- Solutions
- EU sovereign AI platform

EU-sovereign AI platform.
The AI chain, entirely in Europe.
US AI platforms promise an 'EU region', but the processing runs at US corporations with Cloud Act exposure. What matters is which company actually processes your data, not which region a data centre sits in.
Get startedIn short
Regulatory requirements for AI processing in the EU are growing rapidly. Schrems II ruling 2020 + DPF (Adequacy Decision July 2023, confirmed by General Court September 2025) + Schrems-III action pending, third-country transfer requirements remain politically volatile. EU AI Regulation 2024/1689 will be sharply enforced from 02 August 2026 with Article 50 (transparency obligation). In parallel comes the data sovereignty discourse: 'EU region' at US cloud providers doesn't solve Cloud Act risk, the parent corporations are US subjects, jurisdiction follows US law. Real EU sovereign AI means: EU company as provider, EU hosting infrastructure, LLM processing in the EU, full GDPR Art. 28 DPA with transparent subprocessor list. At rinqo the entire AI chain runs in Europe: Hetzner Falkenstein and Nuremberg, language models at European providers, speech recognition in France, speech synthesis from a German provider. That is not a retrofitted setup but the architecture default.
With rinqo, DACH SMBs get an EU-sovereign platform for AI agents: Hetzner Falkenstein/Nuremberg + AI models with contractually guaranteed EU data processing, AI Act Art. 50 by default, automatic DPA, industry templates for DACH SMEs.
Contents
- What 'EU sovereign' really means
- Schrems II + GDPR Art. 28, the legal reality 2026
- AI Act Art. 50, transparency obligation from 02 August 2026
- rinqo's full EU stack in detail
- When EU sovereign is mandatory, and when not
- Digital sovereignty: why server location became a board-level issue
- Local AI vs the European cloud: the realistic choice for SMEs
- Frequently asked questions
Why rinqo?
EU hosting on Hetzner Germany
Falkenstein and Nuremberg, German company, German DPA per Art. 28 GDPR. Processing within the EU.
LLM processing entirely in the EU
Primary LLM with contractually guaranteed EU data processing, optional failover to a purely European fallback provider (opt-in). Complete processing in the EU.
GDPR-native, processing in the EU
No personal data leaves the EU. Not for model training, not for logging, not for telemetry.
AI Act Art. 50 by default
AI disclosure default-active in phone, chat and email. Compliance is architecture default, not configuration effort.
DPA automatic at contract signing
Full DPA per GDPR Art. 28, without negotiation effort. With US providers typically only via sales contact.
Transparent stack
All components (hosting, LLM, voice engine, vector DB, queue) are documented with provider, region, DPA status. Full sovereignty auditability.
Before. After.
US AI platforms with 'EU region': US corporation as parent, Cloud Act exposure, DPA with third-country clauses, AI Act implementation with the buyer.
rinqo: Hetzner DE + AI models with contractually guaranteed EU data processing, DPA with transparent subprocessor list on /security (US parent companies openly disclosed), AI Act default, full EU data residency for all voice/chat/email streams with full auditability.
What 'EU sovereign' really means
EU sovereign AI is more than 'EU region' at US cloud providers. Real EU sovereignty requires four layers: first EU company as provider (legal entity under EU law, not US subsidiary); second EU hosting infrastructure (servers in EU member state, not US cloud region); third LLM processing in the EU (inference on EU servers, contractually guaranteed, no training on customer data); fourth a full DPA per GDPR Art. 28 with a transparent subprocessor list. With US hyperscalers point one is already problematic, parent corporations are US subjects, jurisdiction follows US law (Schrems II). 'EU region' just shifts the server location, not legal sovereignty.
Schrems II + GDPR Art. 28, the legal reality 2026
The Schrems II ruling of the European Court of Justice 2020 classified US third-country transfers of personal data as fundamentally problematic. EDPB clarifications 2024 tightened: additional safeguards (TIA, encryption, sub-processor audits) are mandatory, US cloud providers with US parent must be individually justified. For practices, law firms, banks and all SMBs with personal data in AI workflows this becomes the regulatory breaking point from 2026. EU-sovereign stack avoids the problem from the start, no third-country transfers, no TIA declaration, no US cloud audit needed.
