luckycloud
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign This listing EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Berlin-based German zero-knowledge cloud (luckycloud GmbH, 2015), own DCs in Berlin/Nuremberg/Frankfurt, ISO 27001 BSI.
luckycloud is an EU-owned service hosted in Germany, with no identified CLOUD Act exposure. It is listed under File sharing.
Assessment notes
luckycloud GmbH (Berlin, Solmsstr. 26; HRB 169276 B Charlottenburg; founded 2015 by Luc Mader who built the precursor in 2007 at a Berlin university) operates its own server infrastructure across three ISO 27001 / BSI-certified German data centres (Berlin, Nuremberg, Frankfurt), with zero-knowledge encryption + triple-encryption layering + open-source code; no VC/PE investors, founder-led, multiple TÜV Süd / eco / Alliance for Cyber Security trust signals; EU-owned, own German data centres, ISO 27001 + BSI, public DPA, zero-knowledge E2E encryption, no CLOUD Act exposure.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 0 none disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Yes
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About luckycloud
luckycloud is a Berlin-based zero-knowledge encrypted cloud-storage product operated by luckycloud GmbH at Solmsstraße 26, registered with the Charlottenburg Local Court under HRB 169276 B (VAT DE301776461; managing director Luc Mader). The product traces back to 2007 when Mader built an online platform at his Berlin university to share study materials with friends; the commercial company was founded in 2015 and serves SMBs and consumers across DACH. The product line covers luckycloud One (consumer), Teams, Business, and Enterprise tiers with client-side encryption as a default feature across all plans.
For an EU-sovereignty audit luckycloud is one of the cleanest pure-German listings in the directory. The infrastructure is fully owned and operated by the company itself (luckycloud GmbH creates, manages, and maintains the IT stack independently) across three ISO 27001 / BSI-certified German data centres in Berlin, Nuremberg, and Frankfurt. The product is built on open-source software (the file-sync stack uses luckycloud's own in-house Sync Client which replaced an earlier Seafile-based stack; OnlyOffice powers document editing) and follows a strict zero-knowledge principle with triple-encryption layering: vendor cannot access plaintext customer data. Trust signals include TÜV Süd certification, NETZSIEGER recognition, "Deep Tech" certification, eco Award 2019, and Alliance for Cyber Security membership. Founder-led, no VC/PE investors.
Pricing is sold through a product configurator at luckycloud.de/en/products rather than a static price list: storage, user count and contract runtime are set with sliders and the discount is keyed to the runtime chosen, so no headline figure means anything without its term attached. The only fixed figure published on the site is a "from 1 EUR" teaser on the homepage. The model is paid SMB-and-up with no consumer freemium tier observable. Best fit: German and DACH SMBs and consumers wanting a fully-German alternative to Dropbox / OneDrive / Google Drive with own-DC infrastructure, zero-knowledge encryption, and a small founder-led counterparty. Together with Filen, Cryptee, Internxt, Proton Drive, Tresorit, Nextcloud (self-host), and kDrive, luckycloud is part of the directory's top-tier EU-owned file-sharing shortlist.
Sub-processor map · none disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of luckycloud
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Switzerland · €4/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Switzerland · €10/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Switzerland · €4/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: No Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€4/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€10/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: No
Open source: No
|
€4/mo |