Where we operate

Europe

SAP Business One cloud hosting in the EU, EEA and United Kingdom.

  • Germany
  • Netherlands
  • France
  • Spain
  • Italy
  • Ireland

Support: 24/7 support in English, French and Spanish, aligned to European business hours.

Overview

The most regulated market we serve, and the one where getting residency and documentation right is not optional. GDPR sets the baseline, NIS2 raises the bar on operational security for a widening list of sectors, and DORA adds a further layer for financial entities and their ICT providers. We deploy into EU regions and keep the paperwork a European DPO will ask for.

Markets served

  • Germany
  • Netherlands
  • France
  • Spain
  • Italy
  • Ireland
  • Belgium
  • Sweden
  • Poland
  • Switzerland
  • United Kingdom

Data stays in the EU or EEA region you choose, with backups and disaster recovery copies kept within the same jurisdiction unless you instruct otherwise. UK customers can be kept entirely within UK South and UK West. Where a transfer outside the EEA is genuinely required, it runs on Standard Contractual Clauses with a documented transfer impact assessment.

Microsoft Azure

Netherlands, UK, Ireland, Sweden, Spain & others

AWS

Ireland, Germany, UK, Spain, Sweden & Others

Huawei Cloud

Ireland & Turkey

GDPR (Regulation (EU) 2016/679)

What it governs

The EU's general data protection regulation: lawful basis, data subject rights, security of processing, breach notification within 72 hours, and restrictions on international transfer.

How we support it

EU region deployment, encryption in transit and at rest, access control and logging, a written processor agreement under Article 28, records of processing on our side, and breach detection and notification support inside the 72 hour window.

UK GDPR and Data Protection Act 2018

What it governs

The UK's post Brexit equivalent regime, with its own transfer mechanism.

How we support it

UK South and UK West deployment for full UK residency, the UK International Data Transfer Agreement or Addendum where a transfer is needed, and equivalent processor documentation.

NIS2 Directive (EU 2022/2555)

What it governs

Raises cybersecurity and incident reporting obligations for essential and important entities across a widened set of sectors, and extends to their supply chain.

How we support it

Supply chain security evidence, risk management measures, and incident detection and reporting support on the infrastructure we operate, which is the part of your NIS2 posture you outsource to us.

DORA (Regulation (EU) 2022/2554)

What it governs

Digital operational resilience for EU financial entities, with specific requirements on contracts with ICT third party providers and on resilience testing.

How we support it

Contractual terms addressing the ICT third party requirements, tested disaster recovery with documented results, exit and portability arrangements, and the incident reporting a financial entity must be able to produce.

EU Data Act (Regulation (EU) 2023/2854)

What it governs

Cloud switching, portability and lock in provisions applying to data processing services.

How we support it

Documented exit and data portability arrangements, so leaving is a defined process with a defined format rather than a negotiation.

Standard Contractual Clauses (post Schrems II)

What it governs

The mechanism for lawfully transferring personal data outside the EEA, together with a transfer impact assessment.

How we support it

SCCs in the processing agreement where a transfer is necessary, supplementary technical measures, and our input to your transfer impact assessment. In most cases we simply keep the data in the EEA and the question does not arise.

ISO/IEC 27001:2022

What it governs

The international standard for information security management systems.

How we support it

Our practice is aligned to ISO/IEC 27001:2022 across access control, cryptography, operations security, supplier relationships and incident management.

Compliance is shared between provider and customer. We provide the infrastructure controls, evidence and documentation on our side of that line: residency, encryption, access control, backup, monitoring and incident response. Your obligations as data controller remain yours. This page is general information, not legal advice; confirm your specific obligations with your own counsel.

Move to the cloud, the right way.

Let's talk about your SAP environment, your security and your growth plan. Migration with minimal disruption is what we do.

Common questions

Is our data guaranteed to stay in the EU?

If you choose an EU region, yes. Primary data, backups and disaster recovery copies all stay within it unless you instruct us otherwise. We state in the agreement which components sit in which region.

Are you GDPR compliant?

We act as processor and provide what a processor must: an Article 28 agreement, EU region residency, encryption, access control and logging, records of processing, and breach notification support inside the 72 hour window. Your obligations as controller (lawful basis, notices, data subject rights) remain yours, and we support you in meeting them.

Can UK customers keep everything in the UK?

Yes. Azure UK South and UK West, or AWS Europe (London), keep primary data and copies entirely within the United Kingdom under UK GDPR.

Does NIS2 apply to us because we use a cloud provider?

NIS2 applies based on your own sector and size, not on your use of cloud. But if it applies to you, it reaches your supply chain, which means you will need security and incident reporting evidence from us. We provide it.

Are you ISO 27001 certified?

Our practice is aligned to ISO/IEC 27001:2022, and that control set is what we operate to. We are explicit about the distinction between alignment and certification rather than blurring it, and we will share our control documentation on request.