GDPR hosting, choosing a compliant provider
Updated 2026-07-29
GDPR-compliant hosting is not a box to tick, it is a chain of responsibilities. If your site processes personal data, your host becomes one of your sub-processors within the meaning of the regulation, and its seriousness directly affects your own compliance.
Your concrete obligations
The GDPR applies as soon as you handle personal data: email addresses, IP addresses, login credentials, form submissions. In practice, you must:
- keep a register of processing activities and their purposes;
- bind every sub-processor with a contract (Article 28);
- guarantee data security (encryption, restricted access, backups);
- honour individuals’ rights (access, rectification, erasure);
- limit collection to what is strictly necessary.
Location and sub-processors
The GDPR does not forbid hosting outside France, but it strictly regulates transfers outside the European Union. Staying within the EU makes everything simpler: no transfer mechanism to justify.
Our managed plans (web, WordPress) are hosted in France, on our own hardware. Our VPS and dedicated servers run on Hetzner infrastructure in the European Union (Germany, Finland), and therefore within the GDPR’s perimeter. Every additional sub-processor (CDN, email service, payments) must be identified and put under contract on your side.
Cookieless analytics
The CNIL requires consent for most trackers. Privacy-respecting audience measurement avoids that burden: our web and WordPress plans include Umami, a cookieless analytics solution hosted by us, which exposes none of your visitors’ data to a third party. Properly configured, it can generally be used without a consent banner.
Checklist for choosing a compliant host
Before signing, check that the provider:
- offers a data-processing agreement (Article 28);
- clearly states where the data and the backups are hosted;
- stays within the European Union or justifies its transfers;
- documents its security measures (encryption, isolation, access control);
- allows export and erasure of your data at any time.
We claim no SecNumCloud label and no certification we have not had audited: GDPR compliance is shared work between you and your host, not a sticker.
For our position on data location and applicable law, see sovereignty. For the plans concerned, see web hosting.