Talk to a direct support line +34 856 534 537
EU-sovereign infrastructure

Servers we own, governed by EU law alone.

Inkolumis runs e-commerce, healthcare and legal platforms on infrastructure held entirely within EU jurisdiction. No US-incorporated cloud sits anywhere in the chain, so there is no CLOUD Act exposure to explain to a client.

Owned VPS fleetEU data centres, EU jurisdiction
No US parent entityoutside CLOUD Act reach
Fully managedour team monitors and patches
Named accountabilityone team, one point of contact

'EU-hosted' and 'EU-sovereign'
are two different claims.

Most EU cloud hosting providers stop at data residency: your files sit in an EU data centre, such as 'AWS EU (Frankfurt)' or 'Azure West Europe', but the company operating it is still US-incorporated, subject to the US CLOUD Act regardless of where the hardware sits. Genuine sovereignty requires the data to sit in the EU and the operator to sit outside US jurisdiction entirely. Inkolumis is operated by a UK-incorporated company, and the UK holds its own EU Commission adequacy decision, renewed to 2031, unlike the contested EU-US framework the American hyperscalers rely on.

Question
Typical 'EU-hosted' provider
Inkolumis
Is the operating company US-incorporated?
Usually, yes
No. RoI² Ltd is UK-incorporated. The UK holds an EU Commission adequacy decision, renewed to 2031, confirming essentially equivalent data protection to the GDPR
Who operates the physical servers?
A US hyperscaler (AWS, Azure, GCP)
Inkolumis, on our own infrastructure, located in the EU
Subject to the US CLOUD Act?
Yes, regardless of server location
No
Can you name who is accountable if something fails?
Rarely: routed through a support ticket
Yes: a named team, from day one

Priced for what's
actually at risk.

A brochure page and a patient booking portal carry different exposure, so our GDPR compliant hosting starts with a simple entry tier, then splits into three sector packages built around the specific liability each one carries.

Entry tier

Website Hosting

For sites that inform visitors: no customer data, no login, no database.

from €29/mo, per site, billed monthly
  • Marketing sites, CMS, static pages, contact forms
  • EU data residency on infrastructure we own
  • TLS everywhere, daily backups, WAF, automated patching
  • GDPR-aware handling of form submissions
  • Fully managed: our team runs monitoring, patching and backups
  • Direct support line, answered by the same team every time
Every server is dedicated. Nobody shares your hardware.
  • One physical environment per client. No shared tenancy, at any tier, ever.
  • 99.95% uptime guaranteed, verified against an independent third-party monitor.
  • A full month's fee credited if we miss it. Not the 5 to 20 percent partial credits most hosts cap out at.
  • 30-day claim window, matched to the most generous terms in the market rather than the 5-day window some competitors quietly enforce.
  • Scheduled maintenance still counts toward the guarantee. No 2am-to-5am window where downtime magically stops being downtime.

Secure Data Hosting, by sector

For sites that store something. Priced against
comparable compliance-grade hosting across the market.

E-commerce

Store Hosting

Checkout flows, customer accounts, order history

from €89/mo

Positioned against PCI-scope managed hosting, which runs €55 to 400+/mo depending on how much of the environment is dedicated.

  • Dedicated server, isolated from every other client
  • PCI scope kept small by routing card data through Stripe or Adyen
  • Checkout page, accounts and order history encrypted and logged
  • Signed DPA included as standard
Healthcare & clinics

Clinic Hosting

Booking systems, patient portals, appointment records

from €249/mo

Positioned against the market for signed-DPA health-data hosting, which runs roughly €110 to 550/mo for a single practice.

  • Dedicated server, isolated from every other client
  • Signed DPA with health-data clauses, matched to your country's rules
  • Access logs someone actually reviews on a regular schedule
  • Country-specific compliance check before go-live, e.g. HDS in France
Legal practices

Legal Hosting

Client portals, document access, confidential records

from €129/mo

Positioned between generic managed hosting and full compliance-hosting pricing, reflecting a control problem rather than a certification one.

  • Dedicated server, isolated from every other client
  • Strict, key-based access control per client matter
  • Audit trail that holds up if a client or regulator asks who accessed what
  • Signed DPA included as standard

Starting prices assume a single site or environment at typical traffic. A quote follows the 15-minute infrastructure review, and reflects your actual traffic, storage and compliance scope.

Built for three specific kinds of exposure.

E-commerce

Liability extends well beyond payment data.

PCI DSS is a contractual obligation you accepted with your acquiring bank. Nothing enforces it automatically the way a statute would. What actually happens without it: your processor can raise fees or restrict your account, and if a breach hits while you're non-compliant, you carry the fraud losses and forensic costs yourself.

We route card data through your payment provider (Stripe, Adyen) rather than storing it on our servers, which keeps your PCI scope small. What we secure directly is everything around the transaction: the checkout page, customer accounts, and order history, encrypted, isolated, and logged.

Healthcare & clinics

Health data is a special category under GDPR, treated as such from day one.

Article 9 of the GDPR classes health data as a special category, with stricter rules than ordinary personal data. Some member states go further: France, for example, requires an HDS-certified host for anything touching patient records. We build the compliance picture for your specific country before we build the server.

Booking forms, patient portals and appointment systems get a dedicated environment, a signed DPA with health-data clauses, and access logs someone actually reviews. Not a checkbox: a running practice.

Legal practices

Client confidentiality is a professional duty that predates data-protection law.

For a law firm, the constraint is the duty of confidentiality, which predates GDPR's special categories and sits above them. That shifts the priority from certificates to control: who can access a client matter, when, and whether that access is provable afterwards.

We build around strict, key-based access control and an audit trail that holds up if a client or a regulator ever asks who touched a file and when.

The regulatory direction is clear.

This reflects where EU procurement is already
heading, driven by law that is already in force.

72h
Window under GDPR Article 33 to notify a data breach from the moment you become aware of it. Your host's response time is part of whether you make that window.
2025
The EU Cloud Sovereignty Framework, published October 2025, introduced a scoring mechanism that assesses a provider's exposure to foreign jurisdiction, including the US CLOUD Act.
NIS2
Extends cybersecurity obligations to a much wider range of mid-sized companies across the EU. Many are only now discovering their hosting provider is the weak link.
24/7
Same-day support response, every day of the week, weekends included. Stated as a precise commitment.

A named engineer reviews your setup
and tells you plainly what's exposed.

Send your current hosting setup and the jurisdiction it sits in. You get a direct answer on what's at risk and what moving would involve. Fifteen minutes, no follow-up calls unless you ask for one.