosting disclosures. **Compliance rationale:** Padloc is an AGPLv3 open-source password manager developed by **MaKleSoft** (a German micro-company at Meisenstr. 5, Ansbach, Bavaria; contact Martin Kleinschrodt), end-to-end encrypted and audited by three independent security groups, self-hostable for free for personal/non-profit use, but the **hosted cloud version has material gaps**: the public privacy policy still references the long-defunct 'U.S.-E.U. Privacy Shield Framework' (invalidated by Schrems II in July 2020), names Stripe (US) as payment processor, and does not disclose the cloud hosting location or a sub-processor list, so the hosted product carries material CLOUD Act exposure and an out-of-date privacy posture; self-hosted on EU infrastructure it is EU-owned, self-hosted, with no CLOUD Act exposure. ### Passbolt: https://euvetted.com/p/passbolt - Website: https://www.passbolt.com - Category: Password managers - Country of incorporation: Luxembourg - Hosting country: Luxembourg (Belvaux) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €5/month) - Founded: 2017 - Certifications: SOC2 - DPA: https://www.passbolt.com/terms/cloud/dpa - Sub-processors list: https://www.passbolt.com/terms/cloud/dpa - Last verified: 2026-05-11 Luxembourg-incorporated AGPLv3 open-source team password manager (Passbolt SA), SOC 2 Type II, self-hostable, used by LU/FR government. Passbolt is one of the cleanest open-source password-manager listings in this directory. The legal entity is **Passbolt SA** at 9 Avenue du Blues, L-4368 Belvaux, Luxembourg, incorporated as a formal company in 2017 after the concept originated within a Luxembourg digital agency in 2011. The product was conceived as a collaborative successor to KeePass, with a focus on team credentials sharing, RBAC, audit logging, and OpenPGP-based end-to-end encryption (1:1 keys per credential). Customer references include the **Luxembourg government IT body** and the **French Ministry of the Interior**. These are strong public-sector procurement signals that, combined with the open-source licensing, make Passbolt a natural fit for EU sovereign-procurement workflows. Compliance and transparency posture is best-in-class. Both the Community (free) edition AND the paid Business + Enterprise editions are released under the **GNU Affero General Public License v3 (AGPLv3)**. Buyers can fork the codebase, run audits internally, and never face vendor lock-in. The company commissions **independent third-party audits multiple times per year with all reports public**, including **SOC 2 Type II** attestation. Encryption is OpenPGP with 1:1 per-credential keys; no server operator (including Passbolt's own Cloud team) can decrypt customer vaults. Self-host deployment supports Docker, Kubernetes (Helm), and native installation on Ubuntu, Rocky Linux, and openSUSE. That gives full flexibility to run on Hetzner, OVHcloud, Scaleway, IONOS, STACKIT, or any other EU GPU / VPS infrastructure. Pricing is open-source-friendly and procurement-grade. **Community Edition is free** under AGPLv3 with unlimited users, core feature set, browser extensions, API, role-based access, with community support only. **Business** is €4.50 per user per month billed annually (10-user minimum) and adds tags, LDAP provisioning, SSO (Microsoft, Google, OpenID), account recovery, audit logs, and a packaged VM appliance with next-business-day email support. **Enterprise** is custom with 4-hour SLA, white-glove migration, custom development, and disaster-recovery consulting. Non-profits qualify for special pricing. Best fit: EU public-sector buyers, regulated industries (finance, defence, healthcare), teams that need SAML / LDAP SSO with audit-log compliance, and any procurement-grade buyer who wants AGPLv3 source-availability plus SOC 2 Type II attestation on a Luxembourg-incorporated open-source vendor. **Compliance rationale:** Passbolt SA (9 Avenue du Blues, L-4368 Belvaux, Luxembourg; incorporated 2017, concept since 2011) is a fully **AGPLv3 open-source** team password manager (even the paid Business tier is open source) built around OpenPGP end-to-end encryption, self-hostable by default with Cloud as a managed alternative, and audited by independent third parties several times a year with all reports public; **SOC 2 Type II** attested. Customer base includes the Luxembourg government IT body and France's Ministry of the Interior. Founder team active; investors are Luxembourg / EU (Luxinnovation, Scalefund, Yeast); €11M raised across 2020 (€3M) and 2024 (€8M); 30+ remote-first team. EU-owned, EU-hosted (Luxembourg), with no CLOUD Act exposure. ### pCloud: https://euvetted.com/p/pcloud - Website: https://www.pcloud.com - Category: File sharing - Country of incorporation: Switzerland - Hosting country: Luxembourg (Luxembourg) - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: freemium (from €5/month) - Founded: 2013 - Sub-processors list: https://www.pcloud.com/privacy-policy.html - Last verified: 2026-05-18 Swiss cloud storage with customer-elected EU (Luxembourg) or US (Texas) data residency; signature lifetime plans, 24M+ users. pCloud is a Swiss-incorporated cloud-storage product operated by **pCloud AG** (Baar, Switzerland) and founded in 2013 by Bulgarian engineers Tunio Zafer (CEO) and Anton Titov. Primary engineering and operations are based in Sofia, Bulgaria; the legal seat is Baar in canton Zug. The company reports 24M+ users across 130+ countries and has built its mainstream brand around a distinctive **lifetime plan** offering: one-time payments for permanent access (Premium ~€199 lifetime / 500 GB; Ultra ~€399 lifetime / 2 TB; Family Lifetime plans available), a marketing position no other directory vendor in this category matches. For an EU-sovereignty audit the structurally interesting feature is **customer-elected data residency**: at signup pCloud asks each user to pick between **Luxembourg (European Union)** and **Dallas, Texas (United States)** as the data-region for that account, and files stay in the chosen region. EU customers who pick Luxembourg get a full GDPR-jurisdiction posture; US customers (and any EU customer who picks Texas) end up under US-jurisdiction with the standard CLOUD Act exposure. The Swiss legal entity layered on top with EU adequacy keeps cross-border contracting clean. Where pCloud falls short of Proton Drive, Tresorit, and Internxt is that **zero-knowledge end-to-end encryption is NOT the default**: files are encrypted at rest with AES-256 and in transit with TLS, but pCloud itself holds the keys unless the customer adds **pCloud Crypto** as a paid add-on (~€3.99/month or one-time lifetime), in which case the encryption shifts to client-side and pCloud no longer holds the keys. Pricing in EUR: 10 GB free; Premium 500 GB ~€4.99/month (~€199 lifetime); Premium Plus 2 TB ~€9.99/month (~€399 lifetime); pCloud Crypto add-on for true zero-knowledge encryption is a separate purchase. 10-day money-back guarantee. Best fit: privacy-conscious consumers and SMBs who want a Dropbox alternative with EU data-residency option and the unique lifetime-plan economics; buyers requiring zero-knowledge encryption by default should choose Proton Drive, Tresorit, or Internxt instead. **Compliance rationale:** pCloud AG (Baar, Switzerland; founded 2013 by Tunio Zafer and Anton Titov; primary operations from Sofia, Bulgaria) lets customers pick **Luxembourg (EU) or Dallas, Texas (US)** at signup as the data-residency region (EU customers selecting Luxembourg get full EU jurisdiction under GDPR), plus a 24M+ user base and signature **lifetime plans** as a subscription escape hatch; **pCloud Crypto** is an optional paid add-on that provides true zero-knowledge encryption (without it, files are encrypted at rest but pCloud holds the keys); Swiss-incorporated with customer-elected EU data residency and disclosed sub-processors, but no publicly accessible DPA (the GDPR page directs buyers to contact sales@ to request one, making it on-request-only); zero-knowledge encryption is also not the default, requiring the paid pCloud Crypto add-on. ### pCloud Pass: https://euvetted.com/p/pcloud-pass - Website: https://www.pcloud.com/pass - Category: Password managers - Country of incorporation: Switzerland - Hosting country: Luxembourg - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: freemium (from €30/month) - Founded: 2022 - Last verified: 2026-05-11 Swiss zero-knowledge password manager (pCloud AG, Baar), client-side AES-256, free single-device tier, Luxembourg or US data residency. pCloud Pass is the standalone password-manager product from **pCloud AG**, a Swiss cloud-storage group headquartered in Baar (canton of Zug) and founded in 2013 by Tunio Zafer (CEO) and Anton Titov. The broader pCloud group reports more than 22 million users worldwide, primarily for its consumer cloud-storage product but increasingly through Pass and the wider Suite bundle. pCloud Pass launched in 2022 as a separate offering with zero-knowledge client-side encryption (passwords are encrypted on the user's device before any data leaves it, so pCloud has no ability to read customer vaults under any circumstance) and bundles features standard for the category: AES-256 encryption, password generation, secure sharing, auto-fill across browsers and mobile, biometric unlock, and recovery flows. For an EU-sovereignty audit the picture is nuanced. The legal entity (pCloud AG) is Swiss-incorporated, founder-controlled, and operates under Swiss law. Switzerland holds an EU adequacy decision so cross-border transfers between EU and CH need no SCCs. But pCloud operates two data centres globally, in **Luxembourg (EU)** and **Texas (USA)**, and the customer selects their data-residency region at signup. Buyers who choose EU placement get a clean Swiss-Luxembourg posture; buyers who choose US placement (or default to it without thinking) end up with their encrypted vault on US infrastructure. Per the strict-ownership stance the customer-side choice matters: with explicit EU placement, CLOUD Act exposure is `minor` (Swiss entity, EU at-rest); with US placement, it would be `material`. The score reflects the EU configuration; the Luxembourg-only data-residency point should be a procurement instruction on the actual listing page. Pricing is competitive and lifetime-friendly: the free tier covers one device with basic features; Premium is €29.99/year (annual) or available as a lifetime one-time payment (a distinguishing feature in the password-manager category, where most competitors are subscription-only). Best fit: pCloud Suite customers already on the platform, Swiss / EU SMBs wanting a Swiss-entity password manager without setting up a separate vendor relationship, and consumers who prefer lifetime pricing over subscription. Procurement-grade buyers needing the cleanest possible posture should prefer Proton Pass (CH, Proton Foundation-owned, no US DC option), Passbolt (FR, self-hostable open-source), or Psono (DE, open-source self-host), all covered elsewhere on this directory. **Compliance rationale:** pCloud Pass is the password-manager product of **pCloud AG** (Baar, Switzerland, founded 2013 by Tunio Zafer and Anton Titov, ~22M users across the broader pCloud group). It is Swiss-incorporated, founder-controlled, with client-side AES-256 zero-knowledge encryption so even pCloud cannot decrypt customer vaults, but pCloud operates two data centres (**Luxembourg AND Texas, USA**) and customer-data residency depends on the region the user selects at signup, so EU buyers must explicitly choose the Luxembourg region. Key gaps: pCloud Pass does not publish a standalone DPA (the Business Agreement contains no DPA section and no dedicated data-processing document exists for Pass specifically) and no sub-processor list was found at audit. With EU data-residency selected: Swiss-incorporated, EU-hosted, minor CLOUD Act exposure (Swiss entity, no US parent); without explicit EU placement the posture deteriorates materially. ### Pennylane: https://euvetted.com/p/pennylane - Website: https://www.pennylane.com - Category: Accounting - Country of incorporation: France - Hosting country: France - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2020 - Certifications: ISO27001 - Sub-processors list: https://www.pennylane.com/fr/legal/subcontractors - Last verified: 2026-05-12 French unicorn accounting + financial-management platform for SMEs and accountants; €4.3B valuation (Nov 2025), heavily US-VC-funded. **Pennylane** (Paris, France, founded 2020) has rapidly become one of Europe's most-talked-about accounting platforms: over **1 million users** including freelancers, SMEs (PME/ETI), and accounting firms, with a French-government-certified e-invoicing capability ahead of the 2026 PPF mandate. ISO 27001 certified. The product is genuinely French-built and French-operated, but the cap table is heavily US: **Sequoia Capital**, **DST Global**, **CapitalG** (Alphabet's growth fund), **Meritech Capital**, **TCV**, and **Blackstone Growth** are all on the books, with $770M+ raised across 8 rounds and a $4.3B valuation as of November 2025. For procurement-grade buyers this is the canonical "Made in France, capitalised in the USA" case study. **Compliance rationale:** **Pennylane** (Paris, France, founded 2020) is **ISO 27001 certified** and a French-government-approved electronic-invoicing platform; however the company has raised **$770M+ of mostly US capital** from Sequoia Capital, DST Global, CapitalG (Alphabet), Meritech Capital, TCV, and Blackstone Growth, making it the most US-VC-funded French SaaS in the accounting space; ownership signal flips to `eu_hq_us_funded` and CLOUD Act exposure to material via investor influence. ### Personio: https://euvetted.com/p/personio - Website: https://www.personio.com - Category: HR & people - Country of incorporation: Germany - Hosting country: Germany (Frankfurt) - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2015 - Certifications: ISO27001, SOC2 - DPA: https://www.personio.com/terms/#data-processing-addendum-dpa - Last verified: 2026-05-12 Munich-based HR flagship for European SMBs (founded 2015); ISO 27001 + SOC 2 + TISAX; ~$770M US-VC-funded. **Personio** (Munich, Germany, founded 2015) is the most-funded European HR-tech company ($770M+ across 8 rounds) and serves ~14,000 European SMBs (10-2,000 employees) with payroll, recruiting, time tracking, and people management. The compliance posture is strong: **ISO 27001 + SOC 2 + TISAX**, AWS Frankfurt hosting, EU-only data residency. The ownership-side caveat is straightforward: cap table is **US-VC-dominated**: Lightspeed Venture Partners (US) led Series C, with Index (UK/US), Accel (US), Greenoaks (US), and Lakestar (CH) all on the books. For DACH compliance buyers this is the canonical "German HR vendor, US capital" trade-off. **Compliance rationale:** **Personio** (Munich DE, founded 2015) is the European HR flagship (**ISO 27001 + SOC 2 + TISAX**, AWS Frankfurt hosting, ~14K customers) but $770M+ raised across 8 rounds led by **Lightspeed Venture Partners** (US), **Index Ventures** (US/UK), **Accel** (US), **Greenoaks** (US), giving US VCs durable control and CLOUD Act-relevant influence; ownership signal `eu_hq_us_funded`. ### Pexip: https://euvetted.com/p/pexip - Website: https://www.pexip.com - Category: Video conferencing - Country of incorporation: Norway - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2012 - DPA: https://www.pexip.com/legal/dpa - Sub-processors list: https://help.pexip.com/service/subprocessors.htm - Last verified: 2026-05-18 Norwegian Euronext-listed (Oslo Børs) video collaboration platform, defense + government grade; self-host or hyperscaler-cloud-of-choice. Pexip is a Norwegian video-collaboration platform operated by **Pexip AS** (Oslo, Norway Organisation Number 819 850 232), founded in 2012 and listed on **Oslo Børs (Euronext)** since 14 May 2020 (the first fully-virtual IPO during the pandemic). The product portfolio covers three lines: **Pexip Secure Meetings** (purpose-built for secure environments with custom integrations and on-premise deployment), **Pexip Connect** (meeting-room interoperability across Microsoft Teams, Zoom, Google Meet, Cisco), and **Pexip Engage** (appointment scheduling). The customer roster reads as a who's-who of defense and government video procurement: **NATO**, the **US Department of Veterans Affairs**, the **US Air Force**, the **US Department of the Treasury**, parts of the **Irish government**, and **Airbus**. Strategic partners: Microsoft, Google, Zoom, Cisco, HP, Logitech, NVIDIA. For procurement-grade EU buyers the differentiator is the **flexible deployment model**: Pexip can be deployed self-hosted on the customer's own infrastructure, in the customer's own Azure / GCP / AWS / OCI subscription, in a hybrid configuration, or as a managed SaaS, meaning a regulated buyer can run the entire Pexip stack inside their security perimeter on EU infrastructure (Hetzner, OVHcloud, Scaleway, IONOS, STACKIT, T Cloud Public) and meet the strictest sovereignty requirements. The privacy notice (last updated 11 November 2025) names three controllers: **Pexip AS** (Norway, primary), **Pexip Inc.** (USA, Delaware File Number 5215317, for US-government contracting), and **Pexip Belgium** (Belgium Enterprise number 0537.590.925, for EU-customer contracting where Belgium incorporation is preferred). The dual NO + BE EU legal-entity structure plus the US Inc for US-government customers is a sophisticated procurement-aware architecture. Pricing is enterprise-grade and sales-engaged. Pexip does not publish a self-serve tier price. Best fit: government, defense, judicial, healthcare, financial-services, and other regulated mid-market and enterprise buyers who need video conferencing inside a controlled security perimeter; organisations evaluating Teams / Zoom / Webex alternatives where vendor lock-in to a US hyperscaler is unacceptable; multi-cloud deployments where a single video platform must work across Azure + AWS + GCP + on-prem. The `material` CLOUD Act exposure flag reflects the US Inc entity for US-government contracting and the SaaS-on-hyperscaler default; self-host on EU infrastructure removes the exposure entirely. **Compliance rationale:** Pexip AS (Oslo, founded 2012, Norway Organisation Number 819 850 232) is a Norwegian video-collaboration platform listed on Oslo Børs since May 2020: Euronext-listed, EEA jurisdiction, no US-PE majority on record. The product is uniquely deployable as **self-hosted on customer infrastructure** or on Azure / GCP / AWS / hybrid / managed SaaS. Defense-grade customers include NATO, US Department of Veterans Affairs, US Air Force, US Treasury, the Irish and US governments, and Airbus. EU-adequate jurisdiction (Norway EEA), public DPA with disclosed sub-processors; CLOUD Act exposure held at `material` because the managed SaaS defaults to hyperscaler-of-customer-choice and a US Delaware entity (Pexip Inc.) handles US-government contracting; self-host on EU infrastructure removes the exposure entirely. **Sub-processors mapped:** 15 total, 11 US-owned - GitHub Copilot (United States): Bug investigation tooling [US-owned] - Google (United States): Calendar synchronization (Pexip Engage / Skedify) [US-owned] - Google Cloud Platform (United States): Infrastructure / PoPs (Pexip Hosted Cloud) [US-owned] - Mailchimp / Mandrill (United States): Email notifications (Pexip Engage / Skedify) [US-owned] - Microsoft 365 Copilot (United Kingdom): Zendesk Ticket Connector [US-owned] - Microsoft Azure (United States): Teams CVI service PoPs (Pexip Hosted Cloud) [US-owned] - Microsoft Azure (NL region) (Netherlands): Hosting (Pexip Engage / Skedify) [US-owned] - NetApp (United Kingdom): Database support (Pexip Hosted Cloud) [US-owned] - Sentry.io (United States): Error monitoring [US-owned] - Twilio (United States): Email and SMS services [US-owned] - Zendesk (United States): Helpdesk support [US-owned] - Cronofy (United Kingdom): Calendar sync (Pexip Engage / Skedify) - Elastic (Netherlands): Service log collection (Pexip Hosted Cloud) - Mividas (Sweden): Room management support - Spryng BV (Netherlands): SMS (Pexip Engage / Skedify) ### Pipedrive: https://euvetted.com/p/pipedrive - Website: https://www.pipedrive.com - Category: CRM - Country of incorporation: Estonia - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid (from €13/month) - Founded: 2010 - Certifications: SOC2 - DPA: https://www.pipedrive.com/en/privacy/dpa - Sub-processors list: https://www.pipedrive.com/en/subprocessors - Last verified: 2026-05-10 Estonian-rooted sales CRM with a 300+ Tallinn engineering hub, but US-PE-controlled (Vista Equity) and AWS-hosted across EU and US regions. Pipedrive is an Estonian-rooted sales CRM founded in Tallinn in 2010 by Timo Rein, Urmas Purde, Ragnar Sass, Martin Henk, and Martin Tajur. The product targets SMB and mid-market sales teams with pipeline management, deal automation, AI assistants, and a 400+ integration ecosystem; the company reports more than 100,000 paying customers across 179 countries, with the engineering and product hub still based in Tallinn (300+ employees from 30+ nationalities) and global operations spanning Lisbon, Prague, Berlin, New York, and Florida. For an EU-sovereignty-focused directory, Pipedrive is a tricky listing because the brand identity (Estonian unicorn) is in tension with the cap-table reality. In November 2020, Vista Equity Partners, a US private-equity firm headquartered in Austin, Texas, took a majority investment, valuing the company at US$1.5 billion. Earlier investors (Bessemer Venture Partners, Insight Partners, Atomico, DTCP, Rembrandt Venture Partners) remained as minority shareholders. Customer data is hosted on Amazon Web Services in regions across Europe AND the United States: Pipedrive's own support docs confirm that "Pipedrive accounts are hosted in AWS data centers in Europe and the US" with new sign-ups assigned by region, and historical Rackspace data centres in Frankfurt, Chicago, and London have been migrated under AWS management. Per our strict CLOUD Act stance (parent jurisdiction matters per Schrems II / Microsoft Ireland v US), this triggers material CLOUD Act exposure despite the EU-rooted brand and an SOC 2-attested security program: US-PE-majority ownership (eu_hq_us_funded) combined with AWS hosting across EU and US regions are the two key sovereignty gaps here. Pricing in 2026 starts at the Essential plan at US$14/user/month with annual billing (~€13/user/month) and a 14-day no-credit-card free trial; there is no permanent free tier. The product is in 25+ languages including English, Estonian, German, French, Spanish, Portuguese, Italian, Russian, and Polish. Best fit: SMB and mid-market sales teams that want a polished pipeline-CRM and either tolerate a US-PE-controlled vendor on AWS or specifically want EU-sourced engineering. Procurement teams with strict EU-sovereignty requirements should look at Teamleader (BE), Salesflare (BE), weclapp (DE), or SuperOffice (NO) instead, listed below in this category. **Compliance rationale:** Estonian-rooted CRM with a 300+ Tallinn engineering hub and a named sub-processors page, but Vista Equity Partners (US private equity) has held the majority since November 2020 and customer accounts are hosted on AWS across Europe and the United States. AWS is a US-owned hyperscaler regardless of region, and customers may end up on US-region infrastructure depending on signup geography; the combination of US-PE majority ownership and AWS hosting triggers material CLOUD Act exposure and places ownership at eu_hq_us_funded rather than eu_owned. **Sub-processors mapped:** 22 total, 15 US-owned - Amazon Web Services, Inc. (United States): Hosting and CDN services in Europe and the USA [US-owned] - Cloudflare, Inc. (United States): Content distribution, security, abuse prevention, DNS [US-owned] - Forge Technology, Inc. (Paragon) (United States): Embedded integration platform for Marketplace apps [US-owned] - Intercom R&D Unlimited Company (Ireland): Customer support conversations processor [US-owned] - OpenAI Ireland Limited (Ireland): AI features (email summarization and generation) [US-owned] - Pipedrive Germany GmbH (Germany): Pipedrive affiliate sub-processor [US-owned] - Pipedrive Inc. (United States): Pipedrive affiliate sub-processor [US-owned] - Pipedrive Ireland Ltd (Ireland): Pipedrive affiliate sub-processor [US-owned] - Pipedrive Latvia SIA (Latvia): Pipedrive affiliate sub-processor [US-owned] - Pipedrive OÜ (Estonia): Pipedrive affiliate sub-processor [US-owned] - Pipedrive Portugal Sociedade Unipessoal, Lda (Portugal): Pipedrive affiliate sub-processor [US-owned] - Pipedrive Prague s.r.o. (Czechia): Pipedrive affiliate sub-processor [US-owned] - Pipedrive UK Ltd (United Kingdom): Pipedrive affiliate sub-processor [US-owned] - Rackspace GmbH (Switzerland): Support services for AWS [US-owned] - Twilio SendGrid, Inc. (United States): Smart Email BCC feature provider [US-owned] - Amplify5 ltd (United Kingdom): Customer support conversations processor - Atlassian PTY Ltd. (Loom) (Australia): Image/video/attachment sharing in customer support - Dealfront Finland Oy (Finland): Web Visitors feature provider - Fullview ApS (Denmark): Screen sharing and co-browsing for support - Growster SAS (Surfe) (France): Data enrichment and lead intelligence - Messagebird UK Ltd. (Bird) (United Kingdom): Live Chat feature in LeadBooster - Tet SIA (Latvia): Hosting services for the Campaigns feature ### Pirsch Analytics: https://euvetted.com/p/pirsch - Website: https://pirsch.io - Category: Web analytics - Country of incorporation: Germany - Hosting country: Germany (Gunzenhausen) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €6/month) - Founded: 2020 - DPA: https://pirsch.io/dpa - Sub-processors list: https://pirsch.io/privacy - Last verified: 2026-05-10 German cookieless server-side web analytics on Hetzner Gunzenhausen with bilingual public DPA and Schrems II-aligned posture. Pirsch is a Rheda-Wiedenbrück-based privacy-focused web analytics product operated by Emvi Software GmbH (Nickelstraße 1b, 33378 Rheda-Wiedenbrück). The product is built around server-side, cookieless tracking and explicitly markets itself as "Made and hosted with ❤️ in Germany, Europe" with GDPR, CCPA, PECR, and Schrems II compliance positioning, exactly the BSI-friendly profile that procurement-oriented German buyers tend to gravitate to as a Google Analytics alternative. Customer analytics data sits on a Hetzner Online GmbH cluster in Gunzenhausen, Germany. The privacy policy is unusually transparent for a small vendor: it names every sub-processor with full address, including AWS EMEA SARL (Luxembourg) for transactional email and Google Cloud EMEA Limited (Dublin, Ireland) for workspace/communications, meaning the hosting graph is EU-region but uses US-owned hyperscalers for ancillary services. The remaining sub-processors are Stripe Inc. (San Francisco) for payments, Intuition Machines Inc. (San Francisco) for CAPTCHA verification, and Datev eG (Nuremberg) for tax-document exchange. US transfers are documented under the Standard Contractual Clauses of the European Commission per Art. 46 GDPR. The DPA is publicly available in both English and German via the footer. Pricing in EUR is straightforward: the Standard plan starts at €6/month with 50 websites, unlimited members, and unlimited data retention; a 30-day free trial requires no credit card and SEPA Direct Debit is supported. There is no permanent free tier, so `pricing_tier` is `paid`. Best fit: German and DACH SMBs, agencies, and developers replacing Google Analytics with a cookie-banner-free Schrems-II-aligned tool, who need a credible "data stays in Germany" answer plus a self-serve DPA. Buyers who require open source or a fully self-hostable option should prefer Plausible; buyers who can accept Cloudflare/CDN exposure but want a richer feature set should benchmark against Matomo Cloud. **Compliance rationale:** German GmbH (Emvi Software) running customer analytics on Hetzner in Gunzenhausen with cookieless server-side tracking, a publicly-linked bilingual DE/EN DPA, and SCC-covered US sub-processors limited to ancillary functions (Stripe payments, Intuition Machines CAPTCHA) plus AWS-EU and GCP-EU for email/workspace. EU-owned and EU-hosted with a public DPA, and the US sub-processors (Stripe payments, Intuition Machines CAPTCHA, AWS-EU SES email, GCP-EU workspace) are all ancillary and off the customer-analytics data-at-rest path (core analytics on Hetzner Gunzenhausen), so under a data-at-rest definition CLOUD Act exposure is none. **Sub-processors mapped:** 6 total, 4 US-owned - Amazon Web Services EMEA SARL (Luxembourg): AWS SES email sending (only when contacting or registering); ancillary [US-owned] - Google Cloud EMEA Limited (Ireland): Google Workspace for appointment/contact management and email; ancillary [US-owned] - Intuition Machines, Inc. (United States): CAPTCHA service (bot detection); ancillary [US-owned] - Stripe, Inc. (United States): Payment services; ancillary [US-owned] - Datev eG (Germany): Software for communication with tax advisors/authorities - Hetzner Online GmbH (Germany): Data center / web hosting (visitor data) ### Plandisc: https://euvetted.com/p/plandisc - Website: https://plandisc.com - Category: Project management - Country of incorporation: Denmark - Hosting country: Sweden - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: paid - Founded: 2012 - DPA: https://plandisc.com/hubfs/Compliance/DPA%20(English).pdf - Sub-processors list: https://plandisc.com/en/gdpr - Last verified: 2026-05-11 Danish circular annual-planner (Plandisc, Højbjerg, 2012), Visma-owned, hosted on Visma Private Cloud Sweden, ISAE 3000. Plandisc is a Danish-originated **circular annual planner** (the world's first digital take on the cyclical/rolling planner format) founded in 2012 and headquartered at Axel Kiers Vej 5A, 8270 Højbjerg (the Aarhus suburb), Denmark. Co-founder Torben Stigaard serves as Managing Director. The product visualises annual planning as a disc divided into colour-coded rings representing departments, responsibilities, teams, or target groups, and is widely adopted in Danish and broader Nordic education, marketing, finance, and public-sector teams. Originally a school planning tool, Plandisc expanded across industries and was acquired by **Visma Group** (Norway), the same Nordic software conglomerate that owns Teamleader (Belgium, audited earlier in this directory). For an EU-sovereignty audit Plandisc inherits the Visma ownership pattern. The operating entity is Danish, all customer data is hosted on **Visma Private Cloud** (explicitly an EU-owned data centre in Sweden) and the company carries Grant Thornton **ISAE 3000** and **GDPR 2024** attestation badges; Denmark and Sweden are both EU members with full GDPR coverage and no SCC requirements for cross-border transfers within the EEA. The complication is one layer up: Visma's group cap table includes Hg, Cinven, **TPG (US)**, GIC, and Intermediate Capital Group, so beneath the Norwegian-owned Visma wrapper there is meaningful US-PE exposure that procurement-grade buyers should understand. The data is EU-hosted with ISAE 3000 attestation, but the ownership chain does not meet a zero-US-PE threshold. Pricing is enterprise / volume-negotiated; specific tiers were not captured at audit. Best fit: Danish and Nordic schools, associations, marketing teams, and finance departments that want a unique visual planning tool with EU-only hosting and ISAE 3000 attestation, and accept Visma Group as the corporate counter-party. Procurement-grade EU-only buyers requiring an ownership chain with zero US-PE involvement should look at Stackfield or MeisterTask in the same category. **Compliance rationale:** Plandisc (Højbjerg, Denmark, Axel Kiers Vej 5A, 8270; founded 2012; co-founder Torben Stigaard as MD) is the world's first digital **circular annual-planner**, used widely in Danish and Nordic education, marketing, and public-sector teams; acquired by **Visma Group (Norway)** with hosting on **Visma Private Cloud in Sweden** (EU-owned) and Grant Thornton ISAE 3000 + GDPR 2024 attestations. Same Visma-parent pattern as Teamleader: EU-hosted and operationally clean, but Visma's PE consortium includes US TPG capital at the group layer, introducing minor CLOUD Act exposure at the ownership level that procurement-grade buyers should assess. ### Planio: https://euvetted.com/p/planio - Website: https://plan.io - Category: Git hosting - Country of incorporation: Germany - Hosting country: Germany (Falkenstein) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €19/month) - Founded: 2009 - Last verified: 2026-07-21 Berlin-based hosted Redmine (Planio GmbH) with unlimited Git and SVN repositories, on the company's own German servers; account-gated Art. 28 DPA. Planio is a hosted project-management platform built on the open-source **Redmine** framework, operated by **Planio GmbH** in Berlin. Founded in 2009 by Jan Schulz-Hofen and run as a bootstrapped, founder-owned company, it bundles issue tracking, agile boards, a help desk, team chat, and file storage with **unlimited hosted Git and Subversion repositories** governed by Redmine's role-based permissions and reachable over HTTPS or SSH. It is best understood as a project-management tool with integrated version control rather than a GitHub-style forge. For an EU-sovereignty audit Planio's posture is strong on the fundamentals: it is an EU-owned German GmbH, and all customer data is kept on the company's own servers in Germany, in an ISO 27001-certified Hetzner facility in the Vogtland region, with an encrypted backup to a second data centre in Frankfurt. Planio states a deliberate policy of avoiding third-party cloud services for customer data, so there is no US sub-processor and no CLOUD Act exposure: [[planio.cloud_act]]. A commissioned data-processing agreement under Art. 28 GDPR is provided free of charge and can be signed online, but it lives inside the logged-in customer account rather than on a public page, which is the single factor holding the compliance score at 4/5 for buyers who need to review the DPA before signing up. Pricing is a freemium model: a free Bronze tier (1 project, 2 users, 1 GB) up to paid plans from [[planio.price_from]] per month, all including unlimited Git and SVN repositories. The important trade-off versus a dedicated forge is feature scope: Planio has no pull-request or merge-request review workflow, no built-in CI/CD, and no package or container registry, because its centre of gravity is Redmine project management. Best fit: German and European teams, agencies, and public-sector buyers who want issue tracking and hosted repositories in one EU-owned, German-hosted tool, and who value data residency over forge-specific developer features. **Compliance rationale:** Planio is a **Berlin-based hosted Redmine platform** operated by **Planio GmbH**, a founder-owned, bootstrapped German company (managing director Jan Schulz-Hofen), that bundles hosted **Git and Subversion repositories** into a project-management product. Signals: EU-owned German GmbH, all data on the company's own servers in Germany (an ISO 27001-certified Hetzner facility in the Vogtland region, with encrypted backup to a second data centre in Frankfurt), no US ownership and no US sub-processors: [[planio.cloud_act]]. A commissioned data-processing agreement under Art. 28 GDPR is offered free of charge, but it is reachable only inside a logged-in customer account rather than published openly, which caps the score at 4/5. Note that Git here is repository hosting inside a Redmine issue-tracker, not a GitHub-style forge: there is no pull-request review flow, CI/CD, or package or container registry. **Sub-processors mapped:** 1 total, 0 US-owned - Hetzner Online GmbH (Germany): Server hosting / colocation (ISO 27001-certified facility, Vogtland) and encrypted off-site backup (Frankfurt) ### Plausible Analytics: https://euvetted.com/p/plausible - Website: https://plausible.io - Category: Web analytics - Country of incorporation: Estonia - Hosting country: Germany (Falkenstein) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €8/month) - Founded: 2018 - DPA: https://plausible.io/dpa - Sub-processors list: https://plausible.io/privacy - Last verified: 2026-05-10 Estonian-incorporated privacy-first Google Analytics alternative, bootstrapped, hosted on Hetzner Falkenstein, open source. Plausible Analytics is the textbook procurement-friendly Google Analytics alternative: an Estonian-incorporated, bootstrapped, profitable team-of-ten that runs the entire product on European infrastructure and publishes a clean, public DPA. The legal entity is Plausible Insights OÜ in Tartu, Estonia. Uku Taht launched the project in December 2018 and Marko Saric joined as co-founder in 2020. The company is self-funded, has more than 17,000 paying subscribers, and explicitly rejects outside investment, keeping the cap table firmly EU-owned. The product is a lightweight, cookieless analytics script (~1 KB, ~54× smaller than GA4) that does not use persistent identifiers; daily salts are rotated and deleted, raw IPs and User-Agents are never stored, and no cookie banner is required for visitor analytics. Customer analytics data is "kept fully secured, encrypted and hosted on 100% renewable-energy-powered servers in Falkenstein, Germany"; Hetzner is the named hosting provider. Other product sub-processors are EU-only as well: Bunny CDN (Slovenia) and UpCloud (Finland). The small set of non-EU sub-processors is scoped to ancillary functions and covered by Standard Contractual Clauses: Paddle for billing (UK), Postmark for transactional email (US), and Algolia for documentation search (US, added May 2026). Optional integrations (Google, Help Scout) only engage if a customer turns them on. Pricing starts at €8/month (billed in USD at $9) for the Starter plan with 10k pageviews and three years of data retention; a 30-day free trial requires no credit card. Plausible is also fully open source (AGPL on GitHub) and self-hostable, making it a credible answer for buyers who want the option to escape SaaS entirely. Best fit: privacy-first websites, EU agencies, regulated SMBs, and open-source-friendly engineering teams replacing GA4, and the strongest baseline reference point on this directory for how a "no CLOUD Act drama" web analytics stack actually looks. **Compliance rationale:** Estonian OÜ, bootstrapped and self-funded, runs the entire customer analytics stack on EU-incorporated infrastructure (Hetzner Falkenstein DE, Bunny SI, UpCloud FI) with no customer data at rest on a US-owned cloud; the publicly-linked DPA, AGPL open-source codebase, and self-hosting option round out a strong EU-owned, EU-hosted posture with no CLOUD Act exposure on the customer-data path. The only US-owned sub-processors (Postmark for system email, Algolia for docs search, hCaptcha for signup anti-spam) are ancillary, transient and SCC-covered (none touches analytics data at rest), so under a data-at-rest definition CLOUD Act exposure is none. **Sub-processors mapped:** 7 total, 3 US-owned - Algolia, Inc. (United States): Documentation search (ancillary, added May 2026, SCC-covered) [US-owned] - hCaptcha (Intuition Machines, Inc.) (United States): Anti-spam on account registration (ancillary; signup path, not analytics) [US-owned] - Postmark (ActiveCampaign, LLC) (United States): Transactional emails and scheduled reports (ancillary, SCC-covered) [US-owned] - BunnyWay (Bunny.net) (Slovenia): Content delivery network (CDN), DNS, DDoS protection - Hetzner Online GmbH (Germany): Server hosting and storage of visitor analytics data (Falkenstein, Germany) - Paddle.com Market Ltd (United Kingdom): Payment processing / merchant of record - UpCloud (Finland): Database hosting and storage of data exports ### Posteo: https://euvetted.com/p/posteo - Website: https://posteo.de - Category: Private email - Country of incorporation: Germany - Hosting country: Germany (Berlin) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €1/month) - Founded: 2009 - Sub-processors list: https://posteo.de/en/site/privacy_policy - Last verified: 2026-05-12 Berlin one-person-shop privacy email at €1/mo (Posteo e.K., since 2009); anonymous signup, BSI TR-03108 certified. **Posteo** (Berlin, founded 2009, Posteo e.K., owner Patrik Löhr) is the small-and-cult European privacy email service: **€1/mo flat-rate for 4GB**, **anonymous signup** and **anonymous payment** options (postal cash, no payment-to-account link kept), all servers in German data centres, **100% renewable energy** from Green Planet Energy, no advertising, no profiling. **BSI TR-03108 v2** certified (Bundesamt für Sicherheit in der Informationstechnik standard for secure email transport). Supports PGP and S/MIME end-to-end encryption. Publishes annual transparency reports for authority requests. The Guardian and Stiftung Warentest both cite Posteo as a global leader in secure email. Single-vendor concentration risk because of the tiny team, but for personal privacy-first use this is the cleanest possible pick. **Compliance rationale:** **Posteo e.K.** (Berlin DE, since 2009) is a small founder-owned privacy-maximalist email service: **€1/mo flat**, **anonymous signup + anonymous payment**, German data centres, 100% renewable energy (Green Planet Energy), **BSI TR-03108 v2** certified for secure email transport, public transparency reports for authority requests; PGP + S/MIME end-to-end encryption support; EU-owned, EU-hosted, no CLOUD Act exposure. ### PostHog: https://euvetted.com/p/posthog - Website: https://posthog.com - Category: Web analytics - Country of incorporation: United Kingdom - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: freemium (from €0/month) - Founded: 2020 - DPA: https://posthog.com/dpa - Sub-processors list: https://posthog.com/subprocessors - Last verified: 2026-05-18 London-based open-source product analytics (PostHog, 2020, Y Combinator W20), US + EU Frankfurt cloud regions, MIT-licensed self-host. PostHog is the open-source product-analytics platform founded in **2020 by James Hawkins and Tim Glaser** in London, a Y Combinator Winter 2020 batch alumnus that built one of the most successful B2B-software launches on Hacker News since 2012. The product combines product analytics, session replay, feature flags, A/B testing, surveys, heatmaps, data warehouse, and customer data infrastructure into a single integrated platform; PostHog reports that 98% of customers use the free tier and operates entirely on usage-based pricing ($0.00005 per event for analytics, $0.005 per session-replay recording). For an EU-sovereignty audit PostHog falls into the `eu_hq_us_funded` ownership tier. The HQ is London (UK post-Brexit jurisdiction with EU adequacy decision), but the cap table is heavily US-VC: **Y Combinator** (the canonical Silicon Valley accelerator) led the initial investment and **GV (Google Ventures)** led the $12M Series A; notable angels include Jason Warner (former GitHub CTO), Solomon Hykes (Docker founder), and David Cramer (Sentry founder). For the managed cloud, customers pick between **US (Virginia)** and **EU (Frankfurt)** hosting regions at signup; EU-region customers get GDPR-aligned residency, but the vendor's UK jurisdiction + US-VC ownership + AWS Frankfurt hosting (under PostHog's parent entity) keep the CLOUD Act flag at `material` under the strict-ownership stance. The **self-host edition is the procurement-grade path** for EU buyers. PostHog publishes the full server-side stack as open source on GitHub under a source-available licence; running it on Hetzner / OVHcloud / Scaleway / STACKIT / private DC delivers full sovereignty by construction. Pricing: free tier (extremely generous, most customers stay on free); usage-based above for both cloud and self-host commercial deployments. Best fit: product teams that want an Amplitude / Mixpanel / Heap replacement with permissive self-host option and don't require an EU-incorporated vendor entity. **Compliance rationale:** PostHog (founded 2020 by **James Hawkins** and **Tim Glaser** in London, **Y Combinator Winter 2020** batch) is the open-source product-analytics platform with managed-cloud regions in **US (Virginia)** and **EU (Frankfurt)** plus a self-host edition for full control, but the cap table is anchored by **Y Combinator + Google Ventures (GV)** with $12M+ raised from US sources (plus angels Jason Warner / Solomon Hykes / David Cramer); UK post-Brexit jurisdiction + heavy US-VC funding → `eu_hq_us_funded` ownership with `material` CLOUD Act exposure for the managed-cloud product; the **self-host path on EU infrastructure removes US-vendor exposure entirely**. **Sub-processors mapped:** 4 total, 4 US-owned - Amazon Web Services, Inc. (Germany): Cloud storage of PostHog Cloud data [US-owned] - Modal Labs, Inc. (Germany): Serverless compute infrastructure for isolated code execution [US-owned] - PlanetScale, Inc. (Germany): Operations and performance monitoring of databases [US-owned] - Wiz, Inc. (Germany): Security vulnerability management and detection [US-owned] ### PowerOffice Go: https://euvetted.com/p/poweroffice-go - Website: https://www.poweroffice.no - Category: Accounting - Country of incorporation: Norway - Hosting country: Netherlands - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid (from €30/month) - Founded: 1998 - Certifications: ISO27001 - DPA: https://www.poweroffice.no/tjenestevilkar-og-databehandleravtale - Sub-processors list: https://www.visma.com/trust-centre-products/poweroffice-go - Last verified: 2026-06-12 Norwegian cloud accounting/ERP for SMBs & accounting firms (Bodø, est. 1998); 75% Visma-owned, runs on Microsoft Azure EU. **PowerOffice Go** (operated by **PowerOffice AS**, Bodø, Norway, founded 1998) is one of Norway's leading cloud accounting and light-ERP platforms, used by 100,000+ businesses and 250,000+ users and consistently top-ranked for customer satisfaction in Norwegian accounting software (2020–2025). It is built modularly: accounting + invoicing, payroll, travel/expense, time registration, holiday/absence, so a freelancer can start on one module and an accounting firm can run hundreds of clients from a single console (500+ partner agencies). The product is developed, run and supported entirely from Bodø, the DPA is genuinely public (Appendix 2 of the standard service terms), and security posture is solid: ISO 27001, ISAE 3402 Type II, role-based access, 2FA, hashed passwords, delivered via the Visma Cloud Delivery Model. The procurement caveats are ownership and infrastructure, not the product. PowerOffice was acquired to a **75% majority by Visma** in 2019 (the founder sold for NOK 2.4 billion), placing it inside the Visma group whose own cap table is Hg Capital (UK PE) majority with **TPG (US PE)** as a material co-investor. And production hosting is **Microsoft Azure in an EU/EEA (Netherlands) region**: EEA at rest, but a US-owned hyperscaler, with Twilio/SendGrid (US) handling email. So: a Norwegian local hero on paper, but with a US-PE ownership chain and a US-owned cloud substrate underneath. Norwegian Bookkeeping Act storage obligations are met via EEA hosting; the data is not exported outside the EEA without SCCs/controller approval. **Compliance rationale:** **PowerOffice AS** (Bodø, Norway, founded 1998) publishes a free public DPA + a transparent Visma trust-centre sub-processor list and is ISO 27001 certified (plus ISAE 3402 Type II attestation), but production runs on **Microsoft Azure (EU/EEA, Netherlands region), a US-owned hyperscaler holding data at rest** plus Twilio/SendGrid (US) for email, and the company is **75% owned by Visma since 2019** (Visma itself is Hg-majority with TPG US-PE co-investor); the US sub-processors at rest + US-PE ownership chain cap it at 3/5 with material CLOUD Act exposure despite the otherwise clean Norwegian operating posture. ### PrestaShop: https://euvetted.com/p/prestashop - Website: https://www.prestashop.com - Category: E-commerce - Country of incorporation: France - Hosting country: France - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: freemium - Founded: 2007 - DPA: https://prestashop.com/terms-prestashop-hosted/ - Sub-processors list: https://prestashop.com/prestashop-account-privacy/ - Last verified: 2026-05-12 French open-source e-commerce with hosted SaaS option; parent group Fortidia is an Oaktree Capital portfolio company. **PrestaShop** (Paris, est. 2007, **250,000+ live sites** per their homepage) is the historical French Magento-equivalent: a free open-source e-commerce platform plus a paid **PrestaShop Hosted** offering for merchants who want managed hosting. Acquired by **MBE Worldwide** (Italy) in November 2021; MBE rebranded as **Fortidia** in 2024; Fortidia is a **portfolio company of US-based Oaktree Capital Management**. So the operating entity is French and the brand is French, but the ultimate beneficial owner is a US asset manager, relevant for procurement-grade CLOUD Act assessment. Best fit for merchants who want full platform control with French community + ecosystem; PrestaShop Hosted targets those who want the OSS power without the ops burden. Closer to mid-market than to SMB Shopify-Basic class. **Compliance rationale:** **PrestaShop SA** (Paris, 82 Avenue du Maine 75014, SIREN 497 916 635, founded 2007) is French-operating but sold to **MBE Worldwide** (Italy) November 2021; MBE **rebranded as Fortidia in 2024**, and Fortidia is a **portfolio company of Oaktree Capital Management** (US asset manager), so ultimate beneficial ownership is US, giving `eu_hq_us_funded` ownership signal and material CLOUD Act exposure. DPA and sub-processors list are not publicly surfaced and must be requested via sales. ### Prismic: https://euvetted.com/p/prismic - Website: https://prismic.io - Category: Headless CMS - Country of incorporation: France - Hosting country: United States (Paris) - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium (from €7/month) - Founded: 2013 - DPA: https://prismic-main.cdn.prismic.io/prismic-main/adegtZ1ZCF7ETB2J_Public-PrismicDPA-self-servicerev08.20260408.docx.pdf - Sub-processors list: https://prismic-main.cdn.prismic.io/prismic-main/adeZn51ZCF7ETBov_PrismicSubprocessorsListpub-rev15-202603-cntLEGGDPRCMPProviders-Public.pdf - Last verified: 2026-05-12 Paris headless CMS / page-builder (founded 2013); Slice Machine + Next.js / Nuxt / SvelteKit focus; from €7/mo. **Prismic** (Paris, France, founded 2013) is a developer-and-marketer-focused headless CMS with a distinctive **Slice Machine** + **Page Builder** approach: slices are reusable content components that bridge dev / marketer workflows in a way most pure-API CMSs don't. Strong fit for **Next.js, Nuxt, SvelteKit** projects. Free tier available; paid tiers from ~€7/mo. Cap table is mostly European with US participation in earlier rounds (Notion Capital UK et al), no identified US-PE majority, placing Prismic in `ownership_signal: eu_owned`. No public ISO 27001 or SOC 2 attestation on marketing site at time of research; DPA and sub-processor disclosure are also unverified; verify directly with the vendor before procurement. **Compliance rationale:** **Prismic** (Paris FR, founded 2013) is a developer-and-marketer-focused headless CMS with **Slice Machine** + visual page-builder differentiator; cap table is European-leaning (Notion Capital UK with US participation in earlier rounds) without identified US-PE majority, so `ownership_signal: eu_owned`; no explicit ISO 27001 / SOC 2 attestation on marketing site; DPA and sub-processor disclosure verification pending. ### Proton Drive: https://euvetted.com/p/proton-drive - Website: https://proton.me/drive - Category: File sharing - Country of incorporation: Switzerland - Hosting country: Switzerland (Geneva) - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: freemium (from €4/month) - Founded: 2014 - Certifications: ISO27001, SOC2 - DPA: https://proton.me/legal/dpa - Sub-processors list: https://proton.me/legal/privacy - Last verified: 2026-05-18 Swiss zero-knowledge encrypted cloud (Proton AG, non-profit-foundation-controlled), 11,496 owned servers, ISO 27001 + SOC 2, 5 GB free. Proton Drive is the encrypted cloud-storage product within the **Proton AG** ecosystem (Mail, Drive, VPN, Pass, Calendar, Docs, Sheets, SimpleLogin), headquartered at Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland. Founded in 2014 by Andy Yen and a team that originally met at CERN, Proton serves more than 100 million users worldwide and runs the most singular ownership structure in the directory: as of June 2024 the **non-profit Proton Foundation** (Swiss, Geneva; trustees include Andy Yen, Antonio Gambardella, Carissa Véliz, Tim Berners-Lee, and Dingchao Lu) is the controlling shareholder of Proton AG. The company explicitly takes **no venture capital**, its non-profit structure is designed to permanently prevent takeover attempts, and there is no path for a US-PE / US-VC investor to influence governance. Compliance posture is exceptional. Proton holds **ISO/IEC 27001:2022** with the ISMS scope covering all product lines (Mail, Drive, Pass, VPN, Calendar, SimpleLogin) and **SOC 2 Type II**. The infrastructure footprint is also unusual: by February 2025 Proton had **11,496 servers across 117 countries, all owned and operated by Proton itself**, not rented from hyperscalers. Primary processing is in Switzerland; named US sub-processors are limited to ancillary functions (Zendesk for customer support, Chargebee for billing automation, Stripe and PayPal for card payments, Atlassian for support-data storage) and do not touch zero-knowledge-encrypted customer files. Standard Contractual Clauses, Binding Corporate Rules, and certifications govern any third-country transfers. **Switzerland is not in the EU but holds an EU adequacy decision under Art. 45 GDPR**, so transfers EU↔CH require no SCCs. Drive pricing in EUR: Free includes 5 GB encrypted storage plus Docs and Sheets; Drive Plus is from approximately €4/month for 200 GB and file-version recovery; Proton Unlimited at ~€10/month adds 500 GB, Mail with 15 custom addresses, VPN, Pass, and Proton Sentinel advanced account protection; Duo (2 TB, 2 users), Family (3 TB, 6 users), and Drive Professional (1 TB/user for business). Best fit: every EU and Swiss procurement-grade buyer requiring zero-knowledge encrypted file sharing with the strongest sovereignty story in the directory; particularly compelling for journalists, NGOs, regulated industries, and any organisation needing genuine "no one outside the customer can access this data" guarantees. **Compliance rationale:** Proton AG (Geneva, Route de la Galaise 32, Plan-les-Ouates; founded 2014 by Andy Yen and a team from CERN) is controlled by the **non-profit Proton Foundation** (since June 2024) with **no venture-capital investors anywhere on the cap table**, runs 11,496 owned-and-operated servers across 117 countries with Swiss-jurisdiction primary processing, ISO/IEC 27001:2022 + SOC 2 Type II certifications covering all Proton product lines, and zero-knowledge end-to-end encryption that makes the customer the sole keyholder; Swiss-headquartered and non-profit-foundation-controlled, with a public DPA, disclosed sub-processors, and `none` CLOUD Act exposure under a customer-data-at-rest definition because the US sub-processors (Zendesk for support, Stripe / PayPal / Chargebee for billing) are ancillary and never touch the end-to-end-encrypted file data on Proton's own infrastructure. **Sub-processors mapped:** 7 total, 4 US-owned - Chargebee, Inc. (United States): Payment data processing (billing automation); ancillary [US-owned] - PayPal (United States): Payment data processing; ancillary [US-owned] - Stripe, Inc. (United States): Payment data processing; ancillary [US-owned] - Zendesk, Inc. (United States): Customer support data processing; ancillary [US-owned] - Atlassian Pty Ltd (Australia): Customer support data storage (EU/US/UK processing locations) - ProtonLabs DOOEL Skopje (North Macedonia): Customer support and direct communications (Proton group company) - ProtonLabs Taiwan Co., Ltd (Taiwan): Customer support and direct communications (Proton group company) ### Proton Mail: https://euvetted.com/p/proton-mail - Website: https://proton.me/mail - Category: Private email - Country of incorporation: Switzerland - Hosting country: Switzerland (Geneva) - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: freemium (from €4/month) - Founded: 2014 - Certifications: ISO27001 - DPA: https://proton.me/legal/dpa - Sub-processors list: https://proton.me/legal/privacy - Last verified: 2026-05-12 Swiss end-to-end encrypted email by Proton AG (Geneva); 100M+ users, Foundation-controlled since June 2024. **Proton Mail** is the original product within the **Proton AG** ecosystem (Geneva, Switzerland) and the flagship of the privacy-first email category: **end-to-end + zero-access encryption** (Proton itself cannot read user emails or attachments), 100M+ users, 100,000+ organisations. Since June 2024 Proton AG is controlled by the **Proton Foundation**, a Swiss non-profit, which structurally rules out future VC / PE acquisition pressure. Pricing: Free (1GB), Mail Plus (~€4.99/mo, 15GB + custom domain), Proton Unlimited (~€9.99/mo bundle with Mail + Drive + Pass + Calendar + Docs + Sheets + VPN). For the full Proton ecosystem profile see `proton-drive` and `protonvpn`. Swiss jurisdiction places `ownership_signal: other` (Switzerland is non-EU but strong-privacy-law); CLOUD Act exposure none. **Compliance rationale:** **Proton Mail** is operated by **Proton AG** (Geneva CH), controlled by the non-profit **Proton Foundation** since June 2024, with **end-to-end + zero-access encryption**, Swiss jurisdiction (outside EU but under FADP + strong privacy law), own Swiss data centres, ISO 27001, **100M+ users**, fully open-source clients, independently audited; Foundation-controlled (non-profit, no VC/PE pressure); the US sub-processors (Zendesk support, Stripe/PayPal/Chargebee billing) are ancillary and never touch the end-to-end-encrypted mailbox data, which sits on Proton's own Swiss data centres, so under a customer-data-at-rest definition CLOUD Act exposure is none, consistent with the rest of the Proton estate. **Sub-processors mapped:** 7 total, 4 US-owned - Chargebee, Inc. (United States): Payment data processing; ancillary [US-owned] - PayPal group (United States): Payment data processing; ancillary [US-owned] - Stripe, Inc. (United States): Payment data processing; ancillary [US-owned] - Zendesk, Inc. (United States): Customer support data processing; ancillary [US-owned] - Atlassian Pty Ltd (Australia): Customer support data storage - ProtonLabs DOOEL Skopje (North Macedonia): Customer support / direct communications (Proton group entity) - ProtonLabs Taiwan Co., Ltd (Taiwan): Customer support / direct communications (Proton group entity) ### Proton Pass: https://euvetted.com/p/proton-pass - Website: https://proton.me/pass - Category: Password managers - Country of incorporation: Switzerland - Hosting country: Switzerland (Geneva) - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: freemium (from €2/month) - Founded: 2023 - DPA: https://proton.me/legal/dpa - Sub-processors list: https://proton.me/legal/privacy - Last verified: 2026-05-11 Swiss zero-knowledge password manager (Proton AG / Proton Foundation), open-source apps + extensions, Cure53-audited, free unlimited tier. Proton Pass is the password-manager product in the Proton AG portfolio, the same Geneva-headquartered Swiss company operated under the non-profit **Proton Foundation** (CHE-418.863.304) since the 2024 founder share donation by Andy Yen, Jason Stockman, and Dingchao Lu. The product launched in beta on 20 April 2023 and globally on 28 June 2023 under a freemium model and now serves the broader Proton group's 100M+ accounts. Feature set covers password storage, passkey support, integrated 2FA authenticator, secure password sharing, file attachments, **hide-my-email aliases** (a Proton-network-native privacy feature for breach isolation), dark-web breach monitoring, and dedicated business tier with admin controls, SSO, and compliance reporting. Compliance posture mirrors Proton VPN. End-to-end zero-knowledge encryption means Proton itself cannot decrypt customer vaults under any circumstance. The Android and iOS apps plus browser extensions for Firefox and Chromium-based browsers are **open-source on GitHub** (protonpass/ + ProtonMail/WebClients). **Cure53 conducted a full security audit in May–June 2023** of the mobile apps, browser extensions, and API. No critical issues were found and moderate findings were fixed before global launch. Account data is stored exclusively in Switzerland, Germany, or Norway alongside the rest of Proton's portfolio (same DCs and same engineering ops as Proton Mail and Proton Drive). Switzerland's EU adequacy decision (Art. 45 GDPR) makes cross-border transfers between CH and EU SCC-free. Pricing is freemium with one of the most generous free tiers in the category: **unlimited logins / notes / credit cards / devices, plus 10 hide-my-email aliases, passkeys, and weak/reused-password alerts**. That is comprehensive enough that many users never need to upgrade. **Pass Plus** is the entry paid tier (industry-reported ~€2/month, multi-currency CHF/EUR/USD); business plans with SSO and admin controls above. Best fit: privacy-maximalist consumers, families, and EU SMBs who want a password manager from the same structurally-protected ownership architecture that provides Proton Mail and Proton VPN, and any procurement-grade buyer who wants Cure53-audited zero-knowledge encryption with the lowest possible parent-jurisdiction risk (non-profit Swiss foundation). **Compliance rationale:** Proton Pass is part of the **Proton AG** product portfolio (Plan-les-Ouates, Geneva, Switzerland), controlled since 2024 by the non-profit **Proton Foundation** which structurally shields the company from VC/PE acquisition. Launched June 2023 as freemium with **open-source apps and browser extensions on GitHub**, audited by Cure53 in 2023 (full audit, no critical issues), end-to-end zero-knowledge encryption, account data stored exclusively in Switzerland/Germany/Norway alongside the rest of the Proton estate. Swiss non-profit ownership, EU-adequate jurisdiction, open-source clients, Cure53-audited; the US sub-processors (Zendesk support, Stripe/PayPal/Chargebee billing) are ancillary and never touch the end-to-end-encrypted vault data held on Proton's own infrastructure, so under a customer-data-at-rest definition CLOUD Act exposure is none, mirroring the rest of the Proton estate. **Sub-processors mapped:** 7 total, 4 US-owned - Chargebee, Inc. (United States): Payment data processing; ancillary [US-owned] - PayPal group (United States): Payment data processing; ancillary [US-owned] - Stripe, Inc. (United States): Payment data processing; ancillary [US-owned] - Zendesk, Inc. (United States): Customer support data processing; ancillary [US-owned] - Atlassian Pty Ltd (Australia): Customer support data storage - ProtonLabs DOOEL Skopje (North Macedonia): Customer support / direct communications (Proton group entity) - ProtonLabs Taiwan Co., Ltd (Taiwan): Customer support / direct communications (Proton group entity) ### Proton VPN: https://euvetted.com/p/protonvpn - Website: https://protonvpn.com - Category: VPN - Country of incorporation: Switzerland - Hosting country: Switzerland (Geneva) - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: freemium (from €5/month) - Founded: 2014 - DPA: https://proton.me/legal/dpa - Sub-processors list: https://protonvpn.com/privacy-policy - Last verified: 2026-05-11 CERN-founded Swiss VPN (Proton AG, Geneva), owned by non-profit Proton Foundation; 15,000+ servers, audited no-logs, open-source apps, free tier. Proton VPN is part of the **Proton** privacy-tech group operated by Proton AG (Plan-les-Ouates, Geneva, Switzerland) and is the structurally strongest VPN listing in this directory by procurement-grade criteria. Founded in 2014 by Andy Yen, Jason Stockman, and Dingchao Lu (scientists who met at CERN), Proton has run a privacy-by-default product portfolio (Mail, VPN, Drive, Calendar, Pass) for over a decade. In 2024, the founders and first employee donated their controlling shares to the newly-established **Proton Foundation**, a non-profit registered in Geneva (CHE-418.863.304) which now serves as the primary shareholder of Proton AG. The foundation structure permanently protects Proton from venture-capital acquisition or US private-equity takeover, a unique ownership architecture in the EU/CH privacy-tech landscape. Compliance posture is gold-standard. Switzerland holds an EU adequacy decision under Art. 45 GDPR, so transfers between EU and CH require no SCCs. The privacy policy (last updated 30 July 2025) commits that account data is encrypted and stored exclusively in Switzerland, Germany, or Norway; Proton owns and operates its Secure Core servers and most Swiss/German VPN nodes; all servers feature full-disk encryption with no stored logs or user data. The no-logs policy has been **independently audited and published** (a differentiator vs nearly every other VPN brand that claims no-logs without an audit), and Proton publishes a public transparency report plus a warrant canary documenting law-enforcement requests. All consumer apps are 100% open-source. The product covers 15,000+ servers across 140+ countries, supports up to 10 simultaneous device connections on paid plans, and offers Secure Core (multi-hop through Swiss / Icelandic / Swedish fortified servers), NetShield ad/tracker/malware blocking, port forwarding, P2P/BitTorrent-friendly servers, streaming-unblock servers, and Tor-over-VPN. The **free tier** is uncommonly generous: one device, medium speed, servers in 10 randomly-selected countries, **no data limits, no artificial speed throttling, no ads**, and full privacy guarantees. VPN Plus is the paid entry tier with multi-currency (CHF / EUR / USD); spring-sale 1-year discounts up to 65% have been advertised. Best fit: privacy-maximalist consumers, journalists, activists, EU SMBs, and any organisation needing the strongest possible ownership-and-jurisdiction guarantees in a VPN provider. **Compliance rationale:** Proton VPN, operated by **Proton AG** in Plan-les-Ouates, Geneva, is owned primarily by the non-profit **Proton Foundation** (Swiss-registered, CHE-418.863.304). Founders Andy Yen, Jason Stockman, and Dingchao Lu (CERN alumni) donated their shares in 2024, structurally protecting Proton from US-PE acquisition; account data is encrypted and stored exclusively in Switzerland, Germany, or Norway, Proton owns and operates its Secure Core servers and most Swiss/German nodes, the no-logs policy has been independently audited and published, transparency reports and warrant canary are public, all apps are open-source. Swiss-jurisdiction, non-profit-owned, with a public DPA (proton.me/legal/dpa), no CLOUD Act exposure: the US support/payment sub-processors (Zendesk, Stripe, PayPal, Chargebee) are ancillary and off the service-data path, never touching user traffic or encrypted data (Proton runs its own infrastructure), so under a data-at-rest definition CLOUD Act exposure is none, and the strongest ownership and transparency signal set in this category. **Sub-processors mapped:** 7 total, 4 US-owned - Chargebee, Inc. (United States): Payment data processing; ancillary [US-owned] - PayPal group (United States): Payment data processing; ancillary [US-owned] - Stripe, Inc. (United States): Payment data processing; ancillary [US-owned] - Zendesk, Inc. (United States): Customer support data processing; ancillary [US-owned] - Atlassian Pty Ltd (Australia): Customer support data storage - ProtonLabs DOOEL Skopje (North Macedonia): Customer support / direct communications (Proton group entity) - ProtonLabs Taiwan Co., Ltd (Taiwan): Customer support / direct communications (Proton group entity) ### Psono: https://euvetted.com/p/psono - Website: https://psono.com - Category: Password managers - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: freemium (from €0/month) - Founded: 2017 - Certifications: ISO27001 - Sub-processors list: https://console.esaqa.com/subprocessor/ - Last verified: 2026-05-11 German Apache-2.0 open-source team password manager (esaqa GmbH), self-hostable on EU infrastructure, Cure53-audited 2026, free up to 10 users. Psono is a German open-source team password manager built and operated by **esaqa GmbH** (Tiergartenstr. 13, 91247 Vorra, Germany; CEO Sascha Pfeiffer). The entire product, spanning server, web client, browser extensions, and mobile apps (Flutter), is published under the permissive **Apache 2.0** licence and lives on GitHub. The product reports more than 2 million downloads and is engineered for the enterprise team-credentials use-case: SAML and LDAP single-sign-on, granular role-based access controls, audit logging, compliance policies (mandatory password complexity / rotation / 2FA), shared groups, recovery codes, and a YubiKey / FIDO2 / TOTP second-factor stack. Encryption is multi-layered: client-side encryption-at-rest, TLS in transit, and additional server-side storage encryption, so server operators (including Psono's own SaaS team) cannot read customer vaults. For procurement-grade EU buyers Psono is one of the cleanest listings in this directory. The legal entity is a German GmbH with full HRB transparency, founder-controlled, no PE / VC / parent on record. Apache 2.0 licensing means there is no vendor lock-in (a customer can fork the codebase if Psono ever changes posture), and the **2026 Cure53 audit** plus **ISO 27001 certification** (trust centre at trust.esaqa.com, with a publicly maintained sub-processor register) provide independent third-party validation of the security and compliance architecture, matching the standard set by Proton / Mullvad / IVPN in the VPN category. Self-hosting on EU infrastructure (Hetzner, OVHcloud, Scaleway, IONOS, STACKIT) gives an EU-owned, self-hosted posture with no CLOUD Act exposure and zero vendor-counterparty risk. Pricing is freemium with an unusually generous free tier: **all business features are free for up to 10 users**, including SAML, LDAP, audit logs, and compliance policies, a tier that competitive open-source competitors (Bitwarden, Vaultwarden) gate behind paid plans. Paid tiers scale by user count and offer managed SaaS hosting for buyers who prefer not to self-host, though that hosted path runs on Google Cloud (Ireland) behind Cloudflare with US payment and support sub-processors, which is why the directory rates the default offering at material CLOUD Act exposure and treats self-hosting as the procurement-grade route. Apps for macOS, Windows, Linux, iOS, Android, plus Chrome / Firefox / Safari extensions, plus a Docker Hub-published server image for self-host. Best fit: German and EU SMBs and enterprises that need SAML/LDAP team-credentials management, regulated buyers needing audit-log compliance, and any procurement-grade buyer who wants the structural cleanliness of self-host plus Apache-2.0 open source. **Compliance rationale:** Psono is an **Apache-2.0 open-source** team password manager developed by **esaqa GmbH** (Tiergartenstr. 13, 91247 Vorra, Germany; CEO Sascha Pfeiffer): fully self-hostable on the customer's own infrastructure, multi-level encryption (client-side + SSL + storage), SAML / LDAP / audit-log / compliance-policy features, free for up to 10 users on the business feature set, **ISO 27001 certified** (trust centre at trust.esaqa.com) with a **public sub-processor register**, and **audited by Cure53 in 2026**; for self-hosting buyers on EU infrastructure (Hetzner / OVHcloud / Scaleway) EU-owned, self-hosted, with no CLOUD Act exposure and structurally minimal vendor-counterparty risk. The **hosted SaaS**, however, runs on **Google Cloud (Ireland)** fronted by **Cloudflare** with US payment/support sub-processors (Stripe, Paddle, Sentry, Freshworks), so the directory rates default CLOUD Act exposure as **material** and reserves the clean posture for the self-hosted route. **Sub-processors mapped:** 9 total, 6 US-owned - Apple (United States): Push notifications for iPhones and iPads [US-owned] - Cloudflare (United States): DDoS protection, CDN and DNS [US-owned] - Freshworks Inc. (United States): Ticketing to handle customer support requests [US-owned] - Google Cloud EMEA Limited (Ireland): Hosting (servers, databases, network) for the managed SaaS; US-owned hyperscaler [US-owned] - Sentry Inc. (United States): Error reporting [US-owned] - Stripe Inc. (United States): Credit cards and payments [US-owned] - Brevo (Sendinblue) (France): Transactional email (registration, share, invoice) and email marketing - Paddle.com Inc. (United States): Credit cards and payments (US-resident billing entity) - Scaleway, S.A.S (France): Hosting (servers, databases, network) for the managed SaaS ### Pureservice: https://euvetted.com/p/pureservice - Website: https://www.pureservice.com - Category: Helpdesk - Country of incorporation: Norway - Hosting country: Norway (Oslo) - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2008 - DPA: https://5141712.fs1.hubspotusercontent-na1.net/hubfs/5141712/Pureservice%20tjeneste-,%20lisens-%20og%20databehandleravtale%202.6.pdf - Sub-processors list: https://pureservice.com/servicevendorlist - Last verified: 2026-06-12 Oslo-based Norwegian ITSM / servicedesk (Pureservice AS, founded 2008, Syscom demerger 2018); Swedish-PE-owned (Pamir, 2024); runs on Microsoft Azure Norway. Pureservice is an Oslo-headquartered Norwegian IT and Enterprise Service Management platform operated by **Pureservice AS** (org.nr 929 782 216). It was founded in **2008** inside the Norwegian IT-consultancy **Syscom** (now DXC Technology Norge), spun out as a separate company through a 2018 demerger, and has operated fully independently from its own Egertorget offices in central Oslo since June 2020. The product is a fixed-price, all-inclusive servicedesk: self-service portal, ticketing, workflow automation, asset/CMDB management, AI assistance, dashboards and integrations, serving IT, HR and Finance teams. Pureservice reports 3.5 million end-users, 25,000 case managers and 450+ customer organisations, heavily weighted toward the Norwegian public sector (municipalities, health trusts, universities, energy utilities). Ownership is a clean Nordic story. In **December 2024 Pamir Partners AB**, a Stockholm-based private-equity firm (founded 2011) specialising in small and mid-sized European software companies, acquired a **majority stake** from the private owners after a Nordhaven-run sale process (the business was marketed on ~NOK 48m ARR / ~NOK 20m EBITDA). There is **no US investor on the cap table**: the company is Norwegian (EEA, not EU), now controlled by a Swedish software PE house. Because Norway sits in the EEA rather than the EU and the controlling owner is Swedish, the `ownership_signal` is recorded as `other` rather than `eu_owned`. For an EU/EEA-sovereignty audit the infrastructure layer is where the "local hero" framing breaks down. Pureservice repeatedly markets that customer data is stored "securely in Norway" (Swedish customers in Sweden), and that is literally true, but the hosting platform is **Microsoft Azure**: Norwegian data sits in the **Azure Norway East region (Oslo)**, Swedish data in Azure Sweden. The data therefore stays inside the EEA and never leaves it, but it lives at rest on infrastructure owned by US-incorporated Microsoft, which keeps CLOUD Act exposure at `material`. The ISO 27001:2013 and SOC 2 Type 2 certifications cited on Pureservice's trust pages belong to the **Azure datacenter**, not to Pureservice as an entity, so this listing carries no vendor-held certification token. The public sub-processor list names Microsoft Azure (host), Mailgun (email), DNSimple, Sentry.io and UserGuiding (all US-operated) plus Domeneshop (NO) and Manula, a typical US-SaaS-heavy supporting stack. On the positive side, disclosure is genuinely good: a publicly downloadable combined service/licence/DPA agreement, a public sub-processor list, encryption at rest and in transit, OWASP Top 10 alignment and annual third-party pen-testing. Best fit: Norwegian and Scandinavian public-sector and mid-market IT teams that want a Nordic-owned, Norwegian-data-resident servicedesk and accept Microsoft Azure as the underlying platform. Buyers requiring zero US-hyperscaler / zero-CLOUD-Act infrastructure should treat the "data in Norway" claim as data-residency, not data-sovereignty. **Compliance rationale:** Pureservice AS (Oslo, Norway; org.nr 929 782 216; founded 2008, demerged from Syscom in 2018, fully independent from June 2020) is a Norwegian/Scandinavian ITSM / Enterprise Service Management servicedesk used by 450+ organisations including municipalities, health trusts, energy companies and universities. Majority-owned since December 2024 by Pamir Partners AB (Stockholm), a Swedish lower-mid-market software PE firm, with no US ownership on the cap table. Disclosure is strong for the category: a publicly downloadable combined service/licence/DPA agreement (v2.6) and a public named sub-processor list. The decisive caveat is infrastructure: the marketing claim that 'data is stored securely in Norway' is technically true but resolves to Microsoft Azure's Norway East region (Oslo). Data resides in the EEA but at rest on US-owned Microsoft hardware, so CLOUD Act exposure is material, not none. ISO 27001:2013 and SOC 2 Type 2 are held by the Azure datacenter, NOT by Pureservice itself, so certifications is left empty. The sub-processor list adds further US dependencies: Microsoft Azure (host), Mailgun, DNSimple, Sentry.io and UserGuiding are all US-operated; only Domeneshop is Norwegian. Net: EEA-incorporated and EEA-resident data with a clean Nordic owner, but the entire stack runs on a US hyperscaler plus several US SaaS sub-processors → compliance_score 3. ### rapidmail: https://euvetted.com/p/rapidmail - Website: https://www.rapidmail.com - Category: Email marketing - Country of incorporation: Germany - Hosting country: Germany (Frankfurt) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2008 - Certifications: ISO27001 - DPA: https://www.rapidmail.de/hilfe/dpa - Sub-processors list: https://www.rapidmail.com/data-protection - Last verified: 2026-05-10 Freiburg-based German email marketing tool hosting customer data exclusively in a Frankfurt ISO 27001 data centre, no public cloud. rapidmail is a Freiburg-headquartered German email marketing platform operated by rapidmail GmbH (Positive Group Deutschland GmbH, Amtsgericht Freiburg HRB 706983), founded in 2008. It positions itself as a fully GDPR-compliant ESP for SMBs in DACH and is one of the cleanest "Made in Germany" data-residency stories in the email-marketing category: customer email data and subscriber lists are hosted exclusively in a Frankfurt data centre that holds ISO 27001 and PCI-DSS certifications, and the company explicitly avoids public hyperscaler clouds (no AWS, no GCP, no Azure) for product workloads. The privacy policy (last updated May 2025) is transparent about marketing-site sub-processors (Google Analytics/Ads/reCAPTCHA, HubSpot, Hotjar, Mixpanel, LinkedIn Insight, Bing Ads, Matomo, Axeptio), but these touch the website and lead funnel rather than customer email data, and any US transfers are covered by Standard Contractual Clauses under Art. 46 GDPR. The data protection officer is Nils Möllers of Keyed GmbH, a German external DPO firm. Customer satisfaction signals are strong (97% across 2,600+ reviews), and OMR Reviews has ranked rapidmail as a category Leader. The product is in German and English. Best fit: small and mid-sized German-speaking businesses, associations, and e-commerce shops who want a no-fuss, DSGVO-konformes Newsletter tool with an unambiguous "data stays in Germany" answer for procurement and a German-speaking support team. Limitations to verify before procurement-grade buying: SSO/SAML and audit-log capabilities are not advertised on the public pages reviewed, and the public DPA download URL was not directly resolvable at audit. DPA accessibility for non-enterprise tiers should be confirmed with the vendor. **Compliance rationale:** Freiburg-based GmbH (Positive Group) hosting customer email data exclusively on a German data-centre campus in Frankfurt that holds ISO 27001 and PCI-DSS, with explicit avoidance of public hyperscaler clouds for customer data and SCC-protected US transfers limited to marketing-site analytics. EU-owned, EU-hosted on own infrastructure with no US hyperscaler dependency, and the only US transfers are marketing-site analytics that never touch customer mailing data, so under a customer-data-at-rest definition CLOUD Act exposure is none. **Sub-processors mapped:** 2 total, 0 US-owned - MEGASPACE Internet Service GmbH (Germany): Hosting of servers within Germany - uvensys GmbH (Germany): Hosting of servers within Germany ### Reservio: https://euvetted.com/p/reservio - Website: https://www.reservio.com - Category: Calendar booking - Country of incorporation: Czechia - Hosting country: Czechia - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium - Founded: 2012 - DPA: https://www.reservio.com/terms-and-conditions - Last verified: 2026-05-11 Brno-based Czech booking platform (Reservio s.r.o., ABUGO Group), 500k+ businesses, freemium with branded customer apps. Reservio is a Brno-headquartered Czech online appointment-scheduling platform operated by **Reservio s.r.o.** and a member of the **ABUGO Group**. Incorporated on 6 November 2012, the company has scaled to **500,000+ businesses** on the platform with 21M+ clients and 20M+ bookings per year, large enough to be a serious B2C booking marketplace in Central and Eastern Europe alongside being a B2B scheduling tool. The product surface covers scheduling calendar, online booking website, POS, client management, team management, mobile apps (iOS/Android), SMS and email reminders, online payments, and an optional **branded customer app** (white-label mobile app) for businesses on higher tiers. The freemium model unlocks the scheduling calendar, booking website, client management, team coordination, and integrated POS without payment. For an EU-sovereignty audit Reservio is a clean Czech ownership story: no PE / VC chain visible, member of the ABUGO Group (Czech corporate holding), 10–19 employees with about a third remote. CDN delivery is via **CDN77** (a Czech-incorporated CDN provider, ultimately part of Datacamp Limited in Cyprus); Czech and Cypriot incorporations are both inside the EU so the asset layer is EU-domiciled. Where the listing weakens is procurement-grade documentation: the customer-data hosting provider, a unified DPA artefact, and a named sub-processors list are not directly captured at audit; vendor outreach is needed to surface the canonical URLs before publishing for procurement-led buyers. Best fit: Czech, Slovak, Polish, Hungarian, and broader CEE small and medium service businesses (beauty salons, fitness clubs, language schools, medical practices, equipment rentals); EU SMBs that benefit from Reservio's white-label customer-app option; multilingual booking pages across the CEE language belt. Procurement-grade EU-only buyers requiring formal contract documents should request the DPA, sub-processors list, and hosting region directly before signing. **Compliance rationale:** Reservio s.r.o. (Brno, Czech Republic; incorporated 6 November 2012; member of the **ABUGO Group**) is a Czech online booking platform serving 500,000+ businesses and 21M+ clients annually with a freemium model: scheduling calendar, POS, client and team management, branded customer apps, and SMS / email reminders. CDN delivery via CDN77 (Czech-incorporated CDN provider, ultimately owned by Datacamp Limited in Cyprus) keeps the asset layer EU-domiciled. Signal mix: EU-owned (Czech B2B holding group, no PE/VC chain visible), CLOUD Act flag at `minor`; gaps: the underlying customer-data hosting provider, a publicly accessible DPA artefact, and a named sub-processors list are not captured at audit; vendor outreach required before procurement-grade listing. ### Runbox: https://euvetted.com/p/runbox - Website: https://runbox.com - Category: Private email - Country of incorporation: Norway - Hosting country: Norway - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: paid (from €2/month) - Founded: 1999 - Sub-processors list: https://runbox.com/about/privacy-policy/third-party-services/ - Last verified: 2026-05-15 Norwegian private email since 1999 (Runbox Solutions AS), own NO data centre, 100% renewable hydro, PGP + 2FA + PFS, double carbon-negative. Runbox is operated by Runbox Solutions AS, a Norwegian company that has been in continuous operation as a privacy-focused email service since 1999, making it one of the longest-running independent vendors in this category, alongside Posteo (Berlin, 2009) and Mailbox.org (Berlin, 2014 in current form). The product is straightforward: secure IMAP/POP/SMTP email under Norwegian and EEA privacy law, with PGP encryption, two-factor authentication, Perfect Forward Secrecy on SSL, and standard mail-client compatibility; no proprietary lock-in, no advertising, no tracking. The infrastructure story is genuinely strong. Runbox runs its own infrastructure inside a Norwegian high-security data centre, powered by **100% certified renewable energy from clean Norwegian hydropower**, with multiple redundancy layers for high availability. The company is recognised by the **Ethical Consumer "Best Buy"** designation and carries a **Carbon Balanced Certificate (double carbon-negative via World Land Trust)**, sustainability credentials that match Infomaniak's posture in the same Swiss-Norwegian-Nordic privacy band. As a Norwegian operator, Runbox is explicitly outside the reach of the US CLOUD Act. For an EU-sovereignty audit the only gaps are formal compliance documentation: no ISO/IEC 27001 attestation, no SOC 2, and no publicly linked DPA or sub-processors list were surfaced at audit. None of those gaps suggest poor practice; they just mean that procurement-grade buyers needing those documents will need to request them. Norway is EEA rather than EU, and no formal certifications were documented at audit. Pricing is paid-only (no free tier), competitive and storage-tiered: Micro €19.95/year (€1.66/month, 2 GB); Mini €34.95/year (€2.91/month, 10 GB); Medium €49.95/year (€4.16/month, 25 GB); Max €79.95/year (€6.66/month, 50 GB). 