What 'EU-Hosted' Actually Means for Client Data
"EU-hosted" appears on a great many product pages and means several different things. Some of them are a meaningful commitment. Some are a region dropdown on an American platform. If a client has asked you where their documents are stored, the difference is worth understanding before you answer.
Quick answer (TLDR)
- EU-hosted, EU region, EU data residency and EU company are four separate claims
- Storing data in the EU does not by itself make a service GDPR compliant
- Backups are the most common gap between the claim and the reality
- Sub-processors matter: mail, payments, analytics and support tooling all touch data
- Four questions separate genuine EU-only setups from a region setting
The four claims, separated
"Hosted in the EU." The servers holding your data are physically in the European Union. This is the narrowest and most literal claim, and on its own it says nothing about backups, sub-processors, or who runs the company.
"EU region available." Common on large platforms. You choose a region at signup and your primary data lands there. Usually true as far as it goes. It typically does not tell you where backups, logs, telemetry or support tooling live, and those are separate systems.
"EU data residency." Usually a stronger claim than a region setting, sometimes contractually committed. Read what is actually covered - it often means primary storage and not much else.
"An EU company." This is about corporate nationality, not geography. Which legal entity is your contract with, where is it registered, and which courts have jurisdiction. A US company storing data in Frankfurt has EU hosting and is not an EU company. That may be perfectly fine for your purposes, but it is a different fact.
These four get used interchangeably in marketing copy, including by companies that are being entirely honest. They just are not the same thing.
What GDPR actually cares about
Worth clearing up, because "EU-hosted so we're GDPR compliant" is a common shortcut and it is not right.
GDPR governs how personal data is processed. It applies to processing carried out in the context of an EU establishment regardless of where the processing happens, and to organisations elsewhere that target or monitor people in the EU. Location is not the trigger.
Where location does matter is Chapter V, the rules on transfers outside the EU and EEA. Keeping data inside the EU means those rules are simply not engaged, which removes a category of complexity - assessing transfer mechanisms, standard contractual clauses, and the supplementary measures that go with them. That is a genuine and practical benefit.
But a service storing everything in Ireland can still process data unlawfully, retain it too long, secure it badly or share it with parties it should not. And your own compliance depends on your lawful basis, your notices, your retention practice and your contracts, none of which a hosting location settles.
The honest framing: EU hosting removes one specific problem and makes a client conversation shorter. It does not make anyone compliant.
The four questions that tell claims apart
If you are evaluating a tool, or answering a client, these are the ones that produce real information.
1. Which country holds the primary data, and where are the backups?
Ask about backups explicitly. This is the most common gap, and it is rarely volunteered. A service can hold primary data in an EU region while replicating backups elsewhere for durability, which is a defensible engineering decision and still an answer you should have before telling a client their data never leaves the EU.
2. Which legal entity am I contracting with, and where is it registered?
Look at the terms of service, not the website footer. Which company appears as the counterparty, and which law and courts are named? This determines who you can hold to the contract and where.
3. Which sub-processors touch this data, and where are they?
Every service uses others. Email delivery, payment processing, error monitoring, analytics, customer support tooling, sometimes AI features. Each is a sub-processor and each has its own location. A good vendor publishes the list; a vendor that cannot produce one on request is telling you something.
Note what each sub-processor actually receives. A mail provider that sends notification emails handles addresses and message text, not your stored files. That distinction matters and is worth asking about rather than assuming either way.
4. Can support staff access my content, and from where?
Data at rest in Frankfurt that a support engineer can open from anywhere is a different proposition from data nobody at the vendor routinely reads. Ask what access exists, under what controls, and where the people are.
Where this actually matters for a professional firm
Not everywhere, and it is worth being proportionate.
It matters most when your clients ask - and in some sectors they will, in writing, as part of their own supplier due diligence. Being able to answer in one sentence with a country and a company name is worth a surprising amount.
It matters when you handle special-category data: health information, criminal record data, anything under professional confidentiality obligations. The bar you are held to is higher and the questions come sooner.
It matters when a public-sector or regulated client imposes conditions in the contract. Those conditions are frequently specific about location and about sub-processors.
It matters less for routine business documents where nobody has asked and no rule applies. Choosing a tool purely on hosting location when the actual problem is that clients cannot find their documents is optimising the wrong thing.
Where Droplana sits
We build a client document portal, so this is our own answer to the four questions.
Primary data and backups. Files, comments and metadata are stored exclusively on Hetzner infrastructure in Germany. Objects are stored under opaque, randomly generated identifiers rather than being named after a client, a filename or its contents, and are never exposed on the public internet.
The legal entity. Droplana is operated by Ubique d.o.o., a company registered in Croatia, in the European Union, with a registered seat in Zagreb. Disputes are subject to Croatian law and Croatian courts. A Data Processing Agreement is available on all plans, countersigned on Practice and Studio.
Sub-processors. Server, database and storage with Hetzner in Germany. Mail delivery with Brevo in France. Payments through Creem in Estonia. Code storage with GitHub in the US, which holds no customer data. The mail and payment providers receive only what their function requires - email addresses, billing details - and never file contents.
Encryption and access. Traffic is TLS. Files are encrypted at rest with AES-256 using a key derived per client. The database, application configuration and logs sit on LUKS-encrypted volumes. To be exact about what that protects: it defends against a breach of the storage platform, not against a compromise of the application host itself, because the master key lives there alongside the storage credentials. This is not end-to-end encryption, and if your requirement is that the provider cannot technically read your files, you need a zero-knowledge product rather than ours.
That last paragraph is the part most vendors leave out, and it is the part a technically literate client will ask about.
More on the compliance framing in GDPR-compliant file sharing with clients, and on the access-level side in client portal security levels. The legal page covers why the location question arrives in writing more often in some sectors.
The short version
"EU-hosted" can mean anything from a genuine EU-only stack under an EU company to a region dropdown on a US platform. Ask where the backups are, which entity you are contracting with, who the sub-processors are and where they sit, and whether support staff can read your content. Then be clear with yourself that keeping data in the EU removes the transfer question, and no more than that - compliance is about how you handle the data, not only where it rests.
Want a one-sentence answer when a client asks where their documents are? Try Droplana free - three clients, no card.