Hosted in Europe, all the way down.
French servers, run by a French company, sold by a Swedish one. There is no region to pick and no US parent anywhere in the chain, so the answer is the same however far up somebody asks.
Where your app actually is.
Not the marketing answer. The four facts a procurement form asks for, in the order it asks for them.
The servers are in France
Everything you deploy sits there: your code, your files, the database behind your app, and the backups of both. There is no other region, so nothing can quietly end up in one.
The operator is a French company
OVH SAS, trading as OVHcloud. An EU company with no parent outside the EU, which means the question of who could be compelled to hand your data over has a European answer.
The supplier is a Swedish company
Your contract is with Bernskiold Media AB, registered in Sweden under 556893-1652, invoicing in euros with a European VAT number. Support is answered from Sweden by the people who build the thing.
The backups are in the EU too
Copies taken for recovery are held in the EU and age out on their own cycle within ninety days. Residency that stops at the primary copy is not residency.
“EU region” and “European company” are not the same sentence.
Almost every large host will sell you a region in Europe. Your data sits in Frankfurt or in Dublin, the dropdown says so, and the box on the form gets ticked.
The company operating that region is often not European. Ownership follows the parent, and so does the law that can reach the parent. That is why the serious questionnaires stopped asking where the data centre is and started asking who owns the company holding the data, and who could be ordered to produce it.
agenthost has one answer, and it does not change as you walk up the chain. Nothing to caveat, no footnote about the group structure, no page explaining why the parent company does not really count.
No region to pick
There is no dropdown, so there is no wrong choice inside it, and no default somebody accepted three years ago that nobody has looked at since.
It cannot quietly move
Moving the hosting of what you deploy outside the EU or EEA would count as a sub-processor change: thirty days of written notice, and a right to object and leave. That is in the agreement, not just on this page.
Two sub-processors, both named
The whole list is two entries long, with what each one does and where it sits. Read it before you ask us for it →
The one thing that does leave, said out loud.
We would rather write this on the landing page than let you find it in section 9.
When agenthost sends an email, an invitation to a private app or a one-time sign-in code, that address goes to our email provider, which is established in the United States. The transfer rests on the European Commission’s standard contractual clauses, a transfer impact assessment, and the EU-US Data Privacy Framework where the provider is certified under it. You can ask us for a copy of the safeguards at any time.
Nothing else goes. Not your code, not your files, not your database, not your backups, not your app’s traffic. Card payments are handled by Stripe’s Irish entity and never touch what you deploy at all.
That is the complete list. It is set out the same way in the data processing agreement and the privacy policy, which are the binding versions of this page.
What your client's procurement is going to ask.
Six questions, and the answers you can forward without checking with us first.
Where is the data stored?
France. Code, files, databases and backups, all of it, on servers operated by a French company with no parent outside the EU.
Can we see your DPA?
It is a URL. Published, versioned, dated and already in force for every customer on every plan, including the free one. There is nothing to sign and nothing to countersign. Send them this →
Who are your sub-processors?
Two, named on that same page, with what each does and where it is. Adding or replacing one means thirty days of notice to you and a right to object.
Do you train AI models on our data?
No. What you deploy exists on our systems to run your app and for no other reason. It is not mined, not profiled, and never used to train or evaluate a model, ours or anybody else’s.
How fast do we hear about a breach?
Within forty-eight hours of us becoming aware, at the address on the account, with what we know at that point rather than a finished report weeks later.
What happens when we leave?
Export whatever you want through the service itself, at any time. Everything is deleted thirty days after the account closes, and the backups age out within ninety.
Compliance is something you do. These are the parts we hand you.
Hosting in Europe is a component of a GDPR position, not the whole of one. Here is the honest division of labour.
You are the controller
Whatever lives inside your app is yours to decide about. We only ever process it on your instruction, as your processor, which is exactly what the Article 28 agreement is for and why it exists as a published document.
The record is yours to reach
You hold the keys to your own database, so an access, correction, export or erasure request is something you answer yourself in minutes. No ticket with us, no waiting on our queue to satisfy someone else’s deadline.
What we cannot do for you
We have no ISO 27001 or SOC 2 certificate and we do not fill in spreadsheets. Hosting in the EU does not by itself make your app lawful either. What you collect, why, and what you tell people about it is still your call.
The technical measures behind all of this, isolation, credentials, transport and the rest, are on the security page.
The rest of it.
Is agenthost GDPR compliant?
That is not quite a question a host can answer on its own, and anyone who says otherwise is selling you a badge. What we can say: we act as your processor under a published Article 28 agreement, we keep what you deploy in the EU, our sub-processor list is two entries long, and the one transfer out is documented with its safeguards. Whether your app is compliant depends on what you built and why, which is yours.
Do I have to sign or request anything to get the DPA?
No. It is incorporated into the terms you accepted when you created your account, so it has been in force since your first minute here, on the free plan as much as any other. Save or print the page if your auditor wants it on file, and the version and date at the top identify it.
Can I choose to host outside the EU?
No, and that is the point rather than a limitation we are apologising for. One location means one answer to every question about it, which is worth more than a dropdown to the people who buy this.
I'm not in the EU. Does any of this matter to me?
If any of your users are, then yes, because the rules follow the people rather than your company. And if you sell to European businesses, a supplier with a European answer is one fewer objection in the room, whichever country you invoice from.
Will my app need a cookie banner?
That depends entirely on what you put in it. We add nothing to your app: no injected script, no tag, no analytics, no cookie of ours on your visitors. What your app sets is what your app sets. This site counts page views with a self-hosted Matomo that stores nothing on your device, which is why you were not asked to click anything on the way in.
Will my app be fast in Europe?
It is served from France, so European visitors are close to it. Be realistic about the other direction: there is no global CDN in front of your app, so a visitor in Sydney is a long way from it. For most of what gets built here, that trade is the right way round.
Who answers when I email support?
A person in Sweden who works on agenthost. Not a tier-one queue, and not an offshore desk reading from a script. How support works →
A European answer, on a link you can send.
Ten static sites free forever, no card, and a data processing agreement that was in force before you asked for it.