20% discount on 3-year subscriptions. Best fit: privacy-conscious EU/EEA users who want a long-established Norwegian privacy-email service with first-class PGP support, ethical / sustainability credentials, and explicit CLOUD-Act-non-applicability, and who do not require a free tier or formal ISO 27001 attestation. **Compliance rationale:** Runbox is operated by **Runbox Solutions AS**, a Norwegian company in continuous operation since 1999 (among the longest-running independent privacy-email vendors in Europe) running its **own infrastructure inside a Norwegian high-security data centre powered by 100% certified renewable hydropower**, supporting **PGP encryption**, two-factor authentication, Perfect Forward Secrecy SSL, encrypted Web/POP/IMAP/SMTP, with public privacy policy and terms; Norwegian jurisdiction (EEA, outside EU), no CLOUD Act exposure. Gap: Runbox does not publish a publicly accessible DPA (customers are directed to a DPO contact rather than a self-serve document); no formal ISO 27001 attestation. ### Sage Accounting: https://euvetted.com/p/sage-accounting - Website: https://www.sage.com/en-gb/products/sage-accounting/ - Category: Accounting - Country of incorporation: United Kingdom - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: paid (from €16/month) - Founded: 1981 - Certifications: ISO27001 - DPA: https://www.sage.com/en-gb/legal/terms-and-conditions/product-and-service-terms-and-conditions/data-processing-agreement/ - Sub-processors list: https://www.sage.com/en-gb/-/media/images/sagedotcom/master/global/feature/pdf/legal/sages-sub-processors.pdf - Last verified: 2026-05-12 UK-public accounting incumbent (FTSE 100, Newcastle, est. 1981); Sage Accounting cloud product for SMB. **Sage Group plc** (Newcastle upon Tyne, founded 1981) is one of the largest software companies in Europe: listed on the London Stock Exchange (LSE: SGE, FTSE 100), no US parent, no US-PE control. The SMB cloud product line **Sage Accounting** (also Sage Business Cloud Accounting, formerly Sage One) targets sole traders through small businesses with pricing from ~£12/mo (~€14). ISO 27001 certified. The wider Sage portfolio includes Sage HR (sage.hr, see separate listing), Sage Intacct (mid-market), Sage 50, and Sage 200. Post-Brexit UK jurisdiction places it in `ownership_signal: other` per the directory's rubric; for procurement teams whose CLOUD Act concern is specifically US extraterritorial reach, Sage is one of the cleanest large-vendor options. **Compliance rationale:** **Sage Group plc** (Newcastle UK, founded 1981, FTSE 100, LSE: SGE) is one of Europe's largest software companies: UK-public, no US parent, ISO 27001 certified; UK-post-Brexit places it in `ownership_signal: other` rather than `eu_owned`, but for buyers willing to accept UK jurisdiction the compliance posture is strong; CLOUD Act exposure minor (no US parent / PE). ### Sage HR: https://euvetted.com/p/sage-hr - Website: https://sage.hr - Category: HR & people - Country of incorporation: United Kingdom - Hosting country: Ireland - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: paid (from €7/month) - Founded: 2016 - Certifications: ISO27001 - DPA: https://www.sage.com/en-gb/legal/terms-and-conditions/product-and-service-terms-and-conditions/data-processing-agreement/ - Sub-processors list: https://support.sage.hr/en/articles/1937906-security-policy - Last verified: 2026-05-12 Sage Group plc's HR cloud product (formerly CakeHR from Riga, acquired 2019); UK-public parent, modular SMB HR. **Sage HR** is the HR product within Sage Business Cloud, originally launched as **CakeHR** in Riga, Latvia in 2016 by Latvian founders, acquired by **Sage Group plc** (Newcastle UK, FTSE 100, LSE: SGE) in 2019, and rebranded. The product covers core HR, leave, performance, recruitment, expenses, timesheets, and shift scheduling, with modular pricing from ~£5/user/mo. The parent Sage Group is one of Europe's largest software companies with **no US parent and no US-PE control**, placing Sage HR in a relatively clean UK-jurisdiction bucket (`ownership_signal: other`, post-Brexit UK), with ISO 27001 certification inherited from the group. For SMB buyers who consider UK jurisdiction acceptable, Sage HR is a strong procurement-grade choice. **Compliance rationale:** **Sage HR** (originally **CakeHR**, founded Riga LV 2016) was acquired by **Sage Group plc** (UK FTSE 100, no US parent) in 2019 and is now part of Sage Business Cloud; ISO 27001 inherited from parent, UK jurisdiction = `ownership_signal: other`, no material US-PE involvement = `cloud_act_exposure: minor`; one of the cleanest non-Nordic non-DACH HR options for SMB buyers willing to accept UK jurisdiction. ### Saleor Commerce: https://euvetted.com/p/saleor - Website: https://saleor.io - Category: E-commerce - Country of incorporation: Poland - Hosting country: Ireland (Dublin) - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: freemium - Founded: 2018 - Certifications: SOC2 - DPA: https://saleor.io/legal/dpa - Sub-processors list: https://saleor.io/legal/subprocessors - Last verified: 2026-05-21 Polish headless GraphQL commerce platform; open-source BSD-3; cloud hosted on AWS EU (Ireland) with SOC 2 Type 2. **Saleor Commerce** (founded 2018, Polish team) is a headless, API-first e-commerce platform built around a **GraphQL-native architecture** with 22,900+ GitHub stars and BSD-3-Clause licence. It handles 1B+ API requests and 400k+ orders monthly across its cloud customer base. **Saleor Cloud** offers a fully-managed SaaS with EU data residency on **AWS eu-west-1 (Ireland)** as the primary EU region; data is strictly isolated between regions. Certifications: **SOC 2 Type 2**, GDPR compliant, PCI-DSS compliant. The self-hosted path (self-deploy on EU VPS/PaaS) gives merchants full infrastructure control with zero US-cloud dependency. Saleor targets developers and agencies building composable commerce stacks: it is not an out-of-the-box hosted shop like Shopify, but rather an API layer that any EU-hosted frontend can consume. Best fit for digital agencies, D2C brands, and B2B operators who need deep API customisation with EU data residency. No public DPA or sub-processors list found; request via sales for enterprise contracts. **Compliance rationale:** Saleor Commerce (PL-founded, EU team) achieves SOC 2 Type 2 and offers EU data residency on AWS eu-west-1 (Ireland), but Saleor Cloud runs on AWS (a US-controlled infrastructure), giving material CLOUD Act exposure. No public DPA or sub-processors list; these must be requested via sales for enterprise contracts. ### Salesflare: https://euvetted.com/p/salesflare - Website: https://salesflare.com - Category: CRM - Country of incorporation: Belgium - Hosting country: Belgium - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: paid (from €29/month) - Founded: 2014 - DPA: https://downloads.salesflare.com/legal/180423-DPA-Salesflare.pdf - Last verified: 2026-05-10 Antwerp-based Belgian B2B sales CRM, founder-controlled, focused on automation and pipeline visibility for SMBs. Salesflare is a small, founder-controlled Belgian B2B sales CRM headquartered in Antwerp. Founded in 2014 by Jeroen Corthout and Lieven Janssen, the product targets SMB sales teams with automated CRM data input from email/calendar/social activity, visual sales pipelines, email and link tracking, lead finder credits, personalised email campaigns, and tight integrations with LinkedIn, Gmail, and Outlook. The company reports more than 10,000 paying companies and a 4.8/5 average rating across 400+ public reviews. For an EU-sovereignty audit the picture is partial: the brand is genuinely Belgian and founder-controlled (no public PE acquisition or US-VC majority on record), the privacy policy is delivered through Iubenda (an EU-based privacy-policy-as-a-service provider), and the marketing site does not advertise any US legal entity. What is missing for procurement-grade buyers is positive disclosure: a dedicated DPA URL did not resolve at audit, a named sub-processors annex is not publicly indexed, and the underlying hosting provider for customer CRM data is not stated on accessible public pages. For a small B2B SaaS at this scale, AWS is the industry default, which would translate to material CLOUD Act exposure under the strict-ownership stance, but this needs vendor confirmation before publishing. Pricing in EUR is straightforward and contract-friendly: the Growth plan is €29/month (save €10/mo with annual billing), Pro and Enterprise tiers above; a 30-day free trial requires no credit card, and the company commits to "no features we will suddenly charge you extra for that will not be listed on this page." Best fit: Belgian, Dutch, and broader EU SMB sales teams that want a polished pipeline CRM with founder-led ownership and don't require an enterprise-grade DPA at signup. Procurement-led buyers needing a verified EU-only hosting story should ask Salesflare directly for its DPA, sub-processors list, and AWS region before committing. **Compliance rationale:** Antwerp-based Belgian B2B CRM with founder-controlled ownership (Jeroen Corthout, Lieven Janssen) and 10k+ customers; the privacy policy is hosted on Iubenda (EU privacy-as-a-service) but no public DPA or named sub-processors page is visible at audit, and the underlying hosting provider is not disclosed publicly; eu_owned ownership signal is the key positive, but without a disclosed hosting provider or public DPA the CLOUD Act flag is defensively set to material pending sub-processors disclosure. ### Scalapay: https://euvetted.com/p/scalapay - Website: https://www.scalapay.com - Category: Payments - Country of incorporation: Italy - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2019 - Last verified: 2026-05-21 Milan-based Italian BNPL (Scalapay S.r.l., 2019): 3 interest-free installments, 1,500+ merchants, 9 EU markets; US-VC-funded at $700M Series B. Scalapay is a Milan-based Italian BNPL (buy-now-pay-later) solution operated by **Scalapay S.r.l.** (Via Nervesa 21, 20139 Milano; VAT IT 06891080480; REA MI-2606390), founded in 2019. The core product splits purchases into three equal interest-free monthly installments for online and in-store retail, with a merchant-funded model where consumers pay no fees. The company serves 1,500+ merchants across Italy, France, Germany, Spain, Portugal, Austria, Belgium, the Netherlands, and Finland, covering fashion, electronics, home goods, sports, and travel verticals. Developer API is available at developers.scalapay.com, with integrations for major e-commerce platforms. For an EU-sovereignty audit Scalapay is Italian-incorporated (a genuine Italian S.r.l. with Milan registration) but the cap table is heavily US-weighted. The company raised **$48M in January 2021** (Series A led by Fasanara Capital, UK) and then **$155M in September 2021** at a **$700M post-money valuation** in a Series B round that included **Tiger Global Management** (New York), **Woodson Capital** (US), **Willoughby Capital** (US), and **Baleen Capital** (US) as US-VC participants alongside European backers. Tiger Global's participation at lead or co-lead in the Series B places Scalapay firmly in the `eu_hq_us_funded` tier under the directory's ownership taxonomy. No public DPA, sub-processors list, or explicit EU data-residency commitment was found on accessible public pages at audit. Pricing for merchants is commission-based per transaction (no monthly fee); consumer installment split is interest-free. Best fit: Italian and Southern European online retailers wanting a local-brand BNPL option with Italian-language support and a familiar domestic brand to consumers in Italy and adjacent markets. **Compliance rationale:** Scalapay S.r.l. (Milan, Italy; VAT IT 06891080480) is Italian-incorporated BNPL but raised US$155M Series B in September 2021 at a US$700M valuation with significant US-VC participation (Tiger Global, Woodson Capital, Willoughby Capital, Baleen Capital, all US funds); `ownership_signal: eu_hq_us_funded`, `cloud_act_exposure: material` (US-VC-weighted cap table); no public DPA or sub-processors list found at audit. ### Scaleway: https://euvetted.com/p/scaleway - Website: https://www.scaleway.com - Category: Cloud & hosting - Country of incorporation: France - Hosting country: France (Paris) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €2/month) - Founded: 1999 - Certifications: ISO27001, SECNUMCLOUD - DPA: https://www.scaleway.com/en/contracts/ - Sub-processors list: https://www.scaleway.com/en/privacy-policy/ - Last verified: 2026-05-18 French sovereign cloud (Iliad-owned, Xavier Niel), ANSSI SecNumCloud + HDS + ISO 27001; winner of €180M EU Cloud III tender. Scaleway is the French cloud subsidiary of Iliad Group, Xavier Niel's Euronext-Paris-listed telecoms and tech holding (parent of Free in France and Iliad Italia), operated as Scaleway SAS at 8 Rue de la Ville l'Évêque, 75008 Paris. The company traces back to 1999 (Online.net legacy) and runs four multi-AZ cloud regions in Europe with 65+ global points of presence and 5,000+ GPUs. Flagship customers include Mistral AI, Hugging Face, Aternos, France Télévisions, and Veepee. The product surface covers 100+ cloud services including bare metal (Dedibox, Elastic Metal, Apple Mac mini), GPU instances (L40S, L4, H100, B300-SXM), Kubernetes, serverless containers, managed databases (PostgreSQL, MySQL, Redis, MongoDB), Data Warehouse for ClickHouse, AI clusters, and generative APIs. For procurement-grade EU buyers Scaleway has two structural advantages that place it alongside Hetzner and OVHcloud as an EU-owned, EU-hosted provider with no CLOUD Act exposure. First, on 27 April 2026 it was selected, alongside Post Telecom (with Clever Cloud and OVHcloud), STACKIT, and Proximus (with S3NS, Clarence, and Mistral AI), as one of four winners of the European Commission's **Cloud III Dynamic Purchasing System**, the €180M sovereign-cloud procurement framework that explicitly excluded AWS, Microsoft Azure, and Google Cloud. Second, it carries the ANSSI **SecNumCloud 3.2** qualification (the French government cloud-security framework designed to provide immunity from US extraterritorial laws including the CLOUD Act and FISA Section 702) plus **HDS** certification for healthcare data hosting (issued by the French National Agency for Digital Health in July 2024, with no transfer of personal health data permitted outside France). Scaleway has also been selected to host the French national Health Data Hub, replacing Microsoft Azure in that role, a high-profile public-sector sovereignty win. Pricing is highly competitive: the Stardust instance class starts from approximately €2/month (smallest virtual instance), Public Cloud Compute scales up from there with hourly and monthly billing, and bare metal Dedibox dedicated servers compete directly with Hetzner on price. Best fit: EU public-sector buyers, regulated industries (healthcare, finance, defence), AI-workload teams who want GPU capacity inside an EU sovereign-cloud envelope, and any procurement-grade buyer needing SecNumCloud-grade isolation. Together with OVHcloud and Hetzner, Scaleway forms the recommended three-pillar EU hyperscaler-alternative stack on this directory. **Compliance rationale:** Scaleway SAS (Paris, French subsidiary of Iliad Group, Xavier Niel's Euronext-Paris-listed telecoms and tech group) is one of two French sovereign-cloud answers in this directory: ISO/IEC 27001:2022, HDS (French healthcare data hosting, July 2024), on the SecNumCloud 3.2 qualification path with ANSSI, and selected April 2026 as one of four winners of the European Commission's €180M Cloud III sovereign-cloud tender: EU-owned and EU-hosted with no CLOUD Act exposure for EU-region customer workloads. **Sub-processors mapped:** 11 total, 0 US-owned - 3S Data Center S.A (Poland): Colocation services (data center, Poland) - Atempo (France): Data recording and archiving for cold storage (Object Storage) - Atman sp. z.o.o (Poland): Colocation services (data center, Poland) - Atnorth (Sweden): Colocation services (data center, Sweden) - BrainStorm Network Inc. (Canada): Service provider for VPS Dedibox - Clever Cloud (France): Cloud provider for Web Platform - Confia (France): Recycling of WEEE (electrical/electronic waste) - Digital Realty (United States): Colocation services (datacenter landlord; physical-only, no data access) - Equinix EMEA (United States): Colocation services (datacenter landlord; physical-only, no data access) - Iron Mountain (United States): Colocation services (datacenter landlord; physical-only, no data access) - Op Core (France): Colocation services (data center, France) ### SeaTable: https://euvetted.com/p/seatable - Website: https://seatable.com - Category: Project management - Country of incorporation: Germany - Hosting country: Germany (Frankfurt) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €7/month) - Founded: 2019 - DPA: https://seatable.com/de/auftrag-zur-auftragsverarbeitung/ - Sub-processors list: https://seatable.com/de/unterauftragnehmer/ - Last verified: 2026-05-21 German no-code database + spreadsheet hybrid (SeaTable GmbH, Mainz, HRB 49723), all-EU hosting on Exoscale + Hetzner, public DPA, self-hostable. SeaTable is the German no-code relational-database and spreadsheet platform operated by **SeaTable GmbH** (117er Ehrenhof 5, 55118 Mainz; HRB 49723 AG Mainz; VAT DE331940591; DUNS 343248411; managing directors Christoph Dyllick-Brenzinger and Dr. Ralf Dyllick-Brenzinger). The product is positioned as the EU-sovereignty-first Airtable alternative: multi-type column tables, Kanban/gallery/calendar/map views, Python and JavaScript automations, native app builder, API-first architecture, and integrations with Zapier, Make, and n8n, all without leaving Germany. The compliance posture is among the strongest in this directory. SeaTable Cloud is hosted exclusively on **Exoscale** (Akenes SA, Switzerland, operating certified Frankfurt and Munich data centres: ISO 9001/14001/27001/50001, PCI DSS 3.2, SOC-2 Type II for Munich) with additional infrastructure on **Hetzner Online GmbH** (Germany only). The sub-processors list published at /de/unterauftragnehmer explicitly names only EU-incorporated vendors: Stripe Payments Europe (IE), Brevo/Sendinblue (DE), TeamViewer Germany (DE), Speicherbox (CH), and Zammad (DE self-hosted). The privacy policy states explicitly that no AWS, Google, or Microsoft cloud services are used and that no data transfers outside the EU occur for normal operation. A full public DPA at /de/auftrag-zur-auftragsverarbeitung and a technical/organisational measures document (/de/technisch-organisatorische-massnahmen) are available for download without enterprise gating. Pricing in EUR: Free tier covers up to 25 users with 10,000 rows, 2 GB storage, and 100 automations/month. **Plus €7/user/month** (annual billing) expands to 50,000 rows, 50 GB, and 500 automations. **Enterprise €14/user/month** adds unlimited rows, 100 GB, SAML/OAuth SSO, and advanced admin controls. On-premise **SeaTable Server** licences available for 3, 10, 25, and 50+ users with full Enterprise features. Best fit: DACH and EU SMBs, non-profits, and public-sector teams that need an Airtable-class no-code database with German data residency and zero US-cloud exposure, and IT buyers who want both managed-cloud and on-premise options from the same German vendor. **Compliance rationale:** SeaTable GmbH (Mainz, Germany; HRB 49723 AG Mainz; founders Christoph and Dr. Ralf Dyllick-Brenzinger) hosts all cloud data on Exoscale Frankfurt + Munich (ISO 27001 / PCI DSS certified, Swiss-owned) and Hetzner DE with no US sub-processors anywhere in the customer-data path (explicitly excludes AWS, Google, Microsoft) and publishes both a public DPA and a named sub-processors list; EU-owned, EU-hosted, with the only US sub-processor being **Stripe** (billing/payments only, ancillary and outside the customer-data path), so **CLOUD Act exposure is none**. **Sub-processors mapped:** 6 total, 1 US-owned - Stripe Payments Europe Ltd. (Ireland): Customer management, invoicing, payment processing; ancillary [US-owned] - Akenes SA (Exoscale) (Switzerland): Hosting of test/production systems (database, storage, backup, web hosting) - Hetzner Online GmbH (Germany): Hosting of dev/test/production systems, backup and email - Sendinblue GmbH (Brevo) (Germany): Email marketing system - Speicherbox GmbH (Switzerland): Server support and maintenance - TeamViewer Germany GmbH (Germany): Remote maintenance software and service ### Sender: https://euvetted.com/p/sender - Website: https://www.sender.net - Category: Email marketing - Country of incorporation: Lithuania - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium - Founded: 2012 - Last verified: 2026-05-10 Lithuanian-founded budget email marketing tool with a generous free tier (2,500 subscribers, 15,000 emails/month). Sender is a Lithuanian-founded email marketing platform operated by UAB Sender.lt (Lvivo st. 25, Vilnius; company code 302820904, VAT LT100008985714). It targets SMBs, e-commerce, non-profits, and event organizers as a low-cost MailerLite alternative, with a Free Forever tier covering 2,500 subscribers and 15,000 emails/month, automation, landing pages, signup forms, a 1,600+ template library, and integrations for WordPress/WooCommerce/Shopify/PrestaShop/Zapier. The vendor reports more than 180,000 customers worldwide. Where Sender falls short for procurement-grade buyers is transparency. The public privacy policy does not name specific sub-processors, does not disclose the hosting provider or data-centre location, and does not document a Standard Contractual Clauses or Data Privacy Framework basis for any US transfers; it only mentions "third parties...such as a credit card processing company" without identifying them. Dedicated /dpa/, /sub-processors/, and /security/ paths return 404, and the pricing page itself fails to render the Standard plan price (toggle visible across USD/EUR/GBP/AUD with a 30% annual discount). For a Lithuanian-incorporated vendor that is structurally EU-owned, this lack of disclosure is the single biggest compliance-score limiter. Best fit: solopreneurs, small e-commerce shops, and creators who want a generous free tier and EU-incorporated billing, and don't require enterprise-grade compliance documentation. Mid-market and procurement-led buyers should look at MailerLite (LT, broader transparency), Brevo (FR, public DPA), or CleverReach (DE, ISO 27001 + EU-only customer-data hosting) instead until Sender publishes a sub-processors list and DPA. **Compliance rationale:** Lithuanian UAB Sender.lt with a generous free tier and large customer base, but the public privacy policy does not name sub-processors, disclose hosting location, or document SCC/DPF for US transfers, and dedicated DPA / sub-processors / security pages return 404. EU-owned legal entity but significant transparency gaps: no public DPA, no named sub-processors, no disclosed hosting region. ### sevdesk: https://euvetted.com/p/sevdesk - Website: https://sevdesk.com - Category: Accounting - Country of incorporation: Germany - Hosting country: Germany (Offenburg) - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid (from €9/month) - Founded: 2013 - DPA: https://assets.ctfassets.net/27fz81okgxt2/6b9uv7Ip3xGjkiMWh5TwjP/3772843b6613ab3f99d3af9e69fc991d/Auftragsverarbeitungsvertrag__inkl._TOMs_-_Kunde_-_Stand_14.07.2025.pdf - Sub-processors list: https://assets.ctfassets.net/27fz81okgxt2/6b9uv7Ip3xGjkiMWh5TwjP/3772843b6613ab3f99d3af9e69fc991d/Auftragsverarbeitungsvertrag__inkl._TOMs_-_Kunde_-_Stand_14.07.2025.pdf - Last verified: 2026-05-12 German DACH-focused SMB accounting / invoicing SaaS (Offenburg, est. 2013); now a Cegid Company under KKR-controlled French parent. **sevdesk** (Offenburg, Germany, founded 2013) is one of the most-installed DACH accounting tools for freelancers, founders, and SMBs: pricing starts at **€8.90/mo billed bi-annually**, with German DSGVO + GoBD compliance built in. As of 2022 it is **a Cegid Company**: Cegid is the French ERP / accounting group acquired by **KKR** (US private equity) in 2022 for ~€7B. So the operating brand is German, the immediate parent is French, and the ultimate beneficial owner is US private equity. For DACH SMB procurement this nuance matters: nominally European, materially US-controlled at the group level. **Compliance rationale:** **sevdesk** (Offenburg DE, founded 2013) is DACH-focused SMB accounting with **EU hosting and from €8.90/mo**, but as of 2022 the company is **a Cegid Company** (French ERP group acquired by US PE giant KKR); `eu_hq_us_funded` via French parent which itself is US-PE-controlled; CLOUD Act exposure material via the KKR ownership chain; DPA not surfaced on public site. ### Shopware: https://euvetted.com/p/shopware - Website: https://www.shopware.com - Category: E-commerce - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid (from €600/month) - Founded: 2000 - Certifications: ISO27001, SOC2 - DPA: https://www.shopware.com/de/datenschutz/avv/ - Sub-processors list: https://www.shopware.com/de/datenschutz/avv/ - Last verified: 2026-05-12 German mid-market commerce platform (Schöppingen, est. 2000); Cloud entry €600/mo. PayPal owns ~41% as of Oct 2025. **Shopware** (Schöppingen, DE, founded 2000) is the most visible German Shopify alternative but is structurally **NOT** in Shopify's SMB price range: Cloud **Rise plan starts at €600/month excl. VAT**, with pricing scaling on GMV. The free open-source **Community Edition** is self-hosted and is the realistic indie / SMB path, not the SaaS Cloud. Ownership changed materially in **October 2025**: PayPal took over Carlyle's stake from the 2022 $100M Carlyle + PayPal round, bringing **PayPal's stake to ~41%**. PayPal is a US-public company on Nasdaq, which is a substantive CLOUD Act-relevant ownership flip from the 2024 "eu_owned" perception. Certifications: **ISO 27001 + SOC 2 Type II + PCI DSS + GDPR**. EU data centres claimed; specific provider not transparently named on public site. Best fit for mid-market DACH merchants who need a full-control B2B+B2C platform with on-prem option, **not** for solo merchants comparing Shopify Basic ($39/mo) prices. **Compliance rationale:** **shopware AG** (Schöppingen DE, HRB 11471 Coesfeld) is German-incorporated and EU-hosted with **ISO 27001 + SOC 2 Type II + PCI DSS**, but **PayPal (Nasdaq: PYPL) acquired Carlyle's stake in October 2025 and now holds ~41%**, flipping the ownership signal to `eu_hq_us_funded` and creating material CLOUD Act exposure via the US-public-company parent stake; founders Hamann still majority-own. ### Signaturit (Namirial): https://euvetted.com/p/signaturit - Website: https://www.signaturit.com - Category: E-signature - Country of incorporation: Spain - Hosting country: Spain (Barcelona) - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2013 - DPA: https://ivnosys.com/signaturit-platform/en/dpa/ - Sub-processors list: https://ivnosys.com/signaturit-platform/en/subprocessors/ - Last verified: 2026-07-06 Barcelona-based Spanish digital-trust group (Signaturit, a Namirial company; parent Namirial acquired by Bain Capital, US PE, 2025), 4 QTSPs with highest eIDAS qualifications; platform hosted at rest on AWS. Signaturit Group is a Barcelona-headquartered Spanish digital-trust services group, now consolidated under the Italian parent **Namirial S.p.A.** (Senigallia, Italy), itself one of Europe's largest Qualified Trust Service Providers (QTSPs) under eIDAS. The group operates **four Qualified Trust Service Providers** under one corporate umbrella, holds the highest eIDAS qualifications (Qualified Electronic Signatures, Qualified Electronic Seals, Qualified Time Stamps, Qualified Website Authentication Certificates), and is regularly audited by national regulators across the EU member states where it operates. The product surface covers digital identity verification, identity wallets, qualified electronic signatures, certificate creation and management, document verification, digital preservation, certified communications (email, SMS), KYC, and electronic notifications. In **February 2025 Signaturit acquired Validated ID**, the Barcelona-based digital-identity pioneer founded in 2012 and notably the **first Qualified Trust Service Provider prepared for eIDAS 2** with the EBSI-compliant VIDwallet mobile identity wallet (EBSI is the European Blockchain Services Infrastructure built under the European Commission's digital-identity strategy). The merger consolidates Signaturit's leadership in EU digital trust services and aligns the group with the upcoming eIDAS 2 framework rollout. Combined with parent Namirial, the resulting group is among the largest pure-play EU digital-trust providers serving banks, insurance, telecoms, public sector, and regulated industries. Two sovereignty caveats, corrected at the July 2026 re-verify and both drawn from primary sources the original audit missed. Ownership: the combined group is co-controlled by two US private-equity firms. Namirial was acquired by **Bain Capital** (US, Boston) in a 2025 deal valuing it at roughly €1.1B (closed around July 2025), and Signaturit was itself backed by **PSG Equity** (Providence Strategic Growth, US, Boston) before the two agreed to merge in July 2025; the 2026 cap table runs Bain Capital, Ambienta (the Italian PE seller, reinvested as a minority), PSG Equity and the founders and management. Barcelona and Senigallia remain the operating headquarters, so the group is recorded as `eu_hq_us_funded` (EU-headquartered, US-capital-controlled) rather than fully EU-owned. Infrastructure: the published Signaturit Platform sub-processor annex shows the platform is hosted at rest on **Amazon Web Services** (a US-owned provider, with EU servers in Ireland), and one-time-password SMS and transactional email run through **Twilio** and **SendGrid** (both US, processing partly in the US), which places the listing at `cloud_act_exposure: material`. The eIDAS QTSP status, the public DPA and the EU data-residency posture are still real strengths. Best fit: regulated industries requiring **Qualified Electronic Signatures (QES) under eIDAS**: Spanish public sector, French / Italian banks, EU-wide financial services subject to PSD2 and AML/KYC, healthcare workflows requiring qualified signatures. Pricing is enterprise / volume-based; specific entry-tier EUR figures were not captured at audit. On eIDAS qualification Signaturit sits alongside Yousign (FR), Skribble (CH) and Universign (FR) among the strongest picks in this directory; buyers whose priority is the cleanest ownership-and-sub-processor story with no US-owned infrastructure in the at-rest path should weigh **Skribble (Switzerland, `cloud_act_exposure: none`)** above the Namirial-group options, which now share the same AWS hosting and US-PE parent. **Compliance rationale:** Signaturit Group is the Barcelona-headquartered Spanish digital-trust group operating **four Qualified Trust Service Providers with the highest eIDAS qualifications**, regularly audited by national regulators, and strengthened in February 2025 by the acquisition of Validated ID (the first QTSP prepared for **eIDAS 2**, with the EBSI-compliant VIDwallet). Two sovereignty caveats corrected at the 2026-07 re-verify, both from primary sources the original audit missed: (1) ownership — the combined group is **co-controlled by two US private-equity firms**: **Namirial S.p.A. was acquired by Bain Capital (US, Boston) in 2025** (~€1.1B valuation, closed ~July 2025), and **Signaturit was itself PSG Equity (US, Boston) backed**, the two merging in July 2025 with Ambienta (IT) and founders/management as minority holders, so the group is `eu_hq_us_funded`, not the `eu_owned` recorded in May; (2) CLOUD Act — the published Signaturit Platform DPA sub-processor annex shows the platform is **hosted at rest on Amazon Web Services** (US-owned; EU servers in Ireland) with OTP/SMS and transactional email via Twilio and SendGrid (US), so exposure is `material`, not `none`. eIDAS QTSP status, a public DPA and EU data residency remain genuine strengths; the score sits at 3/5, the same tier as Signicat, capped by the US-owned at-rest sub-processor and the US-PE parent. **Sub-processors mapped:** 17 total, 9 US-owned - Amazon Web Services EMEA SARL (Luxembourg): Primary hosting / storage of information on the platform (servers in Ireland, EU) — customer data at rest [US-owned] - Atlassian Pty Ltd (Australia): Project/incident tracking and collaboration (processing in Ireland, EU); ultimate parent Atlassian Corp is US (Delaware) incorporated [US-owned] - Cloudflare, Inc. (United States): Content Delivery Network / web traffic protection (processing in EU, Spain) [US-owned] - Functional Software, Inc. (Sentry) (United States): Error analysis/detection and log monitoring (processing in EU, Spain) [US-owned] - Mailgun Technologies, Inc. (United States): Inbound email parsing for the signaturit.com MX domain (processing in EU: Belgium/Germany) [US-owned] - SendGrid, Inc. (United States): Transactional email from the platform (processing in the US, SCCs + adequacy) [US-owned] - Twilio Inc (United States): OTP codes via SMS required to complete signature requests (servers in the US, SCCs + adequacy) [US-owned] - Twilio Ireland Ltd (Ireland): SMS/RCS/WhatsApp/Telegram/email messaging (processing in EU and USA; international transfer to US for US-bound recipients); Twilio group is US-owned [US-owned] - Zendesk, Inc (United States): Customer-service ticketing (processing in Ireland, EU) [US-owned] - CM Communication Platform & Technology, S.L.U. (Spain): SMS / messaging (EU processing) - Link Mobility Italia S.r.l (Italy): SMS/RCS/WhatsApp/Telegram/email messaging (EU processing) - LINK Mobility Spain SL (Spain): SMS / messaging (EU processing) - Lleidanetworks Serveis Telemàtics, S.A. (Spain): SMS / messaging (EU processing, Spain) - Mitto AG (Switzerland): SMS/RCS/WhatsApp/Telegram/email messaging (EU processing) - Namirial S.p.A. (Italy): Routing service for SMS/RCS/WhatsApp/Telegram/email messaging (parent group; controlled by Bain Capital, US PE, since 2025) - Veridas Digital Authentication Solutions, S.L. (Spain): Video ID product only: facial biometrics, liveness detection, OCR ID extraction (EU processing) - Vonage B.V. (Netherlands): SMS/RCS/WhatsApp/Telegram/email messaging (EU processing); ultimate parent Ericsson (Sweden) ### Signicat: https://euvetted.com/p/signicat - Website: https://www.signicat.com - Category: E-signature - Country of incorporation: Norway - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2006 - Certifications: ISO27001, ISO27018, SOC2 - DPA: https://developer.signicat.com/terms/agreements/appendix-6-data-processing-agreement.html - Sub-processors list: https://developer.signicat.com/terms/agreements/appendix-9-sub-processors/version-2.0.html - Last verified: 2026-06-12 Trondheim-based pan-European eIDAS QTSP for digital identity, e-ID and qualified e-signatures; Nordic Capital-owned, EEA-hosted on US hyperscalers. Signicat is a Trondheim (Norway) headquartered pan-European digital-identity and electronic-trust platform, describing itself as "the leading provider of digital identity solutions in Europe" with 21,000+ companies served and 500+ staff across Norway, Sweden, Finland, Denmark, the Netherlands, Germany, UK, Spain, Portugal, Romania, Lithuania, Estonia and Latvia. It is a registered eIDAS Qualified Trust Service Provider (QTSP) and one of the first certified under eIDAS 2.0, with qualified services spread across jurisdictions: qualified time-stamps (Norway, via Buypass/SK ID), qualified certificates and remote signature-creation device management (Spain, via UANATACA/ACCV) and qualified signature/seal validation (Lithuania, via the 2021-acquired Dokobit). Beyond e-signing it covers bank-grade e-ID authentication (BankID, MitID, iDIN, itsme), onboarding/KYC, and fraud/identity verification (bolstered by the Sphonic and Inverid acquisitions). Ownership is the key nuance: since April 2019 Signicat has been majority-owned by Nordic Capital (a European private-equity investor, via Fund IX), acquired from Secure Identity Holding and Viking Venture III; Viking Venture III re-invested and remains a Norwegian minority shareholder alongside employee shareholders. There is no US-VC control and no US parent, but Nordic Capital is a PE firm whose funds use Jersey/Luxembourg structures, so this is "other" rather than a clean local-hero "eu_owned" tag. Compliance posture is strong on paper: ISO/IEC 27001:2022, ISO/IEC 27018:2019 (DNV-verified), SOC 2 Type II, OpenID Certified, plus ENS High and Cyber Essentials Plus, with a GDPR-aligned DPA and a public sub-processors appendix, and eIDAS QTSP status. The caveat for sovereignty-focused buyers is infrastructure: the platform is multi-cloud across Google Cloud, AWS and Microsoft Azure (all EEA regions) plus T-Systems and Orange Business, three US-owned hyperscalers at rest, which drives CLOUD Act exposure to "material" despite EEA data residency. Best fit: regulated EU enterprises (banking, insurance, public sector) needing broad national e-ID coverage and qualified signing under one contract; buyers who weight US-infrastructure exclusion above feature breadth should prefer Yousign, Universign or Signaturit. **Compliance rationale:** Signicat AS (Trondheim, Norway; eIDAS Qualified Trust Service Provider; ISO/IEC 27001:2022 + 27018:2019 (DNV) + SOC 2 Type II) is a genuine European identity/trust group with an all-EU/EEA group entity chain and a public DPA + public sub-processors list, but its core platform runs multi-cloud on three US-owned hyperscalers (Google Cloud EMEA/IE, AWS/LU, Microsoft Azure/IE), all with EEA data residency, and Mailchimp (US, USA-stored) is used for some notifications, so despite EEA hosting it carries meaningful CLOUD Act exposure and three US-owned sub-processors, which caps the score at 3/5. ### Simple Analytics: https://euvetted.com/p/simple-analytics - Website: https://www.simpleanalytics.com - Category: Web analytics - Country of incorporation: Netherlands - Hosting country: Netherlands - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €15/month) - Founded: 2018 - Sub-processors list: https://docs.simpleanalytics.com/data-security-and-ownership - Last verified: 2026-05-10 Dutch privacy-first web analytics on Worldstream + Leaseweb (NL) and Bunny CDN (SI), zero-knowledge encryption, cookieless tracking. Simple Analytics is a Dutch privacy-first web analytics product operated by Simple Analytics B.V. (registered in Bussum, Netherlands; KVK 60978856) and founded by Adriaan van Rossum in 2018. It is one of the cleanest "no-CLOUD-Act-exposure" picks in the web-analytics category: customer analytics data is stored on bare-metal infrastructure at Worldstream and Leaseweb in the Netherlands, the CDN runs through Bunny (Slovenia), and the company explicitly states that "only Simple Analytics holds the decryption keys", meaning even the hosting providers cannot read unencrypted customer data. The reference customer list is unusually strong for a small vendor: the Bank of England, Michelin, Hyundai, and the UK Government all appear on the homepage. Compliance positioning is built on a "no personal data" principle: no cookies, no IP collection, no device fingerprinting, no persistent identifiers, which lets the product claim GDPR, UK PECR, German TTDSG, CCPA, and even HIPAA fitness without a Business Associate Agreement. The company publishes documentation of its compliance posture at docs.simpleanalytics.com (compliance, compliance-faq, data-security-and-ownership) and includes correspondence from the UK ICO confirming that no consent banner is required when analytics providers neither read nor write to user devices. Where Simple Analytics is weaker for procurement-grade buyers is in the format of its DPA and sub-processors disclosures: the dedicated /dpa, /sub-processors, and /privacy-policy paths returned 404 or 301-redirect at audit, and there is no single downloadable DPA artefact; the relevant information is split across docs pages. Pricing is freemium and EU-buyer-friendly: the free tier covers one user, five websites, 30 days of history, and unlimited pageviews; Simple is €15/month (one user, ten websites, three years of retention); Team is €40/month plus €20 per additional user; Enterprise is custom-priced with SLA and priority support. EUR/USD/GBP currency switching, bank transfer accepted on invoices €500+, plus Bitcoin/Apple Pay/Google Pay. Best fit: privacy-conscious EU companies, public-sector buyers, and indie publishers who want a no-cookie, no-CLOUD-Act analytics stack with named Dutch hosting and a credible reference list, and don't yet need a unified DPA download. **Compliance rationale:** Dutch B.V. founded by Adriaan van Rossum running a fully EU-incorporated infrastructure stack (Worldstream and Leaseweb in the Netherlands plus Bunny CDN in Slovenia) with zero-knowledge encryption (only Simple Analytics holds the decryption keys), no cookies, no IP collection, and no US-owned cloud anywhere on the customer-data path; EU-owned and EU-hosted with no CLOUD Act exposure, but no single unified public DPA or named sub-processors annex (infrastructure is disclosed in /data-security-and-ownership but a procurement-grade DPA download is missing). **Sub-processors mapped:** 6 total, 0 US-owned - Bunny (Slovenia): CDN, DNS - Hetzner (Germany): Infrastructure hosting - Hyperping (France): Uptime monitoring - Intention (Netherlands): Domain name provider - Leaseweb (Netherlands): Infrastructure hosting - Worldstream (Netherlands): Infrastructure hosting ### SimpleLogin: https://euvetted.com/p/simplelogin - Website: https://simplelogin.io - Category: Email aliasing - Country of incorporation: Switzerland - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: freemium (from €3.5/month) - Founded: 2019 - DPA: https://proton.me/legal/dpa - Sub-processors list: https://simplelogin.io/privacy/ - Last verified: 2026-07-10 Paris-founded (2019) email-alias service acquired by Proton AG in 2022; unlimited aliases, custom domains, PGP forwarding and catch-all on Premium, hosted across Proton/UpCloud data centres in DE, CH, NL and FR. SimpleLogin was founded in Paris in 2019 by Son Nguyen Kim, a Vietnamese-French engineer and former Criteo machine-learning researcher, and acquired by **Proton AG** (Geneva, Switzerland, company number CHE-354.686.492) in April 2022; the founding team went on to build Proton Pass. SimpleLogin is now legally operated by Proton AG rather than a separate French entity. Data is hosted on Proton's own servers and on UpCloud, across data centres in Germany, Switzerland, the Netherlands and France; no single country is stated as the primary location. The Free plan includes 10 aliases, 1 mailbox, reply-from-alias, browser extensions and mobile apps; Premium (from $4/month billed monthly, or $36/year billed annually) adds unlimited aliases, unlimited custom domains, catch-all domains, five subdomains, unlimited mailboxes and PGP encryption of forwarded mail. The client and server code is open source under AGPL-3.0 and self-hostable via Docker (`github.com/simple-login/app`). Named sub-processors: Paddle (card/PayPal payments), Apple (iOS in-app payments), hCaptcha (bot protection on login/register), Cloudflare (DNS), and Zendesk (support tickets); none of these touch alias or forwarded-email content at rest. Proton AG publishes a general Data Processing Agreement, but it does not name SimpleLogin explicitly among covered services. **Compliance rationale:** SimpleLogin is operated by **Proton AG** (Geneva, Switzerland, company number CHE-354.686.492), the same legal entity behind Proton Mail, following its April 2022 acquisition of the Paris-founded SimpleLogin team. Alias and mailbox data is hosted on Proton's own servers and on UpCloud, across data centres in Germany, Switzerland, the Netherlands and France, all EU/EEA or Swiss jurisdictions, so no core data flows through US infrastructure. Proton AG publishes a general Data Processing Agreement covering "email, calendar, drive and other services", which is publicly accessible without login but does not name SimpleLogin explicitly among the covered products. Named sub-processors are Paddle and Apple for payments, hCaptcha for bot protection, Cloudflare for DNS, and Zendesk for support tickets: all ancillary, none touching alias or forwarded-email content at rest, which keeps CLOUD Act exposure minor rather than material. The determining factor holding this listing at 4/5 rather than 5/5 is that the DPA is a company-wide document rather than a SimpleLogin-specific one, combined with a longer list of ancillary US-owned sub-processors than Proton's own mail-only listing carries. **Sub-processors mapped:** 9 total, 5 US-owned - Apple (United States): iOS in-app payment processing [US-owned] - Cloudflare (United States): DNS [US-owned] - Coinbase Commerce (United States): Cryptocurrency payment processing [US-owned] - hCaptcha (United States): Bot protection on login and registration [US-owned] - Zendesk (United States): Support ticketing [US-owned] - Paddle.com Market Ltd (United Kingdom): Card and PayPal payment processing - Plausible Analytics (Estonia): Privacy-aware website analytics - Proton AG (Switzerland): Operator and primary hosting of alias and mailbox data at rest - UpCloud (Finland): Hosting across data centres in Germany, Switzerland, the Netherlands and France ### SimpleX Chat: https://euvetted.com/p/simplex-chat - Website: https://simplex.chat - Category: Video conferencing - Country of incorporation: United Kingdom - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: free (from €0/month) - Founded: 2021 - Last verified: 2026-06-05 UK-incorporated open-source E2EE messenger (SimpleX Chat Ltd, 2021) with no user identifiers of any kind; Double Ratchet + post-quantum key exchange; self-hostable relays, twice audited by Trail of Bits. SimpleX is an open-source end-to-end encrypted messaging network operated by **SimpleX Chat Ltd** (London, Companies House 13691484, incorporated October 2021; first app March 2022), founded by Evgeny Poberezkin. Its defining claim (which holds up against the source code, privacy policy and Trail of Bits' design review) is that it is the **first messenger with no user identifiers of any kind**. There is no account, no username, not even a random global ID: identity is established pairwise, per contact, using separate **unidirectional message queues**, so the relay servers only ever see per-queue addresses and can never reconstruct who is connected to whom. User profiles exist only on-device. Cryptographically, SimpleX uses the **Double Ratchet** algorithm over Curve448 keys with an additional NaCl cryptobox layer at the queue level, fixed-size message padding, and TLS 1.2/1.3 with restricted ciphers; a **post-quantum-resistant key exchange** is performed on every ratchet step. Relays hold only E2EE blobs that are deleted on delivery or after 21 days. Metadata privacy is further hardened by **private message routing** (v6+) and the option to route through a second independent operator (Flux) to split metadata between operators. The implementation was audited by **Trail of Bits** twice (a 2022 implementation review and a 2024 cryptographic-design review), neither finding critical issues. Everything is open source under AGPLv3 (github.com/simplex-chat/simplex-chat), and both the messaging (SMP) and file (XFTP) servers are self-hostable, including on EU infrastructure. The app is **free**: there is no paid tier; the project is funded by investment and donations. It ships consumer apps for iOS, Android, desktop and a terminal CLI, with DMs, groups, channels, audio/video calls, a business-chats feature and a bots API. The honest fit for an EU-sovereignty buyer is nuanced: SimpleX is **UK-incorporated** (GB, outside the EU, though the UK holds an EU adequacy decision), and it is **venture-backed including US investors**: a 2024 pre-seed round was led by Jack Dorsey alongside Asymmetric Capital Partners, on top of a 2022 round from Village Global and angels (all disclosed as passive, no board seats). The default preset relays' hosting country is not publicly disclosed. So the strongest privacy story here is the architecture (no identifiers, self-hostable, twice audited), not EU ownership or EU-default hosting. Best fit: privacy-maximalist individuals and teams who can self-host relays in the EU and want the strongest available metadata and identity privacy; not the pick for a buyer whose binding constraint is EU ownership or a published DPA. **Compliance rationale:** SimpleX Chat Ltd (London, Companies House 13691484, incorporated 2021) operates **SimpleX**, described as the first messaging network with **no user identifiers of any kind**, not even random IDs: identity is pairwise per-queue using separate unidirectional message queues per contact, so relays never see a global user graph and store no profiles. Messages are E2EE (Double Ratchet over Curve448 with a post-quantum-resistant key exchange added each ratchet step) and deleted on delivery or after 21 days; private message routing splits metadata across operators. Audited twice by **Trail of Bits** (2022 implementation, 2024 cryptographic design) with no critical findings; open source under AGPLv3, with self-hostable SMP/XFTP servers (deployable on EU infrastructure). Two caveats keep this below a 5 for a strict EU-sovereignty reviewer: the company is **UK-incorporated** (GB, not EU, though the UK holds EU adequacy), and it is **VC-backed including US investors** (2024 round led by Jack Dorsey with Asymmetric Capital Partners; investments disclosed as passive, no board seats). Default-server hosting country is not transparently disclosed. The honest EU-fit angle is self-hostable in the EU with no server-side identity, not EU-hosted by default. ### sipgate: https://euvetted.com/p/sipgate - Website: https://www.sipgate.de - Category: Video conferencing - Country of incorporation: Germany - Hosting country: Germany (Düsseldorf) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2004 - DPA: https://www.sipgate.co.uk/gdpr - Sub-processors list: https://www.sipgate.co.uk/gdpr - Last verified: 2026-05-11 Düsseldorf-based German VoIP + cloud-telephony operator (founded 2004, self-financed), 130 employees, all-German infrastructure. sipgate is a Düsseldorf-headquartered German cloud-telephony, VoIP, and video-conferencing operator founded in 2004 by **Tim Mois** and **Thilo Salmon**, co-founders who continue to lead the company two decades later. The company is **self-financed with no outside investors** ever taken, a structurally unusual posture for a 21-year-old German tech firm and one of the cleanest ownership architectures in the directory. All 130 employees work from a single Düsseldorf office; all customer infrastructure and servers are physically located in Germany. The product surface is VoIP-first (business phone numbers, IP-PBX features, SIP trunking, cloud-telephony management, fax, SMS) with video-meeting and conferencing functionality layered on top of the telephony stack. For an EU-sovereignty audit sipgate is a textbook clean listing. The legal entity is a German GmbH; ownership is founder-controlled and self-financed (no PE / no VC / no parent conglomerate); customer voice and video data are stored on German infrastructure under German law and BDSG (Bundesdatenschutzgesetz) protection; cross-border transfers between EU and DE require no SCCs; no US legal entity exists for non-EEA customers. The founders are also widely known in the German engineering culture for sipgate's strong remote-work / pair-programming / "team-Fridays" engineering culture, and the company has been a frequent open-source contributor (sipgate.io developer brand, public APIs). Pricing is not self-serve in the consumer sense: sipgate sells business cloud-telephony tiers with VoIP minute bundles, number ranges, and team-plan seats; specific entry-tier figures were not captured at audit (the .com domain 301-redirects to .de). Best fit: German and Austrian SMBs replacing legacy Deutsche Telekom desk phones with cloud-telephony; European businesses that need a single vendor for VoIP + video + SMS with explicit German data residency; companies that specifically want a founder-controlled, self-financed, no-investor-pressure vendor. Buyers needing enterprise-grade video-only conferencing (large webinar, complex moderation) should also evaluate Whereby (NO), Tixeo (FR), or Pexip (NO), all covered in this category. **Compliance rationale:** sipgate GmbH (Düsseldorf, founded 2004 by Tim Mois and Thilo Salmon who still lead the company) is **self-financed with no outside investors**, operates a single office in Düsseldorf with 130 employees, and runs all infrastructure and servers on German soil: 'everything subject to the strictest of German standards and laws' per the corporate page. Primary focus is German cloud-telephony and VoIP for SMBs with video-meeting capabilities layered in. EU-owned (German GmbH, founder-controlled, no external investors), EU-hosted (all-German infrastructure), no CLOUD Act exposure, no US legal entity or US capital. ### Skribble: https://euvetted.com/p/skribble - Website: https://www.skribble.com - Category: E-signature - Country of incorporation: Switzerland - Hosting country: Switzerland (Zurich) - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2018 - Certifications: ISO27001 - DPA: https://www.skribble.com/en-eu/dpa/ - Sub-processors list: https://www.skribble.com/en-eu/privacy/ - Last verified: 2026-05-11 Zurich-based Swiss e-signature platform with dual ZertES + eIDAS QES via Swisscom partnership; ISO 27001, 4,000+ DACH customers. Skribble is a Zurich-headquartered Swiss e-signature platform that distinguishes itself in the QES market by uniquely covering **both Swiss ZertES and EU eIDAS qualified-signature regulations under a single platform**. Founded around 2018 with focus on the DACH region (Germany, Austria, Switzerland), the company has scaled to 4,000+ corporate customers and built its QES capabilities on a partnership with **Swisscom AG**, the Swiss federal-recognised Qualified Trust Service Provider that issues the underlying qualified certificates conforming to both **ZertES** (the Swiss Federal Act on Electronic Signatures) and **eIDAS** (the EU regulation). This dual-bar coverage matters because Switzerland and the EU are separate jurisdictions with no automatic mutual recognition of qualified signatures; a Swiss-only or EU-only QTSP can leave one half of a DACH transaction legally exposed, while Skribble's Swisscom-anchored stack delivers QES that is fully binding under both regimes. Compliance posture is procurement-grade: **ISO 9001 + ISO 27001** certified at the company level, GDPR + DSGVO compliant, Swiss federal legal-validity coverage under ZertES via Swisscom-issued certificates. The platform handles identity verification (video-ident, qualified e-ID, GwG / FATF-aligned KYC for higher signature tiers), signing workflows (Simple, Advanced, Qualified electronic signatures), and audit-trail packaging. Switzerland holds an EU adequacy decision under Art. 45 GDPR so cross-border EU↔CH transfers require no SCCs. Pricing is enterprise / tier-based with monthly per-user and per-document pricing; specific entry-tier EUR figures were not captured at audit. Best fit: DACH companies with material cross-border CH↔EU contracting flows (Swiss banks contracting EU customers, EU insurers signing Swiss policy-holders, Swiss-EU joint ventures, dual-jurisdiction employment contracts), companies in regulated industries needing QES under either ZertES or eIDAS, and any organisation that values having Swisscom-issued qualified certificates as the trust anchor. Procurement-grade EU-only buyers operating purely inside the EU may prefer Yousign (France, ANSSI-supervised) or the Signaturit / Namirial group (though the latter is US-private-equity-owned since 2025 and hosted at rest on AWS, so `cloud_act_exposure: material`), but for any DACH workflow Skribble's dual-regime QES is structurally differentiated. **Compliance rationale:** Skribble is a Zurich-based Swiss e-signature platform that uniquely covers **both ZertES (the Swiss Federal Act on Electronic Signatures) AND eIDAS (the EU regulation)** for Qualified Electronic Signatures via its partnership with **Swisscom AG**, the qualified-certificate issuer that anchors the QES infrastructure. ISO 9001 + ISO 27001 certified, GDPR + DSGVO compliant, serving 4,000+ companies in DACH (Germany / Austria / Switzerland). Swiss legal entity + EU adequacy decision + Swisscom QTSP backbone with no CLOUD Act exposure and a public DPA; the dual-bar ZertES + eIDAS coverage is the directory's strongest cross-jurisdiction QES capability for buyers operating across CH and EU. ### Soverin: https://euvetted.com/p/soverin - Website: https://soverin.com - Category: Private email - Country of incorporation: Netherlands - Hosting country: Netherlands - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €3/month) - Founded: 2014 - Certifications: ISO27001 - Last verified: 2026-05-18 Independent Dutch paid email (from €3.25/mo); ISO 27001 + NIS2 Ready, all data in Netherlands, full IMAP/SMTP/CalDAV/CardDAV compatibility. **Soverin** is operated by **Soverin B.V.** (Amsterdam, KvK 61552275) and has been running since around 2014 as an **independent, self-funded Dutch email provider**: no VC backing, no US parent. The service is paid-only (from **€3.25/mo / €39/yr**, with optional .nl domain at €13/yr); there is no free tier, which is consistent with the "no ads, no profiling, no third-party data" pitch. Mail, calendar and contacts are reachable via standard **IMAP / SMTP / CalDAV / CardDAV** with any client. Soverin deliberately does not implement end-to-end encryption in the Proton/Tuta sense, in exchange for that full protocol compatibility; data is encrypted in transit (TLS) and at rest on the storage layer, and per the privacy statement is processed only within the EU. Certifications held: **ISO 27001**, ISO 14001, ISO 9001, **NIS2 Ready Mark**, perfect Internet.nl score (DNS / email / web / IPv6); NEN 7510 (Dutch healthcare InfoSec) listed as in-progress. The privacy statement names one unnamed sub-processor (external first-line customer support, under DPA + ISO scope) but the document is **not a publicly linked customer-facing DPA**, the key remaining gap given the otherwise clean EU ownership, EU hosting, and multiple ISO certifications. Positioning is squarely against US free webmail (no CLOUD Act exposure); UI in English and Dutch. **Compliance rationale:** **Soverin** is operated by **Soverin B.V.** (Amsterdam NL, KvK 61552275, founded ~2014), an **independent Dutch email provider** with paid-only mailboxes (from €3.25/mo), all data hosted in the Netherlands under EU law, EU-owned, no US parent, no CLOUD Act exposure. Holds **ISO 27001 / 14001 / 9001**, **NIS2 Ready Mark**, full **Internet.nl** score, NEN 7510 in progress. Gaps: **no publicly linked DPA**, no public sub-processors list (privacy statement mentions one unnamed external first-line support partner); the service is **TLS-encrypted, not end-to-end encrypted**, a deliberate trade-off for full IMAP/SMTP/CalDAV/CardDAV compatibility with any client. ### Stackfield: https://euvetted.com/p/stackfield - Website: https://www.stackfield.com - Category: Project management - Country of incorporation: Germany - Hosting country: Germany (Munich) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €9/month) - Founded: 2012 - Certifications: ISO27001, C5 - Last verified: 2026-05-18 Munich-based E2E-encrypted collaboration suite (Stackfield GmbH, 2012); ISO 27001 + BSI C5, DE data centres, AES-256 in browser. Stackfield is the Munich-based end-to-end-encrypted team-collaboration platform operated by **Stackfield GmbH** (Maximiliansplatz 17, 80333 Munich; HRB 199536 Local Court Munich; VAT DE283871998; managing director Cristian Mudure). Founded in 2012 by Christian Mudra and Christopher Diesing, the company serves 10,000+ companies with a single workspace that combines team chat, tasks, project management, document sharing, whiteboards, video conferencing, and email forwarding, positioned explicitly as the European E2E-encrypted alternative to Slack, Microsoft Teams, Asana, and Basecamp. Compliance posture is among the strongest in the project-management category. The product is **end-to-end encrypted with AES-256** applied in the browser before content is transmitted, meaning even Stackfield's own employees cannot read customer messages, files, or tasks. The company holds **ISO/IEC 27001** certification and **BSI C5** (the German government's Cloud Computing Compliance Criteria Catalogue), the same certification combination carried by Hetzner, IONOS, and STACKIT in the hosting category. All customer data is stored exclusively in **German data centres** with location-independent backup. In 2024 Stackfield raised a double-digit-million investment to scale the privacy-first product; founder-led, with no US-VC / US-PE involvement on record. Pricing in EUR is straightforward: Starter €9/user/month (up to 10 users, 6 GB storage, 3 rooms); Business €14/user/month (unlimited rooms and users); Premium €18/user/month (most popular: whiteboards, email forwarding, full video conferencing); Enterprise €28/user/month (SSO, API provisioning, unlimited organisations). 14-day trial of Premium with no credit card; AI add-on €3.90/user/month; Office editing add-on €2.40/user/month from Premium up. Best fit: German and DACH organisations that need a Slack/Teams replacement with E2E encryption by default, BSI C5 / ISO 27001 evidence for procurement, and a Munich-rooted vendor. Combined with Nextcloud (self-host) and MeisterTask (DE, listed below), Stackfield forms a strong "Microsoft 365 alternatives" cluster. **Compliance rationale:** **Stackfield GmbH** (Munich, Maximiliansplatz 17; HRB 199536; founded 2012 by Christian Mudra + Christopher Diesing; ~10,000 customer companies) combines team chat, tasks, projects, files, whiteboards, and video conferencing in a single workspace with **end-to-end AES-256 encryption applied in the browser before transmission** so vendor employees cannot read content; **ISO/IEC 27001 + BSI C5** certified, all data stored in **German data centres only**, founder-led, EU-owned with no CLOUD Act exposure. ### STACKIT: https://euvetted.com/p/stackit - Website: https://stackit.com - Category: Cloud & hosting - Country of incorporation: Germany - Hosting country: Germany (Neckarsulm) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2019 - Certifications: ISO27001, C5, EUCS - DPA: https://www.stackit.de/wp-content/uploads/2024/11/Data-Processing-Agreement_STACKIT-Cloud_Version-2.0.pdf - Last verified: 2026-05-18 German sovereign cloud built by Schwarz Digits (Lidl/Kaufland parent), 4 EU DCs, EU Cloud III €180M winner with SEAL-3 highest rating. STACKIT is the sovereign cloud built by Schwarz Digits, the IT and digital division of the privately-held Schwarz Group, parent of the European discount-retail giants Lidl and Kaufland. Headquartered in Bad Friedrichshall, Germany (Am Campus 1, 74177), STACKIT runs four European data centres at Neckarsulm (DC01, Schwarz Group HQ campus), Ellhofen (DC08, Heilbronn region), Ostermiething (DC10, Salzburg, Austria), and a fifth facility under construction in Lübbenau, Germany. The Schwarz Group has invested approximately €11B in STACKIT, making it one of the most heavily-capitalised European cloud-sovereignty bets and a structurally different proposition from VC-funded EU cloud upstarts: the parent retailer is a private German Stiftung-controlled group with €146B annual turnover, with no PE or US-VC exposure on the cap table at any layer. Sovereignty positioning is the entire product thesis. STACKIT markets itself as "100% European DNA" with the trio "Skalierbar. Sicher. Souverän" (scalable, secure, sovereign). The compliance footprint covers ISO 27001, BSI **C5**, **EUCS** (European Cybersecurity Certification Scheme for cloud services, ENISA), DORA-ready ICT-third-party status for regulated financial services, GDPR, and the Schwarz Group's own **ES³ (European Sovereign Stack Standard)** internal sovereignty measurement framework. The procurement validation came in two moves during 2026: (1) selection as one of four winners of the European Commission's €180M Cloud III sovereign-cloud framework (April 2026), with the highest **SEAL-3** rating signifying engineering against supply-chain disruptions originating outside the EU; and (2) selection by the Dutch Ministry of Justice and Security under the SLM Rijk framework as a sovereign cloud alternative. The product surface spans 11+ categories: infrastructure (compute, block/object storage, networking), managed databases, managed Kubernetes, AI workloads, and colocation. Pricing is via a configurable STACKIT Calculator; specific entry-tier figures were not captured at audit but the product is positioned mid-market to enterprise rather than indie/SMB. Best fit: EU public-sector procurement (post-Cloud III tender), DORA-regulated financial services, large EU corporates needing a non-VC-funded sovereign cloud, and any organisation aligning with Gaia-X or the EU Tech Sovereignty Package. Together with Hetzner, OVHcloud, and Scaleway, STACKIT forms the four-pillar EU hyperscaler-alternative stack on this directory. **Compliance rationale:** STACKIT (Bad Friedrichshall, German Schwarz Digits, the IT arm of privately-held Schwarz Group, parent of Lidl and Kaufland) is built explicitly as a sovereign-cloud alternative to AWS/Azure/GCP: ISO 27001 + BSI C5 + EUCS-aligned + DORA-ready, four EU data centres (Neckarsulm DC01, Ellhofen DC08, Ostermiething Austria DC10, fifth Lübbenau under construction), winner of the European Commission's €180M Cloud III tender (April 2026, SEAL-3 highest sovereignty rating) and the Dutch Ministry of Justice & Security SLM Rijk framework; EU-owned and EU-hosted with no CLOUD Act exposure. ### Stackscale: https://euvetted.com/p/stackscale - Website: https://www.stackscale.com - Category: Cloud & hosting - Country of incorporation: Spain - Hosting country: Spain (Madrid) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2013 - Certifications: ISO27001, ISO27017, ISO27018 - DPA: https://www.stackscale.com/msa.pdf - Sub-processors list: https://www.stackscale.com/privacy-subcontractors/ - Last verified: 2026-05-18 Spanish private cloud + bare metal (Stackscale, Grupo Aire), Madrid + Amsterdam DCs, ISO 27001/27017/27018 + ENS High. Stackscale is a Madrid-based Spanish private-cloud and dedicated-infrastructure provider founded in 2013 and part of **Grupo Aire** since 2022, the Spanish connectivity, VoIP, mobile-enabler, UCaaS, and cloud group also known as Aire Networks. Headquartered at Pl. Pablo Ruiz Picasso 1 in Madrid with offices in Amsterdam (Therese Schwartzestraat 69), Stackscale operates three data centres in Madrid, two in Amsterdam, plus additional facilities in Alicante, Valencia, and Portugal. The product targets IT integrators, IaaS / PaaS / SaaS providers, and medium-to-large enterprises with custom private-cloud builds, dedicated servers, and a multi-100G core network with 4+ Tbps of aggregated capacity. Compliance posture is one of the strongest in the Iberian / Benelux cloud market. Stackscale holds ISO/IEC 27001 plus ISO 27017 and ISO 27018 specifically scoped to cloud security and personal data protection, and is certified under the Spanish government's **ENS (Esquema Nacional de Seguridad)** at the **High** level, the most stringent ENS tier, required for processing sensitive public-sector and regulated data. The parent group Aire Networks additionally carries ISO 9001 (quality management), ISO 14001 (environmental management), ISO 22301 (business continuity), and the same ISO 27017 / 27018 / ENS High certifications. All infrastructure is located within the European Union (Spain, Netherlands, Portugal), which is particularly attractive for organisations that care about GDPR, data residency, and European regulatory compliance. Pricing is custom (the public /cloud/pricing/ URL returned 404 at audit) and oriented to private-cloud configurations rather than self-serve VPS instances; engagement is via sales for sizing and SLA negotiation. 99.99% SLA availability is advertised. Best fit: Spanish and broader Iberian SMBs and mid-market, Dutch and Benelux customers needing Amsterdam-region capacity, Spanish public-sector procurement requiring ENS High, and IT integrators or hosting resellers building infrastructure on top of a Spanish-owned EU-only stack. Together with Hetzner, OVHcloud, Scaleway, IONOS, UpCloud, STACKIT, Cleura, Exoscale, and Open Telekom Cloud / T Cloud Public, Stackscale rounds out the procurement-grade EU hyperscaler-alternative shortlist. **Compliance rationale:** Madrid-based Spanish private-cloud and bare-metal provider (Stackscale, part of Grupo Aire since 2022) running customer workloads exclusively across EU data centres in Madrid (×3), Amsterdam (×2), plus Alicante, Valencia and Portugal, with ISO/IEC 27001 + 27017 + 27018 and the Spanish government's **ENS (Esquema Nacional de Seguridad)** certification at the **High** level (the most stringent ENS tier): EU-owned and EU-hosted with no CLOUD Act exposure. ### StartMail: https://euvetted.com/p/startmail - Website: https://www.startmail.com - Category: Private email - Country of incorporation: Netherlands - Hosting country: Netherlands - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid (from €5/month) - Founded: 2014 - Sub-processors list: https://www.startmail.com/privacy/ - Last verified: 2026-05-15 Dutch private email (StartMail B.V., est. ~2014, by Startpage founders), NL-hosted, one-click PGP, unlimited aliases, USD-priced from $4.99/mo annual. StartMail is a privacy-focused email service operated by StartMail B.V. in the Netherlands. It was founded around 2014 by **Robert E.G. Beens** and **David Bodnick** (the same founders behind the **Startpage** privacy-focused search engine) and the two products share the broader Startpage / Surfboard Holding group history. The product positioning is straightforward: encrypted email under Dutch privacy legislation and GDPR, with one-click PGP encryption support, password-protected encrypted messages for recipients without PGP, unlimited disposable / alias email addresses, no advertising and no tracking, and IMAP/SMTP compatibility with standard email clients. The infrastructure side is clean: StartMail explicitly states that "our servers are located here as well" (referring to the Netherlands) meaning email storage stays under Dutch and EU law. PGP support is a real differentiator versus Gmail / Outlook / iCloud Mail (none of which offer first-class PGP) and against some other privacy-email vendors. A transparency report and a separate data-processing whitepaper are published. For an EU-sovereignty audit, two open questions are worth noting. First, the **Startpage group ownership history**: in 2019 Startpage announced a strategic investment from Privacy One Group, a subsidiary of US ad-tech company **System1**. The deal triggered significant community concern at the time about a US ad-tech investor's relationship to a privacy product. The 2026 status of that investor relationship needs human verification before this listing publishes; `ownership_signal: eu_owned` is provisional pending that check. Second, StartMail's own **pricing page is denominated in USD** (Personal $4.99/month annual = $59.88/year; Business $6.99/month annual = $83.88/year), an unusual choice for a Dutch B.V. and a real signal worth surfacing. DPA and sub-processors URLs were not directly captured at audit. Best fit: privacy-conscious EU users who want PGP-capable email under Dutch law with unlimited aliases, and who are willing to weigh the Startpage-group US-investor history. Buyers who want the strongest possible EU-sovereignty posture should prefer Tuta (DE, founder-owned, post-quantum), Mailbox.org (DE, BSI C5), Posteo (DE, anonymous signup) or Proton Mail (CH, Foundation-controlled), all elsewhere in this directory. **Compliance rationale:** StartMail is operated by **StartMail B.V.** in the Netherlands, founded around 2014 by Robert E.G. Beens and David Bodnick (the same founders behind the **Startpage** privacy search engine) with **servers physically located in the Netherlands** under Dutch privacy law and GDPR, **PGP encryption support** including one-click encryption and password-protected encrypted messages, unlimited disposable email aliases, and a published transparency report. Notable open questions: (a) the broader Startpage group has had **US ad-tech investor exposure historically** (the 2019 Privacy One Group / System1 investment was widely covered and triggered community concern. Current 2026 ownership status needs human verification before publishing; `ownership_signal: eu_owned` is provisional), (b) pricing is published in **USD rather than EUR** (unusual for a Dutch company), and (c) DPA and sub-processors URLs were not captured at audit. ### Storyblok: https://euvetted.com/p/storyblok - Website: https://www.storyblok.com - Category: Headless CMS - Country of incorporation: Austria - Hosting country: Germany - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: freemium - Founded: 2017 - Certifications: ISO27001 - DPA: https://www.storyblok.com/legal/dpa - Sub-processors list: https://www.storyblok.com/legal/dpa - Last verified: 2026-05-12 Austrian headless CMS (Linz, est. 2017); ISO 27001, enterprise customers (Disney, Netflix); Brighton Park US-PE led Series C. **Storyblok** (Linz, Austria, founded 2017) positions itself as the "#1 Enterprise Headless CMS" with a visual-editor differentiator (rather than pure-developer-tool positioning). Customers include **Disney, Netflix, Oatly, Adidas, Renault, Marc O'Polo, Autodesk, Virgin Media O2**. ISO 27001 certified, 99.99% uptime SLA, framework support for Next.js, Astro, Nuxt, React, Vue, Eleventy, Symfony. Funding history: **$47M Series B in 2022** led by Mubadala Capital (UAE) and HV Capital (DE) with 3VC and firstminute; **$80M Series C** subsequently led by **Brighton Park Capital** (US private equity, Greenwich CT). The US-PE-led Series C is the procurement-grade caveat, flipping ownership_signal from eu_owned to eu_hq_us_funded. **Compliance rationale:** **Storyblok** (Linz AT, founded 2017) is **ISO 27001** certified with enterprise customer base (Disney, Netflix, Adidas, Renault); $47M Series B 2022 (Mubadala UAE + HV Capital DE + 3VC + firstminute) and **$80M Series C led by Brighton Park Capital** (US private equity): US-PE-led Series C flips signal to `eu_hq_us_funded` with material CLOUD Act exposure. ### Strapi: https://euvetted.com/p/strapi - Website: https://strapi.io - Category: Headless CMS - Country of incorporation: France - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: freemium (from €15/month) - Founded: 2017 - Certifications: SOC2 - Last verified: 2026-05-12 Paris-based open-source headless CMS (founded 2017); MIT-licensed core, Strapi Cloud PaaS, US-VC-funded (Insight, CRV). **Strapi** (Paris, France, founded 2017) is the most-installed open-source headless CMS: **MIT-licensed core**, **Strapi Cloud** PaaS-hosted offering, and **Enterprise Edition** self-hosted with extended features. The OSS community is significant (>60K GitHub stars). Compliance: **SOC 2 certified, GDPR compliant** (no public ISO 27001 attestation surfaced at time of research). The procurement-grade caveat is funding: Series C 2022 was led by **Insight Partners** (US growth-PE, $90B AUM, New York) with **CRV** and Index. So the company is French-operated but US-PE-controlled at cap-table level. Effective story when self-hosted (MIT) on EU infra: customer data never reaches Strapi, so cap-table US influence is moot for that deployment. **Compliance rationale:** **Strapi** (Paris FR, founded 2017) is the leading open-source headless CMS (MIT license) with Strapi Cloud (PaaS) and Enterprise self-hosted editions; **SOC 2 certified, GDPR compliant**; but Series C 2022 was led by **Insight Partners** (US PE/VC) with **CRV** (US) and Index: material US-VC control flips signal to `eu_hq_us_funded`; no public ISO 27001 attestation. ### STRATO HiDrive: https://euvetted.com/p/strato-hidrive - Website: https://www.strato.de/cloud-speicher/ - Category: File sharing - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €6/month) - Founded: 1997 - Certifications: ISO27001 - DPA: https://www.strato.de/agb/avv/ - Sub-processors list: https://www.strato.de/agb/avv/ - Last verified: 2026-05-14 German cloud storage (STRATO GmbH, United Internet/IONOS group), two German data centres, ISO 27001 + Trusted Cloud, optional zero-knowledge E2E. STRATO HiDrive is the cloud-storage and online-backup product of STRATO GmbH, one of Germany's oldest and largest web-hosting companies, founded in 1997 and headquartered in Berlin. STRATO was owned by Deutsche Telekom until 2017, when it was acquired by United Internet AG (the publicly listed German internet group behind 1&1 and IONOS), so the ownership chain is entirely German and EU: no US parent, no US private equity, no US VC. The sovereignty posture is among the strongest in the file-sharing category. STRATO operates **two high-security data centres physically located in Germany**, is **ISO 27001 certified**, carries the German Federal Ministry for Economic Affairs "Trusted Cloud" seal, and holds TÜV Nord certification. Default encryption is server-side AES-128 with secure TLS transport; for sensitive use cases STRATO offers an **optional zero-knowledge end-to-end encryption add-on for around €2/month**, which moves key control to the customer. As a German company with German hosting and a German listed parent, CLOUD Act exposure is `none`. The single gap at audit is documentation completeness: STRATO publishes a DPA (Auftragsverarbeitungsvertrag) at strato.de/agb/avv/, confirming the public DPA signal; sub-processors URL was not directly captured from the public site and remains to be verified. The product UI is German-first with English available. Pricing is paid-only (free trial months, but no permanent free tier): Starter 500 GB at €6/month, Basic 1 TB at €7.50/month, Plus 2 TB at €12.50/month, Family 2 TB / 5 users at €17.50/month, and Business 1-10 TB from €20/month, with meaningful annual discounts. HiDrive supports a REST API and WebDAV access, making it usable for automated backup workflows. Best fit: German and EU SMBs and individuals who want a large, established German vendor with in-country data centres, recognised certifications, and an optional zero-knowledge layer, and who do not need a free tier. **Compliance rationale:** STRATO HiDrive is the cloud-storage product of **STRATO GmbH** (Berlin, founded 1997; part of the publicly listed German **United Internet / IONOS group** since the 2017 acquisition from Deutsche Telekom), a fully German-incorporated, German-owned vendor running **two high-security data centres in Germany**, ISO 27001 certified, carrying the German government 'Trusted Cloud' seal and TÜV Nord certification, with optional zero-knowledge end-to-end encryption available for €2/month on top of the default server-side AES-128, and a public DPA at strato.de/agb/avv/; EU-owned (German IONOS group), German-hosted, ISO 27001 + Trusted Cloud + TÜV Nord, public DPA, no CLOUD Act exposure; sub-processors URL not yet confirmed at audit. ### SumUp: https://euvetted.com/p/sumup - Website: https://sumup.com - Category: Payments - Country of incorporation: United Kingdom - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid (from €0/month) - Founded: 2012 - DPA: https://www.sumup.com/en-gb/terms/dpa/ - Last verified: 2026-05-11 London-based mPOS fintech (originally Berlin), 4M+ SMBs, heavy US-VC funding (Goldman Sachs led €1.5B 2024); €15B IPO in prep. SumUp is a London-headquartered British fintech (founded in Berlin in 2012 by Daniel Klein, Alessandro Leoni, Marc Alexander Christ, and Stefan Jeschonnek; CEO Daniel Klein) focused on mobile point-of-sale (mPOS), card terminals, and integrated payments for small businesses. The product targets the segment Square dominates in the US (micro-merchants, mobile traders, market vendors, hospitality, retail) with a hardware-led entry (the iconic SumUp Air card reader at €19 one-time) and a flat transaction fee (~1.69% in DACH; varies by market). The company serves 4M+ SMBs across the United States, the United Kingdom, Germany, France, and dozens of other markets across Europe and South America. For an EU-sovereignty audit SumUp sits squarely in the "European brand, US-funded structurally" tier. The cap table is dominated by US institutional investors: **Goldman Sachs** (which led a US$624M / €1.5B funding round in May 2024 at an US$8.5B valuation), **Bain Capital Credit**, **Crestline**, **Oaktree Capital Management**, and **American Express** all hold significant positions, alongside Temasek (Singapore), BBVA Ventures (Spain), and Groupon (US). The company operates **SumUp Inc.** (a Delaware entity at 1209 Orange Street, Wilmington, the classic Delaware-registered-agent address) for US operations and uses US banking partners (Fifth Third Bank as registered Payment Facilitator and Piermont Bank for FDIC-member banking services in the US). SumUp is publicly considering a stock-market listing in **either London or New York** at a valuation of up to US$15B. The eventual venue will define ownership posture but both are non-EU listings. Pricing: SumUp Air card reader €19 one-time + 1.69% per transaction in DACH (rates vary by country); SumUp Solo terminal €79; SumUp One subscription €19/month for 0.99% rate on supported markets. No monthly fee on the base plan. Best fit: micro-merchants and hospitality / retail SMBs wanting an inexpensive hardware-led card-acceptance solution. Procurement-grade EU buyers requiring an EU-controlled ownership chain should choose Adyen, Worldline, or Mollie (NL/FR public-listed European processors) instead. **Compliance rationale:** SumUp is London-headquartered British fintech (HQ moved from Berlin to London long ago, founded 2012 by Daniel Klein, Alessandro Leoni, Marc Alexander Christ, Stefan Jeschonnek), serving 4M+ SMBs across the US, UK, Germany, France, and dozens of other markets, but the cap table is heavily US-funded (Goldman Sachs led €1.5B May 2024, plus Bain Capital Credit, Crestline, Oaktree, American Express), the company operates a US entity (SumUp Inc., Delaware), uses US banking partners (Fifth Third Bank as Payment Facilitator, Piermont Bank for banking services), and a London / New York IPO at up to US$15B is being weighed: `ownership_signal: eu_hq_us_funded`, `cloud_act_exposure: material`; no public DPA or sub-processors list captured at audit. ### SuperOffice: https://euvetted.com/p/superoffice - Website: https://www.superoffice.com - Category: CRM - Country of incorporation: Norway - Hosting country: Norway - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid (from €71/month) - Founded: 1989 - DPA: https://www.superoffice.com/trust-center/agreements/dpa/dpa-oct-2022/ - Sub-processors list: https://www.superoffice.com/privacy/ - Last verified: 2026-05-11 Long-running Norwegian Nordic-enterprise CRM (SuperOffice AS, Oslo) with EU/EEA hosting and on-premise edition; Axcel-owned with Carlyle backing. SuperOffice is one of the longest-running European CRM vendors, founded in 1989 in Oslo and operated by SuperOffice AS (Wergelandsveien 27, 0167 Oslo, Norway) with subsidiaries in Sweden, Denmark, Germany, the Netherlands, Switzerland, and Lithuania. The product targets Nordic enterprise B2B with three modules: Sales (deal management and forecasting), Marketing (campaign management and lead generation), Service (customer support), plus AI-assisted summaries and content generation, and 1,000+ integrations including Microsoft Dynamics, SharePoint, Slack, Trello, and Zapier. The company emphasises 30+ years of European CRM expertise. Ownership is layered: in April 2020 Norwegian SuperOffice AS was acquired by Axcel, the Danish private-equity firm; on 3 June 2025 Axcel secured a €266M continuation fund led by Carlyle AlpInvest, with US-headquartered Carlyle as the ultimate parent of the AlpInvest sub-fund. So while the operating entity sits firmly in Norway/EEA and earlier ownership was fully Nordic, the continuation-fund layer adds meaningful US-PE exposure that procurement-grade buyers should understand. CEO as of 2026 is Bjørn Røsten. Compliance disclosures are partial. The privacy statement (last updated 1 May 2023) names Google Analytics, Facebook, and LinkedIn as marketing-site sub-processors and references a "directory of approved sub-processors" inside the DPA in the Trust Center, not directly resolvable as a public URL at audit. The same statement still cites the EU-U.S. Privacy Shield Framework as an alternative legal basis, which has been invalidated since Schrems II (July 2020) and replaced by the Data Privacy Framework; outdated wording is a transparency red flag. The hosting provider for customer CRM data is described only as "Europe" without a specific provider, region, or city. Per the directory's strict CLOUD Act stance these gaps produce material exposure pending vendor confirmation of the underlying cloud provider and a refreshed transfer-mechanism reference. Pricing in EUR is enterprise-grade: Sales Essentials starts at €71/user/month with annual billing (monthly, quarterly, semi-annual, and annual cycles available); higher Sales / Service / Marketing tiers above; an interactive demo replaces a self-serve free trial. Best fit: Nordic and DACH mid-market and enterprise B2B teams that want a long-running European CRM with deep Microsoft-stack integration. Procurement-led EU-only buyers should request the Trust Center sub-processors list, the AVV/DPA, and a written commitment on the underlying cloud region before signing. **Compliance rationale:** Long-running Norwegian Nordic-enterprise CRM (SuperOffice AS, Oslo) with subsidiaries across NO/SE/DK/DE/NL/CH/LT and customer data hosted 'in Europe', but the privacy statement still references the invalidated Privacy Shield framework (last updated May 2023), the underlying hosting provider is not publicly named, and the 2025 continuation-fund round was led by Carlyle AlpInvest with US Carlyle as ultimate parent. Together these produce material CLOUD Act exposure: US-PE ownership at the fund layer, an unnamed hosting provider, and an outdated transfer-mechanism reference are the three verified gaps. **Sub-processors mapped:** 7 total, 4 US-owned - Amplitude Inc. (United States): Product analytics and usage statistics (processed in Frankfurt) [US-owned] - Mailgun Technologies Inc. (United States): Email service provider for campaigns and ticket replies (processed in Frankfurt) [US-owned] - Microsoft Corporation (United States): Azure document storage; SuperOffice AI language analytics (processed in NL and IE) [US-owned] - Userflow Inc. (United States): In-product user onboarding and activation [US-owned] - i-Centrum AB (Sweden): App Store applications (Bookmycalendar, Contract Manager, Activity Board, Map4You Pro) - InfoBridge B.V. (Netherlands): Calendar synchronization with Microsoft 365 / Google Workspace - Visma IT & Communications AS (Norway): Hosting and operations of all servers/infrastructure; database storage (Norway) ### SuperSaaS: https://euvetted.com/p/supersaas - Website: https://www.supersaas.com - Category: Calendar booking - Country of incorporation: Netherlands - Hosting country: Netherlands - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium (from €8/month) - Founded: 2007 - DPA: https://www.supersaas.com/info/data_processing_agreement - Sub-processors list: https://www.supersaas.com/info/subprocessors - Last verified: 2026-05-11 Amsterdam-based Dutch appointment scheduling (SuperSaaS B.V., founded 2007 by Jan M. Faber), unfunded founder-owned, 205k+ businesses, 35 languages. SuperSaaS is an Amsterdam-headquartered Dutch online appointment-scheduling platform operated by **SuperSaaS B.V.