Sovereignty & regions
EU data, EU law: what sovereignty actually means for your stack
Beyond the region dropdown: where the control plane lives, where the logs and backups go, who the subprocessors are, and which questions to ask any provider claiming an EU region.
"We have an EU region" is a sentence that does less work than most people assume. Here are the questions that actually determine the answer, and ours.
Question 1: where does the control plane live?
Your workload can run in Frankfurt while the system that manages it — the API, the database of what should be running, the audit log — runs somewhere else entirely. That control plane holds your account data, your project names, your environment variable names, your usage history and your invoices.
An EU region with a US control plane means your metadata is subject to a different jurisdiction than your data, and metadata is often the sensitive part.
Ours: the control plane runs on our own hardware in the Netherlands. It is the same infrastructure as everything else, not a separate managed service somewhere convenient.
Question 2: where do the logs go?
Logs are the most commonly overlooked path out of a jurisdiction. They contain request paths, IP addresses, user identifiers, error payloads with real values in them. Many platforms ship logs to a central aggregation service in whichever region the vendor's contract points at.
Ours: logs stay in the region of the workload that produced them. There is no central aggregation elsewhere.
Question 3: where do the backups go?
The second most commonly overlooked path. A backup is a complete copy of your database, and "replicated for durability" often means "replicated to wherever object storage was cheapest".
Ours: backups stay in the region. Our own control-plane snapshots go off-site — deliberately to a different region than the one they describe, because a backup in the same failure domain is not a backup — and those are our operational data, not your customer records.
Question 4: who are the subprocessors, per region?
Not a generic list. Which ones touch data in your region, and what for.
Ours, with what each one sees:
- Mollie (Amsterdam) — payment processing. Sees payment identifiers, not your application data.
- WeFact — invoicing. Sees your billing details.
- Openprovider / Hosting Concepts — domain registration. Sees registrant details, as registry rules require.
- Cloudflare — only if you enable it for your own domain. Your choice, listed because it is a real path.
- A transactional email provider — for mail your app sends.
- The data center per region — physical hosting of hardware we own.
That is the whole list. It is in the DPA and it changes with advance notice, not quietly.
Question 5: is the legal counterparty in the EU?
If your contract is with an entity in another jurisdiction, that jurisdiction's law reaches your relationship regardless of where the servers are. That is what the Schrems litigation was about, and it did not stop being true because everyone got tired of talking about it.
Ours: the contracting entity is a Dutch B.V. Disputes go to a court in Rotterdam. Dutch and EU law, without a chain of intermediate agreements.
Question 6: can you read the DPA before signing up?
If a data processing agreement requires a sales conversation, that is a signal about how the company thinks about the document.
Ours: right here, as an ordinary page. Read it, copy it, send it to your counsel. No form, no email address, no gated PDF.
What sovereignty does not mean
Some honesty in the other direction, because this topic attracts more marketing than it deserves.
It does not mean immunity from every legal process. A Dutch company receives Dutch and EU legal orders and complies with them. What it means is that the process is one you can read about in a law you can look up, with a court you could go to.
It does not automatically mean better security. A badly-run EU host is worse than a well-run American one. Jurisdiction is one property; competence is another, and they are independent.
It does not mean you have no obligations. You are the controller for the data in your app. Where it lives is one of your decisions; what you do with it is the rest of them.
It is not automatically the most important criterion. If your users need low latency in Asia today, our answer to that is worse than a hyperscaler's, and no amount of jurisdictional cleanliness changes it.
Why we can answer these at all
Because we own the hardware. Every question above has an awkward answer when the honest response is "our provider's provider handles that". We can say where the disk is, because we bought it.
That is the same fact that makes the spending ceiling possible, which is not a coincidence — it is one decision with two consequences.
Ask your current provider
The six questions, in order. The answers are usually findable in ten minutes of documentation, and the interesting part is not any single answer but which ones they make hard to find.
Set your limit and start.
One click with a passkey, then you verify a payment method once to start your 14-day free trial (€ 10 of credit). After that it is prepaid pay-as-you-go — you only ever spend credit you have already bought, and no invoice ever arrives above the amount you set.