1. Where the data sits
Bare-metal servers in Falkenstein, Saxony. Your app, your managed PostgreSQL, MySQL or Redis, your persistent volumes, your backups and your logs — all in that one region. No replicas outside Germany.
EU operator • EU infrastructure • EU jurisdiction
Run your Docker apps and managed databases on bare metal in Falkenstein, Germany, operated by a German company under German law. No transfer to a third country. No US parent that could be served a warrant.
Most “European cloud” claims cover only the first. Cloud sovereignty needs all three, so ask about all three.
Bare-metal servers in Falkenstein, Saxony. Your app, your managed PostgreSQL, MySQL or Redis, your persistent volumes, your backups and your logs — all in that one region. No replicas outside Germany.
HOSTIM.DEV UG (haftungsbeschränkt), registered in Germany. No US parent, no US subsidiary, no US infrastructure. Verifiable in the German commercial register and in our Impressum.
German and EU law. Engineering and support are inside the EU. There is no foreign legal path to your data, because there is no foreign legal entity in the chain.
The distinction procurement teams keep running into.
| Question | US platform, EU region | Hostim.dev |
|---|---|---|
| Data physically in the EU | ✅ Usually | ✅ Falkenstein, Germany |
| Operator incorporated in the EU | ❌ US parent | ✅ German UG |
| Outside US Cloud Act reach | ❌ No | ✅ Yes |
| SCCs / Transfer Impact Assessment needed | ✅ Yes, per Schrems II | ❌ No transfer to assess |
| DPA under GDPR Art. 28 | ✅ Usually | ✅ On request, EN or DE |
| Support and engineering in the EU | ❌ Often not | ✅ Yes |
Hosting in the EU keeps personal data inside the EU territorial scope. No transfer to a third country means no Standard Contractual Clauses, no Transfer Impact Assessment and no supplementary measures. The compliance work shrinks from a project to a checkbox. What is left — consent UI, privacy policy, data subject requests, retention in your own tables — is application-level and stays your responsibility. We provide the substrate; you handle the surface.
The 2020 Schrems II decision invalidated Privacy Shield and put strict limits on sending personal data to US providers, even with SCCs in place. The simplest answer is not to transfer. Your containers, your queue workers, your databases and your volumes are all inside the EU, so the transfer analysis never starts.
The Cloud Act lets US authorities demand data held by US companies anywhere in the world, which conflicts with GDPR Article 48 in many cases. It applies to the company, not to the building. A German UG with no US presence is outside its reach.
Today Hostim runs a single EU region in Falkenstein. That is good for residency and simple to attest. It also means we do not yet offer a second EU region for disaster recovery, or per-country localisation such as keeping a Polish customer’s data only in Poland. Both are on the roadmap, not shipped. If your DR plan depends on either, talk to us first.
The honest list is shorter to read than the marketing one, and it is the part a buyer checks.
We are not ISO 27001, SOC 2, BSI C5, TISAX or HIPAA certified. Those are audits we have not completed. If one is mandatory for your buyer, ask us before you build on us.
We are not part of Gaia-X or SecNumCloud. The structural facts — EU operator, EU disks, EU jurisdiction — are what most commercial buyers actually ask about, but they are not a certification.
Stripe handles payments under its own sub-processor chain. Standard for EU SaaS, but name it in your privacy policy. Application data has no non-EU sub-processor.
The policy argument is about dependence. The engineering question is what it costs you to stop depending.
Most European software runs on three American platforms. That is fine until a price change, an export rule or a court decision is made somewhere you have no vote. Digital sovereignty is the work of not being in that position.
Hostim runs standard Docker images on Kubernetes. If your app builds into a container today, it runs here today, and it runs somewhere else tomorrow. Sovereignty you cannot reverse is just a different lock-in.
From €2.50 per month per app, with managed PostgreSQL, MySQL and Redis on the same bill. A European cloud provider is not a premium product here. It is usually the cheaper line item.
An EU sovereign cloud means three things at once: the data is stored in the EU, the operator is an EU-incorporated company, and the governing jurisdiction is EU law. Residency alone is weaker — a US-owned platform with a Frankfurt region has EU residency but is not sovereign, because its parent company remains subject to US law.
Residency is about the disk. Data sovereignty is about the disk, the company and the courts. A US provider can give you an EU region and still be compelled under the US Cloud Act. An EU operator with no US entity cannot be.
Data sovereignty is a question about one dataset: where it lives, who holds it, which law reaches it. Digital sovereignty is the wider question of whether your organisation depends on infrastructure it has no influence over. Hostim.dev answers the first directly, and helps with the second by running standard Docker images, so moving in or out is a deployment change rather than a rewrite.
No. Hostim is operated by HOSTIM.DEV UG (haftungsbeschränkt), a German company with no US parent, no US subsidiary and no US infrastructure. There is no US legal entity in the chain for a US authority to serve.
No. Both Hostim and your data are inside the EU, so there is no transfer to a third country. Schrems II obligations — SCCs, a Transfer Impact Assessment, supplementary measures — apply to transfers, and there is no transfer to assess.
On bare-metal servers in Falkenstein, Saxony, Germany. Application data, managed database data, backups and logs all stay in that one region. There are no replicas outside Germany.
Stripe processes payment data under its own contracts, which is standard for EU SaaS and worth naming in your privacy policy. For application data — your users, your database, your storage volumes — there is no non-EU sub-processor.
Email support@hostim.dev. We send a signed DPA as a PDF in English or German. The substance meets GDPR Article 28.
No. We have not undergone those audits and we do not claim them. We are also not part of Gaia-X or SecNumCloud. If your buyer requires a specific certification, ask us first — we will tell you honestly whether we can meet it.
Yes, under German law, like with any German company. That is the trade-off of EU sovereignty: EU legal access instead of foreign legal access. It is a narrower and more predictable exposure, not zero exposure.
Start now
Open the dashboard and deploy a Docker image, a Git repo or a template. The 5-day trial project needs no card.