Your CRM infrastructure remains under
European jurisdiction.
Every transfer to a third party is explicit.
You know which providers process your data, under which jurisdiction, and at what point.
Why « hosted in Europe » is not enough
Several US legal instruments, notably the Cloud Act and Section 702 of FISA, can allow US authorities to compel certain providers subject to US law to disclose data, even when that data is hosted in Europe.
Cloud Act (2018)
Allows US authorities to compel a provider subject to US law to produce data it holds in its possession, custody, or control, even when stored outside the United States. The exact scope depends on the contractual structure and the entities involved.
FISA 702
Authorises, for foreign intelligence purposes, the targeted collection of communications of non-US persons located outside the United States, with the assistance of certain US electronic service providers. For a European company, this is a risk factor whenever a provider subject to US jurisdiction is part of the chain.
AWS Paris, Azure Amsterdam, Google Frankfurt: these datacentres are operated by US companies. Locating servers in Europe is therefore not enough, on its own, to rule out the potential application of US law when the provider remains subject to US jurisdiction. This is a point commonly examined in DPO, security and procurement audits.
Choosing exclusively European providers does not remove the need for a security and compliance review. It does, however, reduce exposure to extraterritorial US legislation and simplifies control over the subcontracting chain.
The vectors to examine
Hosting is only one exposure vector. A thorough audit covers the entire chain.
Application infrastructure and database
Who operates the servers? Under which jurisdiction?
This is the core exposure point. A server operated by a US entity, even in Europe, remains subject to the Cloud Act.
Structural vectorFile storage (object storage)
Where are attachments, exports and documents stored?
Often overlooked, object storage holds sensitive business data: contracts, client documents, CRM exports.
Structural vectorArtificial intelligence
Does the AI model process your data? Under which jurisdiction?
The leading providers and models (OpenAI, Google, Anthropic) are subject to US jurisdiction. Data sent in context may be exposed — but only if AI is enabled.
Optional vectorThird-party integrations
Do connectors expose data outside the EU?
Gmail, Outlook, WhatsApp and other common services are operated by US entities. Every active integration is a potential vector.
Optional vectorVector by vector
Here is exactly how HOP addresses each of the four identified exposure points.
| Vector | HOP solution | Control measures |
|---|---|---|
| Application infrastructure and database | Hetzner CloudNuremberg + Helsinki | German company with no US parent entity. HOP resources deployed exclusively in the Nuremberg and Helsinki regions. Active/passive architecture across these two European datacentres. European provider, EU region |
| File storage | Scaleway Object StorageParis | French company (Iliad group), with no US parent entity. Data stored in the Paris region. Object encryption enabled on our buckets, mechanism detailed in the architecture sheet. European provider, EU region |
| Artificial intelligence | Client's choice | HOP can connect to the market's leading providers and models: OpenAI, Anthropic, Google Gemini and others. If you want to stay outside US jurisdiction, you can choose Mistral AI (France) or a self-hosted model on your own infrastructure. HOP imposes nothing. Client control |
| Third-party integrations | Explicit activation | No integration is active by default. For any connection involving a transfer outside the EU (Gmail, Outlook, WhatsApp…), an explicit warning is shown before activation. You decide with full knowledge. Client control |
Built for continuity
HOP directly operates its application layer and production infrastructure, with no dependency on a US hyperscaler.
Active/passive architecture across two separate Hetzner datacentres. Failover procedure to backup infrastructure in the event of an incident.
Backups
- Database backup every 4 hours (hourly backup available as an option)
- Stored on Scaleway Object Storage (Paris)
- 24h fine-grained retention
- A daily backup retained for 30 days
- Individual restoration per client
Encryption
- TLS 1.3 for client web connections
- Volume encryption enabled (Hetzner infrastructure)
- Object encryption enabled on Scaleway Object Storage
Monitoring
- Infrastructure monitoring: Hetzner Monitoring
- External supervision: Hyperping
- Application errors: GlitchTip, self-hosted on our infrastructure
- Real-time public status page
- Alerting on critical thresholds
Data isolation
Your data does not share the same logical database as other clients'.
- One database per client: isolation that strongly reduces the risk of cross-client contamination, including in the event of an application error
- Dedicated MySQL user, permissions strictly limited to the relevant database
- Individualised access logs per instance
Operated by HOP
- Infrastructure and application data operated exclusively by the HOP team
- External supervision provided by a French provider, on technical data only
- HOP technical team responsible for maintaining operational conditions
- Failover and restoration tests carried out every month, following documented procedures
The documents you need for your review
List of subprocessors, data location, backup policy, reversibility procedure, availability commitments: the contractual and technical elements useful to your CIO, DPO or procurement team are available before you commit.
Evaluate HOP with your CIO or DPO
We answer your questions on architecture, security, subcontracting and data location directly.
Discuss your target architectureArchitecture sheet
A concise document presenting the architecture, data location, security measures and availability commitments.
Are you an integrator? Access partner documentation