** (Strawinskylaan 6, 1077 XZ Amsterdam) and founded in 2007 by **Jan M. Faber**. The company has reached 205,000+ businesses on the platform across 60 countries and 35 UI languages, and remains **unfunded** (no PE, no VC, no parent), making it one of the longest-running founder-controlled EU SaaS in the directory. The product covers self-service appointment booking for service businesses (yoga / fitness studios, salons, clinics, equipment rentals, classroom bookings, language-school timetables), reminders by email and SMS, payments through PayPal and Stripe, calendar sync, and integrations. For an EU-sovereignty audit SuperSaaS is structurally clean at the ownership layer: Dutch B.V., founder-controlled, no outside capital. Where the listing weakens is at the procurement-documentation layer: the dedicated privacy-policy URL did not resolve at audit, a named sub-processors list is not publicly indexed, and the underlying hosting provider for booking-data storage is not disclosed on accessible public pages. The product takes no transaction fees (PayPal / Stripe / other payment processors charge their fees directly), and the free tier covers up to 50 appointments with SuperSaaS-branded advertising; paid tiers scale by appointment volume from ~US$8/month and remove advertising. Best fit: long-tail service-business segments (yoga studios, salons, dentists, driving instructors, equipment rentals, language schools, sports clubs) that need multilingual booking pages; SuperSaaS's 35-language coverage is unusually broad for the category and aligns with niche-language EU markets that Calendly and Acuity under-serve. Procurement-grade buyers requiring a contract-grade DPA, named sub-processors, and explicit hosting commitment should request these directly from SuperSaaS before signing; alternatively look at Cal.com (open-source self-host) or Reservio (Czech B2C booking) in this category. **Compliance rationale:** SuperSaaS B.V. (Strawinskylaan 6, 1077 XZ Amsterdam, Netherlands; founded 2007 by Jan M. Faber) is an **unfunded, founder-owned Dutch appointment-scheduling platform** with 205,000+ businesses on the platform across 35 UI languages and 60 countries, a structurally rare 19-year-old EU SaaS with no PE / VC / parent on record. Signal mix: EU-owned (Dutch B.V., founder-controlled, no outside capital), CLOUD Act flag at `minor`; gaps: the underlying hosting provider, a publicly accessible DPA artefact, and a named sub-processors list are not captured at audit; DPA is publicly linked at /info/data_processing_agreement but the page did not resolve to verifiable content at audit time. Vendor outreach required before procurement-grade listing. ### Surfshark: https://euvetted.com/p/surfshark - Website: https://surfshark.com - Category: VPN - Country of incorporation: Netherlands - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid (from €3/month) - Founded: 2018 - Sub-processors list: https://surfshark.com/privacy - Last verified: 2026-05-15 NL-incorporated VPN (Surfshark B.V., Amsterdam, KvK 81967985): moved from BVI to NL Oct 2021, merged with Nord Security 2022, RAM-only, Deloitte-audited. Surfshark is operated by Surfshark B.V., a Dutch company at Kabelweg 57, 1014BA Amsterdam (Netherlands chamber of commerce KvK 81967985, VAT NL862287339B01). It was founded in 2018, originally registered in the British Virgin Islands, and **moved its corporate registration to the Netherlands on 1 October 2021**. That move is the structural reason Surfshark qualifies as an EU listing in this directory at all. Day-to-day operations are still in Vilnius, Lithuania. In early 2022 Surfshark and Nord Security announced a merger under a single holding company, but both brands continue to operate independently with separate infrastructure and product roadmaps: Surfshark is a Nord Security sister-brand, not a sub-product. As a product, Surfshark is one of the better-audited consumer VPNs. The server fleet is **4500+ RAM-only diskless servers across 100+ countries**, so configuration is loaded fresh on every boot and nothing persists. **Deloitte performed an independent no-logs audit** confirming the policy. The product offers WireGuard, Nexus mesh routing, Dynamic MultiHop, and an IP Rotator that changes the user's IP every 10 minutes. The marketing site supports 17 languages including all major EU locales. For an EU-sovereignty audit Surfshark is a **mid-tier pick**. It has a stronger EU-incorporation story than a Panama-registered operating entity, and a cleaner ownership trail than CyberGhost (no Kape/Crossrider/Sagi history). Three signal gaps remain: the Nord Security holding-level US-VC minority (General Catalyst co-led the 2022 $100M round), the company's pre-2021 BVI history, and the structural reality that any global VPN service operates servers in the United States. The RAM-only architecture genuinely mitigates the data-at-rest exposure those US locations would otherwise create. For buyers who prioritise a simple, founder-controlled EU ownership chain, Mullvad (Swedish AB, 100% founder-owned) and ProtonVPN (Swiss non-profit Foundation) are stronger picks. Pricing is paid-only (no free tier; 30-day money-back): Surfshark Starter from around €2.50-3/month on a 2-year plan; One and One+ tiers add encrypted email/storage/data-removal extras above. Best fit: mainstream privacy-conscious EU buyers who want a multi-device VPN with audited no-logs and a Dutch corporate entity, at the lower end of the price range. Buyers who prioritise sovereignty over price and feature breadth should prefer Mullvad or ProtonVPN. **Compliance rationale:** Surfshark is operated by **Surfshark B.V.** (Kabelweg 57, 1014BA Amsterdam, the Netherlands; KvK 81967985, VAT NL862287339B01). It moved its registration **from the British Virgin Islands to the Netherlands on 1 October 2021**, which is the structural reason it qualifies as an EU listing. Founded 2018 with operations still in Vilnius, Lithuania; in **early 2022 it merged with Nord Security under one holding company while keeping independent brands and infrastructure**, runs **4500+ RAM-only diskless servers across 100+ countries**, and has a **Deloitte no-logs audit** on record. Ownership signals: Dutch B.V. operating entity (EU-incorporated), Nord Security holding-level US-VC minority (General Catalyst, 2022 round), necessarily global VPN fleet including US locations (CLOUD Act exposure rated `minor`, mitigated by RAM-only architecture). No public DPA surfaced at audit. A stronger EU-incorporation story than a Panama-registered entity, but ownership complexity means it falls short of pure-EU founder-owned picks like Mullvad or the Swiss non-profit structure of ProtonVPN. ### Survicate: https://euvetted.com/p/survicate - Website: https://survicate.com - Category: Forms & surveys - Country of incorporation: Poland - Hosting country: Ireland - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: paid (from €105/month) - Founded: 2013 - Certifications: ISO27001, SOC2 - DPA: https://survicate.com/data-processing-agreement/ - Sub-processors list: https://assets.survicate.com/docs/Privacy%20Policy%205.3.pdf - Last verified: 2026-05-11 Warsaw-based Polish in-product survey and NPS platform on AWS-EU, ISO 27001 + SOC 2 + HIPAA-aligned. Survicate is a Warsaw-based Polish in-product feedback and survey platform founded in 2013 by Kamil Rejent. The product covers in-product surveys, NPS / CSAT / CES tracking, website pop-ups, email and link surveys, and a Research Hub for centralised insights, and is used by more than 2,000 digital businesses including Spotify, Automattic, Vercel, and Amplitude. The company has raised approximately US$1M across several investors including Airbridge Equity Partners, ARIA Fund, Di Volio, Newberg Investments, and PFR Ventures (the Polish state-owned venture arm), keeping the cap table firmly Polish and EU-aligned. The security posture is unusually rich for a vendor at this size: ISO/IEC 27001, SOC 2, PCI-DSS, HIPAA, and GDPR alignment are all attested on the public security page; TLS 1.2 in transit and AES-256 at rest; single sign-on with workspace-level or full-workspace SAML; role-based access controls; workspace isolation; 24/7 monitoring; continuous third-party penetration testing; and an explicit commitment that customer data never trains AI models. The remaining red flag for a strict-CLOUD-Act EU buyer is the underlying infrastructure: customer survey data is hosted on Amazon Web Services in the EU region, a US-owned hyperscaler that, under our parent-jurisdiction stance (Schrems II / Microsoft Ireland v US), counts as material CLOUD Act exposure regardless of EU placement. This is material CLOUD Act exposure despite the otherwise enterprise-grade certifications and tooling. Pricing in EUR/USD is positioned mid-market: the Starter tier is sales-only; the Growth tier starts at US$114/month (~€105) with annual billing; Scale and Enterprise above. A 10-day free trial requires no credit card and allows up to 25 responses plus 100 Research Hub data points. Best fit: mid-market product teams in DACH, France, Poland, and the Nordics that want EU-incorporated ownership, full ISO 27001 + SOC 2 attestation, SSO, and audit logging, and can accept AWS-EU as the underlying hosting layer. Buyers who must avoid US-owned hyperscalers entirely should look at Tally (BE) for forms or use the on-premise Matomo for survey-style polling. **Compliance rationale:** Warsaw-based Polish survey platform (founded 2013 by Kamil Rejent, Polish-investor cap table including PFR Ventures) with strong ISO 27001 + SOC 2 + PCI-DSS + HIPAA attestation, TLS 1.2 / AES-256, SSO and SAML, but customer data is hosted on Amazon Web Services in the EU region, which is a US-owned hyperscaler at rest; per the strict CLOUD Act stance this is material CLOUD Act exposure despite the EU-owned ownership and enterprise-grade certifications. No public DPA URL resolved at audit. ### Sylius: https://euvetted.com/p/sylius - Website: https://sylius.com - Category: E-commerce - Country of incorporation: Poland - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium - Founded: 2011 - Last verified: 2026-05-21 Polish open-source Symfony e-commerce framework (MIT); commercial Plus modules from €800/yr GMV-based. **Sylius** (Sylius sp. z o.o., Opole, Poland, founded 2011) is an open-source e-commerce framework built on Symfony/PHP, serving 10,000+ online stores with 700+ community contributors. The core is **MIT-licensed and free to self-host**; the commercial **Sylius Plus** licence adds enterprise modules (B2B Suite, Marketplace, Multi-store, Returns Management, Loyalty) with pricing starting from **€800/year** scaled to GMV. Sylius is **on-premise by design**: there is no proprietary managed SaaS; merchants self-host on their own EU infrastructure (Hetzner, OVH, Scaleway) or via the Platform.sh PaaS partner, keeping full data control. When self-hosted on EU infrastructure, CLOUD Act exposure is effectively zero. Best fit for mid-market merchants who need deep Symfony customisation, B2B/wholesale flows, or multi-store setups and prefer full control over a managed SaaS. No public DPA or sub-processors list published; enterprise buyers should request via sales. **Compliance rationale:** Sylius sp. z o.o. (Opole, PL, NIP 7272867768) is EU-owned and MIT open-source with no US hosting dependency when self-deployed. Signals: EU-owned ✓, no CLOUD Act exposure ✓. No public DPA, no sub-processors list, and no certifications: the commercial Plus licence adds SLA support but not compliance documentation. ### Taiga: https://euvetted.com/p/taiga - Website: https://www.taiga.io - Category: Project management - Country of incorporation: Spain - Hosting country: Spain - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium - Founded: 2014 - DPA: https://taiga.io/data-processing-addendum-dpa/ - Sub-processors list: https://taiga.io/security/ - Last verified: 2026-05-18 Spanish open-source agile PM (Taiga by Kaleidos, Madrid, 2014), MPL-2.0, Scrum + Kanban; self-hostable + tree.taiga.io managed cloud. Taiga is the open-source agile project-management platform operated by **Kaleidos**, a Madrid-based Spanish software cooperative that built and continues to maintain the project since 2014. The platform is positioned as the open-source Jira / Linear / Clickup alternative: Scrum sprints, Kanban boards, issue tracking, customisable dashboards, video-call integrations, and a wiki module, all under the **Mozilla Public License 2.0** with the full server-side code on GitHub. Taiga is widely used in EU public administrations, universities, and open-source-friendly engineering teams. Two deployment paths are offered. **Self-hosted** on the customer's own infrastructure (Hetzner / OVHcloud / Scaleway / private DC) makes the customer the sole data controller and operator, with no CLOUD Act exposure. The **managed cloud** at tree.taiga.io is the alternative for teams who prefer not to run the stack themselves; the managed tier runs from the Interxion MAD3 datacentre in Madrid, where Digital Realty/Interxion is only the physical colocation landlord with no logical access to customer data and no US-owned hyperscaler sits in the customer-data path, so under a customer-data-at-rest definition its CLOUD Act exposure is none. The combination of MPL-2.0 licensing and a Spanish-owned operating cooperative makes Taiga the strongest agile / Scrum entry on this directory. Pricing for the managed cloud is at /deployment-pricing-options with freemium and paid tiers; specific monthly amounts were not captured at audit. Best fit: EU public-sector procurement, universities, open-source-aligned engineering teams, and any organisation that wants a Jira replacement under EU jurisdiction and AGPL-style open governance. **Compliance rationale:** Taiga is the **open-source agile project-management platform** operated by **Kaleidos** (Madrid, Spain; founded 2014), released under **Mozilla Public License 2.0** with the full server-side stack available on GitHub for self-host on any EU infrastructure: Scrum, Kanban, issue tracking, customisable dashboards; the hosted tier (tree.taiga.io) provides the managed alternative for teams who don't want to operate the stack themselves. Self-hosting on EU infrastructure gives the customer full data control with no CLOUD Act exposure; the managed-cloud tier is EU-owned with a public DPA and ES-only named sub-processors (verified 2026-05-18), hosted at the Interxion MAD3 datacentre in Madrid, where Digital Realty/Interxion acts only as the physical colocation landlord with no logical access to customer data and no US-owned hyperscaler sits in the customer-data path, so under a customer-data-at-rest definition CLOUD Act exposure is none. **Sub-processors mapped:** 2 total, 1 US-owned - Interxion MAD3 (Digital Realty) (Spain): Physical datacenter operations and facilities (Madrid); ancillary (physical-only colocation landlord, no data access) [US-owned] - AITIRE CLOUD (Spain): Infrastructure as a Service (IaaS) hosting and management ### Talkspirit: https://euvetted.com/p/talkspirit - Website: https://www.talkspirit.com - Category: Docs & wikis - Country of incorporation: France - Hosting country: France (Roubaix) - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid - Founded: 2004 - Certifications: ISO27001 - Last verified: 2026-05-21 Paris-based French enterprise social network + intranet (Talkspirit SAS, 2004); OVH-hosted France; ISO 27001 + SecNumCloud; 900+ organisations. Talkspirit is a Paris-headquartered French enterprise social network and organisational operating system operated by **Talkspirit SAS** and founded in 2004 by **Philippe Pinault** and **Olivier Ricard**. The platform is designed as a complete replacement for Meta's Workplace, combining three core modules: **Structure** (dynamic org-chart, role clarity, OKR management), **Collaboration** (projects, documents, shared workspaces), and **Communication** (chat, video meetings, news feed). The product reports **900+ organisations** and 150,000+ users with 160+ partners. For EU-sovereignty procurement Talkspirit is the structurally cleanest French-SaaS listing in the docs-wikis/intranet category. The legal entity is **Talkspirit SAS** (Société par Actions Simplifiée, capital €16,000, SIRET 479 109 332, registered at the Paris Commercial Registry). Data is hosted on **OVH infrastructure in Roubaix, France** per the legal notice. The homepage claims **ISO 27001**, **SecNumCloud** qualification, and EUCS compliance, making it one of very few enterprise social network vendors with a SecNumCloud qualification, which is the highest French sovereign cloud standard and a strong signal for French public-sector procurement. Governing law is explicitly French (Article 8 of ToS), with disputes under the Paris Commercial Court. The privacy policy acknowledges some US sub-processors covered by Standard Contractual Clauses, a minor cloud_act_exposure flag in the strict rubric, but structurally managed through French governing law and French data residency. No public DPA download link was found at audit time; procurement teams should request the AVV/DPA directly. Pricing is sales-engaged (demo-request model); specific EUR tier figures not published on the website. Best fit: French companies and EU public-sector buyers wanting a Workplace from Meta replacement with the highest available French compliance posture (SecNumCloud + ISO 27001); organisations requiring French-law governance; teams needing org-chart, OKR, and project management in one platform alongside chat and news feed. **Compliance rationale:** Talkspirit SAS (Paris, France; 72 rue du Faubourg Saint-Honoré; SIRET 479 109 332) is a **French-founded enterprise social network and intranet platform** hosted on OVH in Roubaix, France. Homepage claims ISO 27001 and SecNumCloud qualifications and EUCS compliance; governing law is French. Privacy policy acknowledges some US sub-processors covered by SCCs. Signals: EU-owned (French SAS), EU-hosted (OVH Roubaix, France), ISO 27001 claimed, SecNumCloud qualification claimed, EUCS compliance claimed, French governing law. Gaps: no separate DPA download link: the Terms of Service confirm the processor role only and direct buyers to request a contract; some US sub-processors managed under SCCs (minor exposure). ### Tally: https://euvetted.com/p/tally - Website: https://tally.so - Category: Forms & surveys - Country of incorporation: Belgium - Hosting country: Belgium - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: freemium (from €20/month) - Founded: 2020 - DPA: https://tally.so/help/data-processing-agreement - Sub-processors list: https://tally.so/help/data-processing-agreement - Last verified: 2026-05-11 Belgian bootstrapped form builder (Tally BV, Ghent) with free unlimited forms, EU-only hosting claim, and 500k+ teams using it. Tally is a Belgian bootstrapped form builder operated by Tally BV (August Van Lokerenstraat 71, 9050 Ghent; Belgian enterprise number 0776.979.007), founded in 2020 by Marie Martens and Filip Minev. The product is a Notion-style form-and-survey builder with a free-unlimited tier, conditional logic, e-signatures, file uploads, payment processing, multi-step workflows, and integrations with Notion, Google Sheets, Airtable, Slack, Make, n8n, Zapier, and webhooks. The company reports more than 500,000 teams using the platform (including Notion, Make, Rakuten, and Glovo) and has scaled almost entirely through bootstrapped growth without venture capital. Compliance posture is solid for a small EU vendor. The marketing site states "Made and hosted in the EU 🇪🇺," the privacy policy locates the data controller as Tally BV in Ghent and confirms data is stored on "high-security servers within the European Union," and the Data Processing Agreement is publicly accessible at /help/data-processing-agreement without account or signature gating. Form data is encrypted in transit and at rest, no cookie-tracking is used on tally.so, and customers retain GDPR rights of access, rectification, erasure, restriction, portability, and objection. Where Tally falls short for procurement-grade buyers is that the DPA's sub-processors annex is marked N/A, only categories (hosting service providers, payment service providers, communication service providers) are disclosed, and the underlying hosting provider is not publicly named, so a buyer cannot independently verify the EU-region claim or the absence of US-cloud at rest without vendor outreach. Pricing in EUR is straightforward: Free covers unlimited forms and submissions within fair-use guidelines (45+ languages, payment processing, signatures, file uploads, conditional logic, integrations); Pro is €20/month adding custom domains, removed Tally branding, team collaboration, custom CSS, and form analytics; Business is €65/month adding data-retention controls, email verification, and 90-day version history. Best fit: indie makers, EU SMBs, agencies, and startups that want a free Typeform alternative from a Ghent-based vendor with a public DPA. Procurement-grade buyers needing a named sub-processors list and a confirmed EU hosting provider should request the disclosure directly before signing. **Compliance rationale:** Bootstrapped Belgian BV (Tally BV, Ghent, CBE 0776.979.007) founded by Marie Martens and Filip Minev, with a publicly-linked DPA and a generous free-unlimited tier; the GDPR sub-processor list (verified 2026-06) shows Tally hosts customer data on Google Cloud (Belgium region), a US-owned hyperscaler as the core host, alongside Cloudflare, SendGrid, Stripe and other US processors, raising CLOUD Act exposure to material despite the EU data region and EU ownership. **Sub-processors mapped:** 13 total, 10 US-owned - Cloudflare (United States): File-upload storage (opt-in, EU region) and DNS [US-owned] - Google AI Studio (United States): AI assistant (opt-in; data hosted in Belgium region) [US-owned] - Google Cloud (United States): Hosting and storage (data hosted in Belgium region) [US-owned] - Mixpanel (United States): Analytics [US-owned] - OpenAI (United States): Abuse detection [US-owned] - SendGrid (United States): Email / form notifications (opt-in) [US-owned] - Sentry (United States): Error monitoring [US-owned] - Stripe (United States): Payments for payment forms (opt-in) [US-owned] - Tinybird (United States): Analytics [US-owned] - UserJot (United States): Customer feedback management [US-owned] - Cello (Germany): Referral program (opt-in) - Missive (Canada): Customer support - Plausible (Estonia): Privacy-friendly analytics ### T Cloud Public (formerly Open Telekom Cloud): https://euvetted.com/p/open-telekom-cloud - Website: https://www.t-cloud-public.com - Category: Cloud & hosting - Country of incorporation: Germany - Hosting country: Germany (Biere) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2016 - Certifications: ISO27001, ISO27017, ISO27018, C5 - DPA: https://www.t-cloud-public.com/_Resources/Persistent/8/a/e/e/8aee7408494e57b855d74fa0e311fdd74ea5cdd7/OTC%20CDPA%20TSI_EN.pdf - Sub-processors list: https://www.open-telekom-cloud.com/cdpa - Last verified: 2026-05-18 Deutsche Telekom's OpenStack public cloud (T-Systems), Biere + Magdeburg DCs, ISO 27001 + BSI C5 + TISAX; rebranded from Open Telekom Cloud. T Cloud Public is the public-cloud platform of Deutsche Telekom AG (Germany's largest telecoms group), operated by T-Systems International GmbH (the enterprise-IT and consulting subsidiary headquartered in Frankfurt am Main). The service was launched in 2016 as **Open Telekom Cloud** (OTC) and was rebranded to T Cloud Public in 2026; the open-telekom-cloud.com domain now 301-redirects to t-cloud-public.com. The platform is OpenStack-based with open APIs that enable straightforward portability of workloads in and out, runs in a **Twin-Core** high-security data-centre region in Biere and Magdeburg (Saxony-Anhalt, Germany), and offers additional regions in the Netherlands and Switzerland for buyers needing geographically diverse EU/EEA-and-adequacy placement. Compliance posture is among the strongest in the directory. T Cloud Public carries ISO/IEC 27001, ISO 27017, ISO 27018, the German government's BSI **C5** Cloud Computing Compliance Criteria Catalogue, and TISAX (the German automotive supply-chain security framework), a combination unusually well-suited to regulated public-sector and DACH-automotive procurement. The product positions itself as "full sovereignty: data stored in European data centres, GDPR-compliant and independent of non-European laws." T-Systems' broader enterprise-services book also supports IT-Grundschutz, DORA-readiness for financial services, and a wide range of public-sector frameworks. Customer base spans Deutsche Telekom's enterprise verticals (healthcare, public sector, research, automotive, media, retail), and OpenStack interoperability makes it a natural target for migration projects out of AWS/Azure/GCP that need an EU-sovereign destination. Pricing is pay-as-you-go with €250 starting credit for new customers; specific compute-instance entry-tier EUR figures were not captured at audit (the public price page directs to a calculator and PDF). Support is included in the base price with 24/7 phone availability in DE and internationally. Best fit: large DACH enterprises, German public-sector procurement (especially those already in the Deutsche Telekom commercial relationship), DORA-regulated financial services, TISAX-required automotive supply chains, and any EU buyer wanting a Deutsche-Telekom-grade enterprise OpenStack alternative to AWS / Azure / GCP. Together with Hetzner, OVHcloud, Scaleway, IONOS, UpCloud, STACKIT, Cleura, and Exoscale, T Cloud Public completes the procurement-grade EU hyperscaler-alternative stack on this directory. **Compliance rationale:** T Cloud Public (formerly Open Telekom Cloud, rebranded in 2026), operated by T-Systems International GmbH (the enterprise-services subsidiary of Deutsche Telekom AG) is an OpenStack-based public cloud running in a Twin-Core data-centre region in Biere and Magdeburg, Germany with additional regions in the Netherlands and Switzerland; carries ISO 27001 + ISO 27017 + ISO 27018 + TISAX + BSI C5, with explicit 'data independent of non-European laws' positioning: EU-owned and EU-hosted with no CLOUD Act exposure. ### Teamleader: https://euvetted.com/p/teamleader - Website: https://www.teamleader.eu - Category: CRM - Country of incorporation: Belgium - Hosting country: Ireland - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: paid (from €37/month) - Founded: 2012 - DPA: https://www.teamleader.eu/legal/data-processing-agreement-teamleader-focus - Sub-processors list: https://www.teamleader.eu/legal/sub-processors-teamleader-focus - Last verified: 2026-05-10 Ghent-based Belgian SMB CRM + invoicing + project tool, owned by Norwegian Visma Group; from €37/month. Teamleader is a Ghent-based Belgian business-management SaaS founded in 2012, combining CRM, quotations, invoicing, expense tracking, and project planning into a single tool for small and mid-sized European businesses. The company reports more than 34,000 customers across Belgium, the Netherlands, Germany, France, Spain, and Italy and ships four product lines: Teamleader Focus (entrepreneurs and small teams), Teamleader Orbit (premium agencies, 20+ employees), Teamleader One (e-invoicing for self-employed and small companies in BE/NL), and Dexxter (automated bookkeeping for Belgian sole proprietors). In June 2022 Teamleader was acquired by Visma Group, the Oslo-headquartered Norwegian software conglomerate. Norway is an EEA member with full GDPR alignment, so transfers to Norway do not require SCCs; this keeps Teamleader broadly EU/EEA-aligned. The complication is one layer up: Visma's own cap table is a private-equity consortium that historically includes Hg Capital (UK), Cinven (UK), TPG (US), GIC (Singapore), and Intermediate Capital Group (UK), so beneath the Norwegian wrapper there is meaningful US private-equity exposure (TPG), enough to mention in a procurement-grade audit even though the direct parent is EEA. Pre-acquisition investors include Fortino Capital, Sage Capital Partners, PMV (Participatiemaatschappij Vlaanderen), Keen Venture Partners, and Altered Capital, all European. Pricing in EUR: from €37/month with a 14-day no-credit-card free trial; no permanent free tier. Public legal pages did not fully resolve at audit (the privacy and security URLs hit redirect loops, /en/legal returned 404), and the underlying hosting provider for customer data was not disclosed in accessible public docs. Best fit: Belgian and Dutch SMBs, agencies, and self-employed professionals who want an end-to-end CRM-plus-invoicing tool from a Ghent-rooted vendor, and who can accept a Norwegian-owned Visma parent with mixed EU/UK/US private-equity sponsorship at the group level. Procurement-led buyers requiring an EU-only ownership chain plus a verified sub-processors list should look at Salesflare (BE) or weclapp (DE) instead, listed below. **Compliance rationale:** Belgian SaaS scale-up (Ghent) for SMB CRM + invoicing, owned by Norwegian Visma Group since June 2022. Visma is EEA-incorporated but its own cap table includes US PE (TPG) alongside Hg Capital, Cinven, GIC and ICG, and Teamleader's hosting provider is not publicly disclosed at audit; without verified sub-processors or DPA URL, and with US-PE exposure at the group level via TPG-via-Visma, the CLOUD Act flag is material pending positive verification of hosting and DPA. ### Teamwork.com: https://euvetted.com/p/teamwork - Website: https://www.teamwork.com - Category: Project management - Country of incorporation: Ireland - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium (from €10/month) - Founded: 2007 - Certifications: SOC2 - DPA: https://www.teamwork.com/legal/teamwork-com-data-processing-agreement/ - Sub-processors list: https://www.teamwork.com/legal/teamwork-com-data-processing-agreement/ - Last verified: 2026-05-18 Irish project-management + time tracking (Cork, 2007), agency-focused, 16k+ businesses, SOC 2 Type 2, Bregal-PE-funded. Teamwork.com is the Cork-headquartered Irish project-management platform purpose-built for client-services agencies, founded in 2007 by **Peter Coppinger** and **Daniel Mackey** and operating as Teamwork Crew Ltd. The product covers projects, tasks, time tracking, billing, resource scheduling, and an integrated chat, distinguishing itself from Asana / Monday by being built specifically for billable-hour workflows. As of January 2025, Daniel Mackey succeeded Peter Coppinger as CEO (Coppinger had served as CEO for 17 years before transitioning to a board director role). The customer base is 16,000+ businesses across the US, UK, Australia, Canada, and Europe. For an EU-sovereignty audit Teamwork presents a mixed signal set. The operating entity is Irish, EU-jurisdiction, and the 2021 $70M growth round was led by **Bregal Milestone**, a European growth-PE firm whose ultimate backer is Bregal Investments (the Brenninkmeijer family office, the European founders of C&A retail). No US PE/VC dominance on the cap table at audit time. The product is **SOC 2 Type 2 certified**, publishes a public DPA and sub-processors list, and explicitly commits that customer data is never used to train third-party AI models. The gaps are the absence of public hosting-region disclosure (AWS is the industry-default at this scale; vendor outreach needed to confirm region) and the lack of ISO 27001 / EUCS / C5 attestations on accessible public pages, resulting in a minor CLOUD Act exposure flag pending hosting confirmation. Pricing in EUR: Free plan covers up to 5 users, 5 projects, 100 automations, 100 MB storage; **Basics €9.99/user/month** (annual billing, ~29% savings) expands to 300 projects with AI comment summarisation; higher Pro / Grow / Scale tiers add unlimited projects, advanced views, custom roles, and enterprise features. Best fit: client-services agencies, consultancies, marketing teams, and project-driven SMBs across the EU and English-speaking markets that need billable-time-aware PM tooling. **Compliance rationale:** Irish PM platform (Teamwork.com, Cork; founded 2007 by Peter Coppinger and Daniel Mackey, Mackey CEO since Jan 2025) serving 16,000+ businesses with an agency-focused product surface (projects, tasks, time-tracking, billing), SOC 2 Type 2 certified, **Bregal Milestone** (European growth-PE, Brenninkmeijer family-anchored) led the 2021 $70M round. EU-owned with a public DPA and sub-processors list, but hosting provider not publicly disclosed (AWS likely at this scale) and ISO 27001 not advertised. EU-incorporated with minor CLOUD Act exposure pending hosting region confirmation. **Sub-processors mapped:** 9 total, 9 US-owned - AWS (United States): Cloud Service Provider [US-owned] - Datadog (United States): Logs & Application Monitoring [US-owned] - DigitalOcean (United States): Video Messaging [US-owned] - LaunchDarkly (United States): Feature Version Release Control [US-owned] - Mailgun (United States): Notification Services [US-owned] - Pendo (United States): Product Analytics [US-owned] - SendGrid (United States): Notification Services [US-owned] - Sentry (United States): Logs & Application Monitoring [US-owned] - Zapier (United States): Integration Provider [US-owned] ### TelemetryDeck: https://euvetted.com/p/telemetrydeck - Website: https://telemetrydeck.com - Category: Web analytics - Country of incorporation: Germany - Hosting country: Germany (Gunzenhausen) - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: freemium (from €9/month) - Founded: 2020 - DPA: https://telemetrydeck.com/dpa/ - Sub-processors list: https://telemetrydeck.com/privacy/ - Last verified: 2026-05-10 German privacy-first mobile + web app analytics with on-device anonymisation, EN/DE DPA, and a transparent sub-processors list. TelemetryDeck is an Augsburg-headquartered privacy-first mobile and web app analytics platform operated by TelemetryDeck GmbH (Von-der-Tann-Str. 54, 86159 Augsburg, Germany), founded in 2020 by Daniel and Lisa during the pandemic and serving more than 6,000 developers across iOS, Android, Flutter, React Native, and the web. The differentiator is on-device anonymisation: signals are hashed before they ever leave the device, so the dashboard sees only aggregate, non-identifying data, which makes app-store privacy nutrition labels trivial and removes the need for in-app tracking consent in most jurisdictions. Trust documentation is unusually thorough for a small German vendor: a publicly-linked DPA in English, an AVV (Auftragsverarbeitungsvertrag) in German, a transparent privacy policy (last updated 30 June 2025) that names every sub-processor with its full legal address, and Standard Contractual Clauses (EU-Standarddatenschutzklauseln) cited for any third-country transfers. The infrastructure side is more mixed than the brand suggests, however. The privacy policy lists three hosting providers: Hetzner Online GmbH in Gunzenhausen (EU-owned, EU region), Microsoft Ireland Operations Ltd. in Dublin (Azure, US-owned hyperscaler in an EU region), and Amazon Web Services, Inc. (Seattle legal-entity address, region unclear), which means a non-trivial portion of customer signal data at rest sits with US-owned hyperscalers. Other sub-processors include HubSpot (US, contact management), Brevo (DE, newsletter), Meta Ireland (Instagram embed), X Corp Ireland (Twitter embed), GitHub (US, code-hosting widget), and Mastodon (DE, social embed). Per the directory's strict CLOUD Act stance, where provider ownership matters more than data-centre region (Schrems II / Microsoft Ireland v US), this combination is material CLOUD Act exposure despite an otherwise excellent transparency posture. Pricing is freemium: 100,000 signals/month free for indie developers, with paid plans starting around €9/month; annual billing offered with 20% discount. Awards: CDR Corporate Digital Responsibility 2024, MyData Award 2025, Augusta Wirtschaftspreis für Frauen. Best fit: indie iOS/Android/Flutter developers and small mobile-app shops who want on-device privacy with a clean DPA story and don't mind the Azure-EU + AWS dependency. Procurement-grade enterprise mobile teams with strict no-US-cloud requirements should look at self-hosted Matomo for mobile, or evaluate whether the Hetzner-only data path can be selected explicitly with TelemetryDeck. **Compliance rationale:** German GmbH (Augsburg) with on-device anonymisation, public DPA + AVV in EN/DE and a transparent named sub-processors list, but the infrastructure mix includes Microsoft Ireland (Azure, US-owned, EU-region), AWS Inc. (Seattle), and HubSpot (US) alongside Hetzner Gunzenhausen, so customer signal data sits across multiple US-owned hyperscalers; EU-owned with a public DPA and disclosed sub-processors, but material CLOUD Act exposure due to Azure and AWS handling customer data at rest. **Sub-processors mapped:** 5 total, 3 US-owned - Amazon Web Services, Inc. (United States): Hosting (analytics infrastructure, eu-central-1 Frankfurt) [US-owned] - HubSpot Inc. (United States): CRM [US-owned] - Microsoft Ireland Operations Ltd. (Ireland): Hosting [US-owned] - Hetzner Online GmbH (Germany): Hosting - Sendinblue GmbH (Brevo) (Germany): Newsletter ### Thalassa Cloud: https://euvetted.com/p/thalassa-cloud - Website: https://thalassa.cloud - Category: Cloud & hosting - Country of incorporation: Netherlands - Hosting country: Netherlands (Arnhem) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €5/month) - Founded: 2024 - Last verified: 2026-06-03 Dutch Kubernetes-native sovereign cloud (Thalassa Cloud Services B.V., Arnhem, 2024); 100% EU-owned, NL-hosted, API-first with an official Terraform provider. Early-stage, no published certifications yet. **Thalassa Cloud** (operated by Thalassa Cloud Services B.V., Meander 251, Arnhem, Netherlands; KvK 99309769) is a bootstrapped, founder-led EU-sovereign public cloud built Kubernetes-native and API-first, positioned as a Dutch alternative to the hyperscalers for DevOps teams. The platform covers virtual machines, managed Kubernetes (with integrated IAM/RBAC and VPC), managed PostgreSQL, S3-compatible object storage, block and file storage, container registry, managed Prometheus and a cost explorer, all provisionable through a REST API, CLI, and official Terraform / OpenTofu / Pulumi providers. Billing is usage-based (per-minute, EUR ex-VAT): the cheapest VM is roughly €5/month, a managed Kubernetes control plane around €19.50/month, with free VPC / subnets / security-groups and free bandwidth. A "Dedicated Private Cloud" option is offered for organisations wanting isolated capacity. The sovereignty positioning is strong and clean on paper: 100% EU-owned, NL-hosted, no non-EU dependencies, GDPR-first design, NIS2 support, and Dutch Cloud Community membership, with named public-sector customers including Provincie Noord-Holland and Dienst Justitiële Inrichtingen (DJI). The caveats are maturity and assurance: founded around 2024 as a bootstrapped startup with a very small team; a single region (Arnhem, nl-ams-1) with the data-centre operator undisclosed; no published certifications (ISO 27001 / BSI C5 / SecNumCloud / SOC 2 are described as available "via partners", i.e. not currently held); a Data Processing Agreement that is referenced in the terms but available only on request; and no public sub-processors list. No GPU instances or bare-metal. Best fit: Dutch / EU teams that want a genuinely EU-owned, Kubernetes-native sovereign cloud and can accept an early-stage provider without formal certifications. Not yet a fit for procurement that mandates ISO 27001 / C5 or a publicly signable DPA. **Compliance rationale:** **Thalassa Cloud Services B.V.** (Arnhem, Netherlands; KvK 99309769, founded ~2024) is a bootstrapped, **100% EU-owned** Kubernetes-native sovereign cloud: virtual machines, managed Kubernetes, managed PostgreSQL, S3-compatible object storage and VPC networking driven by an API-first control plane with an official Terraform/OpenTofu provider. Jurisdiction is clean: Dutch B.V., no US parent, no external/US VC, NL-hosted, and the vendor states no non-EU dependencies, so CLOUD Act exposure is low on its face. The score is held down by the assurance gap, not the sovereignty story: **no published third-party certifications** (no ISO 27001 / BSI C5 / SecNumCloud / SOC 2, only 'via partners'), the **DPA is request-only** (no public URL), there is **no public sub-processors list**, and the platform is **early-stage**: a single region (Arnhem, nl-ams-1), a very small founder-led team, and several services still 'Coming Soon'. Listed for sovereignty coverage as a credible EU-owned NL option, with the early-stage and transparency caveats noted. ### Threema: https://euvetted.com/p/threema - Website: https://threema.com - Category: Video conferencing - Country of incorporation: Switzerland - Hosting country: Switzerland - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: freemium (from €3/month) - Founded: 2012 - Certifications: ISO27001 - DPA: https://threema.com/en/dpa - Sub-processors list: https://threema.com/en/dpa/annex-3 - Last verified: 2026-05-21 Swiss E2EE messenger (Pfäffikon SZ, founded 2012), ISO 27001, all-Swiss hosting, no phone number required; consumer + enterprise (Threema Work) + on-prem. Threema is a Swiss end-to-end encrypted messaging application developed and operated by **Threema GmbH** (Pfäffikon SZ, Switzerland, Commercial Register: CHE-221.440.104), founded in December 2012 by three Swiss developers as a privacy-first alternative to WhatsApp, launching on Apple's App Store the same month the app was conceived. The legal entity was formally registered as Threema GmbH in spring 2014 to support professional expansion. Key milestones: post-Snowden traction in 2013, Threema Work (business edition) launched 2016, surpassed 10 million users in early 2021 following WhatsApp's controversial terms-of-service update, and a new CEO appointed in 2024. The product portfolio is three-tier. **Threema Private** (consumer): one-off purchase app for iOS + Android + desktop, no phone number or email required for sign-up; fully anonymous use possible. **Threema Work** (business): managed admin console, MDM integration, enforced encryption policies, SSO via SAML/OIDC, priced at €3/user/month (Core) or €5/user/month (Professional); 30-day free trial for up to 30 users. **Threema OnPrem** (self-hosted): the full Threema Work stack deployable on customer infrastructure, for buyers who require complete data sovereignty inside their own security perimeter. All three tiers share the same cryptographic core: end-to-end encrypted messages, voice calls, video calls, group chats, file transfers, and polls using the NaCl/libsodium cryptography library; encryption by default with no plaintext fallback. Compliance posture is among the strongest in the messenger category. **ISO/IEC 27001 certified**. Data processing for all essential functions runs **exclusively on Threema's own servers in Switzerland** (confirmed in the publicly available DPA). Switzerland holds an EU adequacy decision (Art. 45 GDPR), SCC-free for EU↔CH transfers. The DPA (threema.com/en/dpa) is publicly accessible without login and references standard contractual safeguards for any third-party functions. The company explicitly positions Threema as compliant with **NIS 2, DORA, and CER** EU directives. Ownership: Threema was acquired by **Comitis Capital GmbH** (a German investment firm focused on purpose-driven companies) from Afinum Management GmbH in early 2026, still EU-controlled, no US capital. Open-source: a Google-free Android version (Threema Libre) ships via F-Droid with reproducible builds for independent verification; the app source code is publicly auditable. Best fit: privacy-conscious individuals replacing WhatsApp or Signal with a Swiss-hosted option; German and EU enterprises needing an auditable E2EE messaging platform under their own IT control; regulated sectors subject to NIS 2 / DORA that need a compliant internal comms layer. **Compliance rationale:** Threema GmbH (Pfäffikon SZ, Switzerland, CHE-221.440.104) processes personal data exclusively on servers in Swiss data centres for all essential functions, holds ISO 27001 certification, publishes a public DPA, and is Swiss-incorporated with EU adequacy: no CLOUD Act exposure, EU-adequate jurisdiction (CH), ISO 27001 certified, public DPA, all-Swiss hosting confirmed in the DPA, open-source clients with reproducible builds. ### Tidio: https://euvetted.com/p/tidio - Website: https://www.tidio.com - Category: Helpdesk - Country of incorporation: Poland - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: freemium - Founded: 2013 - Certifications: SOC2 - DPA: https://www.tidio.com/wp-content/uploads/the-agreement-or-the-dpa.pdf - Last verified: 2026-05-11 Szczecin-based Polish chatbot + live chat (founded 2013 by Tytus Gołas), 300k+ businesses, SOC 2; US-VC-funded (PeakSpan). Tidio is a Szczecin-headquartered Polish customer-service platform founded in 2013 by **Tytus Gołas** (at age 20, in Szczecin) and Marcin Wiktor, and one of the fastest-growing Polish SaaS exports of the decade. The product covers live chat, helpdesk ticketing, chatbots, and an AI agent layer, recently expanded with **Lyro AI Agent** (customer-service automation) and **Hubi AI** (marketing automation) on top of the core multi-channel inbox. The company reports more than **300,000 businesses** on the platform with strong G2 / Capterra / Shopify / WordPress ratings (4.6-4.7 across reviewers). The company carries **SOC 2** attestation. For an EU-sovereignty audit the procurement-grade picture is mixed. The Polish HQ and founder team are clean European; total funding raised is approximately **US$26.8M** and the **Series B was led by PeakSpan Capital** (a US growth-equity firm headquartered in New York) alongside Inovo Venture Partners (Poland) and InPost CEO Rafał Brzoska's individual investment. The PeakSpan lead at the cap-table layer plus the recent AI product expansion (which structurally requires either US LLM-API dependencies like OpenAI / Anthropic or self-trained models on hyperscaler GPU) keeps the listing at `eu_hq_us_funded` with material CLOUD Act exposure under our strict-ownership stance. The underlying hosting provider for customer chat data is not publicly disclosed at audit time but standard AI-SaaS at this scale runs on AWS-EU. Pricing is freemium with paid Communicator, Chatbots, and Tidio+ tiers; specific entry-tier EUR figures were not captured at audit. Best fit: SMB e-commerce businesses on Shopify / WooCommerce that need integrated chat + chatbot + AI agent automation, Polish + European SMBs that want a Polish-founded alternative to Intercom / Drift, and any organisation that can accept a US-VC-funded EU brand with the typical AI-stack US-cloud dependencies. Procurement-grade EU-only buyers requiring clean ownership should look at Crisp (FR), Userlike (DE), or chatlyn (AT, Nordic-VC-funded only) instead. **Compliance rationale:** Tidio (Szczecin, Poland; founded 2013 by **Tytus Gołas** at age 20 and Marcin Wiktor) is the fastest-growing Polish customer-service / chatbot platform with 300,000+ businesses on the platform and SOC 2 certification. Series B led by **PeakSpan Capital (US growth equity, NYC)** with **Inovo Venture Partners (Poland)** and InPost CEO Rafał Brzoska, US$26.8M total raised. EU HQ but US-VC-led cap table: the PeakSpan Capital lead investor position flags the listing as `eu_hq_us_funded`. AI features (Lyro AI Agent, Hubi AI) imply LLM-API dependency on US providers (OpenAI / Anthropic), resulting in material CLOUD Act exposure. No public DPA or sub-processors list captured at audit. ### Tixeo: https://euvetted.com/p/tixeo - Website: https://www.tixeo.com - Category: Video conferencing - Country of incorporation: France - Hosting country: France (Montpellier) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2003 - Certifications: SECNUMCLOUD - Sub-processors list: https://www.tixeo.com/en/privacy-policy/ - Last verified: 2026-05-11 Montpellier-based French secure video conferencing (founded 2003), ANSSI CSPN-certified, SecNumCloud-qualified, defense + government grade. Tixeo is a Montpellier-headquartered French secure-video-collaboration vendor, founded in 2003, and is structurally the most-credentialed sovereign video-conferencing listing in this directory. The product portfolio is three-tier: **TixeoCloud** (managed SaaS), **TixeoServer** (customer-self-hosted on-premise), and **TixeoPrivateCloud** (sovereign cloud hosting on the SecNumCloud-qualified operator **3DS Outscale**). All three modes share the same proprietary end-to-end encrypted multipoint audio/video/data architecture: true E2EE regardless of the number of participants, with encryption-by-default across messaging, file transfer, and collaboration modes. The sovereignty positioning is built on two unmatched-in-category French government certifications. First, **ANSSI CSPN (Certification de Sécurité de Premier Niveau)** awarded by the French Cybersecurity Agency in 2017 and renewed three times since. **Tixeo is the only video-conferencing technology in Europe to hold this CSPN certification and ANSSI qualification**. Second, **TixeoPrivateCloud is SecNumCloud-qualified** via its 3DS Outscale hosting backbone, providing the same legal-protection-from-extraterritorial-laws guarantees that ANSSI builds into the SecNumCloud framework (specifically engineered against US CLOUD Act and FISA Section 702 reach). Compliance posture additionally covers NIS 2 (the EU cybersecurity directive), DORA (financial-services operational resilience), and full GDPR alignment. Software design and development are entirely inside Europe. Tixeo's own messaging is unambiguous: "our proprietary technology is not subject to foreign legislation". Customer base reflects the sovereignty positioning: **30% of Europe's top-100 defence companies** (per the Stockholm International Peace Research Institute 2023 ranking) use Tixeo for secure collaboration, alongside customers from finance, public administration, industry, and energy. Pricing is enterprise / sales-engaged. Tixeo does not publish a self-serve consumer tier. Best fit: defence and aerospace primes (Airbus-class organisations), French and EU public-sector procurement (where CSPN + SecNumCloud are usually mandatory bid criteria), regulated financial services subject to DORA, healthcare systems requiring NIS 2 compliance, and any mid-market or enterprise buyer for whom CLOUD-Act-clean E2EE video is non-negotiable. **Compliance rationale:** Tixeo is a **Montpellier-based French video-collaboration vendor founded in 2003** and is the **only video conferencing technology in Europe that holds both ANSSI CSPN certification (since 2017, renewed three times) AND SecNumCloud qualification (via TixeoPrivateCloud on 3DS Outscale)**, the highest French sovereignty bar. End-to-end encrypted multipoint audio/video/data, NIS 2 + DORA + GDPR compliant, **100% software design and development inside Europe with proprietary technology not subject to foreign legislation**, and 30% of Europe's top-100 defence companies (per Sipri 2023) on the customer list: EU-owned, EU-hosted (FR), no CLOUD Act exposure, ANSSI CSPN + SecNumCloud certified, and the strongest sovereignty positioning in the video-conferencing category. ### Trackboxx: https://euvetted.com/p/trackboxx - Website: https://www.trackboxx.com - Category: Web analytics - Country of incorporation: Germany - Hosting country: Germany - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid - DPA: https://trackboxx.com/daten/trackboxx-av.pdf - Sub-processors list: https://www.trackboxx.com/datenschutz - Last verified: 2026-05-10 German sole-proprietor cookieless analytics, B2B-only, with daily-rotating anonymisation and BunnyCDN script delivery. Trackboxx is a small German cookieless web analytics product operated by Christian Pust as a sole proprietorship (Humboldtstraße 9, 38820 Halberstadt; branch office at Dorfstr. 12, 22956 Grönwohld). The service is sold strictly business-to-business, the imprint explicitly states that "Unser Service richtet sich ausschließlich an Unternehmer" (our service is directed exclusively at commercial customers). Co-founders Christian and Ulrike split development, strategy, marketing, and social media duties. The product runs cookieless analytics with rotating daily encryption codes for visitor anonymisation, marketing itself as "100% DSGVO-konform" with the Bitmi (Bundesverband IT-Mittelstand) member badge. The privacy policy is unusually transparent for a small vendor: the named sub-processors are Paddle (UK, payments / merchant of record), Amazon Web Services (Amazon Simple Email Service for newsletter delivery, the only US-owned sub-processor), Userlike (DE, chat), BunnyCDN (SI, script delivery), and TradeTracker (NL, affiliate tracking). What it does not disclose is the underlying hosting provider or data-centre location for the customer analytics database itself, which is the main gap for procurement-grade buyers. Pricing was not captured at audit (the public /pricing and /preise paths returned 404) and a formal DPA artefact is not linked; the imprint also omits a Handelsregister number and USt-IdNr, which is consistent with a sole-proprietor (Einzelunternehmen) structure but unusual for a vendor courting business buyers. Best fit: small German-speaking SMBs and e-commerce shops that want a low-friction Google Analytics replacement, accept a sole-proprietor counter-party, and don't need a contract-grade DPA. Procurement-led buyers should choose Pirsch, Plausible, or Wide Angle Analytics in this category instead. **Compliance rationale:** German sole-proprietor analytics product (Christian Pust, Halberstadt) with cookieless tracking, daily-rotating anonymisation, and named sub-processors disclosed in the privacy policy. EU-owned but the hosting provider for customer analytics data at rest is not publicly disclosed, the Imprint omits HRB/VAT details, no formal DPA artefact is published, and AWS Simple Email Service (US-owned) is used for newsletter email, resulting in minor CLOUD Act exposure. **Sub-processors mapped:** 3 total, 0 US-owned - BunnyWay d.o.o. (Slovenia): CDN services (BunnyCDN) - Paddle.com Market Ltd. (United Kingdom): Payment processing - TK ENTERPRISES LTD (Cyprus): Hosting / IT-server infrastructure (datacenter Frankfurt, Germany) ### Tresorit: https://euvetted.com/p/tresorit - Website: https://tresorit.com - Category: File sharing - Country of incorporation: Switzerland - Hosting country: Ireland (Dublin) - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: paid (from €10/month) - Founded: 2011 - Certifications: ISO27001 - Sub-processors list: https://support.tresorit.com/hc/en-us/articles/216114397-Third-party-services - Last verified: 2026-05-18 Swiss-Post-owned (state-anchored) E2E encrypted enterprise cloud storage (Tresorit AG, Zurich), Swiss + EU DC options, ISO 27001. Tresorit is the enterprise zero-knowledge end-to-end-encrypted cloud-storage product operated by **Tresorit AG** at Pfingstweidstrasse 60b, 8005 Zurich, Switzerland (CHE-349.825.210), with offices also in Budapest, Hungary and Munich, Germany. Founded in 2011 by Hungarian engineers István Lám and Szilveszter Szebeni, the company built its reputation around mathematically-provable client-side encryption: every file, file name, and metadata is encrypted on the user device before upload, so neither Tresorit nor any data-centre operator can access plaintext customer content. The company serves 11,000+ organisations with 4.9 / 4.5 G2 / Capterra ratings. For an EU-sovereignty audit Tresorit's ownership story is unusually strong. In July 2021 **Swiss Post** (the Swiss state-owned postal and digital-services operator) acquired a majority stake; as of 2026 Swiss Post is the **sole shareholder**, making Tresorit a fully Swiss-state-anchored entity. This pushes the directory's `other` (Switzerland) classification into the highest end of that tier: Swiss jurisdiction with state-owned parent is structurally as close to "sovereign" as a vendor can credibly claim. The compliance footprint matches: **ISO/IEC 27001:2022** certified by TÜV Rheinland (covering sales, development, maintenance, and support of E2E-encrypted cloud services), plus alignment with GDPR, HIPAA, ITAR, FINRA, CCPA, CJIS, **DORA**, **NIS2**, and **TISAX**, an unusually broad regulated-industry coverage including US healthcare (HIPAA), US defence-export controls (ITAR), US financial markets (FINRA), and US criminal-justice systems (CJIS) for the rare global customers who need that combination on top of a Swiss-jurisdiction base. Customer-selectable Swiss or EU data residency, contracts under Swiss law and the Swiss Federal Act on Data Protection. Pricing in EUR: a Personal Plus tier starts at approximately €10/month for ~1 TB; Business plans start in the €14-30/user/month range across SecureCloud and Engage tiers; Enterprise is negotiated. Best fit: regulated enterprises (legal, financial-services, healthcare, defence), Swiss public-sector buyers, journalists and NGOs, and any organisation needing a Dropbox / Box / OneDrive replacement with mathematically-provable zero-knowledge encryption from a state-anchored Swiss vendor. Together with Proton Drive, Tresorit forms the directory's Swiss-encrypted file-sharing dual-pick; Proton wins on consumer / freemium and ecosystem breadth (Mail/VPN/Pass/Calendar/Docs), Tresorit wins on enterprise compliance breadth and the unique Swiss-Post state-owned governance. **Compliance rationale:** **Tresorit AG** (Zurich, Pfingstweidstrasse 60b; CHE-349.825.210) is the enterprise-grade zero-knowledge end-to-end-encrypted cloud-storage product founded in 2011 by István Lám and Szilveszter Szebeni in Hungary and **majority-acquired by Swiss Post (the Swiss state-owned postal operator) in 2021**; Swiss Post is now sole shareholder, putting the company under Swiss government / state-anchored ownership; ISO/IEC 27001:2022 certified by TÜV Rheinland, GDPR + HIPAA + ITAR + FINRA + CCPA + CJIS + DORA + NIS2 + TISAX coverage, customer-selectable Swiss or EU data residency, contracts under Swiss law / Swiss Federal Act on Data Protection. The verified sub-processor list (2026-06) shows Tresorit's primary hosting is Microsoft Azure (a US-owned hyperscaler), which raises CLOUD Act exposure to `material` on a structural reading; in practice the zero-knowledge end-to-end encryption means Azure stores only ciphertext and Tresorit holds no keys, so compelled disclosure yields no readable content. State-anchored Swiss (Swiss Post) ownership, ISO/IEC 27001:2022 certified by TÜV Rheinland; the DPA is account-gated (paid plan + Subscription Owner role) with no standalone public URL, the key documentation gap. **Sub-processors mapped:** 15 total, 13 US-owned - Amazon Simple Email Service (SES) (United States): Transactional and notification emails (data in Ireland/EU) [US-owned] - DocuSign (United States): Electronic signatures for agreements [US-owned] - Google reCAPTCHA (United States): Fraud and misuse prevention during checkout [US-owned] - Microsoft Azure (United States): Primary hosting (E2E-encrypted content stored in Ireland/EU) and application performance monitoring [US-owned] - Pardot (Salesforce) (United States): Marketing campaigns for customers and subscribed visitors [US-owned] - PayPal (United States): Online payments [US-owned] - Productboard (United States): Customer feedback management [US-owned] - Salesforce (United States): Customer relationship management (data in Ireland/EU) [US-owned] - SendGrid (Twilio) (United States): Transactional and notification emails [US-owned] - Stripe (United States): Payment processing [US-owned] - Twilio (United States): Two-factor authentication (voice and SMS) [US-owned] - Zendesk (United States): Customer support tools [US-owned] - Zuora (United States): Subscription billing, invoicing and management [US-owned] - Tresorit GmbH (Germany): Affiliate sub-processor delivering Tresorit services - Tresorit Kft. (Hungary): Affiliate sub-processor delivering Tresorit services ### Tresorit eSign: https://euvetted.com/p/tresorit-esign - Website: https://tresorit.com/m/esign - Category: E-signature - Country of incorporation: Switzerland - Hosting country: Ireland (Dublin) - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: paid (from €5/month) - Founded: 2011 - Certifications: ISO27001 - Sub-processors list: https://support.tresorit.com/hc/en-us/articles/216114397-Third-party-services - Last verified: 2026-06-26 E-signature module of Swiss-Post-owned Tresorit, the directory's only zero-knowledge E2E option with eIDAS Qualified signatures (via Evrotrust QTSP); runs on Azure (default EU region Ireland). Tresorit eSign is the electronic-signature module of **Tresorit AG** (Pfingstweidstrasse 60b, 8005 Zurich; CHE-349.825.210), the zero-knowledge end-to-end-encrypted cloud-storage company that has been a wholly-owned subsidiary of **Swiss Post** (the Swiss state-owned postal and digital-services operator) since 2021. Launched as a product around 2022, eSign is the directory's only e-signature listing that combines genuine **zero-knowledge, end-to-end encryption** of the document workflow with full **eIDAS Qualified Electronic Signatures (QES)**. Tresorit is not itself a Qualified Trust Service Provider; the QES tier is issued through a partnership with **Evrotrust**, an EU-listed QTSP (Bulgaria), and obtaining a qualified signature requires ID/passport plus video identification of the signer, in line with eIDAS. The product also offers simple electronic signatures, Long Term Validation (signature validity guaranteed for 5, 10, or more years), drag-and-drop fillable fields, and signing from any device without a Tresorit account. For an EU-sovereignty audit the posture mirrors Tresorit's storage listing. The infrastructure is **Microsoft Azure**, with the default data-at-rest region in **Ireland (EU)** and customer-selectable EU residency (Germany, France, Netherlands and others) on Business and Enterprise plans; the company is **ISO/IEC 27001:2022** certified (TÜV Rheinland) and aligned with GDPR plus a broad regulated-industry set. The directory records `cloud_act_exposure: material` because Azure is a US-owned hyperscaler sitting in the at-rest path, but the zero-knowledge architecture means Azure stores ciphertext only and Tresorit holds no keys, so compelled disclosure yields no readable content. The two transparency gaps carried over from the storage listing apply here too: there is no public standalone DPA URL (the DPA is delivered to business customers on request) and the sub-processor list is published via the Tresorit help centre rather than a dedicated legal page. Ownership is Swiss-state-anchored (`ownership_signal: other`: Switzerland, with Swiss Post as sole shareholder). Pricing is paid: licences are around €5/month per user, with per-signature pricing of roughly €0.3 for a simple electronic signature and €2.5 for an EU Qualified electronic signature, and a small free quota (about 10 simple and 6 qualified signatures) for evaluation. Best fit: regulated teams (legal, healthcare, finance, security-conscious businesses) already standardised on Tresorit's encrypted storage who want qualified signatures inside the same end-to-end-encrypted workspace rather than bolting on a separate signing platform. Buyers whose priority is the cleanest ownership-and-sub-processor story for purely-EU workflows should look to Skribble (Switzerland, no CLOUD Act exposure); the Namirial-group QTSPs Universign (France) and Signaturit (Spain), once the benchmark here, now carry the same `material` exposure (AWS at rest) plus a US-private-equity parent (Bain Capital, 2025) and, unlike Tresorit eSign, no zero-knowledge encryption to offset it. Tresorit eSign's differentiator remains the zero-knowledge-encryption-plus-QES combination, which none of the other listed options match. **Compliance rationale:** Tresorit eSign is the electronic-signature module of **Tresorit AG** (Zurich; sole shareholder **Swiss Post**, the Swiss state-owned operator) and is the directory's only e-signature option combining **zero-knowledge end-to-end encryption** with **eIDAS Qualified Electronic Signatures**, the latter issued through a partnership with the EU Qualified Trust Service Provider **Evrotrust** (Bulgaria) rather than by Tresorit itself; ISO/IEC 27001:2022 certified, runs on Microsoft Azure with a default EU storage region of Ireland and customer-selectable EU residency. CLOUD Act exposure is `material` because Azure is a US-owned hyperscaler in the at-rest path, but the zero-knowledge architecture means Azure holds ciphertext only and Tresorit holds no keys; held at 4/5 by that US storage sub-processor and the absence of a public standalone DPA URL (request-based), with state-anchored Swiss-Post ownership and the E2E + QES combination as the offsetting strengths. For pure-EU-sovereignty buyers the one category option with no US-owned infrastructure in the at-rest path is Skribble (CH, `cloud_act_exposure: none`); the Namirial-group QTSPs (Universign FR, Signaturit ES) are no longer a cleaner alternative here, since their 2025 Bain Capital (US private-equity) ownership and AWS-at-rest hosting put them at `material` too, without Tresorit's zero-knowledge mitigation. **Sub-processors mapped:** 10 total, 7 US-owned - Amazon Simple Email Service (SES) (United States): Transactional and notification emails (data in Ireland/EU) [US-owned] - Microsoft Azure (United States): Primary hosting (E2E-encrypted content stored in Ireland/EU) and application performance monitoring [US-owned] - SendGrid (Twilio) (United States): Transactional and notification emails [US-owned] - Stripe (United States): Payment processing [US-owned] - Twilio (United States): Two-factor authentication (voice and SMS) [US-owned] - Zendesk (United States): Customer support tools [US-owned] - Zuora (United States): Subscription billing, invoicing and management [US-owned] - Evrotrust Technologies AD (Bulgaria): EU Qualified Trust Service Provider; issuance of eIDAS Qualified Electronic Signatures and signer identity verification - Tresorit GmbH (Germany): Affiliate sub-processor delivering Tresorit services - Tresorit Kft. (Hungary): Affiliate sub-processor delivering Tresorit services ### Tripetto: https://euvetted.com/p/tripetto - Website: https://tripetto.com - Category: Forms & surveys - Country of incorporation: Netherlands - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium (from €90/month) - Founded: 2019 - Last verified: 2026-05-11 Dutch form builder with hosting freedom: free Studio cloud, WordPress plugin, and FormBuilder SDK that lets you self-host data. Tripetto is a Dutch form-and-survey builder centred on the principle of "hosting freedom": customers can run forms on Tripetto's cloud (Studio), inside a self-hosted WordPress plugin, or via the FormBuilder SDK with full self-hosting where survey data never reaches Tripetto servers at all. The product positions itself against Typeform, SurveyMonkey, Google Forms, WPForms, Gravity Forms, and Contact Form 7, and ships with a "magnetic storyboard" form-design canvas, three rendering modes (Autoscroll, Chat, Classic), conversational logic primitives, and 1,000+ automation connectors (Slack, Zapier, Make). For procurement-grade EU buyers the structurally interesting feature is the hybrid hosting model. The FormBuilder SDK is sold as a developer licence (from US$10,800/year, ~€10,000) and lets the customer host all form data on infrastructure of their choosing. Running it on Hetzner, OVH, Scaleway, or any other EU-incorporated host gives the customer full control with no CLOUD Act exposure. The WordPress plugin operates on the customer's WordPress installation, with the same self-control properties. The Studio (cloud) product is where transparency drops off: at audit time the dedicated /privacy/, /security/, /dpa/, /about/, and /legal/ URLs all returned 404, and the cloud product's hosting provider, sub-processors, and DPA artefact were not publicly named, so the cloud Studio carries a defensive minor CLOUD Act flag pending vendor outreach. Pricing for Studio is freemium: free accounts have all core features with Tripetto branding shown on rendered forms, and "Unlock 1" is a one-time US$99 payment per form (~€90) to remove branding and enable advanced connectors and activity tracking. Best fit: developers, agencies, and EU buyers who want full control over form-data residency. The SDK and WordPress plugin paths give a procurement-grade story even though the Studio cloud product needs vendor outreach to verify. The MVP shortlist noted "open-source kernel + cloud"; the open-source claim refers to embeddable runners and the SDK rather than a fully open-source server. **Compliance rationale:** Dutch open-source-kernel form builder shipping in three flavours, Studio (free cloud), WordPress Plugin, and FormBuilder SDK with self-hosting, that explicitly markets 'hosting freedom' so the customer controls where data lives; the self-host path is procurement-friendly, but the Studio cloud product does not publicly disclose its hosting provider or a unified DPA, and DPA/sub-processors/security URLs were not resolvable at audit; CLOUD Act flag is set defensively to minor pending vendor disclosure. ### Trustly: https://euvetted.com/p/trustly - Website: https://trustly.com - Category: Payments - Country of incorporation: Sweden - Hosting country: Sweden (Stockholm) - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2008 - Certifications: ISO27001, SOC2 - Last verified: 2026-05-11 Swedish open-banking A2A payment innovator (Trustly Group AB, 2008), $10B annual volume, 33+ markets; Nordic Capital + BlackRock PE owned. Trustly is a Swedish open-banking payments innovator operated by **Trustly Group AB** in Stockholm, founded in 2008 and the leading European specialist in account-to-account (A2A) "Pay by Bank" transactions: the alternative payment rail that bypasses card schemes entirely by initiating direct bank transfers from consumer accounts. The company processes approximately US$10B annually across 275M transactions, connects 9,000+ merchants to 650M consumer bank accounts globally, and operates in 33+ markets across Europe and North America. Offices span Stockholm (HQ), Örebro, Gzira (Malta), London, Helsinki, Barcelona, Lausanne, Luxembourg, Lisbon, Izmir (Turkey), Ottawa, San Carlos (California), and Vitória (Brazil). Regulatory and compliance posture is strong: Trustly holds a **Swedish payment-institution licence** supervised by **Finansinspektionen** plus a **UK Authorised Payment Institution** licence from the FCA, and provides cross-border services under PSD2. Certifications confirmed on the public site include **ISO 27001**, **SOC 2**, **TÜV Saarland** accreditation, and GDPR alignment. Open-banking expertise predates the regulatory codification: Trustly was building bank-account-to-merchant rails for 13 years before PSD2 made A2A a regulated category. The ownership and history side complicate a procurement-grade audit. **Nordic Capital** (a Stockholm-based Nordic PE firm) acquired Trustly from Bridgepoint in 2018; **BlackRock Private Equity Partners** (US, the private-equity arm of the world's largest asset manager) joined as a co-investor. An IPO was actively explored in 2021 at a rumoured €9B valuation but was put on hold in 2022 after **the Swedish Finansinspektionen imposed a SEK 130M (~€11M) fine for serious anti-money-laundering deficiencies**. As of late 2024 / 2026 Nordic Capital is again exploring options including sale or IPO at approximately US$10B. The BlackRock co-investment plus the AML fine history plus non-EU offices (Ottawa, San Carlos, Izmir, Vitória) result in `ownership_signal: eu_hq_us_funded` and `cloud_act_exposure: material` despite the strong Swedish regulatory anchoring. Pricing is enterprise / volume-negotiated; no public per-transaction tier. Best fit: Swedish, Nordic, and broader EU retailers, gambling operators (Trustly is dominant in regulated gaming), and B2B platforms wanting open-banking-native A2A rails as a Stripe / PayPal alternative. **Compliance rationale:** **Trustly Group AB** (Stockholm, founded 2008) is the leading European open-banking 'Pay by Bank' / account-to-account payments specialist (Swedish-Finansinspektionen-supervised payment institution + UK FCA authorised + EU PSD2, ISO 27001 + SOC 2 + TÜV Saarland + GDPR certifications, ~US$10B annual processed across 275M transactions and 9,000+ merchants) but ownership is a US/Nordic PE consortium (**Nordic Capital** majority since 2018, **BlackRock Private Equity Partners** US co-investor), an IPO at ~US$10B is being explored, and the 2022 Finansinspektionen €11M AML-deficiency fine remains a flag; `ownership_signal: eu_hq_us_funded`, `cloud_act_exposure: material`; no public DPA or sub-processors list accessible at audit. ### Tuta: https://euvetted.com/p/tuta - Website: https://tuta.com - Category: Private email - Country of incorporation: Germany - Hosting country: Germany (Hannover) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €3/month) - Founded: 2011 - Certifications: ISO27001 - Sub-processors list: https://tuta.com/privacy-policy - Last verified: 2026-05-18 Hannover-based end-to-end encrypted mail (formerly Tutanota); post-quantum crypto, own DE data centre, ISO 27001. **Tuta** (Hannover, Germany, founded 2011 by Arne Möhle and Matthias Pfau; Tutanota until 2023 rebrand) is one of the cleanest privacy-first email picks in Europe: **own German data centre**, **end-to-end encryption by default**, **post-quantum cryptography** (forward-looking against future quantum attacks), 100% **open-source clients** for Android, iOS, Windows, macOS, Linux, and browser. Free tier permanent for personal use; paid Revolutionary tier from ~€3/mo. Products: Tuta Mail, Tuta Calendar, Tuta Drive. Customer base: 10,000+ organisations including medical, journalism, human-rights, plus millions of consumers. 100% renewable-energy-powered. Founder-owned, no US VC, no PE, no CLOUD Act exposure. **Compliance rationale:** **Tuta** (formerly Tutanota, Hannover DE, founded 2011 by Arne Möhle and Matthias Pfau) operates its **own German data centre**, ships **end-to-end encrypted** mail / calendar / drive with **post-quantum cryptography**, all clients open-source and auditable, ISO 27001 certified, GDPR + DSGVO, 10,000+ business organisations and millions of consumer users; EU-owned, no US ties, no CLOUD Act exposure. One gap: the DPA is not publicly accessible and is reachable only inside a customer account after signing up for a business plan; no public sub-processors list. ### Typeform: https://euvetted.com/p/typeform - Website: https://www.typeform.com - Category: Forms & surveys - Country of incorporation: Spain - Hosting country: United States - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: freemium (from €26/month) - Founded: 2012 - Certifications: SOC2 - DPA: https://www.typeform.com/dpa - Sub-processors list: https://www.typeform.com/dpa - Last verified: 2026-05-11 Barcelona-headquartered Typeform SL but heavily US-VC-funded with a San Francisco Typeform Inc and AWS hosting; listed with procurement warning. Typeform is a Barcelona-headquartered conversational form and survey platform founded in 2012 by David Okuniev and Robert Muñoz, operated by Typeform SL with a US office and Typeform Inc. entity in San Francisco. The product builds forms, surveys, quizzes, polls, and conversational onboarding flows with 500+ integrations (Slack, Mailchimp, Klaviyo, Zapier, HubSpot, Salesforce, etc.), an AI form builder, and a strong design-driven UX that made the product a category-defining brand. The company markets enterprise penetration as "95% of the Fortune 500" and reports total funding of around US$193M across multiple rounds. For an EU-sovereignty audit, Typeform is the canonical example of "Spanish HQ does not equal EU-controlled". The 2022 Series C raised US$135M led by Sofina (a Belgian listed holding) with significant participation from General Atlantic (US PE), Index Ventures (UK/US), Point Nine (DE), Connect Ventures (UK), Top Tier Capital Partners (US), GP Bullhound (UK), Teamworthy Ventures (US), and Trium Venture Partners, a cap table that is heavily US-VC-weighted alongside European and UK investors. A separate US legal entity (Typeform Inc., San Francisco) contracts non-EEA customers, and customer form data is hosted on Amazon Web Services per the public AWS Marketplace listing. Per the directory's strict CLOUD Act stance, provider parent jurisdiction matters more than data-centre region (Schrems II / Microsoft Ireland v US), the AWS dependency plus the US Inc plus the US-VC ownership translate to material CLOUD Act exposure and an `eu_hq_us_funded` ownership flag. The listing carries a procurement warning: EU-headquartered but not EU-controlled, hosted on a US-owned hyperscaler. Pricing in EUR is mid-range: Basic from ~US$25/month (~€26) on annual billing with 100 responses/month included on the Free tier; Growth, Talent, and Enterprise tiers above. SOC 2 attested at the company level; ISO 27001 commonly cited but not directly verified on the public security page. Best fit: marketing teams and customer-research teams who specifically want the Typeform UX and can accept a US-VC-funded vendor on AWS. Procurement-led EU-only buyers should prefer Tally (BE, EU-owned, EU-hosted, public DPA) for free unlimited forms, Survicate (PL) for in-product surveys, or Findmind (CH) for research workflows, listed alongside in this category. **Compliance rationale:** Barcelona-headquartered (Typeform SL) but the cap table is heavily US-VC (General Atlantic, Index, Point Nine, Connect Ventures, Top Tier Capital Partners, GP Bullhound, Teamworthy, Trium) on top of a Sofina-led Series C, a Typeform Inc. presence in San Francisco contracts non-EEA customers, and customer data sits on AWS (confirmed via AWS Marketplace listing), EU-headquartered but US-VC-funded, with a US legal entity and material CLOUD Act exposure via AWS at rest; no public DPA URL resolved at audit. ### Umami: https://euvetted.com/p/umami - Website: https://umami.is - Category: Web analytics - Country of incorporation: United States - Ownership signal: us_owned - CLOUD Act exposure: direct - Pricing tier: freemium (from €9/month) - Founded: 2020 - DPA: https://umami.is/dpa - Sub-processors list: https://umami.is/subprocessors - Last verified: 2026-05-11 MIT-licensed open-source web analytics (Umami Software Inc., US); EU region on managed cloud, self-host on any EU infrastructure. Umami is the open-source web-analytics platform built and maintained by **Umami Software, Inc.**, a Delaware C-Corporation headquartered in San Francisco, USA. The codebase is licensed under the **MIT License** (one of the most permissive open-source licences available) with the full server stack on GitHub, deployable as a single Docker container backed by PostgreSQL or MySQL, or to Vercel / any Node.js-compatible serverless platform in under ten minutes. The product is positioned as the lightweight Google Analytics alternative with no cookies, no personal data collection, and a clean dashboard UX. For an EU-sovereignty audit Umami is in the same structural position as Outline (also US-incorporated): the managed **Umami Cloud** tier has both **US and EU (Germany)** hosting regions and customers can pick at signup, but the operating entity (Umami Software Inc., Delaware/San Francisco) is directly subject to the **US CLOUD Act and FISA Section 702** regardless of which region the customer picks, making the vendor-level CLOUD Act flag `direct` for the managed cloud. The **MIT-licensed self-host edition** is the EU-sovereignty path: deploy on Hetzner / OVHcloud / Scaleway / STACKIT / private EU DC and the customer becomes the sole data controller. The directory includes Umami specifically because the self-host path is well-supported, MIT-permissive, and the operational footprint is small (one container + one database). Pricing on the managed cloud: free tier with limited views/sites; paid tiers from approximately $9/month (~€8) scaling by event volume. Self-host: free under MIT. Best fit: engineering teams that already operate EU infrastructure and want a Plausible-class GA replacement under permissive licensing, or organisations that need the EU-region managed cloud and accept the US-vendor jurisdiction risk. Buyers needing a fully EU-incorporated vendor should prefer Plausible (EE) or Simple Analytics (NL) in the same category. **Compliance rationale:** **Umami Software, Inc.