Skip to content

Sovereignty and data residency

Last updated:

This page covers the legal entity, governing law, and data path behind the “EU-only, no asterisks” claim. For the specific services that process your data, see sub-processors.

Codebahn is operated by Hackerman AB, incorporated in Sweden. Org. nr 559079-1918. Registered address: Drakenbergsgatan 33, 412 69 Gothenburg, Sweden.

Swedish-owned. Independent. Self-funded. The entity that signs your contract is the same entity that operates the service.

Contracts are governed by Swedish law. The Data Processing Agreement follows GDPR. There is no arbitration clause routing disputes to a US jurisdiction.

Every sub-processor is EU-incorporated. No data leaves the EU for storage, processing, or analytics. CI jobs resolve the most common GitHub Actions from local mirrors on the instance, so action code is fetched within the EU. See sub-processors for the service-by-service list with locations, providers, and retention details.

Data is encrypted in transit (TLS 1.2+, with 1.3 where supported by both endpoints) and at rest (AES-256). Server logs with IP addresses are kept for 30 days. Billing records are kept for seven years, as Swedish bookkeeping law requires.

The US CLOUD Act compels US-incorporated companies to produce data stored abroad on US government request. Codebahn is not a US company and has no US parent. The Act does not apply.

Ticking “EU region” on a US-owned service changes the datacenter, not the legal entity that controls your data. That distinction is the point.

The EU’s tech sovereignty agenda defines the goal: Europe should be able to develop and control its own digital infrastructure without depending on non-EU providers. Source code hosting is part of that infrastructure.

Codebahn meets that bar by construction, not by bolt-on. The entity is Swedish. The servers are French and German. The contracts are governed by EU law. There is no US parent that could be compelled under the CLOUD Act, and no acquisition path that would change that.

If your organization is evaluating providers against EU digital sovereignty requirements, the relevant facts are on this page and the sub-processors list.

The NIS2 Directive (Article 21(2)(d)) requires entities in scope to assess the security of their supply chain, including the jurisdiction and data residency of each supplier. Source code hosting is part of that supply chain. 24 of 27 EU member states have transposed NIS2 into national law.

For financial entities, DORA adds prescriptive ICT third-party risk management requirements on top of NIS2.

Codebahn publishes the answers these assessments require: NIS2 supplier assessment, DORA register of information, sub-processor list, and security posture. No NDA required.

We do not hold ISO 27001 or SOC 2 Type II. If your procurement requires those signed audit reports today, we are not your vendor yet. We intend to pursue certification; we are not there now.