Inside our EU hosting: where your data actually lives
“Hosted in Europe” appears on a lot of websites. It can mean anything from “our servers are physically in Frankfurt, operated by a US corporation” to what we mean by it. So instead of a badge, here’s the actual tour: where your 5DAYS data lives, who touches it, and how it’s protected.
The infrastructure
5DAYS runs entirely on European cloud providers — companies incorporated in Europe, operating datacenters in Europe, answerable to European courts. That last part is the point: infrastructure jurisdiction follows the operator. A datacenter in the EU run by a company subject to the US CLOUD Act doesn’t keep your data under European law. Ours does.
Concretely:
- Application and databases run in datacenters in France and Belgium, operated by European providers.
- Backups are encrypted and replicated across two geographically separate EU locations.
- Spark AI inference runs on Mistral, hosted in Europe. Prompts and retrieved context never leave EU infrastructure.
- Transcription of your meetings happens on the same European stack — recordings are not shipped to third-country APIs.
Encryption, keys, and access
Data is encrypted in transit (TLS 1.3) and at rest (AES-256). More interesting than the algorithms is who can decrypt:
- Access to production is restricted to a small set of named engineers, with hardware-key MFA and audited sessions.
- Support staff see your workspace only if you explicitly grant a time-boxed access — and you see the grant in your audit log.
- There is no “god mode” dashboard that browses customer content. We built the internal tools that way on purpose; the inconvenient design is the guarantee.
Subprocessors: the short list
Every company that processes your data on our behalf is listed in our data-processing agreement. The list is short enough to reproduce here in spirit: European hosting providers, Mistral for AI inference, a European email-delivery service for notifications. All EU-incorporated, all under GDPR, all bound by data-processing agreements that mirror ours.
When we evaluate a new vendor, jurisdiction is the first filter, before features and before price. Several tools we’d have liked to use didn’t pass. That’s the cost of the promise, and we pay it rather than footnote it.
A sovereignty claim is only as strong as the least European link in the chain.
What this means for your compliance
If you’re the person who fills in vendor-assessment questionnaires, the practical upshot:
- Data residency: EU only, including backups, AI processing, and transcription.
- Legal basis: GDPR applies natively — no adequacy gymnastics, no transfer-impact assessments for the core service.
- Auditability: DPA, subprocessor list, and security documentation are available from your workspace settings — no sales call required.
We’ll keep this post updated as the infrastructure evolves. When something changes — a new provider, a new region — the subprocessor list changes first and this post follows. That order matters: paperwork before marketing.
Questions about any of it? Ask us the hard version — hello@5days.com reaches people who actually operate this stack.