** (Delaware C-Corp, San Francisco, USA) maintains the **MIT-licensed** open-source web-analytics platform with **EU (Germany) hosting region available** on the managed Umami Cloud tier; vendor-level CLOUD Act exposure is `direct` (US-incorporated company), but the **MIT-licensed self-host path** lets EU buyers deploy on EU infrastructure for full sovereignty, included because the self-host path on EU infrastructure removes US-vendor exposure entirely. ### Uniqkey: https://euvetted.com/p/uniqkey - Website: https://www.uniqkey.eu - Category: Password managers - Country of incorporation: Denmark - Hosting country: Denmark - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid - Founded: 2017 - Certifications: ISO27001 - DPA: https://support.uniqkey.eu/hc/en-gb/articles/23578974332956-Data-Processing-Agreement - Last verified: 2026-05-18 Danish business password & access manager (Uniqkey A/S, Copenhagen), Danish-hosted, zero-knowledge E2E, ISO 27001, EIFO-backed, NIS2-focused. Uniqkey is a business-focused password and access manager operated by Uniqkey A/S, headquartered in Copenhagen, Denmark. The company was founded in 2017 by Hakan Yagci, is backed by EIFO, Denmark's national export and investment fund (a state promotional bank), and has raised around €5.35M to expand across Europe. That ownership profile is unusually clean for the category: a Danish A/S with national-bank backing, no US parent, no US private equity, and no US venture capital on record. The product splits into two parts: UniqPass (password management) and UniqAccess (access / SSO-style management), delivered through browser extensions and native apps for iOS, Android, Windows and macOS. The sovereignty story is the selling point. Uniqkey states that all data is **hosted on Danish data centres** with no third-party data transfer, uses **zero-knowledge end-to-end encryption** so Uniqkey itself cannot read customer vaults, is **ISO 27001 certified**, and markets a dedicated NIS2-compliance posture aimed at EU businesses that now fall under the expanded NIS2 directive. Reference customers include the Van Gogh Museum and the Danish public-sector IT supplier KMD, meaningful procurement signals for an EU-buyer audience. For an EU-sovereignty audit the only gaps are documentation and pricing transparency. The DPA and a sub-processors list were not directly findable on the public site at audit (a B2B vendor of this type certainly provides a DPA to customers; it simply was not linked publicly), which leaves the sub-processor signal unverified pending a next-pass check. Pricing is **quote-based**: the site advertises "one price, complete solution" with a free trial but does not publish per-user figures, so the EUR entry point is recorded as null. Best fit: EU SMBs and public-sector buyers (especially Nordic ones) that want a business password manager with genuine in-country (Danish) hosting, ISO 27001, zero-knowledge encryption and an explicit NIS2 angle, and who are comfortable with a sales-led pricing process. **Compliance rationale:** Uniqkey is a Danish business password-and-access manager operated by **Uniqkey A/S** (Copenhagen; founded 2017 by Hakan Yagci, backed by Denmark's national promotional bank EIFO plus a €5.35M raise). It is fully Danish-incorporated and EU-owned, **hosted entirely on Danish data centres**, zero-knowledge end-to-end encryption, ISO 27001 certified, with an explicit 'no third-party data transfer' policy and a dedicated NIS2-compliance posture; gap at audit: DPA and sub-processors URLs not publicly linked; structurally strong EU sovereignty profile with those documents pending public confirmation. ### Universign: https://euvetted.com/p/universign - Website: https://www.universign.com - Category: E-signature - Country of incorporation: France - Hosting country: France (Paris) - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2001 - DPA: https://ivnosys.com/signaturit-platform/en/dpa/ - Sub-processors list: https://ivnosys.com/signaturit-platform/en/subprocessors/ - Last verified: 2026-07-06 Long-running French QTSP (originally Cryptolog International, 2001); merged into Signaturit Group (a Namirial Italian company). Universign is a long-running French Qualified Trust Service Provider originally founded in 2001 as **Cryptolog International** in Paris, one of the earliest French entrants in qualified electronic signatures, time stamping, and certificate authority services under the eIDAS framework (and ANSSI's national supervision). The platform built a strong reputation for QES (Qualified Electronic Signature) workflows used by French banks, insurance carriers, and public-sector buyers; before consolidation it operated as one of the four legacy French QTSPs alongside Yousign and Docaposte. As of audit time **universign.com 301-redirects to signaturit.com**: Universign has been **consolidated into the Signaturit Group** (itself now a **Namirial Italian company**) and operates as one of four QTSPs inside the unified group. This consolidation simplifies procurement: a single contracting relationship gives buyers access to French ANSSI-attested QES via the Universign-legacy infrastructure, Spanish QTSP capabilities from the original Signaturit Solutions stack, and EBSI-prepared digital identity from the 2025-acquired Validated ID asset. The aggregate group sits inside the EU regulatory framework with Italian + Spanish + French national bars covered. Best fit: existing Universign customers retained through the consolidation; French enterprises specifically requiring ANSSI-recognised QES; multi-country EU regulated workflows (financial services, insurance, public administration) that benefit from the consolidated multi-QTSP umbrella. Pricing is enterprise / volume-based and aligned with the broader Signaturit Group catalogue; see the parent listing for category context. Universign-branded and Signaturit-branded contracting sit under the same Namirial parent, so they now share the same sovereignty profile: a US-private-equity ultimate owner (Bain Capital, since 2025) and AWS hosting at rest. Buyers who need French ANSSI-supervised QES with no US-owned infrastructure in the at-rest path should compare Yousign, and buyers who can accept a Swiss jurisdiction should compare Skribble (`cloud_act_exposure: none`). **Compliance rationale:** Universign was a long-running French Qualified Trust Service Provider (originally Cryptolog International, Paris, founded 2001). As of audit time **universign.com 301-redirects to signaturit.com** under the consolidated Signaturit Group / Namirial portfolio, with Universign now operating as one of four QTSPs inside that European trust-services group. Compliance posture inherits from the consolidated Signaturit Group and was revised at the 2026-07 re-verify: highest eIDAS QTSP qualifications, ANSSI-recognised French QES capability and regular regulator audits remain, but the Namirial parent was **acquired by Bain Capital (US private equity) in 2025** (so `eu_hq_us_funded`, not `eu_owned`), and the shared Signaturit Platform runs at rest on **Amazon Web Services** with Twilio/SendGrid (US) for OTP and email (so `cloud_act_exposure: material`, not `none`). See the Signaturit listing and `data/sub-processors/signaturit.yaml` for the mapped detail; score 3/5, same tier as Signicat. ### UpCloud: https://euvetted.com/p/upcloud - Website: https://upcloud.com - Category: Cloud & hosting - Country of incorporation: Finland - Hosting country: Finland (Helsinki) - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: paid (from €5/month) - Founded: 2011 - Certifications: ISO27001 - DPA: https://upcloud.com/global/terms-of-service/ - Last verified: 2026-05-18 Finnish performance-focused cloud (Helsinki, 2011), 14+ DCs worldwide including 9 EU regions; ISO 27001; trusted by Plausible. UpCloud is a Helsinki-headquartered Finnish cloud infrastructure provider founded in 2011 and positioned for high-performance compute workloads. The company runs two flagship data centres in Helsinki (FI-HEL1 and FI-HEL2) plus additional EU regions in Frankfurt, Amsterdam, Copenhagen, Stavanger (Norway), Warsaw, Madrid, Stockholm, and London, plus global regions in Chicago, New York, San Jose, Singapore, and Sydney. The customer base spans developer-focused workloads, SaaS, hosting resellers, and notable EU SaaS. UpCloud is one of the named sub-processors used by Plausible Analytics, for example. For procurement-grade EU buyers UpCloud's compliance posture is strong: EU-owned, EU-hosted, with no CLOUD Act exposure when EU regions are selected. The company is ISO/IEC 27001 certified, GDPR-aligned, European-owned with no published US-PE control chain, and explicitly positions itself for "European data sovereignty" with customer-elected region pinning. Finland is an EU member with full GDPR alignment, so transfers between Finnish UpCloud workloads and other EU jurisdictions need no SCCs; the Stavanger region (Norway) is EEA and similarly adequacy-clean. UpCloud's automated infrastructure stack uses MaxIOPS storage (its proprietary distributed block storage) and a 100% uptime SLA, strong reliability differentiators for SMB and mid-market customers without enterprise hyperscaler complexity. Pricing starts at roughly €5/month for the smallest virtual instance (1 vCPU, 1 GB RAM, 25 GB MaxIOPS, 1 TB transfer) on hourly or monthly billing in EUR. Best fit: developers, SaaS builders, and EU SMBs who want a Helsinki-rooted alternative to DigitalOcean or Linode with strong ISO 27001 certification and clean EU jurisdiction. The public pages returned 403 to WebFetch at audit (anti-bot fronting on upcloud.com), so the DPA and sub-processors annex URLs were not directly captured. Vendor outreach recommended before publishing the canonical URLs. **Compliance rationale:** Helsinki-headquartered Finnish cloud provider (founded 2011, European-owned with no public US-PE chain on record), ISO 27001 certified, with two flagship data centres in Helsinki (FI-HEL1, FI-HEL2) plus EU regions in Frankfurt, Amsterdam, Copenhagen, Stavanger, Warsaw, Madrid, Stockholm, and London. A customer-elected region keeps customer workloads under EU jurisdiction; EU-owned and EU-hosted with no CLOUD Act exposure when EU DCs are selected. ### Usercentrics: https://euvetted.com/p/usercentrics - Website: https://usercentrics.com - Category: Cookie consent - Country of incorporation: Germany - Hosting country: Germany (Munich) - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: freemium (from €10/month) - Founded: 2017 - Certifications: ISO27001 - DPA: https://usercentrics.com/wp-content/uploads/2024/12/Usercentrics_DPA_August-2024.pdf - Sub-processors list: https://trust.usercentrics.com/subprocessors - Last verified: 2026-05-12 Munich-based CMP (founded 2017); 2.4M sites / 8.8B monthly consents; now Vista Equity Partners-owned alongside Cookiebot. **Usercentrics GmbH** (Munich, Germany, founded 2017) consolidated the DACH cookie-consent market when it acquired **Cookiebot / Cybot** in 2022. Together the group serves 2.4M websites and 600K+ customers. The product line includes **Usercentrics Web CMP** (entry tier ~€10/mo) and **Usercentrics App CMP** for mobile. ISO 27001 certified. The 2024 acquisition by **Vista Equity Partners** (US private equity giant, $100B AUM, Austin TX) means the entire DACH cookie-consent market consolidation is now US-PE-owned at the ultimate-parent level, a structural fact procurement buyers should be aware of when this is positioned as a "European alternative to OneTrust". **Compliance rationale:** **Usercentrics GmbH** (Munich DE, founded 2017) is **ISO 27001** certified, German-operated, 2.4M websites / 8.8B monthly consents, but was **acquired by Vista Equity Partners** (US private equity) in 2024 alongside its Cookiebot subsidiary, flipping ownership_signal to `eu_hq_us_funded` with material CLOUD Act exposure via US PE control; the company now consolidates the DACH cookie-consent market under US PE. ### Userlike (Lime Connect): https://euvetted.com/p/userlike - Website: https://www.userlike.com - Category: Helpdesk - Country of incorporation: Germany - Hosting country: Germany (Cologne) - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium - Founded: 2011 - DPA: https://userlike-downloads.s3.eu-central-1.amazonaws.com/Userlike-DPA_20230505.pdf - Sub-processors list: https://connect.lime-technologies.com/en/legal/privacy-policy/ - Last verified: 2026-05-11 Cologne-based German live-chat platform (Userlike UG, founded 2011); acquired by Swedish Lime Technologies AB (Nasdaq Stockholm-listed). Userlike is a Cologne-headquartered German live-chat and customer-messaging platform founded around 2011 by **Timoor Taufig** and **David Voswinkel**, operating as Userlike UG / Lime Connect (Userlike) GmbH (Cologne, HRB 73211, Amtsgericht Köln). Historically positioned as a "made-in-Germany" alternative to Intercom and Drift with strong DACH-market traction and DSGVO-aligned engineering culture. The product surface covers live chat, AI chatbots, multi-channel inbox (WhatsApp, Facebook Messenger, Telegram), and contact-centre integrations. **Userlike is now operated by Lime Technologies AB** (the Swedish CRM group publicly listed on Nasdaq Stockholm) under the **Lime Connect** brand. The userlike.com domain 301-redirects to connect.lime-technologies.com at audit time, confirming the post-acquisition consolidation. CEO transition has occurred: as of recent reporting Pascal van Opzeeland holds the CEO role, while the original co-founders (Voswinkel previously held just under 49% of shares in April 2021, Taufig just under 44%) have presumably sold the majority of their stakes to Lime as part of the acquisition. Lime Technologies AB is widely-held on the Swedish public market (no US-PE controlling interest), which keeps the post-acquisition listing firmly `eu_owned`. Pricing is freemium with paid tiers; specific entry-tier EUR figures were not captured at audit. Best fit: German and DACH SMBs and mid-market customers needing live chat + AI chatbot with explicit German engineering heritage; existing Lime CRM customers extending into customer-messaging; procurement-grade EU buyers who want a Swedish-public-listed parent over US-VC-funded competitors. The disclosure picture has gaps post-acquisition: the underlying hosting provider for EU customer data and a named sub-processors list specific to Userlike / Lime Connect are not publicly indexed at audit time. **Compliance rationale:** Userlike (Cologne, Germany; founded ~2011 by Timoor Taufig and David Voswinkel as Userlike UG / Lime Connect (Userlike) GmbH; HRB 73211 AG Köln) is now operated by **Lime Technologies AB** (the Swedish CRM group publicly listed on Nasdaq Stockholm) under the **Lime Connect** brand (userlike.com 301-redirects to connect.lime-technologies.com). Made-in-Germany live-chat platform with AI capabilities; the post-acquisition structure gives Userlike clean EU public-listed parent ownership (Swedish Lime parent) and German engineering operations. EU-owned via the Swedish-listed Lime parent, with a public DPA on record (Userlike-DPA_20230505.pdf). Gaps: no public sub-processors list captured at audit, and the underlying hosting provider for EU customer data is not publicly disclosed post-acquisition. ### Vaultwarden: https://euvetted.com/p/vaultwarden - Website: https://github.com/dani-garcia/vaultwarden - Category: Password managers - Country of incorporation: Spain - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: free - Founded: 2018 - Last verified: 2026-05-18 AGPLv3 Rust Bitwarden-compatible server by Daniel García (Spain), self-host-only, no company, no telemetry; EU-maintained, no CLOUD Act exposure when run on EU infrastructure. Vaultwarden is an unofficial, open-source server implementation of the Bitwarden client API, written in Rust and maintained by Daniel García (GitHub: dani-garcia), a developer based in Spain, together with a community of contributors. It was formerly known as "bitwarden_rs" and was renamed to Vaultwarden to separate itself from the official Bitwarden server and avoid trademark and branding confusion. It is licensed under the **AGPL-3.0** licence, relicensed from GPLv3 specifically to close the loophole that would have allowed commercial SaaS use without contributing back. The reason Vaultwarden belongs in an EU-sovereignty directory is structural: it is **self-host-only**. There is no Vaultwarden cloud product, no Vaultwarden company, no commercial entity, no funding, no DPA, no sub-processors, and no telemetry, because there is nothing hosted to process. It is server software that a user or organisation runs themselves, fully compatible with the official Bitwarden desktop, mobile and browser clients, and deliberately lightweight so it can run on a small VPS or Raspberry Pi where the official resource-heavy Bitwarden server would be impractical. Run on EU infrastructure (Hetzner, OVHcloud, Scaleway, IONOS, STACKIT) it is EU-maintained, self-hosted, with no CLOUD Act exposure and zero vendor-counterparty risk: there is no vendor that could be acquired, change posture, or be served a US warrant. The trade-offs are the usual self-hosting ones, plus a couple specific to Vaultwarden. There is no enterprise SSO / SCIM support (a deliberate scope decision; that is where official Bitwarden's paid tiers differentiate), the operator is responsible for backups, TLS, and updates, and one of the active maintainers is employed by Bitwarden and contributes on their own time independently (reviewed by other maintainers). Vaultwarden is completely free; funding is via donations. Best fit: technically capable EU individuals, homelab users, and SMBs with IT capacity who want a Bitwarden-compatible vault under their own full control on EU infrastructure, and any procurement-grade buyer for whom "no vendor at all" is the strongest possible sovereignty answer. **Compliance rationale:** Vaultwarden is an **AGPLv3 open-source, Rust-written, Bitwarden-compatible server** maintained by Daniel García (dani-garcia), a Spanish developer, with a community of contributors, formerly 'bitwarden_rs', renamed to avoid trademark confusion; it is **self-host-only with no hosted/cloud product and no company entity**, so it has no DPA, no sub-processors, no telemetry and no business model. Run on EU infrastructure (Hetzner, OVHcloud, Scaleway) it is EU-maintained, self-hosted, with no CLOUD Act exposure and zero vendor-counterparty risk: structurally the cleanest possible posture in the password-manager category. ### Visma eAccounting: https://euvetted.com/p/visma-eaccounting - Website: https://www.visma.com - Category: Accounting - Country of incorporation: Norway - Hosting country: Norway (Oslo) - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid - Founded: 1996 - Certifications: ISO27001 - Sub-processors list: https://www.visma.com/trust-centre-products/spiris-bokforing-fakturering-lonvisma-eaccounting - Last verified: 2026-05-12 Nordic ERP + accounting group (Oslo, 1996); 170+ company portfolio, 2.4M customers, Hg-majority + TPG co-invested. **Visma Group** (Oslo, Norway, founded 1996) is the Nordic-region ERP / accounting / business-software incumbent: 170+ operating companies, 15,400 employees, 2.4 million customers across 28 countries. The flagship cloud SMB product is **Visma eAccounting** with country-specific brands (Visma Spcs in Sweden, Visma e-conomic in Denmark, Visma Mamut). Hosting is in Nordic data centres, ISO 27001 certified. Ownership history: KKR (US) acquired majority in 2010, exited in 2017 to **Hg Capital** (UK PE) who retains majority; current co-investors include **TPG** (US PE), ICG (UK), CPP Investments (Canada Pension), and Visma management. The TPG presence is the procurement-grade caveat: material US PE influence on a Norwegian operating group. **Compliance rationale:** **Visma Group** (Oslo, Norway) is the Nordic ERP / accounting incumbent (170+ companies, 15,400 employees, 2.4M customers, €19B valuation 2024), Nordic-hosted, ISO 27001; ownership is **Hg Capital majority** (UK PE) since 2017 with **TPG (US PE) and CPP (Canada Pension)** as co-investors, so US PE exposure is material via TPG even though Norwegian-operating, flipping signal to `eu_hq_us_funded`. ### Volt: https://euvetted.com/p/volt - Website: https://www.volt.io - Category: Payments - Country of incorporation: United Kingdom - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2019 - Last verified: 2026-05-11 London-based open-banking A2A real-time payments (Volt Technologies, 2019), FCA EMI, 2,500 banks across 31 territories; US-VC-led. Volt is a London-based open-banking real-time payments specialist operated by **Volt Technologies Holdings Limited** (42 Berners Street, London W1T 3ND) and founded in 2019. The product is built around Pay-by-Bank instant payments, payouts, refunds, and account verification, connecting 2,500+ banks across 31 territories on three continents and reaching 618M bank accounts. Volt holds a UK FCA **Electronic Money Institution** licence enabling standalone virtual-account products. Notable partnerships include Worldpay (global real-time-payments deal), Shopify (Volt was Shopify's first open-banking provider), Farfetch, Primer, Kinguin, Solidgate, and AsiaBill; target industries cover retail / e-commerce, travel, wealthtech, iGaming, and crypto. For an EU-sovereignty audit Volt sits in the `eu_hq_us_funded` tier. The Series B in June 2023 raised US$60M at a US$350M+ valuation led by **IVP (Institutional Venture Partners)**, a Menlo Park, California-headquartered Silicon Valley venture firm, alongside European participation from **EQT Ventures** (Sweden), **CommerzVentures** (Germany), **Augmentum Fintech** (UK), and **Fuel Ventures** (UK). The US-VC lead at Series B is the defining ownership-tier signal under our strict-ownership stance. The privacy policy names Volt Technologies Holdings Limited as data controller but does not publish a named sub-processors list, hosting provider, or explicit US-transfer mechanism on accessible public pages: gaps for procurement-grade buyers. UK post-Brexit jurisdiction with adequacy decision keeps EU-UK transfers legally clean. Pricing is enterprise / volume-negotiated; no public per-transaction tier applies. Best fit: mid-market and enterprise retailers wanting a Pay-by-Bank rail as a Stripe / Plaid alternative, particularly for high-AOV industries (travel, iGaming, crypto). Procurement-grade EU-only buyers should prefer Trustly (SE, Swedish PI licence, though also material under strict stance) or look at open-banking-native alternatives from EU-controlled providers such as Tink (acquired by Visa, US, flagged) or build on top of Adyen / Worldline (Euronext-listed EU acquirers). **Compliance rationale:** Volt Technologies Holdings Limited (London, 42 Berners Street; founded 2019) is an open-banking real-time A2A payments specialist with an FCA EMI licence, 2,500 connected banks across 31 territories and 618M bank accounts reachable, but the cap table is led by **IVP** (Institutional Venture Partners, Menlo Park, US, Series B June 2023 $60M at $350M+ valuation) alongside EQT Ventures (SE), CommerzVentures (DE), Augmentum Fintech (UK), and Fuel Ventures (UK); UK post-Brexit jurisdiction + US-VC lead results in `ownership_signal: eu_hq_us_funded`, `cloud_act_exposure: material`; no public DPA, sub-processors list, or hosting provider disclosed at audit. ### weclapp: https://euvetted.com/p/weclapp - Website: https://www.weclapp.com - Category: CRM - Country of incorporation: Germany - Hosting country: Germany (Frankfurt) - Ownership signal: eu_owned - CLOUD Act exposure: material - Pricing tier: paid (from €39/month) - Founded: 2008 - Certifications: ISO27001, ISO27018 - DPA: https://www.weclapp.com/en/wp-content/uploads/sites/5/2024/04/AV_Vertrag_DPA_Version_April-2024_DE_EN.pdf - Sub-processors list: https://www.weclapp.com/en/privacy - Last verified: 2026-05-10 German cloud ERP + CRM (weclapp SE), Frankfurt and Karlsruhe data centres, ISO 27001/27018/27701, banking-grade encryption. weclapp is a German cloud ERP + CRM platform operated by weclapp SE, a Societas Europaea legal form adopted to support international expansion, with offices in Frankfurt am Main, Marburg, Kitzingen, and Karlsruhe. Founded in 2008, the platform combines CRM, sales pipelines, quotations, invoicing, accounting, project management, and full inventory/warehouse management for SMBs and mid-market companies, with strong integrations into German marketplaces, payment providers, and shipping platforms (Amazon, eBay, Shopify, etc.). The product has won "ERP-System des Jahres" multiple times and is positioned as the first German cloud ERP with TÜV-certified data protection. For procurement-grade EU buyers the hosting story is among the strongest in this directory. Customer ERP/CRM data is stored exclusively on a Frankfurt am Main data centre with a Karlsruhe backup; both facilities carry an exceptional certification stack (ISO 9001, ISO 27001, ISO 27018, ISO 27701, ISO 22301, ISO 20000-1, PCI-DSS, CSA STAR CCM v4.0, SSAE16 / ISAE3402). No US-owned hyperscaler sits in the customer-data path. The privacy policy (last updated September 2024) names sub-processors transparently; the US-resident ones (Google, Microsoft, Intercom, Productboard, Meta, LinkedIn) are scoped to marketing-site analytics, advertising pixels, customer chat, and product roadmapping rather than customer business records, with SCCs cited under Art. 46 GDPR for any onward transfers. Brevo (FR) handles newsletters and Personio (DE) handles application data. Pricing in EUR: ERP Starter €39/user/month, ERP Services €86/user/month, ERP Trade €163/user/month, Enterprise custom for 10+ licences. A 30-day free trial requires no credit card and auto-cancels. Best fit: German and DACH SMBs and mid-market companies that need an integrated ERP + CRM with explicit German data residency, multi-ISO certifications, and broad e-commerce-marketplace integrations. The lack of an obvious public DPA URL is the primary friction for a fully procurement-grade buyer: request the AVV directly and confirm the Frankfurt / Karlsruhe DC contractual commitments before signing. **Compliance rationale:** German Societas Europaea (weclapp SE) running customer ERP/CRM data exclusively on a Frankfurt data centre with Karlsruhe backup, both certified ISO 9001/27001/27018/27701/22301/20000-1/PCI-DSS/CSA STAR/SSAE16; however, the verified sub-processor list (2026-06) shows production storage and processing run on Amazon Web Services (a US-owned hyperscaler) via its operations partner Exact Cloud Development Benelux, with Microsoft, Splunk, Akamai, ServiceNow and Secureworks (all US) for monitoring and security, so CLOUD Act exposure is material despite the EU data region; a public DPA URL was not resolvable at audit. (An earlier assessment understated the US footprint as marketing-site-only; the dedicated sub-processor page shows AWS as the production host.) **Sub-processors mapped:** 15 total, 9 US-owned - Akamai Technologies Netherlands B.V. (Netherlands): DDoS and cyber-attack protection (via Exact) [US-owned] - Amazon Web Services EMEA SARL (Luxembourg): Production storage and processing (via Exact; data in Frankfurt) [US-owned] - DigitalOcean LLC (United States): Hosting for weclapp webpages and knowledge base [US-owned] - Intercom R&D Unlimited Company (Ireland): Product tours, surveys and chat for customer communications [US-owned] - Microsoft B.V. (Netherlands): Microsoft Defender status monitoring (via Exact) [US-owned] - Microsoft Ireland Operations Ltd. (Ireland): Storage/processing of mail, files, SharePoint, Teams (via Exact) [US-owned] - Secureworks Inc. (United States): 24/7 Security Operations Center (via Exact) [US-owned] - ServiceNow Nederland B.V. (Netherlands): IT process/service management and monitoring (via Exact) [US-owned] - Splunk Inc. (United States): Monitoring AWS cloud infrastructure (via Exact) [US-owned] - CLOUDIWAY SASU (France): Migration of mail, files, SharePoint, Teams (via Exact) - DevOn India-NL B.V. (Netherlands): Migration/operation support with onward sub-processing in India (via Exact) - Exact Cloud Development Benelux B.V. (Netherlands): Service configuration, security monitoring, performance tracking - Exact Group B.V. (Netherlands): Support services to operate the MS Office suite - fiskaly Germany GmbH (Germany): Fiscalisation solution for KassenSichV - Product Fruits s.r.o. (Czechia): Product tours, surveys and in-app support ### Whereby: https://euvetted.com/p/whereby - Website: https://whereby.com - Category: Video conferencing - Country of incorporation: Norway - Hosting country: Ireland - Ownership signal: other - CLOUD Act exposure: minor - Pricing tier: freemium - Founded: 2013 - Certifications: ISO27001 - DPA: https://whereby.com/information/dpa/ - Sub-processors list: https://whereby.com/information/dpa/ - Last verified: 2026-05-11 Norwegian browser-based WebRTC video (ex-appear.in, Videonor-owned), no-install meetings + Embedded SDK; ISO 27001 + GDPR + HIPAA. Whereby is a Norwegian browser-based video-meeting platform originally launched as **appear.in** in 2013 as a summer-intern project inside the Norwegian telecom group **Telenor**. The product grew a strong user base internationally before being spun out and acquired by **Videonor** (a Norwegian holding entity) with the brand renamed to Whereby. The core proposition is unusual in the video-conferencing category: no installs, no accounts for meeting attendees, just a URL that opens in any modern browser via WebRTC. The product surface is two-tier: **Whereby Meetings** for individuals and teams (consumer + business plans), and **Whereby Embedded**, an API/SDK that lets product builders embed Whereby's WebRTC video into their own applications, competing directly with Twilio Video, Daily, Agora, and Zoom SDK. Compliance posture is solid for a consumer-friendly video tool: **ISO/IEC 27001 certified**, GDPR-compliant by design, HIPAA-compliant for US-healthcare customers, and a privacy-first product philosophy carried over from the Telenor engineering culture. The legal entity sits in Norway (EEA member, EU adequacy decision under Art. 45 GDPR, SCC-free for EU↔NO transfers). The underlying infrastructure is not publicly named at audit but, given Telenor's well-documented AWS sovereign-cloud partnership (Telenor's Skygard data centre in Oslo runs AWS sovereign-by-design technology), the most-likely scenario is AWS Stockholm or similar EU-region, which keeps the CLOUD Act flag at `minor` rather than `none` under the directory's strict-ownership stance. Pricing is freemium with a long history of generous free tiers (free unlimited 1-on-1, free group meetings up to 45 minutes); paid plans add custom rooms, branding, longer meetings, advanced controls, recording, and analytics. Embedded pricing is usage-based per video-minute. Best fit: agencies and consultancies needing easy no-install client video calls, educational and healthcare workflows that benefit from no-account meetings, developers building video into their own products via Embedded, and Norwegian / Nordic / European buyers who specifically want a Norwegian-rooted EU-friendly alternative to Zoom and Google Meet. **Compliance rationale:** Whereby (originally **appear.in**, spun out of Norwegian telecom Telenor as a summer intern project and now owned by **Videonor**, a Norwegian entity) is a browser-based WebRTC video-calling platform without installs or accounts at the meeting-attendee level; ISO 27001 certified, GDPR and HIPAA compliant, sold as both consumer-style Whereby Meetings and Whereby Embedded (API/SDK for product builders). Norway holds an EU adequacy decision (SCC-free EU↔NO transfers). CLOUD Act flag held at `minor` reflecting the likely AWS-EU backend (Telenor itself has expanded sovereign-cloud partnerships with AWS) and the absence of explicit hosting-provider disclosure at audit: EU-adequate jurisdiction, ISO 27001 certified, public DPA, but hosting provider not publicly disclosed and no confirmed EU ownership. ### Wide Angle Analytics: https://euvetted.com/p/wide-angle-analytics - Website: https://wideangle.co - Category: Web analytics - Country of incorporation: Germany - Hosting country: France - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid (from €10/month) - Founded: 2017 - Last verified: 2026-05-10 Berlin-based privacy-first web analytics on a European (OVHcloud Open Trusted Cloud) stack with strict GDPR posture. Wide Angle Analytics is a Berlin-based privacy-first web analytics product operated by Input Objects GmbH and trading under the registered EU trademark "WIDE ANGLE ANALYTICS" (application number 018569000). The company markets itself unambiguously as "Web Analytics made and hosted in the European Union," with all data stored on a European cloud and German privacy standards applied throughout. The product is referenced in OVHcloud's Open Trusted Cloud catalogue, which is a strong signal that the underlying infrastructure runs on OVH (the French sovereign-cloud provider) although the vendor's own pages do not name the provider explicitly at audit time. Compliance positioning is rigorous: automatic IP anonymisation, no third-party data sharing, no use of US-owned hyperscalers for customer analytics data at rest, and a GDPR-by-default product configuration. The footer of wideangle.co links explicitly to Privacy Policy, Terms and Conditions, Cookie Policy, Security Policy, Data Processing Agreement (DPA), and an Imprint, but most of those URLs did not resolve at audit time on the paths we tested (/privacy, /dpa, /security, /imprint, /privacy-policy, /legal/imprint all 404). The DPA exists per the footer label (which we trust as a vendor attestation) but a procurement-grade buyer should request the live path before signing. Pricing is multi-currency and EU-aware: $15/€10/£10 per month for the Starter plan covering 10 websites, 50K events/month, single user, and 12 months of data retention; a 14-day free trial is offered (no permanent free tier). Best fit: small and mid-market German-speaking and EU-wide buyers who want a Plausible-style alternative on French sovereign cloud and don't mind that the DPA needs to be requested rather than self-served at the listed URLs. Buyers who need a unified, downloadable DPA + sub-processors annex out of the box should prefer Plausible or Pirsch in the same category. **Compliance rationale:** Berlin-based GmbH (Input Objects) running customer analytics entirely on a European cloud (listed in the OVHcloud Open Trusted Cloud catalogue, which strongly implies OVH-hosted EU-only infrastructure) with German privacy standards and a homepage footer link labelled "Data Processing Agreement"; EU-owned and EU-hosted with no US-owned cloud on the customer-data path, but the DPA is not self-servable (the /policy/dpa page carries no live document and contacting support is required to obtain one). ### Wiki.js: https://euvetted.com/p/wiki-js - Website: https://js.wiki - Category: Docs & wikis - Country of incorporation: Canada - Ownership signal: other - CLOUD Act exposure: none - Pricing tier: free (from €0/month) - Founded: 2016 - Last verified: 2026-05-11 AGPLv3 open-source Node.js wiki by Nicolas Giard (Canada, 2016); 100M+ downloads; multiple DB backends; 40+ languages; self-host only. Wiki.js is an AGPLv3-licensed open-source wiki and documentation platform created by **Nicolas Giard**, a Montréal-based senior software developer (currently at IETF Administration LLC), and first released in 2016. The codebase is written in JavaScript on Node.js with a modern UI, fast performance, and a modular architecture that supports multiple database backends (PostgreSQL, MySQL, MariaDB, MS SQL Server, SQLite), multiple storage backends (Git sync, AWS S3, Azure Blob, Google Cloud Storage, local/network), multiple authentication options (local, LDAP, SAML, Azure AD, social OAuth), and multiple search providers (built-in DB search, Algolia, Azure Search, Elasticsearch). The project reports more than **100M downloads** and 28k+ GitHub stars; supported by sponsors including DigitalOcean, GitHub, Cloudflare, and Netlify. For procurement-grade EU buyers Wiki.js is structurally clean for the self-host path. The licence is full AGPLv3 with the standard copyleft requirements (any network-distributed modification must publish source under AGPL) so it suits in-house documentation use cases without complications. Self-host on EU infrastructure (Hetzner, OVHcloud, Scaleway, IONOS, STACKIT, T Cloud Public, or any other EU-incorporated host) delivers no CLOUD Act exposure and no vendor counterparty. The maintainer is Canadian; Canada holds an EU adequacy decision under Art. 45 GDPR so cross-border transfers between EU and Canada need no SCCs, but for self-host deployments the maintainer-jurisdiction is irrelevant since the customer controls all data flows. Pricing is free for the open-source codebase; commercial support is offered via the maintainer + community. Best fit: developer teams and engineering organisations building internal documentation, EU SMBs and public-sector buyers wanting a Node.js modern stack alternative to MediaWiki / DokuWiki, customers who need Git-versioned content with full self-host control, and any organisation that prefers Node.js to PHP (vs BookStack which is PHP/Laravel-based). **Compliance rationale:** Wiki.js is an **AGPLv3 open-source Node.js wiki** created by **Nicolas Giard** (Montréal, Canada, senior software developer at IETF Administration LLC) in 2016 and led primarily by him through community contributions. 100M+ downloads, 28k+ GitHub stars, 40+ UI languages, no managed cloud, pure self-host on customer-chosen infrastructure. Canada holds EU adequacy decision under Art. 45 GDPR. When deployed on EU infrastructure (Hetzner, OVHcloud, Scaleway, IONOS, STACKIT) there is no CLOUD Act exposure, no vendor counterparty, no commercial entity, and no cap-table risk. ### Wimi: https://euvetted.com/p/wimi - Website: https://www.wimi-teamwork.com - Category: File sharing - Country of incorporation: France - Hosting country: France - Ownership signal: eu_owned - CLOUD Act exposure: none - Pricing tier: freemium (from €3/month) - Founded: 2010 - Certifications: ISO27001, HDS - Last verified: 2026-06-15 French sovereign teamwork suite with built-in Wimi Drive storage, hosted in France with no data leaving the EU. Wimi is a French collaborative suite that bundles project workspaces, team messaging, calendars and document management. Its file component, Wimi Drive, turns the suite into a Dropbox/Google Drive/OneDrive alternative: it syncs workspace documents to Windows and macOS desktops, supports file and folder versioning, shareable internal and external links with edit or view-only rights, and uploads of up to 2 GB per file. The free plan covers up to three users with 10 GB of storage; paid Workplace plans start at €3 per user/month (25 GB) and scale to 100 GB on Pro, while the Enterprise tier adds SSO, API access and unlimited storage. Mobile apps cover iOS and Android alongside the web client. Wimi's positioning rests on digital sovereignty: the publisher, Cloud Solutions SAS (Paris), operates its own ISO 27001-certified datacenters in France (Île-de-France and Hauts-de-France) rather than renting US hyperscaler capacity, and states that customer data, metadata and backups never leave the European Union. It is ISO 27001:2022 certified and markets HDS compliance for health-data hosting, with SecNumCloud qualification publicly stated as in progress rather than obtained. For buyers who want a French-hosted, EU-controlled storage and collaboration base, Wimi is a strong sovereign option, with the caveat that storage is one module of a broader teamwork product rather than a pure file-sync tool. **Compliance rationale:** French-owned vendor running its own ISO 27001-certified datacenters in France with data, metadata and backups kept inside the EU and no US cloud dependency, giving near-zero CLOUD Act exposure. ### Wire: https://euvetted.com/p/wire - Website: https://wire.com - Category: Video conferencing - Country of incorporation: Switzerland - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: paid - Founded: 2012 - DPA: https://wire.com/en/data-processing-addendum - Sub-processors list: https://wire.com/en/data-processing-addendum - Last verified: 2026-05-18 Swiss-headquartered enterprise messaging + video (Wire Swiss GmbH, Zug + Berlin), MLS E2EE, VS-NfD-ready, 90%+ European institutional ownership. Wire is a secure enterprise messaging, calls, and collaboration platform operated by **Wire Swiss GmbH**, headquartered in Zug, Switzerland, with its main development centre in Berlin, Germany. The company was founded in Fall 2012 by **Jonathan Christensen, Alan Duric, and Priidu Zilmer** (engineers who had previously worked at Skype and Microsoft) and is backed by Skype co-founder **Janus Friis**. The current CEO since January 2024 is **Benjamin Schilz**; the advisory board includes Schilz, Diana Meyel (Cipio Partners), Janus Friis, and notably **Rolf Schumann of Schwarz Gruppe** (the German private retail giant that also operates STACKIT), a direct tie between the Wire / Schwarz sovereign-tech ecosystems. The product surface covers instant messaging, voice + video calls, file sharing (Wire Drive), document collaboration, and an enterprise admin console. For procurement-grade EU buyers Wire's ownership architecture is unusually clean: **Wire Group Holdings GmbH is majority-owned by European institutional investors who collectively hold more than 90% of the company**: no US PE or US VC majority anywhere in the cap table. The Zug Switzerland legal entity benefits from CH's EU adequacy decision (Art. 45 GDPR) for SCC-free EU-CH transfers, and customer data is hosted inside the EU. Security architecture is built on **MLS (Messaging Layer Security)**, the IETF-standardised end-to-end encryption protocol, with zero-knowledge keys so Wire itself cannot read customer messages. Wire is **VS-NfD ready** (the German "Verschlusssache: Nur für den Dienstgebrauch" classified-communications standard for restricted government information) and **NIS 2 compliant**. Customer base reflects the security posture: the **German Federal Office for Information Security (BSI)** is a public reference, alongside the **US Air Force** and 1,800+ total organisations covering governments, public authorities, law enforcement, and regulated industries. Wire offers an on-premise deployment option for customers needing fully-controlled infrastructure, plus a managed Wire Cloud. Pricing is enterprise / sales-engaged; specific entry-tier figures not captured at audit. Best fit: governments and defence ministries (especially DACH where VS-NfD readiness is the procurement key), regulated financial services, law-enforcement agencies, and any organisation that wants MLS-based E2EE messaging from a vendor structurally independent of US capital. **Compliance rationale:** Wire Swiss GmbH (HQ Zug, Switzerland, with main development centre in Berlin) was founded Fall 2012 by Jonathan Christensen, Alan Duric, and Priidu Zilmer (Skype/Microsoft alumni; backed by Skype co-founder Janus Friis); **Wire Group Holdings GmbH is majority-owned by European institutional investors, who collectively hold over 90% of the company**, with the advisory board including Rolf Schumann of Schwarz Gruppe (Lidl / STACKIT parent), Diana Meyel of Cipio Partners, Janus Friis, and CEO Benjamin Schilz. End-to-end **MLS encryption** by default with zero-knowledge architecture, hosted inside the EU, **VS-NfD ready** (German classified-communications standard), NIS 2 compliant, customer list includes the **German Bundesamt für Sicherheit in der Informationstechnik (BSI)** plus US Air Force, 1,800+ total. EU-hosted with 90%+ European institutional ownership, but **material CLOUD Act exposure** on the business-operations path: core hosting runs on AWS (US hyperscaler) and US-incorporated sub-processors handle CRM and support (Hubspot, Salesforce, Zendesk). MLS end-to-end encryption keeps message *content* private even from those processors, but customer metadata and CRM records sit with US-jurisdiction vendors, so the messaging is sovereign while the surrounding operations are not. Public DPA with disclosed sub-processors, and VS-NfD government-grade certification for the encrypted messaging layer. **Sub-processors mapped:** 10 total, 7 US-owned - Amazon Web Services EMEA SARL (Luxembourg): Hosting [US-owned] - Box, Inc. (United Kingdom): Signature management [US-owned] - Google Cloud EMEA Limited (Ireland): Email provider [US-owned] - Hubspot Inc. (United States): Website hosting, marketing, CRM [US-owned] - Salesforce, Inc. (United States): CRM services [US-owned] - Stripe Payments Europe, Limited (Ireland): Payment services (with USA transfer via SCCs) [US-owned] - Zendesk, Inc. (United States): Customer support [US-owned] - ContractHero GmbH (Germany): Contract management - Countly Ltd. (United Kingdom): Product analytics - Wire Germany GmbH (Germany): Development of services ### Workbooks: https://euvetted.com/p/workbooks - Website: https://www.workbooks.com - Category: CRM - Country of incorporation: United Kingdom - Hosting country: United Kingdom - Ownership signal: other - CLOUD Act exposure: material - Pricing tier: paid (from €26/month) - Founded: 2007 - DPA: https://www.workbooks.com/wp-content/uploads/msa_us.pdf - Sub-processors list: https://www.workbooks.com/wp-content/uploads/sub-processors-policy.pdf - Last verified: 2026-05-11 Reading-based UK mid-market CRM, BGF-funded, multi-currency pricing in GBP/EUR/USD; post-Brexit jurisdiction with US sales office. Workbooks is a Reading-headquartered UK CRM positioned for mid-market businesses, operated from Unit 9, Suttons Business Park, Reading RG6 1AZ. The product covers contact management, opportunity management, quotations, ticketing, marketing automation, sales forecasting, sales order processing, accounting integration, project management, and AI-enabled CRM features. The company differentiates with a transparent "no-BS" pricing posture and three implementation tracks: SelfStart (self-guided), JumpStart (28-day), and Shared Success (collaborative workshops), and reports an average customer retention rate of over ten years. Workbooks has been rated #1 CRM software for midsize businesses by TechRadar Pro in 2024 and is recognized as a High Performer by G2 across US, UK, and EMEA. Total funding raised is approximately US$30.6M, primarily from BGF (Business Growth Fund), a UK investor. For an EU-sovereignty audit the listing is partial: Workbooks operates from the UK (post-Brexit, "other" ownership tier under our rubric) and has a US sales office in Massachusetts; multi-currency pricing in GBP, EUR, and USD signals an Atlantic customer base. The DPA, sub-processors, and security pages did not resolve at audit (404 on /privacy, /security, and /dpa standard paths), and the underlying hosting provider for customer CRM data is not disclosed on accessible public pages. At mid-market CRM scale the industry-default infrastructure is AWS, which would translate to material CLOUD Act exposure under our strict-ownership stance, but this needs vendor confirmation. Pricing is multi-currency and EU-aware: CRM Edition £32 / €26 / US$ per user/month with 100GB storage and standard support; Business Edition £67 / ~€55 PUPM adds order/invoice management and accounting integration; a "Try for free" offer is advertised on the homepage with limits not fully detailed. Best fit: UK and EU mid-market sales teams who want a long-running British vendor with deep customer-success investment and don't need an EU-only ownership chain. Strict-CLOUD-Act EU buyers should request the DPA, hosting region, and a written commitment on cross-Atlantic data transfers before signing. **Compliance rationale:** Reading-based UK mid-market CRM (Workbooks Online Limited, BGF-funded) with a US sales office in Massachusetts, multi-currency pricing in GBP/EUR/USD, and TechRadar #1 mid-market ranking, but DPA, sub-processors, and security URLs did not resolve at audit, and the underlying hosting provider is not publicly disclosed; UK post-Brexit jurisdiction, a US sales presence, and unverified hosting (likely AWS at this scale) together produce material CLOUD Act exposure. ### Worldline: https://euvetted.com/p/worldline - Website: https://worldline.com - Category: Payments - Country of incorporation: France - Hosting country: France (Paris) - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: paid - Founded: 2014 - Certifications: ISO27001 - DPA: https://worldline.com/content/dam/worldline/local/en-gb/documents/merchant-services-uk/110113702-tc-data-processing-terms-for-online-payments-gateway-gbr-en-240327-2.pdf - Sub-processors list: https://support.legacy.worldline-solutions.com/en/security/service-description/list-of-subcontractors-iecs - Last verified: 2026-05-11 French payment giant (Worldline SA, Paris-listed WLN), #4 PSP worldwide, 18k employees, free-float >90% with no controlling shareholder. Worldline is the largest French and one of the largest European payment-services providers, operated by **Worldline SA** at Tour Voltaire, 1 Place des Degrés, 92059 Paris la Défense Cedex. Founded in 2014 as a carve-out from Atos and trading as **WLN on Euronext Paris**, the company became fully independent of Atos in 2022 when the latter completed the sale of its remaining stake; as of 2026 the free-float exceeds 90% with no single controlling shareholder and a mix of long-only / value / passive institutional investors. The product spans in-store, online, and omnichannel payment acceptance plus an issuing-and-acquiring stack for banks, cross-border services, open-banking infrastructure, and digital-currency rails, serving 1.4M+ merchant clients across 170+ countries with ~18,000 employees and a #4 global PSP ranking by volume. Compliance posture is exceptional and oriented to regulated industries and public-sector procurement. Worldline carries ISO 9001:2015 (quality management), ISO 14001:2015 (environmental), **ISO/IEC 27001:2022** (information security), ISO 22301:2019 (business continuity), **ISAE 3402** and **ISAE 3000** assurance reports (the audit framework used by financial-services suppliers globally), and **PCI-DSS** at the highest tier. National-grade certifications across many of its 170+ operating countries are also in place. The corporate compliance page makes the regulated-supplier story explicit; recent activity (May 2026) includes the finalisation of the Electronic Data Management divestment to SIX (Swiss financial-markets infrastructure) and a March 2026 rights issue, both signs of an active restructuring posture under the post-Atos independent governance. Pricing is enterprise-grade and negotiated; no consumer-grade pricing page applies. Worldline sells through its Merchant Services, Financial Services, and Mobility & e-Transactional Services divisions and is the recommended choice for EU public-sector procurement, banks, retailers operating across multiple EU markets, and any organisation needing a Euronext-listed, fully-independent French alternative to US PSPs. Together with Adyen (NL), Worldline rounds out the directory's two-pillar EU public-listed-PSP shortlist; Mollie (NL) sits below them as the SMB / DNB-licensed e-money option. **Compliance rationale:** **Worldline SA** (Paris la Défense, French SA carved out of Atos in 2014 and fully independent since 2022 when Atos divested its remaining stake) is publicly listed on Euronext Paris (WLN) with `ownership_signal: eu_owned` (**free-float exceeding 90% and no single controlling shareholder**), the world's #4 payment-services provider with 1.4M+ merchant clients across 170+ countries, 18,000 employees, and a deep certification stack (ISO 9001 + 14001 + 22301 + **27001:2022** + ISAE 3402 + ISAE 3000 + PCI-DSS); strong EU-controlled posture with only the unavoidable global card-scheme sub-processors keeping `cloud_act_exposure: minor`. ### YetiForce: https://euvetted.com/p/yetiforce - Website: https://yetiforce.com - Category: Project management - Country of incorporation: Poland - Ownership signal: eu_owned - CLOUD Act exposure: minor - Pricing tier: freemium - Sub-processors list: https://www.yetiforce.com/en/privacy-policy - Last verified: 2026-05-18 Polish open-source CRM + PM (YetiForce, Warsaw, Stohid Technology S.A.), 23k+ deployments, 35+ languages, self-host first. YetiForce is the open-source CRM + project management + business-automation platform built by **Stohid Technology S.A.** (Al. Jana Pawła II 22, 00-133 Warsaw, Poland; KRS 0000940956; NIP 118-000-24-25; REGON 008163492). The product is positioned as a Salesforce / Microsoft Dynamics / SugarCRM alternative for SMBs and mid-market, with modules covering CRM, accounting, project management, HR, marketing, support, document management, and inventory. YetiForce reports **23,000+ deployments across 100+ countries** with localisation in **35+ languages**, a remarkably broad community for an EU-rooted open-source product. The licensing model is open-source-first: the YetiForce CRM codebase is described as "open software without restrictions" with the full server-side stack available for self-hosted deployment on the customer's own infrastructure (Hetzner / OVHcloud / Scaleway / private DC). Commercial revenue comes from the **YetiForce Cloud** managed offering, marketplace add-ons (paid modules), and support packages. For procurement-grade EU buyers, self-hosting on EU infrastructure makes the customer the sole data controller with no CLOUD Act exposure. The managed cloud tier carries a minor CLOUD Act flag pending publicly-disclosed hosting region. Best fit: Polish, CEE, and broader EU SMBs and mid-market companies that want an open-source Salesforce alternative with deep customisation and broad language coverage; particularly strong for self-host-friendly engineering teams and customers who already use Polish-software-stack components. **Compliance rationale:** **Stohid Technology S.A.** (Warsaw, Al. Jana Pawła II 22; KRS 0000940956; NIP 118-000-24-25) operates **YetiForce** as a fully open-source CRM + project management + business-automation platform with 23,000+ deployments across 100+ countries and 35+ languages; the codebase is open without licence restrictions, the recommended deployment is self-host on customer infrastructure, and a managed YetiForce Cloud + marketplace add-ons provide commercial revenue; EU-owned, with the self-hosted deployment giving the customer full data control and no CLOUD Act exposure on EU infrastructure. ### Yousign: https://euvetted.com/p/yousign - Website: https://yousign.com - Category: E-signature - Country of incorporation: France - Hosting country: France (Caen) - Ownership signal: eu_hq_us_funded - CLOUD Act exposure: minor - Pricing tier: paid - Founded: 2013 - DPA: https://yousign.com/data-processing - Sub-processors list: https://yousign.com/subprocessors - Last verified: 2026-05-11 Caen/Paris-based French QTSP (eIDAS-qualified, ANSSI-supervised), B Corp, profitable, 30k+ customers; rebranding to Youtrust in 2026. Yousign is a Caen- and Paris-headquartered French digital-trust platform founded in 2013 and **rebranding in 2026 to Youtrust** as part of a broader expansion into eIDAS 2.0 workflows. The company is a **Qualified Trust Service Provider (QTSP)** on the European Commission's Trust List for France: fully eIDAS-qualified across the three signature levels (Simple Electronic Signature, Advanced Electronic Signature, Qualified Electronic Signature) and supervised under the French ANSSI regulatory framework with the "Trusted Third Party" designation. The product is enriched by identity verification, document verification, electronic seals, and all-in-one compliance workflows for KYC / KYB / AML / CFT, targeting finance, real estate, insurance, healthcare, and B2B verticals. Operating scale: 30,000+ corporate customers, 50M+ documents processed annually, **€40M+ ARR, profitable since end of 2025**, presence in France, Italy, Spain, Germany, Austria, UK, and **B Corp certified** (the certification for companies that meet high standards of social + environmental performance, public transparency, and legal accountability). The B Corp posture is unusual in the EU digital-trust segment and is itself a positive procurement signal for buyers who weight ESG alongside sovereignty. Cap-table caveat: in June 2021, Yousign raised a US$36.6M (€30M) Series A led by **Lead Edge Capital** (a New York-based growth-equity firm) alongside French eFounders (Hexa) as returning investor. The current ownership mix after subsequent dilution and Yousign's path to profitability has not been publicly disclosed at audit time; the listing sits at `eu_hq_us_funded` (EU-headquartered but with a documented US-VC lead investor on record) with the **ANSSI-QTSP regulatory anchor + profitability + B Corp** as positive signals that partially offset the unconfirmed ownership picture. Best fit: French and EU regulated industries (banks, insurers, real-estate, healthcare) that need QES under ANSSI-supervised eIDAS infrastructure with API integration and complete identity-verification workflows. Direct competitors in this category: Signaturit / Namirial Group (Spanish-Italian, but US-private-equity-owned since Bain Capital's 2025 acquisition and hosted at rest on AWS, so `cloud_act_exposure: material`), Skribble (Swiss + dual ZertES/eIDAS, no CLOUD Act exposure). **Compliance rationale:** Yousign (Caen + Paris, France; founded 2013; rebranding to **Youtrust in 2026**) is a **Qualified Trust Service Provider (QTSP)** on the European Commission's Trust List for France: fully eIDAS-qualified across Simple / Advanced / Qualified signature levels, ANSSI-supervised under the French regulatory framework, and **B Corp certified**. The company is profitable since end of 2025 with €40M+ ARR, 30,000+ corporate customers, and 50M+ documents/year. Cap-table caveat: the 2021 Series A of US$36.6M (€30M) was led by **Lead Edge Capital** (a New-York-based US growth-equity firm) alongside French eFounders; current ownership mix not disclosed at audit, so the listing sits at `eu_hq_us_funded` (EU-headquartered with a documented US-VC lead investor), reflecting strong ANSSI-QTSP regulatory anchor, profitability, and EU public benefit (B Corp), but without confirmed full EU ownership. ## Alternatives to US tools (131 comparison pages) ### European alternatives to 1Password: https://euvetted.com/alternatives/1password _About 1Password:_ Canadian-founded password manager, AgileBits Inc., now US-headquartered (Toronto + SF). Passbolt (Luxembourg, Belvaux), Proton Pass (Switzerland, Geneva), and Psono (Germany) are the strongest European alternatives to 1Password on EU Vetted's editorial assessment. All three are EU- or Swiss-owned and hosted and ship end-to-end encryption by default (CLOUD Act exposure, Passbolt: [[passbolt.cloud_act]], Proton Pass: [[proton-pass.cloud_act]], Psono: [[psono.cloud_act]]). For team password sharing with open-source auditability, Passbolt is the top pick. For individuals already in the Proton ecosystem, Proton Pass is the smoothest switch. Verified European alternatives (11): - [heylogin](https://euvetted.com/p/heylogin): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [KeePassXC](https://euvetted.com/p/keepassxc): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [LC-Pass](https://euvetted.com/p/lc-pass): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [NordPass](https://euvetted.com/p/nordpass): hosted in Lithuania, CLOUD Act: material, ownership: eu_owned - [Padloc](https://euvetted.com/p/padloc): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Passbolt](https://euvetted.com/p/passbolt): hosted in Luxembourg, CLOUD Act: none, ownership: eu_owned - [pCloud Pass](https://euvetted.com/p/pcloud-pass): hosted in Luxembourg, CLOUD Act: minor, ownership: other - [Proton Pass](https://euvetted.com/p/proton-pass): hosted in Switzerland, CLOUD Act: none, ownership: other - [Psono](https://euvetted.com/p/psono): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Uniqkey](https://euvetted.com/p/uniqkey): hosted in Denmark, CLOUD Act: none, ownership: eu_owned - [Vaultwarden](https://euvetted.com/p/vaultwarden): hosted in Spain, CLOUD Act: none, ownership: eu_owned **Q: Is 1Password usable under GDPR?** 1Password (AgileBits, Inc.) publishes a Data Processing Addendum based on the EU Standard Contractual Clauses with post-Schrems II supplementary measures, and offers EU data residency on Business and Enterprise tiers. The service is legally usable from the EU and uses end-to-end encryption with the Secret Key model, which means the vendor cannot decrypt vault contents even when served with a legal order. Corporate ownership, not the cryptography, is what keeps European procurement teams evaluating alternatives: AgileBits was Canadian-founded but is now operationally US-headquartered (Toronto + San Francisco) with US sub-processors and investors. For organisations with strict EU-vendor-preference policies, the alternative search is procurement-policy-driven rather than technical-cryptography-driven. **Q: Which 1Password alternative has the strongest compliance profile?** Among the alternatives mapped on this page, three have the strongest compliance signal mix: Passbolt (Luxembourg, Belvaux), Proton Pass (Switzerland, Geneva), and Psono (Germany). All three are EU- or Swiss-owned and hosted and ship with end-to-end encryption as the default (CLOUD Act exposure, Passbolt: [[passbolt.cloud_act]], Proton Pass: [[proton-pass.cloud_act]], Psono: [[psono.cloud_act]]). pCloud Pass (Switzerland) is EU-hosted with end-to-end encryption (CLOUD Act exposure: [[pcloud-pass.cloud_act]] via its sub-processor chain). For team password management specifically, Passbolt is the open-source-friendly pick; for individual-and-family use, Proton Pass is the strongest privacy-flavoured option. **Q: Can I migrate my 1Password vault?** Yes. 1Password supports export in 1pif (1Password Interchange Format) and CSV formats via *1Password app → File → Export → All Items*. Most European alternatives accept CSV import directly; Passbolt and Proton Pass have guided 1Password-import flows. What does not transfer cleanly: 1Password's specific item types (SSH keys with platform-native integration, Watchtower vulnerability warnings, Travel Mode settings). These are rebuilt as native features in the new tool where available. **Q: Does any European alternative match 1Password's autofill and browser experience?** Proton Pass and Psono have well-polished browser extensions with autofill that approach 1Password's UX. Passbolt is team-collaboration-focused with a different mental model (shared organisational vaults rather than personal-plus-shared). For individual use cases optimising for daily autofill UX, Proton Pass is the smoothest switch. For team password sharing in regulated industries, Passbolt is the more procurement-friendly pick. **Q: What about SSO and SCIM provisioning?** Passbolt and Psono both support SSO (SAML 2.0 / OIDC) and SCIM provisioning on their Enterprise tiers, comparable to 1Password Business. Proton Pass enterprise SSO is on the roadmap but less mature today. For organisations where SSO + SCIM are non-negotiable on the contract, Passbolt is the strongest current European option. **Q: Does 1Password fall under the US CLOUD Act?** In practice, yes. AgileBits, Inc. is operationally US-headquartered (Toronto and San Francisco), and the consolidated corporate structure falls within the reach of the US CLOUD Act, which can compel a US company to produce data it controls regardless of where that data is stored. Critically, 1Password's zero-knowledge cryptographic model means the vendor cannot decrypt vault contents. The CLOUD Act exposure is structural/jurisdictional, not a cryptographic weakness. The top-rated alternatives on this page are EU- or Swiss-owned and hosted, with no US parent (CLOUD Act exposure, Passbolt: [[passbolt.cloud_act]], Proton Pass: [[proton-pass.cloud_act]], Psono: [[psono.cloud_act]]). That is a statement about where the company sits, not a claim that AgileBits has received or acted on any particular data request. **Q: What is the cheapest European alternative to 1Password?** Proton Pass (Switzerland) offers a free individual tier and a paid plan bundled with Proton Mail, Calendar, Drive, and VPN starting at around €4/month, making it the most accessible-priced option among the European alternatives mapped here. Psono has a free community edition for self-hosting. Passbolt has a free open-source Community Edition self-hostable at zero licensing cost; the cloud-managed Team tier is paid. Exact pricing changes; check each vendor's current pricing page before deciding. **Q: Is there a GDPR-compliant alternative to 1Password?** All four European alternatives mapped on this page (Passbolt, Proton Pass, Psono, and pCloud Pass) are GDPR-compliant by design: EU or Swiss data residency, end-to-end encryption so the vendor cannot access vault contents, and published DPAs. Passbolt, Proton Pass, and Psono are additionally EU- or Swiss-owned with no US parent (CLOUD Act exposure, Passbolt: [[passbolt.cloud_act]], Proton Pass: [[proton-pass.cloud_act]], Psono: [[psono.cloud_act]]), corporate ownership being the criterion EU procurement teams typically apply beyond baseline GDPR compliance. **Q: Can a European password manager handle SSH keys and developer secrets?** Passbolt is the strongest European option for developer-focused secrets management: it has a CLI, an API, and a Secrets Manager product aimed at machine-to-machine credential flows and CI/CD pipelines. Psono also has a CLI and supports TOTP/SSH key storage. Proton Pass added SSH key support in 2024 but the developer tooling is less mature than Passbolt's. For teams using 1Password Secrets Automation or the 1Password CLI, Passbolt's Secrets Manager is the closest European equivalent today. ### European alternatives to Acuity Scheduling: https://euvetted.com/alternatives/acuity-scheduling _About Acuity Scheduling:_ Squarespace-owned scheduling, US-incorporated. Verified European alternatives (5): - [Cal.com](https://euvetted.com/p/cal-com): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Cronofy](https://euvetted.com/p/cronofy): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Doodle](https://euvetted.com/p/doodle): hosted in Germany, CLOUD Act: minor, ownership: other - [Reservio](https://euvetted.com/p/reservio): hosted in Czechia, CLOUD Act: minor, ownership: eu_owned - [SuperSaaS](https://euvetted.com/p/supersaas): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned ### European alternatives to Adobe Sign: https://euvetted.com/alternatives/adobe-sign _About Adobe Sign:_ Adobe-owned e-signature, part of Document Cloud. Direct CLOUD Act exposure. Verified European alternatives (7): - [Eversign (Xodo Sign)](https://euvetted.com/p/eversign): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Signaturit (Namirial)](https://euvetted.com/p/signaturit): hosted in Spain, CLOUD Act: material, ownership: eu_hq_us_funded - [Signicat](https://euvetted.com/p/signicat): hosted in Norway, CLOUD Act: material, ownership: other - [Skribble](https://euvetted.com/p/skribble): hosted in Switzerland, CLOUD Act: none, ownership: other - [Tresorit eSign](https://euvetted.com/p/tresorit-esign): hosted in Ireland, CLOUD Act: material, ownership: other - [Universign](https://euvetted.com/p/universign): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [Yousign](https://euvetted.com/p/yousign): hosted in France, CLOUD Act: minor, ownership: eu_hq_us_funded ### European alternatives to Affirm: https://euvetted.com/alternatives/affirm _About Affirm:_ US-incorporated BNPL provider, NASDAQ-listed (AFRM). Verified European alternatives (3): - [Alma](https://euvetted.com/p/alma): hosted in France, CLOUD Act: material, ownership: eu_owned - [Scalapay](https://euvetted.com/p/scalapay): hosted in Italy, CLOUD Act: material, ownership: eu_hq_us_funded - [Klarna](https://euvetted.com/p/klarna): hosted in Sweden, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Afterpay: https://euvetted.com/alternatives/afterpay _About Afterpay:_ Australian-founded BNPL, acquired by Block (US) in 2022. Verified European alternatives (3): - [Klarna](https://euvetted.com/p/klarna): hosted in Sweden, CLOUD Act: material, ownership: eu_hq_us_funded - [Alma](https://euvetted.com/p/alma): hosted in France, CLOUD Act: material, ownership: eu_owned - [Scalapay](https://euvetted.com/p/scalapay): hosted in Italy, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Airtable: https://euvetted.com/alternatives/airtable _About Airtable:_ US-incorporated database/spreadsheet hybrid, San Francisco HQ. Direct CLOUD Act exposure. Verified European alternatives (3): - [Baserow](https://euvetted.com/p/baserow): hosted in Spain, CLOUD Act: minor, ownership: eu_owned - [Kantree](https://euvetted.com/p/kantree): hosted in France, CLOUD Act: none, ownership: eu_owned - [SeaTable](https://euvetted.com/p/seatable): hosted in Germany, CLOUD Act: none, ownership: eu_owned ### European alternatives to Amplitude: https://euvetted.com/alternatives/amplitude _About Amplitude:_ US-incorporated product analytics. Direct CLOUD Act exposure. Verified European alternatives (3): - [PostHog](https://euvetted.com/p/posthog): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [TelemetryDeck](https://euvetted.com/p/telemetrydeck): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Matomo](https://euvetted.com/p/matomo): hosted in Germany, CLOUD Act: material, ownership: other ### European alternatives to Anthropic Claude: https://euvetted.com/alternatives/anthropic _About Anthropic Claude:_ US-incorporated AI lab, San Francisco. Direct CLOUD Act exposure. Verified European alternatives (4): - [Aleph Alpha](https://euvetted.com/p/aleph-alpha): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Infomaniak AI Tools](https://euvetted.com/p/infomaniak-ai-tools): hosted in Switzerland, CLOUD Act: none, ownership: other - [LightOn](https://euvetted.com/p/lighton): hosted in France, CLOUD Act: none, ownership: eu_owned - [Mistral AI](https://euvetted.com/p/mistral-ai): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Apple iCloud: https://euvetted.com/alternatives/icloud _About Apple iCloud:_ Apple-owned consumer cloud storage. Direct CLOUD Act exposure. Proton Drive (Switzerland, Geneva, EU-adequacy jurisdiction, zero-knowledge end-to-end encryption, ISO 27001 + SOC 2, Foundation-owned) is the strongest European alternative to Apple iCloud for cloud storage on EU Vetted's editorial assessment. Tresorit (Switzerland, Zurich, Swiss-Post-owned, zero-knowledge E2E, CLOUD Act exposure: [[tresorit.cloud_act]] in its sub-processor chain; contents stay end-to-end encrypted) is the strongest enterprise choice, and kDrive by Infomaniak (Switzerland, Geneva, own Swiss data centres, ISO 27001 + B Corp, CLOUD Act exposure: [[kdrive.cloud_act]]) is the best-value all-rounder. For the cheapest fully-German options, luckycloud and Filen run their own German data centres with zero-knowledge encryption. Apple iCloud is operated by Apple Inc. (NASDAQ: AAPL) and carries direct US CLOUD Act exposure. Verified European alternatives (12): - [Proton Drive](https://euvetted.com/p/proton-drive): hosted in Switzerland, CLOUD Act: none, ownership: other - [Internxt](https://euvetted.com/p/internxt): hosted in Spain, CLOUD Act: minor, ownership: eu_owned - [pCloud](https://euvetted.com/p/pcloud): hosted in Luxembourg, CLOUD Act: minor, ownership: other - [Jottacloud](https://euvetted.com/p/jottacloud): hosted in Norway, CLOUD Act: none, ownership: other - [Icedrive](https://euvetted.com/p/icedrive): hosted in United Kingdom, CLOUD Act: material, ownership: other - [luckycloud](https://euvetted.com/p/luckycloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Filen](https://euvetted.com/p/filen): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Koofr](https://euvetted.com/p/koofr): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Hetzner Storage Share](https://euvetted.com/p/hetzner-storage-share): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Tresorit](https://euvetted.com/p/tresorit): hosted in Ireland, CLOUD Act: material, ownership: other - [kDrive (Infomaniak)](https://euvetted.com/p/kdrive): hosted in Switzerland, CLOUD Act: none, ownership: other - [Nextcloud](https://euvetted.com/p/nextcloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned **Q: Is Apple iCloud usable under GDPR?** iCloud is legally usable from the EU: Apple publishes a Data Processing Addendum and offers Advanced Data Protection, an opt-in mode that applies end-to-end encryption to most iCloud categories (including iCloud Drive and Photos). The reason European users and teams still evaluate alternatives is the underlying ownership: Apple Inc. is US-incorporated and publicly listed (NASDAQ: AAPL), so the consolidated group falls within the reach of the US CLOUD Act. For users who want their files out of US jurisdiction by default (rather than relying on an opt-in setting from a US company), a European provider removes the question at the ownership level. **Q: Which iCloud alternative has the strongest compliance profile?** Among the storage alternatives mapped on this page, Proton Drive (Switzerland) leads on privacy: zero-knowledge end-to-end encryption, Swiss jurisdiction under an EU adequacy decision, non-profit Proton Foundation ownership, ISO 27001 + SOC 2. kDrive by Infomaniak (Switzerland, own data centres, ISO 27001 + B Corp) carries CLOUD Act exposure: [[kdrive.cloud_act]]; Tresorit (Switzerland, owned by state-anchored Swiss Post) pairs zero-knowledge E2E with a material CLOUD Act flag from its current sub-processor chain (CLOUD Act exposure: [[tresorit.cloud_act]]), with file contents end-to-end encrypted regardless. For fully-German hosting, luckycloud (Berlin) and Nextcloud (self-hosted) are EU-owned and EU-hosted (CLOUD Act exposure, luckycloud: [[luckycloud.cloud_act]], Nextcloud: [[nextcloud.cloud_act]]); Filen (Recklinghausen) keeps data at rest in Germany, with a transient US sub-processor accounting for its minor CLOUD Act flag (CLOUD Act exposure: [[filen.cloud_act]]); luckycloud and Filen ship zero-knowledge encryption by default. **Q: Does Apple iCloud fall under the US CLOUD Act?** Yes. Apple Inc. is US-incorporated and publicly listed (NASDAQ: AAPL), so the consolidated group falls within the reach of the US CLOUD Act. A US authority can compel Apple to produce data it controls regardless of where it is stored. Apple's Advanced Data Protection (end-to-end encryption) materially limits what Apple can hand over for the categories it covers, but it is opt-in, off by default, and does not change the ownership question. The European-owned and Swiss providers on this page (Proton Drive, Tresorit, kDrive, luckycloud, Filen, Internxt, Nextcloud, Koofr) are not US-incorporated, which removes that direct exposure. This reflects Apple's corporate structure, not a specific request for data. **Q: How do I move my files off iCloud?** iCloud Drive files download from icloud.com or the Files app, then upload into the new provider's desktop sync folder. The folder hierarchy carries over. For a complete copy, Apple's Data and Privacy portal (privacy.apple.com) lets you request a full export of your iCloud data, including Drive and Photos, delivered as a download. Install the new provider's desktop and mobile apps, point sync at the downloaded files, and verify everything appears on each device before you reduce or cancel your iCloud+ storage plan. Run both in parallel for a few weeks so nothing is lost in transit. **Q: What is the catch with switching from iCloud, and what won't transfer?** The hard part is not your files, it is the Apple-ecosystem integration. iCloud is woven into iOS and macOS: full iPhone/iPad device backup, the Photos library with on-device AI and Memories, Hide My Email and iCloud Private Relay (part of iCloud+), Find My, Messages in iCloud, and Keychain. A third-party storage provider replaces iCloud Drive (your files) cleanly, but it cannot perform a full iOS device backup. Apple does not open that to third parties, so you keep using local Finder/iTunes backups or a partial approach for the device image itself. Plan the file-storage switch first, and treat photos and passwords as separate migrations (see the linked pages below). **Q: Which iCloud alternatives have end-to-end encryption?** Proton Drive, Tresorit, Internxt, Filen, and luckycloud all ship zero-knowledge end-to-end encryption by default. The provider cannot read your file content even in response to a legal request, which is the same guarantee as Apple's Advanced Data Protection but from a non-US company by default. Koofr offers optional client-side encryption via Koofr Vault. kDrive and Jottacloud use server-side encryption (the provider holds the keys) but are EU/Swiss-hosted (CLOUD Act exposure, kDrive: [[kdrive.cloud_act]], Jottacloud: [[jottacloud.cloud_act]]). pCloud offers zero-knowledge only via the paid pCloud Crypto add-on; it is not the default. **Q: What about my iCloud Photos library and iCloud Mail?** Those are separate migrations from iCloud Drive file storage. For iCloud Mail (@icloud.com / @me.com addresses), see our [iCloud Mail alternatives](/alternatives/icloud-mail) page. Proton Mail, Tuta and Mailbox.org are the leading private-email replacements. For the iCloud Photos library specifically, see our [iCloud Photos alternatives](/alternatives/icloud-photos) page; Proton Drive, Internxt and Cryptee all handle encrypted photo storage, though none replicate Apple's on-device Photos AI and Memories. This page focuses on the iCloud Drive / general cloud-storage and backup use case. **Q: What is the cheapest European alternative to iCloud?** Filen (Germany, zero-knowledge, German data centres) is among the most aggressive on price, with paid storage from around €1.99/month and a free tier. For small storage needs, Koofr (Slovenia, hosted in Germany) undercuts even that. Proton Drive offers a generous free tier (5 GB) with end-to-end encryption. pCloud and Internxt both offer one-time lifetime plans, which work out cheaper than a subscription over several years, useful if you want to escape recurring iCloud+ fees entirely. Confirm current pricing on each vendor's page, as storage rates change frequently. ### European alternatives to Apple iCloud Photos: https://euvetted.com/alternatives/icloud-photos _About Apple iCloud Photos:_ Apple-owned photo storage. Direct CLOUD Act exposure. Verified European alternatives (5): - [Cryptee](https://euvetted.com/p/cryptee): hosted in Estonia, CLOUD Act: material, ownership: eu_owned - [Proton Drive](https://euvetted.com/p/proton-drive): hosted in Switzerland, CLOUD Act: none, ownership: other - [Internxt](https://euvetted.com/p/internxt): hosted in Spain, CLOUD Act: minor, ownership: eu_owned - [pCloud](https://euvetted.com/p/pcloud): hosted in Luxembourg, CLOUD Act: minor, ownership: other - [Jottacloud](https://euvetted.com/p/jottacloud): hosted in Norway, CLOUD Act: none, ownership: other ### European alternatives to Asana: https://euvetted.com/alternatives/asana _About Asana:_ US-incorporated work management platform, NYSE-listed (ASAN). MeisterTask (Germany) and Stackfield (Germany, Munich) are the strongest European alternatives to Asana on EU Vetted's editorial signals. Both are EU-owned and EU-hosted project management platforms (CLOUD Act exposure: MeisterTask: [[meistertask.cloud_act]], Stackfield: [[stackfield.cloud_act]]). For agencies billing by the hour, Teamwork.com (Ireland) adds native time tracking and a client portal, though it carries some sub-processor exposure not present in the German options. Asana, Inc. is US-incorporated and falls under CLOUD Act jurisdiction in practice. Verified European alternatives (7): - [factro](https://euvetted.com/p/factro): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [MeisterTask](https://euvetted.com/p/meistertask): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Plandisc](https://euvetted.com/p/plandisc): hosted in Sweden, CLOUD Act: minor, ownership: other - [Teamwork.com](https://euvetted.com/p/teamwork): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [Taiga](https://euvetted.com/p/taiga): hosted in Spain, CLOUD Act: none, ownership: eu_owned - [Kantree](https://euvetted.com/p/kantree): hosted in France, CLOUD Act: none, ownership: eu_owned - [Stackfield](https://euvetted.com/p/stackfield): hosted in Germany, CLOUD Act: none, ownership: eu_owned **Q: Is Asana usable under GDPR?** Asana publishes a Data Processing Addendum based on the EU Standard Contractual Clauses with post-Schrems II supplementary measures, and offers EU data residency on the Enterprise tier. The service is legally usable from the EU. What keeps it on procurement watch-lists is ownership, not paperwork: Asana, Inc. is US-incorporated and publicly listed (NYSE: ASAN), so CLOUD Act jurisdiction applies to the parent structure. That single fact is usually what a transfer impact assessment flags. **Q: Which Asana alternative has the strongest compliance profile?** Among the alternatives mapped on this page, five are EU-owned and EU-hosted: MeisterTask (Germany, CLOUD Act exposure: [[meistertask.cloud_act]]), factro (Germany, Bochum, CLOUD Act exposure: [[factro.cloud_act]]), Kantree (France, CLOUD Act exposure: [[kantree.cloud_act]]), Taiga (Spain, open source, CLOUD Act exposure: [[taiga.cloud_act]]), and Stackfield (Germany, Munich, CLOUD Act exposure: [[stackfield.cloud_act]]). Teamwork.com (Ireland) and Plandisc (Denmark) are EU-hosted with EU-primary infrastructure but carry some sub-processor exposure that the German and French options do not. **Q: Can my Asana tasks transfer?** Yes. Asana supports CSV and JSON export per project via *Settings → Export project*. The exports preserve task names, descriptions, assignees, due dates, custom fields, subtask relationships, and tags. What does not transfer cleanly: Asana-specific automations (Rules), portfolio-level reporting, and Goals tracking. These are rebuilt as native features in the new tool. For teams with under 100 active projects, the migration is a one-evening task per workspace. **Q: What about Asana's portfolios and goals features?** Portfolios (cross-project rollups) and Goals (OKR tracking) are Asana-specific premium features that European alternatives do not all bundle. Stackfield ships portfolios; Teamwork.com has portfolio-style reporting; for Goals/OKRs specifically, most teams pair the European project management tool with a separate OKR tool (e.g. Profit.co, Ally, or a simple shared spreadsheet). If portfolios and Goals are essential to your workflow, evaluate Stackfield and Teamwork first. **Q: Does Asana's AI feature transfer?** No. Asana AI routes through US-based language model providers (OpenAI primarily). European alternatives ship without LLM-based features by default; the European tools deliberately keep AI separate from project data, since embedding US LLMs into European project management would defeat the data-sovereignty argument. If AI task drafting and summarisation are essential, the cleanest European path today is to use Mistral or Aleph Alpha separately on project-level content. **Q: Does Asana fall under the US CLOUD Act?** In practice, yes. Asana, Inc. is US-incorporated and publicly listed on NYSE, meaning the consolidated group falls within CLOUD Act reach. A US authority can compel Asana to produce data it controls regardless of where that data is stored. Asana's EU data residency option (Enterprise tier) reduces storage exposure but does not remove the underlying ownership question. The EU-owned and EU-hosted alternatives on this page (MeisterTask, factro, Stackfield) remove that direct exposure by being incorporated and operated in the EU with no US parent (CLOUD Act exposure: MeisterTask: [[meistertask.cloud_act]], factro: [[factro.cloud_act]], Stackfield: [[stackfield.cloud_act]]). **Q: What is the cheapest European alternative to Asana?** Taiga (Spain, EU-owned, open source) is free and open source, making it the lowest-cost option for teams with SRE capacity to self-host on EU sovereign cloud. Among commercial cloud-hosted alternatives, MeisterTask has the most accessible entry pricing: a free tier for up to 3 projects and per-user paid tiers comparable to Asana's pricing. factro and Kantree have SMB-range pricing without the Asana Business-tier markup. Exact current prices should be confirmed on each vendor's page. **Q: Is there a GDPR-compliant alternative to Asana?** All seven alternatives mapped on this page operate under GDPR and publish data processing agreements. However, GDPR compliance and strong EU data sovereignty are not the same bar. MeisterTask, factro, Stackfield, Kantree, and Taiga are EU-owned and EU-hosted (CLOUD Act exposure: MeisterTask: [[meistertask.cloud_act]], factro: [[factro.cloud_act]], Stackfield: [[stackfield.cloud_act]], Kantree: [[kantree.cloud_act]], Taiga: [[taiga.cloud_act]]), representing the strongest posture for a transfer impact assessment. Teamwork.com and Plandisc are EU-hosted with EU-primary infrastructure but carry some sub-processor exposure. For a formal transfer impact assessment, the EU-owned tools eliminate the CLOUD Act ownership question that Asana raises. **Q: Which Asana alternative is best for engineering teams doing agile sprints?** Taiga (Spain, EU-owned, open source) is the strongest pick for engineering teams wanting Jira-style agile sprint management with full EU sovereignty. It is self-hostable on any EU sovereign cloud, supports Scrum and Kanban natively, and has no commercial vendor lock-in. For engineering teams that prefer a commercial cloud-hosted product, Stackfield (Germany, EU-owned and EU-hosted) covers sprint-style workflows within its broader all-in-one platform, though it is less purpose-built for agile than Taiga. ### European alternatives to AWS: https://euvetted.com/alternatives/aws _About AWS:_ Amazon Web Services. Excluded from EU sovereign cloud tender (April 2026). Scaleway (France, Paris), Hetzner (Germany, Gunzenhausen), and OVHcloud (France, Roubaix) are the strongest European alternatives to AWS on EU Vetted's editorial assessment. All three are EU-owned, EU-hosted, and carry no material CLOUD Act exposure. Scaleway won part of the April 2026 €180M EU sovereign cloud tender. For lowest cost per vCPU, Hetzner leads. For SecNumCloud qualification required by French public sector, OVHcloud is the default. Verified European alternatives (17): - [Aruba Cloud](https://euvetted.com/p/aruba-cloud): hosted in Italy, CLOUD Act: none, ownership: eu_owned - [Cleura](https://euvetted.com/p/cleura): hosted in Sweden, CLOUD Act: none, ownership: eu_owned - [Clever Cloud](https://euvetted.com/p/clever-cloud): hosted in France, CLOUD Act: none, ownership: eu_owned - [Contabo](https://euvetted.com/p/contabo): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Exoscale](https://euvetted.com/p/exoscale): hosted in Switzerland, CLOUD Act: minor, ownership: other - [Hetzner](https://euvetted.com/p/hetzner): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Infomaniak Public Cloud](https://euvetted.com/p/infomaniak-public-cloud): hosted in Switzerland, CLOUD Act: none, ownership: other - [Intility](https://euvetted.com/p/intility): hosted in Norway, CLOUD Act: material, ownership: other - [IONOS](https://euvetted.com/p/ionos): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [netcup](https://euvetted.com/p/netcup): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [OVHcloud](https://euvetted.com/p/ovhcloud): hosted in France, CLOUD Act: none, ownership: eu_owned - [Scaleway](https://euvetted.com/p/scaleway): hosted in France, CLOUD Act: none, ownership: eu_owned - [STACKIT](https://euvetted.com/p/stackit): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Stackscale](https://euvetted.com/p/stackscale): hosted in Spain, CLOUD Act: none, ownership: eu_owned - [T Cloud Public (formerly Open Telekom Cloud)](https://euvetted.com/p/open-telekom-cloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Thalassa Cloud](https://euvetted.com/p/thalassa-cloud): hosted in Netherlands, CLOUD Act: none, ownership: eu_owned - [UpCloud](https://euvetted.com/p/upcloud): hosted in Finland, CLOUD Act: none, ownership: eu_owned **Q: Is AWS usable under GDPR?** AWS publishes a Data Processing Addendum based on the EU Standard Contractual Clauses with post-Schrems II supplementary measures, offers EU region residency (Frankfurt, Paris, Dublin, Stockholm, Milan, Zurich, Spain), and provides a European Sovereign Cloud option. The service is legally usable from the EU. What GDPR compliance does not resolve is ownership: Amazon Web Services, Inc. is US-incorporated and a subsidiary of Amazon.com, Inc., so CLOUD Act jurisdiction applies to the parent group regardless of which AWS region stores the data. That gap is why AWS was excluded from the €180M EU sovereign cloud tender in April 2026, awarded instead to Scaleway, Clever Cloud, OVH, and STACKIT, a procurement-policy signal separate from any single technical compliance argument. **Q: Which AWS alternative has the strongest compliance profile?** This is the strongest category on the site. Ten of the twelve alternatives mapped here are EU-owned, EU-hosted, and carry no material CLOUD Act exposure: Scaleway (France, Paris), Hetzner (Germany, Gunzenhausen), OVHcloud (France, Roubaix), UpCloud (Finland, Helsinki), IONOS (Germany, Frankfurt), STACKIT (Germany, Neckarsulm), Cleura (Sweden), Stackscale (Spain, Madrid), Aruba Cloud (Italy, Arezzo), and T Cloud Public from Deutsche Telekom (Germany, Biere). Exoscale (Switzerland) is EU-hosted with a minor CLOUD Act exposure due to its Swiss domicile. Contabo is EU-hosted but has a broader sub-processor footprint and lacks a fully disclosed sub-processor list. **Q: Can a European cloud replace AWS for a production SaaS workload?** Yes for the majority of workloads. For straightforward compute, storage, and networking (the AWS EC2/S3/VPC trio that powers most SaaS), Scaleway, Hetzner, OVH, IONOS, and STACKIT all have direct equivalents. European clouds still have narrower coverage in a few managed services: AWS-specific products like DynamoDB, Lambda's broadest runtime catalog, and SageMaker have partial European equivalents but with smaller ecosystems. For 80–90% of SaaS hosting workloads, the European clouds are production-ready today. **Q: What about Kubernetes?** Scaleway, OVH, IONOS, STACKIT, Exoscale, and UpCloud all offer managed Kubernetes services. The compatibility with kubectl, Helm, and standard CNCF tooling is identical to AWS EKS, so your manifests do not need rewriting. The differences are in node-pool pricing models and the specific cloud-controller-manager integrations. For most teams, the Kubernetes migration is one of the easier parts of an AWS-to-EU move. **Q: What about S3-compatible object storage?** Every European cloud listed here ships an S3-compatible object storage product. The compatibility is generally 95%+ for standard SDK operations (get, put, list, delete, multipart upload). Some AWS-specific features (Intelligent-Tiering automatic class transitions, S3 Object Lambda, Vault Lock) are not implemented. For backup and archive workloads, Scaleway Glacier, OVH Cold Archive, and IONOS S3 Cold are all viable replacements for S3 Glacier. **Q: Does AWS fall under the US CLOUD Act?** Yes. Amazon Web Services, Inc. is a subsidiary of Amazon.com, Inc., which is US-incorporated. The consolidated group (including AWS's EU-region data centres in Frankfurt, Paris, Dublin, and elsewhere) falls within the reach of the US CLOUD Act, which can compel a US company to produce data it controls regardless of where that data is stored. The April 2026 EU sovereign cloud tender (€180M) explicitly excluded AWS for this reason, awarding the contract to Scaleway, Clever Cloud, OVH, and STACKIT. The ten EU-owned, EU-hosted alternatives on this page carry no material CLOUD Act exposure, removing that direct risk. That conclusion follows from group ownership alone, not from any known or suspected data request against AWS. **Q: Can a European cloud handle a high-traffic SaaS at enterprise scale?** Yes. Scaleway, OVH, and IONOS all operate multi-region infrastructure with the capacity and SLA framing for enterprise SaaS workloads. OVHcloud is the largest European cloud by server count and operates datacentres across Europe, North America, and Asia-Pacific. Scaleway powers multiple publicly-known SaaS products at scale. Hetzner is production-ready for compute-heavy workloads but intentionally minimal on managed-services breadth; teams needing a managed services catalog at enterprise depth should prefer Scaleway or OVH. **Q: Is there a GDPR-compliant alternative to AWS?** All twelve European alternatives mapped on this page are GDPR-compliant by design: EU-headquartered, EU-hosted, published DPAs based on SCCs. The ten that are EU-owned and EU-hosted with no material CLOUD Act exposure meet the stronger bar that regulated-industry and public-sector buyers typically require. For organisations subject to French public-sector procurement rules, OVHcloud's SecNumCloud-qualified tiers are the highest available certification in the European cloud market. **Q: Can a European cloud alternative support serverless and managed database workloads?