# Data sovereignty and GDPR

> OVHcloud hosting in France, a single sub-processor outside the strict European perimeter, a downloadable DPA and configurable retention.
> https://facteur.eu/en/sovereignty

## Knowing where your data is should not take an investigation

We validate electronic signature journeys: we know what it is to justify every link in the chain to an auditor, and to discover that a supplier replicates your data on a continent nobody signed off. This page exists so you do not have to write to us to get it.

### Your messages never leave France

Compute, database and object storage are at OVHcloud, in Roubaix and Gravelines. No replication outside the territory, no American service in the path of a message.

### One sub-processor outside the strict European perimeter

Stripe, to take payment. It never sees the content of a message: only your billing identity. We say so rather than hiding it behind a story of total sovereignty.

### The DPA is downloaded, not negotiated

The data processing agreement is available online, signed, without going through a salesperson or waiting for a procurement cycle. The annexes list the sub-processors and the technical measures.

### Encryption at rest and in transit

TLS required on the API, STARTTLS on inbound SMTP, encrypted volumes and object storage. API keys are stored hashed, never in clear.

### Retention you choose short

Three days by default, up to 90 depending on the plan, and a performance mode that stores nothing at all. The best protection for test data remains not keeping it.

### Deletion on request, without friction

Purge an inbox, an organisation or a whole account from the app, effective immediately, backups included within 30 days.

## The full list, kept up to date

Every addition is announced to account administrators thirty days in advance.

- Sub-processor
- Role
- Location
- Data concerned
- Transfer outside the EU

## The limits, stated plainly

A sovereignty story with no caveats is a sales pitch. Here are ours.

- We are not SecNumCloud qualified and will not be tomorrow. If your requirements demand it, tell us, but do not take our word for it.
- We are not ISO 27001 certified at this stage. Our technical measures are documented in the DPA annexes, and auditable on request.
- Our terms ask you not to send real personal data into test inboxes. We know it happens anyway: that is why default retention is three days and why encryption at rest is not optional.
