Vai al contenuto

Providers and jurisdictions

"Your data stays in the EU" is only worth something if you can check it. This page lists every company involved in running ReefOffice, what each one actually does, what data reaches it, and whose courts it answers to. It is the sub-processor list required by Article 28 of the GDPR, written to be read rather than filed.

ProviderWhat it doesWhat data reaches itJurisdiction
Contabo GmbH Munich, Germany · Amtsgericht München HRB 180722Hosts your private serverEverything you store — at rest it is LUKS2-encrypted with a key Contabo does not hold🇩🇪 Germany
Hetzner Online GmbH Gunzenhausen, GermanyEncrypted off-site backups, and the control plane that manages your serverRestic-encrypted backup archives. Hetzner sees ciphertext only🇩🇪 Germany
OVH SAS (OVHcloud) Roubaix, FranceDNS records for your domain, and Managed EU AI inference when you enable itYour subdomain name; and, only on the Managed AI plans, the text you send to an AI feature. Not used for training🇫🇷 France
o2switch Clermont-Ferrand, FranceEmail delivery for notifications and supportYour email address and the content of messages we send you🇫🇷 France
GoCardless SAS Paris, France · RCS Paris 834 422 180 · payment institution authorised by the ACPR (CIB 17118)Collects subscription payments by SEPA direct debitYour billing name, email, IBAN and payment history. Never your business data🇫🇷 France

Why the jurisdiction matters, not just the location

A server in Frankfurt owned by a US company can still be reached by a US legal order under the CLOUD Act, because that law follows the company rather than the hardware. That is the gap most "EU region" marketing leaves open. Every supplier below is an EU-incorporated company operating EU infrastructure, so both the data and the company answer to EU law.

Who is not on this list

No advertising network, no analytics product, no US hyperscaler, and no AI provider that trains on customer data. ReefOffice runs no third-party tracking scripts on this website — there is nothing to consent to because nothing is collected.

Changes

We give at least 30 days' notice by email before adding or replacing any provider on this list. If you object and we cannot resolve it, you may terminate without penalty and take your data with you. See the Data Processing Agreement for the full terms.

Data Processing Agreement · Privacy policy · Security

Question about a specific provider?

Ask, and we will answer with the contract terms rather than a summary.

Contact us