Skip to content

EU Data Sovereignty

Sovereign by design.

Hosted in the Netherlands. Powered by Mistral and local models. Beyond the reach of the US CLOUD Act and any foreign authority, because compliance alone was never enough.

No foreign accessMistral & local modelsGDPR · NIS2 · EU AI Act

Hosted in the EU, and only the EU

Our infrastructure stays inside the Union, on European providers. No US clouds means no US company in the path, and no foreign authority it could answer to.

An EU-only model stack

We build on Mistral and local, open-weight models. Your data is never sent to US AI providers, and never used to train someone else’s model.

Out of reach of foreign authorities

Because no US company sits between you and your data, there is no CLOUD Act warrant or FISA order that can compel its disclosure. Your data answers to you, and to European law alone.

Compliance, and then some

GDPR, NIS2 and the EU AI Act are built in. But compliance is only the floor: a US provider can be bound by the GDPR and still be compelled under US law. We remove that conflict at the root.

Why it matters

Compliance is the floor, not the ceiling.

Where your data sits is not the same as who can reach it. Data held in a European data centre is not truly European if a US company operates it: under the US CLOUD Act, a US-headquartered provider can be compelled to hand over data wherever in the world it is stored, and FISA 702 permits surveillance with no notice and no realistic way to object. The “sovereign cloud” labels offered by US firms do not change those obligations.

This is why compliance alone is not protection. A US provider serving European customers is bound by the GDPR and, at the same time, compellable under US law, a conflict it cannot contract away. The largest providers have acknowledged, under oath, that they cannot guarantee European data will never be handed to US authorities.

We remove the exposure at its source. Because infrastructure, models and data stay with European parties only, there is no foreign company in the path and no foreign law that reaches it. That is what “sovereign by design” means, not a promise added at the end, but a property of how the system is built.

The CLOUD Act, precisely

Why a US provider can always be compelled, wherever your data sits.

This is not a worst-case scenario or a talking point. It is how US law is written. Here is exactly what it says, and why a contract cannot switch it off.

01

It is US law, and explicit about location.

The CLOUD Act (2018) added 18 U.S.C. § 2713 to the Stored Communications Act. It requires a provider to disclose data in its “possession, custody, or control”, and, in the statute’s own words, “regardless of whether” that data “is located within or outside of the United States.” Where the server stands is, by design, irrelevant.

02

It follows the company, not the building.

The duty binds any provider subject to US jurisdiction: companies incorporated in the US, and foreign companies with meaningful US operations (“minimum contacts”). An EU data centre run by such a company is still within reach.

03

“Control” means being able to get the data, not holding it.

US courts read “possession, custody, or control” broadly: it is enough that a company has the practical ability or legal right to obtain the data. A US parent that can instruct its European subsidiary to hand data over is treated as controlling it, even if the data never physically leaves Europe.

04

A contract cannot override a statute.

Data-residency clauses, standard contractual clauses, “EU data boundary” and “sovereign cloud” programmes are private agreements. They limit which staff touch data day to day; they do not remove the legal duty to obey a valid US order. The EU’s own regulators (EDPB and EDPS) found such contracts have no force against US judicial or administrative demands.

05

For EU data, there is no escape hatch.

A provider may ask a US court to quash an order only when it would break the law of a country that has signed a CLOUD Act “executive agreement” with the US. The EU has none. So an EU customer gets neither that protection nor any notice, and the provider is left choosing between a US order and the GDPR.

06

Surveillance law reaches further still.

Separately from law enforcement, FISA Section 702 and Executive Order 12333 let US intelligence compel data from US providers, typically under a gag order, with no notice to the customer. These are the powers that led the EU Court to strike down the Privacy Shield in Schrems II.

“No, I cannot guarantee that.”
Microsoft France’s Director of Public and Legal Affairs, under oath before the French Senate (10 June 2025), asked whether he could guarantee that French citizens’ data would never be passed to US authorities.

The legal power to compel your data exists, applies wherever it sits, and cannot be contracted away. It disappears only when no US-jurisdiction company is anywhere in the path, which is exactly how Vivaldi is built.

A US-jurisdiction provider, and Vivaldi.

A US-jurisdiction providerVivaldi
Who can compel your dataUS authorities (CLOUD Act, FISA 702, EO 12333)Only a European court, under European law
Does an EU data centre helpNo, the duty follows the company, not the serverYes, and no US company sits in the path
Can a contract stop itNo, a statute overrides private agreementsNothing to override, no foreign law applies
Will you be notifiedOften not, orders can carry a gag orderYes, access only through a process you can see
Which law governs your dataUS and EU law, in conflictEU law alone (GDPR, NIS2, EU AI Act)

Questions, answered

The questions buyers actually ask.

Are EU and open models really as good as OpenAI or Anthropic?

For the work these products do, yes. Mistral’s models are competitive for retrieval, extraction, classification and reasoning over your own data, and because every answer is grounded in your sources, accuracy comes from the retrieval and guardrails as much as the raw model. Where a task genuinely needs a different model, the stack is model-agnostic, within the EU.

Where exactly does our data run?

On Vivaldi’s sovereign cloud in the Netherlands and Germany, or entirely inside your own infrastructure. In the on-premise option the only external dependency is your own Mistral account, or a fully local model. Nothing is processed outside the EU.

Is our data used to train models?

No. Your data is never used to train our models or anyone else’s, and it is never sent to a US provider.

How long does it take to get started?

A scoped pilot is usually a matter of weeks, not months, because we connect to your existing sources instead of asking you to migrate. We start with one focused use case and expand from there.

What happens if we want to leave?

You can. We build on open-weight models and your own systems, so there is no lock-in to proprietary weights or a US platform. Your data and your sources stay yours throughout.

How does this fit GDPR, NIS2 and the EU AI Act?

Compliance is designed in: EU hosting, EU models, full data residency, auditability and documentation aligned to the frameworks. Our consulting team works to these standards every day.

Sovereignty you can verify.

We’ll show you exactly where your data lives, who can and cannot reach it, and which models run.