GDPR · EU sovereignty · Schrems II-free

100% EU-hosted. 100% GDPR-aligned.

The whole platform — code, database, files, AI and emails — runs at Hetzner in Falkenstein/Nuremberg (DE), backup in Helsinki (FI) — managed via Elestio (IE). No pupil data crosses the Atlantic. That is what makes us the realistic EU alternative to Microsoft 365 and Google Workspace for schools and local authorities.

The data journey — and where it doesn't go

No US hops. Every step is documented in our DPA.

Step 1
Pupil / teacher
School in DK / UK
Step 2
Cloudflare
EU edge (Frankfurt, Amsterdam, Copenhagen)
Step 3
Hetzner
Hetzner fsn1 — Falkenstein, DE
Step 4
Supabase
eu-central-1 — Frankfurt, DE

What we don't do: We do not send pupil data to the US. We do not use Azure us-east, AWS us-east or GCP us-central. We do not use US email infrastructure. We do not use Cloudflare nodes outside the EU.

Sub-processors — all in the EU

We give 30 days' notice before changes. The list is part of your DPA.

ProviderRoleLocationLegal basis
Hetzner Online GmbHApp and file hosting + encrypted S3 backupfsn1 Falkenstein (DE) · nbg1 Nuremberg (DE) · hel1 Helsinki (FI, backup)Art. 28-databehandleraftale (EU/EØS)
ElestioManaged infrastructure operationsIreland (EU)Art. 28-databehandleraftale (EU/EØS)
SupabaseDatabase, auth, edge functionseu-central-1 (Frankfurt, DE)Art. 28-databehandleraftale (EU/EØS)
CloudflareCDN and DDoS protection (EU-only routing)EU edge (Frankfurt, Amsterdam, Copenhagen)Art. 28-databehandleraftale (EU/EØS)
OpenAIAI text on pseudonymised dataEU data residency (Frankfurt) + Zero Data RetentionArt. 28-databehandleraftale (EU/EØS) + Zero Data Retention
Google (Gemini)AI text and image generation on pseudonymised teacher promptsEU data residency (Google Cloud europe-west4, NL)Art. 28-databehandleraftale (EU/EØS)
ResendTransactional emailEU (Frankfurt)Art. 28-databehandleraftale (EU/EØS)

GDPR rights — operationalised in the platform

Not just a policy. Every right has a concrete action in the app.

Art. 15
Access
Parents/pupils can export all personal data in a machine-readable format at any time from the profile page.
Art. 16
Rectification
Inaccurate data is corrected directly in the platform. Changes are logged in the audit trail.
Art. 17
Erasure
School transfer deletes or anonymises the account within 30 days. Backups rotate out after 35 days.
Art. 18
Restriction
Accounts can be set to read-only while a complaint is processed — with no data loss.
Art. 20
Portability
The school-transfer bundle exports the full pupil profile (learning history, VARK, grades) as a ZIP to the new school.
Art. 21–22
Objection & automation
No automated decisions with legal effect. AI feedback is advisory — grading always requires a teacher.
NIS2 — another incentive

NIS2 turns vendor choice into a board-level responsibility

The NIS2 directive (EU 2022/2555, transposed in Denmark via the NIS2 Act adopted Dec 2024 / entering into force in 2025) expands requirements on risk management, supply-chain security and incident reporting. Schools themselves are usually out of scope — but their councils and operators are in scope, and the requirements flow downstream into procurement and contracts.

Art. 21
Supply-chain accountability
The management of the in-scope entity (the council) is personally liable for assessing risk across the full supply chain — including cloud and SaaS. US-owned vendors with CLOUD Act exposure are a documented chain risk.
Art. 23
Incident reporting 24/72 h
Early warning within 24 h, full report within 72 h to the CSIRT. That requires a vendor with EU-based support and logs in EU jurisdiction. We deliver incident logs and DPA annexes in the EU time zone.
Art. 34
Fines and personal liability
Up to EUR 10 m or 2% of global turnover for essential entities — plus personal liability for management. A double incentive to choose EU-sovereign vendors from day one.

“GDPR is about personal data. NIS2 is about the entire supply chain. Both point the same way: away from US-controlled cloud services for critical public operations.”

Hard comparison

Us vs. Microsoft 365 vs. Google Workspace vs. Google Classroom

Cut for school leaders and DPOs who need to answer the board tomorrow.

