Trust centre

Don’t take our word for it. Check it.

Sovereignty claims are cheap. Verifiable ones aren’t. Everything below is public, specific, and checkable.

Our infrastructure policy

  • Customer workloads run exclusively on EU-owned infrastructure providers in EU datacenters. We do not use the EU regions of US-owned clouds. Ever.
  • Backups are stored in the EU, at an EU-owned storage provider, in a different datacenter than your site.
  • No Cloudflare or other US CDN in front of your site. EU DNS. If you need a CDN, we offer an EU-owned one on request.
  • This website loads zero third-party resources: no external fonts, no analytics, no trackers.

Data Processing Agreement

Every plan includes our Data Processing Agreement (verwerkersovereenkomst) under Art. 28 GDPR: processing only on your instructions, EU storage, breach notification without undue delay, deletion on termination, audit rights, and the sub-processor chain below.

We are in soft launch and finalising the DPA with Dutch counsel. Ask for the current draft at info@soevereinhosting.eu โ€” we would rather send you an honest draft than publish a template we have not had reviewed.

Sub-processors โ€” the complete chain

Who touches your data, in what role, and under which jurisdiction. If this list changes, existing customers are notified in advance.

PartyRoleCountry / ownershipData location
Soeverein HostingYour hosting provider (processor)Netherlands ๐Ÿ‡ณ๐Ÿ‡ฑEU
Hetzner Online GmbHServer infrastructure โ€” where your site actually runsGermany ๐Ÿ‡ฉ๐Ÿ‡ช (family-owned, no US parent)Falkenstein / Nuremberg, DE
Scaleway S.A.S.Encrypted off-site backup storageFrance ๐Ÿ‡ซ๐Ÿ‡ท (Iliad Group)FR / NL (EU)

Why this list is so short

Most hosts sit on a stack of vendors: a control panel, a CDN, a monitoring SaaS, a US cloud underneath it all. Every one of those is another company that holds a key to your server and another jurisdiction that could compel them. We removed the middle layer entirely.

No control-panel vendor

We build and manage every server ourselves, directly against the datacenter’s API. There is no hosting panel company in between โ€” so there is no third party holding an SSH key to the machine your site runs on, and nobody else who could be compelled to hand one over.

No US company in the path

No US cloud, no Cloudflare in front of your site, no US analytics, no Google Fonts. Your visitors’ requests go to a German server and stop there. Even this page you’re reading loads zero third-party resources โ€” open your browser’s network tab and check.

Why we spell this out: plenty of hosts say “EU cloud” while their management tooling, CDN or support desk sits with a US-owned provider. A sovereignty claim without its footnotes is marketing, not fact. If our chain ever changes, existing customers hear it from us before it happens.

What we claim โ€” and what we don’t

We claim

  • GDPR-compliant processing, with the paperwork to prove it
  • EU-owned infrastructure, EU datacenters, EU backups
  • An independent EU company โ€” no US parent

We don’t claim

  • “GDPR-certified” โ€” no general GDPR certificate exists, and we won’t pretend otherwise
  • Immunity from law โ€” EU providers answer to EU courts, as they should
  • That hosting location alone makes your site GDPR-compliant โ€” your content and processes matter too