** Yes, for the majority of use cases. Scaleway offers serverless containers, serverless functions, managed PostgreSQL, managed MySQL, and a document database equivalent to DynamoDB in common patterns. OVH offers managed databases (PostgreSQL, MySQL, Kafka, Cassandra, Redis) and managed Kubernetes. IONOS and STACKIT offer managed Kubernetes and managed databases. The European managed-services catalog is smaller than AWS's ~250 services, but the services covering 80–90% of SaaS workloads are available today. ### European alternatives to BambooHR: https://euvetted.com/alternatives/bamboohr _About BambooHR:_ Utah-headquartered SMB HRIS. US-incorporated; direct CLOUD Act exposure. Verified European alternatives (5): - [Factorial](https://euvetted.com/p/factorial): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [HiBob](https://euvetted.com/p/hibob): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [Lucca](https://euvetted.com/p/lucca): hosted in France, CLOUD Act: none, ownership: eu_owned - [Personio](https://euvetted.com/p/personio): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Sage HR](https://euvetted.com/p/sage-hr): hosted in Ireland, CLOUD Act: minor, ownership: other ### European alternatives to Basecamp: https://euvetted.com/alternatives/basecamp _About Basecamp:_ US-incorporated project management tool by 37signals, Chicago HQ. Verified European alternatives (5): - [Stackfield](https://euvetted.com/p/stackfield): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Teamwork.com](https://euvetted.com/p/teamwork): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [factro](https://euvetted.com/p/factro): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Kantree](https://euvetted.com/p/kantree): hosted in France, CLOUD Act: none, ownership: eu_owned - [MeisterTask](https://euvetted.com/p/meistertask): hosted in Germany, CLOUD Act: none, ownership: eu_owned ### European alternatives to BigCommerce: https://euvetted.com/alternatives/bigcommerce _About BigCommerce:_ US-listed hosted commerce platform (Nasdaq: BIGC), Australian-founded but US-headquartered post-IPO. Verified European alternatives (5): - [Shopware](https://euvetted.com/p/shopware): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Sylius](https://euvetted.com/p/sylius): hosted in Poland, CLOUD Act: none, ownership: eu_owned - [MyCashflow](https://euvetted.com/p/mycashflow): hosted in Finland, CLOUD Act: none, ownership: eu_owned - [Saleor Commerce](https://euvetted.com/p/saleor): hosted in Ireland, CLOUD Act: material, ownership: eu_owned - [PrestaShop](https://euvetted.com/p/prestashop): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Bitwarden: https://euvetted.com/alternatives/bitwarden _About Bitwarden:_ US-incorporated open-source password manager (Florida/Santa Barbara). GPL self-host option. Verified European alternatives (10): - [heylogin](https://euvetted.com/p/heylogin): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [KeePassXC](https://euvetted.com/p/keepassxc): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [NordPass](https://euvetted.com/p/nordpass): hosted in Lithuania, CLOUD Act: material, ownership: eu_owned - [Padloc](https://euvetted.com/p/padloc): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Passbolt](https://euvetted.com/p/passbolt): hosted in Luxembourg, CLOUD Act: none, ownership: eu_owned - [pCloud Pass](https://euvetted.com/p/pcloud-pass): hosted in Luxembourg, CLOUD Act: minor, ownership: other - [Proton Pass](https://euvetted.com/p/proton-pass): hosted in Switzerland, CLOUD Act: none, ownership: other - [Psono](https://euvetted.com/p/psono): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Uniqkey](https://euvetted.com/p/uniqkey): hosted in Denmark, CLOUD Act: none, ownership: eu_owned - [Vaultwarden](https://euvetted.com/p/vaultwarden): hosted in Spain, CLOUD Act: none, ownership: eu_owned ### European alternatives to Bookwhen: https://euvetted.com/alternatives/bookwhen _About Bookwhen:_ UK-based class and event booking platform. Verified European alternatives (4): - [Reservio](https://euvetted.com/p/reservio): hosted in Czechia, CLOUD Act: minor, ownership: eu_owned - [Doodle](https://euvetted.com/p/doodle): hosted in Germany, CLOUD Act: minor, ownership: other - [SuperSaaS](https://euvetted.com/p/supersaas): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Cal.com](https://euvetted.com/p/cal-com): hosted in United States, CLOUD Act: direct, ownership: us_owned ### European alternatives to Box: https://euvetted.com/alternatives/box _About Box:_ US-incorporated enterprise content management, NYSE-listed (BOX). Verified European alternatives (5): - [Oodrive](https://euvetted.com/p/oodrive): hosted in France, CLOUD Act: none, ownership: eu_owned - [Tresorit](https://euvetted.com/p/tresorit): hosted in Ireland, CLOUD Act: material, ownership: other - [kDrive (Infomaniak)](https://euvetted.com/p/kdrive): hosted in Switzerland, CLOUD Act: none, ownership: other - [Nextcloud](https://euvetted.com/p/nextcloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [pCloud](https://euvetted.com/p/pcloud): hosted in Luxembourg, CLOUD Act: minor, ownership: other ### European alternatives to Braintree: https://euvetted.com/alternatives/braintree _About Braintree:_ US-owned payment gateway, PayPal subsidiary since 2013. Verified European alternatives (6): - [Lemonway](https://euvetted.com/p/lemonway): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Mangopay](https://euvetted.com/p/mangopay): hosted in Luxembourg, CLOUD Act: material, ownership: eu_hq_us_funded - [Worldline](https://euvetted.com/p/worldline): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Adyen](https://euvetted.com/p/adyen): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Dintero](https://euvetted.com/p/dintero): hosted in Norway, CLOUD Act: minor, ownership: other - [Mollie](https://euvetted.com/p/mollie): hosted in Netherlands, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Builder.io: https://euvetted.com/alternatives/builder-io _About Builder.io:_ San Francisco-headquartered visual headless CMS. US-incorporated; direct CLOUD Act exposure. Verified European alternatives (5): - [DatoCMS](https://euvetted.com/p/datocms): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [Hygraph](https://euvetted.com/p/hygraph): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Prismic](https://euvetted.com/p/prismic): hosted in United States, CLOUD Act: minor, ownership: eu_owned - [Storyblok](https://euvetted.com/p/storyblok): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Strapi](https://euvetted.com/p/strapi): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Calendly: https://euvetted.com/alternatives/calendly _About Calendly:_ US-incorporated calendar-booking SaaS. Direct CLOUD Act exposure. Doodle (Switzerland) is the top-ranked European alternative to Calendly on EU Vetted's editorial review: Swiss-incorporated, EU-adequate jurisdiction, CLOUD Act exposure: [[doodle.cloud_act]]. For enterprise integration depth, Cronofy (UK, API-first) is the strongest option, though its UK base carries CLOUD Act exposure: [[cronofy.cloud_act]]. SuperSaaS (Netherlands, EU-hosted, EU-owned) offers the lowest-friction migration for solo consultants from €8/month. Calendly is US-incorporated with US cloud infrastructure and US sub-processors, placing it under CLOUD Act jurisdiction in practice. Verified European alternatives (5): - [Cal.com](https://euvetted.com/p/cal-com): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Cronofy](https://euvetted.com/p/cronofy): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Doodle](https://euvetted.com/p/doodle): hosted in Germany, CLOUD Act: minor, ownership: other - [Reservio](https://euvetted.com/p/reservio): hosted in Czechia, CLOUD Act: minor, ownership: eu_owned - [SuperSaaS](https://euvetted.com/p/supersaas): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned **Q: Is Calendly usable under GDPR?** Calendly publishes a Data Processing Addendum based on the EU Standard Contractual Clauses with post-Schrems II supplementary measures, so it is legally usable from the EU. What keeps procurement teams checking alternatives anyway is the layer underneath that DPA: Calendly is US-incorporated, hosted on US cloud infrastructure, and shares meeting metadata with US-based sub-processors that fall under CLOUD Act jurisdiction. For a transfer impact assessment, that combination, not the DPA itself, is what drives the alternative search. **Q: Which Calendly alternative has the strongest compliance profile?** Among the alternatives mapped on this page, Doodle (Switzerland) carries the cleanest profile: Swiss-incorporated, operating under Switzerland's Federal Act on Data Protection (FADP), with CLOUD Act exposure: [[doodle.cloud_act]]. Reservio (Czech Republic) and SuperSaaS (Netherlands) both operate with EU-primary infrastructure and EU ownership. Cronofy (UK) offers the most enterprise-grade integration set but carries CLOUD Act exposure: [[cronofy.cloud_act]] due to its UK corporate base. **Q: Will my Calendly booking page URL still work after migration?** No. Your custom booking page URL is tied to Calendly's domain (calendly.com/your-handle). After migration, you will receive a new vendor-domain URL. The mitigation is to use a stable redirect on your own domain (e.g. yourcompany.com/book → new vendor URL), which means migrations only break for visitors who bookmarked the old Calendly URL. Most European alternatives accept your own subdomain via CNAME. **Q: Do the European alternatives integrate with Google Calendar and Outlook?** Yes, all five alternatives mapped here support two-way sync with Google Calendar and Microsoft 365. Note that Google Calendar and Outlook themselves are US-hosted services; replacing your booking page is independent from replacing your underlying calendar provider, and most teams do these two migrations on different timelines. **Q: Can I keep my booking automation when I migrate?** Webhooks, Zapier/Make integrations, and email reminder logic transfer cleanly. Calendly-specific routing (round-robin, collective scheduling) is available on Cronofy and SuperSaaS, but the configuration is rebuilt rather than imported. Plan one evening to re-create routing rules and one to re-test confirmation/reminder emails in real inboxes. **Q: Does Calendly fall under the US CLOUD Act?** In practice, yes. Calendly is US-incorporated and its infrastructure providers and sub-processors are based in the United States, placing the service within the reach of the US CLOUD Act, which can compel a US company to produce data it controls regardless of where it is stored. Meeting metadata (including participant names, email addresses, and booking timestamps) is among the data processed. Doodle (Switzerland, Swiss-incorporated, CLOUD Act exposure: [[doodle.cloud_act]]) and Reservio (Czech Republic, EU-incorporated, EU-hosted, CLOUD Act exposure: [[reservio.cloud_act]]) are the alternatives mapped here without US incorporation. This is a statement about corporate jurisdiction and legal structure, not a claim that any particular booking record has been requested. **Q: What is the cheapest European alternative to Calendly?** SuperSaaS (Netherlands, EU-owned, EU-hosted) starts at €8/month for solo consultants and small teams, making it the lowest entry-point among the European alternatives mapped here. Doodle offers a free group-scheduling tier with limited features; paid plans with CNAME support start above that baseline. Reservio has a free plan oriented toward appointment-booking businesses. Exact pricing depends on team size and features needed, so confirm current rates on each vendor's page before committing. **Q: Is there a GDPR-compliant Calendly alternative that supports a custom booking domain?** Yes. Doodle (Switzerland, Swiss-incorporated, CLOUD Act exposure: [[doodle.cloud_act]]), Cronofy (UK, API-first, CLOUD Act exposure: [[cronofy.cloud_act]]), and SuperSaaS (Netherlands, EU-owned, EU-hosted) all support custom subdomains via CNAME on paid plans. This means visitors see your own domain (e.g. book.yourcompany.com) rather than a vendor-branded URL, and a future migration again only requires updating the CNAME record, not notifying all past bookers. Setting up the custom subdomain before the Calendly cutover is the single highest-leverage step in the migration plan. **Q: Which Calendly alternative is best for teams that also use HubSpot or Salesforce?** Cronofy (UK, API-first) is the strongest answer for enterprise CRM integration. It is the only API-first scheduling tool in the European set mapped here, with a native HubSpot connector and documented Salesforce integration paths. All other alternatives rely on Zapier or Make for CRM routing. For teams where the Salesforce or HubSpot native integration is a procurement requirement, Cronofy is the starting point; its UK base carries CLOUD Act exposure: [[cronofy.cloud_act]], which should be weighed against the integration depth advantage. ### European alternatives to ClickUp: https://euvetted.com/alternatives/clickup _About ClickUp:_ US-incorporated work management platform, San Diego HQ. Verified European alternatives (4): - [Teamwork.com](https://euvetted.com/p/teamwork): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [factro](https://euvetted.com/p/factro): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [MeisterTask](https://euvetted.com/p/meistertask): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Taiga](https://euvetted.com/p/taiga): hosted in Spain, CLOUD Act: none, ownership: eu_owned ### European alternatives to Coda: https://euvetted.com/alternatives/coda _About Coda:_ US-incorporated all-in-one docs platform, acquired by Grammarly (US) in 2024. Verified European alternatives (3): - [Nuclino](https://euvetted.com/p/nuclino): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Outline](https://euvetted.com/p/outline): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Anytype](https://euvetted.com/p/anytype): hosted in Germany, CLOUD Act: none, ownership: eu_owned ### European alternatives to Cohere: https://euvetted.com/alternatives/cohere _About Cohere:_ Canadian AI lab (Toronto), enterprise-focused. Heavy US-VC and Salesforce backing. Verified European alternatives (4): - [Aleph Alpha](https://euvetted.com/p/aleph-alpha): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [LightOn](https://euvetted.com/p/lighton): hosted in France, CLOUD Act: none, ownership: eu_owned - [Mistral AI](https://euvetted.com/p/mistral-ai): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [Infomaniak AI Tools](https://euvetted.com/p/infomaniak-ai-tools): hosted in Switzerland, CLOUD Act: none, ownership: other ### European alternatives to Confluence: https://euvetted.com/alternatives/confluence _About Confluence:_ Atlassian-owned wiki/docs platform. Same Atlassian US-listed parent as Jira. Nuclino (Germany, Munich) is the strongest commercial European alternative to Confluence: EU-owned, German-hosted, and ISO 27001 certified (CLOUD Act exposure: [[nuclino.cloud_act]]). For self-hosting on EU sovereign cloud, BookStack (UK, open source) and HumHub (Germany, Munich) are the top picks. Atlassian (NASDAQ: TEAM) operates US infrastructure and falls under CLOUD Act jurisdiction. Verified European alternatives (5): - [BookStack](https://euvetted.com/p/bookstack): hosted in United Kingdom, CLOUD Act: none, ownership: other - [Wiki.js](https://euvetted.com/p/wiki-js): hosted in Canada, CLOUD Act: none, ownership: other - [Nuclino](https://euvetted.com/p/nuclino): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Outline](https://euvetted.com/p/outline): hosted in United States, CLOUD Act: direct, ownership: us_owned - [HumHub](https://euvetted.com/p/humhub): hosted in Germany, CLOUD Act: none, ownership: eu_owned **Q: Is Confluence usable under GDPR?** Atlassian publishes a Data Processing Addendum based on the EU Standard Contractual Clauses with post-Schrems II supplementary measures, and offers EU data residency on Atlassian Cloud Enterprise. The service is legally usable from the EU. What keeps buyers evaluating alternatives anyway is the group structure behind the paperwork: Atlassian Corporation is incorporated in Australia but listed on NASDAQ (TEAM) and runs on US infrastructure, so CLOUD Act jurisdiction still applies. That detail is usually what a Schrems II transfer impact assessment flags first. **Q: Which Confluence alternative has the strongest compliance profile?** Among the alternatives mapped on this page, three are EU-owned or open source with EU-compatible hosting: Nuclino (Germany, Munich, CLOUD Act exposure: [[nuclino.cloud_act]]), BookStack (UK, open source, CLOUD Act exposure: [[bookstack.cloud_act]]), and HumHub (Germany, Munich, CLOUD Act exposure: [[humhub.cloud_act]]). All three are usable as Confluence replacements depending on your binding constraint. Outline is US-incorporated; we list it for awareness but it does not meet the procurement-grade bar. **Q: Can I migrate from Confluence Cloud to a European wiki?** Yes. Atlassian supports XML export of an entire Confluence space via *Space Settings → Content Tools → Export*. The export preserves page hierarchy, body content (in XHTML), attachments, and labels. What does not transfer cleanly: Confluence macros (Page Tree, Children Display, JIRA links, Excerpt Include), custom plugins, and complex permission schemes. For most teams the migration is a 1–2 week effort focused on rebuilding macros as native equivalents. **Q: What about Jira integration?** Confluence's native Jira integration is the single biggest reason teams stay on Atlassian Cloud: issue embeds, requirement-traceability matrices, and release-notes generation rely on it. European wikis do not have native Jira integration. The mitigation is that many teams switching from Confluence also switch from Jira to Taiga (Spain, EU-hosted, open source) or another European project tool, and the wiki-and-PM pairing is rebuilt holistically. If Jira is non-negotiable, plan to embed Jira links as standard HTML in the new wiki and accept some manual sync overhead. **Q: Does any European alternative match Confluence's enterprise-scale wiki features?** Nuclino has the cleanest commercial cloud-hosted alternative for SMB-to-mid-market. BookStack and HumHub are self-hostable on EU sovereign cloud for teams with SRE capacity. For enterprise scale specifically (50 000+ pages, complex permission hierarchies, on-premise mandate), self-hosted Nextcloud with the Notes/Docs apps or self-hosted BookStack are the realistic paths. Atlassian's enterprise-scale wiki tooling does not have a direct commercial European cloud equivalent yet. **Q: Does Confluence fall under the US CLOUD Act?** In practice, yes. Atlassian Corporation is US-listed (NASDAQ: TEAM) and operates globally-distributed cloud infrastructure with US sub-processors. The group structure means a US authority can compel Atlassian to produce data it controls regardless of where that data is stored. EU data residency on Atlassian Cloud Enterprise reduces storage exposure but does not remove the underlying ownership question. The alternatives highlighted on this page (Nuclino, BookStack, HumHub) are EU-owned or open source with no US parent (CLOUD Act exposure, Nuclino: [[nuclino.cloud_act]], BookStack: [[bookstack.cloud_act]], HumHub: [[humhub.cloud_act]]). **Q: What is the cheapest European alternative to Confluence?** BookStack (open source) is free to self-host, making it the lowest-cost option for teams with SRE capacity. HumHub is also open source and free to self-host. Among commercial cloud-hosted alternatives, Nuclino has the most accessible entry pricing, with per-user plans that are typically below Confluence's Cloud Standard tier. For very small teams (under 10 users), Nuclino's free tier covers basic wiki needs. **Q: Is there a GDPR-compliant alternative to Confluence?** All five alternatives mapped on this page operate under GDPR and publish data processing agreements. The strongest GDPR posture belongs to Nuclino (Germany, EU-owned, German-hosted, CLOUD Act exposure: [[nuclino.cloud_act]]) and HumHub (Germany, EU-owned, self-hostable, CLOUD Act exposure: [[humhub.cloud_act]]) on the commercial and self-hosted sides respectively. BookStack (UK, open source) is GDPR-compliant when self-hosted on EU infrastructure. For a formal transfer impact assessment, these three eliminate the ownership question that Atlassian's structure raises. **Q: Which Confluence alternative is best for teams also migrating from Jira?** Pairing Nuclino or BookStack with Taiga (Spain, EU-hosted, open source) covers the Confluence + Jira surface area with full EU sovereignty. Taiga is the European pick for Jira-style agile sprint management. If Jira is non-negotiable to keep, the practical path is to migrate only the Confluence layer to a European wiki and accept that Jira links become standard HTML. Most teams that run this migration find that rebuilding the PM layer in Taiga alongside the wiki migration produces the cleaner long-term stack. ### European alternatives to Constant Contact: https://euvetted.com/alternatives/constant-contact _About Constant Contact:_ US-owned email marketing platform. Direct CLOUD Act exposure. Verified European alternatives (8): - [CleverReach](https://euvetted.com/p/cleverreach): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [GetResponse](https://euvetted.com/p/getresponse): hosted in Poland, CLOUD Act: material, ownership: eu_owned - [Infomaniak Newsletter](https://euvetted.com/p/infomaniak-newsletter): hosted in Switzerland, CLOUD Act: none, ownership: other - [Make](https://euvetted.com/p/make-newsletter): hosted in Norway, CLOUD Act: minor, ownership: other - [rapidmail](https://euvetted.com/p/rapidmail): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Sender](https://euvetted.com/p/sender): hosted in Lithuania, CLOUD Act: minor, ownership: eu_owned - [Brevo](https://euvetted.com/p/brevo): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [MailerLite](https://euvetted.com/p/mailerlite): hosted in Netherlands, CLOUD Act: material, ownership: eu_owned ### European alternatives to Contentful: https://euvetted.com/alternatives/contentful _About Contentful:_ Berlin-founded but US-headquartered + heavily US-funded (Tiger Global, Sapphire, BlackRock); operates as the headless-CMS market anchor for our purposes. Verified European alternatives (6): - [DatoCMS](https://euvetted.com/p/datocms): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [Enonic](https://euvetted.com/p/enonic): hosted in Norway, CLOUD Act: material, ownership: other - [Hygraph](https://euvetted.com/p/hygraph): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Prismic](https://euvetted.com/p/prismic): hosted in United States, CLOUD Act: minor, ownership: eu_owned - [Storyblok](https://euvetted.com/p/storyblok): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Strapi](https://euvetted.com/p/strapi): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to ConvertKit (Kit): https://euvetted.com/alternatives/convertkit _About ConvertKit (Kit):_ US email marketing for creators, recently rebranded to Kit. Direct CLOUD Act exposure. Verified European alternatives (4): - [Keila](https://euvetted.com/p/keila): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [EmailOctopus](https://euvetted.com/p/emailoctopus): hosted in United Kingdom, CLOUD Act: material, ownership: other - [GetResponse](https://euvetted.com/p/getresponse): hosted in Poland, CLOUD Act: material, ownership: eu_owned - [MailerLite](https://euvetted.com/p/mailerlite): hosted in Netherlands, CLOUD Act: material, ownership: eu_owned ### European alternatives to Dashlane: https://euvetted.com/alternatives/dashlane _About Dashlane:_ French-founded, now US-headquartered (NYC). Significant US-VC funding. Verified European alternatives (6): - [heylogin](https://euvetted.com/p/heylogin): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [KeePassXC](https://euvetted.com/p/keepassxc): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [NordPass](https://euvetted.com/p/nordpass): hosted in Lithuania, CLOUD Act: material, ownership: eu_owned - [Padloc](https://euvetted.com/p/padloc): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Uniqkey](https://euvetted.com/p/uniqkey): hosted in Denmark, CLOUD Act: none, ownership: eu_owned - [Vaultwarden](https://euvetted.com/p/vaultwarden): hosted in Spain, CLOUD Act: none, ownership: eu_owned ### European alternatives to DigitalOcean: https://euvetted.com/alternatives/digitalocean _About DigitalOcean:_ US-incorporated developer cloud, NYSE-listed (DOCN). Verified European alternatives (8): - [Contabo](https://euvetted.com/p/contabo): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Exoscale](https://euvetted.com/p/exoscale): hosted in Switzerland, CLOUD Act: minor, ownership: other - [netcup](https://euvetted.com/p/netcup): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [UpCloud](https://euvetted.com/p/upcloud): hosted in Finland, CLOUD Act: none, ownership: eu_owned - [Infomaniak Public Cloud](https://euvetted.com/p/infomaniak-public-cloud): hosted in Switzerland, CLOUD Act: none, ownership: other - [Hetzner](https://euvetted.com/p/hetzner): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [IONOS](https://euvetted.com/p/ionos): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Thalassa Cloud](https://euvetted.com/p/thalassa-cloud): hosted in Netherlands, CLOUD Act: none, ownership: eu_owned ### European alternatives to DocuSign: https://euvetted.com/alternatives/docusign _About DocuSign:_ US-owned e-signature leader. Direct CLOUD Act exposure. Skribble (Switzerland, Zurich, Swiss-hosted, CLOUD Act exposure: [[skribble.cloud_act]]) and Yousign (France, Caen, EU-headquartered, EU-hosted, CLOUD Act exposure: [[yousign.cloud_act]]) are the strongest European alternatives to DocuSign on the data-sovereignty axis; Skribble adds Swiss ZertES alongside eIDAS, and Yousign is the most-adopted French QTSP with the smoothest migration UX. Universign (France, Paris) and Signaturit (Spain, Barcelona) are longer-running QTSPs with deeper enterprise track records, but both are now US-private-equity-owned (Bain Capital and PSG Equity) and hosted at rest on AWS, so CLOUD Act exposure: [[universign.cloud_act]]. All are Qualified Trust Service Providers (QTSPs) on the EU Trusted List. DocuSign, Inc. (NASDAQ: DOCU) is US-incorporated; its standard product issues advanced signatures, not eIDAS-qualified signatures. Verified European alternatives (7): - [Eversign (Xodo Sign)](https://euvetted.com/p/eversign): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Signaturit (Namirial)](https://euvetted.com/p/signaturit): hosted in Spain, CLOUD Act: material, ownership: eu_hq_us_funded - [Signicat](https://euvetted.com/p/signicat): hosted in Norway, CLOUD Act: material, ownership: other - [Skribble](https://euvetted.com/p/skribble): hosted in Switzerland, CLOUD Act: none, ownership: other - [Tresorit eSign](https://euvetted.com/p/tresorit-esign): hosted in Ireland, CLOUD Act: material, ownership: other - [Universign](https://euvetted.com/p/universign): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [Yousign](https://euvetted.com/p/yousign): hosted in France, CLOUD Act: minor, ownership: eu_hq_us_funded **Q: Is DocuSign usable under GDPR?** DocuSign publishes a Data Processing Addendum based on the EU Standard Contractual Clauses with post-Schrems II supplementary measures and offers an EU data residency option for stored signed documents. The service is legally usable from the EU. Two things keep procurement teams evaluating alternatives anyway: the underlying ownership (DocuSign, Inc. is US-incorporated and publicly listed on NASDAQ as DOCU), and the **eIDAS qualification status** of the signature itself. European-issued qualified electronic signatures (QES) carry stronger legal weight under eIDAS Regulation (EU) No 910/2014 than DocuSign's standard advanced signature, which is what prompts the alternative search for procurement teams handling regulated contracts. **Q: What is the difference between an advanced and qualified electronic signature?** Under eIDAS, three signature levels exist: simple electronic signature (SES), advanced electronic signature (AES), and qualified electronic signature (QES). Only QES carries legal equivalence to a handwritten signature across the EU and reverses the burden of proof in court. QES requires a Qualified Trust Service Provider (QTSP) listed on the EU Trusted List. Yousign, Universign, Signaturit, and Skribble (via partners) all operate as QTSPs and can issue QES; DocuSign's standard product is AES, with QES only via specific enterprise tiers and additional setup. **Q: Which DocuSign alternative has the strongest compliance profile?** On the sovereignty axis, the cleanest option mapped on this page is Skribble (Switzerland, Zurich), the only one with CLOUD Act exposure none: Swiss-incorporated, Swiss-hosted, no US sub-processor in the data path. Yousign (France, Caen) is EU-headquartered and EU-hosted with a public DPA, carrying only minor exposure, though it is US-VC-funded (ownership signal eu_hq_us_funded). Universign (France, Paris) and Signaturit (Spain, Barcelona, part of the Namirial group) are longer-running QTSPs with strong certification depth, but as of the July 2026 re-verify both are US-private-equity-owned (Namirial by Bain Capital, Signaturit by PSG Equity) and their shared platform is hosted at rest on Amazon Web Services with Twilio/SendGrid for OTP and email, which places them at CLOUD Act exposure material. All four are eIDAS-qualified trust service providers; for Swiss law work specifically, Skribble also supports ZertES (Swiss federal electronic signature law). **Q: Can my DocuSign templates transfer to the alternative?** Partially. Template field positions, signer roles, and routing logic transfer conceptually but need to be rebuilt in the new tool. The DocuSign template export (XML format) is not directly importable. The practical path is to print each active DocuSign template to PDF with field markers visible, then re-create in the new tool's template editor. For teams with 10–30 templates, this is a one-week task. Signed envelopes already in DocuSign remain accessible; they do not transfer to the new tool's history. **Q: What about my signed-document archive?** Signed documents in DocuSign should be downloaded and archived to your own document management system before any cancellation. DocuSign envelopes contain the signed PDF, the audit trail certificate, and any supporting documents; all should be exported and stored. Most teams keep these in their existing cloud storage (Tresorit, Proton Drive, Nextcloud, see our Dropbox alternatives page). Long-term archival of QES-signed documents needs to preserve the signature validation chain (typically 7–10 years per national law). **Q: Does DocuSign fall under the US CLOUD Act?** In practice, yes. DocuSign, Inc. is US-incorporated and publicly listed on NASDAQ as DOCU, meaning the consolidated group falls within CLOUD Act reach. A US authority can compel DocuSign to produce signed-document data it controls regardless of where that data is stored. DocuSign's EU data residency option reduces storage exposure but does not remove the underlying ownership question. Among the alternatives here, Skribble (Swiss-incorporated, Swiss-hosted, no US sub-processor) removes that direct exposure most cleanly. Universign and Signaturit reduce the ownership-jurisdiction question relative to a US-listed operator but do not eliminate US exposure: both are US-private-equity-owned and run at rest on AWS, so the directory records them at CLOUD Act exposure material rather than none. **Q: What is the cheapest European alternative to DocuSign?** Yousign (France, EU-headquartered, EU-hosted) typically offers the most accessible pricing among the eIDAS-qualified European alternatives, with SMB-range per-user plans. For non-regulated AES-level agreements where QES is not required, Eversign / Xodo Sign (Austria) is lower-cost but carries CLOUD Act exposure: [[eversign.cloud_act]] post-acquisition (now part of US-owned Xodo). For teams with very low volumes, most European QTSPs offer per-envelope pricing that is competitive with DocuSign at low volumes. Exact current pricing should be confirmed on each vendor's page. **Q: Is there a GDPR-compliant alternative to DocuSign?** All five alternatives mapped on this page operate under GDPR and publish data processing agreements. The strongest sovereignty posture (non-US ownership and non-US hosting with no CLOUD Act exposure) belongs to Skribble (Switzerland, Swiss-hosted, no US sub-processor in the data path). Yousign has EU-primary infrastructure and is EU-headquartered, with only minor exposure though it is US-VC-funded. Universign (France) and Signaturit (Spain, Namirial group) publish DPAs and are EU-operated, but both are US-private-equity-owned and AWS-hosted, so they sit at CLOUD Act exposure material. For a formal transfer impact assessment focused on signed-document data, Skribble is the recommended starting point, with Yousign next. **Q: Does any European alternative to DocuSign integrate with Salesforce or HubSpot?** Yes. Yousign and Universign both offer native Salesforce connectors, and Yousign has a HubSpot integration. Skribble supports Microsoft 365 natively. The long-tail enterprise integrations (Workday, Microsoft Dynamics) are typically available via Zapier or webhook rather than native connectors, in contrast to DocuSign's broader enterprise integration ecosystem. For teams where CRM-embedded signing is the primary workflow, Yousign is the European alternative with the deepest commercial integration story. ### European alternatives to Drift (Salesloft): https://euvetted.com/alternatives/drift _About Drift (Salesloft):_ US-incorporated conversational marketing, acquired by Salesloft (US) in 2023. Verified European alternatives (5): - [Crisp](https://euvetted.com/p/crisp): hosted in France, CLOUD Act: material, ownership: eu_owned - [Userlike (Lime Connect)](https://euvetted.com/p/userlike): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Customerly](https://euvetted.com/p/customerly): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [Tidio](https://euvetted.com/p/tidio): hosted in Poland, CLOUD Act: material, ownership: eu_hq_us_funded - [LiveChat (Text)](https://euvetted.com/p/livechat): hosted in Poland, CLOUD Act: minor, ownership: eu_owned ### European alternatives to Dropbox: https://euvetted.com/alternatives/dropbox _About Dropbox:_ US-incorporated cloud storage pioneer, NASDAQ-listed (DBX). Proton Drive (Switzerland, Geneva, EU-owned, EU-hosted, zero-knowledge E2E, CLOUD Act exposure: [[proton-drive.cloud_act]]) and Tresorit (Switzerland, Zurich, Swiss-Post-owned, zero-knowledge E2E, CLOUD Act exposure: [[tresorit.cloud_act]] via its sub-processor chain, while file contents stay end-to-end encrypted) are the strongest European alternatives to Dropbox. For cost-competitive Swiss hosting without the E2E premium, kDrive by Infomaniak (Switzerland, Geneva, EU-owned, EU-hosted, CLOUD Act exposure: [[kdrive.cloud_act]]) is the leading SMB choice. Most of the alternatives mapped here are EU/EEA- or Swiss-owned and European-hosted; each listing shows its verified exposure level. Verified European alternatives (18): - [Proton Drive](https://euvetted.com/p/proton-drive): hosted in Switzerland, CLOUD Act: none, ownership: other - [Tresorit](https://euvetted.com/p/tresorit): hosted in Ireland, CLOUD Act: material, ownership: other - [kDrive (Infomaniak)](https://euvetted.com/p/kdrive): hosted in Switzerland, CLOUD Act: none, ownership: other - [Internxt](https://euvetted.com/p/internxt): hosted in Spain, CLOUD Act: minor, ownership: eu_owned - [pCloud](https://euvetted.com/p/pcloud): hosted in Luxembourg, CLOUD Act: minor, ownership: other - [Nextcloud](https://euvetted.com/p/nextcloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [luckycloud](https://euvetted.com/p/luckycloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Filen](https://euvetted.com/p/filen): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Koofr](https://euvetted.com/p/koofr): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [STRATO HiDrive](https://euvetted.com/p/strato-hidrive): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [leitzcloud](https://euvetted.com/p/leitzcloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Jottacloud](https://euvetted.com/p/jottacloud): hosted in Norway, CLOUD Act: none, ownership: other - [Icedrive](https://euvetted.com/p/icedrive): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Orbifs](https://euvetted.com/p/orbifs): hosted in France, CLOUD Act: minor, ownership: other - [Hetzner Storage Share](https://euvetted.com/p/hetzner-storage-share): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Leviia](https://euvetted.com/p/leviia): hosted in France, CLOUD Act: none, ownership: eu_owned - [Oodrive](https://euvetted.com/p/oodrive): hosted in France, CLOUD Act: none, ownership: eu_owned - [Wimi](https://euvetted.com/p/wimi): hosted in France, CLOUD Act: none, ownership: eu_owned **Q: Is Dropbox usable under GDPR?** Dropbox publishes an EU Standard Contractual Clauses-based DPA with post-Schrems II supplementary measures, so using it from the EU is legally workable. What keeps it on procurement watchlists is the layer underneath that DPA: Dropbox, Inc. is US-incorporated and publicly listed (NASDAQ: DBX), the platform runs on US cloud infrastructure, and key sub-processors fall under CLOUD Act jurisdiction. That combination is usually the first thing a transfer impact assessment flags. **Q: Which Dropbox alternative has the strongest compliance profile?** This is the strongest category on the site. Eight of the nine alternatives mapped here are EU or Swiss-owned, EU-hosted, and carry no material CLOUD Act exposure. Among them: Proton Drive (Switzerland, Geneva, privacy-leading, zero-knowledge), kDrive (Switzerland, Geneva), Nextcloud (Germany, Stuttgart, self-hostable open source), luckycloud (Germany, Berlin), Filen (Germany, zero-knowledge E2E), Internxt (Spain, zero-knowledge), leitzcloud (Germany), and pCloud (Switzerland, EU-hosted in Luxembourg, though without end-to-end encryption by default). Tresorit (Switzerland, Zurich, enterprise E2E, zero-knowledge) remains the enterprise encryption benchmark, but its current sub-processor chain gives it a material CLOUD Act flag (CLOUD Act exposure: [[tresorit.cloud_act]]); file contents stay end-to-end encrypted regardless. **Q: Will my Dropbox file structure transfer?** Yes. Dropbox supports a clean file export and most European alternatives accept the same folder hierarchy on upload. The two things that need attention: shared-link URLs change (you will reissue the share links after migration), and any Dropbox-specific features like Paper documents and Showcase pages need to be exported separately. For most teams the migration is a straightforward folder-tree upload. **Q: Do the alternatives support team folder permissions and SSO?** Yes for both, on the business/enterprise tiers. Tresorit, kDrive, Nextcloud, and leitzcloud all support team folder permissions with role-based access and SSO (SAML 2.0, OIDC). Proton Drive's team features are newer but cover the same ground for typical SMB use. For SSO with Active Directory specifically, Nextcloud has the deepest integration. **Q: What about end-to-end encryption?** Three alternatives mapped here ship with end-to-end encryption by default: Tresorit (zero-knowledge for the file content and metadata), Proton Drive (zero-knowledge for content and most metadata), and Filen (zero-knowledge end-to-end). Internxt is also zero-knowledge by design. For teams where E2E is a compliance requirement (legal, healthcare, government), these are the four to evaluate first. **Q: Does Dropbox fall under the US CLOUD Act?** Yes. Dropbox, Inc. is a US-incorporated public company (NASDAQ: DBX), and the consolidated group falls within the reach of the US CLOUD Act regardless of where EU customer data is stored. For a Schrems II transfer impact assessment, this is the core question. The alternatives on this page with no material CLOUD Act exposure (Proton Drive, kDrive, Nextcloud, luckycloud, Filen, Internxt, leitzcloud, pCloud) are not US-incorporated, which removes direct CLOUD Act exposure. Tresorit is likewise not US-incorporated, but its current sub-processor chain carries a material CLOUD Act flag (CLOUD Act exposure: [[tresorit.cloud_act]]), even though file contents stay end-to-end encrypted. These classifications track incorporation and ownership as publicly disclosed, not how well any given vendor encrypts your files. **Q: Is there a GDPR-compliant alternative to Dropbox with end-to-end encryption?** Yes. Tresorit, Proton Drive, Filen, and Internxt all offer zero-knowledge end-to-end encryption by default, meaning the vendor cannot read your file content even in response to a legal request. All four publish GDPR-compliant data processing agreements and are EU or Swiss-owned and EU-hosted. Proton Drive, Filen, and Internxt carry no material CLOUD Act exposure; Tresorit carries a material flag via its current sub-processor chain (CLOUD Act exposure: [[tresorit.cloud_act]]), though zero-knowledge encryption means file contents stay unreadable to the vendor either way. For organisations with the strictest data-confidentiality requirements (legal, healthcare, public sector), these four are the recommended starting point. **Q: What is the cheapest European alternative to Dropbox?** Proton Drive and Filen both offer generous free tiers with end-to-end encryption. Filen is particularly competitive on paid storage pricing. kDrive by Infomaniak offers competitive monthly pricing for SMBs with a broader product bundle (Drive, Mail, Meet, Sign). For self-hosted deployments, Nextcloud eliminates per-seat cost entirely if you run your own infrastructure. It is the lowest-cost-per-TB option at scale. Confirm current pricing on each vendor's page as rates change frequently. **Q: Can a European cloud-storage tool still sync with my existing desktop and mobile apps?** Yes. Every alternative mapped on this page ships native desktop sync clients for Mac, Windows, and Linux, plus mobile apps for iOS and Android. Tresorit, kDrive, Nextcloud, and Proton Drive all mirror Dropbox's folder-sync UX. The practical difference is the sync client branding and setup process; day-to-day file access works identically. For office-document co-editing, pair the storage layer with OnlyOffice or Collabora. Both integrate natively with Nextcloud and kDrive. ### European alternatives to Evernote: https://euvetted.com/alternatives/evernote _About Evernote:_ Originally US, acquired by Italian Bending Spoons in 2022. Verified European alternatives (6): - [Cryptee](https://euvetted.com/p/cryptee): hosted in Estonia, CLOUD Act: material, ownership: eu_owned - [CryptPad](https://euvetted.com/p/cryptpad): hosted in France, CLOUD Act: none, ownership: eu_owned - [Joplin](https://euvetted.com/p/joplin): hosted in France, CLOUD Act: none, ownership: eu_owned - [Anytype](https://euvetted.com/p/anytype): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Nextcloud](https://euvetted.com/p/nextcloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Nuclino](https://euvetted.com/p/nuclino): hosted in Germany, CLOUD Act: material, ownership: eu_owned ### European alternatives to ExpressVPN: https://euvetted.com/alternatives/expressvpn _About ExpressVPN:_ British Virgin Islands-incorporated, owned by Kape Technologies (UK, listed) since 2021. Verified European alternatives (11): - [NordVPN](https://euvetted.com/p/nordvpn): hosted in Lithuania, CLOUD Act: minor, ownership: other - [AirVPN](https://euvetted.com/p/airvpn): hosted in Italy, CLOUD Act: none, ownership: eu_owned - [AzireVPN](https://euvetted.com/p/azirevpn): hosted in Sweden, CLOUD Act: material, ownership: us_owned - [CyberGhost](https://euvetted.com/p/cyberghost): hosted in Romania, CLOUD Act: minor, ownership: other - [F-Secure VPN](https://euvetted.com/p/f-secure-vpn): hosted in Finland, CLOUD Act: minor, ownership: eu_owned - [IVPN](https://euvetted.com/p/ivpn): hosted in Gibraltar, CLOUD Act: none, ownership: other - [Mullvad VPN](https://euvetted.com/p/mullvad): hosted in Sweden, CLOUD Act: none, ownership: eu_owned - [Opera VPN](https://euvetted.com/p/opera-vpn): hosted in Norway, CLOUD Act: material, ownership: other - [OVPN](https://euvetted.com/p/ovpn): hosted in Sweden, CLOUD Act: none, ownership: eu_owned - [Proton VPN](https://euvetted.com/p/protonvpn): hosted in Switzerland, CLOUD Act: none, ownership: other - [Surfshark](https://euvetted.com/p/surfshark): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned ### European alternatives to Fiserv: https://euvetted.com/alternatives/fiserv _About Fiserv:_ US-incorporated financial services tech giant, NYSE-listed (FI). Verified European alternatives (8): - [Worldline](https://euvetted.com/p/worldline): hosted in France, CLOUD Act: minor, ownership: eu_owned - [SumUp](https://euvetted.com/p/sumup): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [Adyen](https://euvetted.com/p/adyen): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Dintero](https://euvetted.com/p/dintero): hosted in Norway, CLOUD Act: minor, ownership: other - [Mollie](https://euvetted.com/p/mollie): hosted in Netherlands, CLOUD Act: material, ownership: eu_hq_us_funded - [Trustly](https://euvetted.com/p/trustly): hosted in Sweden, CLOUD Act: material, ownership: eu_hq_us_funded - [GoCardless](https://euvetted.com/p/gocardless): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Volt](https://euvetted.com/p/volt): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Formspree: https://euvetted.com/alternatives/formspree _About Formspree:_ US-incorporated form backend service. Verified European alternatives (3): - [Formspark](https://euvetted.com/p/formspark): hosted in Switzerland, CLOUD Act: minor, ownership: other - [Tripetto](https://euvetted.com/p/tripetto): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Formbricks](https://euvetted.com/p/formbricks): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to FreshBooks: https://euvetted.com/alternatives/freshbooks _About FreshBooks:_ Canadian SMB invoicing + accounting SaaS (Toronto). Non-EU North American. Verified European alternatives (8): - [Conta](https://euvetted.com/p/conta): hosted in Ireland, CLOUD Act: material, ownership: other - [Fiken](https://euvetted.com/p/fiken): hosted in Norway, CLOUD Act: material, ownership: other - [Lexware](https://euvetted.com/p/lexware): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Pennylane](https://euvetted.com/p/pennylane): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [PowerOffice Go](https://euvetted.com/p/poweroffice-go): hosted in Netherlands, CLOUD Act: material, ownership: eu_hq_us_funded - [Sage Accounting](https://euvetted.com/p/sage-accounting): hosted in United Kingdom, CLOUD Act: minor, ownership: other - [sevdesk](https://euvetted.com/p/sevdesk): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Visma eAccounting](https://euvetted.com/p/visma-eaccounting): hosted in Norway, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Freshdesk (Freshworks): https://euvetted.com/alternatives/freshdesk _About Freshdesk (Freshworks):_ Freshworks-owned helpdesk. Indian-founded, NASDAQ-listed (FRSH), US-headquartered. Verified European alternatives (4): - [Pureservice](https://euvetted.com/p/pureservice): hosted in Norway, CLOUD Act: material, ownership: other - [Customerly](https://euvetted.com/p/customerly): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [chatlyn](https://euvetted.com/p/chatlyn): hosted in Austria, CLOUD Act: minor, ownership: eu_owned - [Crisp](https://euvetted.com/p/crisp): hosted in France, CLOUD Act: material, ownership: eu_owned ### European alternatives to GitBook: https://euvetted.com/alternatives/gitbook _About GitBook:_ Originally French-founded, GitBook Inc. is now Delaware-incorporated with material US-VC funding. Verified European alternatives (4): - [BookStack](https://euvetted.com/p/bookstack): hosted in United Kingdom, CLOUD Act: none, ownership: other - [Wiki.js](https://euvetted.com/p/wiki-js): hosted in Canada, CLOUD Act: none, ownership: other - [Nuclino](https://euvetted.com/p/nuclino): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Outline](https://euvetted.com/p/outline): hosted in United States, CLOUD Act: direct, ownership: us_owned ### European alternatives to GitHub: https://euvetted.com/alternatives/github _About GitHub:_ US-incorporated code-hosting and collaboration platform owned by Microsoft (Redmond, US). Direct CLOUD Act exposure. Codeberg (Germany, Berlin, non-profit, EU-hosted, free, CLOUD Act exposure: [[codeberg.cloud_act]]) and Codebahn (Swedish operator, France-hosted, paid and supported with a public DPA, CLOUD Act exposure: [[codebahn.cloud_act]]) are the strongest European alternatives to GitHub. Both run the open-source Forgejo engine, so the same platform can also be self-hosted on your own EU infrastructure. GitHub itself is owned by Microsoft (US) and carries direct CLOUD Act exposure; the European options here are EU-owned and EU-hosted, and each listing shows its verified exposure level. Verified European alternatives (4): - [Codebahn](https://euvetted.com/p/codebahn): hosted in France, CLOUD Act: none, ownership: eu_owned - [Codeberg](https://euvetted.com/p/codeberg): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [GitLab by Stackhero](https://euvetted.com/p/stackhero-gitlab): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Planio](https://euvetted.com/p/planio): hosted in Germany, CLOUD Act: none, ownership: eu_owned **Q: Is GitHub usable under GDPR?** GitHub publishes a Standard Contractual Clauses-based DPA, so using it from the EU is legally workable. What keeps it on procurement watchlists is the layer underneath: GitHub, Inc. is a wholly owned subsidiary of Microsoft Corporation (US), and the consolidated group falls within reach of the US CLOUD Act regardless of where repository data is stored. That is usually the first thing a Schrems II transfer impact assessment flags. **Q: Which GitHub alternative has the strongest compliance profile?** Codebahn (Swedish operator, France-hosted) is the strongest on paper: it publishes a public DPA, names an all-EU sub-processor chain (Scaleway, Hetzner, Mollie, Crisp), and carries CLOUD Act exposure: [[codebahn.cloud_act]]. Codeberg (Germany) is a non-profit run on the association's own hardware in Berlin, EU-owned and EU-hosted with CLOUD Act exposure: [[codeberg.cloud_act]]; as a free community service it does not sign a commercial DPA, which is the one gap for procurement buyers who need a self-serve agreement. **Q: Will my repositories and git history transfer?** Yes. Both alternatives run Forgejo, whose migration importer pulls a repository over HTTPS with an access token and preserves the full git history, along with issues, pull requests, labels, milestones, releases, and the wiki in most cases. The git data itself is portable by design, so even a bare `git push --mirror` moves every branch and tag. Plan a little extra time for anything GitHub-specific (see the trade-off list below). **Q: Do the alternatives support CI/CD like GitHub Actions?** Both offer hosted CI, though not with GitHub Actions' exact syntax or marketplace. Codeberg provides Codeberg CI, based on Woodpecker; Codebahn includes EU-based CI runners on its paid organisation tiers. Migrating a pipeline means rewriting the workflow file and re-pointing any Actions-marketplace steps to equivalents, which is usually the largest single piece of a GitHub migration. **Q: Does GitHub fall under the US CLOUD Act?** Yes. GitHub, Inc. is a US-incorporated Microsoft subsidiary, so the CLOUD Act can in principle compel production of repository content, CI logs, and metadata regardless of storage location. The European alternatives here are not US-incorporated, which removes direct exposure: Codeberg (Germany) carries CLOUD Act exposure: [[codeberg.cloud_act]] and Codebahn (Swedish operator) carries CLOUD Act exposure: [[codebahn.cloud_act]]. These classifications track incorporation and ownership as publicly disclosed. **Q: Is there a free European alternative to GitHub?** Yes. Codeberg is a free, donation-funded non-profit forge, which makes it the natural home for open-source and personal projects. Codebahn is a paid, commercially supported service from [[codebahn.price_from]] per month, better suited to businesses that need a contractual DPA, hosted CI, and support. Both run the same open-source Forgejo engine. **Q: Can I self-host a GitHub alternative on EU infrastructure instead?** Yes. Forgejo and Gitea (both open source) and GitLab Community Edition run on any EU infrastructure such as Hetzner, OVHcloud, Scaleway, IONOS, or STACKIT. Self-hosting removes the platform operator as a third-party processor entirely, which is the strongest posture for code that contains trade secrets or regulated data. The trade-off is that you take on operations, backups, and security patching yourself. ### European alternatives to GitLab: https://euvetted.com/alternatives/gitlab _About GitLab:_ US-incorporated DevOps platform (GitLab Inc., Delaware; NASDAQ: GTLB). Direct CLOUD Act exposure despite remote-first roots. Codeberg (Germany, Berlin, non-profit, EU-hosted, free, CLOUD Act exposure: [[codeberg.cloud_act]]) and Codebahn (Swedish operator, France-hosted, paid and supported with a public DPA, CLOUD Act exposure: [[codebahn.cloud_act]]) are the strongest European alternatives to GitLab.com. Both run the open-source Forgejo engine. GitLab.com is operated by GitLab Inc. (US, NASDAQ: GTLB) and carries direct CLOUD Act exposure; note that self-hosting GitLab's own Community Edition on EU infrastructure is a separate, valid path, because there you are the operator, not GitLab Inc. Verified European alternatives (4): - [Codebahn](https://euvetted.com/p/codebahn): hosted in France, CLOUD Act: none, ownership: eu_owned - [Codeberg](https://euvetted.com/p/codeberg): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [GitLab by Stackhero](https://euvetted.com/p/stackhero-gitlab): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Planio](https://euvetted.com/p/planio): hosted in Germany, CLOUD Act: none, ownership: eu_owned **Q: Is GitLab.com a European service?** No. GitLab Inc. is US-incorporated (Delaware, listed on NASDAQ as GTLB), so the hosted GitLab.com service falls within reach of the US CLOUD Act in the same way as Microsoft-owned GitHub. GitLab's remote-first culture and European staff do not change the incorporation of the operating company. Self-hosting the open-source GitLab Community Edition on EU infrastructure is a different matter, because there the operator is you. **Q: Which GitLab alternative has the strongest compliance profile?** Codebahn (Swedish operator, France-hosted) is the strongest on paper: it publishes a public DPA, names an all-EU sub-processor chain (Scaleway, Hetzner, Mollie, Crisp), and carries CLOUD Act exposure: [[codebahn.cloud_act]]. Codeberg (Germany) is a non-profit run on the association's own hardware in Berlin, EU-owned and EU-hosted with CLOUD Act exposure: [[codeberg.cloud_act]]; as a free community service it does not sign a commercial DPA. **Q: Will my repositories and history transfer from GitLab?** Yes. Both alternatives run Forgejo, whose migration importer accepts a GitLab source and preserves the full git history along with issues, merge requests (imported as pull requests), labels, milestones, and releases in most cases. The git data itself is portable, so a bare `git push --mirror` moves every branch and tag regardless. **Q: Do the alternatives match GitLab's full DevOps feature set?** Not entirely, and this is the main trade-off. GitLab is a broad DevOps platform (CI/CD, container registry, security scanning, package management, and more in one product). The Forgejo-based alternatives cover the core forge workflow well (repositories, code review, issues, CI/CD, package and container registries) but do not replicate GitLab's full built-in security and compliance-scanning suite. Teams that rely heavily on those specific features should weigh self-hosting GitLab CE on EU infrastructure instead. **Q: Does GitLab.com fall under the US CLOUD Act?** Yes. GitLab Inc. is a US-incorporated public company, so the CLOUD Act can in principle compel production of repository content, CI logs, and metadata regardless of storage location. The European alternatives here are not US-incorporated: Codeberg (Germany) carries CLOUD Act exposure: [[codeberg.cloud_act]] and Codebahn (Swedish operator) carries CLOUD Act exposure: [[codebahn.cloud_act]]. Self-hosted GitLab CE run by an EU entity is likewise outside direct US reach. **Q: Is there a free European alternative to GitLab?** Yes. Codeberg is a free, donation-funded non-profit forge, ideal for open-source and personal projects. Codebahn is a paid, commercially supported service from [[codebahn.price_from]] per month, better suited to businesses that need a contractual DPA, hosted CI, and support. Both run the open-source Forgejo engine. **Q: Can I keep GitLab but host it in the EU myself?** Yes, and for GitLab specifically this is a common path. The open-source GitLab Community Edition can be self-hosted on any EU infrastructure such as Hetzner, OVHcloud, Scaleway, IONOS, or STACKIT. Running it under an EU legal entity removes direct US CLOUD Act exposure while keeping the exact GitLab feature set and workflow your team already knows. The trade-off is that you take on operations, upgrades, backups, and security patching. ### European alternatives to Gmail: https://euvetted.com/alternatives/gmail _About Gmail:_ Google LLC (Alphabet US, Nasdaq: GOOGL). Direct CLOUD Act exposure; primary anchor for privacy-flight searches. Verified European alternatives (12): - [Proton Mail](https://euvetted.com/p/proton-mail): hosted in Switzerland, CLOUD Act: none, ownership: other - [Tuta](https://euvetted.com/p/tuta): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Mailbox.org](https://euvetted.com/p/mailbox-org): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Posteo](https://euvetted.com/p/posteo): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Mailfence](https://euvetted.com/p/mailfence): hosted in Belgium, CLOUD Act: none, ownership: eu_owned - [StartMail](https://euvetted.com/p/startmail): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Infomaniak Mail (kSuite)](https://euvetted.com/p/infomaniak-mail): hosted in Switzerland, CLOUD Act: none, ownership: other - [Kolab Now](https://euvetted.com/p/kolab-now): hosted in Switzerland, CLOUD Act: none, ownership: other - [Mailo](https://euvetted.com/p/mailo): hosted in France, CLOUD Act: none, ownership: eu_owned - [Runbox](https://euvetted.com/p/runbox): hosted in Norway, CLOUD Act: none, ownership: other - [Soverin](https://euvetted.com/p/soverin): hosted in Netherlands, CLOUD Act: none, ownership: eu_owned - [LC-Connect](https://euvetted.com/p/lc-connect): hosted in Germany, CLOUD Act: none, ownership: eu_owned ### European alternatives to Google Analytics 4: https://euvetted.com/alternatives/google-analytics _About Google Analytics 4:_ Google-owned analytics. Schrems II prohibits use without SCCs and supplementary measures. Plausible (Estonia, Hetzner Falkenstein hosting) is the strongest European alternative to Google Analytics 4 on EU Vetted's editorial assessment. It is EU-owned, EU-hosted, CLOUD Act exposure: [[plausible.cloud_act]], fully cookieless, EU-only data flow. Pirsch (Germany, EU-owned, Germany-hosted, CLOUD Act exposure: [[pirsch.cloud_act]]) is the strongest DACH choice with German server-side analytics. For teams needing GA4-depth feature parity, Matomo (self-hostable, or cloud with German datacenter) is the most complete option. Verified European alternatives (10): - [GoatCounter](https://euvetted.com/p/goatcounter): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Matomo](https://euvetted.com/p/matomo): hosted in Germany, CLOUD Act: material, ownership: other - [Pirsch Analytics](https://euvetted.com/p/pirsch): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Plausible Analytics](https://euvetted.com/p/plausible): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Simple Analytics](https://euvetted.com/p/simple-analytics): hosted in Netherlands, CLOUD Act: none, ownership: eu_owned - [Trackboxx](https://euvetted.com/p/trackboxx): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Umami](https://euvetted.com/p/umami): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Wide Angle Analytics](https://euvetted.com/p/wide-angle-analytics): hosted in France, CLOUD Act: minor, ownership: eu_owned - [TelemetryDeck](https://euvetted.com/p/telemetrydeck): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [PostHog](https://euvetted.com/p/posthog): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded **Q: Is Google Analytics 4 usable under GDPR?** Google Analytics 4 is technically usable from the EU when configured with the EU-US Data Privacy Framework, Server-Side Tagging, and IP anonymisation. Several European data-protection authorities (CNIL in France, DSB in Austria, and Garante in Italy) have issued guidance that the standard GA4 configuration without supplementary measures does not meet Schrems II requirements. The legal-landscape complexity is what prompts buyers to evaluate alternatives, rather than any single ruling against GA4. **Q: Which Google Analytics alternative has the strongest compliance profile?** Among the alternatives mapped on this page, Plausible (Estonia, Hetzner Falkenstein hosting) has the strongest compliance profile: EU-owned, EU-hosted, CLOUD Act exposure: [[plausible.cloud_act]], and fully cookieless with an EU-only data flow. Pirsch (Germany, Gunzenhausen hosting), Simple Analytics (Netherlands), Wide Angle Analytics (Germany), and GoatCounter (Ireland) are all EU-owned and EU-hosted with no material CLOUD Act exposure and EU-primary infrastructure. **Q: Can I keep my historical Google Analytics data?** Yes. Google offers a BigQuery export for GA4 properties. You can export the full event-level dataset before cancellation. The historical data does not transfer into a European alternative's dashboards (each tool starts a fresh timeline from when you install its script), but the raw export is yours forever. For year-over-year analysis, most teams keep the BigQuery export as the historical record and run the new tool for forward-looking analytics. **Q: Will the new analytics tools work without a cookie banner?** Plausible, Pirsch, Simple Analytics, GoatCounter, and Wide Angle Analytics are cookieless by design, which means under most EU interpretations of the ePrivacy Directive you do not need a consent banner for them. This is a major UX win; the cookieless analytics tools also report 5–15% higher page-view counts than GA4 because they capture visitors who declined cookies. Matomo and PostHog are configurable for cookieless operation but ship cookie-based by default. **Q: How does the data quality compare to Google Analytics?** For page views, sources, devices, and basic conversion funnels: the European alternatives produce data that is directly comparable to GA4 and often more accurate (no consent-banner sample loss). For deep funnel analysis, attribution modelling, and integrations with Google Ads, GA4 still has more depth; Matomo and PostHog are closest among the European set. If your weekly workflow is page-traffic and source tracking, Plausible or Pirsch is enough; if you run paid acquisition campaigns with multi-touch attribution, evaluate Matomo on top. **Q: Does Google Analytics fall under the US CLOUD Act?** Yes. Google LLC is a subsidiary of Alphabet Inc., which is US-incorporated. The consolidated group falls within the reach of the US CLOUD Act regardless of which Google data centre processes the analytics data. Several European data-protection authorities (France's CNIL, Austria's DSB, Italy's Garante) have specifically cited CLOUD Act-related transfer concerns in their guidance on standard GA4 configurations. The alternatives assessed on this page (Plausible, Pirsch, Simple Analytics, Wide Angle Analytics, and GoatCounter) are EU-owned and EU-hosted, removing that exposure. That's a read of Alphabet's corporate structure, not a claim about any specific data request. **Q: Is there a GDPR-compliant alternative to Google Analytics?** Yes. The cookieless European alternatives (Plausible, Pirsch, Simple Analytics, GoatCounter, Wide Angle Analytics) are GDPR-compliant by design: EU data residency, no personal data collection (no IP storage, no fingerprinting, no cross-site tracking), and no consent banner required for analytics under most EU interpretations of the ePrivacy Directive. Matomo is GDPR-compliant when self-hosted in the EU or on Matomo Cloud's German datacenter, with configurable anonymisation. All are preferable to the supplementary-measures approach required for GA4. **Q: Can a European analytics tool handle e-commerce conversion tracking?** Yes. Plausible, Pirsch, Matomo, and Wide Angle Analytics all support custom event tracking that covers standard e-commerce patterns: product page views, add-to-cart, begin-checkout, purchase. Matomo has the most mature e-commerce analytics module, including revenue tracking, product performance, cart abandonment, and coupon analysis, comparable to GA4's e-commerce reports. Plausible and Pirsch handle the basics (purchase events, revenue attribution per source) with lighter implementation overhead. **Q: Can a European analytics tool replace Google Analytics for a SaaS product-analytics workflow?** For standard web analytics (page views, sessions, feature adoption events, conversion to signup), Plausible, Pirsch, and Matomo are direct replacements. For product-analytics depth (user paths, funnel drops, cohort retention, feature flags, session replay), PostHog (UK-based, UK-hosted with EU-region option) is the closest European-set equivalent to Mixpanel or Amplitude. Wide Angle Analytics adds event-level querying. For most SaaS product teams whose primary need is page-level traffic and event conversion rather than deep behavioural analytics, Plausible or Matomo handles the workflow. ### European alternatives to Google Cloud Platform (GCP): https://euvetted.com/alternatives/google-cloud _About Google Cloud Platform (GCP):_ Google-owned cloud platform. Direct CLOUD Act exposure regardless of EU region. Verified European alternatives (13): - [Aruba Cloud](https://euvetted.com/p/aruba-cloud): hosted in Italy, CLOUD Act: none, ownership: eu_owned - [Cleura](https://euvetted.com/p/cleura): hosted in Sweden, CLOUD Act: none, ownership: eu_owned - [Clever Cloud](https://euvetted.com/p/clever-cloud): hosted in France, CLOUD Act: none, ownership: eu_owned - [Hetzner](https://euvetted.com/p/hetzner): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Infomaniak Public Cloud](https://euvetted.com/p/infomaniak-public-cloud): hosted in Switzerland, CLOUD Act: none, ownership: other - [IONOS](https://euvetted.com/p/ionos): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [OVHcloud](https://euvetted.com/p/ovhcloud): hosted in France, CLOUD Act: none, ownership: eu_owned - [Scaleway](https://euvetted.com/p/scaleway): hosted in France, CLOUD Act: none, ownership: eu_owned - [Stackscale](https://euvetted.com/p/stackscale): hosted in Spain, CLOUD Act: none, ownership: eu_owned - [Thalassa Cloud](https://euvetted.com/p/thalassa-cloud): hosted in Netherlands, CLOUD Act: none, ownership: eu_owned - [Intility](https://euvetted.com/p/intility): hosted in Norway, CLOUD Act: material, ownership: other - [STACKIT](https://euvetted.com/p/stackit): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [T Cloud Public (formerly Open Telekom Cloud)](https://euvetted.com/p/open-telekom-cloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned ### European alternatives to Google Docs: https://euvetted.com/alternatives/google-docs _About Google Docs:_ Google-owned online word processor. Direct CLOUD Act exposure. Verified European alternatives (4): - [CryptPad](https://euvetted.com/p/cryptpad): hosted in France, CLOUD Act: none, ownership: eu_owned - [OnlyOffice](https://euvetted.com/p/onlyoffice): hosted in Latvia, CLOUD Act: minor, ownership: other - [Cryptee](https://euvetted.com/p/cryptee): hosted in Estonia, CLOUD Act: material, ownership: eu_owned - [Collabora Online](https://euvetted.com/p/collabora-online): hosted in United Kingdom, CLOUD Act: minor, ownership: other ### European alternatives to Google Drive: https://euvetted.com/alternatives/google-drive _About Google Drive:_ Google-owned cloud storage, part of Workspace. Direct CLOUD Act exposure. Proton Drive (Switzerland, Geneva, EU-adequacy jurisdiction, zero-knowledge end-to-end encryption, ISO 27001 + SOC 2, Foundation-owned) is the strongest European alternative to Google Drive on EU Vetted's editorial assessment. Tresorit (Switzerland, Zurich, Swiss-Post-owned, zero-knowledge E2E, CLOUD Act exposure: [[tresorit.cloud_act]] in its sub-processor chain; contents stay end-to-end encrypted) is the enterprise standard, and kDrive by Infomaniak (Switzerland, Geneva, own Swiss data centres, ISO 27001 + B Corp) is the best-value all-rounder and bundles Docs/Sheets-style collaboration. For teams who want the whole Workspace replaced, Nextcloud (Germany, self-hostable) pairs storage with OnlyOffice/Collabora office editing. Google Drive is operated by Google LLC (Alphabet Inc., NASDAQ: GOOGL) and carries direct US CLOUD Act exposure. Verified European alternatives (18): - [Proton Drive](https://euvetted.com/p/proton-drive): hosted in Switzerland, CLOUD Act: none, ownership: other - [Tresorit](https://euvetted.com/p/tresorit): hosted in Ireland, CLOUD Act: material, ownership: other - [kDrive (Infomaniak)](https://euvetted.com/p/kdrive): hosted in Switzerland, CLOUD Act: none, ownership: other - [Internxt](https://euvetted.com/p/internxt): hosted in Spain, CLOUD Act: minor, ownership: eu_owned - [pCloud](https://euvetted.com/p/pcloud): hosted in Luxembourg, CLOUD Act: minor, ownership: other - [Nextcloud](https://euvetted.com/p/nextcloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [luckycloud](https://euvetted.com/p/luckycloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Filen](https://euvetted.com/p/filen): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Koofr](https://euvetted.com/p/koofr): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [STRATO HiDrive](https://euvetted.com/p/strato-hidrive): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Jottacloud](https://euvetted.com/p/jottacloud): hosted in Norway, CLOUD Act: none, ownership: other - [Icedrive](https://euvetted.com/p/icedrive): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Orbifs](https://euvetted.com/p/orbifs): hosted in France, CLOUD Act: minor, ownership: other - [Hetzner Storage Share](https://euvetted.com/p/hetzner-storage-share): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Leviia](https://euvetted.com/p/leviia): hosted in France, CLOUD Act: none, ownership: eu_owned - [Wimi](https://euvetted.com/p/wimi): hosted in France, CLOUD Act: none, ownership: eu_owned - [leitzcloud](https://euvetted.com/p/leitzcloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Oodrive](https://euvetted.com/p/oodrive): hosted in France, CLOUD Act: none, ownership: eu_owned **Q: Is Google Drive usable under GDPR?** Google Drive (and Google Workspace) is legally usable from the EU: Google publishes an EU Standard Contractual Clauses-based Data Processing Addendum with post-Schrems II supplementary measures and offers EU data-region options for Workspace. The reason European teams still evaluate alternatives is the underlying ownership: Google LLC is a subsidiary of Alphabet Inc., which is US-incorporated and publicly listed (NASDAQ: GOOGL), so the consolidated group falls within the reach of the US CLOUD Act regardless of the storage region. For a transfer impact assessment, that ownership profile plus files stored in Google's cloud is what prompts the alternative search. **Q: Which Google Drive alternative has the strongest compliance profile?** Among the alternatives mapped on this page, Proton Drive (Switzerland) leads on privacy: zero-knowledge end-to-end encryption, Swiss jurisdiction under an EU adequacy decision, non-profit Proton Foundation ownership, ISO 27001 + SOC 2. kDrive by Infomaniak (Switzerland, own data centres, ISO 27001 + B Corp) carries CLOUD Act exposure: [[kdrive.cloud_act]]; Tresorit (Switzerland, Swiss-Post-owned) pairs zero-knowledge E2E with a material CLOUD Act flag from its current sub-processor chain (CLOUD Act exposure: [[tresorit.cloud_act]]), with file contents end-to-end encrypted regardless. For German hosting, luckycloud (Berlin) and Nextcloud (self-hosted) are EU-owned and EU-hosted (CLOUD Act exposure, luckycloud: [[luckycloud.cloud_act]], Nextcloud: [[nextcloud.cloud_act]]); Filen (Recklinghausen) keeps data at rest in Germany, with a transient US sub-processor accounting for its minor CLOUD Act flag (CLOUD Act exposure: [[filen.cloud_act]]); luckycloud and Filen ship zero-knowledge encryption by default. **Q: Does Google Drive fall under the US CLOUD Act?** Yes. Google LLC is a subsidiary of Alphabet Inc., which is US-incorporated and publicly listed (NASDAQ: GOOGL), so the consolidated group falls within the reach of the US CLOUD Act. A US authority can compel Google to produce data it controls regardless of where that data is stored, including EU Workspace regions. The European-owned and Swiss providers on this page (Proton Drive, Tresorit, kDrive, Nextcloud, luckycloud, Filen, Internxt, Koofr) are not US-incorporated, which removes that direct exposure. This reads Google's corporate structure, not any specific legal request. **Q: How do I migrate my files off Google Drive?** Use Google Takeout (takeout.google.com) to export your full Drive. It delivers a download (or a transfer to another cloud) of your files in their original formats. Native Google Docs, Sheets, and Slides are exported as Microsoft Office or OpenDocument files, so they open in any office suite. Install your new provider's desktop sync app, drop the exported files into the sync folder, and the folder tree carries over. Run both in parallel for a few weeks, verify everything appears on each device, then wind down Drive. For large Workspace tenants, Takeout can be scheduled per-user. **Q: What replaces Google Docs / Sheets real-time collaboration?** The closest European equivalent is OnlyOffice or Collabora Online, both of which provide real-time co-editing of documents, spreadsheets, and presentations in the browser with full Microsoft Office format compatibility. They integrate natively with Nextcloud and kDrive, so you get the storage layer and the collaborative office suite from one EU-hosted stack. Proton also ships Proton Docs (end-to-end-encrypted collaborative documents) inside Proton Drive. If live co-authoring is central to your team, evaluate kDrive (with its built-in office tools) or a Nextcloud + OnlyOffice deployment first. **Q: Which Google Drive alternatives have end-to-end encryption?** Proton Drive, Tresorit, Internxt, Filen, and luckycloud all ship zero-knowledge end-to-end encryption by default. The provider cannot read your file content even in response to a legal request. Koofr offers optional client-side encryption via Koofr Vault. kDrive and Jottacloud use server-side encryption (the provider holds the keys) but are EU/Swiss-hosted (CLOUD Act exposure, kDrive: [[kdrive.cloud_act]], Jottacloud: [[jottacloud.cloud_act]]). Google Drive is encrypted in transit and at rest, but Google holds the keys; client-side encryption exists in Workspace only on specific paid tiers and with setup. **Q: Can a European tool replace Google Workspace for a whole team, not just Drive?** For storage plus office collaboration, yes: Nextcloud (self-hosted or on an EU host) pairs Files with OnlyOffice/Collabora for documents, plus Talk for messaging and Groupware for mail/calendar. The closest single-stack Workspace replacement under your own control. kDrive bundles Drive with Mail, Docs, and Meet from one Swiss vendor. What you give up is Google's depth of real-time multi-user editing at very large scale and the Gmail/Meet/Workspace admin fabric. For the email side specifically, see our private-email alternatives; for video, our Google Meet and Zoom alternatives. **Q: What is the cheapest European alternative to Google Drive?** Filen (Germany, zero-knowledge, German data centres) is among the most aggressive on price, from around €1.99/month with a free tier. Koofr (Slovenia, German-hosted) starts even lower for small allocations. Proton Drive offers a generous 5 GB free tier with end-to-end encryption. pCloud and Internxt both offer one-time lifetime plans, cheaper than a subscription over several years. For teams self-hosting Nextcloud, there is no per-seat cost, only your own infrastructure. Confirm current pricing on each vendor's page, as storage rates change frequently. ### European alternatives to Google Forms: https://euvetted.com/alternatives/google-forms _About Google Forms:_ Google-owned form tool, part of Workspace. Direct CLOUD Act exposure. Verified European alternatives (7): - [Typeform](https://euvetted.com/p/typeform): hosted in United States, CLOUD Act: material, ownership: eu_hq_us_funded - [Tally](https://euvetted.com/p/tally): hosted in Belgium, CLOUD Act: material, ownership: eu_owned - [Formdesk](https://euvetted.com/p/formdesk): hosted in Netherlands, CLOUD Act: none, ownership: eu_owned - [Survicate](https://euvetted.com/p/survicate): hosted in Ireland, CLOUD Act: material, ownership: eu_owned - [LimeSurvey](https://euvetted.com/p/limesurvey): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Tripetto](https://euvetted.com/p/tripetto): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Formbricks](https://euvetted.com/p/formbricks): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Google Gemini: https://euvetted.com/alternatives/google-gemini _About Google Gemini:_ Google's LLM family. Direct CLOUD Act exposure via Alphabet Inc. Verified European alternatives (4): - [Infomaniak AI Tools](https://euvetted.com/p/infomaniak-ai-tools): hosted in Switzerland, CLOUD Act: none, ownership: other - [Aleph Alpha](https://euvetted.com/p/aleph-alpha): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [LightOn](https://euvetted.com/p/lighton): hosted in France, CLOUD Act: none, ownership: eu_owned - [Mistral AI](https://euvetted.com/p/mistral-ai): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Google Meet: https://euvetted.com/alternatives/google-meet _About Google Meet:_ Google's video conferencing, part of Workspace. Direct CLOUD Act exposure. Verified European alternatives (4): - [kMeet (Infomaniak)](https://euvetted.com/p/kmeet): hosted in Switzerland, CLOUD Act: none, ownership: other - [Pexip](https://euvetted.com/p/pexip): hosted in Norway, CLOUD Act: material, ownership: other - [sipgate](https://euvetted.com/p/sipgate): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Whereby](https://euvetted.com/p/whereby): hosted in Ireland, CLOUD Act: minor, ownership: other ### European alternatives to Google Photos: https://euvetted.com/alternatives/google-photos _About Google Photos:_ Google's consumer photo storage and search. Direct CLOUD Act exposure. Verified European alternatives (4): - [Cryptee](https://euvetted.com/p/cryptee): hosted in Estonia, CLOUD Act: material, ownership: eu_owned - [Proton Drive](https://euvetted.com/p/proton-drive): hosted in Switzerland, CLOUD Act: none, ownership: other - [pCloud](https://euvetted.com/p/pcloud): hosted in Luxembourg, CLOUD Act: minor, ownership: other - [Filen](https://euvetted.com/p/filen): hosted in Germany, CLOUD Act: minor, ownership: eu_owned ### European alternatives to Gusto: https://euvetted.com/alternatives/gusto _About Gusto:_ San Francisco-headquartered payroll + HR for US SMBs. US-only operating but referenced as the SMB HR benchmark. Verified European alternatives (3): - [Factorial](https://euvetted.com/p/factorial): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Personio](https://euvetted.com/p/personio): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Sage HR](https://euvetted.com/p/sage-hr): hosted in Ireland, CLOUD Act: minor, ownership: other ### European alternatives to Heap: https://euvetted.com/alternatives/heap _About Heap:_ US-incorporated autocapture analytics, acquired by Contentsquare (FR) in 2024. Verified European alternatives (3): - [PostHog](https://euvetted.com/p/posthog): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [Matomo](https://euvetted.com/p/matomo): hosted in Germany, CLOUD Act: material, ownership: other - [TelemetryDeck](https://euvetted.com/p/telemetrydeck): hosted in Germany, CLOUD Act: material, ownership: eu_owned ### European alternatives to HelloSign (Dropbox Sign): https://euvetted.com/alternatives/hellosign _About HelloSign (Dropbox Sign):_ Originally US HelloSign, acquired by Dropbox (US) in 2019, now Dropbox Sign. Verified European alternatives (5): - [Eversign (Xodo Sign)](https://euvetted.com/p/eversign): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Signaturit (Namirial)](https://euvetted.com/p/signaturit): hosted in Spain, CLOUD Act: material, ownership: eu_hq_us_funded - [Skribble](https://euvetted.com/p/skribble): hosted in Switzerland, CLOUD Act: none, ownership: other - [Tresorit eSign](https://euvetted.com/p/tresorit-esign): hosted in Ireland, CLOUD Act: material, ownership: other - [Yousign](https://euvetted.com/p/yousign): hosted in France, CLOUD Act: minor, ownership: eu_hq_us_funded ### European alternatives to Help Scout: https://euvetted.com/alternatives/help-scout _About Help Scout:_ US-incorporated customer support platform, Boston HQ. Verified European alternatives (6): - [chatlyn](https://euvetted.com/p/chatlyn): hosted in Austria, CLOUD Act: minor, ownership: eu_owned - [Crisp](https://euvetted.com/p/crisp): hosted in France, CLOUD Act: material, ownership: eu_owned - [Userlike (Lime Connect)](https://euvetted.com/p/userlike): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [LiveChat (Text)](https://euvetted.com/p/livechat): hosted in Poland, CLOUD Act: minor, ownership: eu_owned - [Customerly](https://euvetted.com/p/customerly): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [Tidio](https://euvetted.com/p/tidio): hosted in Poland, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Hetzner: https://euvetted.com/alternatives/hetzner _About Hetzner:_ Family-founded German hyperscaler alternative (Gunzenhausen, 1997). Cross-reference: listed in our directory as a product. Scaleway (France, Paris), OVHcloud (France, Roubaix), and IONOS (Germany, Frankfurt) are the strongest European alternatives to Hetzner on EU Vetted's editorial assessment. All three are EU-owned and EU-hosted, and all three add what Hetzner deliberately leaves out: managed databases, managed Kubernetes, and enterprise support tiers. Nobody in the European market beats Hetzner on price per vCPU; the reason to move is service breadth, not sovereignty. Verified European alternatives (12): - [Aruba Cloud](https://euvetted.com/p/aruba-cloud): hosted in Italy, CLOUD Act: none, ownership: eu_owned - [Cleura](https://euvetted.com/p/cleura): hosted in Sweden, CLOUD Act: none, ownership: eu_owned - [Contabo](https://euvetted.com/p/contabo): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Exoscale](https://euvetted.com/p/exoscale): hosted in Switzerland, CLOUD Act: minor, ownership: other - [netcup](https://euvetted.com/p/netcup): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [OVHcloud](https://euvetted.com/p/ovhcloud): hosted in France, CLOUD Act: none, ownership: eu_owned - [Scaleway](https://euvetted.com/p/scaleway): hosted in France, CLOUD Act: none, ownership: eu_owned - [STACKIT](https://euvetted.com/p/stackit): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Stackscale](https://euvetted.com/p/stackscale): hosted in Spain, CLOUD Act: none, ownership: eu_owned - [T Cloud Public (formerly Open Telekom Cloud)](https://euvetted.com/p/open-telekom-cloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [UpCloud](https://euvetted.com/p/upcloud): hosted in Finland, CLOUD Act: none, ownership: eu_owned - [IONOS](https://euvetted.com/p/ionos): hosted in Germany, CLOUD Act: none, ownership: eu_owned **Q: Is Hetzner itself not European enough?** Hetzner is one of the strongest sovereignty profiles in our directory: family-founded in Gunzenhausen in 1997, EU-owned, EU-hosted, ISO 27001 and BSI C5 Type 2 attested, CLOUD Act exposure: [[hetzner.cloud_act]]. People searching for Hetzner alternatives are usually not leaving for compliance reasons. They leave because Hetzner intentionally ships a minimal product: compute, storage, network, and very little in the way of managed services. **Q: Why do teams move away from Hetzner?** Four reasons come up repeatedly. First, no managed databases and no managed Kubernetes, so your team operates Postgres, Redis, and the control plane yourself. Second, enterprise procurement: some buyers need contractual SLAs, named account managers, and certifications like SecNumCloud that Hetzner does not hold. Third, GPU capacity: Hetzner's dedicated GPU line is narrow and often sold out. Fourth, account vetting: Hetzner's strict signup checks are good for abuse prevention but a real hurdle for some legitimate teams. **Q: Which alternative is closest to Hetzner on price?** None of them match it, and it is worth saying that plainly: Hetzner's price per vCPU and per GB of storage is the benchmark for the whole European market. Contabo (Munich, VPS from about €5/month) and Aruba Cloud (Italy, entry plans from about €1/month) compete at the budget end. IONOS and Scaleway entry instances start around €2/month but the mid-range costs more than Hetzner's equivalent. Budget 1.5 to 3 times your current Hetzner bill for a like-for-like footprint elsewhere, less any savings from dropping self-managed services. **Q: Which alternative offers managed Kubernetes and managed databases?** Scaleway (managed Kubernetes, managed PostgreSQL and MySQL, serverless containers), OVHcloud (managed Kubernetes plus managed Postgres, MySQL, Kafka, Redis and more), IONOS (managed Kubernetes and managed databases), STACKIT (managed Kubernetes and databases with a DACH enterprise frame), and UpCloud (managed Kubernetes and managed databases from Helsinki). This is the single most common reason teams outgrow Hetzner, and every major alternative on this page covers it. **Q: I need SecNumCloud for a French public-sector contract. Where do I go?