Trust centre
Don’t take our word for it. Check it.
Sovereignty claims are cheap. Verifiable ones aren’t. Everything below is public, specific, and checkable.
Our infrastructure policy
- Customer workloads run exclusively on EU-owned infrastructure providers in EU datacenters. We do not use the EU regions of US-owned clouds. Ever.
- Backups are stored in the EU, at an EU-owned storage provider, in a different datacenter than your site.
- No Cloudflare or other US CDN in front of your site. EU DNS. If you need a CDN, we offer an EU-owned one on request.
- This website loads zero third-party resources: no external fonts, no analytics, no trackers.
Data Processing Agreement
Every plan includes our Data Processing Agreement (verwerkersovereenkomst) under Art. 28 GDPR: processing only on your instructions, EU storage, breach notification without undue delay, deletion on termination, audit rights, and the sub-processor chain below.
We are in soft launch and finalising the DPA with Dutch counsel. Ask for the current draft at info@soevereinhosting.eu โ we would rather send you an honest draft than publish a template we have not had reviewed.
Sub-processors โ the complete chain
Who touches your data, in what role, and under which jurisdiction. If this list changes, existing customers are notified in advance.
| Party | Role | Country / ownership | Data location |
|---|---|---|---|
| Soeverein Hosting | Your hosting provider (processor) | Netherlands ๐ณ๐ฑ | EU |
| Hetzner Online GmbH | Server infrastructure โ where your site actually runs | Germany ๐ฉ๐ช (family-owned, no US parent) | Falkenstein / Nuremberg, DE |
| Scaleway S.A.S. | Encrypted off-site backup storage | France ๐ซ๐ท (Iliad Group) | FR / NL (EU) |
Why this list is so short
Most hosts sit on a stack of vendors: a control panel, a CDN, a monitoring SaaS, a US cloud underneath it all. Every one of those is another company that holds a key to your server and another jurisdiction that could compel them. We removed the middle layer entirely.
No control-panel vendor
We build and manage every server ourselves, directly against the datacenter’s API. There is no hosting panel company in between โ so there is no third party holding an SSH key to the machine your site runs on, and nobody else who could be compelled to hand one over.
No US company in the path
No US cloud, no Cloudflare in front of your site, no US analytics, no Google Fonts. Your visitors’ requests go to a German server and stop there. Even this page you’re reading loads zero third-party resources โ open your browser’s network tab and check.
Why we spell this out: plenty of hosts say “EU cloud” while their management tooling, CDN or support desk sits with a US-owned provider. A sovereignty claim without its footnotes is marketing, not fact. If our chain ever changes, existing customers hear it from us before it happens.
What we claim โ and what we don’t
We claim
- GDPR-compliant processing, with the paperwork to prove it
- EU-owned infrastructure, EU datacenters, EU backups
- An independent EU company โ no US parent
We don’t claim
- “GDPR-certified” โ no general GDPR certificate exists, and we won’t pretend otherwise
- Immunity from law โ EU providers answer to EU courts, as they should
- That hosting location alone makes your site GDPR-compliant โ your content and processes matter too