# European providers only: the rule and its reasons

> Which rule applies to the providers behind the privymail.eu mail service, which services it excludes, what it costs and where it ends.

## "European" can mean five things

A mail service calls itself European. That can mean: the data is stored in Europe. Or: the servers belong to a European company. Or: the people with access work in Europe. Or: the software runs on the service's own servers instead of at a bought-in service. Or: payment, support and monitoring also come from European providers. Those are five different statements, and a service can meet the first and none of the others.

For the privymail.eu mail service, a rule applies that demands all five. This post explains what it excludes, what it costs and where it ends.

## The rule demands all five

1. **Data.** Customer data is stored exclusively in the EU.
2. **Infrastructure.** Servers, storage, backups and DNS are with verified providers from the EU.
3. **Operations.** The company and the people with access to production systems are based in the EU.
4. **Software.** The data path runs open-source software that privymail.eu operates itself, and its own code.
5. **Supply chain.** Services for operations, support and payment come from Europe. Exceptions are disclosed.

Two considerations lie behind this. Who can demand that data be handed over depends not only on where a server stands, but also on which law governs the company that operates or owns it. And every bought-in service is one more company that sees data. What a company does not hold, it can neither lose nor hand over.

The rule is not a verdict on any country, nor on the quality of the services it excludes. Many of them are mature and more convenient than what has to be operated in-house in their place. The rule does not exclude software of foreign origin: what matters is who operates a program and where it sends data, not where it was written.

## Which services drop out, and what takes their place

| Type of service | Instead |
|---|---|
| Data centres of providers outside the EU | servers with verified providers from the EU |
| Sending services for email | the service's own mail servers |
| CAPTCHA services | a self-hosted computational puzzle that your browser solves |
| SMS services for sign-in | passkeys and one-time codes, no SMS |
| Monitoring as a cloud service | self-hosted monitoring |
| Payment services outside Europe | SEPA direct debit and bank transfer through European payment providers |
| Delivery networks, analytics and font services for the website | a single server delivers the website, without analytics and with its own fonts |

## Eight questions for every provider

"Verified" has a fixed meaning here. A provider of servers, storage, backups or DNS is measured against eight questions:

1. Where is the company based?
2. Who owns it, and is its parent company controlled from the EU?
3. Does it have subsidiaries in third countries?
4. Which data locations does the contract guarantee?
5. Which subprocessors does it use?
6. Which certifications does it back with an attestation and not just a marketing claim?
7. Does it have technical access to the stored data?
8. Can it be left again, because nothing depends on a service that only it offers?

Two questions decide the matter alone, the second and the seventh: if a provider is not controlled from the EU, or if it could read stored data, it is ruled out. The check is due again every year, and the check of ownership every quarter, because a company can be sold.

## What can be verified

What can be verified is what has been published, and that is the state of this website. It is operated by patchletter UG (haftungsbeschränkt) in Gelsenkirchen, Germany. The website loads fonts, images and styles from its own server, contains no JavaScript and embeds no third-party resources. A signed manifest describes its server and the software in use, with a capture time. It covers only the website and its server.

## What the rule costs

Whatever is not bought in for the mail service, privymail.eu has to operate itself. Without a sending service, delivery is in-house work: making sure mail arrives and does not end up in the spam folder. Without rented monitoring, the same goes for running the monitoring. That takes time a bought-in service would save.

Selection takes longer too. No provider is selected before locations, ownership, subprocessors and contract terms have been reviewed. And the rule binds for good: if a provider changes owner, a move has to be possible. That is why the eighth question is on the list.

## Where the rule ends

- **Hardware.** The rule applies to services and those who operate them. Where a processor or a hard disk was built is outside it.
- **Certificates.** Which certificate authorities your browser trusts is decided by its vendor and your operating system, not by whoever runs a website.
- **Development.** The rule applies to everything that touches customer data. Libraries and development tools also come from package registries and code platforms outside the EU. What flows there is code and details about dependencies, not customer data.
- **The other side.** If you write to an address with a provider outside the EU, your mail is afterwards stored there too.
- **European law.** The rule does not protect against requests from European authorities. A separate principle applies to them: every request is reviewed legally, and the people affected are notified where that is permitted.

## Further reading

The five layers are shown under [Europe](https://privymail.eu/en/europe.md), the website's signed manifest under [Transparency](https://privymail.eu/en/transparency.md), the aims behind them under [About](https://privymail.eu/en/about.md). The building blocks of the service and their order are listed in the [roadmap](https://privymail.eu/en/roadmap.md). How the manifest is produced and what it does not prove is covered in [This website can be verified](https://privymail.eu/en/blog/verifiable-website.md). Two rows of the table have posts of their own: [why there are no codes by SMS](https://privymail.eu/en/blog/no-sms.md) and [how the computational puzzle manages without a third-party service](https://privymail.eu/en/blog/captcha-without-tracking.md).

---

- privymail.eu: patchletter UG (haftungsbeschränkt) · Germany
- This page as HTML: https://privymail.eu/en/blog/european-suppliers-only/
- Deutsche Fassung: https://privymail.eu/blog/european-suppliers-only.md