AreaUsMicrosoft 365Google WorkspaceGoogle Classroom (free)
Data locationEU (NL + DE), never USGlobal — EU Data Boundary with exceptionsGlobal — Workspace stores in EU, but metadata flows to USGlobal — no data location guarantee in the free tier
CLOUD Act exposureNo — Danish-owned and using EU legal entitiesYes — US parent companyYes — US parent companyYes — same US parent (Alphabet)
Schrems IINo third-country transfer — Schrems II not relevantRequires TIA + supplementary measuresRequires TIA + supplementary measuresRequires TIA — Danish DPA advised against use without risk assessment
DPA bundled with contractYes — signed alongside the subscriptionSeparate agreement, demanding wordingSeparate agreementSchool self-accepts the DPA online — flagged by the Danish DPA
AI training on pupil dataNo — ZDR + pseudonymisationCopilot is not trained, but telemetry is collected. Opt-out is complexGemini for Education is not trained, but opt-out for other services is complexFundamentals covers core — 'Additional services' (YouTube, etc.) run on consumer terms per pupil
Danish DPA precedentBuilt to align with the Danish DPA's 2022 and 2024 guidanceUse rolled back in several Danish municipalities (e.g. Helsingør, 2022)Use rolled back in several municipalities (e.g. Aarhus review)Banned or suspended in e.g. Helsingør (2022) — named directly in the ruling
Sub-processors fixedFull list in the DPA — 30-day notice before changesHundreds of sub-processors globallyLarge sub-processor footprintSame footprint as Workspace + no local admin control in free tier
NIS2 supply-chain riskLow — EU-owned, EU hosting, EU support, incident logs in EU jurisdictionHigh — CLOUD Act + US parent makes the supply chain hard to risk-assessHigh — CLOUD Act + US parent, same supply-chain exposureVery high — consumer terms, no vendor agreement on the free tier

Comparison based on publicly available product and contract documentation as of 2026 and supervisory authority decisions. Always verify the current contract text.

Technical guarantees

AES-256 at rest

Storage buckets and database encrypted with AES-256.

TLS 1.3 in transit

All traffic is end-to-end encrypted with modern ciphers.

Row-Level Security

Postgres access control ensures each role only sees its own rows.

Granular audit log

Every access to a sensitive scope is logged — DPO-review ready.

Pseudonymisation before AI

Pupil names are replaced with “Pupil A”, “Pupil B” before the prompt is sent.

Danish-owned, Danish-operated

SkoleElev ApS, registered in Denmark, support team based in Copenhagen.

Documents for DPO and tenders

Everything a public tender asks for — ready from day one

Data Processing Agreement (DPA)
Template aligned with the Danish DPA's standard contract.
Sub-processor list
Living list — 30-day notice before changes.
DPIA
Impact-assessment template — pre-filled for core flows.
ROPA
Records of processing activities (Art. 30).
Breach procedure (72 hours)
Procedure and contact paths for reporting to the supervisory authority.
Erasure protocol
What is deleted when — including backup rotation.

Questions school leaders and DPOs ask

What about Schrems II?+

Schrems II concerns data transfer to third countries. We transfer no data outside the EU — for hosting, AI or email. Schrems II is therefore not relevant for our platform, and you avoid both TIA and supplementary measures.

Are you exposed to the US CLOUD Act?+

No. SkoleElev ApS is Danish-owned and uses only EU legal entities at our sub-processors. US authorities cannot demand access via the CLOUD Act because we are not subject to US jurisdiction.

What happens to pupil data on school transfer?+

The school can export the pupil as a transfer bundle (ZIP with profile, learning history, VARK, grades). The old school's copy is anonymised after 30 days. Backups rotate out after 35 days.

How are SSO and MFA handled?+

MFA is supported for staff and parents via standard providers. For pupils we support OIDC SSO. No credentials are stored on our side.

Where does the supervisory authority find your documentation?+

We maintain DPA, DPIA, ROPA and sub-processor list in a customer portal. The DPO can access them directly without raising an information request — often a requirement in public tenders.

Get the DPA, DPIA and sub-processor list sent today

30 minutes with our DPO — we walk through where your data sits, what you sign, and how to document it to your own DPO and parent board.

See the practical EU alternative