EU and Privacy
A platform you can defend
to a client's legal team.
Belgian company under EU jurisdiction. Customer data hosted in the EU. GDPR consent built into the platform. Your client's compliance posture becomes part of the platform you choose, by architecture rather than by a setting someone has to remember to switch on.
EU law is the law that applies to your client's data
Nimbu is built and run by Zenjoy, a Belgian company under EU jurisdiction, regulated by the APD (Autorité de protection des données / Gegevensbeschermingsautoriteit). Customer data is hosted in the EU.
Which legal system has authority
Most platforms answer the privacy question with where the servers happen to sit this quarter. The question underneath it is which legal system has authority over the company holding the data. For Nimbu, that system is European, and it does not change when a data-transfer framework is renegotiated or struck down in court.
Jurisdiction is not a configuration screen
A US-incorporated vendor can host EU data in Frankfurt and still answer to a different legal system. A Belgian company under the APD answers to one. That distinction is structural. It is not something a region setting in a control panel can replicate.
One answer to give the DPO
When a client's DPO or legal team asks where the data lives and who can reach it, you want a clean answer in the proposal rather than a research project. Belgian company, APD jurisdiction, EU-hosted data. That is the answer.
That ordering matters.
Server location and legal jurisdiction are two different questions
This is the structural fact, stated once and plainly. Any CMS or commerce platform incorporated in the United States is reachable by US authorities under the CLOUD Act, regardless of where its servers are located.
What the CLOUD Act does
The US CLOUD Act (2018) lets US authorities compel a US-incorporated company to produce data it controls, even when that data is stored on infrastructure in the EU. This is a fact about how those companies are organised as legal entities, not a claim about any specific vendor.
Why it surfaced publicly
In 2025, Microsoft France testified before the French Senate that it could not guarantee EU customer data would never be transferred to US authorities, because the parent company is subject to US law. The server region was European. The jurisdiction was not.
What this means for your client
Server location and a Data Privacy Framework certification address transfer mechanics. They do not change which legal system has ultimate authority over the company. A Belgian company under EU jurisdiction is a different answer to a different question, and it is the answer you can put in writing.
Server region was European. The jurisdiction was not.
Native consent
One tag replaces a third-party consent tool
Consent ships with the platform. You model purposes, applications, and cookies once, with required, opt-out, and default flags, and translatable copy for every locale. Then you drop one Liquid tag into any theme. The consent banner renders privacy-first, served from Nimbu's CDN.
What this removes is a whole class of audit risk. A bolted-on consent tool is a separate vendor with a separate contract that drifts out of compliance when nobody is watching it. When consent is part of the platform, it is part of every site you ship, by default.
- Model purposes per site Required, opt-out, and default flags with translatable copy for every locale.
- CDN-served banner Script served from Nimbu. No third-party CMP to license, configure, or keep current.
- Ships on day one Every site you build handles consent from the moment it goes live, in every language.
Sensitive fields encrypted at rest, keys held in the EU
Sensitive customer fields are encrypted at rest, with the keys held in the EU. To be precise about scope, because precision is the point: this is field-level encryption for designated sensitive fields, not full-database encryption.
The encryption is part of the data model. When you model a channel, an encrypted field type is available alongside text, select, relation, and date. Sensitive data is handled at the storage layer rather than patched in afterward.
- Part of the data model Encrypted field type available at channel creation, not retrofitted.
- Keys held in the EU EU key management. Not a US-incorporated parent under the CLOUD Act.
- Honest about scope Field-level encryption for designated sensitive fields. That is what we claim and what we deliver.
The answer you can hand to a client's legal team
When a client signs with your agency, they inherit the compliance posture of the platforms you build on. A platform with EU jurisdiction, EU-hosted data, and field-level encryption of sensitive data is a posture you can hand a client without a caveat.
-
Belgian company under APD jurisdiction
EU law is the law that applies to your client's data, by structure not by setting.
-
Customer data hosted in the EU
Not a region setting. EU-hosted by default for every site on the platform.
-
GDPR consent built in
One consent_manager tag. CDN-served banner. No third-party CMP to license or audit.
-
Sensitive fields encrypted with EU-held keys
Field-level, honest scope. Part of the data model from day one.
-
Not a US-incorporated entity under the CLOUD Act
A structural fact about how Nimbu is organised. It is the answer you put in writing.
-
DPA and subprocessor list available on request
The procurement document set a client's legal team will ask for, at /security.
Proposal ready
A block you can paste into a client proposal
This uses only claims Nimbu stands behind. Copy it into an RFP response or a proposal as-is. Do not extend it to claims Nimbu does not make.
Data protection and EU jurisdiction
This site is built on Nimbu, a European site and commerce platform operated by Zenjoy, a Belgian company. As an EU-incorporated company, Nimbu is under EU jurisdiction and is registered with the Belgian data protection authority (APD, Autorité de protection des données / Gegevensbeschermingsautoriteit).
- Hosting: Customer data is hosted in the EU.
- Consent: GDPR consent and cookie management are built into the platform, including a CDN-served consent banner configured per site and per language.
- Encryption: Sensitive customer fields are encrypted at rest, with encryption keys held in the EU.
- Jurisdiction: As a Belgian company under EU jurisdiction, Nimbu is not a US-incorporated entity subject to the US CLOUD Act.
A Data Processing Agreement (DPA) and a current subprocessor list are available on request.
Keep it factual and keep it inside these lines.
When the client's legal team asked where the data lived and who could reach the authenticated parts, we had the EU jurisdiction and APD answer in the proposal, and the platform that actually delivered the portal.
Book a demo and bring a real client scenario
We will walk through jurisdiction, EU hosting, built-in consent, and field-level encryption against the kind of question your client's legal team is going to ask you. 30 minutes. A personal reply.
Request received.
We read every request personally and will get back to you to schedule the call.
Book a demo
We reply personally to plan a 30-minute call.
Something went wrong while sending. Please try again in a moment.