Koofr
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based This listing EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Slovenian cloud storage (Koofr d.o.o., est. 2013), German ISO 27001 data centres, optional client-side encryption via the open-source Koofr Vault, 10 GB free.
Koofr is a European service hosted in Germany, with at most minor, transient US exposure under the CLOUD Act. It is listed under File sharing.
Assessment notes
Koofr is operated by Koofr d.o.o. (Stegne 23A, Ljubljana, Slovenia; founded 2013, based in Technology Park Ljubljana), a fully EU-incorporated, EU-owned company that stores all data in ISO 27001-certified data centres in Germany, is GDPR-compliant by default, runs no file scanning or tracking, and offers optional client-side encryption via the Koofr Vault product; EU-owned and Germany-hosted with optional zero-knowledge encryption via Koofr Vault; CLOUD Act exposure was re-read down from none to minor in August 2026 once the privacy policy was read in full, because payments run through Braintree, part of PayPal, Inc. (US) — a single transient processor with no access to stored files, which is exactly the rubric's minor case rather than the clean none previously assumed; no Cloudflare and no US hyperscaler is named anywhere. The key documentation gap remains the absence of a public DPA, and the privacy policy that carries the processor disclosure has not been revised since 16 May 2018.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 0 none disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Not assessed
-
Public DPA: No
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: No
Jump to
About Koofr
Koofr is a Slovenian cloud storage service operated by Koofr d.o.o., based at Stegne 23A in Ljubljana and a long-time member of Technology Park Ljubljana. Founded in 2013, it celebrated its tenth year of service in 2023 and is one of the cleaner small-vendor EU storage listings in this directory, fully Slovenian-incorporated, EU-owned, with no US parent, no US VC, and no PE on record.
The infrastructure story is solid: Koofr stores all customer data in ISO 27001-certified data centres in Germany, markets itself as "GDPR compliant by default," and explicitly commits to not scanning, indexing or tracking customer files. Standard transport encryption and encrypted storage apply to all accounts. For users who want true zero-knowledge encryption, Koofr offers Koofr Vault, a client-side-encrypted layer where files are encrypted in the browser/app before upload, so Koofr cannot read them. Koofr Vault is fully open-source, so its encryption can be independently audited. The apps and web UI are localised into more than 20 languages, including most major EU languages (German, French, Italian, Spanish, Dutch, Polish, Portuguese, Swedish, and others) alongside Slovenian and several global languages. A distinctive feature is that Koofr can connect and unify external clouds (Dropbox, Google Drive, OneDrive, Amazon) into a single interface, which is useful for migration but should be understood by privacy-focused buyers as an opt-in bridge to non-EU services.
For an EU-sovereignty audit the open question is documentation, not infrastructure. Koofr still publishes no DPA, and that is what caps this listing. It does name its processors, but only in prose inside a privacy policy that has not been revised since 16 May 2018, and only two of the four are named at all: Braintree Payments, described there as part of PayPal, Inc. (US), for card payments, and Headway for website services, alongside an unnamed accounting provider and a bank. No Cloudflare, no AWS, GCP or Azure and no US hyperscaler appears anywhere, and koofr.eu answers from plain Apache with no US CDN in front of it. That one transient US payment processor, which has no access to stored files, is why CLOUD Act exposure is recorded as Minor rather than clear. The rest of the signal mix is strong: Slovenian entity, German ISO 27001 certified hosting, no file scanning, optional client-side encryption via Koofr Vault.
Pricing is freemium and unusually granular: 10 GB free forever; "Briefcase" tiers from €0.50/month (25 GB) and €1/month (100 GB); "Suitcase" tiers €4-10/month (250 GB to 1 TB); "Crate" tiers €20-35/month (2.5-5 TB) plus custom 10 TB+. Note that subscriptions are currently billed yearly and prices include 22% Slovenian VAT. Long-term subscribers can also join a Loyalty Program offering subscription discounts of up to 50%. The former free-storage referral scheme has been discontinued; there is no monetary affiliate programme. Best fit: privacy-conscious EU individuals and small teams who want German-hosted storage from an independent Slovenian vendor, especially those who will use Koofr Vault for sensitive files.
Sub-processor map · none disclosed
Frameworks & certifications · none listed
Capability matrix
Table 1Capabilities of Koofr
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Switzerland · €4/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Switzerland · €10/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Switzerland · €4/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: No Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€4/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€10/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: No
Open source: No
|
€4/mo |