Skip to content
Digital Sovereignty

Your data. Your AI. Verifiable, not merely claimed.

Many digital services today run on US cloud and US AI. That leaves control over your customer data not with you — but with a provider subject to US law. We do it differently, but without the usual promise: US companies are involved on our side too. The difference is that we name every single one, that your data stays in the EU — and that you can leave whenever you want.

Where does your data really run?

Four points hardly any agency talks about — because most are affected themselves.

US access despite servers in Europe

The US CLOUD Act allows US authorities to demand data from US providers — worldwide, including from data centers in Frankfurt. In 2025, Microsoft's head of France confirmed under oath before the Senate that even a »European« cloud cannot guarantee the exclusion of US access.

US CLOUD Act · Hearing, French Senate, June 2025

GDPR fines in the billions

Cumulative GDPR fines reached around €7.1 billion by early 2026. Each violation carries fines of up to €20 million or 4 % of global annual revenue. If you do not know where your data resides, you share that risk.

GDPR Art. 83 · cumulative fines as of Jan 2026

EU AI Act — labelling obligation already applies

Since February 2025, AI must be recognizable as AI (transparency obligations). From August 2026, enforcement and penalties for AI models take effect — up to €35 million or 7 % of revenue. Many »ChatGPT-Wrapper« solutions do not meet the labelling requirement today.

EU AI Act, Art. 50 · Regulation (EU) 2024/1689

Provider dependency (vendor lock-in)

If your website, data and AI sit with a US provider, you often cannot get out cleanly — no complete export, no migration without loss. Your most important asset, your customer data, then effectively belongs to the platform.

EU Data Act · applicable since September 2025

Sovereign by design — not a surcharge, but the standard

What comes built in with us, instead of being retrofitted at a cost.

Data held in the EU

Your data stays in the EU, and your website is delivered by a global network so it loads quickly everywhere. For delivery and protection against attacks we use Cloudflare, covered by a data processing agreement and EU standard contractual clauses and named in the privacy policy. A server exclusively in Germany is available on request.

AI labelled as AI

Every AI answer we deliver for you, we label as AI — exactly as the EU AI Act requires. Set from the start, not retrofitted later.

GDPR from day one

Data held in the EU, proper data processing agreements, clear data flows. For us, data protection is the foundation of the architecture — not a cookie-banner fig leaf.

Your data belongs to you

No lock-in: you can fully export and take your data with you at any time. The tool is replaceable — your customer relationship remains yours.

How it usually works — and how it works with us

Where the data sitsoften not named; EU region of a US corporationdata held in the EU — provider and region are stated in the privacy policy
US government access (CLOUD Act)legally possible with US providerswith us as well — we say so, and cover it with data processing agreements and EU standard contractual clauses
AI modelspredominantly US services (e.g. OpenAI)every model we use is named; EU or local model on request
AI labelling (AI Act)mandatory since February 2025set on every delivery, never retrofitted
Data exportlimited depending on the providercomplete, at any time, contractually guaranteed (T&Cs § 6.5)
Operatorvaries by providerMerust Trust SL, Valencia — address in the imprint

The legal situation — brief and sourced

  • US CLOUD Act: US access to data held by US providers worldwide, including within the EU.
  • GDPR: up to 20 million € or 4 % of global annual turnover per breach; according to public tallies, the fines imposed add up to around 7 billion € (as of early 2026).
  • EU AI Act: transparency and labelling duties since February 2025; enforcement and penalties for AI models from August 2026 — up to 35 million € or 7 % of turnover.
  • EU Data Act: applicable since September 2025 — strengthens data portability and bars unlawful third-country access.

As of July 2026. Summary of the publicly known legal framework, not legal advice. Rules and deadlines may change.

Frequently asked questions about data and independence

What prospective clients ask before entrusting their data to anyone.

Where exactly does my data sit?

Data is held in the EU; the pages are delivered via European data centres. Which service providers are involved in your project, you receive in writing before the contract is signed — not on request, but unprompted. If a tool processes data outside the EU, we say so and name the legal basis, instead of hiding it under “cloud”.

What happens to my website if I stop commissioning you?

You keep it. After payment in full, the website and source code belong to you; we hand over the project so that another service provider can carry on — source code, access credentials, documentation. There is no switch we could use to turn your site off, and no licence that expires when the contract ends.

Do you use my data to train AI?

No. Your content and your customers' data are not used to train models — neither by us nor, as far as we can control it contractually, by the providers we use. Where we use AI, the data processing agreement states which provider it is and what it processes.

What does “replaceable” mean concretely — and where does it end?

We build so that the AI provider can be swapped without rewriting the application, and so that your content remains exportable in common formats. Honest about the limit: complete independence from every service provider does not exist once you use search engines, maps or payment services. We reduce the dependency; we do not claim to abolish it.

Will I get a data processing agreement?

Yes, as standard and at no extra charge, together with the list of subprocessors and the technical and organisational measures. You need one as soon as we process personal data on your behalf — which is already the case with a contact form.

EU infrastructure

Data held in the EU — a server exclusively in Germany is available on request.

GDPR from day one

Data protection under EU law, built into every line of code.

Encrypted

TLS transmission, protected access, secured backups.

Your data belongs to you

No vendor lock-in — exportable at any time.

Know where your data sits.

We take an unhurried look at where your data sits today, who processes it — and what of that you ought to change.

Have your sovereignty reviewedWhat Conexa Digital stands for