** OVHcloud and Scaleway. Both are French, EU-owned, and hold ANSSI SecNumCloud qualification on specific product ranges (always check that the specific tier you buy is inside the qualified scope, not just the vendor logo). Hetzner holds ISO 27001 and BSI C5 Type 2, which covers German and most EU procurement, but SecNumCloud is a French qualification Hetzner does not have. **Q: Can I download my Hetzner snapshots and move them?** No. Hetzner Cloud snapshots and images cannot be downloaded or exported. Plan the migration at the filesystem and application layer instead: rebuild servers from your provisioning code on the new provider, then move data with rsync, database replication, or object-storage sync. If your servers are not yet defined in code, writing the Terraform or Ansible first makes the move far safer. **Q: What happens to my traffic bill after Hetzner?** Check this before signing anything. Hetzner includes 20 TB of egress per cloud server, which is unusually generous. Most alternatives meter egress at some point: pricing models differ per provider and per product line, and a traffic-heavy workload that costs nothing extra on Hetzner can add real money elsewhere. Estimate your monthly egress from Hetzner's traffic graphs and price it on the target provider before you commit. **Q: Is there a GPU option among the European alternatives?** Scaleway and OVHcloud both sell GPU instances on EU soil and are the usual next stop when Hetzner's GPU line is sold out or too narrow. For sustained large training workloads, compare the committed-use pricing on both; on-demand GPU pricing anywhere in Europe is significantly above US hyperscaler spot capacity, so the sovereignty premium is real in this segment. ### European alternatives to Hotjar: https://euvetted.com/alternatives/hotjar _About Hotjar:_ Maltese-founded heatmap/session-replay tool, now part of French Contentsquare group. Verified European alternatives (4): - [Matomo](https://euvetted.com/p/matomo): hosted in Germany, CLOUD Act: material, ownership: other - [Plausible Analytics](https://euvetted.com/p/plausible): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [PostHog](https://euvetted.com/p/posthog): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [Formbricks](https://euvetted.com/p/formbricks): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to HubSpot: https://euvetted.com/alternatives/hubspot _About HubSpot:_ US-owned all-in-one marketing/sales/service CRM. Direct CLOUD Act exposure. centralstationCRM (Germany) is the strongest European CRM alternative to HubSpot for EU compliance: German-owned, German-hosted, no CLOUD Act exposure, built for DACH SMBs. For an all-in-one ERP+CRM replacement, weclapp (Germany, Frankfurt) is the leading European option: EU-owned, EU-hosted, with a public DPA and disclosed sub-processors. No single European tool matches HubSpot's full marketing+sales+service bundle; the realistic strategy is to unbundle across a European CRM plus a European email platform. Verified European alternatives (9): - [Capsule CRM](https://euvetted.com/p/capsule): hosted in United States, CLOUD Act: material, ownership: other - [centralstationCRM](https://euvetted.com/p/centralstationcrm): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Lime CRM](https://euvetted.com/p/lime-crm): hosted in Sweden, CLOUD Act: minor, ownership: eu_owned - [Pipedrive](https://euvetted.com/p/pipedrive): hosted in Estonia, CLOUD Act: material, ownership: eu_hq_us_funded - [Salesflare](https://euvetted.com/p/salesflare): hosted in Belgium, CLOUD Act: material, ownership: eu_owned - [SuperOffice](https://euvetted.com/p/superoffice): hosted in Norway, CLOUD Act: material, ownership: eu_hq_us_funded - [Teamleader](https://euvetted.com/p/teamleader): hosted in Ireland, CLOUD Act: material, ownership: other - [weclapp](https://euvetted.com/p/weclapp): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Workbooks](https://euvetted.com/p/workbooks): hosted in United Kingdom, CLOUD Act: material, ownership: other **Q: Is HubSpot usable under GDPR?** HubSpot publishes a Data Processing Addendum based on the EU Standard Contractual Clauses with post-Schrems II supplementary measures, so it is legally usable from the EU. What still sends procurement teams looking elsewhere is the ownership and infrastructure profile: HubSpot, Inc. is US-incorporated and publicly listed (NYSE: HUBS), the platform runs on US cloud infrastructure with EU-region failover, and the parent corporate structure means CLOUD Act jurisdiction applies. For a transfer impact assessment, that combination is what prompts the alternative search. **Q: No European tool matches HubSpot's full marketing+sales+service breadth. What's the practical strategy?** Correct: HubSpot's all-in-one bundle (CRM + email marketing + service desk + CMS + analytics) does not have a single-vendor European equivalent at the same depth. The realistic strategy is to unbundle: use a European CRM (Pipedrive, Teamleader, weclapp, centralstationCRM) as the system of record, pair with a European email marketing tool (CleverReach, MailerLite, see our Mailchimp alternatives page), and add a European helpdesk (Crisp, Userlike) if needed. The total monthly cost typically lands below an equivalent HubSpot Marketing Hub bundle. **Q: Which HubSpot alternative has the strongest compliance profile?** Among the alternatives mapped on this page, centralstationCRM (Germany) has the strongest profile: EU-owned, German-hosted, no material CLOUD Act exposure, with a public DPA. weclapp (Germany, Frankfurt) and Lime CRM (Sweden) are also EU-owned and EU-hosted with public DPAs, though weclapp carries some shared sub-processor exposure. Pipedrive (Estonia), Teamleader (Belgium), and Salesflare (Belgium) are EU-owned with primary EU infrastructure but all have material CLOUD Act exposure via US sub-processors. **Q: Can I export my HubSpot data?** Yes. HubSpot supports CSV export of Contacts, Companies, Deals, and Tickets via *Settings → Account Management → Account Defaults → Export*. The exports preserve custom properties, owner assignments, and timestamps. What does not transfer cleanly: HubSpot workflows (sequences, automations), Marketing emails (these export as HTML but the analytics history stays in HubSpot), and Landing Pages. Plan to rebuild these in the new tool rather than attempt to import. **Q: How does ad-tracking transfer work without HubSpot Marketing Hub?** HubSpot Marketing Hub bundles ad-platform tracking pixels into the contact timeline. After migration, you can replicate this with a European stack: install Google Tag Manager (or self-hosted equivalent) on your site, route conversion events to your European analytics tool (Plausible Goals, Pirsch Events, Wide Angle Analytics; see our Google Analytics alternatives page), and import the conversion-tagged contacts into your CRM via webhook. The setup is more bespoke than HubSpot's bundled flow but completely tractable for a marketing-ops practitioner. **Q: Does HubSpot fall under the US CLOUD Act?** Yes. HubSpot, Inc. is a US-incorporated public company (NYSE: HUBS), and the consolidated group falls within the reach of the US CLOUD Act regardless of where EU customer data is stored. This means EU-region data storage on its own does not eliminate jurisdiction for a Schrems II transfer impact assessment. centralstationCRM (Germany) and weclapp (Germany) are EU-incorporated with no US parent, which removes direct CLOUD Act exposure for CRM data. **Q: Is there a GDPR-compliant CRM alternative to HubSpot?** Yes. All nine European alternatives mapped on this page publish GDPR-compliant data processing agreements. The compliance depth varies significantly: centralstationCRM (Germany) has documented German hosting, EU ownership, and no material CLOUD Act exposure; Pipedrive (Estonia) and Teamleader (Belgium) have EU ownership but material CLOUD Act exposure via US sub-processors. For European procurement seeking the cleanest CRM compliance profile, centralstationCRM is the strongest pure-CRM choice. **Q: What is the cheapest European alternative to HubSpot?** centralstationCRM offers a free tier for small teams, making it the lowest-cost entry point among the European CRM alternatives mapped here. Pipedrive and Salesflare both have competitive per-seat pricing with free trials. weclapp is priced as an all-in-one ERP+CRM platform, so the per-seat cost is higher but replaces multiple tools. The total-cost comparison depends on which HubSpot hubs you are currently paying for. The CRM-only tier of HubSpot is free, so the relevant comparison is against HubSpot Marketing Hub or Sales Hub paid plans. **Q: Can a European CRM still integrate with Google Workspace and Microsoft 365?** Yes. Every European CRM mapped on this page supports two-way email sync with Google Workspace and Microsoft 365. Pipedrive, Teamleader, weclapp, and Salesflare all have direct Google Workspace and Microsoft 365 integrations for calendar sync and email tracking. This is the most critical integration to verify before committing to a migration, as it is the feature most likely to determine day-to-day sales team adoption. **Q: Can a European alternative handle HubSpot marketing automation workflows?** Partially, with an unbundled approach. No single European CRM replicates HubSpot Marketing Hub's full workflow engine at the same depth. The realistic European path is to pair a European CRM (centralstationCRM, Pipedrive, weclapp) with a European email marketing tool (CleverReach, MailerLite, Maileon) that handles campaign automation, and connect them via Zapier or Make. This is more bespoke than HubSpot's bundled workflow but gives you full data-sovereignty across every component. ### European alternatives to iCloud Mail: https://euvetted.com/alternatives/icloud-mail _About iCloud Mail:_ Apple Inc. (Nasdaq: AAPL). Direct CLOUD Act exposure; consumer-skewed. Verified European alternatives (9): - [Proton Mail](https://euvetted.com/p/proton-mail): hosted in Switzerland, CLOUD Act: none, ownership: other - [Tuta](https://euvetted.com/p/tuta): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Mailbox.org](https://euvetted.com/p/mailbox-org): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [StartMail](https://euvetted.com/p/startmail): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Infomaniak Mail (kSuite)](https://euvetted.com/p/infomaniak-mail): hosted in Switzerland, CLOUD Act: none, ownership: other - [Kolab Now](https://euvetted.com/p/kolab-now): hosted in Switzerland, CLOUD Act: none, ownership: other - [Mailo](https://euvetted.com/p/mailo): hosted in France, CLOUD Act: none, ownership: eu_owned - [Runbox](https://euvetted.com/p/runbox): hosted in Norway, CLOUD Act: none, ownership: other - [Soverin](https://euvetted.com/p/soverin): hosted in Netherlands, CLOUD Act: none, ownership: eu_owned ### European alternatives to Intercom: https://euvetted.com/alternatives/intercom _About Intercom:_ US-owned customer messaging platform. Direct CLOUD Act exposure. Crisp (France, Nantes) is the strongest European alternative to Intercom on EU Vetted's compliance signals: EU-owned, French-hosted, CLOUD Act exposure: [[crisp.cloud_act]], a multi-channel inbox, and an opt-in AI tier using European LLM routing. For DACH teams, Userlike (Germany, Cologne) is the most-adopted option: EU-owned, German-hosted, ISO 27001 certified, with strong German enterprise references. Intercom, Inc. (San Francisco) is US-incorporated and falls under CLOUD Act jurisdiction. Verified European alternatives (6): - [Crisp](https://euvetted.com/p/crisp): hosted in France, CLOUD Act: material, ownership: eu_owned - [Userlike (Lime Connect)](https://euvetted.com/p/userlike): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [LiveChat (Text)](https://euvetted.com/p/livechat): hosted in Poland, CLOUD Act: minor, ownership: eu_owned - [Customerly](https://euvetted.com/p/customerly): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [chatlyn](https://euvetted.com/p/chatlyn): hosted in Austria, CLOUD Act: minor, ownership: eu_owned - [Tidio](https://euvetted.com/p/tidio): hosted in Poland, CLOUD Act: material, ownership: eu_hq_us_funded **Q: Is Intercom usable under GDPR?** Intercom publishes a Data Processing Addendum based on the EU Standard Contractual Clauses with post-Schrems II supplementary measures and offers EU data residency on enterprise tiers. The service is legally usable from the EU. What keeps SaaS teams evaluating alternatives anyway is the underlying ownership: Intercom, Inc. is US-incorporated (San Francisco), with sub-processors that fall under CLOUD Act jurisdiction. For SaaS teams whose customer chat logs contain personal data, account questions, or product feedback, the ownership profile is what prompts the alternative search. **Q: Which Intercom alternative has the strongest compliance profile?** Among the alternatives mapped on this page, Crisp (France, Nantes) has the strongest signal set: EU-owned, EU-hosted, CLOUD Act exposure: [[crisp.cloud_act]]. Userlike (Germany, Cologne), LiveChat (Poland), Customerly (Ireland), and chatlyn (Austria) are EU-owned with EU-primary infrastructure and carry CLOUD Act exposure via certain sub-processors (Userlike: [[userlike.cloud_act]], LiveChat: [[livechat.cloud_act]], Customerly: [[customerly.cloud_act]], chatlyn: [[chatlyn.cloud_act]]). Tidio (Poland) has heavier sub-processor exposure (CLOUD Act exposure: [[tidio.cloud_act]]), making its sovereignty story less clean. For DACH SMBs specifically, Userlike and Crisp are the procurement-clearest picks. **Q: Can I migrate my Intercom conversation history?** Yes, but with caveats. Intercom supports CSV export of conversations and contacts via *Settings → Data → Export*. The exports preserve conversation metadata (timestamps, assignees, tags) and message bodies, but inline images and file attachments are referenced as URLs that may expire after Intercom cancellation. Download attachments separately before cancellation. Most European alternatives accept CSV import for the customer database; conversation history is typically archived as PDF for compliance rather than imported live. **Q: What about Intercom's product tour and onboarding features?** Intercom's Product Tours and onboarding messages are a separate product surface beyond the core messaging tool. European messaging alternatives ship lighter onboarding features by default. chatlyn has hotel-industry-specific onboarding flows and Userlike has a basic in-product messaging system, but none match Intercom Product Tours at full depth. If product onboarding is core to your workflow, plan to pair the European customer messaging tool with a dedicated product-tour vendor or a self-built onboarding overlay. **Q: Does any European alternative match Intercom's AI features?** Most European alternatives ship without LLM-based features by default, since embedding US LLMs into customer chat data would defeat the data-sovereignty argument. Crisp offers an AI feature opt-in with European LLM routing. For teams where AI customer-support automation is core, evaluate Crisp's AI tier specifically; for others, the European tools' approach of leaving AI as an explicit opt-in is the compliance-preferable default. **Q: Does Intercom fall under the US CLOUD Act?** In practice, yes. Intercom, Inc. is US-incorporated and headquartered in San Francisco, meaning the consolidated group falls within CLOUD Act reach. A US authority can compel Intercom to produce customer conversation data it controls regardless of where that data is stored. Intercom's EU data residency option reduces storage exposure but does not remove the underlying ownership question. Crisp (France), EU-owned, French-hosted, CLOUD Act exposure: [[crisp.cloud_act]], is the alternative on this page with the cleanest sovereignty profile. **Q: What is the cheapest European alternative to Intercom?** Crisp (France) has a free tier for up to two agents, making it the most accessible entry point among the European alternatives. Tidio (Poland) also has a free tier and is typically the lowest-cost commercial option, though its CLOUD Act exposure ([[tidio.cloud_act]]) is heavier than Crisp's ([[crisp.cloud_act]]). Userlike (Germany) starts at SMB-accessible pricing for small teams. Exact current pricing should be confirmed on each vendor's page, as rates change frequently. **Q: Is there a GDPR-compliant alternative to Intercom?** All six alternatives mapped on this page operate under GDPR and publish data processing agreements. The strongest GDPR posture belongs to Crisp (France): EU ownership, EU hosting, CLOUD Act exposure: [[crisp.cloud_act]]. Userlike, LiveChat, Customerly, and chatlyn are EU-owned with EU-primary infrastructure and carry CLOUD Act exposure through certain sub-processors (Userlike: [[userlike.cloud_act]], LiveChat: [[livechat.cloud_act]], Customerly: [[customerly.cloud_act]], chatlyn: [[chatlyn.cloud_act]]). For a formal transfer impact assessment, Crisp is the recommended starting point, as it eliminates the CLOUD Act ownership question that Intercom raises. **Q: Which Intercom alternative is best for SaaS product-led growth teams?** Customerly (Ireland) is the European pick built around product-led growth, combining live chat, in-product NPS surveys, and basic email automation in one tool designed to convert visitors into trial sign-ups. It is EU-owned and EU-hosted with a public DPA. For teams focused purely on multi-channel support quality rather than conversion funnels, Crisp (France), EU-owned, French-hosted, CLOUD Act exposure: [[crisp.cloud_act]], has the strongest sovereignty profile with comparable feature depth. chatlyn (Austria) is purpose-built for hospitality and is not the right fit for generic SaaS PLG workflows. ### European alternatives to Jira: https://euvetted.com/alternatives/jira _About Jira:_ Atlassian-owned issue tracker. Australian-founded, NASDAQ-listed (TEAM), now US-headquartered. Verified European alternatives (5): - [Taiga](https://euvetted.com/p/taiga): hosted in Spain, CLOUD Act: none, ownership: eu_owned - [factro](https://euvetted.com/p/factro): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Kantree](https://euvetted.com/p/kantree): hosted in France, CLOUD Act: none, ownership: eu_owned - [MeisterTask](https://euvetted.com/p/meistertask): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Teamwork.com](https://euvetted.com/p/teamwork): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned ### European alternatives to JotForm: https://euvetted.com/alternatives/jotform _About JotForm:_ US-incorporated form builder with Turkish founders, San Francisco HQ. Verified European alternatives (4): - [Formdesk](https://euvetted.com/p/formdesk): hosted in Netherlands, CLOUD Act: none, ownership: eu_owned - [Tripetto](https://euvetted.com/p/tripetto): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Typeform](https://euvetted.com/p/typeform): hosted in United States, CLOUD Act: material, ownership: eu_hq_us_funded - [Tally](https://euvetted.com/p/tally): hosted in Belgium, CLOUD Act: material, ownership: eu_owned ### European alternatives to LastPass: https://euvetted.com/alternatives/lastpass _About LastPass:_ US-incorporated password manager, owned by GoTo (US PE: Francisco Partners + Elliott Management). Verified European alternatives (11): - [LC-Pass](https://euvetted.com/p/lc-pass): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [heylogin](https://euvetted.com/p/heylogin): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [KeePassXC](https://euvetted.com/p/keepassxc): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [NordPass](https://euvetted.com/p/nordpass): hosted in Lithuania, CLOUD Act: material, ownership: eu_owned - [Padloc](https://euvetted.com/p/padloc): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Passbolt](https://euvetted.com/p/passbolt): hosted in Luxembourg, CLOUD Act: none, ownership: eu_owned - [pCloud Pass](https://euvetted.com/p/pcloud-pass): hosted in Luxembourg, CLOUD Act: minor, ownership: other - [Proton Pass](https://euvetted.com/p/proton-pass): hosted in Switzerland, CLOUD Act: none, ownership: other - [Psono](https://euvetted.com/p/psono): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Uniqkey](https://euvetted.com/p/uniqkey): hosted in Denmark, CLOUD Act: none, ownership: eu_owned - [Vaultwarden](https://euvetted.com/p/vaultwarden): hosted in Spain, CLOUD Act: none, ownership: eu_owned ### European alternatives to Linear: https://euvetted.com/alternatives/linear _About Linear:_ US-incorporated issue tracker for product teams, San Francisco HQ. Verified European alternatives (4): - [Taiga](https://euvetted.com/p/taiga): hosted in Spain, CLOUD Act: none, ownership: eu_owned - [Kantree](https://euvetted.com/p/kantree): hosted in France, CLOUD Act: none, ownership: eu_owned - [MeisterTask](https://euvetted.com/p/meistertask): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [factro](https://euvetted.com/p/factro): hosted in Germany, CLOUD Act: none, ownership: eu_owned ### European alternatives to Linode (Akamai): https://euvetted.com/alternatives/linode _About Linode (Akamai):_ US-incorporated VPS provider, acquired by Akamai (US) in 2022. Verified European alternatives (6): - [Contabo](https://euvetted.com/p/contabo): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Exoscale](https://euvetted.com/p/exoscale): hosted in Switzerland, CLOUD Act: minor, ownership: other - [netcup](https://euvetted.com/p/netcup): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [UpCloud](https://euvetted.com/p/upcloud): hosted in Finland, CLOUD Act: none, ownership: eu_owned - [Infomaniak Public Cloud](https://euvetted.com/p/infomaniak-public-cloud): hosted in Switzerland, CLOUD Act: none, ownership: other - [Hetzner](https://euvetted.com/p/hetzner): hosted in Germany, CLOUD Act: none, ownership: eu_owned ### European alternatives to Magento: https://euvetted.com/alternatives/magento _About Magento:_ Adobe Commerce (Nasdaq: ADBE). Open-source kernel plus paid Adobe Commerce Cloud. Direct US ownership. Verified European alternatives (5): - [PrestaShop](https://euvetted.com/p/prestashop): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [Shopware](https://euvetted.com/p/shopware): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Sylius](https://euvetted.com/p/sylius): hosted in Poland, CLOUD Act: none, ownership: eu_owned - [Saleor Commerce](https://euvetted.com/p/saleor): hosted in Ireland, CLOUD Act: material, ownership: eu_owned - [MyCashflow](https://euvetted.com/p/mycashflow): hosted in Finland, CLOUD Act: none, ownership: eu_owned ### European alternatives to Mailchimp: https://euvetted.com/alternatives/mailchimp _About Mailchimp:_ US-owned email marketing platform owned by Intuit. Heavy US sub-processor footprint and direct CLOUD Act exposure. Maileon (Germany, EU-owned, EU-hosted, CLOUD Act exposure: [[maileon.cloud_act]]) and CleverReach (Germany, EU-owned, Germany-only hosted, CLOUD Act exposure: [[cleverreach.cloud_act]]) are the strongest European alternatives to Mailchimp on EU Vetted's editorial assessment: both are German-owned, Germany-only hosted, with no material CLOUD Act exposure. For indie senders with tight budgets, MailerLite (Lithuanian/Polish-owned, EU-primary hosted, but with US sub-processors for AI and payments) offers the smoothest migration and a generous free tier. All three handle standard list/campaign/automation workflows. Verified European alternatives (13): - [Brevo](https://euvetted.com/p/brevo): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [CleverReach](https://euvetted.com/p/cleverreach): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [EmailOctopus](https://euvetted.com/p/emailoctopus): hosted in United Kingdom, CLOUD Act: material, ownership: other - [GetResponse](https://euvetted.com/p/getresponse): hosted in Poland, CLOUD Act: material, ownership: eu_owned - [Infomaniak Newsletter](https://euvetted.com/p/infomaniak-newsletter): hosted in Switzerland, CLOUD Act: none, ownership: other - [Inxmail](https://euvetted.com/p/inxmail): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Keila](https://euvetted.com/p/keila): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Maileon](https://euvetted.com/p/maileon): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [MailerLite](https://euvetted.com/p/mailerlite): hosted in Netherlands, CLOUD Act: material, ownership: eu_owned - [Mailjet](https://euvetted.com/p/mailjet): hosted in France, CLOUD Act: material, ownership: eu_owned - [Make](https://euvetted.com/p/make-newsletter): hosted in Norway, CLOUD Act: minor, ownership: other - [rapidmail](https://euvetted.com/p/rapidmail): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Sender](https://euvetted.com/p/sender): hosted in Lithuania, CLOUD Act: minor, ownership: eu_owned **Q: Is Mailchimp actually GDPR-compliant?** Mailchimp signs an EU Standard Contractual Clauses-based DPA and added Supplementary Measures after Schrems II. It is legally usable from the EU, but the data still flows to the US under direct CLOUD Act jurisdiction (Mailchimp is owned by Intuit, a US corporation). For DACH procurement teams writing a transfer impact assessment, that combination (US ownership, US data residency, US sub-processors) is what triggers an alternative search, not the DPA itself. **Q: Which Mailchimp alternative has BSI C5 certification?** Among the alternatives mapped on this page, the German vendors with the strongest German cloud-compliance frameworks are CleverReach and Inxmail. CleverReach holds ISO 27001 and operates from German-only data centres; Inxmail combines ISO 27001 with BSI C5 alignment and targets the enterprise tier. Maileon stands out as the most compliance-complete listing: EU-owned, Germany-only hosted, CLOUD Act exposure: [[maileon.cloud_act]]. **Q: Can I keep my Mailchimp templates when I migrate?** Partly. Mailchimp uses its own template syntax with merge tags like *|FNAME|*; most European platforms use slightly different placeholders (CleverReach and rapidmail use {FIRSTNAME} or similar). HTML structure transfers cleanly via copy-paste, but conditional blocks and Mailchimp-specific dynamic content do not. Plan a one-off design rebuild for your three or four most-used templates. **Q: Will my deliverability drop after switching?** If you change the sending domain or the IP pool, yes, temporarily. Most European tools will run a guided IP warmup (CleverReach, rapidmail, Maileon all do this for paid plans), typically about 7–14 days to reach previous open rates if your list is clean. Keep the old Mailchimp account paused, not deleted, for two billing cycles so you can re-send hard-bouncing addresses if needed. **Q: Is MailerLite truly European-owned?** MailerLite is Lithuanian-founded and currently owned by the Polish public group cyber_Folks via its Vercom subsidiary, so the ultimate parent is EU-listed. The EEA legal entity is MailerLite Limited (Dublin). However, MailerLite, Inc. (San Francisco) is the controller for non-EEA customers and several US sub-processors handle AI features and payments. EU ownership is present, but the US legal entity and US sub-processors leave it with CLOUD Act exposure: [[mailerlite.cloud_act]]. **Q: Does Mailchimp fall under the US CLOUD Act?** Yes. Mailchimp is owned by Intuit, Inc., a US-incorporated public company, and the consolidated group falls within the reach of the US CLOUD Act regardless of where EU customer data is stored. This is the core reason European procurement teams run transfer impact assessments for Mailchimp. The strongest alternatives on this page (Maileon, CleverReach, Inxmail) are EU-owned and Germany-hosted, which removes the US-ownership question Mailchimp raises (CLOUD Act exposure: Maileon: [[maileon.cloud_act]], CleverReach: [[cleverreach.cloud_act]], Inxmail: [[inxmail.cloud_act]]). This assessment is based on publicly disclosed corporate structure. **Q: Is there a GDPR-compliant alternative to Mailchimp for sending newsletters?** Yes. Every European alternative mapped on this page publishes a GDPR-compliant data processing agreement. The compliance depth varies: Maileon is EU-owned, Germany-only hosted, CLOUD Act exposure: [[maileon.cloud_act]]; CleverReach holds ISO 27001 and operates from German-only data centres, CLOUD Act exposure: [[cleverreach.cloud_act]]; MailerLite is EU-owned but carries US sub-processors for AI and payments (CLOUD Act exposure: [[mailerlite.cloud_act]]), which limits its clean-signal profile. For the strictest GDPR posture, Maileon or Inxmail are the two to evaluate first. **Q: What is the cheapest European alternative to Mailchimp?** MailerLite has the most accessible free tier among the European alternatives mapped here: 500 subscribers and 12,000 emails per month at no cost. For paid tiers, rapidmail and CleverReach are competitive at list sizes under 25,000. Maileon and Inxmail are enterprise-priced and are not suited to indie or small-SMB budgets. Brevo offers an unlimited-contact free tier (capped by monthly send volume), which suits high-contact-count but low-frequency senders. **Q: Can a European email platform still integrate with my e-commerce store?** Yes. WooCommerce, Shopify, Magento, and Prestashop integrations are standard across CleverReach, MailerLite, rapidmail, and Brevo. The gap is with niche US e-commerce add-ons: if you rely on a US-specific Shopify app that auto-syncs Mailchimp tags, you will need to rebuild that workflow via a Zapier or Make automation. The major platform integrations (WooCommerce abandoned-cart, Shopify post-purchase) are covered natively. ### European alternatives to MailerLite: https://euvetted.com/alternatives/mailerlite _About MailerLite:_ Lithuanian-founded email marketing platform, owned by Polish cyber_Folks / Vercom group. Cross-reference: listed in our directory as a product. Verified European alternatives (6): - [EmailOctopus](https://euvetted.com/p/emailoctopus): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Infomaniak Newsletter](https://euvetted.com/p/infomaniak-newsletter): hosted in Switzerland, CLOUD Act: none, ownership: other - [Sender](https://euvetted.com/p/sender): hosted in Lithuania, CLOUD Act: minor, ownership: eu_owned - [CleverReach](https://euvetted.com/p/cleverreach): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Brevo](https://euvetted.com/p/brevo): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [GetResponse](https://euvetted.com/p/getresponse): hosted in Poland, CLOUD Act: material, ownership: eu_owned ### European alternatives to Mangopay: https://euvetted.com/alternatives/mangopay _About Mangopay:_ Luxembourg-licensed marketplace payments specialist, owned by Advent International (US PE) since 2022. Cross-reference: listed in our directory as a product. Lemonway (France, ACPR-licensed, EU-owned) is the strongest European alternative to Mangopay on EU Vetted's editorial assessment, and the closest like-for-like: both are wallet-based marketplace payment institutions. Adyen for Platforms (Netherlands, publicly listed credit institution) is the enterprise-scale option. Mangopay itself remains Luxembourg-licensed and technically strong; what sends buyers here is ownership, since Advent International (US private equity) has controlled it since April 2022. Verified European alternatives (3): - [Lemonway](https://euvetted.com/p/lemonway): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Adyen](https://euvetted.com/p/adyen): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [GoCardless](https://euvetted.com/p/gocardless): hosted in United Kingdom, CLOUD Act: material, ownership: other **Q: Is Mangopay not European?** Operationally it is: Mangopay S.A. is a Luxembourg e-money institution supervised by the CSSF, with a UK FCA licence alongside, and it runs marketplace payments for 2,500+ platforms including Vinted, Malt, and Chrono24. The ownership chain is the caveat: Advent International, a Boston-based private-equity firm, acquired Mangopay in April 2022. In our assessment that sets ownership signal: [[mangopay.ownership]] and CLOUD Act exposure: [[mangopay.cloud_act]]. Whether that matters depends on whether your screening looks at regulatory domicile or at who controls the company. **Q: What is the closest like-for-like replacement?** Lemonway (Paris). Same category (wallet-based payment institution for marketplaces), same regulatory family (ACPR-licensed, passported in 29 countries), similar customer profile (400+ platforms including SNCF Connect and Decathlon, €12.4B annual volume in 2025), and a European cap table (Breega, Speedinvest, Toscafund) with CLOUD Act exposure: [[lemonway.cloud_act]]. Feature-for-feature Mangopay's surface is broader; Lemonway's ownership answer is cleaner. **Q: When is Adyen for Platforms the better answer?** At enterprise scale, or when your platform needs global acquiring, in-person payments, or sellers outside the EEA and UK. Adyen (Amsterdam, publicly listed, DNB-licensed credit institution, CLOUD Act exposure: [[adyen.cloud_act]]) runs platform payments on its own banking infrastructure across regions. The trade-off is the model: balance accounts on a credit institution rather than the e-wallet structure Mangopay and Lemonway share, and an enterprise sales and onboarding process to match. **Q: Can seller wallets and balances be transferred to the new provider?** No. E-money balances cannot be bulk-transferred between regulated institutions; each seller's funds must be paid out through Mangopay to the seller's own bank account before their wallet closes, and the seller then completes KYC with the new provider. That two-step (flush payouts, re-verify sellers) is the heart of any Mangopay migration and the reason to plan it in cohorts rather than as a cutover date. **Q: Do sellers have to pass KYC again?** Yes, all of them. KYC and KYB files are not portable between payment institutions; the receiving institution must verify sellers itself under its own obligations. Expect re-verification friction concentrated in the long tail of small or dormant sellers, decide in advance what happens to sellers who never complete it, and communicate deadlines inside the product, not only by email. **Q: Is GoCardless really a Mangopay alternative?** Only for a specific slice. GoCardless (UK, FCA-authorised) is the direct-debit and recurring-collections specialist; if what you actually run on Mangopay is subscription-style collections or B2B invoicing rather than multi-party marketplace flows, GoCardless covers that job well. It has no wallet or escrow model, so it does not replace marketplace machinery. Note the pending Mollie acquisition announced in December 2025. **Q: Will the alternative handle escrow-style flows the way Mangopay does?** Lemonway, yes: the same wallet-based structure where funds sit in a seller's or transaction's wallet until release conditions are met. Adyen models the same outcomes through balance accounts and split logic, which platform teams find workable but structurally different. If escrow semantics are central to your product (custom marketplaces, crowdfunding, rentals with deposits), have both vendors walk through your exact release flows before choosing. **Q: What does the migration cost in practice?** All three providers price custom for platforms, so the visible line is the quote; the invisible lines are re-integration (wallet and webhook models differ), seller re-onboarding (product work plus support load plus some seller attrition), and a quarter or more of parallel running with balances winding down on the old rail. Teams that have done it report the seller-communication effort as the piece they underestimated, not the engineering. ### European alternatives to MediaWiki: https://euvetted.com/alternatives/mediawiki _About MediaWiki:_ Wikimedia Foundation (US 501c3) open-source wiki software powering Wikipedia. Verified European alternatives (3): - [BookStack](https://euvetted.com/p/bookstack): hosted in United Kingdom, CLOUD Act: none, ownership: other - [Wiki.js](https://euvetted.com/p/wiki-js): hosted in Canada, CLOUD Act: none, ownership: other - [Outline](https://euvetted.com/p/outline): hosted in United States, CLOUD Act: direct, ownership: us_owned ### European alternatives to MEGA: https://euvetted.com/alternatives/mega _About MEGA:_ New Zealand-incorporated encrypted cloud storage, founded by Kim Dotcom. Verified European alternatives (3): - [Filen](https://euvetted.com/p/filen): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Internxt](https://euvetted.com/p/internxt): hosted in Spain, CLOUD Act: minor, ownership: eu_owned - [Proton Drive](https://euvetted.com/p/proton-drive): hosted in Switzerland, CLOUD Act: none, ownership: other ### European alternatives to Microsoft 365: https://euvetted.com/alternatives/microsoft-365 _About Microsoft 365:_ Microsoft cloud productivity suite. Direct CLOUD Act exposure. Verified European alternatives (4): - [OnlyOffice](https://euvetted.com/p/onlyoffice): hosted in Latvia, CLOUD Act: minor, ownership: other - [Collabora Online](https://euvetted.com/p/collabora-online): hosted in United Kingdom, CLOUD Act: minor, ownership: other - [Nextcloud](https://euvetted.com/p/nextcloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Proton Drive](https://euvetted.com/p/proton-drive): hosted in Switzerland, CLOUD Act: none, ownership: other ### European alternatives to Microsoft Azure: https://euvetted.com/alternatives/azure _About Microsoft Azure:_ Microsoft-owned cloud platform. Direct CLOUD Act exposure regardless of EU region. Verified European alternatives (11): - [Intility](https://euvetted.com/p/intility): hosted in Norway, CLOUD Act: material, ownership: other - [STACKIT](https://euvetted.com/p/stackit): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [T Cloud Public (formerly Open Telekom Cloud)](https://euvetted.com/p/open-telekom-cloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Aruba Cloud](https://euvetted.com/p/aruba-cloud): hosted in Italy, CLOUD Act: none, ownership: eu_owned - [Cleura](https://euvetted.com/p/cleura): hosted in Sweden, CLOUD Act: none, ownership: eu_owned - [Hetzner](https://euvetted.com/p/hetzner): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [IONOS](https://euvetted.com/p/ionos): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [OVHcloud](https://euvetted.com/p/ovhcloud): hosted in France, CLOUD Act: none, ownership: eu_owned - [Scaleway](https://euvetted.com/p/scaleway): hosted in France, CLOUD Act: none, ownership: eu_owned - [Stackscale](https://euvetted.com/p/stackscale): hosted in Spain, CLOUD Act: none, ownership: eu_owned - [Thalassa Cloud](https://euvetted.com/p/thalassa-cloud): hosted in Netherlands, CLOUD Act: none, ownership: eu_owned ### European alternatives to Microsoft Bookings: https://euvetted.com/alternatives/microsoft-bookings _About Microsoft Bookings:_ Microsoft 365's scheduling tool. Direct CLOUD Act exposure. Verified European alternatives (5): - [Reservio](https://euvetted.com/p/reservio): hosted in Czechia, CLOUD Act: minor, ownership: eu_owned - [SuperSaaS](https://euvetted.com/p/supersaas): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Cal.com](https://euvetted.com/p/cal-com): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Cronofy](https://euvetted.com/p/cronofy): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Doodle](https://euvetted.com/p/doodle): hosted in Germany, CLOUD Act: minor, ownership: other ### European alternatives to Microsoft Dynamics 365: https://euvetted.com/alternatives/microsoft-dynamics _About Microsoft Dynamics 365:_ Microsoft-owned enterprise CRM/ERP. Direct CLOUD Act exposure via Microsoft Corp. Verified European alternatives (3): - [combit CRM](https://euvetted.com/p/combit-crm): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [YetiForce](https://euvetted.com/p/yetiforce): hosted in Poland, CLOUD Act: minor, ownership: eu_owned - [Lime CRM](https://euvetted.com/p/lime-crm): hosted in Sweden, CLOUD Act: minor, ownership: eu_owned ### European alternatives to Microsoft Office Online: https://euvetted.com/alternatives/microsoft-office-online _About Microsoft Office Online:_ Microsoft's web-based Office. Direct CLOUD Act exposure. Verified European alternatives (3): - [Collabora Online](https://euvetted.com/p/collabora-online): hosted in United Kingdom, CLOUD Act: minor, ownership: other - [CryptPad](https://euvetted.com/p/cryptpad): hosted in France, CLOUD Act: none, ownership: eu_owned - [OnlyOffice](https://euvetted.com/p/onlyoffice): hosted in Latvia, CLOUD Act: minor, ownership: other ### European alternatives to Microsoft OneDrive: https://euvetted.com/alternatives/onedrive _About Microsoft OneDrive:_ Microsoft-owned cloud storage, part of Microsoft 365. Direct CLOUD Act exposure. Proton Drive (Switzerland, Geneva, EU-owned, EU-hosted, zero-knowledge E2E, CLOUD Act exposure: [[proton-drive.cloud_act]]) and Tresorit (Switzerland, Zurich, Swiss-Post-owned, zero-knowledge E2E, CLOUD Act exposure: [[tresorit.cloud_act]] via its sub-processor chain, while file contents stay end-to-end encrypted) are the strongest European alternatives to Microsoft OneDrive. For cost-competitive Swiss hosting with built-in Office co-editing, kDrive by Infomaniak (Switzerland, Geneva, EU-owned, EU-hosted, CLOUD Act exposure: [[kdrive.cloud_act]]) is the leading SMB choice, and Nextcloud (Germany, Stuttgart, EU-owned, EU-hosted, CLOUD Act exposure: [[nextcloud.cloud_act]]) is the closest self-hostable replacement for the OneDrive-plus-Office workflow. Most of the alternatives mapped here are EU/EEA- or Swiss-owned and European-hosted; each listing shows its verified exposure level. Verified European alternatives (15): - [leitzcloud](https://euvetted.com/p/leitzcloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Tresorit](https://euvetted.com/p/tresorit): hosted in Ireland, CLOUD Act: material, ownership: other - [kDrive (Infomaniak)](https://euvetted.com/p/kdrive): hosted in Switzerland, CLOUD Act: none, ownership: other - [Nextcloud](https://euvetted.com/p/nextcloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [luckycloud](https://euvetted.com/p/luckycloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Koofr](https://euvetted.com/p/koofr): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [STRATO HiDrive](https://euvetted.com/p/strato-hidrive): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Orbifs](https://euvetted.com/p/orbifs): hosted in France, CLOUD Act: minor, ownership: other - [Hetzner Storage Share](https://euvetted.com/p/hetzner-storage-share): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Leviia](https://euvetted.com/p/leviia): hosted in France, CLOUD Act: none, ownership: eu_owned - [Wimi](https://euvetted.com/p/wimi): hosted in France, CLOUD Act: none, ownership: eu_owned - [Icedrive](https://euvetted.com/p/icedrive): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Jottacloud](https://euvetted.com/p/jottacloud): hosted in Norway, CLOUD Act: none, ownership: other - [Proton Drive](https://euvetted.com/p/proton-drive): hosted in Switzerland, CLOUD Act: none, ownership: other - [pCloud](https://euvetted.com/p/pcloud): hosted in Luxembourg, CLOUD Act: minor, ownership: other **Q: Is OneDrive usable under GDPR?** Microsoft publishes an EU Standard Contractual Clauses-based DPA and runs an EU Data Boundary for Microsoft 365, so OneDrive is legally usable from the EU. What keeps procurement teams evaluating alternatives anyway is the ownership and infrastructure profile beneath that paperwork: OneDrive is part of Microsoft 365, operated by Microsoft Corporation (US-incorporated, NASDAQ: MSFT), running on Microsoft Azure, with the consolidated group under CLOUD Act jurisdiction. For a Schrems II transfer impact assessment, that combination is what prompts the alternative search, not the DPA itself. **Q: Which OneDrive alternative has the strongest compliance profile?** This is the strongest category on the site. Of the nine alternatives mapped here, eight sit outside CLOUD Act reach and are EU- or Swiss-owned with EU hosting, a sharp contrast to OneDrive's Microsoft Azure backend. The line-up: Proton Drive (Switzerland, Geneva, privacy-leading, zero-knowledge), kDrive (Switzerland, Geneva), Nextcloud (Germany, Stuttgart, self-hostable open source), luckycloud (Germany, Berlin), Filen (Germany, zero-knowledge E2E), Internxt (Spain, zero-knowledge), leitzcloud (Germany), and pCloud (Switzerland, EU-hosted in Luxembourg, though without end-to-end encryption by default). Tresorit (Switzerland, Zurich, enterprise E2E, zero-knowledge) remains the enterprise encryption benchmark, but its current sub-processor chain gives it a material CLOUD Act flag (CLOUD Act exposure: [[tresorit.cloud_act]]); file contents stay end-to-end encrypted regardless. **Q: Will my OneDrive files and folder structure transfer?** Yes. OneDrive supports a clean file export and most European alternatives accept the same folder hierarchy on upload. Two things need attention: shared-link URLs change (you reissue the share links after migration), and if you use Windows Known Folder Move (Desktop, Documents, and Pictures redirected into OneDrive) you point those folders back to local or to the new vendor's sync client before you stop syncing. Native Office files (.docx, .xlsx, .pptx) move as standard files, so unlike a Paper-style format there is no export conversion step. **Q: Do the alternatives support team folders, SSO and Office co-editing?** Yes on all three, on the business/enterprise tiers. Tresorit, kDrive, Nextcloud, and leitzcloud support team folder permissions with role-based access and SSO (SAML 2.0, OIDC). For the Office co-editing that OneDrive ties to Microsoft 365, kDrive and Nextcloud integrate OnlyOffice or Collabora for real-time co-authoring of Word, Excel, and PowerPoint files in the browser. If Active Directory SSO specifically is the requirement, Nextcloud integrates most deeply with it. **Q: What about end-to-end encryption?** Default end-to-end encryption ships on three of the alternatives mapped here: Tresorit (zero-knowledge for the file content and metadata), Proton Drive (zero-knowledge for content and most metadata), and Filen (zero-knowledge end-to-end). Internxt is also zero-knowledge by design. OneDrive itself does not end-to-end encrypt your files (Microsoft can access them) so for teams where E2E is a compliance requirement (legal, healthcare, government), these four are the ones to evaluate first. **Q: Does OneDrive fall under the US CLOUD Act?** Yes. OneDrive is part of Microsoft 365, operated by Microsoft Corporation, a US-incorporated public company (NASDAQ: MSFT), and the consolidated group falls within the reach of the US CLOUD Act regardless of where EU customer data is stored. The EU Data Boundary changes data location, not the operator's legal jurisdiction. Of the alternatives on this page, the ones with no material CLOUD Act exposure (Proton Drive, kDrive, Nextcloud, luckycloud, Filen, Internxt, leitzcloud, pCloud) share one trait: none is US-incorporated, so direct CLOUD Act exposure does not apply. Tresorit is likewise not US-incorporated, but its current sub-processor chain carries a material CLOUD Act flag (CLOUD Act exposure: [[tresorit.cloud_act]]), even though file contents stay end-to-end encrypted. That's a read of the corporate chain based on publicly available information, not a claim about any specific data request. **Q: Is there a GDPR-compliant alternative to OneDrive with end-to-end encryption?** Yes. Zero-knowledge end-to-end encryption ships by default on four: Tresorit, Proton Drive, Filen, and Internxt, meaning none of them can read your file content, even under a legal request. GDPR-compliant DPAs are published by all four, and each is EU or Swiss-owned with EU hosting. Proton Drive, Filen, and Internxt carry no material CLOUD Act exposure; Tresorit carries a material flag via its current sub-processor chain (CLOUD Act exposure: [[tresorit.cloud_act]]), though zero-knowledge encryption means file contents stay unreadable to the vendor either way. For organisations with the strictest data-confidentiality requirements (legal, healthcare, public sector) these four are the recommended starting point. **Q: What is the cheapest European alternative to OneDrive?** Proton Drive and Filen both offer generous free tiers with end-to-end encryption. Filen is particularly competitive on paid storage pricing. kDrive by Infomaniak offers competitive monthly pricing for SMBs with a broader product bundle (Drive, Mail, Meet, Sign) that overlaps the Microsoft 365 surface. Running Nextcloud on your own infrastructure removes per-seat cost from the equation entirely for self-hosted deployments, making it the lowest-cost-per-TB option at scale. Confirm current pricing on each vendor's page as rates change frequently. **Q: Can I still co-edit Office documents without Microsoft 365?** Yes. The Office co-authoring that OneDrive ties to Microsoft 365 is replaced by OnlyOffice or Collabora, both of which open and co-edit Word, Excel, and PowerPoint files with high fidelity in the browser. kDrive and Nextcloud both integrate one of these natively, so a team gets real-time co-editing of the same .docx/.xlsx/.pptx files without a Microsoft 365 subscription. For documents where you want end-to-end encryption during editing, CryptPad is the E2E option, at the cost of some formatting fidelity on complex files. ### European alternatives to Microsoft SharePoint: https://euvetted.com/alternatives/sharepoint _About Microsoft SharePoint:_ Microsoft-owned document collaboration platform. Direct CLOUD Act exposure. Verified European alternatives (4): - [HumHub](https://euvetted.com/p/humhub): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [STRATO HiDrive](https://euvetted.com/p/strato-hidrive): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Orbifs](https://euvetted.com/p/orbifs): hosted in France, CLOUD Act: minor, ownership: other - [Nextcloud](https://euvetted.com/p/nextcloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned ### European alternatives to Microsoft Teams: https://euvetted.com/alternatives/microsoft-teams _About Microsoft Teams:_ Microsoft-owned video + collaboration. Direct CLOUD Act exposure. No single European tool matches Teams' full all-in-one bundle. The realistic strategy is to unbundle. Stackfield (Germany, Munich, EU-owned, EU-hosted, CLOUD Act exposure: [[stackfield.cloud_act]]) is the closest single-product match for chat plus tasks plus meetings. Tixeo (France, Montpellier, EU-owned, EU-hosted, SecNumCloud-qualified) is the top choice for sovereign video. Wire (Switzerland, EU-hosted, end-to-end encrypted by default, CLOUD Act exposure: [[wire.cloud_act]] via its sub-processor chain) is strongest for enterprise messaging. sipgate (Germany, Düsseldorf, EU-owned, EU-hosted, CLOUD Act exposure: [[sipgate.cloud_act]]) consolidates voice, video, and PBX. Verified European alternatives (10): - [Element (Matrix)](https://euvetted.com/p/element-matrix): hosted in United Kingdom, CLOUD Act: material, ownership: other - [HansaChat](https://euvetted.com/p/hansachat): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Stackfield](https://euvetted.com/p/stackfield): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Wire](https://euvetted.com/p/wire): hosted in Switzerland, CLOUD Act: material, ownership: other - [kMeet (Infomaniak)](https://euvetted.com/p/kmeet): hosted in Switzerland, CLOUD Act: none, ownership: other - [Pexip](https://euvetted.com/p/pexip): hosted in Norway, CLOUD Act: material, ownership: other - [sipgate](https://euvetted.com/p/sipgate): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Talkspirit](https://euvetted.com/p/talkspirit): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Tixeo](https://euvetted.com/p/tixeo): hosted in France, CLOUD Act: none, ownership: eu_owned - [Whereby](https://euvetted.com/p/whereby): hosted in Ireland, CLOUD Act: minor, ownership: other **Q: Is Microsoft Teams usable under GDPR?** Microsoft publishes a Data Processing Addendum based on the EU Standard Contractual Clauses with post-Schrems II supplementary measures, and offers the EU Data Boundary for Microsoft 365 (announced 2023, expanded 2024) that keeps most customer content in the EU. The service is legally usable from the EU. What keeps procurement teams evaluating alternatives anyway is the underlying ownership: Microsoft Corporation is US-incorporated and publicly listed (NASDAQ: MSFT), and the parent corporate structure means CLOUD Act jurisdiction applies regardless of the EU Data Boundary. The April 2026 €180M EU sovereign cloud tender (which excluded Microsoft) and France's announced migration of 2.5M civil servants off Microsoft are the institutional signals European procurement teams are responding to. **Q: Which Microsoft Teams alternative has the strongest compliance profile?** Among the alternatives mapped on this page, the cleanest signal set belongs to Stackfield (Germany, Munich, EU-owned, EU-hosted, CLOUD Act exposure: [[stackfield.cloud_act]]), Tixeo (France, Montpellier, EU-owned, EU-hosted, CLOUD Act exposure: [[tixeo.cloud_act]]), and sipgate (Germany, Düsseldorf, EU-owned, EU-hosted, CLOUD Act exposure: [[sipgate.cloud_act]]). Element/Matrix (UK, open-source, no US parent, CLOUD Act exposure: [[element-matrix.cloud_act]]) and Wire (Switzerland, Swiss-owned, Swiss-hosted, CLOUD Act exposure: [[wire.cloud_act]]) carry exposure via their sub-processor chains, but both encrypt message contents end-to-end. Tixeo specifically holds SecNumCloud qualification (the French government's highest cloud-sovereignty certification), making it the default for French public sector and defence-adjacent buyers. **Q: Can a European tool replace Microsoft Teams' full feature surface?** No European tool matches Teams' full all-in-one bundle (chat + video + file sharing + Microsoft 365 deep integration + Power Platform + Phone System) in a single product. The realistic strategy is to unbundle, similar to the HubSpot/Salesforce unbundling logic. For chat: Stackfield, Element, or Wire. For video: Tixeo, Whereby, Pexip, or sipgate. For file storage: see our Dropbox alternatives page (Nextcloud, kDrive, Tresorit). For phone system: sipgate's strength is the bundled phone-and-video product. **Q: What about the deep Microsoft 365 integration?** Teams' tight integration with Outlook, OneDrive, SharePoint, and Office is its main lock-in mechanism. European alternatives cannot replicate this if you stay on Microsoft 365; you would need to migrate Microsoft 365 itself for a fully-European stack. Many DACH organisations and the French government's civil-service migration are doing exactly this, pairing Nextcloud (file storage + office suite via Collabora) with a European messaging tool (Stackfield, Element) and a European email host. The full migration takes 6–18 months for medium-sized enterprises. **Q: What about Teams Phone and SIP trunking?** Teams Phone bundles direct calling functionality with calendars and Microsoft 365. The strongest European bundled-phone-and-video alternative is sipgate (Germany), which combines IP telephony, mobile telephony, and video meetings. For larger enterprises needing SIP-trunking interoperability with existing PBX hardware, Pexip's video infrastructure pairs well with traditional European telcos. **Q: Does Microsoft Teams fall under the US CLOUD Act?** In practice, yes. Microsoft Corporation is US-incorporated (NASDAQ: MSFT), and the consolidated group (including the EU Data Boundary infrastructure) falls within the reach of the US CLOUD Act, which can compel a US company to produce data it controls regardless of where that data is stored. Microsoft's EU Data Boundary keeps most content in EU regions and reduces the practical data-transfer surface, but it does not eliminate the US legal authority question over the parent company. The EU- or Swiss-based alternatives on this page remove that direct parent-company exposure to varying degrees: Stackfield, Tixeo, and sipgate carry the cleanest signals (CLOUD Act exposure for Stackfield: [[stackfield.cloud_act]], Tixeo: [[tixeo.cloud_act]], sipgate: [[sipgate.cloud_act]]), while Wire (CLOUD Act exposure: [[wire.cloud_act]]) and Element/Matrix (CLOUD Act exposure: [[element-matrix.cloud_act]]) carry sub-processor-chain exposure but keep contents end-to-end encrypted. That's a read of the corporate chain, not a claim that any particular data request has occurred. **Q: Is there a GDPR-compliant alternative to Microsoft Teams?** All seven European alternatives mapped on this page (Stackfield, Tixeo, Wire, Element/Matrix, sipgate, Whereby, and Pexip) are GDPR-compliant by design: EU, EEA, or Swiss data residency, published DPAs, and no US parent-company jurisdiction. Stackfield, Tixeo, and sipgate carry the cleanest exposure signals (CLOUD Act exposure for Stackfield: [[stackfield.cloud_act]], Tixeo: [[tixeo.cloud_act]], sipgate: [[sipgate.cloud_act]]); Wire (CLOUD Act exposure: [[wire.cloud_act]]) and Element/Matrix (CLOUD Act exposure: [[element-matrix.cloud_act]]) carry sub-processor exposure but encrypt contents end-to-end. For the strongest GDPR compliance posture on video collaboration specifically, Tixeo (France, SecNumCloud-qualified) is the highest-certified option in the European market. **Q: Can a European collaboration tool handle guest access and external meeting participants?** Yes. Stackfield, Element/Matrix, and Wire all support guest or external-user access for collaboration with clients, contractors, and partners outside your organisation. Element/Matrix's federation model is the strongest for cross-organisation communication: the Matrix protocol enables encrypted communication between independently-hosted servers, comparable to email federation. sipgate and Tixeo support external video meeting participants via browser-based join links, without requiring the guest to have an account. **Q: What is the cheapest European alternative to Microsoft Teams?** For basic team chat and video meetings, Whereby (Norway, EEA-hosted, no US parent) and open-source options like Element Community Edition (self-hosted Matrix) are the lowest-cost entry points. Stackfield starts at around €5–7 per user per month for the Team tier, which is comparable to Teams Essentials pricing. Wire has a higher per-seat price that reflects its enterprise security and Swiss hosting positioning. For SMBs that want a free tier for small teams, Element/Matrix self-hosted has no per-seat licensing cost, though it requires infrastructure. ### European alternatives to Mixpanel: https://euvetted.com/alternatives/mixpanel _About Mixpanel:_ US-owned product analytics. Direct CLOUD Act exposure. Verified European alternatives (7): - [TelemetryDeck](https://euvetted.com/p/telemetrydeck): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Matomo](https://euvetted.com/p/matomo): hosted in Germany, CLOUD Act: material, ownership: other - [Pirsch Analytics](https://euvetted.com/p/pirsch): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Plausible Analytics](https://euvetted.com/p/plausible): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [PostHog](https://euvetted.com/p/posthog): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [Simple Analytics](https://euvetted.com/p/simple-analytics): hosted in Netherlands, CLOUD Act: none, ownership: eu_owned - [Wide Angle Analytics](https://euvetted.com/p/wide-angle-analytics): hosted in France, CLOUD Act: minor, ownership: eu_owned ### European alternatives to monday.com: https://euvetted.com/alternatives/monday _About monday.com:_ Israeli-founded, NASDAQ-listed work management platform (MNDY). MeisterTask (Germany, EU-owned, EU-hosted, no CLOUD Act exposure) and factro (Germany, Bochum, EU-owned, EU-hosted, no CLOUD Act exposure) are the strongest European alternatives to monday.com. Both are visual work management platforms with clean EU sovereignty profiles. monday.com (NASDAQ: MNDY) runs on AWS US infrastructure and falls under CLOUD Act jurisdiction. For agencies needing time tracking, Teamwork.com (Ireland, EU-hosted with minor sub-processor exposure) is the recommended pick. Verified European alternatives (6): - [factro](https://euvetted.com/p/factro): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Kantree](https://euvetted.com/p/kantree): hosted in France, CLOUD Act: none, ownership: eu_owned - [Plandisc](https://euvetted.com/p/plandisc): hosted in Sweden, CLOUD Act: minor, ownership: other - [SeaTable](https://euvetted.com/p/seatable): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Teamwork.com](https://euvetted.com/p/teamwork): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [MeisterTask](https://euvetted.com/p/meistertask): hosted in Germany, CLOUD Act: none, ownership: eu_owned **Q: Is monday.com a US company?** monday.com was founded in Tel Aviv in 2012 and the engineering organisation remains largely in Israel; the company is publicly listed on NASDAQ as MNDY since 2021. The platform runs on AWS US infrastructure, with sub-processors that fall under CLOUD Act jurisdiction. For a European procurement team writing a Schrems II transfer impact assessment, the Israeli founding history does not change the data-flow analysis: the operational profile is what prompts buyers to evaluate alternatives, regardless of where the company was originally founded. **Q: Which monday.com alternative has the strongest compliance profile?** Among the alternatives mapped on this page, three carry no material CLOUD Act exposure and are fully EU-owned and EU-hosted: Kantree (France), factro (Germany, Bochum), and MeisterTask (Germany). Teamwork.com (Ireland) and Plandisc (Denmark) have EU-primary infrastructure but carry minor sub-processor exposure. For DACH SMBs specifically, factro and MeisterTask are the procurement-clearest picks. **Q: Can monday.com boards transfer to a European tool?** Yes for the core data. monday.com supports CSV and Excel export per board via *Board menu → More actions → Export to Excel*. The export preserves item names, columns, status values, dates, and people assignments. What does not transfer cleanly: monday.com Automations, Integrations apps, and dashboard widgets, all of which need reconstructing from scratch as native features once you land on the new tool. For teams with 10–30 active boards, the migration is a one-week effort including QA. **Q: Does any European alternative have monday.com's visual UX?** MeisterTask and factro are the closest visual matches; both use a card-and-board interaction model with custom-property columns. Kantree is more flexible (closer to Notion-style database views than monday's status-board model). For teams that chose monday.com specifically for the visual UX, MeisterTask and factro are the lowest-friction switches; Stackfield is a viable third option if you want a more all-in-one platform. **Q: What about monday.com's CRM and dev-team-specific products?** monday.com Sales CRM and monday Dev are separate product surfaces beyond the core monday Work Management. For Sales CRM specifically, see our HubSpot or Salesforce alternatives page (Pipedrive, weclapp, centralstationCRM are the European picks). For dev-team workflows, Taiga (Spain, EU-owned, open-source clients) covers Jira-style agile sprints with EU sovereignty. **Q: Does monday.com fall under the US CLOUD Act?** In practice, yes. monday.com (NASDAQ: MNDY) runs on AWS US infrastructure and its corporate structure falls within CLOUD Act reach. A US authority can compel monday.com to produce data it controls regardless of where that data is stored. The EU-owned and EU-hosted alternatives on this page (MeisterTask, factro, Kantree) have no material CLOUD Act exposure, which removes that direct risk. This is an assessment of corporate and infrastructure profile, not a claim about any specific data request. **Q: What is the cheapest European alternative to monday.com?** MeisterTask (Germany) has the most accessible pricing among the commercial European alternatives, with a free tier and per-user paid plans comparable to monday.com's Basic tier. factro and Kantree offer SMB-range pricing without monday.com's volume-based pricing complexity. For teams comfortable self-hosting, Taiga (Spain, EU-owned, open-source clients) is free to self-host. Current pricing should be confirmed on each vendor's page, as rates change frequently. **Q: Is there a GDPR-compliant alternative to monday.com?** All five alternatives mapped on this page operate under GDPR and publish data processing agreements. The strongest GDPR posture (EU-owned and EU-hosted with no CLOUD Act exposure) is held by MeisterTask, factro, and Kantree. Teamwork.com and Plandisc have EU-primary infrastructure but carry minor sub-processor exposure. For procurement teams writing a formal transfer impact assessment, the fully EU-sovereign tools are the recommended starting point. **Q: Does any European alternative match monday.com's annual planning and strategic-cadence features?** Plandisc (Denmark, EU-hosted) is the European pick built specifically for annual planning cycles, OKR cadences, and quarterly planning workflows. Its circular calendar visualisation is a different mental model from monday.com's board view but better suited for strategic-cadence teams. For standard work management with visual boards, MeisterTask and factro are the closer functional matches. No European alternative bundles all of monday's Work Management, CRM, and Dev product surfaces in one tool. ### European alternatives to Mozilla VPN: https://euvetted.com/alternatives/mozilla-vpn _About Mozilla VPN:_ Mozilla-branded VPN (powered by Mullvad infrastructure). Mozilla Corp is US-incorporated. Verified European alternatives (6): - [NordVPN](https://euvetted.com/p/nordvpn): hosted in Lithuania, CLOUD Act: minor, ownership: other - [AzireVPN](https://euvetted.com/p/azirevpn): hosted in Sweden, CLOUD Act: material, ownership: us_owned - [CyberGhost](https://euvetted.com/p/cyberghost): hosted in Romania, CLOUD Act: minor, ownership: other - [OVPN](https://euvetted.com/p/ovpn): hosted in Sweden, CLOUD Act: none, ownership: eu_owned - [Proton VPN](https://euvetted.com/p/protonvpn): hosted in Switzerland, CLOUD Act: none, ownership: other - [Surfshark](https://euvetted.com/p/surfshark): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned ### European alternatives to Mullvad VPN: https://euvetted.com/alternatives/mullvad _About Mullvad VPN:_ Swedish privacy-maximalist VPN (Amagicom AB, Gothenburg). Cross-reference: listed in our directory as a product. Verified European alternatives (5): - [IVPN](https://euvetted.com/p/ivpn): hosted in Gibraltar, CLOUD Act: none, ownership: other - [AirVPN](https://euvetted.com/p/airvpn): hosted in Italy, CLOUD Act: none, ownership: eu_owned - [OVPN](https://euvetted.com/p/ovpn): hosted in Sweden, CLOUD Act: none, ownership: eu_owned - [Proton VPN](https://euvetted.com/p/protonvpn): hosted in Switzerland, CLOUD Act: none, ownership: other - [Opera VPN](https://euvetted.com/p/opera-vpn): hosted in Norway, CLOUD Act: material, ownership: other ### European alternatives to NordVPN: https://euvetted.com/alternatives/nordvpn _About NordVPN:_ Lithuanian-founded, Panama-incorporated (Nord Security Group). EU/Nordic operations but Panamanian legal seat. Verified European alternatives (10): - [AirVPN](https://euvetted.com/p/airvpn): hosted in Italy, CLOUD Act: none, ownership: eu_owned - [AzireVPN](https://euvetted.com/p/azirevpn): hosted in Sweden, CLOUD Act: material, ownership: us_owned - [CyberGhost](https://euvetted.com/p/cyberghost): hosted in Romania, CLOUD Act: minor, ownership: other - [F-Secure VPN](https://euvetted.com/p/f-secure-vpn): hosted in Finland, CLOUD Act: minor, ownership: eu_owned - [IVPN](https://euvetted.com/p/ivpn): hosted in Gibraltar, CLOUD Act: none, ownership: other - [Mullvad VPN](https://euvetted.com/p/mullvad): hosted in Sweden, CLOUD Act: none, ownership: eu_owned - [Opera VPN](https://euvetted.com/p/opera-vpn): hosted in Norway, CLOUD Act: material, ownership: other - [OVPN](https://euvetted.com/p/ovpn): hosted in Sweden, CLOUD Act: none, ownership: eu_owned - [Proton VPN](https://euvetted.com/p/protonvpn): hosted in Switzerland, CLOUD Act: none, ownership: other - [Surfshark](https://euvetted.com/p/surfshark): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned ### European alternatives to Notion: https://euvetted.com/alternatives/notion _About Notion:_ US-incorporated note-taking + workspace platform, San Francisco HQ. Nuclino (Germany, Munich) and Anytype (Germany, Berlin) are the strongest European alternatives to Notion. Both are EU-owned and Germany-hosted (CLOUD Act exposure, Nuclino: [[nuclino.cloud_act]], Anytype: [[anytype.cloud_act]]). For end-to-end encrypted collaboration, CryptPad (France, Paris) is the privacy-leading choice. All three are GDPR-native with no US parent corporate structure. Verified European alternatives (10): - [Anytype](https://euvetted.com/p/anytype): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Nuclino](https://euvetted.com/p/nuclino): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Outline](https://euvetted.com/p/outline): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Baserow](https://euvetted.com/p/baserow): hosted in Spain, CLOUD Act: minor, ownership: eu_owned - [CryptPad](https://euvetted.com/p/cryptpad): hosted in France, CLOUD Act: none, ownership: eu_owned - [Joplin](https://euvetted.com/p/joplin): hosted in France, CLOUD Act: none, ownership: eu_owned - [SeaTable](https://euvetted.com/p/seatable): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Wiki.js](https://euvetted.com/p/wiki-js): hosted in Canada, CLOUD Act: none, ownership: other - [BookStack](https://euvetted.com/p/bookstack): hosted in United Kingdom, CLOUD Act: none, ownership: other - [OnlyOffice](https://euvetted.com/p/onlyoffice): hosted in Latvia, CLOUD Act: minor, ownership: other **Q: Is Notion usable under GDPR?** Notion publishes a Data Processing Addendum based on the EU Standard Contractual Clauses with post-Schrems II supplementary measures, so it is legally usable from the EU. What keeps buyers evaluating alternatives anyway is the ownership and infrastructure profile beneath that paperwork: Notion Labs Inc. is US-incorporated, the platform runs on US cloud infrastructure, and the AI features route through US-based language model providers. For a transfer impact assessment, that combination is what prompts the alternative search. **Q: Which Notion alternative has the strongest compliance profile?** Among the alternatives mapped on this page, Anytype (Germany, Berlin, local-first, CLOUD Act exposure: [[anytype.cloud_act]]), CryptPad (France, Paris, end-to-end encrypted, CLOUD Act exposure: [[cryptpad.cloud_act]]), and BookStack (UK, open source, CLOUD Act exposure: [[bookstack.cloud_act]]) carry the cleanest signals; Nuclino (Germany, Munich) is EU-owned, CLOUD Act exposure: [[nuclino.cloud_act]]. OnlyOffice (Latvia, Riga) is EU-hosted with sub-processor exposure (CLOUD Act exposure: [[onlyoffice.cloud_act]]), and is the closest match for office-document-heavy teams. **Q: Can I export my Notion content?** Yes. Notion supports HTML, Markdown, CSV, and PDF export per workspace at *Settings → Workspace → Export all workspace content*. The Markdown export preserves nested page structure and most formatting. Database exports come as CSV (one per database). Embedded files are included in the export. What does not transfer cleanly: Notion's database views (Kanban, calendar, gallery), formula columns, and rollup columns. These need to be rebuilt in the new tool. **Q: Does any European alternative match Notion's block-based editing?** Nuclino and Anytype are the closest matches for Notion's block-based mental model. Nuclino is faster and simpler, with a tree-structured workspace; Anytype goes further with a local-first storage model where your data is on your own device by default. Neither has Notion's full database engine; for spreadsheet-like databases with formulas, OnlyOffice or a dedicated tool is a better fit. **Q: What about AI features?** Notion AI routes through US-based language model providers (OpenAI primarily). Among the European alternatives, AI features are emerging, but the European tools deliberately ship without OpenAI embedding by default, since that defeats the data-sovereignty argument. If AI editing is a non-negotiable for your workflow, the cleanest European path today is Nuclino + a separately-managed Mistral API integration for the writing-assist parts, kept opt-in per document. **Q: Does Notion fall under the US CLOUD Act?** In practice, yes. Notion Labs Inc. is US-incorporated, and the consolidated group falls within the reach of the US CLOUD Act regardless of where European customer data is stored. That single fact is the crux of any Schrems II transfer impact assessment. The EU-incorporated alternatives on this page have no US parent; the cleanest exposure signals belong to Anytype and CryptPad (CLOUD Act exposure, Anytype: [[anytype.cloud_act]], CryptPad: [[cryptpad.cloud_act]]), while Nuclino's CLOUD Act exposure is [[nuclino.cloud_act]]. That's a read of the corporate chain based on public information, not a claim about any specific data request. **Q: Is there a GDPR-compliant alternative to Notion?** Yes. Each European alternative on this page has a GDPR-compliant DPA in place. The compliance depth varies: Nuclino and Anytype are fully EU-hosted (CLOUD Act exposure, Nuclino: [[nuclino.cloud_act]], Anytype: [[anytype.cloud_act]]); OnlyOffice operates from Latvia with sub-processor exposure (CLOUD Act exposure: [[onlyoffice.cloud_act]]). For the strictest GDPR posture (including end-to-end encryption so the vendor cannot read document content), CryptPad (France, EU-owned, Paris-hosted) is the strongest option. **Q: What is the cheapest European alternative to Notion?** CryptPad offers a free tier with end-to-end encrypted documents, spreadsheets, and presentations with no subscriber required. Nuclino starts at competitive per-seat pricing with a generous free tier for small teams. Anytype is free for personal use with local-first storage. OnlyOffice has a self-hosted open-source edition that eliminates per-seat cost entirely if you have the infrastructure to run it. Exact pricing changes frequently; verify on each vendor's pricing page. **Q: Can a European workspace tool handle Notion databases and structured data?** Partially. None of the European alternatives replicate Notion's full relational database engine with formula columns, rollups, and linked databases at the same depth. For simple tables (3–5 columns, no formulas), Nuclino and Anytype have list views that approximate the function. For spreadsheet-like structured data with formulas, OnlyOffice is the European tool with the deepest capability. Teams that rely heavily on Notion databases typically pair a European workspace with OnlyOffice rather than trying to find a single-tool replacement. ### European alternatives to Notion Calendar: https://euvetted.com/alternatives/notion-calendar _About Notion Calendar:_ Calendar tool (formerly Cron) acquired by Notion (US) in 2022. Verified European alternatives (3): - [Plandisc](https://euvetted.com/p/plandisc): hosted in Sweden, CLOUD Act: minor, ownership: other - [Cal.com](https://euvetted.com/p/cal-com): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Cronofy](https://euvetted.com/p/cronofy): hosted in United Kingdom, CLOUD Act: material, ownership: other ### European alternatives to Obsidian: https://euvetted.com/alternatives/obsidian _About Obsidian:_ Local-first knowledge graph by a small Canadian-led team. Verified European alternatives (3): - [Joplin](https://euvetted.com/p/joplin): hosted in France, CLOUD Act: none, ownership: eu_owned - [Anytype](https://euvetted.com/p/anytype): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Nuclino](https://euvetted.com/p/nuclino): hosted in Germany, CLOUD Act: material, ownership: eu_owned ### European alternatives to OneTrust: https://euvetted.com/alternatives/onetrust _About OneTrust:_ Atlanta-headquartered US privacy + consent management leader. Insight Partners + Coatue-funded. Direct CLOUD Act exposure. Verified European alternatives (5): - [ConsentManager](https://euvetted.com/p/consentmanager): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Cookiebot](https://euvetted.com/p/cookiebot): hosted in Denmark, CLOUD Act: material, ownership: eu_hq_us_funded - [Didomi](https://euvetted.com/p/didomi): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Iubenda](https://euvetted.com/p/iubenda): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [Usercentrics](https://euvetted.com/p/usercentrics): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to OpenAI: https://euvetted.com/alternatives/openai _About OpenAI:_ US-incorporated AI lab, Microsoft-aligned. Direct CLOUD Act exposure. Verified European alternatives (5): - [Aleph Alpha](https://euvetted.com/p/aleph-alpha): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Black Forest Labs](https://euvetted.com/p/black-forest-labs): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Infomaniak AI Tools](https://euvetted.com/p/infomaniak-ai-tools): hosted in Switzerland, CLOUD Act: none, ownership: other - [LightOn](https://euvetted.com/p/lighton): hosted in France, CLOUD Act: none, ownership: eu_owned - [Mistral AI](https://euvetted.com/p/mistral-ai): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Outlook: https://euvetted.com/alternatives/outlook _About Outlook:_ Microsoft Corporation (Nasdaq: MSFT). Direct CLOUD Act exposure; consumer + Microsoft 365 / Exchange Online business mail. Proton Mail (Switzerland, Geneva, EU-adequacy jurisdiction, CLOUD Act exposure: [[proton-mail.cloud_act]], end-to-end + zero-access encryption, Foundation-owned) is the strongest European alternative to Outlook on EU Vetted's editorial assessment. Tuta (Germany, Hannover, EU-owned, own German data centre, post-quantum end-to-end encryption, CLOUD Act exposure: [[tuta.cloud_act]]) is the cleanest fully-German privacy pick. For DACH buyers who want a procurement-grade German suite, Mailbox.org (Germany, Berlin, EU-owned, ISO 27001 + BSI C5, from €1/month) is the strongest choice and bundles mail, drive, calendar and office. Outlook / Microsoft 365 Mail is operated by Microsoft Corporation (NASDAQ: MSFT) and carries direct US CLOUD Act exposure. Verified European alternatives (12): - [LC-Connect](https://euvetted.com/p/lc-connect): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Proton Mail](https://euvetted.com/p/proton-mail): hosted in Switzerland, CLOUD Act: none, ownership: other - [Tuta](https://euvetted.com/p/tuta): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Mailbox.org](https://euvetted.com/p/mailbox-org): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Posteo](https://euvetted.com/p/posteo): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Mailfence](https://euvetted.com/p/mailfence): hosted in Belgium, CLOUD Act: none, ownership: eu_owned - [StartMail](https://euvetted.com/p/startmail): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Infomaniak Mail (kSuite)](https://euvetted.com/p/infomaniak-mail): hosted in Switzerland, CLOUD Act: none, ownership: other - [Kolab Now](https://euvetted.com/p/kolab-now): hosted in Switzerland, CLOUD Act: none, ownership: other - [Mailo](https://euvetted.com/p/mailo): hosted in France, CLOUD Act: none, ownership: eu_owned - [Runbox](https://euvetted.com/p/runbox): hosted in Norway, CLOUD Act: none, ownership: other - [Soverin](https://euvetted.com/p/soverin): hosted in Netherlands, CLOUD Act: none, ownership: eu_owned **Q: Is Outlook usable under GDPR?** Outlook.com and Microsoft 365 / Exchange Online are legally usable from the EU: Microsoft publishes an EU Standard Contractual Clauses-based Data Processing Addendum with post-Schrems II supplementary measures, operates the EU Data Boundary for Microsoft 365, and offers EU data residency for stored mailbox data. US ownership, not the residency region, is why the alternative search continues: Microsoft Corporation is US-incorporated and publicly listed (NASDAQ: MSFT), so the consolidated group falls within the reach of the US CLOUD Act regardless of which region stores the mailbox. For a transfer impact assessment, that combination of US ownership plus mail content stored in the cloud is what prompts the alternative search. **Q: Which Outlook alternative has the strongest compliance profile?** Among the alternatives mapped on this page, Proton Mail (Switzerland) has the strongest privacy posture: end-to-end + zero-access encryption (Proton itself cannot read message content), Swiss jurisdiction under an EU adequacy decision, non-profit Proton Foundation ownership, ISO 27001, and CLOUD Act exposure: [[proton-mail.cloud_act]] (a transient sub-processor; data at rest stays in the EU). For a fully-German answer, Tuta (Hannover) runs its own German data centre with post-quantum end-to-end encryption, and Mailbox.org (Berlin) holds the rare combination of ISO 27001 plus BSI C5, the German Federal Office for Information Security's standard for trusted cloud services. Posteo (Berlin) and Mailfence (Belgium) are also EU-owned and EU-hosted (CLOUD Act exposure, Posteo: [[posteo.cloud_act]], Mailfence: [[mailfence.cloud_act]]). **Q: Can I keep my email address when I switch from Outlook?** If you use your own custom domain (you@yourcompany.com), yes, you move the domain's MX records to the new provider and your address is unchanged. Every paid plan on this page supports custom domains. If you currently use an @outlook.com, @hotmail.com or @live.com address, that address stays with Microsoft and cannot be transferred; the standard path is to set up forwarding from the old address to the new mailbox for 6–12 months while you update your contacts, logins, and account recovery details. Most teams on a company domain complete the switch with zero address changes. **Q: How do I migrate my existing Outlook mailbox?** Mail migrates over IMAP. Most European providers (Proton Mail via the Easy Switch / Import-Export tool, Mailbox.org, Tuta, Infomaniak, Posteo) offer a built-in importer that connects to your Outlook / Microsoft 365 account and copies your existing folders, messages, and structure across. Calendars export as .ics and contacts as .vcf / .csv, then import into the new account. The practical sequence: create the new mailbox, run the IMAP import, set up forwarding from Outlook, test send/receive for a week, then switch the domain's MX records last so new mail lands in the new mailbox. **Q: Does Outlook fall under the US CLOUD Act?** Yes. Microsoft Corporation is US-incorporated and publicly listed (NASDAQ: MSFT), so the consolidated group falls within the reach of the US CLOUD Act. A US authority can compel Microsoft to produce mailbox data it controls regardless of whether that data is stored in an EU data centre or under the EU Data Boundary. Microsoft's EU residency commitments reduce where data sits but do not remove the underlying ownership question. The EU-owned and Swiss providers on this page (Proton Mail, Tuta, Mailbox.org, Posteo, Mailfence, Infomaniak) are not US-incorporated, which removes that direct exposure. That's a read on corporate structure drawn from public information, not an assertion about any particular data request. **Q: Which European email providers offer end-to-end encryption?** Proton Mail and Tuta both ship end-to-end encryption by default, meaning the provider cannot read your message content even in response to a legal request; Tuta additionally uses post-quantum cryptography. Mailbox.org, Mailfence, and Posteo support OpenPGP for end-to-end-encrypted mail with other PGP users, but mail is not zero-access encrypted by default. For the strongest confidentiality requirement (legal, healthcare, journalism, activism), Proton Mail and Tuta are the two to evaluate first. Note that end-to-end encryption only applies between users whose clients both support it; mail sent to a standard Outlook or Gmail recipient travels with transport encryption unless you use a password-protected message. **Q: Is there a German-hosted alternative to Outlook for business?** Yes. Mailbox.org (Heinlein Support GmbH, Berlin) is the procurement-grade German pick: own German data centres, ISO 27001 + BSI C5, OpenPGP support, and a bundled Mail + Drive + Calendar + Office suite from €1/month: a direct Microsoft 365 Mail replacement for DACH buyers who need a German vendor on the contract. Tuta (Hannover) is the strongest fully-German privacy option with its own data centre and post-quantum end-to-end encryption. Posteo (Berlin) is the cheapest German option with a strong green-energy and data-minimisation story. For a Swiss-hosted business suite, Infomaniak's kSuite (Geneva) bundles mail with drive, calendar and meet. **Q: Can a European email provider replace Microsoft 365 / Exchange for a whole team?** For the core mail, calendar, and contacts workflow, yes. Mailbox.org, Infomaniak kSuite, and Proton (Mail + Calendar + Drive) all cover shared domains, multiple mailboxes, calendars, and address books with mobile and desktop sync. What you give up is the deep Microsoft 365 integration: Teams meetings tied to Exchange calendars, shared room/resource mailboxes, SharePoint document co-authoring, and Copilot. Teams that mainly need reliable business email on their own domain switch cleanly; teams whose daily workflow is built around Teams and SharePoint should plan those replacements separately (see our Microsoft Teams alternatives page) rather than expecting the email provider to cover them. ### European alternatives to PayPal: https://euvetted.com/alternatives/paypal _About PayPal:_ US-incorporated payments giant, NASDAQ-listed. Adyen (Netherlands, Amsterdam) is the strongest European alternative to PayPal: EU-owned, EU-hosted, PSD2-regulated, with minimal CLOUD Act exposure and ISO 27001 certification, making it the enterprise standard for high-volume European e-commerce. For SMBs wanting the smoothest migration with iDEAL, SEPA, and Bancontact, Mollie (Netherlands, EU-owned and EU-hosted) is the top pick. For BNPL-centric European checkouts, Klarna (Sweden, EU-owned and EU-hosted) leads. Verified European alternatives (7): - [Adyen](https://euvetted.com/p/adyen): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Dintero](https://euvetted.com/p/dintero): hosted in Norway, CLOUD Act: minor, ownership: other - [GoCardless](https://euvetted.com/p/gocardless): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Mollie](https://euvetted.com/p/mollie): hosted in Netherlands, CLOUD Act: material, ownership: eu_hq_us_funded - [Klarna](https://euvetted.com/p/klarna): hosted in Sweden, CLOUD Act: material, ownership: eu_hq_us_funded - [SumUp](https://euvetted.com/p/sumup): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [Trustly](https://euvetted.com/p/trustly): hosted in Sweden, CLOUD Act: material, ownership: eu_hq_us_funded **Q: Is PayPal usable under GDPR?** PayPal Holdings, Inc. publishes a Data Processing Addendum based on the EU Standard Contractual Clauses with post-Schrems II supplementary measures, and operates PayPal (Europe) S.