GDPR & Data Sovereignty

100% EU-hosted, 100% GDPR-compliant, 0% US cloud

After Schrems II, using American cloud platforms is legally uncertain for European businesses. Canvos eliminates that risk entirely.

100% EU-hosted
100% GDPR-compliant
0% US cloud
89.5% sovereignty score

Why US cloud is a risk
for European businesses

The Schrems II ruling by the European Court of Justice has fundamental consequences for every organisation using US cloud.

Privacy Shield invalidated

The Court ruled in 2020 that the EU-US Privacy Shield provides insufficient protection. Data transfers to the US have been legally uncertain since.

CLOUD Act

The US can compel American companies to hand over data, even when stored in the EU. This applies to Microsoft, Google, Amazon and all US providers.

FISA Section 702

US intelligence agencies may request data of non-American persons from US cloud providers without a court order.

Fine risk

The GDPR provides for fines up to 4% of annual turnover or €20 million. European supervisory authorities are increasingly enforcing on international data transfers.

From storage to deletion —
GDPR at every level

Canvos is designed with GDPR as its foundation, not an afterthought.

📍

Data location

All data is stored in Datacenter United, Ghent, Belgium. Data never leaves the EU. No replication to non-EU locations.

⚙️

Processing

All processing takes place on European servers. AI inference locally via Ollama. No data sent to external cloud APIs.

⏱️

Retention

Retention policies configurable per organisation. Automatic deletion after retention period. GDPR right to erasure built in.

🗑️

Deletion

Full account and data deletion on request. Automatic trash cleanup. Export capability for data portability.

What your Data Protection Officer
needs to know

Share this checklist with your DPO. Every point is verifiable.

Data Processing Agreement available

Canvos offers a standard DPA in accordance with Article 28 GDPR, signed by a Belgian legal entity.

No international data transfers

All data stays in Belgium. No sub-processors outside the EU. No CLOUD Act exposure.

Technical security measures

36+ hardening measures, encryption at rest & in transit, rate limiting, CORS, CSP headers, input validation.

Organisational measures

Data classification (4 levels), DLP rules, sharing policies, email policies, retention policies — all configurable and enforceable.

Audit trail & compliance reporting

Structured logging on 130+ routes. Export in JSON, CSV or CEF. Monthly compliance reports per organisation.

Right to erasure guaranteed

Full account and data deletion on request. Retention policy with automatic cleanup built in.

Data portability

Export all your data in standard formats. No vendor lock-in, no proprietary formats.

Security at every layer

From network to application — Canvos implements security at every level.

Encryption

TLS 1.3 in transit, AES-256 at rest. All communication between components encrypted. Email with mandatory TLS enforcement.

Access control

Role-based access, per-organisation isolation, SSO built in. No shared credentials, no cross-tenant data access.

Audit logging

Structured logging on 130+ routes. Who, what, when, result. Tamper-evident, exportable in 3 formats.

Application security

Rate limiting, CORS, CSP headers, input validation, SQL injection prevention, XSS protection. 36+ measures active by default.

GDPR-compliant working starts with the right choice

Request a demo and discuss your GDPR requirements with our team. We will show you how Canvos simplifies your compliance.

Request a demo Order now