Skip to content

EU Hosted · 100% Open Source

EU Data Sovereignty

EU infrastructure. Open-source stack. EU-sovereign by design. Your data stays in the EU.

Why sovereignty matters

Where your data lives determines which laws govern it. When your IoT platform runs on infrastructure we operate inside the EU, your data stays under European law and GDPR, with a clear line of accountability you can document.

For operators of essential services, that clarity is valuable. EU data residency gives you a stable legal basis for your telemetry: data stays within the EU, and you always know which jurisdiction applies.

Nordic IoT is built for this. We operate on European infrastructure with European software, governed by EU law. You keep control of your data and the right to audit every layer of the stack.

Our infrastructure

Hosting: Hetzner (Germany & Finland)

All servers run on Hetzner infrastructure located in Germany and Finland. Hetzner Online GmbH is a German company subject to EU data protection law. Data is replicated and processed within the EU.

Software: 100% open source

Our entire software stack is open source: Linux operating system, PostgreSQL database, and custom application code. There are no proprietary black boxes, no vendor lock-in, and no hidden data collection. You can audit the entire stack.

EU infrastructure end to end

Our platform runs on infrastructure we operate within the EU. Content delivery, fonts, and analytics are all served from EU infrastructure, with self-hosted fonts and cookie-free analytics. Even this website is served this way.

Nordic IoT gives you genuine EU data residency with no asterisks.

IoT device connectivity

Device connectivity uses Telenor Connexion IoT SIM cards. Telenor is a Norwegian company. Data from devices travels through European mobile networks to European servers. Private APN options are available for additional network isolation.

Device-level encryption

Every Nordic IoT gateway uses LUKS full-disk encryption (AES-256). All data stored on the device is encrypted at rest. If a device is physically stolen or decommissioned, storage contents are unreadable without the encryption key.

What this means for you

  • Clear jurisdiction: your data stays under EU law, on infrastructure we operate, so accountability is simple to document
  • EU jurisdiction: your data is subject to GDPR and national EU/EEA laws
  • Full auditability: open-source stack means you can verify exactly what software runs on your infrastructure
  • No vendor lock-in: standard protocols (Modbus, MQTT, REST) and open formats throughout
  • Simplified NIS2 readiness: EU infrastructure with documented supply chain simplifies your compliance documentation
  • GDPR-aligned by design: data residency in the EU keeps your compliance basis simple

Want to discuss data sovereignty?

We can provide detailed documentation of our infrastructure, data flows, and supply chain for your compliance records.