Quick answer: If your project handles personal data of EU residents, GDPR applies to YOU as the controller; Cloud2Y acts as the infrastructure provider. You choose where data physically resides — the Amsterdam location keeps it inside the EU, while Kyiv, Lviv and Singapore sit outside. For DPA paperwork and current compliance specifics, ask via support ticket; the authoritative terms are contractual.
Overview
GDPR compliance is a stack: the law regulates the data controller (you), who chooses processors and infrastructure (hosting) appropriate to the data. Hosting location is one input among many — encryption, access control, breach procedures and your own privacy policy matter just as much. This article maps the hosting-related part of that stack.
Before you start
- Classify your data: does your project store EU residents' personal data at all?
- Decide your residency stance: EU-only storage points you to the Amsterdam location.
- Remember GDPR is about processes, not just place — document who accesses what and how incidents are handled.
Step-by-step guide
Hosting-side GDPR checklist:
- Choose the server location matching your residency requirements at order time (moving later is a manual migration).
- Request the processor-side paperwork you need (DPA / processing terms) via ticket — get the current documents rather than relying on summaries.
- Encrypt personal data at rest and in transit; restrict admin access with keys and 2FA.
- Implement your controller duties on the server: retention limits, deletion workflows, breach detection and logging.
- Cover your own users with an accurate privacy policy naming your infrastructure setup.
Common issues
- "EU hosting = GDPR compliant": location alone does not make you compliant — your processes complete the picture.
- Non-EU locations with EU users: possible under GDPR transfer mechanisms, but that is a legal-design question for your counsel.
- Backups forgotten: offsite backups also contain personal data — apply the same residency and encryption logic to them.
When to contact support
Ask via ticket for the current DPA/processing documentation, questions about physical data location, or infrastructure details your compliance audit needs. Legal interpretation of GDPR for your product belongs with your lawyer.
Frequently asked questions
Which Cloud2Y location keeps my data inside the EU?
Amsterdam. Kyiv and Lviv are in Ukraine and Singapore is in Asia-Pacific, so projects with strict EU residency requirements should select the Amsterdam location at order time.
Does hosting in the EU make my project GDPR compliant?
No. Location is one input; compliance also needs your own processes - lawful basis, retention, deletion workflows, breach handling and a privacy policy covering your users.
How do I get a DPA or processing terms from Cloud2Y?
Request the current documents via a support ticket. Always rely on the paperwork issued to you rather than summaries, since compliance documents evolve over time.
Related articles
Need a hand? Contact Cloud2Y support →
