Guides

Data sovereignty, without the marketing

Updated 2026-07-29

“Sovereign”, “trusted cloud”, “100% French”: these words are everywhere, and often emptied of meaning. Here is how to separate substance from marketing.

The real question

It is not “where is my data physically?” but “who can legally demand my data?”. Data stored in Europe but managed by a company subject to US law remains accessible to US authorities.

The Cloud Act

The Clarifying Lawful Overseas Use of Data Act (2018) allows US authorities to compel a company under US jurisdiction to hand over data, even when it is stored outside the United States. In other words: hosting with the European subsidiary of a US giant does not shield you.

Conversely, a European host with no legal ties to the United States falls outside this mechanism. That is concrete and verifiable — no label required to check it.

The GDPR

The General Data Protection Regulation governs the processing of personal data in the European Union: purposes, retention, individual rights, sub-processors. A serious European host lists its sub-processors and where they are located. That is a baseline, not a marketing pitch.

The questions to ask a host

  1. Where is my data physically? (a country, not a vague “in Europe”)
  2. Who is the legal entity behind the infrastructure, and of what nationality?
  3. Are there sub-processors? Which ones, and where?
  4. Can I retrieve and delete my data at any time?
  5. Do you run third-party trackers on your own pages?

Where we stand

We answer these questions publicly, plan by plan, on the sovereignty page: our managed plans run on our own hardware in France, our VPS and dedicated servers on European infrastructure (Germany, Finland). We do not claim to be “certified sovereign” — we simply show you where your data is. That transparency is our argument.