100% EU-hosted. 100% GDPR-aligned.
The whole platform — code, database, files, AI and emails — runs at Hetzner in Falkenstein/Nuremberg (DE), backup in Helsinki (FI) — managed via Elestio (IE). No pupil data crosses the Atlantic. That is what makes us the realistic EU alternative to Microsoft 365 and Google Workspace for schools and local authorities.
The data journey — and where it doesn't go
No US hops. Every step is documented in our DPA.
What we don't do: We do not send pupil data to the US. We do not use Azure us-east, AWS us-east or GCP us-central. We do not use US email infrastructure. We do not use Cloudflare nodes outside the EU.
Sub-processors — all in the EU
We give 30 days' notice before changes. The list is part of your DPA.
| Provider | Role | Location | Legal basis |
|---|---|---|---|
| Hetzner Online GmbH | App and file hosting + encrypted S3 backup | fsn1 Falkenstein (DE) · nbg1 Nuremberg (DE) · hel1 Helsinki (FI, backup) | Art. 28-databehandleraftale (EU/EØS) |
| Elestio | Managed infrastructure operations | Ireland (EU) | Art. 28-databehandleraftale (EU/EØS) |
| Supabase | Database, auth, edge functions | eu-central-1 (Frankfurt, DE) | Art. 28-databehandleraftale (EU/EØS) |
| Cloudflare | CDN and DDoS protection (EU-only routing) | EU edge (Frankfurt, Amsterdam, Copenhagen) | Art. 28-databehandleraftale (EU/EØS) |
| OpenAI | AI text on pseudonymised data | EU data residency (Frankfurt) + Zero Data Retention | Art. 28-databehandleraftale (EU/EØS) + Zero Data Retention |
| Google (Gemini) | AI text and image generation on pseudonymised teacher prompts | EU data residency (Google Cloud europe-west4, NL) | Art. 28-databehandleraftale (EU/EØS) |
| Resend | Transactional email | EU (Frankfurt) | Art. 28-databehandleraftale (EU/EØS) |
GDPR rights — operationalised in the platform
Not just a policy. Every right has a concrete action in the app.
NIS2 turns vendor choice into a board-level responsibility
The NIS2 directive (EU 2022/2555, transposed in Denmark via the NIS2 Act adopted Dec 2024 / entering into force in 2025) expands requirements on risk management, supply-chain security and incident reporting. Schools themselves are usually out of scope — but their councils and operators are in scope, and the requirements flow downstream into procurement and contracts.
“GDPR is about personal data. NIS2 is about the entire supply chain. Both point the same way: away from US-controlled cloud services for critical public operations.”
Us vs. Microsoft 365 vs. Google Workspace vs. Google Classroom
Cut for school leaders and DPOs who need to answer the board tomorrow.
| Area | Us | Microsoft 365 | Google Workspace | Google Classroom (free) |
|---|---|---|---|---|
| Data location | EU (NL + DE), never US | Global — EU Data Boundary with exceptions | Global — Workspace stores in EU, but metadata flows to US | Global — no data location guarantee in the free tier |
| CLOUD Act exposure | No — Danish-owned and using EU legal entities | Yes — US parent company | Yes — US parent company | Yes — same US parent (Alphabet) |
| Schrems II | No third-country transfer — Schrems II not relevant | Requires TIA + supplementary measures | Requires TIA + supplementary measures | Requires TIA — Danish DPA advised against use without risk assessment |
| DPA bundled with contract | Yes — signed alongside the subscription | Separate agreement, demanding wording | Separate agreement | School self-accepts the DPA online — flagged by the Danish DPA |
| AI training on pupil data | No — ZDR + pseudonymisation | Copilot is not trained, but telemetry is collected. Opt-out is complex | Gemini for Education is not trained, but opt-out for other services is complex | Fundamentals covers core — 'Additional services' (YouTube, etc.) run on consumer terms per pupil |
| Danish DPA precedent | Built to align with the Danish DPA's 2022 and 2024 guidance | Use rolled back in several Danish municipalities (e.g. Helsingør, 2022) | Use rolled back in several municipalities (e.g. Aarhus review) | Banned or suspended in e.g. Helsingør (2022) — named directly in the ruling |
| Sub-processors fixed | Full list in the DPA — 30-day notice before changes | Hundreds of sub-processors globally | Large sub-processor footprint | Same footprint as Workspace + no local admin control in free tier |
| NIS2 supply-chain risk | Low — EU-owned, EU hosting, EU support, incident logs in EU jurisdiction | High — CLOUD Act + US parent makes the supply chain hard to risk-assess | High — CLOUD Act + US parent, same supply-chain exposure | Very high — consumer terms, no vendor agreement on the free tier |
Comparison based on publicly available product and contract documentation as of 2026 and supervisory authority decisions. Always verify the current contract text.
Technical guarantees
AES-256 at rest
Storage buckets and database encrypted with AES-256.
TLS 1.3 in transit
All traffic is end-to-end encrypted with modern ciphers.
Row-Level Security
Postgres access control ensures each role only sees its own rows.
Granular audit log
Every access to a sensitive scope is logged — DPO-review ready.
Pseudonymisation before AI
Pupil names are replaced with “Pupil A”, “Pupil B” before the prompt is sent.
Danish-owned, Danish-operated
SkoleElev ApS, registered in Denmark, support team based in Copenhagen.
Everything a public tender asks for — ready from day one
Questions school leaders and DPOs ask
What about Schrems II?+
Schrems II concerns data transfer to third countries. We transfer no data outside the EU — for hosting, AI or email. Schrems II is therefore not relevant for our platform, and you avoid both TIA and supplementary measures.
Are you exposed to the US CLOUD Act?+
No. SkoleElev ApS is Danish-owned and uses only EU legal entities at our sub-processors. US authorities cannot demand access via the CLOUD Act because we are not subject to US jurisdiction.
What happens to pupil data on school transfer?+
The school can export the pupil as a transfer bundle (ZIP with profile, learning history, VARK, grades). The old school's copy is anonymised after 30 days. Backups rotate out after 35 days.
How are SSO and MFA handled?+
MFA is supported for staff and parents via standard providers. For pupils we support OIDC SSO. No credentials are stored on our side.
Where does the supervisory authority find your documentation?+
We maintain DPA, DPIA, ROPA and sub-processor list in a customer portal. The DPO can access them directly without raising an information request — often a requirement in public tenders.
Get the DPA, DPIA and sub-processor list sent today
30 minutes with our DPO — we walk through where your data sits, what you sign, and how to document it to your own DPO and parent board.

