Inkolumis runs e-commerce, healthcare and legal platforms on infrastructure held entirely within EU jurisdiction. No US-incorporated cloud sits anywhere in the chain, so there is no CLOUD Act exposure to explain to a client.
Most EU cloud hosting providers stop at data residency: your files sit in an EU data centre, such as 'AWS EU (Frankfurt)' or 'Azure West Europe', but the company operating it is still US-incorporated, subject to the US CLOUD Act regardless of where the hardware sits. Genuine sovereignty requires the data to sit in the EU and the operator to sit outside US jurisdiction entirely. Inkolumis is operated by a UK-incorporated company, and the UK holds its own EU Commission adequacy decision, renewed to 2031, unlike the contested EU-US framework the American hyperscalers rely on.
A brochure page and a patient booking portal carry different exposure, so our GDPR compliant hosting starts with a simple entry tier, then splits into three sector packages built around the specific liability each one carries.
For sites that inform visitors: no customer data, no login, no database.
For sites that store something. Priced against
comparable compliance-grade hosting across the market.
Checkout flows, customer accounts, order history
Positioned against PCI-scope managed hosting, which runs €55 to 400+/mo depending on how much of the environment is dedicated.
Booking systems, patient portals, appointment records
Positioned against the market for signed-DPA health-data hosting, which runs roughly €110 to 550/mo for a single practice.
Client portals, document access, confidential records
Positioned between generic managed hosting and full compliance-hosting pricing, reflecting a control problem rather than a certification one.
Starting prices assume a single site or environment at typical traffic. A quote follows the 15-minute infrastructure review, and reflects your actual traffic, storage and compliance scope.
PCI DSS is a contractual obligation you accepted with your acquiring bank. Nothing enforces it automatically the way a statute would. What actually happens without it: your processor can raise fees or restrict your account, and if a breach hits while you're non-compliant, you carry the fraud losses and forensic costs yourself.
We route card data through your payment provider (Stripe, Adyen) rather than storing it on our servers, which keeps your PCI scope small. What we secure directly is everything around the transaction: the checkout page, customer accounts, and order history, encrypted, isolated, and logged.
Article 9 of the GDPR classes health data as a special category, with stricter rules than ordinary personal data. Some member states go further: France, for example, requires an HDS-certified host for anything touching patient records. We build the compliance picture for your specific country before we build the server.
Booking forms, patient portals and appointment systems get a dedicated environment, a signed DPA with health-data clauses, and access logs someone actually reviews. Not a checkbox: a running practice.
For a law firm, the constraint is the duty of confidentiality, which predates GDPR's special categories and sits above them. That shifts the priority from certificates to control: who can access a client matter, when, and whether that access is provable afterwards.
We build around strict, key-based access control and an audit trail that holds up if a client or a regulator ever asks who touched a file and when.
This reflects where EU procurement is already
heading, driven by law that is already in force.
Send your current hosting setup and the jurisdiction it sits in. You get a direct answer on what's at risk and what moving would involve. Fifteen minutes, no follow-up calls unless you ask for one.