Compliance
EU Data Sovereignty
The ability to keep data and AI processing entirely within the EU, free from access rights under third-country laws like the US Cloud Act.
Also known as: Data Sovereignty, AI Data Sovereignty
What does EU data sovereignty actually mean?
EU data sovereignty describes the ability to process personal and business-critical data so that it is subject exclusively to EU law, in particular the GDPR. This includes not just where data is stored, but which company has access to it and which country’s law that company is subject to.
Why EU hosting alone is not enough
A server located in the EU does not automatically make processing sovereign. If the hosting provider belongs to a US corporation, for example through a subsidiary, access by US authorities under the US Cloud Act can never be fully ruled out legally, regardless of the physical server location. Only when both processing and the operating company sit entirely outside this access risk can you speak of genuine data sovereignty.
EU data sovereignty at LoyJoy
For chat, LoyJoy runs the model Gemma 4 on its own hardware in its own data center in Münster. This removes external subprocessors and the US Cloud Act attack surface entirely for chat. Learn more on the compliance page and in the list of subprocessors in the Trust Center.