à r.l. et Cie, S.C.A. as the regulated European entity (a Luxembourg-licensed credit institution). The service is legally usable from the EU. What keeps merchants evaluating alternatives anyway is the ownership layer beneath that paperwork: PayPal Holdings, Inc. is US-incorporated (NASDAQ: PYPL), and the parent corporate structure means CLOUD Act jurisdiction applies despite the Luxembourg-licensed subsidiary. For higher-volume merchants, the fee structure also typically favours European alternatives. **Q: Which PayPal alternative has the strongest compliance profile?** Among the alternatives mapped on this page, Adyen (Netherlands, Amsterdam hosting) has the strongest profile: EU-owned, EU-hosted, PSD2-regulated, ISO 27001 certified, and with minimal CLOUD Act exposure. Mollie (Netherlands, Amsterdam), GoCardless (UK), Klarna (Sweden), SumUp (UK), and Trustly (Sweden, Stockholm) are all EU- or UK-owned with primary EU/UK infrastructure, but carry material exposure via shared sub-processors. For high-volume enterprise European e-commerce, Adyen is the cleanest pick; for marketplace and SMB use cases, Mollie has the smoothest UX. **Q: Can I migrate my PayPal customer database?** Customer email lists can be exported from PayPal Reports (transaction history, customer reports). Saved payment method credentials (card-on-file, PayPal accounts) cannot be ported between processors due to PCI-DSS regulations. The mitigation is straightforward: when an existing customer returns to your checkout, route them through a re-authorisation flow on the new processor. For subscription businesses, send proactive emails before the next charge cycle to update payment methods. **Q: What about PayPal's buyer protection and dispute handling?** PayPal's buyer protection is widely recognised by consumers, and removing the PayPal button from your checkout can cause a temporary conversion dip. The European alternatives offer comparable dispute-resolution infrastructure (Adyen, Mollie, Klarna all have payment-method-specific consumer protections under PSD2), but the brand recognition is different. Many European e-commerce stores keep PayPal alongside a European primary processor for the first 6–12 months of migration to smooth the customer-perception transition. **Q: What about Apple Pay, Google Pay, and pay-later options?** Apple Pay and Google Pay are supported by Adyen, Mollie, and Klarna. Note that both are US-controlled wallet platforms, so using them means a US sub-processor sits in your checkout flow regardless of which European PSP you use. For pay-later (BNPL), Klarna is the European leader; Mollie integrates with Klarna for BNPL availability on its merchant tier; Adyen supports multiple BNPL providers via its unified API. **Q: Does PayPal fall under the US CLOUD Act?** In practice, yes. PayPal Holdings, Inc. is US-incorporated (NASDAQ: PYPL), and the consolidated corporate structure, including the Luxembourg-licensed subsidiary PayPal (Europe) S.à r.l. et Cie, S.C.A., falls within the reach of the US CLOUD Act, which can compel a US company to produce data it controls regardless of where that data is stored. The Luxembourg subsidiary structure satisfies EU payment-regulation requirements (as a licensed credit institution) but does not eliminate the US legal authority over the parent. Adyen on this page is EU-owned and EU-hosted (Netherlands, Amsterdam), removing that direct exposure. That's a read of the corporate chain, not a claim that any particular data request has occurred. **Q: What is the cheapest European alternative to PayPal?** For low-to-medium volume European e-commerce, Mollie (Netherlands) is typically the most cost-accessible option: per-transaction pricing with no monthly minimum, comparable to PayPal's standard rate card for European merchants. SumUp (UK-owned, EU-hosted) is competitive for very low-volume in-person and online merchants with a flat-rate transaction model. Adyen's interchange-plus pricing becomes the most competitive at high volume (€100k+/month) but has a minimum monthly fee that makes it less suitable for micro-merchants. Exact rates depend on payment method, card type, and volume; confirm current pricing with each vendor. **Q: Is there a GDPR-compliant alternative to PayPal?** All six European alternatives mapped on this page (Adyen, Mollie, Klarna, GoCardless, SumUp, and Trustly) are GDPR-compliant by design: EU or UK data residency, published DPAs based on SCCs, and PSD2-regulated. Adyen additionally is EU-owned, EU-hosted in Amsterdam, with minimal CLOUD Act exposure, making it the strongest pick for regulated-industry procurement that requires a clean EU-ownership chain. All are preferable to the EU-subsidiary-with-US-parent structure of PayPal Holdings. **Q: Can a European payment processor handle marketplace payouts?** Yes, with the right specialist. Adyen and Mollie both have payout APIs for marketplace use cases, but the dedicated European marketplace-payout specialists are Mangopay (Luxembourg) and Lemonway (France). Both are PSD2-licensed e-money institutions built specifically for multi-sided marketplace models: escrow, multi-party payment splitting, seller KYC, and regulatory compliance for marketplace operators. For marketplaces currently using PayPal Payouts, Mangopay is typically the closest structural replacement. ### European alternatives to Pipedrive: https://euvetted.com/alternatives/pipedrive _About Pipedrive:_ Estonian-rooted CRM, majority owned by Vista Equity Partners (US) since 2020. EU brand, US-PE controlled. Cross-reference: listed in our directory as a product. Verified European alternatives (3): - [Capsule CRM](https://euvetted.com/p/capsule): hosted in United States, CLOUD Act: material, ownership: other - [centralstationCRM](https://euvetted.com/p/centralstationcrm): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Salesflare](https://euvetted.com/p/salesflare): hosted in Belgium, CLOUD Act: material, ownership: eu_owned ### European alternatives to Plaid: https://euvetted.com/alternatives/plaid _About Plaid:_ US-incorporated open banking infrastructure provider, San Francisco HQ. GoCardless (UK, bank account data plus direct debit), Trustly (Sweden, account-to-account payments across 33 markets), and Volt (UK, real-time A2A across 2,500 connected banks) are the European alternatives to Plaid on EU Vetted's editorial assessment. Which one fits depends on what you use Plaid for: account data goes to GoCardless, payments go to Trustly or Volt. Honest caveat: none of the three has a fully clean EU ownership chain; all carry UK jurisdiction or US-investor exposure. Verified European alternatives (3): - [Trustly](https://euvetted.com/p/trustly): hosted in Sweden, CLOUD Act: material, ownership: eu_hq_us_funded - [Volt](https://euvetted.com/p/volt): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [GoCardless](https://euvetted.com/p/gocardless): hosted in United Kingdom, CLOUD Act: material, ownership: other **Q: Does Plaid even work in Europe?** Yes. Plaid operates in the EU and UK through licensed local entities and connects to European banks through PSD2 interfaces. The reason European buyers look at alternatives is not availability, it is structure: Plaid Inc. is US-incorporated with headquarters in San Francisco, so the consolidated group sits under US CLOUD Act jurisdiction, and bank-account data is among the more sensitive categories a vendor can hold. **Q: What is the difference between account data (AIS) and payments (PIS)?** PSD2 splits open banking into two regulated roles. Account information services (AIS) read balances and transactions with the user's consent: lenders checking affordability, accounting tools syncing bank feeds. Payment initiation services (PIS) move money directly from the user's account: checkout, top-ups, payouts. Plaid bundles both behind one API. In Europe the specialists split: GoCardless for data, Trustly and Volt for payments. Knowing which half you actually use is the first step of any migration. **Q: Which alternative covers bank account data like Plaid Transactions?** GoCardless. Its Bank Account Data product (the former Nordigen, acquired in 2022) provides PSD2 account information coverage across European banks and is the established European answer to Plaid's data products. GoCardless is UK-based and FCA-authorised; note that Mollie announced an acquisition of GoCardless in December 2025, pending regulatory approval, so its ownership answer is currently in transition. **Q: Which alternative covers payments like Plaid Payment Initiation?** Trustly (Sweden, Stockholm) is the established account-to-account player: around US$10B in annual volume across 33+ markets, strong in the Nordics, used for pay-ins and payouts. Volt (UK, London) is the newer real-time A2A network with 2,500 connected banks across 31 territories. Both are licensed European payment institutions; both carry US-investor caveats in our assessment ([[trustly.cloud_act]] and [[volt.cloud_act]] exposure respectively). **Q: Is there a fully EU-owned Plaid replacement?** Not in our dataset at the time of this audit, and pretending otherwise would not help you. GoCardless and Volt are UK-jurisdiction with mixed cap tables; Trustly is Swedish with Nordic Capital and BlackRock private equity as owners. Tink, the other large European aggregator, was acquired by Visa in 2022, which is why it is not listed here as an EU-owned answer. If your screening requires a clean EU ownership chain end to end, open banking is currently a category where you document the exception rather than avoid it. **Q: Do I need my own PSD2 licence to use these providers?** Generally no; that is the point of using them. GoCardless, Trustly, and Volt hold their own AIS/PIS authorisations and you operate under their regulated umbrella, the same way you use Plaid's licences today. If you are building a regulated financial product yourself, your own licensing questions are separate and belong with your counsel. **Q: What does migrating off Plaid actually involve?** The hard part is not your code, it is your users' bank connections. Consents and account links do not transfer between providers: every connected user must re-link their bank through the new provider's flow, and PSD2 consent renewal rules mean dormant links expire anyway. Plan it like a re-onboarding campaign with in-product prompts and a long tail, not like an API swap. The API rewrite itself (auth, webhooks, data models) is ordinary integration work. **Q: We also have US users. Can a European provider cover them?** Mostly no, and it is better to hear that early. US bank connectivity is Plaid's home advantage; the European alternatives focus on EEA and UK coverage. Products with meaningful US user bases usually end up running Plaid for US accounts alongside a European provider for EEA/UK accounts, which also happens to shrink the data exposure on each side to its own region. ### European alternatives to Plausible Analytics: https://euvetted.com/alternatives/plausible _About Plausible Analytics:_ Estonian-incorporated privacy-first analytics, bootstrapped and self-funded. Cross-reference: listed in our directory as a product. Verified European alternatives (5): - [GoatCounter](https://euvetted.com/p/goatcounter): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Trackboxx](https://euvetted.com/p/trackboxx): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Umami](https://euvetted.com/p/umami): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Pirsch Analytics](https://euvetted.com/p/pirsch): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Wide Angle Analytics](https://euvetted.com/p/wide-angle-analytics): hosted in France, CLOUD Act: minor, ownership: eu_owned ### European alternatives to Proton VPN: https://euvetted.com/alternatives/protonvpn _About Proton VPN:_ Swiss VPN within the Proton AG ecosystem, non-profit Foundation-controlled. Cross-reference: listed in our directory as a product. Verified European alternatives (6): - [F-Secure VPN](https://euvetted.com/p/f-secure-vpn): hosted in Finland, CLOUD Act: minor, ownership: eu_owned - [Mullvad VPN](https://euvetted.com/p/mullvad): hosted in Sweden, CLOUD Act: none, ownership: eu_owned - [Opera VPN](https://euvetted.com/p/opera-vpn): hosted in Norway, CLOUD Act: material, ownership: other - [IVPN](https://euvetted.com/p/ivpn): hosted in Gibraltar, CLOUD Act: none, ownership: other - [AirVPN](https://euvetted.com/p/airvpn): hosted in Italy, CLOUD Act: none, ownership: eu_owned - [OVPN](https://euvetted.com/p/ovpn): hosted in Sweden, CLOUD Act: none, ownership: eu_owned ### European alternatives to Qualaroo: https://euvetted.com/alternatives/qualaroo _About Qualaroo:_ US-owned in-product survey tool, part of ProProfs. Verified European alternatives (5): - [Formbricks](https://euvetted.com/p/formbricks): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Survicate](https://euvetted.com/p/survicate): hosted in Ireland, CLOUD Act: material, ownership: eu_owned - [LimeSurvey](https://euvetted.com/p/limesurvey): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Typeform](https://euvetted.com/p/typeform): hosted in United States, CLOUD Act: material, ownership: eu_hq_us_funded - [Tally](https://euvetted.com/p/tally): hosted in Belgium, CLOUD Act: material, ownership: eu_owned ### European alternatives to QuickBooks Online: https://euvetted.com/alternatives/quickbooks _About QuickBooks Online:_ Intuit Inc. (Nasdaq: INTU). US-owned SMB accounting market leader; direct CLOUD Act exposure. Verified European alternatives (8): - [Conta](https://euvetted.com/p/conta): hosted in Ireland, CLOUD Act: material, ownership: other - [Fiken](https://euvetted.com/p/fiken): hosted in Norway, CLOUD Act: material, ownership: other - [Lexware](https://euvetted.com/p/lexware): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Pennylane](https://euvetted.com/p/pennylane): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [PowerOffice Go](https://euvetted.com/p/poweroffice-go): hosted in Netherlands, CLOUD Act: material, ownership: eu_hq_us_funded - [Sage Accounting](https://euvetted.com/p/sage-accounting): hosted in United Kingdom, CLOUD Act: minor, ownership: other - [sevdesk](https://euvetted.com/p/sevdesk): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Visma eAccounting](https://euvetted.com/p/visma-eaccounting): hosted in Norway, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to RingCentral: https://euvetted.com/alternatives/ringcentral _About RingCentral:_ US-incorporated UCaaS provider, NYSE-listed (RNG). Verified European alternatives (5): - [sipgate](https://euvetted.com/p/sipgate): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Pexip](https://euvetted.com/p/pexip): hosted in Norway, CLOUD Act: material, ownership: other - [Whereby](https://euvetted.com/p/whereby): hosted in Ireland, CLOUD Act: minor, ownership: other - [Element (Matrix)](https://euvetted.com/p/element-matrix): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Wire](https://euvetted.com/p/wire): hosted in Switzerland, CLOUD Act: material, ownership: other ### European alternatives to Roam Research: https://euvetted.com/alternatives/roam-research _About Roam Research:_ US-incorporated networked-thought note-taking app. Verified European alternatives (3): - [Joplin](https://euvetted.com/p/joplin): hosted in France, CLOUD Act: none, ownership: eu_owned - [Anytype](https://euvetted.com/p/anytype): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Nuclino](https://euvetted.com/p/nuclino): hosted in Germany, CLOUD Act: material, ownership: eu_owned ### European alternatives to Sailthru: https://euvetted.com/alternatives/sailthru _About Sailthru:_ US-owned email + personalization platform, part of Marigold. Verified European alternatives (5): - [CleverReach](https://euvetted.com/p/cleverreach): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Inxmail](https://euvetted.com/p/inxmail): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Maileon](https://euvetted.com/p/maileon): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Brevo](https://euvetted.com/p/brevo): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [GetResponse](https://euvetted.com/p/getresponse): hosted in Poland, CLOUD Act: material, ownership: eu_owned ### European alternatives to Salesforce: https://euvetted.com/alternatives/salesforce _About Salesforce:_ US-incorporated enterprise CRM. Largest single CLOUD Act surface in B2B SaaS. centralstationCRM (Germany) and weclapp (Germany, Frankfurt) are the strongest European CRM alternatives to Salesforce on EU Vetted's editorial assessment. centralstationCRM is EU-owned, EU-hosted, and carries no material CLOUD Act exposure; weclapp is EU-owned and EU-hosted with Frankfurt infrastructure. YetiForce (Poland, open source) is also EU-owned, EU-hosted, and self-hostable on EU sovereign cloud with no material CLOUD Act exposure. No European CRM matches Salesforce's full seven-cloud enterprise surface; the realistic strategy is to identify which Salesforce clouds you actually use before evaluating alternatives. Salesforce, Inc. is US-incorporated; CLOUD Act jurisdiction applies regardless of Hyperforce EU data residency. Verified European alternatives (11): - [combit CRM](https://euvetted.com/p/combit-crm): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Workbooks](https://euvetted.com/p/workbooks): hosted in United Kingdom, CLOUD Act: material, ownership: other - [YetiForce](https://euvetted.com/p/yetiforce): hosted in Poland, CLOUD Act: minor, ownership: eu_owned - [Capsule CRM](https://euvetted.com/p/capsule): hosted in United States, CLOUD Act: material, ownership: other - [centralstationCRM](https://euvetted.com/p/centralstationcrm): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Lime CRM](https://euvetted.com/p/lime-crm): hosted in Sweden, CLOUD Act: minor, ownership: eu_owned - [Pipedrive](https://euvetted.com/p/pipedrive): hosted in Estonia, CLOUD Act: material, ownership: eu_hq_us_funded - [Salesflare](https://euvetted.com/p/salesflare): hosted in Belgium, CLOUD Act: material, ownership: eu_owned - [SuperOffice](https://euvetted.com/p/superoffice): hosted in Norway, CLOUD Act: material, ownership: eu_hq_us_funded - [Teamleader](https://euvetted.com/p/teamleader): hosted in Ireland, CLOUD Act: material, ownership: other - [weclapp](https://euvetted.com/p/weclapp): hosted in Germany, CLOUD Act: material, ownership: eu_owned **Q: Is Salesforce usable under GDPR?** Salesforce publishes a Data Processing Addendum based on the EU Standard Contractual Clauses with post-Schrems II supplementary measures and offers a Hyperforce EU residency option that keeps customer data in the EU. Procurement teams keep evaluating alternatives anyway because of the underlying ownership: Salesforce, Inc. is US-incorporated and publicly listed (NYSE: CRM), and the parent corporate structure means CLOUD Act jurisdiction applies regardless of which region hosts the data. For a transfer impact assessment, that combination is what prompts the alternative search. **Q: Can a European CRM realistically replace Salesforce for an enterprise?** It depends on which Salesforce surface area you actually use. Salesforce ships seven major clouds (Sales, Service, Marketing, Commerce, Experience, Analytics, Platform); most European customers use only Sales + Service + maybe Marketing. For Sales Cloud functionality, weclapp, Pipedrive, SuperOffice, and Lime CRM all reach the same depth at SMB-to-mid-market scale. For Service Cloud, pair with a European helpdesk (Crisp, Userlike; see our Intercom alternatives). For Marketing Cloud, pair with a European email marketing tool (CleverReach, MailerLite; see our Mailchimp alternatives). **Q: Which Salesforce alternative has the strongest compliance profile?** Among the alternatives mapped on this page, centralstationCRM (Germany), combit CRM (Germany, Konstanz), and YetiForce (Poland, open source) all have no material CLOUD Act exposure and are EU-owned and EU-hosted. weclapp (Germany, Frankfurt) is EU-owned and EU-hosted with ISO 27001 certification; Lime CRM (Sweden) is EU-owned and EU-hosted with disclosed sub-processors. For enterprise scale specifically, weclapp is the most direct Salesforce replacement among the strongest-signal set. **Q: Can I export my Salesforce data?** Yes. Salesforce supports CSV export of all standard objects (Accounts, Contacts, Leads, Opportunities, Cases, Activities) via *Setup → Data Management → Data Export*. The exports preserve custom fields and relationships. What does not transfer cleanly: Salesforce Apex code, custom Lightning components, complex workflow automations, and report-and-dashboard definitions. Most of these need to be rebuilt rather than imported into the new tool. **Q: What about all the Salesforce-native integrations our team relies on?** Most enterprise Salesforce integrations (DocuSign, Slack, Outreach, ZoomInfo) have native or Zapier-mediated equivalents on European CRMs. The big gap is third-party AppExchange apps without a European equivalent, usually 5–15 per enterprise. Audit your AppExchange dependencies before migration; for any with no European peer, plan to either keep that workflow on Salesforce (if procurement allows) or build a webhook-based replacement. **Q: Does Salesforce fall under the US CLOUD Act?** In practice, yes. Salesforce, Inc. is US-incorporated and publicly listed (NYSE: CRM). The consolidated group (including the Hyperforce EU-region infrastructure) falls within the reach of the US CLOUD Act, which can compel a US company to produce data it controls regardless of where it is stored. Hyperforce EU data residency keeps data physically in the EU but does not change the CLOUD Act exposure at the parent-company level. centralstationCRM, combit CRM, and YetiForce (all EU-owned and EU-hosted with no US parent in the corporate chain) are the alternatives on this page with no material CLOUD Act exposure. That's a read on who owns and controls each company, not an allegation about any given data request. **Q: What is the cheapest European alternative to Salesforce?** centralstationCRM (Germany, EU-owned, EU-hosted, no CLOUD Act exposure) is among the most accessible-priced European CRMs for small teams, with per-seat pricing suited to teams of 3–30. YetiForce (Poland, EU-owned, open source) is free to self-host under an open-source licence, making the total cost of ownership dependent on your EU cloud hosting bill rather than a vendor licence. Pipedrive (Estonia, EU-owned but with US sub-processors introducing some CLOUD Act exposure) and Salesflare (Belgium, EU-owned, EU-hosted) both offer competitive per-seat pricing with trial periods. Exact rates change frequently; confirm current pricing on each vendor's page before committing. **Q: Is there a GDPR-compliant Salesforce alternative that is self-hostable on EU sovereign cloud?** YetiForce (Poland, EU-owned, open source) is the strongest answer. It is self-hostable on any EU cloud provider (Scaleway, OVH, Hetzner, or your own data centre) and carries no material CLOUD Act exposure. The trade-off is operational overhead: you need an SRE-capable team to maintain the application stack. For organisations without that capacity, centralstationCRM (Germany, EU-owned, EU-hosted, no CLOUD Act exposure) is the managed-service alternative with a comparable compliance profile. **Q: Which European CRM is best for teams that are also leaving Slack?** Teams migrating from both Salesforce and Slack simultaneously face a sequencing decision. On EU Vetted's editorial mapping, the European alternatives to Salesforce that integrate most cleanly with the European Slack alternatives (Stackfield, Element/Matrix, Wire) are weclapp and centralstationCRM via webhook or Zapier. For teams already committed to Pipedrive as their Salesforce alternative, Stackfield has a documented Pipedrive integration. Sequencing: migrate the CRM first, then messaging, since CRM data is the higher-risk migration. **Q: Can a European CRM handle multi-currency and EU VAT for international sales teams?** weclapp (Germany, EU-owned, EU-hosted) handles multi-currency natively alongside its ERP and invoicing modules, making it the strongest answer for DACH teams that need CRM + invoicing in one product with proper EU VAT handling. Pipedrive (Estonia, EU-owned but with US sub-processors) supports multi-currency in the pipeline view; for VAT-compliant invoicing it is typically paired with a European accounting tool such as Lexoffice, sevDesk, or Pennylane. centralstationCRM is a pure-CRM product without invoicing. ### European alternatives to Sanity: https://euvetted.com/alternatives/sanity _About Sanity:_ Norwegian-founded but San Francisco-headquartered headless CMS (Sanity Inc.). US-incorporated parent; direct CLOUD Act exposure. Verified European alternatives (6): - [DatoCMS](https://euvetted.com/p/datocms): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [Enonic](https://euvetted.com/p/enonic): hosted in Norway, CLOUD Act: material, ownership: other - [Hygraph](https://euvetted.com/p/hygraph): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Prismic](https://euvetted.com/p/prismic): hosted in United States, CLOUD Act: minor, ownership: eu_owned - [Storyblok](https://euvetted.com/p/storyblok): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Strapi](https://euvetted.com/p/strapi): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to SavvyCal: https://euvetted.com/alternatives/savvycal _About SavvyCal:_ US-incorporated polished scheduling tool, indie-built. Verified European alternatives (4): - [Cal.com](https://euvetted.com/p/cal-com): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Cronofy](https://euvetted.com/p/cronofy): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Doodle](https://euvetted.com/p/doodle): hosted in Germany, CLOUD Act: minor, ownership: other - [SuperSaaS](https://euvetted.com/p/supersaas): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned ### European alternatives to SendGrid: https://euvetted.com/alternatives/sendgrid _About SendGrid:_ Twilio-owned transactional email API. US-incorporated. Mailjet (France, Paris, EU-owned, EU-only data centres, ISO 27001, CLOUD Act exposure: [[mailjet.cloud_act]]) is the closest European replacement for SendGrid as a transactional email API plus SMTP relay, and Brevo (France, Paris, EU-headquartered, transactional API with SMS and CRM, CLOUD Act exposure: [[brevo.cloud_act]]) is the broader multi-channel option. Both are transactional-capable but carry material CLOUD Act exposure through their sub-processor chains, so they improve jurisdiction and hosting without removing exposure entirely. For the cleanest jurisdiction, Infomaniak (Switzerland, Geneva, Swiss-owned, own data centres, CLOUD Act exposure: none) operates transactional sending from Switzerland. The zero-exposure German options in this category (Maileon, CleverReach) are marketing-newsletter tools, not transactional APIs, so match them to the job. Verified European alternatives (8): - [Omnivery](https://euvetted.com/p/omnivery): hosted in Czechia, CLOUD Act: minor, ownership: eu_owned - [Brevo](https://euvetted.com/p/brevo): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [Inxmail](https://euvetted.com/p/inxmail): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Maileon](https://euvetted.com/p/maileon): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [MailerLite](https://euvetted.com/p/mailerlite): hosted in Netherlands, CLOUD Act: material, ownership: eu_owned - [Mailjet](https://euvetted.com/p/mailjet): hosted in France, CLOUD Act: material, ownership: eu_owned - [Keila](https://euvetted.com/p/keila): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Infomaniak Newsletter](https://euvetted.com/p/infomaniak-newsletter): hosted in Switzerland, CLOUD Act: none, ownership: other **Q: Is SendGrid GDPR-compliant?** SendGrid publishes an EU Standard Contractual Clauses-based DPA and offers an EU data-residency region, so it is legally usable from the EU. Ownership, not the residency region, is what keeps the search going: SendGrid is owned by Twilio, Inc., a US-incorporated public company (NYSE: TWLO), so the consolidated group falls under CLOUD Act jurisdiction regardless of where email data is stored. For a transfer impact assessment on the recipient data, sender identity, and message content a mail API holds, that is what prompts the alternative search. **Q: Which SendGrid alternative is an actual transactional email API, not a newsletter tool?** This distinction matters in this category. SendGrid is a transactional email API (REST API, SMTP relay, event webhooks for deliveries, bounces, opens). The European options built for the same job are Mailjet (transactional and marketing API with SMTP relay, France, EU data centres, CLOUD Act exposure: [[mailjet.cloud_act]]) and Brevo (transactional API plus SMS, CRM, and automation, France, CLOUD Act exposure: [[brevo.cloud_act]]). Infomaniak (Switzerland) also runs transactional sending. Several other listings in this category (Maileon, CleverReach, rapidmail, Inxmail) are marketing-newsletter platforms, not transactional APIs; they are strong for campaigns, not for app-generated receipts and password resets. **Q: Do any SendGrid alternatives remove CLOUD Act exposure entirely?** Not among the direct transactional-API replacements. Mailjet and Brevo are EU-owned or EU-headquartered and host in the EU, but both carry material CLOUD Act exposure via their sub-processor chains (Mailjet: [[mailjet.cloud_act]], Brevo: [[brevo.cloud_act]]). The provider in this category with no material CLOUD Act exposure for transactional sending is Infomaniak (Switzerland, own Swiss data centres). If a hard zero-US-involvement requirement is the binding constraint and you need a transactional API, Infomaniak is the one to assess first, then verify the current sub-processor list against your transfer impact assessment. **Q: Will my SendGrid integration and templates transfer?** Partly, and the API layer is the main work. Mailjet and Brevo both expose REST APIs and SMTP relays, so the send mechanism maps over, but the endpoints, authentication, and payload shape differ from SendGrid's. You rewrite the integration code and re-point your app. Dynamic templates rebuild rather than import: SendGrid uses Handlebars syntax, while Mailjet and Brevo use their own template languages, so recreate your three or four most-used templates by hand. Event webhooks (delivery, bounce, open, click) exist on both but with different payloads, so update your webhook handlers. **Q: What about email deliverability after switching?** Deliverability is tied to sending domain and IP reputation, so plan a warm-up. If you change sending domain or move to a new IP pool, expect a temporary dip while the new reputation builds, typically one to two weeks on a clean list. Mailjet and Brevo both offer dedicated-IP options with guided warm-up on higher tiers; Infomaniak sends from its own Swiss infrastructure. Keep SPF, DKIM, and DMARC aligned on the new sending domain before cutover, and migrate in stages (transactional first, bulk later) so a reputation dip never hits critical mail like password resets. **Q: Is there a GDPR-compliant alternative to SendGrid with EU data residency?** Yes. Mailjet operates EU-only data centres and is ISO 27001-certified (France, EU-owned, CLOUD Act exposure: [[mailjet.cloud_act]]); Brevo is EU-headquartered with a public DPA (France, CLOUD Act exposure: [[brevo.cloud_act]]); and Infomaniak runs its own Swiss data centres with no material CLOUD Act exposure. All three publish GDPR-compliant data processing agreements. EU data residency is the baseline they share; where they differ is the sub-processor chain, which is what separates Infomaniak's clean exposure from Mailjet's and Brevo's material flags. **Q: What is the cheapest European alternative to SendGrid?** Mailjet and Brevo both start at around [[mailjet.price_from]] per month for paid sending tiers and offer free tiers for low send volumes, which makes them accessible for a small app's transactional mail. Brevo's free tier is volume-limited rather than contact-limited, which suits spiky transactional patterns. Confirm current send-volume limits on each vendor's pricing page, as transactional-email pricing is metered by emails sent and changes frequently. **Q: Can a European provider handle high-volume transactional sending?** Yes. Mailjet and Brevo both run at scale for transactional and marketing volume, with dedicated IPs, sub-accounts, and the throughput controls high-volume senders need. The practical gating factor is not capacity but reputation management (dedicated IP allocation, warm-up, and bounce handling) which both support on business tiers. For regulated senders who want Swiss jurisdiction at volume, Infomaniak is the sovereignty-first option; benchmark its throughput limits against your peak send rate before committing. ### European alternatives to Shopify: https://euvetted.com/alternatives/shopify _About Shopify:_ Canadian-headquartered hosted commerce platform (TSX/NYSE: SHOP). Not US but North American; SMB DTC market leader with US sub-processor stack. Shopware (Germany, Schöppingen) and PrestaShop (France, Paris) are the two most prominent European alternatives to Shopify, both open-source platforms whose self-hosted editions, run on EU infrastructure, put the data chain entirely under your control. Note that their managed clouds carry US-ownership stakes (PayPal holds ~41% of Shopware; PrestaShop's parent Fortidia is Oaktree-owned). For the cleanest EU ownership, Sylius (Poland, MIT open-source, EU-owned) is the developer/B2B pick, and MyCashflow (Finland, own Helsinki hosting, EU-owned) is the cleanest fully-managed EU SaaS. Shopify Inc. is Canadian-headquartered, US-stock-listed, and runs on Google Cloud, so EU merchant data sits on US-controlled infrastructure. Verified European alternatives (6): - [Shopware](https://euvetted.com/p/shopware): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [PrestaShop](https://euvetted.com/p/prestashop): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [Sylius](https://euvetted.com/p/sylius): hosted in Poland, CLOUD Act: none, ownership: eu_owned - [MyCashflow](https://euvetted.com/p/mycashflow): hosted in Finland, CLOUD Act: none, ownership: eu_owned - [Saleor Commerce](https://euvetted.com/p/saleor): hosted in Ireland, CLOUD Act: material, ownership: eu_owned - [CCV Shop](https://euvetted.com/p/ccv-shop): hosted in Netherlands, CLOUD Act: material, ownership: eu_hq_us_funded **Q: Is Shopify a problem under GDPR?** Shopify is legally usable from the EU. It publishes a DPA with Standard Contractual Clauses. The nuance European merchants weigh is infrastructure and ownership: Shopify Inc. is Canadian-headquartered and listed on the NYSE/TSX, and the Shopify platform runs on Google Cloud, a US hyperscaler. So EU merchant and customer data is processed on US-controlled infrastructure, which brings CLOUD Act exposure at the hosting layer even though Shopify itself is Canadian. For merchants who want their store data on genuinely EU-controlled infrastructure, that is what prompts the alternative search. **Q: Is there a true EU-owned, EU-hosted alternative to Shopify?** Partly, and being honest about it matters. There is no EU-owned managed SaaS at Shopify's scale and price point. The cleanest fully-managed EU SaaS is MyCashflow (Finland), which runs on its own Helsinki infrastructure with no hyperscaler dependency, but it is a smaller platform. The most capable European platforms (Shopware, PrestaShop, Sylius, Saleor) are open-source: self-hosted on EU infrastructure (Hetzner, OVHcloud, Scaleway) they put the data chain entirely under your control, but you (or an agency) run the hosting. Their managed clouds, by contrast, carry US-ownership or US-infrastructure nuances. **Q: Which Shopify alternative has the cleanest ownership?** Sylius (Poland) and MyCashflow (Finland) are the cleanest EU-owned options on this page: no US venture capital, private equity, or parent on record. Sylius is MIT-licensed open-source you self-host; MyCashflow is a managed SaaS on its own Finnish servers. Shopware (Germany) and PrestaShop (France) are European-operated and widely used, but Shopware is ~41% owned by PayPal (US, NASDAQ) and PrestaShop's parent Fortidia is a portfolio company of US asset manager Oaktree. Saleor (Poland) is EU-founded but its managed cloud runs on AWS; CCV Shop (Netherlands) is owned by US-based Fiserv. **Q: Does Shopify fall under the US CLOUD Act?** Shopify Inc. itself is Canadian-incorporated, not US, so the company is not directly a US entity. The CLOUD Act exposure comes through the hosting layer: Shopify runs its platform on Google Cloud, and Google LLC (Alphabet, US) falls within CLOUD Act reach for data it processes. EU merchant and customer data on Shopify therefore sits on US-controlled infrastructure. Self-hosting an EU open-source platform (Shopware CE, PrestaShop, Sylius, Saleor) on an EU host removes both the US-infrastructure and US-ownership questions. That's a read on corporate and infrastructure structure drawn from public information, not an allegation about any actual data request. **Q: Can I migrate my Shopify store to a European platform?** Yes, though an e-commerce migration is more involved than moving files. Export your products, customers, and orders from Shopify (CSV exports plus the Admin API for larger catalogues). The new platform imports the catalogue; most EU platforms have a Shopify-import tool or an agency partner who does this routinely. Plan for: re-creating your theme/storefront, re-connecting payment and shipping providers, setting up URL redirects from old Shopify product URLs to preserve SEO, and re-testing checkout. For self-hosted platforms, provision EU hosting first. Budget a few weeks and run the new store in staging before cutover. **Q: Do I need a developer to run a European Shopify alternative?** It depends on the platform. MyCashflow and CCV Shop are fully-managed SaaS: no developer needed, similar to Shopify's experience. Shopware and PrestaShop offer managed cloud tiers (less setup) as well as free self-hosted editions (more control, more ops). Sylius and Saleor are developer-oriented and effectively require technical resource or an agency. They are best for mid-market and B2B stores with custom requirements. Match the platform to whether you want turn-key SaaS or full control via self-hosting. **Q: What about payments, can I avoid US payment processors too?** Yes, and it is a separate decision from the platform. European platforms let you connect EU payment providers (Mollie, Adyen, and others) rather than Shopify Payments. If avoiding US payment infrastructure is part of your goal, see our payment-processor alternatives (Stripe, PayPal pages) for EU options like Mollie. Note that Shopware's largest shareholder is PayPal, which is one reason payment-rail independence and platform independence are worth assessing together. **Q: Which is cheapest?** The free self-hosted open-source editions (Shopware Community Edition, PrestaShop, Sylius core, Saleor) have no licence cost: you pay only for EU hosting (from a few euros a month on Hetzner/OVH for a small store) plus any developer time. Among managed SaaS, CCV Shop starts around €36/month and MyCashflow around €49/month, both with 0% transaction fees. Shopware's managed Cloud is mid-market priced (from ~€600/month) and is not aimed at the Shopify-Basic price tier. Confirm current pricing on each vendor's page. ### European alternatives to Signal: https://euvetted.com/alternatives/signal _About Signal:_ Signal Foundation (US 501c3), Mountain View. Open-source E2E messenger. Non-profit but US. Verified European alternatives (5): - [Threema](https://euvetted.com/p/threema): hosted in Switzerland, CLOUD Act: none, ownership: other - [Olvid](https://euvetted.com/p/olvid): hosted in France, CLOUD Act: minor, ownership: eu_owned - [SimpleX Chat](https://euvetted.com/p/simplex-chat): hosted in United Kingdom, CLOUD Act: minor, ownership: other - [Element (Matrix)](https://euvetted.com/p/element-matrix): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Wire](https://euvetted.com/p/wire): hosted in Switzerland, CLOUD Act: material, ownership: other ### European alternatives to Simple Analytics: https://euvetted.com/alternatives/simple-analytics _About Simple Analytics:_ Dutch privacy-first web analytics on Worldstream + Leaseweb NL + Bunny SI. Cross-reference: listed in our directory as a product. Verified European alternatives (5): - [GoatCounter](https://euvetted.com/p/goatcounter): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Trackboxx](https://euvetted.com/p/trackboxx): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Umami](https://euvetted.com/p/umami): hosted in United States, CLOUD Act: direct, ownership: us_owned - [Pirsch Analytics](https://euvetted.com/p/pirsch): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Wide Angle Analytics](https://euvetted.com/p/wide-angle-analytics): hosted in France, CLOUD Act: minor, ownership: eu_owned ### European alternatives to Slack: https://euvetted.com/alternatives/slack _About Slack:_ Salesforce-owned team messaging since 2021. Direct CLOUD Act exposure. Stackfield (Germany, Munich), Element/Matrix (UK, open source), and Wire (Switzerland) are the three European alternatives to Slack verified by EU Vetted's editorial team. Stackfield is EU-owned, Munich-hosted, with CLOUD Act exposure: [[stackfield.cloud_act]]; Wire is end-to-end encrypted by default with Swiss data residency (CLOUD Act exposure: [[wire.cloud_act]] via its chain); Element/Matrix is the open-protocol, self-hostable option. Self-hosted on EU infrastructure it removes the vendor from the data chain, while the managed Element cloud carries [[element-matrix.cloud_act]] exposure. Slack is a Salesforce subsidiary and runs on US infrastructure, placing it under CLOUD Act jurisdiction in practice. Verified European alternatives (5): - [Element (Matrix)](https://euvetted.com/p/element-matrix): hosted in United Kingdom, CLOUD Act: material, ownership: other - [HansaChat](https://euvetted.com/p/hansachat): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Stackfield](https://euvetted.com/p/stackfield): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Wire](https://euvetted.com/p/wire): hosted in Switzerland, CLOUD Act: material, ownership: other - [Talkspirit](https://euvetted.com/p/talkspirit): hosted in France, CLOUD Act: minor, ownership: eu_owned **Q: Is Slack usable under GDPR?** Slack publishes a Data Processing Addendum based on the EU Standard Contractual Clauses with post-Schrems II supplementary measures, so it is legally usable from the EU. What keeps buyers looking anyway is ownership and infrastructure: Slack Technologies LLC has been a subsidiary of Salesforce since 2021, the platform runs on Salesforce / AWS US infrastructure, and the consolidated structure means CLOUD Act jurisdiction applies. For a transfer impact assessment, that combination is what prompts the alternative search. **Q: Why does this page only list three alternatives?** Team messaging is a thinner category in Europe than email or storage. The three mapped here (Stackfield in Germany, Element/Matrix in the UK, and Wire in Switzerland) are the European tools that meet our editorial bar for procurement-grade documentation, hosting transparency, and a published DPA. We will add Mattermost (US-based, EU-hostable) and Rocket.Chat (Brazil) when self-hostable on EU sovereign cloud; they exist but did not make the editorial cut for primary listings here. Curating thin is preferable to padding the list with tools that do not pass our verification. **Q: Which Slack alternative is closest to Slack's UX?** Stackfield is the closest match to Slack's day-to-day interaction model: channels, threads, direct messages, file attachments, and integrations all map to familiar Slack equivalents. Element/Matrix runs on the open Matrix protocol with a more federated mental model; Wire is enterprise-grade with end-to-end encryption as the default. For teams that want a near-drop-in Slack replacement with German hosting, Stackfield is the start. **Q: Can I export my Slack message history?** Workspace owners on Slack's paid tiers can export the full message history via *Settings → Workspace Settings → Import/Export Data*. The export comes as a ZIP file with per-channel JSON. Element/Matrix supports importing a Slack export directly via the *matrix-slack-bridge* tool; Stackfield offers a guided import service for paying customers. Wire's import is manual and works best for moving the active set of conversations rather than the full archive. **Q: What about end-to-end encryption?** Wire and Element/Matrix both support end-to-end encryption by default: Wire as the standard and Element via the Megolm protocol on the Matrix backbone. Stackfield uses zero-knowledge encryption with German server-side keys. For teams where E2E is a hard requirement (legal practice, government work, regulated industries), Wire and Element are the two to evaluate first. **Q: Does Slack fall under the US CLOUD Act?** In practice, yes. Slack Technologies LLC is a subsidiary of Salesforce, Inc., which is US-incorporated and publicly listed. The consolidated structure (including any EU-region data storage) falls within the reach of the US CLOUD Act, which can compel a US company to produce data it controls regardless of where it is stored. The alternatives on this page (Stackfield, Element/Matrix, Wire) are either EU-owned, EU-hosted, or Swiss-hosted, each removing or substantially reducing that direct exposure. That is a statement about who owns and controls the company, not a claim that any specific data request has happened. **Q: What is the cheapest European alternative to Slack?** Stackfield's free tier covers up to 5 users with basic channel and messaging features. Element's open-source self-hosted route is free if your team has the hosting capacity on an EU cloud provider such as Scaleway or OVH. For teams of 5–50 that want a managed service, Stackfield's paid plan is typically the lowest-cost managed option in the European set; Wire's enterprise pricing is higher per seat due to the E2E security posture. Exact rates vary by team size, so confirm current pricing on each vendor's page. **Q: Is there a GDPR-compliant Slack alternative that supports federation or self-hosting?** Element/Matrix is the strongest answer here. The Matrix protocol is federated by design: you can self-host your own Matrix homeserver on any EU cloud (Scaleway, OVH, Hetzner) and still communicate with other Matrix users on other servers. Element is the commercial cloud-hosted entry point; the self-hosted path is well-documented and widely used in European public-sector procurement. Mattermost is also self-hostable and EU-cloud-deployable, though it does not yet have a primary listing on this page due to its US corporate base. **Q: Can my team keep using the same Salesforce CRM integration if we leave Slack?** Slack has a native Salesforce integration built by Salesforce themselves. If you migrate to Stackfield, Element, or Wire, the native connector is replaced by a Zapier or Make webhook-based integration, or by a custom microservice if your Salesforce usage is enterprise-grade. For teams leaving both Salesforce and Slack simultaneously, the CRM migration should be planned separately; see the Salesforce alternatives page for the parallel decision. ### European alternatives to Square (Block): https://euvetted.com/alternatives/square _About Square (Block):_ US-incorporated payments + POS provider, part of Block Inc (NYSE: SQ). Verified European alternatives (6): - [SumUp](https://euvetted.com/p/sumup): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [Dintero](https://euvetted.com/p/dintero): hosted in Norway, CLOUD Act: minor, ownership: other - [Mollie](https://euvetted.com/p/mollie): hosted in Netherlands, CLOUD Act: material, ownership: eu_hq_us_funded - [GoCardless](https://euvetted.com/p/gocardless): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Worldline](https://euvetted.com/p/worldline): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Adyen](https://euvetted.com/p/adyen): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned ### European alternatives to Squarespace Commerce: https://euvetted.com/alternatives/squarespace-commerce _About Squarespace Commerce:_ Squarespace Inc. (NYSE: SQSP). Hosted website builder with e-commerce capabilities; US-incorporated, direct CLOUD Act exposure. Verified European alternatives (6): - [CCV Shop](https://euvetted.com/p/ccv-shop): hosted in Netherlands, CLOUD Act: material, ownership: eu_hq_us_funded - [MyCashflow](https://euvetted.com/p/mycashflow): hosted in Finland, CLOUD Act: none, ownership: eu_owned - [Shopware](https://euvetted.com/p/shopware): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [PrestaShop](https://euvetted.com/p/prestashop): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [Sylius](https://euvetted.com/p/sylius): hosted in Poland, CLOUD Act: none, ownership: eu_owned - [Saleor Commerce](https://euvetted.com/p/saleor): hosted in Ireland, CLOUD Act: material, ownership: eu_owned ### European alternatives to Stripe: https://euvetted.com/alternatives/stripe _About Stripe:_ US-incorporated payments infrastructure. EU entity (Stripe Payments Europe Ltd) does not eliminate CLOUD Act exposure. Adyen (Netherlands, CLOUD Act exposure: [[adyen.cloud_act]]) and Worldline (France, CLOUD Act exposure: [[worldline.cloud_act]]) are the strongest European alternatives to Stripe on EU Vetted's editorial assessment: both are publicly listed, EU-owned, EU-hosted payment institutions. For indie and small-SMB merchants, Mollie (Netherlands) offers the smoothest migration, with native iDEAL, SEPA, and Bancontact. All are PSD2/SCA-regulated. Verified European alternatives (8): - [Adyen](https://euvetted.com/p/adyen): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Dintero](https://euvetted.com/p/dintero): hosted in Norway, CLOUD Act: minor, ownership: other - [GoCardless](https://euvetted.com/p/gocardless): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Mollie](https://euvetted.com/p/mollie): hosted in Netherlands, CLOUD Act: material, ownership: eu_hq_us_funded - [Trustly](https://euvetted.com/p/trustly): hosted in Sweden, CLOUD Act: material, ownership: eu_hq_us_funded - [Volt](https://euvetted.com/p/volt): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [Worldline](https://euvetted.com/p/worldline): hosted in France, CLOUD Act: minor, ownership: eu_owned - [SumUp](https://euvetted.com/p/sumup): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded **Q: Doesn't Stripe have an EU entity already?** Yes. Stripe Payments Europe Ltd is registered in Dublin and is the regulated payment institution for European merchants. What keeps the alternative search alive is the underlying ownership: Stripe Inc. (the US parent) sits above the Irish subsidiary, US sub-processors handle parts of the data flow, and the consolidated structure means CLOUD Act jurisdiction applies in practice. For a Schrems II transfer impact assessment, the EU subsidiary structure does not eliminate the underlying ownership question. **Q: Which Stripe alternative has the strongest compliance profile?** Among the alternatives mapped on this page, Worldline (France, Paris hosting) and Adyen (Netherlands, Amsterdam hosting) have the strongest compliance profile. Both are publicly-listed, EU-owned, EU-hosted payment institutions with full PSD2/SCA infrastructure and no material CLOUD Act exposure. Adyen is the typical enterprise pick; Worldline has stronger public-sector credentials. **Q: Will my Stripe customer card data transfer to the alternative?** No. Saved card credentials cannot be exported between PCI-DSS-regulated payment processors. This is a regulatory feature, not a vendor lock-in. The mitigation is to run both processors in parallel during the migration window and ask returning customers to re-authorise (most do, with a short prompt in the checkout flow). For subscription businesses with active recurring charges, the migration is more involved (see step 3 below). **Q: Do the European alternatives support SEPA, iDEAL, Bancontact, and Sofort?** Yes. Every alternative mapped here has stronger native support for European payment methods than Stripe ships out of the box. Mollie was built around iDEAL and SEPA from day one; Adyen has the widest ladder of European local methods; Klarna covers BNPL across the Nordic and DACH region. For Direct Debit specifically, GoCardless is the specialist. **Q: What about Apple Pay and Google Pay?** Apple Pay and Google Pay are supported by Adyen, Mollie, Worldline, and Klarna. Note that both are US-controlled wallet platforms, so using them as a payment method means a US sub-processor sits in your checkout flow regardless of which PSP you use. If your transfer impact assessment treats wallet processors as material exposure, the mitigation is to offer SEPA Direct Debit / SOFORT / iDEAL as the primary EU customer path and keep Apple Pay / Google Pay as a fallback. **Q: Does Stripe fall under the US CLOUD Act?** In practice, yes. Stripe Inc. is US-incorporated, so the consolidated group (including Stripe Payments Europe Ltd in Dublin) falls within the reach of the US CLOUD Act, which can compel a US company to produce data it controls regardless of where that data is stored. Adyen and Worldline, the two strongest alternatives mapped on this page, are EU-owned and EU-hosted, which removes that direct exposure. That's a read on ownership and control, not a claim that any particular request has been made. **Q: What is the cheapest European alternative to Stripe?** For low-volume merchants, Mollie (Netherlands) has the most transparent and accessible pricing among the European alternatives mapped here: per-transaction rates with no monthly minimum, comparable to Stripe's standard pricing. Adyen and Worldline use interchange-plus pricing that becomes competitive at higher volume but is less suited to very small merchants. Exact rates depend on payment method, card type, and volume, so confirm current pricing on each vendor's page. **Q: Can a European payment processor still accept US and international customers?** Yes. Every European processor on this page (Adyen, Mollie, Worldline, Klarna) accepts Visa, Mastercard, and American Express globally, including US-issued cards. Adyen in particular is built for cross-border commerce and is used by global enterprises. Choosing an EU-based processor changes who owns and hosts the payment infrastructure; it does not restrict which customers' cards you can charge. ### European alternatives to Stripe Connect: https://euvetted.com/alternatives/stripe-connect _About Stripe Connect:_ Stripe's marketplace payments product. Same direct CLOUD Act exposure as Stripe parent. Lemonway (France, ACPR-licensed, EU-owned), Mangopay (Luxembourg, CSSF-licensed, the marketplace specialist behind Vinted and Malt), and Adyen for Platforms (Netherlands, a publicly listed Dutch credit institution) are the strongest European alternatives to Stripe Connect on EU Vetted's editorial assessment. Lemonway has the cleanest EU ownership chain; Mangopay has the deepest marketplace feature set but is owned by Advent International (US private equity) since 2022; Adyen is the enterprise pick. Verified European alternatives (6): - [Lemonway](https://euvetted.com/p/lemonway): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Mangopay](https://euvetted.com/p/mangopay): hosted in Luxembourg, CLOUD Act: material, ownership: eu_hq_us_funded - [Volt](https://euvetted.com/p/volt): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [Trustly](https://euvetted.com/p/trustly): hosted in Sweden, CLOUD Act: material, ownership: eu_hq_us_funded - [Worldline](https://euvetted.com/p/worldline): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Adyen](https://euvetted.com/p/adyen): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned **Q: Does an EU alternative really cover what Stripe Connect does?** The core, yes: seller onboarding with KYC/KYB, split payments, commission collection, scheduled payouts, and PSD2-compliant checkout are covered by Mangopay, Lemonway, and Adyen for Platforms. The models differ though. Stripe Connect works with connected accounts; Mangopay and Lemonway are e-money institutions that give every seller a regulated wallet. Wallets map naturally to escrow-style flows (hold funds until delivery), which marketplaces often bolt awkwardly onto Connect. **Q: Do my sellers have to go through KYC again?** Yes, all of them. KYC/KYB files are not portable between regulated payment institutions; the new provider must verify every seller itself. This is the single biggest cost of leaving Stripe Connect and it needs to be planned as a product project (re-onboarding flows, seller communication, cohort-by-cohort migration), not an API swap. Budget for a percentage of long-tail sellers who never complete re-verification. **Q: Which alternative has the cleanest European ownership?** Lemonway (Paris, ACPR-licensed payment institution, passported in 29 countries, 400+ marketplaces including SNCF Connect and Decathlon). The cap table is European (Breega, Speedinvest, Toscafund) and CLOUD Act exposure is [[lemonway.cloud_act]]. Mangopay is Luxembourg-licensed but has been owned by Advent International, a Boston private-equity firm, since 2022, which sets its ownership signal to [[mangopay.ownership]]. Adyen is EU-owned via a broad Euronext free float. **Q: Is Mangopay still a European alternative if a US fund owns it?** It depends on which question you are asking. Operationally Mangopay is a Luxembourg e-money institution supervised by the CSSF, with a UK FCA licence alongside; customer funds sit under EU regulation. On ownership, Advent International (US private equity) has controlled it since April 2022, so its CLOUD Act exposure is [[mangopay.cloud_act]]. Buyers screening on regulatory domicile usually accept it; buyers screening on ownership chain usually go to Lemonway or Adyen instead. **Q: What about marketplaces with sellers outside Europe?** Adyen for Platforms is the strongest option: a Dutch credit institution with EU, UK, and US banking licences and global acquiring, built for platforms operating across regions. Mangopay and Lemonway are strongest inside the EEA and UK. If most of your sellers are in the US, an EU-licensed wallet provider will constrain you; that is a genuine Stripe Connect strength to weigh honestly. **Q: Does Stripe Connect fall under the US CLOUD Act?** The same analysis as Stripe generally: Stripe Inc. is US-incorporated, and the consolidated group, including Stripe Payments Europe Ltd in Dublin, sits within reach of the US CLOUD Act, which can compel a US company to produce data it controls regardless of where it is stored. That is a read on ownership and control, not a claim that any request has been made. The EU-owned alternatives on this page (Lemonway, Adyen, Worldline) remove that direct exposure. **Q: What do A2A providers like Trustly and Volt have to do with marketplace payments?** They cover one slice: pay-ins. Trustly (Sweden) and Volt (UK) move money account-to-account through open banking, which cuts card fees on high-value checkout, and both list marketplace platforms among their use cases. Neither replaces the seller-onboarding, wallet, and payout machinery of Connect; in practice they appear as an additional payment method on top of Mangopay, Lemonway, or Adyen rather than instead of them. **Q: What does the EU alternative cost compared to Stripe Connect?** Mangopay, Lemonway, and Adyen for Platforms all price custom for platforms (volume, wallet count, payout patterns), so a like-for-like public comparison is not possible; expect a sales process rather than a pricing page. What changes the economics more than the headline rate is European payment-method mix: SEPA and open-banking pay-ins through these providers are structurally cheaper than card-first flows. Model your actual mix before comparing quotes. ### European alternatives to SugarCRM: https://euvetted.com/alternatives/sugarcrm _About SugarCRM:_ US-incorporated mid-market CRM, owned by Accel-KKR (US PE). Verified European alternatives (4): - [combit CRM](https://euvetted.com/p/combit-crm): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [YetiForce](https://euvetted.com/p/yetiforce): hosted in Poland, CLOUD Act: minor, ownership: eu_owned - [Lime CRM](https://euvetted.com/p/lime-crm): hosted in Sweden, CLOUD Act: minor, ownership: eu_owned - [weclapp](https://euvetted.com/p/weclapp): hosted in Germany, CLOUD Act: material, ownership: eu_owned ### European alternatives to Surfshark: https://euvetted.com/alternatives/surfshark _About Surfshark:_ Lithuanian-founded, now part of Nord Security Group (Panama incorporation). NL operating presence. Verified European alternatives (7): - [AirVPN](https://euvetted.com/p/airvpn): hosted in Italy, CLOUD Act: none, ownership: eu_owned - [F-Secure VPN](https://euvetted.com/p/f-secure-vpn): hosted in Finland, CLOUD Act: minor, ownership: eu_owned - [Mullvad VPN](https://euvetted.com/p/mullvad): hosted in Sweden, CLOUD Act: none, ownership: eu_owned - [Opera VPN](https://euvetted.com/p/opera-vpn): hosted in Norway, CLOUD Act: material, ownership: other - [IVPN](https://euvetted.com/p/ivpn): hosted in Gibraltar, CLOUD Act: none, ownership: other - [Proton VPN](https://euvetted.com/p/protonvpn): hosted in Switzerland, CLOUD Act: none, ownership: other - [OVPN](https://euvetted.com/p/ovpn): hosted in Sweden, CLOUD Act: none, ownership: eu_owned ### European alternatives to SurveyMonkey (Momentive): https://euvetted.com/alternatives/surveymonkey _About SurveyMonkey (Momentive):_ US-owned survey market leader. Direct CLOUD Act exposure. Verified European alternatives (8): - [LimeSurvey](https://euvetted.com/p/limesurvey): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Typeform](https://euvetted.com/p/typeform): hosted in United States, CLOUD Act: material, ownership: eu_hq_us_funded - [Findmind](https://euvetted.com/p/findmind): hosted in Switzerland, CLOUD Act: minor, ownership: other - [Survicate](https://euvetted.com/p/survicate): hosted in Ireland, CLOUD Act: material, ownership: eu_owned - [Tally](https://euvetted.com/p/tally): hosted in Belgium, CLOUD Act: material, ownership: eu_owned - [Tripetto](https://euvetted.com/p/tripetto): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Formbricks](https://euvetted.com/p/formbricks): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Formdesk](https://euvetted.com/p/formdesk): hosted in Netherlands, CLOUD Act: none, ownership: eu_owned ### European alternatives to tawk.to: https://euvetted.com/alternatives/tawk-to _About tawk.to:_ US-incorporated free live chat service. Verified European alternatives (6): - [Crisp](https://euvetted.com/p/crisp): hosted in France, CLOUD Act: material, ownership: eu_owned - [Userlike (Lime Connect)](https://euvetted.com/p/userlike): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [LiveChat (Text)](https://euvetted.com/p/livechat): hosted in Poland, CLOUD Act: minor, ownership: eu_owned - [Customerly](https://euvetted.com/p/customerly): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned - [Tidio](https://euvetted.com/p/tidio): hosted in Poland, CLOUD Act: material, ownership: eu_hq_us_funded - [chatlyn](https://euvetted.com/p/chatlyn): hosted in Austria, CLOUD Act: minor, ownership: eu_owned ### European alternatives to Trello: https://euvetted.com/alternatives/trello _About Trello:_ US/Australian-owned Kanban tool, part of Atlassian since 2017. MeisterTask (Germany, Munich area, EU-owned, EU-hosted, ISO 27001, CLOUD Act exposure: [[meistertask.cloud_act]]) is the closest European replacement for Trello on Kanban-board UX, and Stackfield (Germany, Munich, EU-owned, EU-hosted, ISO 27001 + BSI C5, end-to-end encrypted, CLOUD Act exposure: [[stackfield.cloud_act]]) is the strongest choice where compliance and encryption are the binding constraint. For open-source and self-hostable agile boards, Taiga (Spain, Madrid, EU-owned, CLOUD Act exposure: [[taiga.cloud_act]]) covers Scrum and Kanban. Trello is part of Atlassian, US-incorporated since its 2022 re-domicile (NASDAQ: TEAM), with direct CLOUD Act exposure; most of the alternatives mapped here are EU-owned and EU-hosted, and each listing shows its verified exposure level. Verified European alternatives (5): - [MeisterTask](https://euvetted.com/p/meistertask): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [factro](https://euvetted.com/p/factro): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Kantree](https://euvetted.com/p/kantree): hosted in France, CLOUD Act: none, ownership: eu_owned - [Stackfield](https://euvetted.com/p/stackfield): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Teamwork.com](https://euvetted.com/p/teamwork): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned **Q: Is Trello usable under GDPR?** Trello publishes an EU Standard Contractual Clauses-based DPA and offers EU data residency on higher Atlassian tiers, so it is legally usable from the EU. What still gets flagged in a vendor-ownership review is Atlassian's structure: Trello is part of Atlassian, which re-domiciled to the United States in 2022 and is US-incorporated and publicly listed (NASDAQ: TEAM), so the group falls within the reach of the US CLOUD Act regardless of where board data is stored. That is the line item a transfer impact assessment flags, and it is what sends buyers looking at alternatives. **Q: Which Trello alternative is closest to the Kanban-board experience?** MeisterTask (Germany, Munich area, EU-owned, EU-hosted, ISO 27001, CLOUD Act exposure: [[meistertask.cloud_act]]) is the closest like-for-like: a clean Kanban board with lists, cards, checklists, and automations, built for the same lightweight task flow as Trello. Stackfield adds Kanban inside a broader encrypted collaboration suite. For teams that want agile boards specifically (Scrum plus Kanban), Taiga is the open-source option, and SeaTable or Baserow give you Kanban views on top of a no-code database if your work outgrows simple cards. **Q: Which Trello alternative has the strongest compliance profile?** Stackfield (Germany, Munich, EU-owned, EU-hosted, ISO 27001 and BSI C5, end-to-end encrypted in the browser, CLOUD Act exposure: [[stackfield.cloud_act]]) is the compliance benchmark here: it is the only listing combining German hosting, BSI C5, and AES-256 end-to-end encryption. MeisterTask (ISO 27001, German hosting, CLOUD Act exposure: [[meistertask.cloud_act]]) and Factro (100% Made in Germany, CLOUD Act exposure: [[factro.cloud_act]]) are strong German-hosted options without the encryption layer. For regulated teams, Stackfield is the one to evaluate first. **Q: Will my Trello boards and cards transfer?** Mostly, with some manual setup. Trello exports boards as JSON (and CSV on paid plans), and several alternatives offer Trello importers or accept CSV: MeisterTask has a Trello import path, and the no-code tools (SeaTable, Baserow) ingest CSV cleanly. What does not transfer automatically is Butler automation rules and Power-Up configurations. You rebuild those natively. Attachments and comments usually come across; verify card-history fidelity on a single test board before migrating everything. **Q: What about Power-Ups and Butler automation?** These are the Trello-specific pieces you reconfigure rather than import. Most European alternatives have native automation in place of Butler: MeisterTask, Stackfield, and Teamwork all ship rule-based automations for recurring tasks, status changes, and assignments. For Power-Up integrations (calendar, time tracking, reporting), check whether the alternative covers the function natively first. MeisterTask and Stackfield bundle several Power-Up equivalents, so the integration count you needed in Trello is often smaller after the switch. **Q: Does Trello fall under the US CLOUD Act?** Yes. Trello is part of Atlassian, which re-domiciled from Australia to the United States in 2022; Atlassian Corporation is US-incorporated and publicly listed (NASDAQ: TEAM), so the consolidated group falls within the reach of the US CLOUD Act regardless of where EU board data is stored. The alternatives on this page with no material CLOUD Act exposure (MeisterTask, Stackfield, Taiga, Factro, Kantree, SeaTable) are not US-incorporated, which removes direct CLOUD Act exposure. Baserow and Teamwork carry a minor flag via their sub-processor chains (Baserow: [[baserow.cloud_act]], Teamwork: [[teamwork.cloud_act]]). This reflects Atlassian's public corporate structure and filings, not any specific data request. **Q: Is there a GDPR-compliant alternative to Trello with end-to-end encryption?** Yes. Stackfield (Germany, Munich, EU-owned, EU-hosted, ISO 27001 + BSI C5, CLOUD Act exposure: [[stackfield.cloud_act]]) applies AES-256 end-to-end encryption in the browser, so the provider cannot read your board content. It is the one option here built around encryption as a default rather than an add-on. All the alternatives mapped publish GDPR-compliant data processing agreements and are EU-owned and EU-hosted; Stackfield is the recommended starting point where end-to-end encryption is a hard requirement. **Q: What is the cheapest European alternative to Trello?** Factro (Germany, Bochum, CLOUD Act exposure: [[factro.cloud_act]]) offers a free tier for up to ten users, which is generous for a small team. Among paid plans, SeaTable starts at around [[seatable.price_from]] per user per month and Stackfield at around [[stackfield.price_from]]. For open-source self-hosting, Taiga and Baserow remove per-seat cost entirely if you run your own infrastructure. Confirm current pricing on each vendor's page as tiers change frequently. **Q: Can a European tool replace Trello for a non-technical team?** Yes. MeisterTask is the most Trello-like for a non-technical team. The board, lists, and cards work the way people already expect, with no setup beyond inviting members. Stackfield is approachable too, adding chat and document collaboration around the boards. The no-code database tools (SeaTable, Baserow) are more powerful but ask for a little more setup; choose them only if your team has outgrown simple cards and wants structured fields, filtered views, and relations. ### European alternatives to TrustArc: https://euvetted.com/alternatives/trustarc _About TrustArc:_ US privacy compliance + consent platform. Direct CLOUD Act exposure. Verified European alternatives (3): - [Cookiebot](https://euvetted.com/p/cookiebot): hosted in Denmark, CLOUD Act: material, ownership: eu_hq_us_funded - [Didomi](https://euvetted.com/p/didomi): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Usercentrics](https://euvetted.com/p/usercentrics): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Trustly: https://euvetted.com/alternatives/trustly _About Trustly:_ Swedish open-banking A2A payments leader, Nordic Capital + BlackRock PE-owned. Cross-reference: listed in our directory as a product. Verified European alternatives (3): - [Volt](https://euvetted.com/p/volt): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [GoCardless](https://euvetted.com/p/gocardless): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Lemonway](https://euvetted.com/p/lemonway): hosted in France, CLOUD Act: minor, ownership: eu_owned ### European alternatives to Typeform: https://euvetted.com/alternatives/typeform _About Typeform:_ Spanish-founded form builder, now US-funded with US infrastructure. LimeSurvey (Germany, Hamburg) and Formdesk (Netherlands, Wassenaar) are the top-rated European alternatives to Typeform on EU Vetted. Both are EU-owned, EU-hosted, and sit outside CLOUD Act jurisdiction. For the closest visual UX match to Typeform's quiz style, Tally (Belgium, EU-owned, EU-hosted, CLOUD Act exposure: [[tally.cloud_act]]) is the starting point with a generous free tier. Typeform, despite its Barcelona founding, is US-funded with US infrastructure and US sub-processors that fall under CLOUD Act jurisdiction in practice. Verified European alternatives (7): - [Findmind](https://euvetted.com/p/findmind): hosted in Switzerland, CLOUD Act: minor, ownership: other - [Formdesk](https://euvetted.com/p/formdesk): hosted in Netherlands, CLOUD Act: none, ownership: eu_owned - [Survicate](https://euvetted.com/p/survicate): hosted in Ireland, CLOUD Act: material, ownership: eu_owned - [Tally](https://euvetted.com/p/tally): hosted in Belgium, CLOUD Act: material, ownership: eu_owned - [Tripetto](https://euvetted.com/p/tripetto): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [LimeSurvey](https://euvetted.com/p/limesurvey): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Formbricks](https://euvetted.com/p/formbricks): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded **Q: Isn't Typeform European already?** Typeform was founded in Barcelona in 2012 and the engineering team is still largely in Spain. The corporate structure has evolved since: Typeform is now US-funded with US-based infrastructure providers and US sub-processors, which is why procurement teams running a Schrems II transfer impact assessment treat it the same way they treat any US-incorporated SaaS. The Spanish founding story does not change the data-flow analysis. **Q: Which Typeform alternative has the strongest compliance profile?** Among the alternatives mapped on this page, LimeSurvey (Germany, open source, Hamburg hosting) and Formdesk (Netherlands, Wassenaar hosting) have the strongest compliance profiles. Both are EU-owned, EU-hosted, and carry no material CLOUD Act exposure. Tally (Belgium, EU-owned, EU-hosted) offers a generous free tier and is the closest match for Typeform's quiz-style UX. **Q: Will Typeform's conversational UX transfer to the alternatives?** Tally is the closest visual and interaction match to Typeform's one-question-per-screen flow. LimeSurvey and Formdesk default to traditional multi-question pages but can be configured for one-per-screen with logic jumps. The Typeform-specific brand polish (animated transitions, large display fonts) is the part that does not transfer without manual CSS work. **Q: Can I export my Typeform responses before migrating?** Yes. Typeform supports CSV and XLSX export from *Results → Download* on each form. The response data structure transfers cleanly to any of the alternatives mapped here. What does not transfer is the form definition itself; you will rebuild each form's structure in the new tool. For teams with fewer than 10 active forms this is a one-evening task. **Q: Do any of the alternatives support payments and file uploads?** Tally supports both Stripe-style payments and file uploads on its free tier. Tripetto and Survicate handle file uploads on paid tiers; payments require integration via Zapier. Formdesk and LimeSurvey both support file uploads natively. For payments, the European-friendly path is to combine your form builder with Mollie or Stripe Connect; none of the European form builders mapped here have a direct payment processor lock-in. **Q: Does Typeform fall under the US CLOUD Act?** In practice, yes. Despite its Barcelona roots, Typeform is US-funded and uses US-based infrastructure providers and sub-processors. Form response data (including respondent names, email addresses, and answer content) flows through systems subject to US CLOUD Act jurisdiction, which can compel a US company to produce data it controls regardless of storage location. LimeSurvey (Germany, EU-owned, EU-hosted) and Formdesk (Netherlands, EU-owned, EU-hosted) are the alternatives on this page with no material CLOUD Act exposure. That reflects where Typeform is incorporated and funded, not a claim about any specific request made against Typeform's data. **Q: What is the cheapest European alternative to Typeform?** Tally (Belgium, EU-owned, EU-hosted) offers the most generous free tier among the European alternatives mapped here: unlimited forms and unlimited responses at no cost, making it the closest free-tier match for Typeform's pricing model. LimeSurvey is free to self-host on any EU cloud; the managed LimeSurvey.com service starts at a low monthly rate. Tripetto and Survicate have paid-only plans with trials. For teams that want zero monthly cost and an EU-hosted option, Tally or self-hosted LimeSurvey are the starting points. **Q: Is there a GDPR-compliant Typeform alternative with a free plan?** Tally (Belgium, EU-owned, EU-hosted, CLOUD Act exposure: [[tally.cloud_act]]) is the strongest answer on cost: it offers unlimited forms and unlimited responses on its free tier with EU-primary hosting. LimeSurvey (Germany, EU-owned, EU-hosted, CLOUD Act exposure: [[limesurvey.cloud_act]]) is free to self-host under an open-source licence, and the community cloud version has a free basic tier. Formdesk and Survicate both have trial periods but no permanent free tiers. Tally's free plan is the most practical for solo founders and small teams who want the Typeform visual feel without the cost. **Q: Which European form builder is best for NPS and in-product surveys?** Survicate (Poland, EU-hosted) is the specialist here. It ships with in-product survey widgets, NPS tracking, and customer satisfaction dashboards out of the box, including a JavaScript snippet that embeds directly into your SaaS product. LimeSurvey also supports NPS workflows and can be embedded via iframe or API. For teams where the primary use case is product analytics surveys rather than marketing-page forms, Survicate is the most direct Typeform replacement. Note that Survicate carries material CLOUD Act exposure via sub-processors; the company and primary infrastructure are Polish. ### European alternatives to Vtiger: https://euvetted.com/alternatives/vtiger _About Vtiger:_ Indian-owned open-source CRM with US presence. Verified European alternatives (6): - [centralstationCRM](https://euvetted.com/p/centralstationcrm): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [combit CRM](https://euvetted.com/p/combit-crm): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Salesflare](https://euvetted.com/p/salesflare): hosted in Belgium, CLOUD Act: material, ownership: eu_owned - [Teamleader](https://euvetted.com/p/teamleader): hosted in Ireland, CLOUD Act: material, ownership: other - [weclapp](https://euvetted.com/p/weclapp): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [YetiForce](https://euvetted.com/p/yetiforce): hosted in Poland, CLOUD Act: minor, ownership: eu_owned ### European alternatives to Webex (Cisco): https://euvetted.com/alternatives/webex _About Webex (Cisco):_ Cisco-owned video conferencing. Direct CLOUD Act exposure via Cisco Systems Inc. Verified European alternatives (6): - [Tixeo](https://euvetted.com/p/tixeo): hosted in France, CLOUD Act: none, ownership: eu_owned - [kMeet (Infomaniak)](https://euvetted.com/p/kmeet): hosted in Switzerland, CLOUD Act: none, ownership: other - [Pexip](https://euvetted.com/p/pexip): hosted in Norway, CLOUD Act: material, ownership: other - [Whereby](https://euvetted.com/p/whereby): hosted in Ireland, CLOUD Act: minor, ownership: other - [Element (Matrix)](https://euvetted.com/p/element-matrix): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Wire](https://euvetted.com/p/wire): hosted in Switzerland, CLOUD Act: material, ownership: other ### European alternatives to WhatsApp: https://euvetted.com/alternatives/whatsapp _About WhatsApp:_ Meta-owned messaging platform. Direct CLOUD Act exposure via Meta Platforms Inc. Threema (Switzerland, Pfäffikon, EU-owned, all-Swiss hosting, no CLOUD Act exposure, ISO 27001, no phone number required) is the easiest consumer-ready European alternative to WhatsApp. Olvid (France, Paris, EU-owned, ANSSI CSPN-certified, mandated for French government ministers) is the government-grade option and the only messenger here that end-to-end encrypts metadata as well as content. For organisations that want to self-host, Element/Matrix and Wire are the federated, open-source choices used across European public sectors. All five alternatives mapped here are end-to-end encrypted by default; none is US-owned. Verified European alternatives (5): - [Olvid](https://euvetted.com/p/olvid): hosted in France, CLOUD Act: minor, ownership: eu_owned - [SimpleX Chat](https://euvetted.com/p/simplex-chat): hosted in United Kingdom, CLOUD Act: minor, ownership: other - [Threema](https://euvetted.com/p/threema): hosted in Switzerland, CLOUD Act: none, ownership: other - [Element (Matrix)](https://euvetted.com/p/element-matrix): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Wire](https://euvetted.com/p/wire): hosted in Switzerland, CLOUD Act: material, ownership: other **Q: Is WhatsApp usable under GDPR?** WhatsApp messages are end-to-end encrypted, and WhatsApp Ireland Ltd publishes an EU Standard Contractual Clauses-based data policy, so it is legally usable from the EU. What keeps this question alive for WhatsApp specifically is its ownership and metadata profile: WhatsApp is owned by Meta Platforms, Inc. (US-incorporated), the parent group falls under US CLOUD Act jurisdiction, and while message content is encrypted, the surrounding metadata (who messages whom, when, contact graphs) is processed within the Meta ecosystem. For a privacy or sovereignty assessment, that combination is what prompts the alternative search. **Q: Which WhatsApp alternative has the strongest privacy profile?** On metadata specifically (the axis WhatsApp is weakest on), Olvid and SimpleX are the strongest. Olvid (France) end-to-end encrypts both content and metadata and requires no phone number, email or identifier; its servers cannot determine who is talking to whom. SimpleX (UK-incorporated) goes further at the architecture level: it has no user identifiers of any kind, using separate per-contact message queues so relays never see a global contact graph. For a consumer-ready Swiss option with a simpler setup, Threema is the pragmatic pick: ISO 27001, all-Swiss hosting, and no phone number required. **Q: Can I move my WhatsApp chat history to a European messenger?** Generally no, and this is the honest limitation to plan around. WhatsApp chats are end-to-end encrypted and stored in WhatsApp's own backup format; there is no supported export that another messenger can import as live conversations. Migrating to a European alternative means re-establishing contacts and starting fresh conversations, not porting history. Most people keep WhatsApp installed read-only for a transition period to reference old threads while moving active conversations across. Some tools (Threema, Signal) can import a one-off local archive for your own records, but cross-app chat migration is not something any of these alternatives offer. **Q: Do these alternatives need a phone number like WhatsApp?** Several do not, which is a meaningful privacy difference. Threema, Olvid and SimpleX all work without a phone number or email: you connect by scanning a QR code or exchanging an invitation link, so your identity is not tied to your SIM. Element/Matrix uses a username on a homeserver rather than a phone number. This removes the contact-discovery-by-phone-number mechanism that WhatsApp relies on, which is one of the main metadata-leak concerns European privacy reviewers raise. **Q: Does WhatsApp fall under the US CLOUD Act?** Yes. WhatsApp is owned by Meta Platforms, Inc., a US-incorporated company, and the consolidated group falls within the reach of the US CLOUD Act regardless of where EU user data is processed. Message content is end-to-end encrypted and therefore not readable, but the corporate-structure question is what a sovereignty assessment turns on. The alternatives on this page that are not US-incorporated, Threema (Switzerland, CLOUD Act exposure: [[threema.cloud_act]]), Wire (Switzerland, CLOUD Act exposure: [[wire.cloud_act]]) and Olvid (France, CLOUD Act exposure: [[olvid.cloud_act]]), sit outside direct US jurisdiction. Element/Matrix (CLOUD Act exposure: [[element-matrix.cloud_act]]) and SimpleX (CLOUD Act exposure: [[simplex-chat.cloud_act]]) are UK-incorporated (EU-adequate jurisdiction); self-hosting the homeserver or relays removes server-side exposure entirely for organisations that run their own infrastructure. That verdict rests on corporate structure and publicly available filings, not on how well any of these apps encrypts your messages. **Q: Which WhatsApp alternative is best for a government or regulated organisation?** For European public-sector and regulated use, the established choices are Olvid, Element/Matrix and Wire. Olvid holds France's ANSSI CSPN certification and was mandated by the French Prime Minister for ministers and ministerial cabinets. Element (built on the open Matrix protocol) underpins sovereign government deployments including the German armed forces' BwMessenger and France's Tchap, and is fully self-hostable. Wire is used in government and defence contexts with a self-hostable, open-source stack on the modern MLS encryption standard. All three let an organisation keep the server inside its own security perimeter. **Q: Are these European messengers actually end-to-end encrypted?** Yes. All five are end-to-end encrypted by default, same as WhatsApp. Threema uses the NaCl/libsodium cryptography library; Wire uses the IETF MLS standard; Element/Matrix uses the Olm/Megolm implementation of the Double Ratchet; Olvid uses a custom protocol with academic validation that also encrypts metadata; SimpleX uses the Double Ratchet over Curve448 with a post-quantum-resistant key exchange. The practical differences are not whether content is encrypted, but whether metadata is protected, whether an identifier is required, and whether you can self-host. **Q: Is there a free WhatsApp alternative from Europe?