Compliance

EU Data Sovereignty

The ability to keep data and AI processing entirely within the EU, free from access rights under third-country laws like the US Cloud Act.

Also known as: Data Sovereignty, AI Data Sovereignty

What does EU data sovereignty actually mean?

EU data sovereignty describes the ability to process personal and business-critical data so that it is subject exclusively to EU law, in particular the GDPR. This includes not just where data is stored, but which company has access to it and which country’s law that company is subject to.

Why EU hosting alone is not enough

A server located in the EU does not automatically make processing sovereign. If the hosting provider belongs to a US corporation, for example through a subsidiary, access by US authorities under the US Cloud Act can never be fully ruled out legally, regardless of the physical server location. Only when both processing and the operating company sit entirely outside this access risk can you speak of genuine data sovereignty.

EU data sovereignty at LoyJoy

For chat, LoyJoy runs the Gemma 4 model on its own hardware in its Münster data center. This removes external AI subprocessors from this processing step. No chat data is sent to external US-based model providers during chat inference.

For telephony, the speech-to-speech model now also runs exclusively in an EU Data Zone, so no data processing takes place outside the EU/EEA there either. Since the underlying service is run by a US provider, chat on our own hardware remains the more far-reaching approach for customers with the highest sovereignty requirements. Learn more on the compliance page and in the list of subprocessors in the Trust Center.

Ready to try LoyJoy?

Request your free personalized demo now.