European Sovereign Software, With Every Link Named

A German company builds it. European servers run it, under our own hands. Your files are encrypted with keys held in Europe — and the clause that says so is in the agreement you sign.

An EU Region Is Not Sovereignty.

01

A location is not a jurisdiction

A data centre inside a platform with a US parent is still reachable by a foreign order. Where the disk sits is a different question from who can be made to read it.

02

The sub-processor list is where it breaks

Most vendors stop at EU hosting. The copy of your client's rate card sits with whoever they subcontracted, and you learn the names during a security review.

03

Procurement asks in writing

Your client's legal team sends the questionnaire: where the data is, who can reach it, is there an agreement, how the keys are held. Answering it from memory costs a week.

04

Claims nobody can check

European values, EU infrastructure, no company, no certificate, no clause. That is a marketing sentence, not an answer to a vendor review.

How the Chain Fits Together.

Five links, each one written down somewhere you can read.

  1. A European company builds it

    GRAN Software Solutions GmbH, in Germany. The product carries the Software Made in Europe seal of BITMi, the German federal association for IT small and medium business.

  2. We run the platform ourselves

    Your workspace sits on a platform we operate ourselves, rather than inside somebody else's — the part the Software Hosted in Europe seal certifies.

  3. Storage and backups stay in the EU

    Storage and backups stay inside the European Union, with providers located there. The terms put it in one sentence: data is stored exclusively within the EU/EEA.

  4. Keys are held in Europe, apart from the files

    Every invoice PDF and every attachment gets its own key. That key is kept by a European provider, never beside the file it unlocks.

  5. The paperwork comes with the account

    A data processing agreement under Art. 28 GDPR is concluded when you register. A new sub-processor is announced fourteen days ahead, and you may object.

The chain, in full

Where your data lives

Both seals are held by GRAN Software Solutions GmbH for Consulting Cockpit.

  • Our own platform, run by us. Not a rented workspace inside somebody else's.
  • Storage stays inside the EU/EEA.
  • Every file carries its own key, and the key never sits beside it.
  • Product analytics run on our own server. No advertising network.

Two European providers. Both named in the agreement you sign.

What We Claim, and What We Do Not.

A sovereignty claim is worth exactly the parts of it you can check.

Storage inside the EU/EEA, in writing

Not EU regions available on request: the terms state that data is stored exclusively within the EU/EEA, on providers located there.

New sub-processors are announced, not discovered

Fourteen days before one is engaged, with the right to object and, if no solution is found, to leave on fourteen days' notice.

No advertising trackers, no pixels

Product analytics run on our own European server. There is no advertising network in the product and no tracking cookie to dismiss.

What we do not claim

We are not Gaia-X certified and hold no EU Cloud Sovereignty Framework level. The ISO certificates belong to our providers' data centres — that is their audit, not ours.

When a client's auditor asks who changed an hour and when, the answer comes from the record rather than from memory, see Audit Everything

Common Questions.

Where exactly is our data stored?

Inside the European Union. The terms state that data is stored exclusively within the EU/EEA, on providers located there, and the two providers we use are named in the data processing agreement you sign.

Who can see it?

Only the people needed to run the service, under the processing agreement and tied to a named role. Inside a client workspace, every change is recorded with a name and a timestamp.

What about the US CLOUD Act?

No US provider sits in the path of your client data, so there is no US parent to serve an order on. The one US service we rely on is certificate issuance: Let's Encrypt signs our TLS certificates and sees our domain names, never your data.

Do we get a data processing agreement?

Yes. One under Art. 28 GDPR is concluded when you register, and it is published so you can read it before you sign up.

Will we be told when a sub-processor changes?

Fourteen days in advance. If you object on reasonable data protection grounds and no solution is found, you may end the agreement on fourteen days' notice.

Can we take our data and leave?

Invoices and timesheets export to CSV at any time. On termination your data is deleted or returned within 30 days, except invoices, which German commercial and tax law requires us to retain.

Check the Chain Yourself.

Start a 30-day trial and read the agreement before a client's vendor review asks for it. Free for 30 days.