** Yes. SimpleX is fully free and open source, funded by investment and donations. Element/Matrix is free to use on public homeservers and free to self-host (open source). Olvid has a free consumer tier covering core messaging. Threema is a one-off paid app for consumers (no subscription) with paid Work/Enterprise tiers for business; Wire is business-focused with paid plans. For a no-cost personal switch, SimpleX, Element/Matrix or Olvid's free tier are the starting points. ### European alternatives to WooCommerce: https://euvetted.com/alternatives/woocommerce _About WooCommerce:_ WordPress e-commerce plugin owned by Automattic Inc. (US, Delaware C-corp). Self-hosted PHP plugin; CLOUD Act direct via Automattic. Verified European alternatives (6): - [PrestaShop](https://euvetted.com/p/prestashop): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [CCV Shop](https://euvetted.com/p/ccv-shop): hosted in Netherlands, CLOUD Act: material, ownership: eu_hq_us_funded - [Shopware](https://euvetted.com/p/shopware): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Sylius](https://euvetted.com/p/sylius): hosted in Poland, CLOUD Act: none, ownership: eu_owned - [MyCashflow](https://euvetted.com/p/mycashflow): hosted in Finland, CLOUD Act: none, ownership: eu_owned - [Saleor Commerce](https://euvetted.com/p/saleor): hosted in Ireland, CLOUD Act: material, ownership: eu_owned ### European alternatives to Workday: https://euvetted.com/alternatives/workday _About Workday:_ Workday Inc. (Nasdaq: WDAY). US-incorporated enterprise HR + finance cloud; direct CLOUD Act exposure. Verified European alternatives (3): - [HiBob](https://euvetted.com/p/hibob): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [Lucca](https://euvetted.com/p/lucca): hosted in France, CLOUD Act: none, ownership: eu_owned - [Personio](https://euvetted.com/p/personio): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Workplace: https://euvetted.com/alternatives/workplace _About Workplace:_ Alias for Workplace from Meta. Retired by Meta in 2025. Verified European alternatives (5): - [HumHub](https://euvetted.com/p/humhub): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Talkspirit](https://euvetted.com/p/talkspirit): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Stackfield](https://euvetted.com/p/stackfield): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Element (Matrix)](https://euvetted.com/p/element-matrix): hosted in United Kingdom, CLOUD Act: material, ownership: other - [Nextcloud](https://euvetted.com/p/nextcloud): hosted in Germany, CLOUD Act: none, ownership: eu_owned ### European alternatives to Worldpay: https://euvetted.com/alternatives/worldpay _About Worldpay:_ Originally UK, sold by FIS (US) to GTCR (US PE) in 2024. Material US exposure. Adyen (Netherlands) and Worldline (France) are the strongest European alternatives to Worldpay on EU Vetted's editorial assessment: both are publicly listed, EU-owned payment institutions with enterprise acquiring at scale. Worldpay's UK roots predate its US ownership; since 2024 it is majority-owned by GTCR, a Chicago private-equity firm, with FIS retaining a minority. For SMB online payments Mollie (Netherlands) is the smoother landing; for in-person SMB payments SumUp is the European-built option with a US-funded cap table. Verified European alternatives (9): - [Adyen](https://euvetted.com/p/adyen): hosted in Netherlands, CLOUD Act: minor, ownership: eu_owned - [Trustly](https://euvetted.com/p/trustly): hosted in Sweden, CLOUD Act: material, ownership: eu_hq_us_funded - [Worldline](https://euvetted.com/p/worldline): hosted in France, CLOUD Act: minor, ownership: eu_owned - [Lemonway](https://euvetted.com/p/lemonway): hosted in France, CLOUD Act: minor, ownership: eu_owned - [SumUp](https://euvetted.com/p/sumup): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [Volt](https://euvetted.com/p/volt): hosted in United Kingdom, CLOUD Act: material, ownership: eu_hq_us_funded - [Dintero](https://euvetted.com/p/dintero): hosted in Norway, CLOUD Act: minor, ownership: other - [Mollie](https://euvetted.com/p/mollie): hosted in Netherlands, CLOUD Act: material, ownership: eu_hq_us_funded - [GoCardless](https://euvetted.com/p/gocardless): hosted in United Kingdom, CLOUD Act: material, ownership: other **Q: Is Worldpay a British company or an American one?** Both, in sequence. Worldpay started in the UK and was one of Europe's largest acquirers. It was bought by the US processor Vantiv in 2018, folded into FIS in 2019, and in 2024 FIS sold a majority stake to GTCR, a Chicago-based private-equity firm, keeping a minority itself. Whatever the brand's London history, the ownership chain today runs through the US, which is what sets its exposure in our assessment. **Q: Which alternative can actually replace Worldpay at enterprise scale?** Adyen and Worldline. Adyen (Amsterdam, publicly listed, a DNB-licensed credit institution processing €1.4 trillion a year) covers global e-commerce, in-person terminals, and platform payments on a single contract. Worldline (Paris, publicly listed, the fourth-largest payment services provider worldwide) is the European heavyweight with the strongest public-sector and banking references. Both hold the transaction volumes Worldpay merchants bring. **Q: We are an SMB, not an enterprise. Where do we land?** For online payments, Mollie (Netherlands, DNB-licensed) has the lowest setup friction and transparent per-transaction pricing, with native iDEAL, SEPA, and Bancontact. For card terminals and point of sale, SumUp (European-built, London-headquartered) is the fastest to deploy: pay-as-you-go readers with no monthly contract. Note both carry US-funded cap tables in our assessment ([[mollie.cloud_act]] and [[sumup.cloud_act]] exposure respectively); the EU-owned SMB path is thinner than the enterprise one. **Q: Does switching acquirers mean losing saved customer cards?** Saved card credentials cannot be exported wholesale between PCI-DSS-regulated processors the way a database can. There are two mitigations: network tokens (Visa and Mastercard tokens that can, with scheme and vendor cooperation, be re-linked at a new acquirer) and re-authorisation flows for returning customers. Plan for both, and assume a portion of stored credentials will need the customer to re-enter their card once. **Q: What happens to our terminal fleet?** Terminals are usually acquirer-locked. A move from Worldpay to Adyen or Worldline generally means new hardware or re-certification of existing devices, and the timeline for shipping and activating terminals across sites is often the critical path of the whole migration, ahead of anything software. Get the hardware plan and per-device pricing in writing before you sign. **Q: Which alternative has the strongest sovereignty profile?** Worldline: French, publicly listed with a free float above 90% and no controlling shareholder, EU-owned and EU-hosted, with CLOUD Act exposure limited to unavoidable card-scheme dependencies ([[worldline.cloud_act]]). Adyen sits close behind ([[adyen.cloud_act]]) with a Dutch banking licence and a broad public float. Dintero (Norway) is a smaller but notably clean option: Finanstilsynet-authorised and, since 2025, the only Norwegian-owned direct Visa/Mastercard acquirer. **Q: Are contract exit terms a real obstacle?** Often, yes. Enterprise acquiring contracts commonly carry notice periods, minimum-volume commitments, and early-termination fees, and Worldpay agreements are no exception to industry practice. Read your notice window before starting vendor conversations, and time the migration so the parallel-running phase ends as the old contract lapses rather than paying for both longer than needed. **Q: Do the European alternatives cover recurring payments and direct debit?** Yes. Adyen, Worldline, and Mollie all handle recurring card billing and SEPA Direct Debit. If collections by direct debit are the core of your model (subscriptions, invoicing, B2B collections), GoCardless is the bank-debit specialist with the deepest European coverage; note it is UK-based, and a Mollie acquisition announced in December 2025 is pending regulatory approval, so its ownership answer is in transition. ### European alternatives to Xero: https://euvetted.com/alternatives/xero _About Xero:_ Xero Limited (NZX/ASX: XRO). New Zealand-headquartered cloud accounting; non-EU public company. Verified European alternatives (8): - [Conta](https://euvetted.com/p/conta): hosted in Ireland, CLOUD Act: material, ownership: other - [Fiken](https://euvetted.com/p/fiken): hosted in Norway, CLOUD Act: material, ownership: other - [Lexware](https://euvetted.com/p/lexware): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Pennylane](https://euvetted.com/p/pennylane): hosted in France, CLOUD Act: material, ownership: eu_hq_us_funded - [PowerOffice Go](https://euvetted.com/p/poweroffice-go): hosted in Netherlands, CLOUD Act: material, ownership: eu_hq_us_funded - [Sage Accounting](https://euvetted.com/p/sage-accounting): hosted in United Kingdom, CLOUD Act: minor, ownership: other - [sevdesk](https://euvetted.com/p/sevdesk): hosted in Germany, CLOUD Act: material, ownership: eu_hq_us_funded - [Visma eAccounting](https://euvetted.com/p/visma-eaccounting): hosted in Norway, CLOUD Act: material, ownership: eu_hq_us_funded ### European alternatives to Zendesk: https://euvetted.com/alternatives/zendesk _About Zendesk:_ US-incorporated customer service platform, taken private by Hellman & Friedman + Permira in 2022. Crisp (France, Nantes, EU-owned, French-hosted, fully bootstrapped with no VC or US parent) is the strongest European alternative to Zendesk on EU Vetted's editorial assessment. Userlike (Germany, Cologne, EU-owned via Swedish-listed Lime Technologies, German engineering) is the strongest DACH option, and LiveChat / Text (Poland, Wrocław, EU-owned, Warsaw-listed since 2014) is the most established full-suite product. One honest caveat for the category: every AI-era support tool here carries a minor US dependency through LLM APIs for its AI features, so none is fully CLOUD-Act-free, but Crisp, Userlike and LiveChat are EU-owned and EU-hosted, with that exposure limited to the optional AI layer. Zendesk, Inc. is US-incorporated (owned by Hellman & Friedman + Permira) and carries direct CLOUD Act exposure. Verified European alternatives (7): - [Pureservice](https://euvetted.com/p/pureservice): hosted in Norway, CLOUD Act: material, ownership: other - [LiveChat (Text)](https://euvetted.com/p/livechat): hosted in Poland, CLOUD Act: minor, ownership: eu_owned - [chatlyn](https://euvetted.com/p/chatlyn): hosted in Austria, CLOUD Act: minor, ownership: eu_owned - [Userlike (Lime Connect)](https://euvetted.com/p/userlike): hosted in Germany, CLOUD Act: minor, ownership: eu_owned - [Tidio](https://euvetted.com/p/tidio): hosted in Poland, CLOUD Act: material, ownership: eu_hq_us_funded - [Crisp](https://euvetted.com/p/crisp): hosted in France, CLOUD Act: material, ownership: eu_owned - [Customerly](https://euvetted.com/p/customerly): hosted in Ireland, CLOUD Act: minor, ownership: eu_owned **Q: Is Zendesk usable under GDPR?** Zendesk is legally usable from the EU: it publishes a Standard Contractual Clauses-based DPA with supplementary measures and offers an EU data-hosting region. What keeps support teams reading past that paperwork is who actually signs the contract: Zendesk, Inc. is US-incorporated and, since 2022, owned by the US private-equity firms Hellman & Friedman and Permira, so the consolidated group falls within the reach of the US CLOUD Act regardless of the data region. If you're running a transfer impact assessment on where your customer-conversation data lives, that ownership structure is the fact that matters. **Q: Which Zendesk alternative has the cleanest ownership?** Crisp (France) has the cleanest ownership story in the category: a French SAS, fully bootstrapped, with no venture capital, no private equity, and no parent company a decade after founding. Userlike (Germany) is owned by Lime Technologies, a Swedish company listed on Nasdaq Stockholm, EU public-market ownership with German engineering. LiveChat / Text (Poland) has been listed on the Warsaw Stock Exchange since 2014 with no US controlling interest. Customerly (Ireland) and chatlyn (Austria) are EU-owned; Tidio (Poland) is EU-headquartered but US-VC-led (PeakSpan Capital), which is why we flag it as the most US-exposed of the six. **Q: Does Zendesk fall under the US CLOUD Act?** Yes. Zendesk, Inc. is US-incorporated, and since its 2022 take-private it is owned by Hellman & Friedman and Permira (US private equity), so the consolidated group falls within the reach of the US CLOUD Act. A US authority can compel production of data Zendesk controls regardless of the storage region. The EU-owned providers on this page (Crisp, Userlike, LiveChat, Customerly, chatlyn) are not US-incorporated, which removes the direct ownership exposure (see the AI caveat below). We're describing Zendesk's corporate structure and ownership chain here, not its day-to-day data-handling practices, and the detail comes from public filings and reporting on the 2022 buyout. **Q: If these tools use AI, are they really free of US cloud exposure?** Honestly, not entirely, and we flag it rather than hide it. The AI features in modern support tools (AI agents, reply suggestions, chatbots) typically call a US-based LLM API such as OpenAI or Anthropic. That is why we mark even the cleanest EU vendors here as carrying minor CLOUD Act exposure: their core platform and customer data are EU-owned and EU-hosted, but the optional AI layer routes prompts through a US API. If that matters for your threat model, you can usually disable the AI features and run the core helpdesk on a clean EU footing, or ask the vendor about EU-region LLM routing. Crisp, for example, hosts messaging in the Netherlands and Germany with French operations, and the US dependency is the AI/CDN layer, not the core. **Q: Do these match Zendesk's ticketing depth?** It depends on your needs. For shared inbox, live chat, multi-channel messaging (email, WhatsApp, Messenger), chatbots, knowledge base, and AI assist, the European tools are directly competitive: Crisp, LiveChat/Text, and Userlike all cover this well. Where Zendesk still leads is very deep enterprise ticketing: complex SLA management, large-scale workflow automation, advanced CX analytics, and its huge app marketplace. Mid-market and SMB support teams generally find the EU tools a clean replacement; large enterprises with heavily customised Zendesk instances should map their specific ticketing workflows before switching. **Q: How do I migrate from Zendesk?** Export your Zendesk data: tickets and conversation history (via the API or a data export), macros/canned responses, knowledge-base articles (Help Center export), and your agent and group structure. The new tool imports contacts and, in most cases, historical conversations; macros and KB articles are usually re-created or imported via CSV. Re-create your routing rules and business hours, connect your channels (email forwarding, WhatsApp, chat widget), and run both tools in parallel for a couple of weeks so agents adjust and you catch any workflow gaps before cutover. **Q: What is the best European Zendesk alternative for a small team?** Crisp (France) is a strong SMB pick: flat-rate pricing that explicitly rejects per-agent metering, a generous feature set (inbox, chat, chatbot, knowledge base, CRM), and clean bootstrapped EU ownership. Tidio (Poland) is popular for small e-commerce stores on Shopify/WooCommerce (note its US-VC ownership). For DACH small businesses that want German engineering and a German-language product, Userlike is the natural fit. Confirm current pricing on each vendor's page, as support tools often price by agent seat or conversation volume. ### European alternatives to Zoho CRM: https://euvetted.com/alternatives/zoho-crm _About Zoho CRM:_ Indian-owned CRM (Zoho Corporation, Chennai). Non-EU jurisdiction but not US either. Verified European alternatives (5): - [Pipedrive](https://euvetted.com/p/pipedrive): hosted in Estonia, CLOUD Act: material, ownership: eu_hq_us_funded - [SuperOffice](https://euvetted.com/p/superoffice): hosted in Norway, CLOUD Act: material, ownership: eu_hq_us_funded - [Teamleader](https://euvetted.com/p/teamleader): hosted in Ireland, CLOUD Act: material, ownership: other - [weclapp](https://euvetted.com/p/weclapp): hosted in Germany, CLOUD Act: material, ownership: eu_owned - [Workbooks](https://euvetted.com/p/workbooks): hosted in United Kingdom, CLOUD Act: material, ownership: other ### European alternatives to Zoom: https://euvetted.com/alternatives/zoom _About Zoom:_ US-incorporated video conferencing leader, NASDAQ-listed (ZM). Tixeo (France, Montpellier, CLOUD Act exposure: [[tixeo.cloud_act]]) and sipgate (Germany, Düsseldorf, CLOUD Act exposure: [[sipgate.cloud_act]]) are the strongest European alternatives to Zoom on EU Vetted's editorial assessment. Both are EU-owned and EU-hosted. Tixeo is SecNumCloud-qualified with end-to-end encryption as the default; sipgate bundles video, voice, and PBX for DACH teams. Whereby (Norway) and Pexip (Norway) are both EU-hosted with public DPAs, though neither is EU-owned. Verified European alternatives (5): - [kMeet (Infomaniak)](https://euvetted.com/p/kmeet): hosted in Switzerland, CLOUD Act: none, ownership: other - [Pexip](https://euvetted.com/p/pexip): hosted in Norway, CLOUD Act: material, ownership: other - [sipgate](https://euvetted.com/p/sipgate): hosted in Germany, CLOUD Act: none, ownership: eu_owned - [Tixeo](https://euvetted.com/p/tixeo): hosted in France, CLOUD Act: none, ownership: eu_owned - [Whereby](https://euvetted.com/p/whereby): hosted in Ireland, CLOUD Act: minor, ownership: other **Q: Is Zoom usable under GDPR?** Zoom publishes a Data Processing Addendum based on the EU Standard Contractual Clauses with post-Schrems II supplementary measures, so it is legally usable from the EU. What still sends procurement teams looking at alternatives is the ownership and infrastructure sitting behind that DPA: Zoom Video Communications, Inc. is US-incorporated and publicly listed (NASDAQ: ZM), the platform runs on US cloud infrastructure with EU-region failover, and the parent corporate structure means CLOUD Act jurisdiction applies. For a transfer impact assessment, that combination is what prompts the alternative search. **Q: Which Zoom alternative has the strongest compliance profile?** Among the alternatives mapped on this page, Tixeo (France, Montpellier) and sipgate (Germany, Düsseldorf) have the strongest signal set: both are EU-owned and EU-hosted (CLOUD Act exposure, Tixeo: [[tixeo.cloud_act]], sipgate: [[sipgate.cloud_act]]). Tixeo holds SecNumCloud qualification (the French government's highest cloud-sovereignty certification), making it the default choice for French public sector and defence-adjacent buyers. sipgate combines video, voice, and PBX with documented German hosting. Whereby (Norway) and Pexip (Norway) are EU-hosted with public DPAs, but neither is EU-owned. **Q: Can my Zoom meeting links transfer to the alternative?** No. Your Zoom meeting URLs are tied to Zoom's domain (zoom.us/j/xxxxx). After migration, you receive new meeting URLs on the new vendor's domain. The mitigation is to use your calendar invites as the canonical source of meeting links, not the Zoom URL itself. When the new tool is in place, future calendar invites carry the new URL; past invites continue to work because Zoom remains active during the parallel-running window. **Q: Do the European alternatives support large webinars?** Pexip and Tixeo both handle webinars with hundreds of participants in their enterprise tiers; Pexip in particular is built around large-scale video infrastructure used by broadcast media and government. Whereby is positioned for small-group meetings rather than 500-attendee webinars; for a webinar-heavy workflow, Pexip is the most direct match for Zoom Webinars. sipgate's video product is meeting-shaped rather than webinar-shaped. **Q: What about end-to-end encryption?** Tixeo ships with end-to-end encryption as the default, which is part of the SecNumCloud qualification it holds. Wire (listed separately under our Slack alternatives) also supports E2E video calls. Whereby and Pexip both support E2E for one-on-one and small-group meetings; for large meetings, the cryptographic model is transport-encryption rather than zero-knowledge end-to-end. Where E2E is a hard requirement, Tixeo is the clearest match. **Q: Does Zoom fall under the US CLOUD Act?** In practice, yes. Zoom Video Communications, Inc. is US-incorporated, so the consolidated group (including any EU-region infrastructure) falls within the reach of the US CLOUD Act, which can compel a US company to produce data it controls regardless of where that data is stored. The EU-owned and EU-hosted alternatives on this page (Tixeo, sipgate) remove that direct exposure. This describes Zoom's corporate structure, not any actual request for meeting recordings or other data. **Q: What is the cheapest European alternative to Zoom?** Whereby (Norway) offers the most accessible pricing among the European alternatives mapped here, with a free tier covering 1:1 meetings and paid plans starting at approximately €8.99/month per host for small-group calls. sipgate has a freemium model that becomes competitive for DACH teams bundling voice and video. Pexip and Tixeo are enterprise-priced; exact rates depend on participant volume and negotiated terms, so confirm current pricing directly with each vendor. **Q: Is there a GDPR-compliant alternative to Zoom that is also browser-based?** Whereby (Norway, EU-hosted with a public DPA) is the strongest browser-based option: participants join in one click with no client install required, which is the primary friction-reducer for external customer calls. Pexip also supports a WebRTC browser join path for participants. Both publish DPAs based on EU Standard Contractual Clauses with EU-primary infrastructure. Tixeo and sipgate require client installation for full feature access. **Q: Can a European video tool handle Zoom Rooms hardware?** Standard SIP/H.323 conference-room hardware works with Pexip and sipgate, both of which interoperate with room systems from Cisco, Poly, and Logitech. Specifically Zoom-Room-certified hardware needs reconfiguration; the Zoom Rooms firmware is not compatible with third-party video platforms. Tixeo supports on-premise deployments that can be integrated with SIP-capable room hardware. If hardware continuity is a binding constraint, audit your specific room-system models with the target vendor before committing to migration. **Q: Which European alternative is best for French government or public-sector buyers?** Tixeo (France, Montpellier, EU-owned, EU-hosted, SecNumCloud-qualified) is the default answer for French public-sector and defence-adjacent buyers. It holds SecNumCloud qualification (the French government's highest cloud-sovereignty certification) and has been used by French ministries and several European defence contractors. End-to-end encryption is the default, and on-premise deployment is supported for classified or sensitive workloads. No other alternative mapped on this page holds SecNumCloud. ## Insights (11 editorial posts) ### European and private search engines (2026): who actually runs their own index: https://euvetted.com/insights/european-search-engines Published: 2026-07-10 Author: EU Vetted Editorial A private search engine is not automatically its own search engine Two very different products are sold under the same label. Most searches for a private search engine or a European search engine return a mix of them, and telling them apart is the whole point of this page. The first kind runs its own web index: it operates a crawler, stores its own copy of the web, and ranks results itself. The second kind is an interface. It protects your privacy, or carries a European brand, but it fetches results from Microsoft Bing or Google and hands them back to you. Both can be reasonable choices. They are not the same thing, and the difference decides how independent the service actually is. Building and running an index at web scale is rare and costly, so independent-index operators are the exception, not the rule. Everything below was checked against the operators' own pages on 10 July 2026. Qwant, Ecosia, and the shared European index Qwant is French. Since 2023 it has been owned by Synfonium, the group assembled by OVHcloud founder Octave Klaba: his investment vehicles Jezby Ventures and Deep Code hold about 75 percent and the French state investor Caisse des Dépôts holds about 25 percent. Ecosia is German and structured differently. It is steward-owned, and the Purpose Foundation holds a veto share that, by the company's own account, means Ecosia cannot be sold and its profits stay tied to its mission. In November 2024 the two formed a joint venture, European Search Perspective (EUSP), owned equally and based in Paris, to build a European search index. The index is called Staan. This is the most substantial attempt yet to give a European search engine an index of its own rather than reselling Bing. On its current state, the primary sources say this. Ecosia announced on 7 August 2025 that it had begun serving results from the EUSP index to users in France, and said it was aiming to serve 30 percent of French queries from it by the end of 2025. Ecosia's own help center, checked on 10 July 2026, lists three result providers, Microsoft Bing, Google and EUSP, and states plainly that EUSP is currently only available in France while Bing is available to all users. So in July 2026 both products still serve most of their results, and nearly all results outside France, from Bing. What cannot be established from a primary source: the exact share of French queries the index serves today, and whether Qwant's own consumer results are yet served from Staan rather than from Bing. The EUSP corporate site still describes the index in prospective terms, and Ecosia's help center only documents Ecosia's use of it. Treat the index as real and partially live in France, and treat everything beyond that as not yet confirmed. Startpage: a privacy proxy over Google, Dutch and part US-owned Startpage is Dutch, operated by Surfboard Holding B.V. in the Netherlands. It is not an independent search engine: it queries Google and returns those results to you without the tracking, logging or profiling that a direct Google search carries. That is a real privacy function, and it is a proxy, not an index. Its ownership deserves to be stated plainly rather than omitted. In 2019 the US advertising-technology company System1 took a significant stake in Startpage through a unit called Privacy One Group, a change that drew criticism at the time for how little was disclosed. Startpage's position is that its Dutch and EU legal basis for data protection is unchanged. Both facts are true at once: the results are private by design, and the company has a US investor in its ownership chain. Verified 10 July 2026. Mojeek: an independent index, but UK and outside the EU Mojeek is the clearest example of the rare category. It is operated by Mojeek Limited in the United Kingdom, and it crawls and serves its own index using its own crawler, MojeekBot, covering several billion pages by its own account. It does not resell Bing or Google. For a reader who specifically wants results from an operator that indexes the web itself, Mojeek is the straightforward answer. The caveat is jurisdictional. The United Kingdom left the EU, so Mojeek is not an EU company and does not fall under EU law by membership. For buyers whose requirement is strictly EU jurisdiction, that places it alongside Switzerland as adjacent rather than inside. For buyers whose requirement is independence from the Bing and Google indexes, Mojeek meets it directly. Verified 10 July 2026. SearXNG: powerful, but you have to run it yourself SearXNG is often listed next to the products above, and it is a different kind of thing. It is free, open-source metasearch software: it takes your query, sends it to other search engines, and merges the results while stripping tracking. It has no index of its own, and it is not a hosted service you sign up for. For a reader who wants an answer today, that has two practical consequences. Running it as intended means self-hosting it on your own infrastructure, which gives you full control and no third party in the middle. Alternatively you can use one of the public instances run by volunteers, but then you are trusting whoever operates that instance, and the quality and privacy of those instances vary. SearXNG is a strong option for someone willing to host it, and not a drop-in consumer product for someone who is not. Verified 10 July 2026. Where Brave Search sits Brave Search is worth placing correctly. It runs its own independent index, which is genuinely uncommon and puts it in the same rare category as Mojeek on that single measure. But Brave Software, Inc. is incorporated in San Francisco, so the operator sits under US jurisdiction, including the US CLOUD Act (Clarifying Lawful Overseas Use of Data Act), which can reach data held by US-incorporated operators. Brave Search is therefore a private search engine with its own index, and a US one. We mention it only so it is not miscounted as European. Verified 10 July 2026. Serving results is not the same as owning an index Engine Operator country Own index Independent of Bing/Google Qwant, Ecosia (via EUSP/Staan) France, Germany building, partial in France partly; most results still Bing Startpage Netherlands (US investor) no (Google proxy) no Mojeek United Kingdom yes yes SearXNG self-hosted no (metasearch) depends on the engines it queries Brave Search United States yes yes, but US-operated The honest summary in July 2026 is that Europe has one serious attempt at its own search index, EUSP's Staan, and it is only partially live and only in France. Everything else is a trade-off: an EU brand over Bing, a privacy proxy over Google, an independent index outside the EU, or software you run yourself. How this was checked Every fact here was taken from the operators' own pages and announcements on 10 July 2026: the European Search Perspective corporate site, Ecosia's launch post and its help center article on result providers, Startpage's ownership disclosures and contemporaneous reporting, Mojeek's own description of its crawler and index, and Brave's own description of its index and company. Where a current status could not be confirmed from a primary source, in particular the live share of French queries served by EUSP and whether Qwant's consumer results come from Staan yet, the article states that it is not established rather than filling the gap. Search engines are free consumer products with no pricing tier, DPA or sub-processor list, so this is an article rather than a directory listing. ### The state of US exposure in European cookie-consent platforms, 2026: https://euvetted.com/insights/us-exposure-in-cookie-consent Published: 2026-07-09 Author: EU Vetted Editorial Of [[stat:cat:cookie-consent:total]] European consent platforms, [[stat:cat:cookie-consent:clear]] is fully clear of US exposure Consent management platforms exist for one reason: to document that a website processes personal data lawfully. That makes their own data path worth reading closely, and it is not as European as the category's branding suggests. We checked every consent platform in our directory against its published ownership records and infrastructure disclosures, and classified each on our four-level CLOUD Act exposure scale (none, minor, material, direct). CLOUD Act exposure Platforms None [[stat:cat:cookie-consent:clear]] Minor [[stat:cat:cookie-consent:minor]] Material [[stat:cat:cookie-consent:material]] Direct [[stat:cat:cookie-consent:direct]] Any exposure [[stat:cat:cookie-consent:any]] Every platform, and where the exposure enters Platform Country Ownership Hosting CLOUD Act exposure Where it enters ConsentManager [[consentmanager.country]] [[consentmanager.ownership]] [[consentmanager.hosting_country]] [[consentmanager.cloud_act]] German-operated on its own European data centres rather than a hyperscaler; ISO 27001 certified, IAB TCF v2 CMP Iubenda [[iubenda.country]] [[iubenda.ownership]] [[iubenda.hosting_country]] [[iubenda.cloud_act]] Parent Team.blue (Belgium) is European-controlled; the residual caution is disclosure, since a public sub-processor list and DPA URL are not surfaced Didomi [[didomi.country]] [[didomi.ownership]] [[didomi.hosting_country]] [[didomi.cloud_act]] Paris-based and funded by EU and French investors with no US parent identified; DPA and sub-processor list are not published openly Cookiebot [[cookiebot.country]] [[cookiebot.ownership]] [[cookiebot.hosting_country]] [[cookiebot.cloud_act]] Danish product on Danish infrastructure, but acquired by Usercentrics in 2022, whose own acquirer since 2024 is Vista Equity Partners (US private equity) Usercentrics [[usercentrics.country]] [[usercentrics.ownership]] [[usercentrics.hosting_country]] [[usercentrics.cloud_act]] Munich-operated and ISO 27001 certified, but acquired by Vista Equity Partners (US private equity) in 2024, together with its Cookiebot subsidiary The consolidation story is the category's defining fact. Usercentrics bought Cookiebot in 2022 and now runs much of the DACH consent market; Vista Equity Partners bought Usercentrics in 2024. Two of the most widely deployed European consent platforms therefore answer, through their ownership chain, to a US ultimate parent, while their operations, certifications and hosting remain German and Danish. Neither vendor hides this, but it rarely appears in the category's marketing. The two French and Italian platforms in the middle of the table show a different pattern: European ownership with limited public disclosure. Both classify as minor rather than none because a verification that cannot read a published sub-processor list has to leave room for what it cannot see. Our four-level classification records whether customer data could fall under US extraterritorial reach: none (EU/EEA/Swiss operator, no US parent, no notable US sub-processor), minor (a transient US sub-processor such as a CDN, with data at rest staying in the EU), material (a US parent or US-owned hyperscaler in the core data path), and direct (the operator itself is US-incorporated). One method note applies in this category: where a vendor does not publish its sub-processor list, we do not award the none classification, however European the rest of the picture looks. For consent platforms the data path we read is specific: where the banner script is served from, where consent logs are stored, and who ultimately owns the operator. Sources are the vendors' own published documents: sub-processor lists where available, DPA annexes and ownership records, re-checked quarterly. Every figure and verdict on this page renders live from the dataset, so the page updates when a re-verification changes a classification. The cross-category picture is in our CLOUD Act exposure analysis; all listings with per-platform detail are on the cookie-consent category page. The figures on this page may be republished with attribution. Cite as "Source: EU Vetted, verified July 2026" and link to this page. Numbers render live from our dataset and change when a quarterly re-verification changes a classification, so the link, not a copied figure, is the durable reference. ### The state of US exposure in European e-signature, 2026: https://euvetted.com/insights/us-exposure-in-e-signature Published: 2026-07-09 Author: EU Vetted Editorial Of [[stat:cat:e-signature:total]] European e-signature platforms, [[stat:cat:e-signature:clear]] is fully clear of US exposure We checked every e-signature platform in our directory against its own published sub-processor list, DPA and ownership records, and classified each on our four-level CLOUD Act exposure scale (none, minor, material, direct). The July 2026 re-verification changed this category noticeably: two qualified trust service providers that read as clean in marketing terms, Signaturit and Universign, moved to material once their group ownership and platform sub-processor annexes were read against primary sources. CLOUD Act exposure Platforms None [[stat:cat:e-signature:clear]] Minor [[stat:cat:e-signature:minor]] Material [[stat:cat:e-signature:material]] Direct [[stat:cat:e-signature:direct]] Any exposure [[stat:cat:e-signature:any]] Every platform, and where the exposure enters Platform Country Ownership Hosting CLOUD Act exposure Where it enters Skribble [[skribble.country]] [[skribble.ownership]] [[skribble.hosting_country]] [[skribble.cloud_act]] Swiss entity, qualified signatures anchored by Swisscom under both ZertES and eIDAS; no US layer documented in the document or evidence path Yousign [[yousign.country]] [[yousign.ownership]] [[yousign.hosting_country]] [[yousign.cloud_act]] French ANSSI-supervised QTSP; the caveat sits in the cap table, where a US growth-equity firm led the 2021 Series A Universign [[universign.country]] [[universign.ownership]] [[universign.hosting_country]] [[universign.cloud_act]] Now part of Signaturit Group (Namirial), whose parent was acquired by Bain Capital (US) in 2025; the shared platform stores data at rest on AWS, with Twilio and SendGrid for OTP and email Signaturit [[signaturit.country]] [[signaturit.ownership]] [[signaturit.hosting_country]] [[signaturit.cloud_act]] Group co-controlled by Bain Capital and PSG Equity (both US private equity); the platform DPA lists AWS at rest (EU region) plus Twilio and SendGrid Signicat [[signicat.country]] [[signicat.ownership]] EEA (multi-cloud) [[signicat.cloud_act]] All-EU/EEA corporate chain, but the platform runs multi-cloud on Google Cloud, AWS and Azure (EEA residency), with Mailchimp used for some notifications Tresorit eSign [[tresorit-esign.country]] [[tresorit-esign.ownership]] [[tresorit-esign.hosting_country]] [[tresorit-esign.cloud_act]] Owned by Swiss Post, zero-knowledge encryption throughout, but at-rest storage sits on Microsoft Azure (EU region); qualified certificates come via Evrotrust (Bulgaria) Eversign [[eversign.country]] [[eversign.ownership]] [[eversign.hosting_country]] [[eversign.cloud_act]] Acquired by Apryse (Denver, US) in 2022 and rebranded Xodo Sign; the operating company answers to a US parent The pattern is consistent with what we see across the whole directory: the flag on the website is rarely where the exposure comes from. E-signature is actually the category where Europe holds a structural legal advantage, because a qualified electronic signature can only be issued through a trust service provider supervised in an EU member state (or its Swiss ZertES equivalent). The qualified trust layer is European by construction. The exposure enters around that layer. Documents wait in storage before and after signing, audit trails and evidence files accumulate, signature requests go out by email, one-time passwords go out by SMS, and identity checks call external providers. Each of those steps can sit with a US-incorporated processor regardless of where the signature certificate comes from. And ownership matters on its own: the 2025 consolidation of the Signaturit Group under Namirial brought two US private-equity firms into control of what used to read as a purely European QTSP portfolio, which is what moved both Signaturit and Universign in our July 2026 re-verification. Our four-level classification records whether customer data could fall under US extraterritorial reach: none (EU/EEA/Swiss operator, no US parent, no notable US sub-processor), minor (a transient US sub-processor such as a CDN, with data at rest staying in the EU), material (a US parent or US-owned hyperscaler in the core data path), and direct (the operator itself is US-incorporated). For e-signature the data path we read is specific: document storage before and after signing, the audit-trail and evidence layer, OTP and email delivery, and identity verification. Sources are the vendors' own published documents: sub-processor lists, DPA annexes and ownership records, re-checked quarterly. Every figure and verdict on this page renders live from the dataset, so the page updates when a re-verification changes a classification. The cross-category picture is in our CLOUD Act exposure analysis; the platforms that clear the strictest bar are listed on e-signature without US sub-processors; all listings with per-platform detail are on the e-signature category page. The figures on this page may be republished with attribution. Cite as "Source: EU Vetted, verified July 2026" and link to this page. Numbers render live from our dataset and change when a quarterly re-verification changes a classification, so the link, not a copied figure, is the durable reference. ### The state of US exposure in European email marketing, 2026: https://euvetted.com/insights/us-exposure-in-email-marketing Published: 2026-07-09 Author: EU Vetted Editorial Of [[stat:cat:email-marketing:total]] European email marketing tools, [[stat:cat:email-marketing:clear]] are fully clear of US exposure Email marketing is where "European brand is not the same as leaving US jurisdiction" shows most starkly in our dataset. The category's household names, French, German and Polish companies with genuine EU roots, mostly classify as materially exposed, while the fully clear options are three lower-profile providers that run their own European infrastructure. We checked every tool against its own published sub-processor list, DPA and ownership records, and classified each on our four-level CLOUD Act exposure scale (none, minor, material, direct). CLOUD Act exposure Tools None [[stat:cat:email-marketing:clear]] Minor [[stat:cat:email-marketing:minor]] Material [[stat:cat:email-marketing:material]] Direct [[stat:cat:email-marketing:direct]] Any exposure [[stat:cat:email-marketing:any]] Every tool, and where the exposure enters Tool Country Ownership Hosting CLOUD Act exposure Where it enters rapidmail [[rapidmail.country]] [[rapidmail.ownership]] [[rapidmail.hosting_country]] [[rapidmail.cloud_act]] Freiburg GmbH keeping customer email data exclusively on an ISO 27001 German data-centre campus in Frankfurt, with deliberate avoidance of hyperscaler clouds; US transfers are limited to marketing-site analytics off the mailing-data path Maileon [[maileon.country]] [[maileon.ownership]] [[maileon.hosting_country]] [[maileon.cloud_act]] XQueue GmbH (Offenbach), ISO 27001 certified, German data centres, twenty years of operating history Infomaniak Newsletter [[infomaniak-newsletter.country]] [[infomaniak-newsletter.ownership]] [[infomaniak-newsletter.hosting_country]] [[infomaniak-newsletter.cloud_act]] Product of Infomaniak Group SA (Geneva), founder-led and independent, running on its own Swiss data centres Inxmail [[inxmail.country]] [[inxmail.ownership]] [[inxmail.hosting_country]] [[inxmail.cloud_act]] Freiburg GmbH with EU-only hosting and TÜV-certified ISO 27001; a small US footprint exists for marketing-site analytics, and the DPA is gated to the enterprise contracting flow Sender [[sender.country]] [[sender.ownership]] not disclosed [[sender.cloud_act]] Lithuanian entity whose public policy names no sub-processors and discloses no hosting region; dedicated DPA and security pages return 404 Make [[make-newsletter.country]] [[make-newsletter.ownership]] [[make-newsletter.hosting_country]] [[make-newsletter.cloud_act]] Norwegian AS storing subscriber data on Norwegian servers, but Intercom (support chat) and Google Workspace (internal documents) sit in the operational chain Keila [[keila.country]] [[keila.ownership]] [[keila.hosting_country]] [[keila.cloud_act]] Bootstrapped German open-source platform (AGPLv3) on Hetzner (DE) and Scaleway (FR) with a downloadable DPA; the only US-linked sub-processor is an optional CAPTCHA MailerLite [[mailerlite.country]] [[mailerlite.ownership]] [[mailerlite.hosting_country]] [[mailerlite.cloud_act]] EU-owned (Polish parent via Vercom) with EU primary storage, but a US legal entity serves non-EEA customers, US sub-processors include Intercom, Stripe and OpenAI, and no public DPA is surfaced Brevo [[brevo.country]] [[brevo.ownership]] [[brevo.hosting_country]] [[brevo.cloud_act]] French SAS with a public DPA, but primary at-rest storage runs on Google Cloud (Belgium region) with Cloudflare and OpenAI in the sub-processor annex Mailjet [[mailjet.country]] [[mailjet.ownership]] [[mailjet.hosting_country]] [[mailjet.cloud_act]] French SAS under Sinch (Sweden) with an EU data region, but the platform hosts on Google Cloud, a US-owned hyperscaler CleverReach [[cleverreach.country]] [[cleverreach.ownership]] [[cleverreach.hosting_country]] [[cleverreach.cloud_act]] Markets "Email Marketing Made in Germany", yet recipient and subscriber data is processed and stored on Amazon Web Services in EU regions GetResponse [[getresponse.country]] [[getresponse.ownership]] EEA (not detailed publicly) [[getresponse.cloud_act]] Polish S.A. with EEA-primary processing per its privacy policy, but no publicly accessible DPA and no named sub-processor list, only category descriptions EmailOctopus [[emailoctopus.country]] [[emailoctopus.ownership]] not disclosed [[emailoctopus.cloud_act]] London company with no public certifications and no disclosed hosting provider; its historical relationship with Amazon SES suggests where the sending runs The middle of this table is a transparency story as much as a jurisdiction story. Keila, a bootstrapped open-source platform, publishes a downloadable DPA and a named sub-processor list; Sender, with a far larger customer base, publishes neither, and its compliance pages return 404. Where disclosure is missing we classify conservatively, because a chain we cannot read is not a chain we can call clean. The bottom third is the hyperscaler story. Brevo, Mailjet and CleverReach are exactly the brands a European buyer reaches for when leaving Mailchimp, and all three keep subscriber data at rest on US-owned clouds in EU regions. The EU region answers a latency and data-residency question. It does not answer the jurisdiction question, which follows the hosting provider's parent company rather than the server's postcode. Our four-level classification records whether customer data could fall under US extraterritorial reach: none (EU/EEA/Swiss operator, no US parent, no notable US sub-processor), minor (a transient US sub-processor such as a CDN, with data at rest staying in the EU), material (a US parent or US-owned hyperscaler in the core data path), and direct (the operator itself is US-incorporated). For email marketing the data path we read is specific: where subscriber lists and campaign data rest, what sends the email, what tracks the opens and clicks, and who owns and finances the operator. Sources are the vendors' own published documents: sub-processor lists where available, DPA annexes and ownership records, re-checked quarterly. Every figure and verdict on this page renders live from the dataset, so the page updates when a re-verification changes a classification. The cross-category picture is in our CLOUD Act exposure analysis; the same tools compared as Mailchimp replacements are in best European Mailchimp alternatives and on the Mailchimp alternatives page; all listings with per-tool detail are on the email marketing category page. The figures on this page may be republished with attribution. Cite as "Source: EU Vetted, verified July 2026" and link to this page. Numbers render live from our dataset and change when a quarterly re-verification changes a classification, so the link, not a copied figure, is the durable reference. ### The state of US exposure in European web analytics, 2026: https://euvetted.com/insights/us-exposure-in-web-analytics Published: 2026-07-09 Author: EU Vetted Editorial Of [[stat:cat:web-analytics:total]] European analytics tools, [[stat:cat:web-analytics:clear]] are fully clear of US exposure Web analytics is the healthiest category in our directory by this measure: [[stat:cat:web-analytics:clear]] of [[stat:cat:web-analytics:total]] tools run their entire visitor-data path on EU-incorporated infrastructure with no US parent above them. The surprises are elsewhere, in well-known names that read as clean and are not. We checked every tool against its own published sub-processor list, DPA and ownership records, and classified each on our four-level CLOUD Act exposure scale (none, minor, material, direct). CLOUD Act exposure Tools None [[stat:cat:web-analytics:clear]] Minor [[stat:cat:web-analytics:minor]] Material [[stat:cat:web-analytics:material]] Direct [[stat:cat:web-analytics:direct]] Any exposure [[stat:cat:web-analytics:any]] Every tool, and where the exposure enters Tool Country Ownership Hosting CLOUD Act exposure Where it enters Plausible Analytics [[plausible.country]] [[plausible.ownership]] [[plausible.hosting_country]] [[plausible.cloud_act]] Bootstrapped Estonian company; analytics run on Hetzner (DE), Bunny (SI) and UpCloud (FI), with the few US sub-processors ancillary and off the analytics data path Pirsch Analytics [[pirsch.country]] [[pirsch.ownership]] [[pirsch.hosting_country]] [[pirsch.cloud_act]] German GmbH with analytics data at rest on Hetzner; US sub-processors are limited to ancillary functions such as payments and CAPTCHA Simple Analytics [[simple-analytics.country]] [[simple-analytics.ownership]] [[simple-analytics.hosting_country]] [[simple-analytics.cloud_act]] Dutch company on Worldstream and Leaseweb (NL) plus Bunny CDN (SI), with zero-knowledge encryption; the gap is a missing unified public DPA GoatCounter [[goatcounter.country]] [[goatcounter.ownership]] [[goatcounter.hosting_country]] [[goatcounter.cloud_act]] Open-source project run from Ireland on Hetzner (DE and FI), no third-party sharing; no formal DPA artefact, which matters for procurement but not jurisdiction Wide Angle Analytics [[wide-angle-analytics.country]] [[wide-angle-analytics.ownership]] [[wide-angle-analytics.hosting_country]] [[wide-angle-analytics.cloud_act]] Berlin GmbH on European cloud infrastructure (OVHcloud Open Trusted Cloud catalogue); the DPA is not self-servable and must be requested from support Trackboxx [[trackboxx.country]] [[trackboxx.ownership]] [[trackboxx.hosting_country]] [[trackboxx.cloud_act]] German product, but the at-rest hosting provider is not publicly disclosed and AWS Simple Email Service (US) handles newsletter email Matomo [[matomo.country]] [[matomo.ownership]] [[matomo.hosting_country]] [[matomo.cloud_act]] The controlling entity is InnoCraft Limited (New Zealand) and Matomo Cloud stores customer data at rest on AWS (EU region); the on-premise edition avoids both TelemetryDeck [[telemetrydeck.country]] [[telemetrydeck.ownership]] [[telemetrydeck.hosting_country]] [[telemetrydeck.cloud_act]] German GmbH with an admirably transparent sub-processor list, which is exactly how we know Azure and AWS handle customer signal data at rest alongside Hetzner PostHog [[posthog.country]] [[posthog.ownership]] US or EU (Frankfurt) region [[posthog.cloud_act]] London-founded but Y Combinator and Google Ventures anchor the cap table, and the managed cloud runs US and EU regions Umami [[umami.country]] [[umami.ownership]] DE region available [[umami.cloud_act]] Umami Software, Inc. is a Delaware C-Corp; the MIT-licensed self-host path on EU infrastructure removes the vendor exposure entirely Two patterns are worth reading out of this table. First, privacy engineering and jurisdiction are different axes: Matomo and TelemetryDeck are serious privacy products, and both still classify material because of who owns the entity or what the data sits on at rest. TelemetryDeck deserves credit for being the reason we can say so precisely, since its sub-processor disclosure is among the most transparent in the category. Second, open source changes the answer: Matomo on-premise and self-hosted Umami run entirely on infrastructure the customer chooses, which removes the exposure their managed clouds carry. The verdicts in this table are for the hosted products, since that is what most buyers deploy. Our four-level classification records whether customer data could fall under US extraterritorial reach: none (EU/EEA/Swiss operator, no US parent, no notable US sub-processor), minor (a transient US sub-processor such as a CDN, with data at rest staying in the EU), material (a US parent or US-owned hyperscaler in the core data path), and direct (the operator itself is US-incorporated). For web analytics the data path we read is specific: where visitor events are stored at rest, what serves the tracking script, and who owns and finances the operator. Sources are the vendors' own published documents: sub-processor lists, DPA annexes and ownership records, re-checked quarterly. Every figure and verdict on this page renders live from the dataset, so the page updates when a re-verification changes a classification. The cross-category picture is in our CLOUD Act exposure analysis; the same tools compared as Google Analytics replacements are in best European Google Analytics alternatives and on the Google Analytics alternatives page; all listings with per-tool detail are on the web analytics category page. The figures on this page may be republished with attribution. Cite as "Source: EU Vetted, verified July 2026" and link to this page. Numbers render live from our dataset and change when a quarterly re-verification changes a classification, so the link, not a copied figure, is the durable reference. ### 7 Best European Dropbox Alternatives (2026): Compliance-Verified: https://euvetted.com/insights/best-european-dropbox-alternatives Published: 2026-06-10 Author: EU Vetted Editorial How we built this list Most "best Dropbox alternatives" round-ups paraphrase each vendor's marketing page. We started from EU Vetted's verified dataset instead: for every service we recorded who actually owns the operating company, where the data physically sits, which sub-processors touch it, and whether any link in that chain is reachable under the US CLOUD Act. What follows are the seven strongest European options we could stand behind as of June 2026, ranked on that evidence. The full side-by-side table, with every signal per tool, lives on our Dropbox alternatives comparison. If your requirement is strictly "no US sub-processors anywhere in the chain", the filtered list is at cloud storage without US sub-processors. 1. Proton Drive: best overall Swiss, controlled by the non-profit Proton Foundation, and zero-knowledge end-to-end encrypted, so the operator cannot read your files even under legal compulsion. Storage runs on Proton's own Swiss infrastructure; pricing starts at €4/month, with a workable free tier. Its only US touchpoint is transient and sits outside the file path, which keeps CLOUD Act exposure at [[proton-drive.cloud_act]]. Full E2E does cost you server-side content search and a thinner integration ecosystem than Dropbox. Full profile → 2. kDrive (Infomaniak): best like-for-like switch If you want Dropbox's workflow without Dropbox's jurisdiction, kDrive is the closest match: desktop sync, shared drives, office-document editing, from €4/month. Infomaniak has run its own Geneva data centres since 1994 (ISO 27001, B Corp), and the data path contains no US sub-processor, so we rate exposure [[kdrive.cloud_act]]. This is the pragmatic choice for teams that need the move to be boring. Full profile → 3. Filen: best budget end-to-end encryption A young German service (Recklinghausen, 2021) offering true zero-knowledge E2E from €2/month, the lowest price for client-side encryption in this list. Data sits in a Tier IV ISO 27001 German data centre, and a single transient US item outside the file path leaves exposure at [[filen.cloud_act]]. The product is leaner than Dropbox, with fewer collaboration features, which is about all most private users switching for privacy actually need. Full profile → 4. Nextcloud: best self-hosted / sovereignty-maximal The German open-source standard. Run it yourself (or via a European hoster) and the sub-processor question disappears, because you are the operator: exposure [[nextcloud.cloud_act]]. Managed offerings start around €6/month per user. It is a content-collaboration platform rather than just storage, covering files, calendars, office editing and video calls, and European public administrations deploy it for exactly that reach. It is also the most work of anything here. Full profile → 5. luckycloud: strictest German zero-knowledge Berlin-based, running its own data centres in Berlin, Nuremberg and Frankfurt, with zero-knowledge encryption and no US sub-processor in the chain: exposure [[luckycloud.cloud_act]]. This is the profile that satisfies the strictest German procurement reading: German owner, German hardware, German law, encrypted so the operator cannot look. The apps are less polished than Proton or kDrive; the paperwork is stronger than either. Full profile → 6. Jottacloud: best for backup volume Norwegian (EEA, so fully under the GDPR), hosted exclusively in Norway on renewable power, with no US links in the chain: exposure [[jottacloud.cloud_act]]. Its unlimited-storage personal plan (~€7/month) makes it the volume pick for photo archives, machine backups and media libraries, where the per-terabyte price beats everyone else here. Sync works well, but the product's centre of gravity is backup rather than team collaboration. Full profile → 7. Koofr: cheapest entry into EU storage Slovenian, storing data in German ISO 27001 data centres, with optional client-side encryption: exposure [[koofr.cloud_act]]. Paid plans start around €1/month, and it has a useful trick: it connects your existing Dropbox, Drive or OneDrive accounts into one interface, which makes it a practical bridge while you migrate rather than a single leap. The budget pick that still clears the strict jurisdictional bar. Full profile → How to choose between them Decide on two axes. Encryption model: if "the operator must not be able to read my files" is the requirement, that points to Proton Drive, Filen or luckycloud (zero-knowledge), or self-hosted Nextcloud. If standard server-side encryption is acceptable, kDrive, Jottacloud and Koofr behave most like the service you are leaving. Jurisdictional strictness: all seven are European-owned and European-hosted; five run an entirely EU/EEA chain end-to-end, while Proton Drive and Filen carry a transient US item outside the file path. Each profile documents the chain, so you can apply your own bar. Prices and feature matrices move, so this page is re-verified quarterly against vendor disclosures. The complete comparison with every compliance signal sits at alternatives to Dropbox, and each profile above links the vendor's DPA and sub-processor list so you can check our work. ### 7 Best European Google Analytics Alternatives (2026): Compliance-Verified: https://euvetted.com/insights/best-european-google-analytics-alternatives Published: 2026-06-10 Author: EU Vetted Editorial Ranked on evidence, not screenshots GA4 is the single most-replaced tool in the privacy migration, and most "alternatives" lists rank by feature screenshots. We built this one from EU Vetted's verified dataset: per tool we record actual ownership, hosting, the sub-processor chain and CLOUD Act exposure, which are the things a DPO or a careful founder has to defend. These are the seven strongest European options as of June 2026. The full side-by-side comparison lives at Google Analytics alternatives; the whole category, filterable by every signal, sits at web analytics. 1. Plausible Analytics: best overall The textbook GA4 replacement: Estonian-incorporated, bootstrapped (no US investors to satisfy), hosted on Hetzner in Falkenstein, Germany, open source (AGPL), and cookieless with a script roughly 54× smaller than GA4's. From €8/month with GA import. Its two US sub-processors (transactional email, docs search) sit outside the analytics data path, so customer data stays on EU-incorporated hosts and exposure reads [[plausible.cloud_act]]. Full profile → 2. Pirsch Analytics: best for DACH German company, German servers (Hetzner), a bilingual public DPA, server-side and cookieless by design, from €6/month. Functionally it is close to Plausible; the difference is jurisdictional packaging, so if your client or legal department wants a German vendor with German paperwork end-to-end, Pirsch is the shortest conversation. A single transient US item leaves exposure at [[pirsch.cloud_act]]. Full profile → 3. Simple Analytics: strictest clean chain Dutch, hosted on Dutch infrastructure (Worldstream, Leaseweb) with a Slovenian CDN, and no US sub-processor anywhere, which gives it exposure of [[simple-analytics.cloud_act]], the strictest profile among the managed tools here. Clean one-page dashboard, email reports, from €15/month. It has fewer analytical features than Matomo by design, and that simplicity is the product. Full profile → 4. Matomo (self-hosted): feature parity with GA The open-source heavyweight: funnels, heatmaps, session recordings, raw data access, the closest thing to full GA feature parity in open source. Self-host it on EU infrastructure and you are the operator, with no external chain at all. The caveat sits in the managed option: InnoCraft is NZ-incorporated and Matomo Cloud runs on AWS (EU regions), where exposure rises to [[matomo.cloud_act]], so the self-hosted route is the one that clears a strict bar. Full profile → 5. GoatCounter: best free option Open-source, run by a solo developer, hosted on Hetzner (DE/FI), and free for personal use, with a radical privacy posture: no IP storage at all, and exposure of [[goatcounter.cloud_act]]. The right answer for blogs, side projects and anyone who needs honest visit counts rather than a full analytics suite. It is not aimed at marketing teams and does not pretend to be. Full profile → 6. Wide Angle Analytics: best on a European sovereign stack Berlin-based company running on OVHcloud's Open Trusted Cloud programme, a deliberately European infrastructure choice, from €10/month. Strict-GDPR positioning (EU-only data flow, configurable data residency), with exposure limited to [[wide-angle-analytics.cloud_act]]. A solid mid-point between the minimalists and Matomo. Full profile → 7. Trackboxx: German minimalist for B2B sites A German sole-proprietor product, cookieless with daily-rotating anonymisation, on German infrastructure with a Slovenian CDN, and exposure of [[trackboxx.cloud_act]]. B2B-focused and deliberately small, it is the kind of tool you choose for a corporate site where the entire analytics requirement is "which pages, how many, from where, GDPR-clean". Full profile → How to choose between them Start from what you actually use in GA4. Most sites use about 5% of it (pageviews, referrers, conversions) and for that the lightweight cookieless tier (Plausible, Pirsch, Simple Analytics, GoatCounter, Trackboxx) is the better product: faster script, no banner for the analytics itself, dashboards a human can read. If you genuinely need funnels, heatmaps and raw data, self-hosted Matomo is the European answer, so budget for the operations work. On jurisdiction: Simple Analytics and GoatCounter run an entirely EU/EEA chain end-to-end; Plausible, Pirsch, Wide Angle and Trackboxx carry only a transient US item outside the analytics data path; and Matomo's flag ([[matomo.cloud_act]]) attaches to the managed Matomo Cloud, while a self-hosted install sits outside that sub-processor chain. Each profile documents the exact chain with sources, so you can apply your own threshold. Full comparison: alternatives to Google Analytics. ### 7 Best European Mailchimp Alternatives (2026), Compliance-Verified: https://euvetted.com/insights/best-european-mailchimp-alternatives Published: 2026-06-10 Author: EU Vetted Editorial Where European software is genuinely strong Email marketing is one area where European software has real depth (Germany and France have run serious platforms for two decades), yet most "Mailchimp alternatives" lists are paid-placement listicles. We built this one from EU Vetted's verified dataset: ownership, hosting region, sub-processor chain and CLOUD Act exposure per platform, taken from the vendors' own documents. Seven strongest European options, as of June 2026. Full side-by-side comparison with every signal: Mailchimp alternatives. The whole category, filterable: email marketing. 1. Maileon, cleanest chain for business senders German enterprise email marketing (XQueue GmbH, Offenbach, since 2002), ISO 27001, EU data centres, 3,000+ customers, and the only platform in this list whose chain we rate [[maileon.cloud_act]] for CLOUD Act exposure: German owner, EU chain end-to-end. It is aimed at businesses rather than hobby newsletters, and pricing is quote-based. If the requirement is "subscriber data must never touch US jurisdiction", this is the pick. Full profile → 2. CleverReach, best free-tier German option German platform with customer data stored exclusively in Germany, a permanently free tier, and paid plans from ~€15/month, where a single transient US item leaves exposure at [[cleverreach.cloud_act]]. The pragmatic default for DACH SMBs: solid automation, German DPA and support, and an easy upgrade path from free to paid as the list grows. Full profile → 3. Brevo, the European heavyweight Paris-headquartered, and the closest European match to Mailchimp's full scope: email, SMS, chat, CRM and marketing automation, from €8/month with a free tier. The honest caveat is the sub-processor chain, which we rate [[brevo.cloud_act]] for US exposure, so it wins on features and price rather than jurisdictional purity. For most non-regulated senders that trade-off is acceptable, and our profile documents it so you decide deliberately. Full profile → 4. rapidmail, DACH simplicity Freiburg-based, with customer data exclusively in a Frankfurt ISO 27001 data centre and a GDPR-first design. It has less automation depth than Brevo, and much less complexity, built for the small business that wants newsletters done correctly in German, with German support, under German law. Exposure: [[rapidmail.cloud_act]]. Full profile → 5. Inxmail, German enterprise pedigree Freiburg again, but the enterprise end: ISO 27001 (TÜV Rheinland-certified), two decades of large-sender deliverability work, with agencies and corporates as the core market. Paid, quote-based, and exposure of [[inxmail.cloud_act]]. The choice when email is a revenue channel run by a team rather than a side task, and the paperwork has to satisfy a German legal department. Full profile → 6. Mailjet, API + marketing in one Paris-founded, ISO 27001, EU-only data centres, from €8/month, and notable for covering transactional email (API) and marketing campaigns in one platform, which simplifies a stack that would otherwise need two vendors. It is now part of a US-owned group, so exposure rises to [[mailjet.cloud_act]]. It is the same deliberate trade-off as Brevo: European product and hosting, US-reachable ownership chain. Full profile → 7. Sender, budget pick for small lists Lithuanian, with the most generous free tier in this list (2,500 subscribers / 15,000 emails per month) and cheap paid plans. The feature set covers the essentials (campaigns, basic automation, forms) without enterprise pretensions, and exposure sits at [[sender.cloud_act]]. The right answer for a newsletter that has outgrown nothing yet except Mailchimp's pricing. Full profile → How to choose between them Sort yourself into one of three buckets. Strict compliance senders (regulated industries, public sector, privacy-positioned brands): Maileon, then CleverReach or rapidmail, all German chains with minimal exposure and German paperwork. Feature-first marketing teams: Brevo or Mailjet, full suites at aggressive prices, accepting documented material US exposure in the ownership chain. Small lists on a budget: Sender free or CleverReach free, upgrading when volume demands. The automations are your real migration cost, so rebuild rather than port. Prices and chains move, and this page is re-verified quarterly. The complete comparison with every compliance signal sits at alternatives to Mailchimp. ### 7 Best European Password Managers (2026), GDPR-Checked: https://euvetted.com/insights/best-european-password-managers Published: 2026-06-10 Author: EU Vetted Editorial Why the operator, not just the crypto Most password-manager round-ups compare features and prices. This one starts where those stop: who operates the service, in which jurisdiction, with which sub-processors. End-to-end encryption protects your vault's contents, while your account data, metadata, sharing structures and the update channel live with the operator. These are the seven strongest European options as of June 2026, drawn from EU Vetted's verified dataset. Related filtered views: open-source password managers and password managers without US sub-processors. Full category: password managers. 1. Proton Pass: best overall for individuals Swiss, controlled by the non-profit Proton Foundation, zero-knowledge, with open-source apps and extensions, from €2/month and a free tier included. If you already use Proton Mail or Drive it folds into the same suite, and its only US touchpoint is transient, leaving exposure at [[proton-pass.cloud_act]]. The default recommendation for individuals and families leaving a US incumbent. Full profile → 2. Passbolt: best for teams Luxembourg-incorporated, AGPL open source, SOC 2 Type II audited, and built specifically for team credential workflows (granular sharing, access control, API). Run it as their EU-hosted cloud or self-host the Community Edition; either way we rate exposure [[passbolt.cloud_act]], the cleanest managed team option in the list. From €5/user/month, free self-hosted. Full profile → 3. Uniqkey: best for business access management Danish (Copenhagen), Danish-hosted, zero-knowledge, and positioned beyond a vault: employee access management, shadow-IT visibility, offboarding workflows, with exposure at [[uniqkey.cloud_act]]. This is the pick when the buyer is IT management at a 50–500 person company rather than a team lead with a credit card. Paid, quote-based. Full profile → 4. Psono: best self-hosted team vault German (esaqa GmbH), Apache-2.0 open source, designed for self-hosting on your own EU infrastructure, at which point the operator question collapses into your hosting choice and exposure sits at [[psono.cloud_act]]. Free self-hosted, with a managed tier available. The engineering-team answer: full control, a real audit trail, and no per-seat rent on the self-hosted route. Full profile → 5. KeePassXC: zero operator, zero chain The fully-offline classic, maintained from Germany under GPLv3: an encrypted file on your disk, no vendor cloud, no account, no sub-processors. There is nothing to subpoena but you, which is why exposure reads [[keepassxc.cloud_act]]. Free. The trade-offs are built-in sync (none; you sync the file yourself) and team features (none). For a single technical user it remains the most unassailable answer in the category. Full profile → 6. Vaultwarden: Bitwarden's clients, your server An independent open-source (AGPL, Rust) server implementation compatible with Bitwarden's apps and browser extensions. Host it on European infrastructure and you keep the polished client ecosystem while replacing the US-operated service layer; the operator is you, so exposure is [[vaultwarden.cloud_act]]. Free, provided you supply the server and the discipline to patch and back up. Full profile → 7. pCloud Pass: consumer simplicity, Swiss operator From the Swiss storage company pCloud: zero-knowledge, client-side AES-256, with a free single-device tier and lifetime-licence pricing (a one-off around €30) for people who hate subscriptions. Exposure: [[pcloud-pass.cloud_act]]. Fewer features than Proton Pass; the draw is the pricing model and the simplicity. Full profile → How to choose between them Pick the operating model first, the product second. Managed, for individuals: Proton Pass, or pCloud Pass for lifetime pricing. Managed, for teams and companies: Passbolt, then Uniqkey as the access-management superset. Self-hosted: Psono or Vaultwarden, the strongest jurisdictional posture after offline, at the cost of running a server. Offline: KeePassXC, no chain at all and no convenience to match. Whatever you choose, check two things on the profile before committing: the recovery flow (a forgotten master password is the most common real-world failure) and the import path from your current tool. CSV import is universal, but shared collections and TOTP seeds usually need manual re-creation. Every profile links the vendor's own documentation so you can verify the chain yourself. ### Picking 'European' isn't enough: where EU software still sits under the US CLOUD Act: https://euvetted.com/insights/cloud-act-exposure Published: 2026-06-04 Author: EU Vetted Editorial Only [[stat:ca_none_pct]]% of Europe's privacy-first tools are fully clear of the CLOUD Act We assessed [[stat:total]] EU- and privacy-first SaaS tools, across [[stat:cat_count]] software categories, for exposure to the US CLOUD Act: whether a US parent, US incorporation, or a core US sub-processor can place customer data under US extraterritorial reach. These are the tools European buyers reach for when they are deliberately trying to leave US software. Even so, only a minority are fully outside the law's reach. CLOUD Act exposure Tools Share None: EU operator, no US parent or notable US sub-processor [[stat:ca_none]] [[stat:ca_none_pct]]% Minor: a transient US sub-processor (CDN, maps); data at rest stays in the EU [[stat:ca_minor]] [[stat:ca_minor_pct]]% Material: US parent, or a core sub-processor is a US-owned hyperscaler [[stat:ca_material]] [[stat:ca_material_pct]]% Direct: the operator itself is US-incorporated [[stat:ca_direct]] [[stat:ca_direct_pct]]% Any exposure (minor + material + direct) [[stat:ca_any]] [[stat:ca_any_pct]]% So around three in five of these European alternatives still carry some US exposure ([[stat:ca_any_pct]]%), and roughly one in three ([[stat:ca_matdir_pct]]%) carry material or direct exposure: a US owner, US incorporation, or a US hyperscaler at the core of the stack. The figures are a live snapshot of our dataset, re-verified quarterly. The company's flag is rarely the problem. The stack underneath is The exposure seldom comes from the vendor being American. It comes from what runs underneath: hosting, sub-processors, and who provides the capital. Strapi (France) and Storyblok (Austria) are European-built headless CMSs, yet both are classed material through their infrastructure and ownership chain. Mollie (Netherlands), GoCardless, Klarna (Sweden), SumUp and Mangopay are European payment names, all material. Cal.com is open-source and widely used in Europe, but the operating company is US-incorporated (direct). Ownership tells the same story. Of the [[stat:total]] tools, [[stat:own_eu_pct]]% are EU-owned, but [[stat:own_eu_funded_pct]]% are EU-headquartered yet US-funded. Control, along with infrastructure choices, tends to follow the capital. Another [[stat:own_adequacy_pct]]% sit in non-EU but adequacy-adjacent jurisdictions such as Switzerland and the UK, and [[stat:own_us_pct]]% are US-owned. For a buyer, the practical lesson is simple: a European brand is not the same as leaving US jurisdiction. The sub-processor chain decides it, and it has to be read tool by tool. Categories where no option is fully clear In [[stat:cat_zero_clear]] of [[stat:cat_count]] categories, not a single tool we audited is free of CLOUD Act exposure: Category Tools Fully clear Detail Payments [[stat:cat:payments:total]] [[stat:cat:payments:clear]] [[stat:cat:payments:material]] of [[stat:cat:payments:total]] material (Mollie, GoCardless, Klarna, SumUp, Mangopay…) Accounting [[stat:cat:accounting:total]] [[stat:cat:accounting:clear]] Pennylane, sevdesk, Visma all material Headless CMS [[stat:cat:headless-cms:total]] [[stat:cat:headless-cms:clear]] Strapi and Storyblok, both EU-built, material Helpdesk and live chat [[stat:cat:helpdesk:total]] [[stat:cat:helpdesk:clear]] every tool carries at least a minor US sub-processor Calendar and booking [[stat:cat:calendar-booking:total]] [[stat:cat:calendar-booking:clear]] Cal.com is direct (US-incorporated) Payments is the sharpest case. Of the [[stat:cat:payments:total]] European payment providers we list, none is fully clear: [[stat:cat:payments:material]] are material. The reason is structural: the card-processing and cloud infrastructure underneath pulls even EU-owned providers into scope. It is the clearest example of the pattern in this whole dataset: European ownership, US exposure, decided downstream. Per-category deep dives with the full per-platform tables: e-signature, cookie consent, web analytics, email marketing. Where Europe does have clean options The picture is not uniform. Several categories have strong fully-clear coverage: Private email: [[stat:cat:private-email:clear]] of [[stat:cat:private-email:total]] clear (Tuta, mailbox.org, Posteo, Infomaniak) Cloud hosting: [[stat:cat:cloud-hosting:clear]] of [[stat:cat:cloud-hosting:total]] clear (Hetzner, OVHcloud, Scaleway) File sharing: [[stat:cat:file-sharing:clear]] of [[stat:cat:file-sharing:total]] clear Password managers: [[stat:cat:password-managers:clear]] of [[stat:cat:password-managers:total]] clear The pattern is consistent: Europe has fully-sovereign options where the category is infrastructure-light and identity-owned (email, storage, secrets), and struggles where the category depends on deep payment rails or US-hosted platform infrastructure. Why this matters now Demand for this is established: IDC has identified protection from extraterritorial data requests as the leading driver of sovereign-cloud adoption in Europe. Policy is moving the same way: the EU Tech Sovereignty Package, announced on 27 May 2026, puts the question "is this actually EU-controlled?" into mainstream procurement. What has been missing is a per-tool, per-category map of where a European buyer can and cannot actually escape the CLOUD Act today. The headline is not that Europe lacks alternatives (it often does not) but that availability is uneven, and that picking by flag alone leaves most buyers more exposed than they assume. How we assess this For each tool we record sourced, factual signals (operator jurisdiction, parent company, named sub-processors and hosting region) and classify CLOUD Act exposure on a four-level scale: none, minor, material, direct, each with a published definition. It is an editorial assessment based on public disclosures, not a vendor self-report, and we re-check it quarterly. Read the full method on our how we assess page. Figures here are a live snapshot of our current dataset and shift as it grows and vendors change their disclosures. To check any individual tool, browse it in the directory: every listing carries its hosting region, sub-processor chain, CLOUD Act level and the date we last verified it. For providers we assess as carrying no material CLOUD Act exposure, start with our verified German cloud providers and French cloud providers. ### The EU Tech Sovereignty Package: what it actually changes for your SaaS stack: https://euvetted.com/insights/eu-tech-sovereignty-package Published: 2026-05-28 Author: EU Vetted Editorial On 27 May 2026 the European Commission unveiled its Tech Sovereignty Package, a coordinated bundle of policy instruments anchored by the Cloud and AI Development Act (CADA), the cloud/AI law the Commission is tabling alongside the package, which would harmonise an EU-wide definition of "sovereign cloud" and ease data-centre build-out, plus the second iteration of the Chips Act and a refreshed open-source strategy. Its headline measure is a proposed restriction on the US hyperscalers (AWS, Azure and Google Cloud) for sensitive public-sector data in healthcare, finance and the judiciary, across all 27 member states. It is a proposal, not yet law: it still needs the member states' approval to take effect. The announcement was telegraphed for weeks; the substance, less so. This page is a pragmatic reading from the perspective of someone who has to make actual SaaS purchasing decisions in the next twelve months, not a policy explainer. The single most useful framing is this: the package is the institutional consolidation of moves that were already happening, not a new direction. NIS2 has been in force since October 2024. DORA has been in force since January 2025. The €180M sovereign cloud tender awarded on 17 April 2026 to Scaleway, Clever Cloud, OVH and STACKIT (with AWS, Azure and Google Cloud excluded) was the signal that real procurement budget had begun to move. France is migrating 2.5 million civil servants off Microsoft. Schleswig-Holstein is 80% Microsoft-free. The International Criminal Court dropped Microsoft for OpenDesk in November 2025. Dutch banks have publicly begun seeking alternatives. The package is the framework that organises these moves into a doctrine. For a buyer, the practical question is not "is US software now illegal". It is not, and the package proposes no general ban for private-sector buyers. What it does propose is a binding limit on the US hyperscalers for sensitive public-sector data; everything outside that perimeter is direction-of-travel, not prohibition. The practical question is where on the spectrum of resilience your current stack sits, and how much of that you need to change before your next renewal cycle. Three things change for European SaaS buyers in the second half of 2026, and they change at different speeds. Public-sector procurement hardens immediately, and now names the hyperscalers. The package's headline restriction targets AWS, Azure and Google Cloud directly for sensitive public-sector data in healthcare, finance and the judiciary. Beyond those sectors, tenders for regulated EU entities (public administration, defence supply chain, the rest of finance) will increasingly write sovereign-cloud and EU-sub-processor requirements directly into the bid. For vendors selling into these markets, the absence of an EU hosting region or a clean sub-processor chain is no longer a soft objection. It is a disqualification at procurement intake. The first sign you will see this in the wild is updated boilerplate in RFPs from German Länder, French ministries and large EU institutions. Private-sector buyers face procurement pressure transmitted downstream. A French SaaS selling into a SecNumCloud-required ministry must itself sit in a SecNumCloud-aligned posture or lose the tender. A German fintech under DORA must demonstrate that its critical sub-suppliers (analytics, identity, document signing, observability) meet equivalent operational-resilience controls. This pressure cascades. A DACH SMB that thought it was insulated from sovereignty considerations finds itself answering vendor-due-diligence questionnaires it did not have to answer twelve months ago. The default-question changes. Until 2025, the default question on a procurement call was "is this tool functionally adequate, with a signed DPA." In 2026 the default question is "is this tool functionally adequate, with a signed DPA, and is the hosting + sub-processor chain defensible against a Schrems II transfer impact assessment." The third clause used to be a specialist concern. It is now in the standard checklist. A clear-eyed reading also has to name what the package does not change, because hype cycles around announcements like this can mislead buyers into wasted migration projects. The CLOUD Act remains. A US-incorporated company, even if it stores all data in Frankfurt, remains subject to US extraterritorial subpoena. The package does not (and cannot) change US law. What it does is make CLOUD Act exposure a more visible procurement signal, particularly for regulated buyers. The signal was always there; the package raises its weight. Schrems II still requires a vendor-specific transfer impact assessment. No certification, including SecNumCloud or BSI C5, blanket-discharges a controller from the Schrems II obligation. The assessment is still per-controller, per-data-flow. The package is expected to reference these frameworks positively, but a reference is not an exemption. EU-owned does not automatically mean Schrems-safe. Several European vendors run substantial workloads on US hyperscalers, route email through Mailgun or Postmark, or pipe analytics through Segment. Ownership is one independent signal; sub-processor chain is another; physical hosting is a third. They have to be evaluated separately, which is the practice this directory tries to make routine. Most US software is not going anywhere fast. Replacement velocity for entrenched horizontal tools (Slack, Notion, Salesforce, GitHub) is constrained by switching costs, integration sprawl and team familiarity. The package accelerates the direction of travel; it does not collapse the timeline. Expect category-by-category migration, starting where the buyer has highest leverage (email, document signing, password management, file storage) before moving to deeply entrenched collaboration suites. For a buyer with limited time, the most useful operational reading is a four-question audit applied to each tool already in the stack. Who owns the operating entity? EU-owned, EU-headquartered with US funding, US-owned. This is the ownership signal: the simplest to verify and the one that determines baseline CLOUD Act exposure. Where does the data sit at rest, in which region, on whose infrastructure, and who holds the keys? A "European" tool whose primary storage is us-east-1 is not an EU-hosted tool. The data centre matters more than the corporate flag. Under CADA's emerging "sovereign cloud" criteria, even an EU region looks set to be insufficient on its own: encryption-key custody outside the provider's control is becoming part of the test. Which sub-processors touch the data? Read the public sub-processors document. Flag every US-owned entry. A vendor with two transient US sub-processors and no data-at-rest exposure is in a very different posture from one piping events to Segment and Mixpanel. What does the public DPA actually say about international transfers? Standard Contractual Clauses are necessary but no longer sufficient. Supplementary measures, named hosting region, named sub-processors, and an audit-rights clause are what a defensible procurement file now contains. Run that audit on the top ten tools in the stack. The ones that fail two or more questions are the ones to plan migrations for at the next renewal, not necessarily all at once, but with a calendar attached. The framing this directory uses, and that the package implicitly endorses, is resilience as a spectrum, not a binary. A SaaS stack is rarely either "sovereign" or "compromised." It is some combination of: EU-owned tools with US sub-processors; US tools with German data residency; open-source self-hosted; SecNumCloud-qualified for the regulated workloads; pragmatic US choices where no credible alternative exists yet. A buyer's job in 2026 is not to chase a sovereignty maximum. It is to make the trade-offs visible, document them, and move on the highest-leverage replacements first. The Tech Sovereignty Package is the framework that says the trade-offs are legitimate procurement concerns. The work of making them is still on the buyer. Browse our verified European cloud providers, SecNumCloud-qualified services, encrypted cloud storage, private email, open-source password managers, and EU VPN providers. Each entry is annotated with ownership, hosting, sub-processor chain, CLOUD Act exposure, and the date we last verified the public disclosures. That is the format the next twelve months will reward. --- Crawler policy: AI crawlers, search/citation (OAI-SearchBot, ChatGPT-User, PerplexityBot, Perplexity-User, Claude-SearchBot, Claude-User) and training (GPTBot, ClaudeBot, Google-Extended, Applebot-Extended, CCBot), are explicitly permitted in https://euvetted.com/robots.txt. Per-page index (slim): https://euvetted.com/llms.txt