AI Act Art. 50, transparency obligation from 02 August 2026
Article 50 of the EU AI Regulation 2024/1689 obliges providers from 02 August 2026 to disclose AI interactions with end customers. Concretely: AI calls must be marked as AI in opening sentence, AI chats need visible disclosure banner, AI emails standard note. Violations can incur fines up to €15 million or 3% of global annual turnover. With US providers compliance implementation sits with the buyer, they must build the disclosure note into every workflow. rinqo does this automatically in all channels.
rinqo's full EU stack in detail
Hosting: Hetzner Online GmbH, Falkenstein and Nuremberg, German DPA per GDPR Art. 28. App + API + database + vector database + queue + voice service all on Hetzner hardware. Voice pipeline: self-operated on Hetzner hardware, telephony via EU data centres (Dublin and Frankfurt). LLM: AI models with contractually guaranteed EU data processing (no training on customer data), a purely European fallback provider as an opt-in failover (sub-processor only once the option is activated). STT: speech recognition in an EU setup with a DPA; speech recognition on our own servers in Germany as an expansion stage. TTS: a German speech synthesis provider, hosted in the EU, connected via API. The complete subprocessor list is documented on /security.
When EU sovereign is mandatory, and when not
Mandatory: practices with patient data, law firms with client conversations, banks/insurance with financial data, all industries with professional secrecy (tax consulting, notary, healing professions), public administration. Strongly recommended: all DACH SMBs with employee data in AI workflows. Optional: purely product-related applications without personal data (e.g. anonymous FAQ bots on marketing pages). Anyone not clearly serving this filter risks objections from data protection authorities and fines under EU AI Act and GDPR.
Digital sovereignty: why server location became a board-level issue
Digital sovereignty means you control who can access your company data, and under which jurisdiction. For years this sat with the IT department. The US CLOUD Act moved it to the boardroom: US authorities can compel US providers to hand over data, regardless of where the servers are located. A data centre in Frankfurt offers no protection if your contracting party is a US corporation. That is why server location is now decided by management, not just by IT. In practice, digital sovereignty comes down to three criteria. First, EU servers: your data is processed and stored on servers within the EU. Second, an EU contracting party: your DPA counterpart is subject to European law, not the CLOUD Act. Third, exit capability: you can export your data and switch providers without bringing your business to a standstill. If any one of the three is missing, your sovereignty has a gap, no matter how the marketing sounds. For AI systems this weighs twice as heavily, because phone calls, chats and emails containing customer data run through the system. So ask every provider about exactly these three points. At rinqo, the answers look like this: hosting with Hetzner in Falkenstein and Nuremberg (ISO 27001:2022), a DPA under Art. 28 GDPR, language-model processing contractually guaranteed within the EU. Your data is not used for model training. The entire stack is documented, every component listed with its provider and region.
- EU servers: processing and storage on servers within the EU
- EU contracting party: your DPA counterpart is subject to European law, not the CLOUD Act
- Exit capability: exportable data, provider switch without operational standstill
Local AI vs the European cloud: the realistic choice for SMEs
For most SMEs, the European cloud is the practical route to GDPR-compliant AI. Local AI, meaning your own language models on your own hardware, is the maximum form of control: no data leaves the building, no external contracting party, no third-country question. Honestly assessed, that control comes at a price. Capable language models need GPU servers, and you carry the purchase and electricity costs yourself. Add operations, monitoring, model updates, security patches and the staff who take permanent responsibility for all of it. A phone agent additionally demands real-time operation and telephony integration, which is continuous operations, not a weekend project. Local AI therefore pays off mainly for businesses with their own IT team and specialist requirements. The European cloud delivers the sovereignty benefits without that operational burden: EU servers, an EU contracting party, a DPA under Art. 28 GDPR, and the provider handles operations and updates. rinqo deliberately chose this route. Hosting runs on Hetzner in Falkenstein and Nuremberg (ISO 27001:2022). Language-model processing runs contractually guaranteed within the EU, with no training on your data. A purely European fallback provider is available as an opt-in failover. We handle the setup, several agents (phone, chat, email, personal assistant, marketing agent) work in 17+ languages. The sober calculation is: full control versus predictable operations. For phone, chat and email in everyday SME work, the cloud wins almost every time.
Frequently asked questions
Sources
- EU AI Regulation 2024/1689, Art. 50
- ECJ ruling C-311/18 (Schrems II)
- EDSA, Empfehlungen 01/2020 zu ergänzenden Maßnahmen bei Drittlandtransfers
- GDPR Art. 28 (Processor)
Last updated: 2026-09-05

Founder, rinqo
Founder of rinqo. Builds a company memory where an organisation's knowledge comes together and stays available, and the AI agents that work from it: on the phone, in the inbox, in chat, in marketing and in further roles. Writes here about bringing AI into companies, about data protection, and about what holds up in daily operation. Developed in Germany, processed in the EU, no US providers.
Last updated:
Try it live
View agent